Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

kontrola logu (combofix) - opravení spouštění pevných disků

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu (combofix) - opravení spouštění pevných di

#16 Příspěvek od Caroprd111 »

Obrázek Stáhněte OTL http://oldtimer.geekstogo.com/OTL.exe na plochu
  • Spusťte, poté do spodního políčka vložte následující skript.

Kód: Vybrat vše

 netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys 
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys 
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
tcpip.sys
cryptsvc.dll
Changer.sys
JakNDis.sys
isapnp.sys 
cdrom.sys 
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav 
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
CREATERESTOREPOINT 
  • Označte položku Pro všechny uživatele.
  • Označte položky Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
  • Klikněte na tlačítko Prohledat
  • Po dokončení, sem vložte logy OTL.Txt a Extras.txt
Obrázek

krataska
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 01 zář 2010 10:53

Re: kontrola logu (combofix) - opravení spouštění pevných di

#17 Příspěvek od krataska »

OTL logfile created on: 8.9.2010 19:24:47 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\petra\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

767.00 Mb Total Physical Memory | 43.00 Mb Available Physical Memory | 6.00% Memory free
1.00 Gb Paging File | 0.00 Gb Available in Paging File | 36.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 25.39 Gb Total Space | 2.02 Gb Free Space | 7.96% Space Free | Partition Type: NTFS
Drive D: | 49.13 Gb Total Space | 5.96 Gb Free Space | 12.13% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 1.31 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 74.55 Gb Total Space | 33.67 Gb Free Space | 45.17% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TEST-3A14A8A427
Current User Name: petra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.09.08 19:19:40 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\petra\Plocha\OTL.exe
PRC - [2010.08.30 20:31:07 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.06.01 14:53:46 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010.03.25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009.11.16 17:36:19 | 000,172,792 | ---- | M] (ICQ, LLC.) -- C:\Program Files\ICQ6.5\ICQ.exe
PRC - [2009.01.13 23:54:35 | 000,603,904 | ---- | M] (TuneUp Software) -- C:\WINDOWS\system32\TUProgSt.exe
PRC - [2007.11.08 23:40:06 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2004.12.27 21:14:18 | 000,057,344 | ---- | M] (SlySoft, Inc.) -- C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
PRC - [2004.08.18 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004.08.09 07:03:38 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2003.05.14 07:20:02 | 000,055,296 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2002.06.03 11:38:12 | 000,049,152 | ---- | M] (ScanSoft, Inc) -- C:\Program Files\ScanSoft\OmniPageSE\opware32.exe


========== Modules (SafeList) ==========

MOD - [2010.09.08 19:19:40 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\petra\Plocha\OTL.exe
MOD - [2004.08.18 14:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
MOD - [2004.08.18 14:00:00 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2002.06.03 11:37:50 | 000,167,936 | ---- | M] (ScanSoft, Inc) -- C:\Program Files\ScanSoft\OmniPageSE\ophook32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2010.03.25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2009.01.13 23:54:35 | 000,603,904 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)
SRV - [2009.01.13 23:54:29 | 000,360,192 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\WINDOWS\system32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2008.12.11 14:31:36 | 000,027,904 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2008.07.29 19:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2007.08.09 09:27:52 | 000,073,728 | ---- | M] (HP) [Auto | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2006.11.03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2005.08.10 23:17:28 | 000,118,272 | ---- | M] (TuneUp Software GmbH) [On_Demand | Stopped] -- C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe -- (TUWinStylerThemeSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - File not found [Kernel | On_Demand | Running] -- C:\DOCUME~1\petra\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010.03.25 21:30:22 | 000,151,216 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2008.07.02 19:55:43 | 000,278,984 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2007.05.04 21:11:18 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2005.03.03 19:53:57 | 000,048,640 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.02.23 17:59:54 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005.01.02 03:10:37 | 000,026,240 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2005.01.02 03:07:05 | 000,009,728 | ---- | M] (Elaborate Bytes AG) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2004.12.03 12:20:41 | 000,020,544 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2004.08.09 13:33:26 | 000,114,016 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\prohlp02.sys -- (prohlp02)
DRV - [2004.08.09 13:29:28 | 000,053,920 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\prodrv06.sys -- (prodrv06)
DRV - [2004.08.04 01:08:22 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2004.07.19 16:49:54 | 000,007,040 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\prosync1.sys -- (prosync1)
DRV - [2004.03.22 22:59:52 | 000,701,440 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2003.12.01 17:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp01.sys -- (sfhlp01)
DRV - [2003.05.14 12:44:06 | 000,740,044 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2001.08.18 00:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003\..\URLSearchHook: {3e1a778f-6ffb-46a4-8810-070db1c563fd} - C:\Program Files\YouTubeVideo\tbYouT.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 208.62.125.146:80

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/result ... EF&v=18&q="
FF - prefs.js..browser.search.order.1: "Fast Browser Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163"
FF - prefs.js..browser.search.selectedEngine: "Fast Browser Search"
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:3.2.9
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "chrome://browser-region/locale/region.properties"


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.09.08 16:14:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.09.08 16:14:40 | 000,000,000 | ---D | M]

[2008.07.07 17:56:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Mozilla\Extensions
[2010.09.08 16:21:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Mozilla\Firefox\Profiles\5gsazu8b.default\extensions
[2010.09.05 10:09:56 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\petra\Data aplikací\Mozilla\Firefox\Profiles\5gsazu8b.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009.06.08 12:13:00 | 000,000,000 | ---D | M] (Quick Locale Switcher) -- C:\Documents and Settings\petra\Data aplikací\Mozilla\Firefox\Profiles\5gsazu8b.default\extensions\{25A1388B-6B18-46c3-BEBA-A81915D0DE8F}
[2009.04.12 18:45:45 | 000,000,000 | ---D | M] (Boost for Facebook) -- C:\Documents and Settings\petra\Data aplikací\Mozilla\Firefox\Profiles\5gsazu8b.default\extensions\{47624dda-b77e-4feb-820a-e4f077d5d4ca}
[2009.12.05 10:46:54 | 000,000,000 | ---D | M] (ImTranslator) -- C:\Documents and Settings\petra\Data aplikací\Mozilla\Firefox\Profiles\5gsazu8b.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2008.12.25 16:59:22 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\petra\Data aplikací\Mozilla\Firefox\Profiles\5gsazu8b.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2009.06.12 16:12:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Mozilla\Firefox\Profiles\5gsazu8b.default\extensions\illimitux@illimitux.net
[2008.12.25 16:59:13 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\petra\Data aplikací\Mozilla\Firefox\Profiles\5gsazu8b.default\searchplugins\sweetim.xml
[2010.08.31 11:11:46 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.08.03 15:07:42 | 000,373,104 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
[2009.09.11 11:06:38 | 000,003,700 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fast.png
[2009.09.11 11:06:39 | 000,001,963 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fast.xml
[2010.05.15 20:50:25 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.05.15 20:50:25 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.05.15 20:50:25 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.05.15 20:50:25 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.05.15 20:50:25 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2010.09.08 16:48:01 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {055FD26D-3A88-4e15-963D-DC8493744B1D} - No CLSID value found.
O2 - BHO: (YouTubeVideo Toolbar) - {3e1a778f-6ffb-46a4-8810-070db1c563fd} - C:\Program Files\YouTubeVideo\tbYouT.dll (Conduit Ltd.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (YouTubeVideo Toolbar) - {3e1a778f-6ffb-46a4-8810-070db1c563fd} - C:\Program Files\YouTubeVideo\tbYouT.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003\..\Toolbar\WebBrowser: (YouTubeVideo Toolbar) - {3E1A778F-6FFB-46A4-8810-070DB1C563FD} - C:\Program Files\YouTubeVideo\tbYouT.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CloneCDTray] C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe (SlySoft, Inc.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Místní vyhledávání.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1957994488-2111687655-1343024091-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_13.dll (Sun Microsystems, Inc.)
O9 - Extra Button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - C:\Program Files\FlashCapture\fciext.dll File not found
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {32564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv8dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-95C8-443543540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.3.30.65 62.240.184.2
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll ()
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\petra\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\petra\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.08.05 14:51:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009.03.12 19:53:38 | 000,000,000 | ---D | M] - G:\Autonehoda 23.1.2009 -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027075282206720)

========== Files/Folders - Created Within 30 Days ==========

[2010.09.08 19:19:23 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\petra\Plocha\OTL.exe
[2010.09.08 16:38:47 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.09.08 16:38:47 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.09.08 16:38:47 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.09.08 16:38:47 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.09.08 16:14:03 | 000,389,488 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\petra\Plocha\OGAPluginInstall.exe
[2010.09.06 10:26:43 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\petra\PrivacIE
[2010.09.06 08:44:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\petra\Plocha\test
[2010.09.03 20:34:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\petra\Plocha\Skalná
[2010.09.03 15:52:11 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010.09.03 09:49:13 | 000,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2010.09.03 09:49:13 | 000,017,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
[2010.09.02 16:30:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010.09.02 16:23:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2010.09.02 16:23:00 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2010.09.02 16:22:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2010.09.02 16:22:45 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2010.09.02 16:21:39 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2010.09.02 16:21:39 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010.09.02 16:21:38 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2010.09.02 16:21:38 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010.09.02 16:21:38 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010.09.02 16:21:38 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010.09.02 16:12:10 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\petra\IETldCache
[2010.09.02 16:08:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010.09.02 16:06:44 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010.09.02 16:00:57 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010.09.02 15:13:29 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0
[2010.09.02 15:05:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2010.09.02 15:03:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie7updates
[2010.09.02 15:02:59 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010.09.02 11:42:06 | 000,221,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2010.09.02 11:14:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot_bak
[2010.09.02 10:25:10 | 000,272,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthport.sys
[2010.09.02 10:23:43 | 000,454,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2010.09.02 10:18:36 | 002,060,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2010.09.02 10:18:35 | 002,018,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2010.09.02 10:18:34 | 002,183,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2010.09.02 10:18:29 | 002,139,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2010.09.02 10:14:19 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browserchoice.exe
[2010.09.01 23:23:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2010.09.01 15:16:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\petra\Plocha\gmer
[2010.09.01 15:08:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2010.09.01 15:02:41 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.09.01 15:02:39 | 000,000,000 | ---D | C] -- C:\rsit
[2010.09.01 14:38:34 | 000,610,800 | ---- | C] (Duplex Secure Ltd.) -- C:\Documents and Settings\petra\Plocha\SPTDinst-v172-x86.exe
[2010.09.01 11:00:54 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.09.01 10:58:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.09.01 10:57:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2026.05.26 23:09:54 | 000,003,120 | ---- | M] () -- C:\WINDOWS\MF_C421.lfa
[2026.05.26 23:09:54 | 000,003,120 | ---- | M] () -- C:\WINDOWS\MF_C420.lfa
[2010.09.08 19:19:40 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\petra\Plocha\OTL.exe
[2010.09.08 19:07:05 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010.09.08 19:00:00 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2010.09.08 19:00:00 | 000,000,478 | ---- | M] () -- C:\WINDOWS\tasks\Úklid 1 kliknutím.job
[2010.09.08 18:47:01 | 000,000,940 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.09.08 16:56:17 | 000,266,240 | ---- | M] () -- C:\Documents and Settings\petra\Plocha\log.doc
[2010.09.08 16:50:43 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.09.08 16:48:13 | 000,001,051 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.09.08 16:48:01 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.09.08 16:37:18 | 003,840,033 | R--- | M] () -- C:\Documents and Settings\petra\Plocha\ComboFix.exe
[2010.09.08 16:29:23 | 012,845,056 | ---- | M] () -- C:\Documents and Settings\petra\NTUSER.DAT
[2010.09.08 16:15:15 | 000,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.09.08 16:14:21 | 000,389,488 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\petra\Plocha\OGAPluginInstall.exe
[2010.09.08 16:14:17 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.09.08 16:09:27 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.09.08 16:08:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.09.06 14:54:03 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\petra\ntuser.ini
[2010.09.04 09:03:57 | 000,465,336 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.09.04 09:03:56 | 000,080,082 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.09.04 09:03:55 | 000,481,832 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2010.09.04 09:03:55 | 000,101,990 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2010.09.04 09:03:53 | 001,146,378 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.09.04 00:11:40 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.09.02 22:42:26 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.09.02 16:30:28 | 000,000,832 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Microsoft Security Essentials.lnk
[2010.09.02 16:28:56 | 000,083,432 | ---- | M] () -- C:\Documents and Settings\petra\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2010.09.02 16:28:25 | 002,354,504 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.09.01 15:12:38 | 000,077,312 | ---- | M] () -- C:\Documents and Settings\petra\Plocha\mbr.exe
[2010.09.01 15:02:22 | 000,339,991 | ---- | M] () -- C:\Documents and Settings\petra\Plocha\RSIT.exe
[2010.09.01 14:59:51 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\petra\Plocha\Defogger.exe
[2010.09.01 14:38:35 | 000,610,800 | ---- | M] (Duplex Secure Ltd.) -- C:\Documents and Settings\petra\Plocha\SPTDinst-v172-x86.exe
[2010.09.01 11:01:00 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2010.08.31 20:56:42 | 000,215,552 | ---- | M] () -- C:\Documents and Settings\petra\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.28 20:58:18 | 000,205,494 | ---- | M] () -- C:\Documents and Settings\petra\Plocha\BonJovi001.jpg
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]

========== Files Created - No Company Name ==========

[2026.05.26 23:09:54 | 000,003,120 | ---- | C] () -- C:\WINDOWS\MF_C421.lfa
[2026.05.26 23:09:54 | 000,003,120 | ---- | C] () -- C:\WINDOWS\MF_C420.lfa
[2010.09.08 16:56:17 | 000,266,240 | ---- | C] () -- C:\Documents and Settings\petra\Plocha\log.doc
[2010.09.08 16:38:47 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.09.08 16:38:47 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.09.08 16:38:47 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.09.08 16:38:47 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.09.08 16:38:47 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.09.02 16:35:57 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.09.02 16:30:28 | 000,000,832 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Microsoft Security Essentials.lnk
[2010.09.01 15:08:22 | 000,077,312 | ---- | C] () -- C:\Documents and Settings\petra\Plocha\mbr.exe
[2010.09.01 15:02:14 | 000,339,991 | ---- | C] () -- C:\Documents and Settings\petra\Plocha\RSIT.exe
[2010.09.01 14:59:50 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\petra\Plocha\Defogger.exe
[2010.09.01 11:01:00 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.09.01 11:00:56 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2010.09.01 10:55:14 | 003,840,033 | R--- | C] () -- C:\Documents and Settings\petra\Plocha\ComboFix.exe
[2010.08.28 20:58:17 | 000,205,494 | ---- | C] () -- C:\Documents and Settings\petra\Plocha\BonJovi001.jpg
[2009.06.10 21:08:28 | 000,000,097 | ---- | C] () -- C:\WINDOWS\RMAC.ini
[2009.03.14 21:11:39 | 000,009,728 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2009.01.10 12:58:18 | 000,000,055 | ---- | C] () -- C:\WINDOWS\crywmvtoavi.ini
[2008.08.14 13:13:48 | 000,000,825 | ---- | C] () -- C:\WINDOWS\MyHeritage.INI
[2008.08.14 13:12:00 | 000,454,656 | ---- | C] () -- C:\WINDOWS\System32\PaintX.dll
[2008.06.21 20:14:52 | 000,025,601 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2008.06.11 02:07:20 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008.06.11 02:03:26 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008.06.11 02:03:26 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008.05.30 17:39:17 | 000,000,224 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.05.23 00:18:54 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008.04.26 20:37:07 | 000,002,816 | ---- | C] () -- C:\Documents and Settings\petra\Data aplikací\PatchUpdate_InstantShareJPG.log
[2008.04.26 20:37:07 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_InstantSHareJPG.ini
[2008.04.26 20:32:06 | 000,003,603 | ---- | C] () -- C:\Documents and Settings\petra\Data aplikací\PatchUpdate_IZClosingDiscError.log
[2008.04.26 20:32:06 | 000,000,217 | ---- | C] () -- C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini
[2008.04.26 20:30:58 | 000,046,519 | ---- | C] () -- C:\Documents and Settings\petra\Data aplikací\Update_HP_RedboxHprblog_HPSU.log
[2008.04.26 20:30:58 | 000,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2008.04.08 18:51:28 | 000,786,432 | ---- | C] () -- C:\WINDOWS\System32\libhpdf.dll
[2007.12.17 15:54:16 | 000,641,336 | ---- | C] () -- C:\Documents and Settings\petra\Data aplikací\NMM-MetaData.db
[2007.11.01 20:25:55 | 000,001,747 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\QTSBandwidthCache
[2007.07.23 10:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007.07.23 10:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007.07.23 10:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007.07.23 10:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007.07.23 10:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007.07.23 10:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2007.07.23 10:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007.07.23 10:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2007.07.23 10:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2007.05.04 21:11:18 | 000,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2007.05.04 21:11:18 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2007.02.22 21:48:25 | 000,000,129 | ---- | C] () -- C:\WINDOWS\disney.ini
[2007.02.22 21:48:22 | 000,000,175 | ---- | C] () -- C:\WINDOWS\disneysy.ini
[2007.02.05 15:49:36 | 000,021,464 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007.02.05 15:49:36 | 000,015,578 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007.02.05 15:49:30 | 000,014,936 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2006.12.27 17:13:06 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2006.12.25 14:31:07 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006.12.24 20:22:25 | 000,001,616 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
[2006.10.29 19:38:51 | 000,000,035 | ---- | C] () -- C:\WINDOWS\Worldbuilder.INI
[2006.10.03 20:26:02 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2006.08.19 21:52:05 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\petra\Local Settings\Data aplikací\fusioncache.dat
[2006.08.14 21:10:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\RussSqr.INI
[2006.08.05 15:33:05 | 000,215,552 | ---- | C] () -- C:\Documents and Settings\petra\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006.08.05 15:27:05 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2006.08.05 15:21:18 | 000,000,566 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2006.08.05 15:14:03 | 000,000,525 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2006.08.05 14:41:47 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006.03.18 15:16:04 | 000,540,178 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2005.10.14 11:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 11:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005.10.14 11:56:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 11:56:50 | 000,152,064 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 11:56:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2005.04.27 22:38:00 | 000,372,736 | ---- | C] () -- C:\WINDOWS\System32\hpzidi01.dll
[2005.04.27 22:37:49 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2005.02.17 12:31:58 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.02.17 12:31:58 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2004.03.22 22:50:40 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
[2003.04.09 15:38:04 | 000,005,664 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002.03.17 02:00:00 | 000,007,420 | ---- | C] () -- C:\WINDOWS\UA000079.DLL
[1997.06.14 02:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll

========== LOP Check ==========

[2007.11.01 11:44:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Data aplikací\Windows Desktop Search
[2009.03.04 11:19:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
[2008.12.22 11:16:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ashtons. Family Resort
[2008.04.24 22:17:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\EscapeTheMuseum
[2007.12.02 13:23:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2009.03.04 11:19:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\FarmFrenzy-PizzaParty
[2008.08.06 20:24:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\FarmFrenzy2
[2009.01.18 12:16:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Fugazo
[2008.04.25 23:31:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\HiddenSecretsNightmare
[2007.12.15 12:41:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Installations
[2008.10.11 18:09:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MumboJumbo
[2008.09.26 16:00:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MysteryChronicles
[2008.08.19 11:17:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\n7-89-o9-3r-4t-r9
[2007.12.12 14:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Oberon
[2007.12.17 15:45:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2008.12.07 12:41:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PlayFirst
[2009.01.11 12:05:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PlayPond
[2008.03.07 19:27:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sandlot Games
[2008.06.20 19:47:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ScanSoft
[2008.06.20 19:47:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SSScanAppDataDir
[2006.08.05 15:14:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SSScanWizard
[2009.02.13 16:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SugarGames
[2009.01.04 16:24:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Tages
[2009.08.25 13:13:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2007.12.04 23:03:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\The Filter
[2009.01.13 23:49:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2008.01.27 20:29:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ulead Systems
[2008.02.01 22:02:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Watermark Factory
[2008.09.24 18:12:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\YoYoGames
[2009.05.14 13:02:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Zylom
[2009.01.13 23:48:53 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{55A29068-F2CE-456C-9148-C869879E2357}
[2007.11.23 14:07:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mamka\Data aplikací\ICQ
[2007.11.16 17:32:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mamka\Data aplikací\ICQ Toolbar
[2007.12.15 18:36:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mamka\Data aplikací\PC Suite
[2009.12.24 12:10:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mamka\Data aplikací\pdfforge
[2010.04.09 21:45:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mamka\Data aplikací\ScanSoft
[2009.12.24 12:10:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mamka\Data aplikací\Search Settings
[2007.11.17 18:55:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mamka\Data aplikací\TuneUp Software
[2008.01.27 16:53:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mamka\Data aplikací\Ulead Systems
[2007.11.16 17:27:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mamka\Data aplikací\Windows Desktop Search
[2008.11.08 13:00:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Abra Academy2
[2007.02.23 10:38:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Ace
[2009.02.08 19:35:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Alien Skin
[2008.12.22 11:16:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Ashtons. Family Resort
[2008.12.07 22:03:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\avidemux
[2008.09.01 15:55:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Big Fish Games
[2010.01.16 12:49:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Canon
[2006.09.19 20:29:11 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\petra\Data aplikací\CrystalSpace
[2008.10.23 15:56:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Dragon Altar Games
[2008.08.31 19:35:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\GameHouse
[2008.12.28 20:19:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Games
[2008.12.07 22:03:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\gtk-2.0
[2009.05.22 17:58:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\ICQ
[2007.11.01 20:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\ICQ Toolbar
[2009.08.28 13:48:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Image Zone Express
[2009.05.29 11:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\IronCode
[2006.09.04 13:22:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\LANGMaster
[2008.10.26 18:18:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Mushroom Age
[2007.01.05 21:41:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\My Battle for Middle-earth(tm) II Files
[2007.04.08 14:46:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\My Games
[2007.11.19 22:28:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\NetTravel
[2007.12.28 13:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Nokia
[2007.12.28 12:48:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\PC Suite
[2008.12.07 12:41:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\PlayFirst
[2009.03.12 20:11:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Publish Providers
[2009.12.23 10:31:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Scanahand
[2006.08.05 15:14:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\ScanSoft
[2009.03.12 20:08:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Sony
[2009.03.11 18:07:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Sony Setup
[2007.12.04 12:39:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\SoundSpectrum
[2009.05.12 12:09:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Synthesia
[2008.08.14 13:11:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\The Complete Genealogy Reporter - FTB
[2006.08.07 19:58:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\The Labyrinth Plus! Edition
[2006.08.05 15:17:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\TuneUp Software
[2008.01.25 10:52:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Ulead Systems
[2009.12.30 17:46:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\uTorrent
[2007.10.15 20:19:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Windows Desktop Search
[2009.02.06 18:30:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Zoner
[2010.09.08 19:00:00 | 000,000,486 | ---- | M] () -- C:\WINDOWS\Tasks\1-Click Maintenance.job
[2010.09.08 16:14:17 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010.09.08 19:00:00 | 000,000,478 | ---- | M] () -- C:\WINDOWS\Tasks\Úklid 1 kliknutím.job

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -- [2007.11.08 23:40:06 | 000,068,856 | ---- | M] (Google Inc.)

< c:\windows\*.* /U >

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >
[2007.10.15 21:03:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2010.09.08 16:15:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2008.11.08 13:00:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Abra Academy2
[2007.02.23 10:38:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Ace
[2009.04.18 13:27:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Adobe
[2007.01.05 21:40:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\AdobeUM
[2007.05.07 17:45:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Ahead
[2009.02.08 19:35:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Alien Skin
[2007.12.02 17:30:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Apple Computer
[2006.10.29 21:07:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\ArcSoft
[2008.12.22 11:16:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Ashtons. Family Resort
[2008.12.07 22:03:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\avidemux
[2008.09.01 15:55:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Big Fish Games
[2010.01.16 12:49:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Canon
[2006.09.19 20:29:11 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\petra\Data aplikací\CrystalSpace
[2008.07.17 20:32:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\DivX
[2008.10.23 15:56:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Dragon Altar Games
[2008.08.31 19:35:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\GameHouse
[2008.12.28 20:19:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Games
[2009.08.30 21:59:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Google
[2008.12.07 22:03:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\gtk-2.0
[2006.08.07 19:56:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Help
[2006.12.24 20:22:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\HP
[2009.05.22 17:58:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\ICQ
[2007.11.01 20:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\ICQ Toolbar
[2006.08.05 14:59:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Identities
[2009.08.28 13:48:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Image Zone Express
[2007.11.01 20:29:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\InstallShield
[2009.05.29 11:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\IronCode
[2006.09.04 13:22:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\LANGMaster
[2007.12.29 20:38:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Macromedia
[2009.03.24 22:00:53 | 000,000,000 | --SD | M] -- C:\Documents and Settings\petra\Data aplikací\Microsoft
[2007.06.21 20:59:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Microsoft Games
[2008.07.07 17:56:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Mozilla
[2008.10.26 18:18:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Mushroom Age
[2007.01.05 21:41:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\My Battle for Middle-earth(tm) II Files
[2007.04.08 14:46:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\My Games
[2007.11.19 22:28:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\NetTravel
[2007.12.28 13:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Nokia
[2007.12.20 20:39:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\OpenOffice.org2
[2007.12.28 12:48:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\PC Suite
[2008.12.07 12:41:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\PlayFirst
[2008.01.24 19:01:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\PSpad
[2009.03.12 20:11:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Publish Providers
[2007.12.30 17:59:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Real
[2009.12.23 10:31:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Scanahand
[2006.08.05 15:14:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\ScanSoft
[2008.07.18 16:22:43 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\petra\Data aplikací\SecuROM
[2009.03.12 20:08:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Sony
[2009.03.11 18:07:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Sony Setup
[2007.12.04 12:39:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\SoundSpectrum
[2007.11.06 22:19:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Sun
[2009.05.12 12:09:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Synthesia
[2008.08.14 13:11:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\The Complete Genealogy Reporter - FTB
[2006.08.07 19:58:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\The Labyrinth Plus! Edition
[2006.08.05 15:17:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\TuneUp Software
[2008.01.25 10:52:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Ulead Systems
[2009.12.30 17:46:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\uTorrent
[2007.10.15 20:19:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Windows Desktop Search
[2009.02.06 18:30:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\petra\Data aplikací\Zoner

krataska
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 01 zář 2010 10:53

Re: kontrola logu (combofix) - opravení spouštění pevných di

#18 Příspěvek od krataska »

< %APPDATA%\*.exe /s >
[2008.05.29 10:03:08 | 000,037,176 | ---- | M] () -- C:\Documents and Settings\petra\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2007.10.15 21:19:54 | 000,023,558 | R--- | M] () -- C:\Documents and Settings\petra\Data aplikací\Microsoft\Installer\{A908E57D-71A3-4AE1-9A76-C239521BBED9}\_18be6784.exe
[2007.10.15 21:19:54 | 000,023,558 | R--- | M] () -- C:\Documents and Settings\petra\Data aplikací\Microsoft\Installer\{A908E57D-71A3-4AE1-9A76-C239521BBED9}\_294823.exe


< MD5 for: AGP440.SYS >
[2004.08.18 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\agp440.sys

< MD5 for: ATAPI.SYS >
[2004.08.18 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\atapi.sys
[2004.08.18 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2004.08.18 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: CDROM.SYS >
[2004.08.18 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cdrom.sys
[2009.12.22 20:39:20 | 000,062,592 | ---- | M] (Microsoft Corporation) MD5=7B53584D94E9D8716B2DE91D5F1CB42D -- C:\WINDOWS\system32\dllcache\cdrom.sys
[2009.12.22 20:39:20 | 000,062,592 | ---- | M] (Microsoft Corporation) MD5=7B53584D94E9D8716B2DE91D5F1CB42D -- C:\WINDOWS\system32\drivers\cdrom.sys
[2004.08.18 14:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtUninstallKB952011$\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2004.08.18 14:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2004.08.18 14:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\cryptsvc.dll
[2004.08.18 14:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\eventlog.dll
[2004.08.18 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2004.08.18 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004.08.18 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\explorer.exe
[2004.08.18 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2004.08.18 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\explorer.exe
[2004.08.18 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: HAL.DLL >
[2004.08.18 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2004.08.18 14:00:00 | 000,081,280 | ---- | M] (Microsoft Corporation) MD5=4AF58CA3425F28FC5E3DB47DC122F722 -- C:\WINDOWS\system32\hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\hal.dll

< MD5 for: CHANGER.SYS >
[2004.08.18 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\changer.sys

< MD5 for: ISAPNP.SYS >
[2004.08.18 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\isapnp.sys

< MD5 for: LSASS.EXE >
[2004.08.18 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2004.08.18 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2004.08.18 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ndis.sys
[2004.08.18 14:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2004.08.18 14:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys
[2004.08.18 14:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: NETLOGON.DLL >
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\SoftwareDistribution\Download\2c72bf78e3c24debcddfa92e9f03ffa3\sp2qfe\netlogon.dll
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\SoftwareDistribution\Download\9778f8cdabb029412b74f168c04bff53\sp2qfe\netlogon.dll
[2004.08.18 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2004.08.18 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004.08.18 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004.08.18 14:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2004.08.18 14:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004.08.18 14:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\scecli.dll

< MD5 for: SMSS.EXE >
[2004.08.18 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\dllcache\smss.exe
[2004.08.18 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\smss.exe
[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\smss.exe

< MD5 for: SVCHOST.EXE >
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\svchost.exe
[2004.08.18 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2004.08.18 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\dllcache\svchost.exe
[2004.08.18 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\SoftwareDistribution\Download\1d2803a1f84cfd41d61e509943d67213\sp2gdr\tcpip.sys
[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\SoftwareDistribution\Download\1d2803a1f84cfd41d61e509943d67213\sp2qfe\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\SoftwareDistribution\Download\1d2803a1f84cfd41d61e509943d67213\sp3gdr\tcpip.sys
[2004.08.18 14:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\SoftwareDistribution\Download\1d2803a1f84cfd41d61e509943d67213\sp3qfe\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\userinit.exe
[2004.08.18 14:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2004.08.18 14:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\dllcache\userinit.exe
[2004.08.18 14:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004.08.18 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2004.08.18 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2004.08.18 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\system32\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\winlogon.exe

< MD5 for: WS2_32.DLL >
[2004.08.18 14:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2004.08.18 14:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2004.08.18 14:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ws2_32.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2010.03.10 08:17:40 | 000,420,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\vbscript.dll
[7 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[1 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]

< %systemroot%\System32\config\*.sav >
[2006.08.05 15:35:37 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006.08.05 15:35:37 | 000,663,552 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006.08.05 15:35:37 | 000,462,848 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[2010.03.10 08:17:40 | 000,420,352 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\vbscript.dll
[7 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< %systemroot%\system32\drivers\*.sys /3 >
[1 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]

< %systemroot%\system32\*.* /3 >
[2010.09.08 16:15:15 | 000,002,422 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[7 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

========== Alternate Data Streams ==========

@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:417B6FAC
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:C22674B6
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:ADE16379
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:3815BC84
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:8DF68137
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:22741C1F
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:072F1F69
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:F01E7F17
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:9857FAE3
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:52641FBE
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:90865A6D
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:561B1D2B
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:7C411C08
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:52E1DB1D
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:E65E15CD
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:888AFB86
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:5C6EBC69
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:27D1368B
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D2F60835
< End of report >

krataska
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 01 zář 2010 10:53

Re: kontrola logu (combofix) - opravení spouštění pevných di

#19 Příspěvek od krataska »

OTL Extras logfile created on: 8.9.2010 19:24:47 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\petra\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

767.00 Mb Total Physical Memory | 43.00 Mb Available Physical Memory | 6.00% Memory free
1.00 Gb Paging File | 0.00 Gb Available in Paging File | 36.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 25.39 Gb Total Space | 2.02 Gb Free Space | 7.96% Space Free | Partition Type: NTFS
Drive D: | 49.13 Gb Total Space | 5.96 Gb Free Space | 12.13% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 1.31 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 74.55 Gb Total Space | 33.67 Gb Free Space | 45.17% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TEST-3A14A8A427
Current User Name: petra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_USERS\S-1-5-21-1957994488-2111687655-1343024091-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\IncrediMail\bin\ImpCnt.exe" = C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail -- (IncrediMail, Ltd.)
"C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{03F1CC67-5BD8-4C36-8394-76311B2AE69A}" = ArcSoft PhotoStudio 5
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{45235788-142C-44BE-8A4D-DDE9A84492E5}" = AGEIA PhysX v7.09.13
"{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 pro Windows
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5E65E94D-69F2-4850-9E93-6459C53A0F50}" = Microsoft .NET Framework 1.1 Czech Language Pack
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{6249C22D-E6A8-407B-BA8B-40298848ED94}" = OmniPage SE
"{6628DF4A-A8F5-4DA8-909D-C13A070E3D53}" = Jazyková sada (cs-CZ) pro Learning Essentials
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A120BD4-6AB8-4BF9-82A8-FC7B0FD61029}" = Nero 7 Ultra Edition
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79546A5F-AE7C-4693-8670-A3401B43ABD2}" = HP Deskjet 5900 series
"{7B1AF68B-4606-4152-9991-1E9D4FF5F0FA}" = Microsoft Antimalware Service CS-CZ Language Pack
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{8234A27D-C5A4-4F84-8718-3BF34BCFC89F}" = JourneySoftwarePromo
"{868D7896-99D4-4513-BC62-2B3AD3E24926}" = TuneUp Utilities 2006
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90110405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0405-0000-0000000FF1CE}" = Sada Compatibility Pack pro systém Office 2007
"{90280405-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional s aplikací FrontPage
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9763E36A-08E9-4228-BBCE-12989A4EB1A8}" = QuickTime
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5222E5A-13CB-4C98-9F5C-21CF6896A25C}" = HPDeskjet5900Series
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A62392EE-03CB-4FA8-8E79-B5F95A346FB3}" = Kontrola české gramatiky pro sadu Microsoft Office 2003
"{A908E57D-71A3-4AE1-9A76-C239521BBED9}" = Microsoft Kalkulačka+
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D14C0D-FDAA-4DF2-8441-A902805CCE8C}" = ArcSoft PhotoBase 3
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0F136FF-8BD5-4650-9E79-17162D30C12D}" = Windows XP Creativity Fun Packs - Digital Photography
"{DBC3FDEC-D5F4-439C-9A18-EF454A74E3DE}_is1" = NOD32 FiX v2.1
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E72019B8-1287-4093-BE9B-1CFA7BA1A8D2}" = Windows Desktop Search 3.01
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F3BD8E81-C020-44F9-B014-1E0214D23556}" = SA30xx Media Converter
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}" = Microsoft SQL Server Native Client
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FE64AE29-0883-4C70-8388-DC026019C900}" = HP Image Zone Express
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"All ATI Software" = Softarová utilita ATI - Odinstalovat
"ATI Display Driver" = ATI Display Driver
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.8 (Unicode)
"AXIS Media Control" = AXIS Media Control
"AXIS Media Control Embedded" = AXIS Media Control Embedded
"CloneCD" = CloneCD
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"G-Force" = G-Force
"HP Imaging Device Functions" = HP Imaging Device Functions 5.0
"HP Photo & Imaging" = HP Image Zone 5.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Kancelář pro obec 4.1_is1" = KPO 4.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.5.11)" = Mozilla Firefox (3.5.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoFiltre Studio" = PhotoFiltre Studio
"Picasa 3" = Picasa 3
"PSPad editor_is1" = PSPad editor
"Shockwave" = Shockwave
"Totalcmd" = Total Commander (Remove or Repair)
"Vizros Plug-ins 4.1" = Vizros Plug-ins 4.1
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01005" = Microsoft User-Mode Driver Framework Feature Pack 1.5
"Xenofex2" = Alien Skin Xenofex 2.0
"YouTubeVideo Toolbar" = YouTubeVideo Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8.9.2010 10:35:33 | Computer Name = TEST-3A14A8A427 | Source = ESENT | ID = 485
Description = wuauclt (3268) Pokus o odstranění složky C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edbtmp.log
se nezdařil. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru,
neboť jej právě využívá jiný proces. . Operace odstranění složky se nezdaří a dojde
k chybě -1032 (0xfffffbf8).

Error - 8.9.2010 10:35:43 | Computer Name = TEST-3A14A8A427 | Source = ESENT | ID = 489
Description = wuauclt (3268) Pokus o otevření souboru C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb
jen pro čtení se nezdařil. Došlo k systémové chybě 32 (0x00000020): Proces nemá
přístup k souboru, neboť jej právě využívá jiný proces. . Operace otevření souboru
se nezdaří a dojde k chybě -1032 (0xfffffbf8).

Error - 8.9.2010 10:35:43 | Computer Name = TEST-3A14A8A427 | Source = ESENT | ID = 485
Description = wuauclt (720) Pokus o odstranění složky C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb00725.log
se nezdařil. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru,
neboť jej právě využívá jiný proces. . Operace odstranění složky se nezdaří a dojde
k chybě -1032 (0xfffffbf8).

Error - 8.9.2010 10:35:47 | Computer Name = TEST-3A14A8A427 | Source = ESENT | ID = 485
Description = wuauclt (3268) Pokus o odstranění složky C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edbtmp.log
se nezdařil. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru,
neboť jej právě využívá jiný proces. . Operace odstranění složky se nezdaří a dojde
k chybě -1032 (0xfffffbf8).

Error - 8.9.2010 10:35:47 | Computer Name = TEST-3A14A8A427 | Source = ESENT | ID = 413
Description = wuauclt (3268) Nový soubor protokolu nelze vytvořit, protože není
možné zapisovat na jednotku protokolu. Jednotka může být označena jen pro čtení,
na disku je nedostatek místa nebo je jednotka chybně nakonfigurována či poškozena.
Chyba -1032

Error - 8.9.2010 10:35:47 | Computer Name = TEST-3A14A8A427 | Source = ESENT | ID = 454
Description = wuauclt (3268) Při zotavení či obnovení databáze došlo k neočekávané
chybě -1032.

Error - 8.9.2010 10:35:47 | Computer Name = TEST-3A14A8A427 | Source = ESENT | ID = 485
Description = wuauclt (3268) Pokus o odstranění složky C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edbtmp.log
se nezdařil. Došlo k systémové chybě 32 (0x00000020): Proces nemá přístup k souboru,
neboť jej právě využívá jiný proces. . Operace odstranění složky se nezdaří a dojde
k chybě -1032 (0xfffffbf8).

Error - 8.9.2010 10:35:48 | Computer Name = TEST-3A14A8A427 | Source = ESENT | ID = 486
Description = wuauclt (720) Pokus o přesunutí souboru C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edbtmp.log
do složky C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log se nezdařil. Došlo
k systémové chybě 183 (0x000000b7): Nelze vytvořit soubor, který již existuje.
. Operace přesunutí souboru se nezdaří a dojde k chybě -1022 (0xfffffc02).

Error - 8.9.2010 10:35:48 | Computer Name = TEST-3A14A8A427 | Source = ESENT | ID = 413
Description = wuauclt (720) Nový soubor protokolu nelze vytvořit, protože není možné
zapisovat na jednotku protokolu. Jednotka může být označena jen pro čtení, na disku
je nedostatek místa nebo je jednotka chybně nakonfigurována či poškozena. Chyba
-1022

Error - 8.9.2010 10:35:48 | Computer Name = TEST-3A14A8A427 | Source = ESENT | ID = 492
Description = wuauclt (720) Posloupnost souborů protokolu v C:\WINDOWS\SoftwareDistribution\DataStore\Logs\
byla zastavena. Došlo k závažné chybě. Databáze, které používají tuto posloupnost
souborů protokolu, již nelze aktualizovat. Odstraňte potíže a restartujte nebo
obnovte databázi ze záložní kopie.

[ System Events ]
Error - 30.8.2010 16:39:54 | Computer Name = TEST-3A14A8A427 | Source = Cdrom | ID = 262151
Description = Zařízení \Device\CdRom1 má chybný blok.

Error - 30.8.2010 16:39:55 | Computer Name = TEST-3A14A8A427 | Source = Cdrom | ID = 262151
Description = Zařízení \Device\CdRom1 má chybný blok.

Error - 30.8.2010 16:39:55 | Computer Name = TEST-3A14A8A427 | Source = Cdrom | ID = 262151
Description = Zařízení \Device\CdRom1 má chybný blok.

Error - 4.9.2010 3:01:38 | Computer Name = TEST-3A14A8A427 | Source = Service Control Manager | ID = 7000
Description = Služba adfs neuspěla při spuštění v důsledku následující chyby: %%2

Error - 4.9.2010 15:13:21 | Computer Name = TEST-3A14A8A427 | Source = Service Control Manager | ID = 7000
Description = Služba adfs neuspěla při spuštění v důsledku následující chyby: %%2

Error - 4.9.2010 16:38:19 | Computer Name = TEST-3A14A8A427 | Source = Windows Update Agent | ID = 20
Description = Instalace se nezdařila: Instalace následující aktualizace se nezdařila
z důvodu chyby (0x80070643): Aktualizace Microsoft Office 2003 Service Pack 3 (SP3).

Error - 5.9.2010 4:07:18 | Computer Name = TEST-3A14A8A427 | Source = Service Control Manager | ID = 7000
Description = Služba adfs neuspěla při spuštění v důsledku následující chyby: %%2

Error - 5.9.2010 9:11:33 | Computer Name = TEST-3A14A8A427 | Source = Windows Update Agent | ID = 20
Description = Instalace se nezdařila: Instalace následující aktualizace se nezdařila
z důvodu chyby (0x80070643): Aktualizace Microsoft Office 2003 Service Pack 3 (SP3).

Error - 6.9.2010 8:55:52 | Computer Name = TEST-3A14A8A427 | Source = Windows Update Agent | ID = 20
Description = Instalace se nezdařila: Instalace následující aktualizace se nezdařila
z důvodu chyby (0x80070643): Aktualizace Microsoft Office 2003 Service Pack 3 (SP3).

Error - 8.9.2010 10:08:49 | Computer Name = TEST-3A14A8A427 | Source = Service Control Manager | ID = 7000
Description = Služba adfs neuspěla při spuštění v důsledku následující chyby: %%2

[ TuneUp Events ]
Error - 13.2.2009 10:14:38 | Computer Name = TEST-3A14A8A427 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "s": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2009-02-13 15:14:38', '\device\harddiskvolume3\hry\wendy's
wellness\xvwmprd.exe','1696',0)

Error - 13.2.2009 10:14:38 | Computer Name = TEST-3A14A8A427 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "s": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2009-02-13 15:14:38', '\device\harddiskvolume3\hry\wendy's
wellness\xvwmprd.exe','184',0)

Error - 13.2.2009 10:14:59 | Computer Name = TEST-3A14A8A427 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "s": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2009-02-13 15:14:59', '\device\harddiskvolume3\hry\wendy's
wellness\wellness.exe','3748',0)

Error - 13.2.2009 10:14:59 | Computer Name = TEST-3A14A8A427 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "s": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2009-02-13 15:14:59', '\device\harddiskvolume3\hry\wendy's
wellness\wellness.exe','228',0)

Error - 13.2.2009 11:33:36 | Computer Name = TEST-3A14A8A427 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "s": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2009-02-13 16:33:36', '\device\harddiskvolume3\hry\wendy's
wellness\uninstall.exe','128',0)

Error - 24.3.2009 15:22:15 | Computer Name = TEST-3A14A8A427 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE StartMenuEntries
SET Outdated='1'

Error - 24.3.2009 15:22:15 | Computer Name = TEST-3A14A8A427 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE SecurityProducts
SET Outdated='1'

Error - 24.3.2009 15:22:15 | Computer Name = TEST-3A14A8A427 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: INSERT INTO
Applications (Exe, Started, Ended, State, Resumed) SELECT Exe, Started, Ended,
State, Resumed FROM MemApplications;DELETE FROM MemApplications;INSERT INTO Applications
(Exe, Started, Ended, State, Resumed) SELECT Exe, Started, '2009-03-24 20:22:15',
1, Resumed FROM ActiveApps;DELETE FROM ActiveApps

Error - 12.4.2009 14:01:42 | Computer Name = TEST-3A14A8A427 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE StartMenuEntries
SET Outdated='1'

Error - 12.4.2009 14:01:42 | Computer Name = TEST-3A14A8A427 | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: database or disk is full; when executing SQL: UPDATE SecurityProducts
SET Outdated='1'


< End of report >

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu (combofix) - opravení spouštění pevných di

#20 Příspěvek od Caroprd111 »

Obrázek Spusťte OTL a do spodního okna vložte následující skript.

Kód: Vybrat vše

:Commands
[EMPTYTEMP] 
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]

:OTL
DRV - File not found [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - File not found [Kernel | On_Demand | Running] -- C:\DOCUME~1\petra\LOCALS~1\Temp\catchme.sys -- (catchme)
O2 - BHO: (no name) - {055FD26D-3A88-4e15-963D-DC8493744B1D} - No CLSID value found.
O9 - Extra Button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - C:\Program Files\FlashCapture\fciext.dll File not found
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {32564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv8dmo.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-95C8-443543540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Reg Error: Key error.)
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:417B6FAC
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:C22674B6
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:ADE16379
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:3815BC84
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:8DF68137
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:22741C1F
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:072F1F69
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:F01E7F17
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:9857FAE3
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:52641FBE
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:90865A6D
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:561B1D2B
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:7C411C08
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:52E1DB1D
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:E65E15CD
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:888AFB86
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:5C6EBC69
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:27D1368B
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D2F60835
Klikněte na Opravit, PC se restartuje, log vložte sem.
Obrázek

krataska
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 01 zář 2010 10:53

Re: kontrola logu (combofix) - opravení spouštění pevných di

#21 Příspěvek od krataska »

Je normální, že se mi smazaly všechny dokumenty a v podstatě skoro vše, co bylo na disku C: ?

Po restaru mi vyskočilo pouze toto:


Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu (combofix) - opravení spouštění pevných di

#22 Příspěvek od Caroprd111 »

Složku C:\OTL zazipujte a někam uložte. Odkaz na soubor mi pošlete.
Obrázek

krataska
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 01 zář 2010 10:53

Re: kontrola logu (combofix) - opravení spouštění pevných di

#23 Příspěvek od krataska »

V příloze je ta složka
Přílohy
_OTL.rar
(360 bajtů) Staženo 32 x

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu (combofix) - opravení spouštění pevných di

#24 Příspěvek od Caroprd111 »

Jaké konkrétní soubory zmizely?
Obrázek

krataska
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 01 zář 2010 10:53

Re: kontrola logu (combofix) - opravení spouštění pevných di

#25 Příspěvek od krataska »

Komplet všechny, které jsem měla v dokumentech. Jako fotky, mnou uložené dokumenty atd. Dále nějaké programy. Jako na úpravu fotek. Všichni zástupci, které jsem měla na ploše. V podstatě téměř vše, co bylo uloženo na C: v Obrázkách, Hudbě, Dokumentech a na Ploše.

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu (combofix) - opravení spouštění pevných di

#26 Příspěvek od Caroprd111 »

Zkuste obnovení systému.
Obrázek

krataska
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 01 zář 2010 10:53

Re: kontrola logu (combofix) - opravení spouštění pevných di

#27 Příspěvek od krataska »

Vše je opět v pořádku. :)

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu (combofix) - opravení spouštění pevných di

#28 Příspěvek od Caroprd111 »

Jak se chová PC :???:
Obrázek

krataska
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 01 zář 2010 10:53

Re: kontrola logu (combofix) - opravení spouštění pevných di

#29 Příspěvek od krataska »

Mám zjišťovat něco specifického? Přijde mi, že se chová stále stejně. Asi tak, že procesor stále něco zpracovává. Pokud je to tedy procesor. Mám starší počítač a nějak tak stále "vrčí". To je asi jediné, čeho jsem si všimla.

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: kontrola logu (combofix) - opravení spouštění pevných di

#30 Příspěvek od Caroprd111 »

Spíš jde o objektivní posouzení chování PC.


ObrázekOdinstalujte ComboFix přes:
Start >> Spustit, zkopírujte do okénka:

ComboFix /Uninstall

stiskněte Enter



Obrázek Stáhněte T-Cleaner http://sweb.cz/Marinus/T-Cleaner.exe
  • Spusťte, pro potvrzení volby mačkejte klávesu A, Enter
  • Po použití program vymažte. Pozor, antiviry ho mohou falešně označit za vir.

Obrázek Stáhněte TFC http://oldtimer.geekstogo.com/TFC.exe
  • Spusťte.
  • Klikněte na "Start". Potvrďte hlášku kliknutím na "Ok" (Bude následovat restart)

Obrázek Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
  • Spusťte.
  • Klikněte na "CleanUp!". Potvrďte hlášky kliknutím na "Yes" (Bude následovat restart)


Obrázek Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
  • Nainstalujte a v průběhu instalace odškrtněte, že chcete instalovat yahoo toolbar.

    Obrázek Záložka Čistič
  • Dejte analyzovat, po dokončení dejte Spustit Ccleaner.

    Obrázek Záložka Registry
  • Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
    Obrázek OK Obrázek Zavřít

Podle pravidel fóra se zde nelegálním softwarem nezabýváme (nelegální programy představují bezpečnostní hrozbu).
Obstarejte si legální zabezpečení PC (antivir, firewall), poté sem vložte nový log z RSIT a log z CKScanner.

Vyberte si třeba free Aviru nebo Avast + nějaký firewall (doporučuji ZoneAlarm) http://www.viry.cz/forum/viewtopic.php?f=29&t=6152 + http://www.viry.cz/forum/viewtopic.php?f=41&t=6523

Obrázek Stáhněte na plochu CKScanner http://downloads.malwareremoval.com/CKScanner.exe
  • Spusťte a klikněte na "Search For Files", po dokončení skenu klikněte na "Save List to File" -> "OK"
  • Log s názvem ckfiles.txt bude uložený na ploše, obsah tohoto souboru sem vložte.
Obrázek

Odpovědět