Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

samovolne spuštění Windows Live Messenger

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
L.M.
1. Stupeň Varování
Příspěvky: 140
Registrován: 22 čer 2010 15:15

Re: samovolne spuštění Windows Live Messenger

#16 Příspěvek od L.M. »

Zdravím ja se omlouvam že tu skaču pokud chcete Windows MSN dat pryč tak stači
když kliknete na start spusti zadat tento příkaz -
RunDll32 advpack.dll,LaunchINFSection %windir%\INF\msmsgs.inf,BLC.Remove
ENTER restart :turned:

Tadeas.skuhra
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 25 čer 2008 15:10

Re: samovolne spuštění Windows Live Messenger

#17 Příspěvek od Tadeas.skuhra »

je-li tomu tak, tak dík

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: samovolne spuštění Windows Live Messenger

#18 Příspěvek od motji »

Omlouvám se za vstup
Pomohlo to?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Tadeas.skuhra
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 25 čer 2008 15:10

Re: samovolne spuštění Windows Live Messenger

#19 Příspěvek od Tadeas.skuhra »

nepomohlo, hodilo to chybu, "Chyba: nelze najít soubor INF C:\Windows\INF\msmsgs.inf."
tož co s tím?=)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: samovolne spuštění Windows Live Messenger

#20 Příspěvek od motji »

Poprosím Vás o nový log z OTL :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Tadeas.skuhra
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 25 čer 2008 15:10

Re: samovolne spuštění Windows Live Messenger

#21 Příspěvek od Tadeas.skuhra »

tady je =)


OTL logfile created on: 28/10/2010 10:07:38 - Run 2
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Users\Tadeáš\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 50.00% Memory free
8.00 Gb Paging File | 5.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.01 Gb Total Space | 279.30 Gb Free Space | 61.79% Space Free | Partition Type: NTFS

Computer Name: TADEAS-VAIO | User Name: Tadeáš | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/10/21 19:59:50 | 000,085,184 | ---- | M] (Macrovision ) -- C:\Program Files (x86)\Common Files\InstallShield Shared\Service\InstallShield Licensing Service.exe
PRC - [2010/08/12 15:15:34 | 000,081,296 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Care\VCSpt.exe
PRC - [2010/05/28 11:14:24 | 000,205,168 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe
PRC - [2010/04/01 11:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2010/02/19 19:19:24 | 000,529,776 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
PRC - [2010.10.22 22:11:45 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Tadeáš\Desktop\OTL.exe
PRC - [2010.10.12 08:37:00 | 000,974,904 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2010.10.03 19:57:13 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
PRC - [2010.08.22 13:02:26 | 000,133,432 | ---- | M] (ICQ, LLC.) -- C:\Program Files (x86)\ICQ7.2\ICQ.exe
PRC - [2010.06.10 06:58:32 | 001,218,008 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
PRC - [2010.06.10 06:58:32 | 000,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe
PRC - [2010.05.18 13:38:46 | 000,075,776 | ---- | M] (Sony of America Corporation) -- C:\Program Files\Sony\VAIO Care\listener.exe
PRC - [2010.03.25 14:39:22 | 000,490,280 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010.02.17 15:53:26 | 000,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/11/30 21:20:00 | 000,112,488 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe
PRC - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MPF\MpfSrv.exe
PRC - [2009/10/24 05:18:54 | 000,360,224 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\PMB\PMBDeviceInfoProvider.exe
PRC - [2009/10/13 21:25:54 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/10/02 13:02:56 | 000,026,640 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MSK\msksrver.exe
PRC - [2009/09/14 21:24:08 | 000,206,336 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
PRC - [2009/09/14 20:53:48 | 000,642,416 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
PRC - [2009/08/26 21:24:00 | 000,320,880 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009.12.16 07:31:35 | 000,026,624 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe
PRC - [2009.10.24 05:18:52 | 000,597,792 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\PMB\PMBVolumeWatcher.exe
PRC - [2009.10.13 21:25:30 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009.07.07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2008/09/18 12:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
PRC - [2008/06/05 10:19:18 | 000,479,232 | ---- | M] (Nikon Corporation) -- C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe
PRC - [2007/07/24 13:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2007/01/04 21:48:50 | 000,112,152 | ---- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe


========== Modules (SafeList) ==========

MOD - [2010.10.22 22:11:45 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Tadeáš\Desktop\OTL.exe
MOD - [2010.08.21 07:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2009.10.20 15:36:40 | 000,633,192 | ---- | M] (Stardock Corporation) -- C:\Program Files (x86)\Stardock\MyColors\wblind.dll
MOD - [2009.06.09 09:56:14 | 000,034,168 | ---- | M] (Stardock.Net, Inc) -- C:\Program Files (x86)\Stardock\MyColors\wbhelp.dll
MOD - [2009.06.09 09:55:58 | 000,057,904 | ---- | M] () -- C:\Windows\SysWOW64\wbload.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010.09.22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010.09.20 10:47:58 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2010.08.12 15:15:34 | 000,257,936 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe -- (SampleCollector)
SRV:64bit: - [2010.04.09 13:37:36 | 001,223,024 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent)
SRV:64bit: - [2010.02.24 13:16:08 | 000,696,848 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV:64bit: - [2010.02.19 19:19:28 | 000,115,568 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe -- (VcmXmlIfHelper)
SRV:64bit: - [2010.02.19 19:19:24 | 000,529,776 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV:64bit: - [2010.02.17 16:45:16 | 000,155,456 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV:64bit: - [2009.11.30 21:51:18 | 000,571,248 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV:64bit: - [2009.11.25 21:06:06 | 000,821,760 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Smart Network\VSNService.exe -- (VSNService)
SRV:64bit: - [2009.10.14 14:31:44 | 000,116,224 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService)
SRV:64bit: - [2009.09.21 18:24:40 | 001,420,560 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2009.09.21 18:00:44 | 000,831,760 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2009.09.04 23:35:12 | 000,873,248 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2009.09.01 23:42:00 | 000,361,840 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe -- (VcmINSMgr)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2010.10.21 19:59:50 | 000,085,184 | ---- | M] (Macrovision ) [Auto | Running] -- C:\Program Files (x86)\Common Files\InstallShield Shared\Service\InstallShield Licensing Service.exe -- (InstallShield Licensing Service)
SRV - [2010.09.20 10:47:56 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.06.10 06:58:32 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2010.05.28 11:14:24 | 000,205,168 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2010.03.25 14:39:22 | 000,490,280 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010.02.17 15:53:26 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2009.10.27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2009.10.24 05:18:54 | 000,360,224 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2009.10.15 18:34:36 | 000,427,304 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2009.10.15 18:34:36 | 000,091,432 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe -- (SOHPlMgr)
SRV - [2009.10.15 18:34:36 | 000,075,048 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2009.10.15 18:34:34 | 000,120,104 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2009.10.15 18:34:34 | 000,070,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe -- (SOHDBSvr)
SRV - [2009.10.13 21:25:30 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2009.10.02 13:02:56 | 000,026,640 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MSK\MskSrver.exe -- (MSK80Service)
SRV - [2009.09.14 21:24:08 | 000,206,336 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe -- (VzCdbSvc)
SRV - [2009.09.14 21:24:08 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe -- (VAIO Entertainment TV Device Arbitration Service)
SRV - [2009.09.14 20:53:48 | 000,642,416 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2009.08.31 03:59:30 | 000,362,992 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe -- (Roxio Upnp Server 10)
SRV - [2009.08.31 03:59:18 | 000,313,840 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe -- (Roxio UPnP Renderer 10)
SRV - [2009.07.08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2009.07.07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
SRV - [2009.06.16 09:58:08 | 000,020,480 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe -- (WDSmartWareBackgroundService)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.06.09 09:56:16 | 000,337,200 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files (x86)\Stardock\MyColors\VistaSrv.exe -- (WindowBlinds)
SRV - [2008.09.18 12:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe -- (uCamMonitor)
SRV - [2007.07.24 13:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2007.01.04 21:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010.09.23 00:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010.07.30 13:36:01 | 000,021,200 | ---- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TVicHW64.sys -- (TVICHW64)
DRV:64bit: - [2010.07.15 15:18:22 | 000,176,144 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\Mpfp.sys -- (MPFP)
DRV:64bit: - [2010.06.30 08:07:55 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010.02.17 16:52:42 | 000,308,296 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2010.02.17 16:52:42 | 000,102,472 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2010.02.17 16:52:42 | 000,049,480 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfesmfk.sys -- (mfesmfk)
DRV:64bit: - [2010.02.17 16:45:32 | 000,040,904 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdk.sys -- (mferkdk)
DRV:64bit: - [2009.11.18 22:03:16 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2009.11.18 22:03:15 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2009.11.18 22:03:15 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2009.11.18 22:03:13 | 000,052,264 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btusbflt.sys -- (btusbflt)
DRV:64bit: - [2009.11.18 22:02:45 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2009.11.06 22:34:48 | 000,084,512 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2009.11.06 22:27:30 | 000,093,696 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimssne64.sys -- (rimspci)
DRV:64bit: - [2009.11.05 08:30:19 | 001,542,656 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009.11.04 11:59:59 | 000,253,488 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2009.10.27 22:06:59 | 000,151,040 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009.10.13 21:16:40 | 000,409,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.10.10 04:41:20 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009.09.15 22:09:08 | 000,075,776 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\risdsne64.sys -- (risdsnpe)
DRV:64bit: - [2009.09.15 14:40:42 | 006,952,960 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64) Intel(R)
DRV:64bit: - [2009.08.19 22:09:21 | 000,011,392 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SFEP.sys -- (SFEP)
DRV:64bit: - [2009.07.31 22:02:03 | 000,393,216 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009.07.14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.26 16:32:04 | 000,019,968 | ---- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys -- (ArcSoftKsUFilter)
DRV:64bit: - [2009.05.20 12:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009.02.13 12:02:52 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2007.04.17 13:51:50 | 000,014,112 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\regi.sys -- (regi)
DRV - [2008.08.14 07:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)
DRV - [2007.04.17 22:09:28 | 000,011,032 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\drivers\regi.sys -- (regi)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.10.03 19:58:24 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2010.09.19 16:12:18 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho64.dll ()
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [MarketingTools] C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe (Sony Corporation)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files (x86)\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NVIDIA driver monitor] C:\Users\Public\nvsvc32.exe ()
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\SONY\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [NVIDIA driver monitor] C:\Users\Public\nvsvc32.exe ()
O4 - Startup: C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.lnk = C:\Users\Tadeáš\AppData\Local\Temp\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.bat File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8:64bit: - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1a05dae5-840e-11df-815b-5442490b19bc}\Shell - "" = AutoRun
O33 - MountPoints2\{1a05dae5-840e-11df-815b-5442490b19bc}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{a8d440d4-7a10-11df-b81d-506313f28287}\Shell - "" = AutoRun
O33 - MountPoints2\{a8d440d4-7a10-11df-b81d-506313f28287}\Shell\AutoRun\command - "" = H:\WD SmartWare.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010.10.28 01:43:06 | 000,000,000 | ---D | C] -- C:\Windows\cs
[2010.10.28 01:40:10 | 000,048,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fssfltr.sys
[2010.10.28 01:39:26 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2010.10.28 01:38:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSN Toolbar
[2010.10.28 01:38:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bing Bar Installer
[2010.10.28 01:37:03 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Local\Windows Live
[2010.10.28 01:36:34 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2010.10.28 01:36:34 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll
[2010.10.28 01:36:34 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2010.10.28 01:36:34 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll
[2010.10.28 01:36:33 | 004,068,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2010.10.28 01:36:33 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2010.10.28 01:36:32 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2010.10.27 10:14:12 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll
[2010.10.27 10:14:11 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll
[2010.10.27 10:14:11 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll
[2010.10.27 10:14:10 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax
[2010.10.27 10:14:10 | 000,258,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax
[2010.10.27 10:14:10 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax
[2010.10.27 10:14:10 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax
[2010.10.27 10:13:54 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys
[2010.10.25 18:43:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ocad9
[2010.10.24 12:55:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2010.10.24 12:54:01 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\Virus Removal Tool
[2010.10.24 00:18:11 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2010.10.22 22:55:12 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\Malwarebytes
[2010.10.22 22:54:53 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010.10.22 22:54:52 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010.10.22 22:54:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010.10.22 22:54:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.10.22 22:11:32 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Tadeáš\Desktop\OTL.exe
[2010.10.22 09:19:11 | 000,000,000 | ---D | C] -- C:\rsit
[2010.10.21 23:45:15 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Documents\My Received Files
[2010.10.21 22:26:42 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Tracing
[2010.10.21 22:09:10 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\Nová složka (4)
[2010.10.21 21:59:49 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\Geografie obyvatelstva a sídel
[2010.10.21 20:00:14 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallShield
[2010.10.21 19:59:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield Shared
[2010.10.21 19:54:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OCAD
[2010.10.20 11:23:44 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\UJEP
[2010.10.19 17:24:55 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\Nová složka
[2010.10.17 23:04:51 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\U Gule - 15.10.2010
[2010.10.17 22:53:14 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\FEC
[2010.10.14 21:58:19 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll
[2010.10.14 21:58:19 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2010.10.14 21:58:18 | 002,085,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ole32.dll
[2010.10.14 21:58:16 | 000,483,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\StructuredQuery.dll
[2010.10.14 21:58:13 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comctl32.dll
[2010.10.14 21:58:11 | 001,024,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpmde.dll
[2010.10.14 21:58:10 | 000,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpmde.dll
[2010.10.14 21:58:09 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40.dll
[2010.10.14 21:58:09 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40u.dll
[2010.10.14 21:57:58 | 000,702,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2010.10.14 21:57:58 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2010.10.14 21:57:57 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2010.10.14 21:57:57 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2010.10.14 21:57:57 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2010.10.14 21:57:56 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2010.10.14 21:57:56 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2010.10.14 21:57:56 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2010.10.14 21:57:56 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2010.10.14 21:57:56 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2010.10.14 21:57:55 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2010.10.14 21:57:55 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2010.10.14 21:57:55 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2010.10.14 21:57:55 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2010.10.14 21:57:43 | 014,627,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2010.10.14 21:57:42 | 011,406,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2010.10.14 21:57:41 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2010.10.14 21:57:40 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2010.10.14 21:57:38 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sscore.dll
[2010.10.12 13:48:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bullfrog
[2010.10.08 00:41:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2010.10.08 00:41:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2010.10.08 00:40:39 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010.10.08 00:37:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2010.10.08 00:37:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2010.10.08 00:35:23 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010.10.08 00:32:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Toolbar
[2010.10.08 00:31:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite
[2010.10.07 20:26:48 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\focení
[2010.10.07 15:20:01 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Local\Microsoft Help
[2010.10.06 14:40:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinKart
[2010.10.04 01:06:28 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Local\Evernote
[2010.10.03 19:58:15 | 000,185,920 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2010.10.03 19:58:06 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2010.10.03 19:58:06 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2010.10.03 19:57:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2010.10.03 19:57:17 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2010.10.03 19:57:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Real
[2010.10.03 19:57:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2010.10.03 19:57:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Real
[2010.10.03 19:57:09 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\Real
[2010.09.29 20:50:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ubisoft
[2010.09.28 20:22:12 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\MyPhoneExplorer
[2010.09.28 20:22:02 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\QuickStoresToolbar
[2010.09.28 20:21:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MyPhoneExplorer
[2010.09.28 18:53:30 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\UJEP
[2010.09.28 15:34:54 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\dvdcss
[2010.09.28 15:12:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BitTorrent
[2010.09.28 15:12:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
[2010.09.28 15:12:03 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\BitTorrent

========== Files - Modified Within 30 Days ==========

[2010.10.28 10:07:00 | 000,000,966 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010.10.28 10:05:11 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.10.28 10:05:11 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.10.28 09:58:42 | 000,034,267 | ---- | M] () -- C:\Windows\SysNative\Config.MPF
[2010.10.28 09:57:25 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010.10.28 09:57:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.10.28 09:56:56 | 3156,807,680 | -HS- | M] () -- C:\hiberfil.sys
[2010.10.27 09:12:38 | 001,470,062 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010.10.27 09:12:38 | 000,631,292 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2010.10.27 09:12:38 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010.10.27 09:12:38 | 000,121,914 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2010.10.27 09:12:38 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010.10.25 18:43:35 | 000,000,878 | ---- | M] () -- C:\Users\Tadeáš\Desktop\OCAD 9.lnk
[2010.10.24 17:08:23 | 000,001,248 | ---- | M] () -- C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.lnk
[2010.10.24 15:27:14 | 000,000,092 | -HS- | M] () -- C:\Windows\setup_9.0.0.722_24.10.2010_13-20drv.spi
[2010.10.22 22:54:57 | 000,001,013 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.10.22 22:11:45 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Tadeáš\Desktop\OTL.exe
[2010.10.22 14:12:58 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLdu.DAT
[2010.10.21 23:52:59 | 000,247,504 | ---- | M] () -- C:\Users\Public\Documents\cc_20101021_235113.reg
[2010.10.21 20:10:56 | 034,799,416 | ---- | M] () -- C:\Users\Tadeáš\Desktop\zobr_1 kopie.bmp
[2010.10.21 19:59:53 | 000,001,878 | ---- | M] () -- C:\Users\Public\Desktop\Launch OCAD 10 Trial.lnk
[2010.10.20 15:45:41 | 032,651,763 | ---- | M] () -- C:\Users\Tadeáš\Documents\Bez názvu (2).wma
[2010.10.20 12:20:13 | 000,078,320 | ---- | M] () -- C:\Users\Public\Documents\Petr Löbel, Tadeáš Skuhra, výroky z VŠ.docx
[2010.10.19 22:58:27 | 001,716,736 | ---- | M] () -- C:\Users\Tadeáš\Desktop\aktualita - Chile, zasypaní horníci.ppt
[2010.10.18 16:17:59 | 000,220,361 | ---- | M] () -- C:\Users\Tadeáš\Desktop\133143138.jpg
[2010.10.18 16:11:41 | 001,791,583 | ---- | M] () -- C:\Users\Tadeáš\Desktop\nike.jpg
[2010.10.15 17:44:33 | 001,930,532 | ---- | M] () -- C:\Users\Tadeáš\Desktop\2009-06-29 5351-plocha.jpg
[2010.10.15 17:31:31 | 005,492,980 | ---- | M] () -- C:\Users\Tadeáš\Desktop\10-13-2010_16981.jpg
[2010.10.15 15:10:01 | 001,901,477 | ---- | M] () -- C:\Users\Tadeáš\Desktop\2009-06-29 5351.jpg
[2010.10.15 11:17:19 | 003,059,928 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010.10.14 22:12:50 | 006,795,088 | ---- | M] () -- C:\Users\Tadeáš\Desktop\10-13-2010_1698.jpg
[2010.10.13 22:33:22 | 000,064,671 | ---- | M] () -- C:\Users\Tadeáš\Desktop\petr a ja.jpg
[2010.10.13 16:39:57 | 007,021,382 | ---- | M] () -- C:\Users\Tadeáš\Desktop\10-07-2010_1585.jpg
[2010.10.13 09:39:08 | 000,001,174 | ---- | M] () -- C:\Users\Public\Desktop\Dungeon Keeper 2.lnk
[2010.10.12 11:19:52 | 008,331,274 | ---- | M] () -- C:\Users\Tadeáš\Desktop\Božanov 3.mp4
[2010.10.09 22:00:25 | 000,059,372 | ---- | M] () -- C:\Users\Tadeáš\Desktop\DSC_1139h.jpg
[2010.10.08 21:26:48 | 042,103,213 | ---- | M] () -- C:\Users\Tadeáš\Documents\Bez názvu.wma
[2010.10.08 10:31:00 | 000,521,192 | ---- | M] () -- C:\Users\Tadeáš\Desktop\10-07-2010_1622.jpg
[2010.10.07 18:11:01 | 000,356,669 | ---- | M] () -- C:\Users\Tadeáš\Desktop\DSC_1139.jpg
[2010.10.06 14:40:44 | 000,000,940 | ---- | M] () -- C:\Users\Tadeáš\Desktop\WinKart.lnk
[2010.10.04 13:42:11 | 000,002,212 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010.10.03 19:58:24 | 000,001,268 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer SP.lnk
[2010.10.03 19:58:15 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2010.10.03 19:58:06 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2010.10.03 19:58:06 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2010.10.03 19:57:17 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp71.dll
[2010.10.03 19:57:17 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2010.09.28 20:22:02 | 000,000,187 | ---- | M] () -- C:\Users\Tadeáš\Desktop\QuickStores.url
[2010.09.28 20:22:01 | 000,002,061 | ---- | M] () -- C:\Users\Public\Desktop\MyPhoneExplorer.lnk
[2010.09.28 15:12:58 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\BitTorrent.lnk

========== Files Created - No Company Name ==========

[2010.10.25 18:43:35 | 000,000,878 | ---- | C] () -- C:\Users\Tadeáš\Desktop\OCAD 9.lnk
[2010.10.24 17:08:23 | 000,001,248 | ---- | C] () -- C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.lnk
[2010.10.24 15:27:14 | 000,000,092 | -HS- | C] () -- C:\Windows\setup_9.0.0.722_24.10.2010_13-20drv.spi
[2010.10.22 22:54:57 | 000,001,013 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.10.21 23:51:16 | 000,247,504 | ---- | C] () -- C:\Users\Public\Documents\cc_20101021_235113.reg
[2010.10.21 20:16:39 | 034,799,416 | ---- | C] () -- C:\Users\Tadeáš\Desktop\zobr_1 kopie.bmp
[2010.10.21 19:59:53 | 000,001,878 | ---- | C] () -- C:\Users\Public\Desktop\Launch OCAD 10 Trial.lnk
[2010.10.20 15:45:41 | 032,651,763 | ---- | C] () -- C:\Users\Tadeáš\Documents\Bez názvu (2).wma
[2010.10.18 16:17:59 | 000,220,361 | ---- | C] () -- C:\Users\Tadeáš\Desktop\133143138.jpg
[2010.10.18 16:11:40 | 001,791,583 | ---- | C] () -- C:\Users\Tadeáš\Desktop\nike.jpg
[2010.10.15 17:44:28 | 001,930,532 | ---- | C] () -- C:\Users\Tadeáš\Desktop\2009-06-29 5351-plocha.jpg
[2010.10.15 17:31:17 | 005,492,980 | ---- | C] () -- C:\Users\Tadeáš\Desktop\10-13-2010_16981.jpg
[2010.10.14 21:29:03 | 006,795,088 | ---- | C] () -- C:\Users\Tadeáš\Desktop\10-13-2010_1698.jpg
[2010.10.14 13:22:35 | 001,716,736 | ---- | C] () -- C:\Users\Tadeáš\Desktop\aktualita - Chile, zasypaní horníci.ppt
[2010.10.13 22:33:21 | 000,064,671 | ---- | C] () -- C:\Users\Tadeáš\Desktop\petr a ja.jpg
[2010.10.13 17:08:50 | 001,901,477 | ---- | C] () -- C:\Users\Tadeáš\Desktop\2009-06-29 5351.jpg
[2010.10.13 16:39:45 | 007,021,382 | ---- | C] () -- C:\Users\Tadeáš\Desktop\10-07-2010_1585.jpg
[2010.10.13 09:39:08 | 000,001,174 | ---- | C] () -- C:\Users\Public\Desktop\Dungeon Keeper 2.lnk
[2010.10.12 11:19:22 | 008,331,274 | ---- | C] () -- C:\Users\Tadeáš\Desktop\Božanov 3.mp4
[2010.10.09 22:00:25 | 000,059,372 | ---- | C] () -- C:\Users\Tadeáš\Desktop\DSC_1139h.jpg
[2010.10.08 21:26:48 | 042,103,213 | ---- | C] () -- C:\Users\Tadeáš\Documents\Bez názvu.wma
[2010.10.08 10:30:26 | 000,521,192 | ---- | C] () -- C:\Users\Tadeáš\Desktop\10-07-2010_1622.jpg
[2010.10.07 18:10:34 | 000,356,669 | ---- | C] () -- C:\Users\Tadeáš\Desktop\DSC_1139.jpg
[2010.10.06 20:46:31 | 000,078,320 | ---- | C] () -- C:\Users\Public\Documents\Petr Löbel, Tadeáš Skuhra, výroky z VŠ.docx
[2010.10.06 14:40:44 | 000,000,940 | ---- | C] () -- C:\Users\Tadeáš\Desktop\WinKart.lnk
[2010.10.04 13:42:11 | 000,002,212 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010.10.03 19:58:24 | 000,001,268 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer SP.lnk
[2010.09.28 20:22:02 | 000,000,187 | ---- | C] () -- C:\Users\Tadeáš\Desktop\QuickStores.url
[2010.09.28 20:22:01 | 000,002,061 | ---- | C] () -- C:\Users\Public\Desktop\MyPhoneExplorer.lnk
[2010.09.28 15:12:58 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\BitTorrent.lnk
[2010.08.07 13:57:54 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2010.06.18 18:23:54 | 000,000,268 | RH-- | C] () -- C:\ProgramData\HAL
[2010.06.18 18:23:54 | 000,000,268 | RH-- | C] () -- C:\Users\Tadeáš\AppData\Roaming\Graphics
[2010.06.18 18:23:54 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLdw.DAT
[2010.06.18 18:18:24 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Guitar
[2010.06.18 18:18:24 | 000,000,268 | RH-- | C] () -- C:\Users\Tadeáš\AppData\Roaming\Grand Piano
[2010.06.18 18:18:24 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLdu.DAT
[2010.06.18 16:01:35 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.12.16 07:32:54 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\SonyVideoProcessor.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.09 09:55:58 | 000,057,904 | ---- | C] () -- C:\Windows\SysWow64\wbload.dll
[2008.10.22 05:29:06 | 000,173,550 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2002.08.29 18:33:56 | 000,319,488 | R--- | C] () -- C:\Users\Tadeáš\AppData\Roaming\MafiaSetup.exe

========== LOP Check ==========

[2010.09.01 14:52:09 | 000,000,000 | -HSD | M] -- C:\Users\Tadeáš\AppData\Roaming\.#
[2010.08.07 14:33:00 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Atari
[2010.07.31 09:44:54 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Auslogics
[2010.10.12 14:27:28 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\BitTorrent
[2010.06.30 08:26:19 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\DAEMON Tools Lite
[2010.10.28 09:58:09 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\ICQ
[2010.08.07 13:30:11 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Leadertech
[2010.09.28 20:55:07 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\MyPhoneExplorer
[2010.06.18 19:08:03 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Nikon
[2010.10.08 00:33:06 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\QuickStoresToolbar
[2010.06.18 18:50:03 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\SMS posílač Treca
[2010.09.29 21:09:19 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Ubisoft
[2010.06.27 18:22:24 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Western Digital
[2010.06.20 13:19:52 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Zoner
[2009.12.16 07:59:22 | 000,000,372 | ---- | M] () -- C:\Windows\Tasks\McDefragTask.job
[2010.10.13 08:40:43 | 000,032,624 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: samovolne spuštění Windows Live Messenger

#22 Příspěvek od motji »

:arrow: Tyto složky znáte?
C:\Users\Public\Documents\UJEP
C:\Users\Public
C:\Program Files (x86)\OCAD
C:\Users\Tadeáš\Desktop\UJEP
C:\Users\Tadeáš\Desktop\Nová složka (4)



:arrow: Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx (WRC Class)
O4 - HKLM..\Run: [NVIDIA driver monitor] C:\Users\Public\nvsvc32.exe ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()

:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\Users\Tadeáš\AppData\Roaming\.#
C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.lnk
C:\Windows\setup_9.0.0.722_24.10.2010_13-20drv.spi
C:\Program Files (x86)\Ask.com
C:\Program Files (x86)\Bing Bar Installer
C:\Users\Public\
 C:\Program Files (x86)\DAEMON Tools Toolbar\

:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]

-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Tadeas.skuhra
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 25 čer 2008 15:10

Re: samovolne spuštění Windows Live Messenger

#23 Příspěvek od Tadeas.skuhra »

ano, ty složky poznávám..


All processes killed
========== OTL ==========
No active process named explorer.exe was found!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\grooveLocalGWS\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88FED34C-F0CA-4636-A375-3CB6248B04CD}\ not found.
File {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found.
File {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{314111c7-a502-11d2-bbca-00c04f8ec294}\ not found.
File {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found.
File {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03C514A3-1EFB-4856-9F99-10D7BE1653C0}\ not found.
File {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324}\ not found.
File {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found not found.
Starting removal of ActiveX control {C345E174-3E87-4F41-A01C-B066A90A49B4}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C345E174-3E87-4F41-A01C-B066A90A49B4}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C345E174-3E87-4F41-A01C-B066A90A49B4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C345E174-3E87-4F41-A01C-B066A90A49B4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C345E174-3E87-4F41-A01C-B066A90A49B4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C345E174-3E87-4F41-A01C-B066A90A49B4}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NVIDIA driver monitor deleted successfully.
C:\Users\Public\nvsvc32.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
64bit-Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll moved successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
C:\Users\Tadeáš\AppData\Roaming\.# folder moved successfully.
C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.lnk moved successfully.
C:\Windows\setup_9.0.0.722_24.10.2010_13-20drv.spi moved successfully.
C:\Program Files (x86)\Ask.com folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer\OFFLINE\JS folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer\OFFLINE\Images folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer\OFFLINE\CSS folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer\OFFLINE folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer\BootStrapper folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer folder moved successfully.
C:\Users\Public\Videos\Sample Videos folder moved successfully.
C:\Users\Public\Videos folder moved successfully.
C:\Users\Public\Recorded TV\Sample Media folder moved successfully.
C:\Users\Public\Recorded TV folder moved successfully.
C:\Users\Public\Pictures\Sample Pictures folder moved successfully.
C:\Users\Public\Pictures folder moved successfully.
C:\Users\Public\Music\Seznamy stop folder moved successfully.
C:\Users\Public\Music\Sample Music folder moved successfully.
C:\Users\Public\Music\Neznámý interpret\Neznámé album (24.6.2010 20-51-04) folder moved successfully.
C:\Users\Public\Music\Neznámý interpret folder moved successfully.
C:\Users\Public\Music\1967 - The Piper At The Gates Of Dawn folder moved successfully.
C:\Users\Public\Music\1966 - Tonite Let's All Make Love in London folder moved successfully.
C:\Users\Public\Music folder moved successfully.
C:\Users\Public\Libraries folder moved successfully.
C:\Users\Public\Favorites folder moved successfully.
C:\Users\Public\Downloads folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO-P103 - geografie obyvatelstva a sídel\Nová složka folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO-P103 - geografie obyvatelstva a sídel folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO- P110 - základy fyzické geografie folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - P111 - vývoj geografického myšlení folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - P107 - Geografie ČR folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_9\topo_25 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_9\info folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_9 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_8 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_7\AirBaseXML folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_7 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_5 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_4\gdb.gdb folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_4 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_3 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_10\topo_25 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_10\info folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_10 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\Obrazy folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\styly folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\system folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K9 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K6 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K5 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K4 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K2 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K1 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\G4 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\G3 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\G2 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\download folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Obrázky folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\klady folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Dokumenty folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\BLAHA folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\6 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 104 - Kvantitativní metody folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 311 - regionální geografie světa A folder moved successfully.
C:\Users\Public\Documents\UJEP folder moved successfully.
C:\Users\Public\Documents\Stardock\WindowBlinds\Vista Images folder moved successfully.
C:\Users\Public\Documents\Stardock\WindowBlinds\Think Green folder moved successfully.
C:\Users\Public\Documents\Stardock\WindowBlinds folder moved successfully.
C:\Users\Public\Documents\Stardock\ThemeManager folder moved successfully.
C:\Users\Public\Documents\Stardock\IconPackager\Think Green folder moved successfully.
C:\Users\Public\Documents\Stardock\IconPackager folder moved successfully.
C:\Users\Public\Documents\Stardock folder moved successfully.
C:\Users\Public\Documents\obraz folder moved successfully.
C:\Users\Public\Documents\My Videos folder moved successfully.
C:\Users\Public\Documents\My Pictures folder moved successfully.
C:\Users\Public\Documents\My Music folder moved successfully.
C:\Users\Public\Documents\microsoft\IdentityCRL\production folder moved successfully.
C:\Users\Public\Documents\microsoft\IdentityCRL folder moved successfully.
C:\Users\Public\Documents\microsoft folder moved successfully.
C:\Users\Public\Documents\DAEMON Tools Images folder moved successfully.
C:\Users\Public\Documents\ASSASSINS CREED folder moved successfully.
C:\Users\Public\Documents folder moved successfully.
C:\Users\Public\Desktop folder moved successfully.
Folder move failed. C:\Users\Public scheduled to be moved on reboot.
C:\Program Files (x86)\DAEMON Tools Toolbar\Resources folder moved successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar folder moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Tadeáš
->Temp folder emptied: 2039914 bytes
->Temporary Internet Files folder emptied: 6902395 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 447347933 bytes
->Flash cache emptied: 2985 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 462690 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 210480 bytes
RecycleBin emptied: 4380716 bytes

Total Files Cleaned = 440,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: Tadeáš
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.16.0 log created on 10282010_143732

Files\Folders moved on Reboot...
C:\Users\Public\Videos folder moved successfully.
C:\Users\Public\Pictures folder moved successfully.
C:\Users\Public\Music folder moved successfully.
C:\Users\Public\Documents folder moved successfully.
Folder move failed. C:\Users\Public scheduled to be moved on reboot.
C:\Users\Tadeáš\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Windows\temp\mcafee_ywKO928GMy6LTZD not found!
File\Folder C:\Windows\temp\mcmsc_gxH38e64juB1kEt not found!
File\Folder C:\Windows\temp\mcmsc_lcnRNPlj2gL8rKm not found!
File\Folder C:\Windows\temp\mcmsc_ZyoPLc9PLC63ATA not found!
File\Folder C:\Windows\temp\sqlite_Qi0uf8skyd7WVVh not found!
File\Folder C:\Windows\temp\sqlite_RUSjgwq9qbuB8PU not found!
File\Folder C:\Windows\temp\sqlite_u3iOt1PfGcJb12q not found!
File\Folder C:\Windows\temp\sqlite_X0jqCmPMhcOSmdu not found!

Registry entries deleted on Reboot...

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: samovolne spuštění Windows Live Messenger

#24 Příspěvek od motji »

Co počítač?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět