samovolne spuštění Windows Live Messenger

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
L.M.
1. Stupeň Varování
Příspěvky: 140
Registrován: 22 Črv 2010 15:15

Re: samovolne spuštění Windows Live Messenger

#16 Příspěvek od L.M. »

Zdravím ja se omlouvam že tu skaču pokud chcete Windows MSN dat pryč tak stači
když kliknete na start spusti zadat tento příkaz -
RunDll32 advpack.dll,LaunchINFSection %windir%\INF\msmsgs.inf,BLC.Remove
ENTER restart :turned:

Tadeas.skuhra
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 25 Črv 2008 15:10

Re: samovolne spuštění Windows Live Messenger

#17 Příspěvek od Tadeas.skuhra »

je-li tomu tak, tak dík

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: samovolne spuštění Windows Live Messenger

#18 Příspěvek od motji »

Omlouvám se za vstup
Pomohlo to?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Tadeas.skuhra
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 25 Črv 2008 15:10

Re: samovolne spuštění Windows Live Messenger

#19 Příspěvek od Tadeas.skuhra »

nepomohlo, hodilo to chybu, "Chyba: nelze najít soubor INF C:\Windows\INF\msmsgs.inf."
tož co s tím?=)

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: samovolne spuštění Windows Live Messenger

#20 Příspěvek od motji »

Poprosím Vás o nový log z OTL :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Tadeas.skuhra
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 25 Črv 2008 15:10

Re: samovolne spuštění Windows Live Messenger

#21 Příspěvek od Tadeas.skuhra »

tady je =)


OTL logfile created on: 28/10/2010 10:07:38 - Run 2
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Users\Tadeáš\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 50.00% Memory free
8.00 Gb Paging File | 5.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.01 Gb Total Space | 279.30 Gb Free Space | 61.79% Space Free | Partition Type: NTFS

Computer Name: TADEAS-VAIO | User Name: Tadeáš | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/10/21 19:59:50 | 000,085,184 | ---- | M] (Macrovision ) -- C:\Program Files (x86)\Common Files\InstallShield Shared\Service\InstallShield Licensing Service.exe
PRC - [2010/08/12 15:15:34 | 000,081,296 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Care\VCSpt.exe
PRC - [2010/05/28 11:14:24 | 000,205,168 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe
PRC - [2010/04/01 11:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2010/02/19 19:19:24 | 000,529,776 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
PRC - [2010.10.22 22:11:45 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Tadeáš\Desktop\OTL.exe
PRC - [2010.10.12 08:37:00 | 000,974,904 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2010.10.03 19:57:13 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
PRC - [2010.08.22 13:02:26 | 000,133,432 | ---- | M] (ICQ, LLC.) -- C:\Program Files (x86)\ICQ7.2\ICQ.exe
PRC - [2010.06.10 06:58:32 | 001,218,008 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
PRC - [2010.06.10 06:58:32 | 000,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe
PRC - [2010.05.18 13:38:46 | 000,075,776 | ---- | M] (Sony of America Corporation) -- C:\Program Files\Sony\VAIO Care\listener.exe
PRC - [2010.03.25 14:39:22 | 000,490,280 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010.02.17 15:53:26 | 000,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/11/30 21:20:00 | 000,112,488 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe
PRC - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MPF\MpfSrv.exe
PRC - [2009/10/24 05:18:54 | 000,360,224 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\PMB\PMBDeviceInfoProvider.exe
PRC - [2009/10/13 21:25:54 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/10/02 13:02:56 | 000,026,640 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MSK\msksrver.exe
PRC - [2009/09/14 21:24:08 | 000,206,336 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
PRC - [2009/09/14 20:53:48 | 000,642,416 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
PRC - [2009/08/26 21:24:00 | 000,320,880 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009.12.16 07:31:35 | 000,026,624 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe
PRC - [2009.10.24 05:18:52 | 000,597,792 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\SONY\PMB\PMBVolumeWatcher.exe
PRC - [2009.10.13 21:25:30 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009.07.07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2008/09/18 12:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
PRC - [2008/06/05 10:19:18 | 000,479,232 | ---- | M] (Nikon Corporation) -- C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe
PRC - [2007/07/24 13:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2007/01/04 21:48:50 | 000,112,152 | ---- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe


========== Modules (SafeList) ==========

MOD - [2010.10.22 22:11:45 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Tadeáš\Desktop\OTL.exe
MOD - [2010.08.21 07:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2009.10.20 15:36:40 | 000,633,192 | ---- | M] (Stardock Corporation) -- C:\Program Files (x86)\Stardock\MyColors\wblind.dll
MOD - [2009.06.09 09:56:14 | 000,034,168 | ---- | M] (Stardock.Net, Inc) -- C:\Program Files (x86)\Stardock\MyColors\wbhelp.dll
MOD - [2009.06.09 09:55:58 | 000,057,904 | ---- | M] () -- C:\Windows\SysWOW64\wbload.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010.09.22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010.09.20 10:47:58 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2010.08.12 15:15:34 | 000,257,936 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe -- (SampleCollector)
SRV:64bit: - [2010.04.09 13:37:36 | 001,223,024 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent)
SRV:64bit: - [2010.02.24 13:16:08 | 000,696,848 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV:64bit: - [2010.02.19 19:19:28 | 000,115,568 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe -- (VcmXmlIfHelper)
SRV:64bit: - [2010.02.19 19:19:24 | 000,529,776 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV:64bit: - [2010.02.17 16:45:16 | 000,155,456 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV:64bit: - [2009.11.30 21:51:18 | 000,571,248 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV:64bit: - [2009.11.25 21:06:06 | 000,821,760 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Smart Network\VSNService.exe -- (VSNService)
SRV:64bit: - [2009.10.14 14:31:44 | 000,116,224 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService)
SRV:64bit: - [2009.09.21 18:24:40 | 001,420,560 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2009.09.21 18:00:44 | 000,831,760 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2009.09.04 23:35:12 | 000,873,248 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2009.09.01 23:42:00 | 000,361,840 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe -- (VcmINSMgr)
SRV:64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2010.10.21 19:59:50 | 000,085,184 | ---- | M] (Macrovision ) [Auto | Running] -- C:\Program Files (x86)\Common Files\InstallShield Shared\Service\InstallShield Licensing Service.exe -- (InstallShield Licensing Service)
SRV - [2010.09.20 10:47:56 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.06.10 06:58:32 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2010.05.28 11:14:24 | 000,205,168 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2010.03.25 14:39:22 | 000,490,280 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010.02.17 15:53:26 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2009.10.27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2009.10.24 05:18:54 | 000,360,224 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2009.10.15 18:34:36 | 000,427,304 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2009.10.15 18:34:36 | 000,091,432 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe -- (SOHPlMgr)
SRV - [2009.10.15 18:34:36 | 000,075,048 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2009.10.15 18:34:34 | 000,120,104 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2009.10.15 18:34:34 | 000,070,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe -- (SOHDBSvr)
SRV - [2009.10.13 21:25:30 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2009.10.02 13:02:56 | 000,026,640 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MSK\MskSrver.exe -- (MSK80Service)
SRV - [2009.09.14 21:24:08 | 000,206,336 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe -- (VzCdbSvc)
SRV - [2009.09.14 21:24:08 | 000,069,632 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe -- (VAIO Entertainment TV Device Arbitration Service)
SRV - [2009.09.14 20:53:48 | 000,642,416 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2009.08.31 03:59:30 | 000,362,992 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe -- (Roxio Upnp Server 10)
SRV - [2009.08.31 03:59:18 | 000,313,840 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe -- (Roxio UPnP Renderer 10)
SRV - [2009.07.08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2009.07.07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
SRV - [2009.06.16 09:58:08 | 000,020,480 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe -- (WDSmartWareBackgroundService)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.06.09 09:56:16 | 000,337,200 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files (x86)\Stardock\MyColors\VistaSrv.exe -- (WindowBlinds)
SRV - [2008.09.18 12:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe -- (uCamMonitor)
SRV - [2007.07.24 13:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2007.01.04 21:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010.09.23 00:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010.07.30 13:36:01 | 000,021,200 | ---- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TVicHW64.sys -- (TVICHW64)
DRV:64bit: - [2010.07.15 15:18:22 | 000,176,144 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\Mpfp.sys -- (MPFP)
DRV:64bit: - [2010.06.30 08:07:55 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010.02.17 16:52:42 | 000,308,296 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2010.02.17 16:52:42 | 000,102,472 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2010.02.17 16:52:42 | 000,049,480 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfesmfk.sys -- (mfesmfk)
DRV:64bit: - [2010.02.17 16:45:32 | 000,040,904 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdk.sys -- (mferkdk)
DRV:64bit: - [2009.11.18 22:03:16 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2009.11.18 22:03:15 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2009.11.18 22:03:15 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2009.11.18 22:03:13 | 000,052,264 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btusbflt.sys -- (btusbflt)
DRV:64bit: - [2009.11.18 22:02:45 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2009.11.06 22:34:48 | 000,084,512 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2009.11.06 22:27:30 | 000,093,696 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimssne64.sys -- (rimspci)
DRV:64bit: - [2009.11.05 08:30:19 | 001,542,656 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009.11.04 11:59:59 | 000,253,488 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2009.10.27 22:06:59 | 000,151,040 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009.10.13 21:16:40 | 000,409,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009.10.10 04:41:20 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009.09.15 22:09:08 | 000,075,776 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\risdsne64.sys -- (risdsnpe)
DRV:64bit: - [2009.09.15 14:40:42 | 006,952,960 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64) Intel(R)
DRV:64bit: - [2009.08.19 22:09:21 | 000,011,392 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SFEP.sys -- (SFEP)
DRV:64bit: - [2009.07.31 22:02:03 | 000,393,216 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009.07.14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.26 16:32:04 | 000,019,968 | ---- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys -- (ArcSoftKsUFilter)
DRV:64bit: - [2009.05.20 12:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009.02.13 12:02:52 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2007.04.17 13:51:50 | 000,014,112 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\regi.sys -- (regi)
DRV - [2008.08.14 07:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)
DRV - [2007.04.17 22:09:28 | 000,011,032 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\drivers\regi.sys -- (regi)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.10.03 19:58:24 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2010.09.19 16:12:18 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho64.dll ()
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [MarketingTools] C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe (Sony Corporation)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files (x86)\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NVIDIA driver monitor] C:\Users\Public\nvsvc32.exe ()
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\SONY\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [NVIDIA driver monitor] C:\Users\Public\nvsvc32.exe ()
O4 - Startup: C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.lnk = C:\Users\Tadeáš\AppData\Local\Temp\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.bat File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8:64bit: - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx (WRC Class)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1a05dae5-840e-11df-815b-5442490b19bc}\Shell - "" = AutoRun
O33 - MountPoints2\{1a05dae5-840e-11df-815b-5442490b19bc}\Shell\AutoRun\command - "" = G:\autorun.exe -- File not found
O33 - MountPoints2\{a8d440d4-7a10-11df-b81d-506313f28287}\Shell - "" = AutoRun
O33 - MountPoints2\{a8d440d4-7a10-11df-b81d-506313f28287}\Shell\AutoRun\command - "" = H:\WD SmartWare.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010.10.28 01:43:06 | 000,000,000 | ---D | C] -- C:\Windows\cs
[2010.10.28 01:40:10 | 000,048,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fssfltr.sys
[2010.10.28 01:39:26 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2010.10.28 01:38:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSN Toolbar
[2010.10.28 01:38:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bing Bar Installer
[2010.10.28 01:37:03 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Local\Windows Live
[2010.10.28 01:36:34 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2010.10.28 01:36:34 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll
[2010.10.28 01:36:34 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2010.10.28 01:36:34 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll
[2010.10.28 01:36:33 | 004,068,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2010.10.28 01:36:33 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2010.10.28 01:36:32 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2010.10.27 10:14:12 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll
[2010.10.27 10:14:11 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll
[2010.10.27 10:14:11 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll
[2010.10.27 10:14:10 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax
[2010.10.27 10:14:10 | 000,258,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax
[2010.10.27 10:14:10 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax
[2010.10.27 10:14:10 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax
[2010.10.27 10:13:54 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys
[2010.10.25 18:43:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ocad9
[2010.10.24 12:55:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2010.10.24 12:54:01 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\Virus Removal Tool
[2010.10.24 00:18:11 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2010.10.22 22:55:12 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\Malwarebytes
[2010.10.22 22:54:53 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010.10.22 22:54:52 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2010.10.22 22:54:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010.10.22 22:54:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010.10.22 22:11:32 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Tadeáš\Desktop\OTL.exe
[2010.10.22 09:19:11 | 000,000,000 | ---D | C] -- C:\rsit
[2010.10.21 23:45:15 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Documents\My Received Files
[2010.10.21 22:26:42 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Tracing
[2010.10.21 22:09:10 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\Nová složka (4)
[2010.10.21 21:59:49 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\Geografie obyvatelstva a sídel
[2010.10.21 20:00:14 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallShield
[2010.10.21 19:59:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield Shared
[2010.10.21 19:54:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OCAD
[2010.10.20 11:23:44 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\UJEP
[2010.10.19 17:24:55 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\Nová složka
[2010.10.17 23:04:51 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\U Gule - 15.10.2010
[2010.10.17 22:53:14 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\FEC
[2010.10.14 21:58:19 | 000,148,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\t2embed.dll
[2010.10.14 21:58:19 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2010.10.14 21:58:18 | 002,085,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ole32.dll
[2010.10.14 21:58:16 | 000,483,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\StructuredQuery.dll
[2010.10.14 21:58:13 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comctl32.dll
[2010.10.14 21:58:11 | 001,024,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpmde.dll
[2010.10.14 21:58:10 | 000,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpmde.dll
[2010.10.14 21:58:09 | 000,954,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40.dll
[2010.10.14 21:58:09 | 000,954,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc40u.dll
[2010.10.14 21:57:58 | 000,702,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2010.10.14 21:57:58 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2010.10.14 21:57:57 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2010.10.14 21:57:57 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2010.10.14 21:57:57 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2010.10.14 21:57:56 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2010.10.14 21:57:56 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2010.10.14 21:57:56 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2010.10.14 21:57:56 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2010.10.14 21:57:56 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2010.10.14 21:57:55 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2010.10.14 21:57:55 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2010.10.14 21:57:55 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2010.10.14 21:57:55 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2010.10.14 21:57:43 | 014,627,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2010.10.14 21:57:42 | 011,406,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2010.10.14 21:57:41 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2010.10.14 21:57:40 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2010.10.14 21:57:38 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sscore.dll
[2010.10.12 13:48:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bullfrog
[2010.10.08 00:41:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2010.10.08 00:41:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2010.10.08 00:40:39 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010.10.08 00:37:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2010.10.08 00:37:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2010.10.08 00:35:23 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010.10.08 00:32:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Toolbar
[2010.10.08 00:31:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite
[2010.10.07 20:26:48 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\Desktop\focení
[2010.10.07 15:20:01 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Local\Microsoft Help
[2010.10.06 14:40:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinKart
[2010.10.04 01:06:28 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Local\Evernote
[2010.10.03 19:58:15 | 000,185,920 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2010.10.03 19:58:06 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2010.10.03 19:58:06 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2010.10.03 19:57:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2010.10.03 19:57:17 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2010.10.03 19:57:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Real
[2010.10.03 19:57:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2010.10.03 19:57:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Real
[2010.10.03 19:57:09 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\Real
[2010.09.29 20:50:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ubisoft
[2010.09.28 20:22:12 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\MyPhoneExplorer
[2010.09.28 20:22:02 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\QuickStoresToolbar
[2010.09.28 20:21:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MyPhoneExplorer
[2010.09.28 18:53:30 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\UJEP
[2010.09.28 15:34:54 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\dvdcss
[2010.09.28 15:12:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BitTorrent
[2010.09.28 15:12:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
[2010.09.28 15:12:03 | 000,000,000 | ---D | C] -- C:\Users\Tadeáš\AppData\Roaming\BitTorrent

========== Files - Modified Within 30 Days ==========

[2010.10.28 10:07:00 | 000,000,966 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010.10.28 10:05:11 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.10.28 10:05:11 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.10.28 09:58:42 | 000,034,267 | ---- | M] () -- C:\Windows\SysNative\Config.MPF
[2010.10.28 09:57:25 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010.10.28 09:57:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.10.28 09:56:56 | 3156,807,680 | -HS- | M] () -- C:\hiberfil.sys
[2010.10.27 09:12:38 | 001,470,062 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010.10.27 09:12:38 | 000,631,292 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2010.10.27 09:12:38 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010.10.27 09:12:38 | 000,121,914 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2010.10.27 09:12:38 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010.10.25 18:43:35 | 000,000,878 | ---- | M] () -- C:\Users\Tadeáš\Desktop\OCAD 9.lnk
[2010.10.24 17:08:23 | 000,001,248 | ---- | M] () -- C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.lnk
[2010.10.24 15:27:14 | 000,000,092 | -HS- | M] () -- C:\Windows\setup_9.0.0.722_24.10.2010_13-20drv.spi
[2010.10.22 22:54:57 | 000,001,013 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.10.22 22:11:45 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Tadeáš\Desktop\OTL.exe
[2010.10.22 14:12:58 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLdu.DAT
[2010.10.21 23:52:59 | 000,247,504 | ---- | M] () -- C:\Users\Public\Documents\cc_20101021_235113.reg
[2010.10.21 20:10:56 | 034,799,416 | ---- | M] () -- C:\Users\Tadeáš\Desktop\zobr_1 kopie.bmp
[2010.10.21 19:59:53 | 000,001,878 | ---- | M] () -- C:\Users\Public\Desktop\Launch OCAD 10 Trial.lnk
[2010.10.20 15:45:41 | 032,651,763 | ---- | M] () -- C:\Users\Tadeáš\Documents\Bez názvu (2).wma
[2010.10.20 12:20:13 | 000,078,320 | ---- | M] () -- C:\Users\Public\Documents\Petr Löbel, Tadeáš Skuhra, výroky z VŠ.docx
[2010.10.19 22:58:27 | 001,716,736 | ---- | M] () -- C:\Users\Tadeáš\Desktop\aktualita - Chile, zasypaní horníci.ppt
[2010.10.18 16:17:59 | 000,220,361 | ---- | M] () -- C:\Users\Tadeáš\Desktop\133143138.jpg
[2010.10.18 16:11:41 | 001,791,583 | ---- | M] () -- C:\Users\Tadeáš\Desktop\nike.jpg
[2010.10.15 17:44:33 | 001,930,532 | ---- | M] () -- C:\Users\Tadeáš\Desktop\2009-06-29 5351-plocha.jpg
[2010.10.15 17:31:31 | 005,492,980 | ---- | M] () -- C:\Users\Tadeáš\Desktop\10-13-2010_16981.jpg
[2010.10.15 15:10:01 | 001,901,477 | ---- | M] () -- C:\Users\Tadeáš\Desktop\2009-06-29 5351.jpg
[2010.10.15 11:17:19 | 003,059,928 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010.10.14 22:12:50 | 006,795,088 | ---- | M] () -- C:\Users\Tadeáš\Desktop\10-13-2010_1698.jpg
[2010.10.13 22:33:22 | 000,064,671 | ---- | M] () -- C:\Users\Tadeáš\Desktop\petr a ja.jpg
[2010.10.13 16:39:57 | 007,021,382 | ---- | M] () -- C:\Users\Tadeáš\Desktop\10-07-2010_1585.jpg
[2010.10.13 09:39:08 | 000,001,174 | ---- | M] () -- C:\Users\Public\Desktop\Dungeon Keeper 2.lnk
[2010.10.12 11:19:52 | 008,331,274 | ---- | M] () -- C:\Users\Tadeáš\Desktop\Božanov 3.mp4
[2010.10.09 22:00:25 | 000,059,372 | ---- | M] () -- C:\Users\Tadeáš\Desktop\DSC_1139h.jpg
[2010.10.08 21:26:48 | 042,103,213 | ---- | M] () -- C:\Users\Tadeáš\Documents\Bez názvu.wma
[2010.10.08 10:31:00 | 000,521,192 | ---- | M] () -- C:\Users\Tadeáš\Desktop\10-07-2010_1622.jpg
[2010.10.07 18:11:01 | 000,356,669 | ---- | M] () -- C:\Users\Tadeáš\Desktop\DSC_1139.jpg
[2010.10.06 14:40:44 | 000,000,940 | ---- | M] () -- C:\Users\Tadeáš\Desktop\WinKart.lnk
[2010.10.04 13:42:11 | 000,002,212 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010.10.03 19:58:24 | 000,001,268 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer SP.lnk
[2010.10.03 19:58:15 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll
[2010.10.03 19:58:06 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll
[2010.10.03 19:58:06 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll
[2010.10.03 19:57:17 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp71.dll
[2010.10.03 19:57:17 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2010.09.28 20:22:02 | 000,000,187 | ---- | M] () -- C:\Users\Tadeáš\Desktop\QuickStores.url
[2010.09.28 20:22:01 | 000,002,061 | ---- | M] () -- C:\Users\Public\Desktop\MyPhoneExplorer.lnk
[2010.09.28 15:12:58 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\BitTorrent.lnk

========== Files Created - No Company Name ==========

[2010.10.25 18:43:35 | 000,000,878 | ---- | C] () -- C:\Users\Tadeáš\Desktop\OCAD 9.lnk
[2010.10.24 17:08:23 | 000,001,248 | ---- | C] () -- C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.lnk
[2010.10.24 15:27:14 | 000,000,092 | -HS- | C] () -- C:\Windows\setup_9.0.0.722_24.10.2010_13-20drv.spi
[2010.10.22 22:54:57 | 000,001,013 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010.10.21 23:51:16 | 000,247,504 | ---- | C] () -- C:\Users\Public\Documents\cc_20101021_235113.reg
[2010.10.21 20:16:39 | 034,799,416 | ---- | C] () -- C:\Users\Tadeáš\Desktop\zobr_1 kopie.bmp
[2010.10.21 19:59:53 | 000,001,878 | ---- | C] () -- C:\Users\Public\Desktop\Launch OCAD 10 Trial.lnk
[2010.10.20 15:45:41 | 032,651,763 | ---- | C] () -- C:\Users\Tadeáš\Documents\Bez názvu (2).wma
[2010.10.18 16:17:59 | 000,220,361 | ---- | C] () -- C:\Users\Tadeáš\Desktop\133143138.jpg
[2010.10.18 16:11:40 | 001,791,583 | ---- | C] () -- C:\Users\Tadeáš\Desktop\nike.jpg
[2010.10.15 17:44:28 | 001,930,532 | ---- | C] () -- C:\Users\Tadeáš\Desktop\2009-06-29 5351-plocha.jpg
[2010.10.15 17:31:17 | 005,492,980 | ---- | C] () -- C:\Users\Tadeáš\Desktop\10-13-2010_16981.jpg
[2010.10.14 21:29:03 | 006,795,088 | ---- | C] () -- C:\Users\Tadeáš\Desktop\10-13-2010_1698.jpg
[2010.10.14 13:22:35 | 001,716,736 | ---- | C] () -- C:\Users\Tadeáš\Desktop\aktualita - Chile, zasypaní horníci.ppt
[2010.10.13 22:33:21 | 000,064,671 | ---- | C] () -- C:\Users\Tadeáš\Desktop\petr a ja.jpg
[2010.10.13 17:08:50 | 001,901,477 | ---- | C] () -- C:\Users\Tadeáš\Desktop\2009-06-29 5351.jpg
[2010.10.13 16:39:45 | 007,021,382 | ---- | C] () -- C:\Users\Tadeáš\Desktop\10-07-2010_1585.jpg
[2010.10.13 09:39:08 | 000,001,174 | ---- | C] () -- C:\Users\Public\Desktop\Dungeon Keeper 2.lnk
[2010.10.12 11:19:22 | 008,331,274 | ---- | C] () -- C:\Users\Tadeáš\Desktop\Božanov 3.mp4
[2010.10.09 22:00:25 | 000,059,372 | ---- | C] () -- C:\Users\Tadeáš\Desktop\DSC_1139h.jpg
[2010.10.08 21:26:48 | 042,103,213 | ---- | C] () -- C:\Users\Tadeáš\Documents\Bez názvu.wma
[2010.10.08 10:30:26 | 000,521,192 | ---- | C] () -- C:\Users\Tadeáš\Desktop\10-07-2010_1622.jpg
[2010.10.07 18:10:34 | 000,356,669 | ---- | C] () -- C:\Users\Tadeáš\Desktop\DSC_1139.jpg
[2010.10.06 20:46:31 | 000,078,320 | ---- | C] () -- C:\Users\Public\Documents\Petr Löbel, Tadeáš Skuhra, výroky z VŠ.docx
[2010.10.06 14:40:44 | 000,000,940 | ---- | C] () -- C:\Users\Tadeáš\Desktop\WinKart.lnk
[2010.10.04 13:42:11 | 000,002,212 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2010.10.03 19:58:24 | 000,001,268 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer SP.lnk
[2010.09.28 20:22:02 | 000,000,187 | ---- | C] () -- C:\Users\Tadeáš\Desktop\QuickStores.url
[2010.09.28 20:22:01 | 000,002,061 | ---- | C] () -- C:\Users\Public\Desktop\MyPhoneExplorer.lnk
[2010.09.28 15:12:58 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\BitTorrent.lnk
[2010.08.07 13:57:54 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2010.06.18 18:23:54 | 000,000,268 | RH-- | C] () -- C:\ProgramData\HAL
[2010.06.18 18:23:54 | 000,000,268 | RH-- | C] () -- C:\Users\Tadeáš\AppData\Roaming\Graphics
[2010.06.18 18:23:54 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLdw.DAT
[2010.06.18 18:18:24 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Guitar
[2010.06.18 18:18:24 | 000,000,268 | RH-- | C] () -- C:\Users\Tadeáš\AppData\Roaming\Grand Piano
[2010.06.18 18:18:24 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLdu.DAT
[2010.06.18 16:01:35 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009.12.16 07:32:54 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\SonyVideoProcessor.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.09 09:55:58 | 000,057,904 | ---- | C] () -- C:\Windows\SysWow64\wbload.dll
[2008.10.22 05:29:06 | 000,173,550 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2002.08.29 18:33:56 | 000,319,488 | R--- | C] () -- C:\Users\Tadeáš\AppData\Roaming\MafiaSetup.exe

========== LOP Check ==========

[2010.09.01 14:52:09 | 000,000,000 | -HSD | M] -- C:\Users\Tadeáš\AppData\Roaming\.#
[2010.08.07 14:33:00 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Atari
[2010.07.31 09:44:54 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Auslogics
[2010.10.12 14:27:28 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\BitTorrent
[2010.06.30 08:26:19 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\DAEMON Tools Lite
[2010.10.28 09:58:09 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\ICQ
[2010.08.07 13:30:11 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Leadertech
[2010.09.28 20:55:07 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\MyPhoneExplorer
[2010.06.18 19:08:03 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Nikon
[2010.10.08 00:33:06 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\QuickStoresToolbar
[2010.06.18 18:50:03 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\SMS posílač Treca
[2010.09.29 21:09:19 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Ubisoft
[2010.06.27 18:22:24 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Western Digital
[2010.06.20 13:19:52 | 000,000,000 | ---D | M] -- C:\Users\Tadeáš\AppData\Roaming\Zoner
[2009.12.16 07:59:22 | 000,000,372 | ---- | M] () -- C:\Windows\Tasks\McDefragTask.job
[2010.10.13 08:40:43 | 000,032,624 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: samovolne spuštění Windows Live Messenger

#22 Příspěvek od motji »

:arrow: Tyto složky znáte?
C:\Users\Public\Documents\UJEP
C:\Users\Public
C:\Program Files (x86)\OCAD
C:\Users\Tadeáš\Desktop\UJEP
C:\Users\Tadeáš\Desktop\Nová složka (4)



:arrow: Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx (WRC Class)
O4 - HKLM..\Run: [NVIDIA driver monitor] C:\Users\Public\nvsvc32.exe ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()

:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\Users\Tadeáš\AppData\Roaming\.#
C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.lnk
C:\Windows\setup_9.0.0.722_24.10.2010_13-20drv.spi
C:\Program Files (x86)\Ask.com
C:\Program Files (x86)\Bing Bar Installer
C:\Users\Public\
 C:\Program Files (x86)\DAEMON Tools Toolbar\

:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]

-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Tadeas.skuhra
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 25 Črv 2008 15:10

Re: samovolne spuštění Windows Live Messenger

#23 Příspěvek od Tadeas.skuhra »

ano, ty složky poznávám..


All processes killed
========== OTL ==========
No active process named explorer.exe was found!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\grooveLocalGWS\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88FED34C-F0CA-4636-A375-3CB6248B04CD}\ not found.
File {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found.
File {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{314111c7-a502-11d2-bbca-00c04f8ec294}\ not found.
File {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found.
File {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03C514A3-1EFB-4856-9F99-10D7BE1653C0}\ not found.
File {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324}\ not found.
File {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found not found.
Starting removal of ActiveX control {C345E174-3E87-4F41-A01C-B066A90A49B4}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C345E174-3E87-4F41-A01C-B066A90A49B4}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C345E174-3E87-4F41-A01C-B066A90A49B4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C345E174-3E87-4F41-A01C-B066A90A49B4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C345E174-3E87-4F41-A01C-B066A90A49B4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C345E174-3E87-4F41-A01C-B066A90A49B4}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NVIDIA driver monitor deleted successfully.
C:\Users\Public\nvsvc32.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
64bit-Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll moved successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
C:\Users\Tadeáš\AppData\Roaming\.# folder moved successfully.
C:\Users\Tadeáš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_setup_9.0.0.722_24.10.2010_13-20.exe.lnk moved successfully.
C:\Windows\setup_9.0.0.722_24.10.2010_13-20drv.spi moved successfully.
C:\Program Files (x86)\Ask.com folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer\OFFLINE\JS folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer\OFFLINE\Images folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer\OFFLINE\CSS folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer\OFFLINE folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer\BootStrapper folder moved successfully.
C:\Program Files (x86)\Bing Bar Installer folder moved successfully.
C:\Users\Public\Videos\Sample Videos folder moved successfully.
C:\Users\Public\Videos folder moved successfully.
C:\Users\Public\Recorded TV\Sample Media folder moved successfully.
C:\Users\Public\Recorded TV folder moved successfully.
C:\Users\Public\Pictures\Sample Pictures folder moved successfully.
C:\Users\Public\Pictures folder moved successfully.
C:\Users\Public\Music\Seznamy stop folder moved successfully.
C:\Users\Public\Music\Sample Music folder moved successfully.
C:\Users\Public\Music\Neznámý interpret\Neznámé album (24.6.2010 20-51-04) folder moved successfully.
C:\Users\Public\Music\Neznámý interpret folder moved successfully.
C:\Users\Public\Music\1967 - The Piper At The Gates Of Dawn folder moved successfully.
C:\Users\Public\Music\1966 - Tonite Let's All Make Love in London folder moved successfully.
C:\Users\Public\Music folder moved successfully.
C:\Users\Public\Libraries folder moved successfully.
C:\Users\Public\Favorites folder moved successfully.
C:\Users\Public\Downloads folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO-P103 - geografie obyvatelstva a sídel\Nová složka folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO-P103 - geografie obyvatelstva a sídel folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO- P110 - základy fyzické geografie folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - P111 - vývoj geografického myšlení folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - P107 - Geografie ČR folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_9\topo_25 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_9\info folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_9 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_8 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_7\AirBaseXML folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_7 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_5 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_4\gdb.gdb folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_4 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_3 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_10\topo_25 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_10\info folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\seminar_10 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\Obrazy folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\styly folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\system folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K9 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K6 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K5 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K4 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K2 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\K1 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\G4 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\G3 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images\G2 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\images folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie\download folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky\kartografie folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Přednášky folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Obrázky folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\klady folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\Dokumenty folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\BLAHA folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS\6 folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I\GIS folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 105 - GIS I folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 104 - Kvantitativní metody folder moved successfully.
C:\Users\Public\Documents\UJEP\KGEO - 311 - regionální geografie světa A folder moved successfully.
C:\Users\Public\Documents\UJEP folder moved successfully.
C:\Users\Public\Documents\Stardock\WindowBlinds\Vista Images folder moved successfully.
C:\Users\Public\Documents\Stardock\WindowBlinds\Think Green folder moved successfully.
C:\Users\Public\Documents\Stardock\WindowBlinds folder moved successfully.
C:\Users\Public\Documents\Stardock\ThemeManager folder moved successfully.
C:\Users\Public\Documents\Stardock\IconPackager\Think Green folder moved successfully.
C:\Users\Public\Documents\Stardock\IconPackager folder moved successfully.
C:\Users\Public\Documents\Stardock folder moved successfully.
C:\Users\Public\Documents\obraz folder moved successfully.
C:\Users\Public\Documents\My Videos folder moved successfully.
C:\Users\Public\Documents\My Pictures folder moved successfully.
C:\Users\Public\Documents\My Music folder moved successfully.
C:\Users\Public\Documents\microsoft\IdentityCRL\production folder moved successfully.
C:\Users\Public\Documents\microsoft\IdentityCRL folder moved successfully.
C:\Users\Public\Documents\microsoft folder moved successfully.
C:\Users\Public\Documents\DAEMON Tools Images folder moved successfully.
C:\Users\Public\Documents\ASSASSINS CREED folder moved successfully.
C:\Users\Public\Documents folder moved successfully.
C:\Users\Public\Desktop folder moved successfully.
Folder move failed. C:\Users\Public scheduled to be moved on reboot.
C:\Program Files (x86)\DAEMON Tools Toolbar\Resources folder moved successfully.
C:\Program Files (x86)\DAEMON Tools Toolbar folder moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Tadeáš
->Temp folder emptied: 2039914 bytes
->Temporary Internet Files folder emptied: 6902395 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 447347933 bytes
->Flash cache emptied: 2985 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 462690 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 210480 bytes
RecycleBin emptied: 4380716 bytes

Total Files Cleaned = 440,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: Tadeáš
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.16.0 log created on 10282010_143732

Files\Folders moved on Reboot...
C:\Users\Public\Videos folder moved successfully.
C:\Users\Public\Pictures folder moved successfully.
C:\Users\Public\Music folder moved successfully.
C:\Users\Public\Documents folder moved successfully.
Folder move failed. C:\Users\Public scheduled to be moved on reboot.
C:\Users\Tadeáš\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Windows\temp\mcafee_ywKO928GMy6LTZD not found!
File\Folder C:\Windows\temp\mcmsc_gxH38e64juB1kEt not found!
File\Folder C:\Windows\temp\mcmsc_lcnRNPlj2gL8rKm not found!
File\Folder C:\Windows\temp\mcmsc_ZyoPLc9PLC63ATA not found!
File\Folder C:\Windows\temp\sqlite_Qi0uf8skyd7WVVh not found!
File\Folder C:\Windows\temp\sqlite_RUSjgwq9qbuB8PU not found!
File\Folder C:\Windows\temp\sqlite_u3iOt1PfGcJb12q not found!
File\Folder C:\Windows\temp\sqlite_X0jqCmPMhcOSmdu not found!

Registry entries deleted on Reboot...

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: samovolne spuštění Windows Live Messenger

#24 Příspěvek od motji »

Co počítač?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět