Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Zamrzne PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
roskild
Návštěvník
Návštěvník
Příspěvky: 299
Registrován: 05 říj 2008 08:57

Re: Zamrzne PC

#16 Příspěvek od roskild »

Mám jeden log na ploche,tu je:

OTL logfile created on: 13. 12. 2010 9:54:37 - Run 3
OTL by OldTimer - Version 3.2.17.3 Folder = D:\D_DOKUMENTY\Data\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000041B | Country: Slovensko | Language: SKY | Date Format: d. M. yyyy

1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 64,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 86,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 20,02 Gb Total Space | 7,64 Gb Free Space | 38,16% Space Free | Partition Type: NTFS
Drive D: | 209,14 Gb Total Space | 8,33 Gb Free Space | 3,99% Space Free | Partition Type: NTFS

Computer Name: PC | User Name: KC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/12/13 09:43:39 | 000,575,488 | ---- | M] (OldTimer Tools) -- D:\D_DOKUMENTY\Data\Desktop\OTL.exe
PRC - [2010/10/29 08:42:40 | 001,221,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2010/10/08 13:00:10 | 000,836,464 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2010/08/02 11:52:03 | 000,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/05/07 21:16:31 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2010/02/26 05:41:12 | 000,810,120 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2010/02/26 05:40:58 | 002,140,880 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2004/10/14 09:11:10 | 001,388,544 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
PRC - [2004/09/23 12:41:54 | 000,860,160 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
PRC - [2002/09/20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


========== Modules (SafeList) ==========

MOD - [2010/12/13 09:43:39 | 000,575,488 | ---- | M] (OldTimer Tools) -- D:\D_DOKUMENTY\Data\Desktop\OTL.exe
MOD - [2010/08/23 17:12:33 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/02/26 05:42:34 | 000,033,560 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010/02/26 05:41:12 | 000,810,120 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2009/06/02 09:10:08 | 000,637,952 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2006/12/19 16:53:46 | 000,024,072 | ---- | M] (TuneUp Software GmbH) [Auto | Stopped] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2002/09/20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))


========== Driver Services (SafeList) ==========

DRV - [2010/11/20 17:29:46 | 000,138,184 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PnkBstrK.sys -- (PnkBstrK)
DRV - [2010/08/18 10:14:11 | 000,015,488 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpcsys.SYS -- (MPCSYS)
DRV - [2010/07/29 16:00:59 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2010/05/10 19:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/05/07 06:55:42 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010/04/03 21:55:32 | 010,232,128 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2010/02/26 05:41:36 | 000,095,872 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2010/02/26 05:41:06 | 000,114,984 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010/02/26 05:39:24 | 000,139,192 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2010/02/17 19:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/02/09 07:37:56 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2009/02/09 07:37:48 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009/02/09 07:37:46 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009/02/09 07:37:46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008/08/26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/04/13 23:23:10 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008/04/13 23:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) Ovladač zvukové karty USB (WDM)
DRV - [2005/10/27 14:06:30 | 000,356,096 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt61.sys -- (RT61)
DRV - [2005/03/04 04:10:26 | 000,074,496 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)
DRV - [2005/03/01 05:01:00 | 000,392,704 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
DRV - [2004/09/13 17:00:00 | 000,088,960 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MidiSyn.sys -- (MidiSyn)
DRV - [2004/08/03 23:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2003/08/28 08:14:30 | 000,181,574 | R--- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CX88Vid.SYS -- (CX23880)
DRV - [2003/08/21 08:35:54 | 000,095,804 | R--- | M] (Conexant Systems, Inc.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\CX88Tune.SYS -- (CXTUNE)
DRV - [2003/03/19 06:50:06 | 000,009,159 | R--- | M] (Conexant Systems, Inc.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\CX88XBar.SYS -- (CX88XBAR)
DRV - [2002/11/22 03:12:20 | 000,010,334 | R--- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\cx88aud.sys -- (CX88AUD)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-484763869-436374069-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-484763869-436374069-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.zoznam.sk/
IE - HKU\S-1-5-21-484763869-436374069-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-484763869-436374069-725345543-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-484763869-436374069-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-484763869-436374069-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = socks=

FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/06/01 18:55:34 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2010/08/02 11:52:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/02 19:57:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/20 08:31:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/05/18 18:49:00 | 000,000,000 | ---D | M]

[2010/05/09 12:42:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Mozilla\Extensions
[2010/05/09 12:42:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\KC\Data aplikací\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/11/25 17:31:41 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/06 21:09:22 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/07/12 17:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2010/10/18 15:13:45 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010/10/18 15:13:45 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010/10/18 15:13:45 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010/10/18 15:13:45 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010/10/18 15:13:45 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010/10/18 15:13:45 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml

O1 HOSTS File: ([2010/11/22 20:06:28 | 000,000,736 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (WebTranslator) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Program Files\PC Translator\webie.dll ()
O3 - HKU\S-1-5-21-484763869-436374069-725345543-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SoundMax] C:\Program Files\Analog Devices\SoundMAX\SMax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-484763869-436374069-725345543-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-484763869-436374069-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-484763869-436374069-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-484763869-436374069-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-484763869-436374069-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: WikiKomentáře Google... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Program Files\PC Translator\webie.dll ()
O9 - Extra 'Tools' menuitem : &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Program Files\PC Translator\webie.dll ()
O9 - Extra 'Tools' menuitem : Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Program Files\PC Translator\webie.dll ()
O9 - Extra 'Tools' menuitem : Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Program Files\PC Translator\webie.dll ()
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windows ... 3561583687 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/Shar ... /cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microso ... 7118629984 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.100.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\KC\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\KC\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/03 13:40:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.ffds - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2010/12/13 09:43:29 | 000,575,488 | ---- | C] (OldTimer Tools) -- D:\D_DOKUMENTY\Data\Desktop\OTL.exe
[2010/12/12 12:25:32 | 085,378,728 | ---- | C] ( ) -- D:\D_DOKUMENTY\Dokumenty\setup_9.0.0.722_12.12.2010_12-24.exe
[2010/12/12 12:24:45 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\KC\Recent
[2010/12/10 20:32:43 | 000,000,000 | ---D | C] -- D:\D_DOKUMENTY\Dokumenty\FLV
[2010/12/01 08:07:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\KC\Data aplikací\vlc
[2010/11/28 15:14:53 | 000,000,000 | ---D | C] -- C:\Program Files\Lavalys
[2010/11/28 15:14:09 | 000,000,000 | ---D | C] -- C:\Program Files\HD Tune
[2010/11/22 19:59:05 | 000,428,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\REGEDIT.COM
[2010/11/22 19:59:05 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\TASKMGR.COM
[2010/11/22 19:06:59 | 000,000,000 | ---D | C] -- D:\D_DOKUMENTY\Dokumenty\vds
[2010/11/21 09:30:19 | 000,000,000 | ---D | C] -- C:\Program Files\CleanUp!
[2010/11/20 22:43:48 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/11/20 17:27:48 | 000,000,000 | ---D | C] -- D:\D_DOKUMENTY\Dokumenty\u
[2010/11/20 16:30:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\KC\Data aplikací\Driver Smith
[2010/11/20 08:57:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010/11/13 14:22:09 | 000,000,000 | ---D | C] -- D:\D_DOKUMENTY\Dokumenty\Wondershare YouTube Downloader
[2010/11/13 14:21:34 | 000,000,000 | ---D | C] -- C:\Program Files\Wondershare
[2010/07/23 08:41:13 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\KC\Data aplikací\pcouffin.sys
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/13 09:43:39 | 000,575,488 | ---- | M] (OldTimer Tools) -- D:\D_DOKUMENTY\Data\Desktop\OTL.exe
[2010/12/13 09:43:00 | 000,000,992 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/13 08:37:20 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/12/13 08:36:38 | 000,276,202 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010/12/13 08:36:30 | 000,000,988 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/13 08:36:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/12/12 18:58:37 | 000,125,952 | ---- | M] () -- C:\Documents and Settings\KC\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/12 18:39:42 | 001,221,078 | ---- | M] () -- D:\D_DOKUMENTY\Dokumenty\na.bmp
[2010/12/12 18:38:42 | 000,172,658 | ---- | M] () -- D:\D_DOKUMENTY\Dokumenty\0005797587.jpg
[2010/12/12 12:50:19 | 085,378,728 | ---- | M] ( ) -- D:\D_DOKUMENTY\Dokumenty\setup_9.0.0.722_12.12.2010_12-24.exe
[2010/12/10 20:30:27 | 000,000,202 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/12/10 19:41:27 | 004,115,651 | ---- | M] () -- D:\D_DOKUMENTY\Dokumenty\first.flv
[2010/12/10 19:05:31 | 000,000,000 | ---- | M] () -- C:\23990098.$$$
[2010/12/10 19:02:28 | 000,000,054 | ---- | M] () -- C:\WINDOWS\Lic.xxx
[2010/12/10 18:22:25 | 000,000,384 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/12/08 09:11:45 | 005,794,828 | ---- | M] () -- D:\D_DOKUMENTY\Dokumenty\ChemicalFactoryDigitalDNBroskild.mp3
[2010/12/05 12:09:00 | 007,285,902 | ---- | M] () -- C:\WINDOWS\REGBK16.ZIP
[2010/12/01 09:22:14 | 000,014,180 | ---- | M] () -- D:\D_DOKUMENTY\Dokumenty\Dok1.docx
[2010/12/01 09:21:54 | 000,002,443 | ---- | M] () -- D:\D_DOKUMENTY\Data\Desktop\Microsoft Office Word 2007.lnk
[2010/12/01 08:02:26 | 019,985,265 | ---- | M] () -- D:\D_DOKUMENTY\Data\Desktop\VLC.exe
[2010/11/28 15:14:56 | 000,000,657 | ---- | M] () -- D:\D_DOKUMENTY\Data\Desktop\EVEREST Ultimate Edition.lnk
[2010/11/28 15:14:09 | 000,000,535 | ---- | M] () -- D:\D_DOKUMENTY\Data\Desktop\HD Tune.lnk
[2010/11/22 20:06:28 | 000,000,736 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/11/22 20:06:22 | 007,286,153 | ---- | M] () -- C:\WINDOWS\REGBK15.ZIP
[2010/11/20 18:27:22 | 000,425,140 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.22440361
[2010/11/20 17:29:46 | 000,138,184 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/11/20 17:28:44 | 000,000,184 | ---- | M] () -- D:\D_DOKUMENTY\Data\Desktop\Koš.lnk
[2010/11/20 08:52:19 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101120-182722.backup
[2010/11/20 08:31:03 | 000,001,735 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Adobe Reader 9.lnk
[2010/11/19 10:02:53 | 003,911,589 | R--- | M] () -- D:\D_DOKUMENTY\Data\Desktop\ComboFix.exe
[2010/11/13 14:21:42 | 000,000,843 | ---- | M] () -- D:\D_DOKUMENTY\Data\Desktop\Wondershare YouTube Downloader.lnk
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/12 18:39:42 | 001,221,078 | ---- | C] () -- D:\D_DOKUMENTY\Dokumenty\na.bmp
[2010/12/12 18:38:42 | 000,172,658 | ---- | C] () -- D:\D_DOKUMENTY\Dokumenty\0005797587.jpg
[2010/12/10 19:41:26 | 004,115,651 | ---- | C] () -- D:\D_DOKUMENTY\Dokumenty\first.flv
[2010/12/08 09:11:16 | 005,794,828 | ---- | C] () -- D:\D_DOKUMENTY\Dokumenty\ChemicalFactoryDigitalDNBroskild.mp3
[2010/12/05 12:07:54 | 007,285,902 | ---- | C] () -- C:\WINDOWS\REGBK16.ZIP
[2010/12/01 09:22:14 | 000,014,180 | ---- | C] () -- D:\D_DOKUMENTY\Dokumenty\Dok1.docx
[2010/12/01 07:59:29 | 019,985,265 | ---- | C] () -- D:\D_DOKUMENTY\Data\Desktop\VLC.exe
[2010/11/28 15:14:56 | 000,000,657 | ---- | C] () -- D:\D_DOKUMENTY\Data\Desktop\EVEREST Ultimate Edition.lnk
[2010/11/28 15:14:09 | 000,000,535 | ---- | C] () -- D:\D_DOKUMENTY\Data\Desktop\HD Tune.lnk
[2010/11/22 20:04:47 | 007,286,153 | ---- | C] () -- C:\WINDOWS\REGBK15.ZIP
[2010/11/19 10:02:30 | 003,911,589 | R--- | C] () -- D:\D_DOKUMENTY\Data\Desktop\ComboFix.exe
[2010/11/13 14:21:42 | 000,000,843 | ---- | C] () -- D:\D_DOKUMENTY\Data\Desktop\Wondershare YouTube Downloader.lnk
[2010/10/29 08:43:14 | 000,000,134 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2010/10/16 23:49:18 | 000,138,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/10/15 09:41:02 | 000,000,036 | ---- | C] () -- C:\WINDOWS\mafosav.INI
[2010/10/03 22:42:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\pestpatrol5.INI
[2010/09/10 15:30:01 | 000,000,655 | ---- | C] () -- C:\WINDOWS\webtran4.INI
[2010/08/18 10:06:26 | 000,015,488 | ---- | C] () -- C:\WINDOWS\System32\drivers\mpcsys.SYS
[2010/08/12 15:42:32 | 000,000,122 | ---- | C] () -- C:\Documents and Settings\KC\Local Settings\Data aplikací\fusioncache.dat
[2010/07/23 08:41:21 | 000,000,033 | ---- | C] () -- C:\Documents and Settings\KC\Data aplikací\pcouffin.log
[2010/07/23 08:41:13 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\KC\Data aplikací\inst.exe
[2010/07/23 08:41:13 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\KC\Data aplikací\pcouffin.cat
[2010/07/23 08:41:13 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\KC\Data aplikací\pcouffin.inf
[2010/07/01 19:09:51 | 000,002,913 | ---- | C] () -- C:\WINDOWS\wdict32.INI
[2010/05/16 17:18:52 | 000,003,728 | ---- | C] () -- C:\WINDOWS\wtran32.INI
[2010/05/16 16:18:29 | 000,002,313 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2010/05/15 20:22:51 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2010/05/07 12:24:45 | 000,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010/05/07 08:33:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\msicpl.ini
[2010/05/07 06:55:42 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2010/05/06 21:45:42 | 000,125,952 | ---- | C] () -- C:\Documents and Settings\KC\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 00:21:54 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/05/26 21:22:14 | 000,015,552 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008/05/26 21:22:10 | 000,021,464 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008/05/26 21:22:04 | 000,014,910 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2006/07/27 18:28:42 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/10/14 11:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005/10/14 11:56:50 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005/10/14 11:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005/10/14 11:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005/10/14 11:56:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005/10/14 11:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005/10/14 11:56:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2005/01/03 16:56:31 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2005/01/03 15:46:37 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\Install6x.dll
[2005/01/03 15:38:48 | 000,131,072 | R--- | C] () -- C:\WINDOWS\System32\smdll.dll
[2005/01/03 15:38:44 | 000,032,768 | R--- | C] () -- C:\WINDOWS\System32\Auxiliary.dll
[2005/01/03 14:31:08 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

========== LOP Check ==========

[2010/05/18 18:45:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2010/07/18 09:50:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ashampoo
[2010/10/03 22:32:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\CA
[2010/05/07 06:54:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010/05/18 18:48:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010/05/06 21:27:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2010/06/01 18:54:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Installations
[2010/05/19 08:29:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2010/06/01 18:55:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2010/06/22 15:47:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Rapidshare Search Tool
[2010/11/20 08:42:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010/05/06 14:09:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2010/07/23 10:43:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\vsosdk
[2010/05/07 06:52:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\AnvSoft
[2010/08/25 17:47:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Ashampoo
[2010/05/07 07:27:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\DAEMON Tools Lite
[2010/11/20 16:30:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Driver Smith
[2010/10/14 09:49:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\fltk.org
[2005/01/03 15:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\GHISLER
[2010/05/27 17:35:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Hide IP NG
[2010/11/14 17:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\ICQ
[2010/10/16 23:44:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Leadertech
[2010/10/19 19:44:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\LG Electronics
[2010/06/01 18:55:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Nokia
[2010/05/11 13:43:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Opera
[2010/06/01 18:56:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\PC Suite
[2005/01/03 16:59:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Thunderbird
[2005/01/03 16:16:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\TuneUp Software
[2010/11/13 15:47:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\uTorrent
[2010/08/02 11:42:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Vso
[2010/06/05 06:18:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Windows Desktop Search
[2010/06/05 10:13:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Windows Search
[2005/01/03 16:53:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Zoner
[2010/12/10 18:22:25 | 000,000,384 | ---- | M] () -- C:\WINDOWS\Tasks\1-Click Maintenance.job

========== Purity Check ==========



========== Custom Scans ==========


< Kód: >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2010/10/29 08:41:59 | 000,030,208 | ---- | M] (Microsoft Corporation)
"swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -- [2010/05/07 21:16:31 | 000,039,408 | ---- | M] (Google Inc.)

< c:\windows\*.* /U >
[1 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2010/05/08 16:21:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Adobe
[2010/05/07 06:52:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\AnvSoft
[2010/08/25 17:47:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Ashampoo
[2010/05/25 16:58:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\CyberLink
[2010/05/07 07:27:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\DAEMON Tools Lite
[2010/05/06 21:45:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\DivX
[2010/11/20 16:30:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Driver Smith
[2010/08/08 07:59:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\dvdcss
[2010/07/26 20:45:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\FastStone
[2010/10/14 09:49:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\fltk.org
[2005/01/03 15:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\GHISLER
[2005/01/03 17:02:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Google
[2010/08/19 13:32:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Help
[2010/05/27 17:35:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Hide IP NG
[2010/05/06 15:04:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\HP
[2010/11/14 17:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\ICQ
[2005/01/03 13:45:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Identities
[2010/10/19 19:40:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\InstallShield
[2010/05/19 06:11:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Lavasoft
[2010/10/16 23:44:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Leadertech
[2010/10/19 19:44:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\LG Electronics
[2010/05/06 17:27:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Macromedia
[2010/10/28 08:36:29 | 000,000,000 | --SD | M] -- C:\Documents and Settings\KC\Data aplikací\Microsoft
[2005/01/03 16:49:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Mozilla
[2010/06/01 18:55:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Nokia
[2010/05/11 13:43:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Opera
[2010/06/01 18:56:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\PC Suite
[2010/08/02 12:06:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Real
[2010/10/30 00:02:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Skype
[2010/10/30 00:01:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\skypePM
[2010/08/12 12:00:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\SUPERAntiSpyware.com
[2005/01/03 16:59:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Thunderbird
[2005/01/03 16:16:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\TuneUp Software
[2010/11/13 15:47:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\uTorrent
[2010/12/01 17:15:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\vlc
[2010/08/02 11:42:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Vso
[2010/09/23 06:37:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Winamp
[2010/06/05 06:18:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Windows Desktop Search
[2010/06/05 10:13:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Windows Search
[2010/10/29 08:43:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\WinRAR
[2005/01/03 16:53:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KC\Data aplikací\Zoner

< %APPDATA%\*.exe /s >
[2010/08/02 11:42:38 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\KC\Data aplikací\inst.exe
[2010/08/06 15:51:30 | 000,388,096 | R--- | M] (Trend Micro Inc.) -- C:\Documents and Settings\KC\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
[2010/09/19 06:11:31 | 000,452,104 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\KC\Data aplikací\Real\Update\setup3.12\setup.exe
[2010/12/13 09:07:46 | 000,506,024 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\KC\Data aplikací\Real\Update\setup3.13\setup.exe


< MD5 for: AGP440.SYS >
[2007/11/29 15:05:20 | 016,772,785 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2007/11/29 15:05:20 | 016,772,785 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys

< MD5 for: CDROM.SYS >
[2007/11/29 15:05:20 | 016,772,785 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008/04/13 23:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008/04/13 23:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2004/08/03 21:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2004/08/17 14:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008/04/14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008/04/14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008/04/14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2008/04/14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2004/08/17 14:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008/04/14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\Program Files\Anolis\Installer\Backup xpize-2010-10-29 09-41\explorer.exe
[2008/04/14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/11/29 14:54:05 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=9B32416BD5988C97B6397CE0B02CAF97 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2010/10/29 08:42:40 | 001,221,120 | ---- | M] (Microsoft Corporation) MD5=C6004861F5FA2E1A2783EF0AC37AB289 -- C:\WINDOWS\explorer.exe

< MD5 for: HAL.DLL >
[2007/11/29 15:05:20 | 016,772,785 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008/04/13 23:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008/04/13 23:01:30 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL
[2004/08/03 21:59:10 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll

< MD5 for: CHANGER.SYS >
[2007/11/29 15:05:20 | 016,772,785 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008/04/13 23:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys

< MD5 for: ISAPNP.SYS >
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008/04/14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2001/10/24 11:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2001/10/25 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\isapnp.sys
[2008/04/14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008/04/14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys

< MD5 for: LSASS.EXE >
[2004/08/17 14:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008/04/14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2008/04/14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008/04/14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008/04/13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008/04/13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008/04/13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2004/08/03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

< MD5 for: NETLOGON.DLL >
[2004/08/17 14:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008/04/14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/17 14:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SMSS.EXE >
[2004/08/17 14:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2008/04/14 07:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008/04/14 07:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe

< MD5 for: SVCHOST.EXE >
[2008/04/14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008/04/14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004/08/17 14:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: TCPIP.SYS >
[2008/04/13 23:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008/04/13 23:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008/06/20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008/06/20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008/06/20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008/06/20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2007/11/29 14:47:37 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008/04/14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004/08/17 14:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/17 14:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2004/08/17 14:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008/04/14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008/04/14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008/04/14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010/05/07 06:55:42 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2005/01/03 14:28:57 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2005/01/03 14:28:57 | 000,663,552 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2005/01/03 14:28:57 | 000,475,136 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2010/12/13 08:36:38 | 000,276,202 | ---- | M] () -- C:\WINDOWS\system32\NvApps.xml
[2010/12/13 08:37:20 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

========== Alternate Data Streams ==========

@Alternate Data Stream - 269 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:CB0AACC9
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8

< End of report >

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Zamrzne PC

#17 Příspěvek od motji »

Otestujte na www.virustotal.com
C:\WINDOWS\System32\drivers\mpcsys.SYS
-Na virustotalu dáte procházet, a do spodního okénka nakopírujete přímo cestu k souboru a dáte odeslat
-z prohlížeče zkopírujete adresu ke stránce s výsledky
-pokud se Vás zeptá, dejte soubor otestovat znovu, tak aby to byl soubor z Vašeho počítače
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

roskild
Návštěvník
Návštěvník
Příspěvky: 299
Registrován: 05 říj 2008 08:57

Re: Zamrzne PC

#18 Příspěvek od roskild »


Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Zamrzne PC

#19 Příspěvek od motji »

Nefunguje mi to, nezobrazí se mi výsledek :(
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

roskild
Návštěvník
Návštěvník
Příspěvky: 299
Registrován: 05 říj 2008 08:57

Re: Zamrzne PC

#20 Příspěvek od roskild »

motji píše:Nefunguje mi to, nezobrazí se mi výsledek :(
Teraz som klikol na link a funguje,zobrazilo výsledky :o

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Zamrzne PC

#21 Příspěvek od motji »

Teď už taky :D


:arrow: Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
@Alternate Data Stream - 269 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:CB0AACC9
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8
IE - HKU\S-1-5-21-484763869-436374069-725345543-1003\..\URLSearchHook: - Reg Error: Key error. File not found

:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s

:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]
[Reboot]

-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

roskild
Návštěvník
Návštěvník
Příspěvky: 299
Registrován: 05 říj 2008 08:57

Re: Zamrzne PC

#22 Příspěvek od roskild »

Vykonané :) . . . tu je log:

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2 deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:CB0AACC9 deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8 deleted successfully.
Registry value HKEY_USERS\S-1-5-21-484763869-436374069-725345543-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
C:\WINDOWS\system32\SET22A9.tmp moved successfully.
C:\WINDOWS\msdownld.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1FCF.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP20A1.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2187.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP228F.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP22F4.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2402.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2462.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP24E4.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2509.tmp folder moved successfully.
C:\WINDOWS\CSC\csc1.tmp moved successfully.
C:\WINDOWS\Installer\MSI2D2.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users
-> No Temporary Internet Files cache folder defined!

User: Default User
->Temp folder emptied: 0 bytes
-> No Temporary Internet Files cache folder defined!

User: KC
->Temp folder emptied: 4977534 bytes
-> No Temporary Internet Files cache folder defined!
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 6136251 bytes
->Opera cache emptied: 585131 bytes
->Flash cache emptied: 88299 bytes

User: LocalService
->Temp folder emptied: 0 bytes
-> No Temporary Internet Files cache folder defined!

User: NetworkService
->Temp folder emptied: 0 bytes
-> No Temporary Internet Files cache folder defined!

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 66679 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 9252832 bytes

Total Files Cleaned = 20,00 mb


[EMPTYFLASH]

User: All Users

User: Default User

User: KC
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.17.3 log created on 12152010_133156

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Ale ďalšia vec sa stala,pred chvíľkou sa mi zobrazila modrá obrazovka,popísané niečo a reštart.Ten problém sme minule úspešne odstránili a už je to asi znova tu :?:

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Zamrzne PC

#23 Příspěvek od motji »

Ve složce C:\WINDOWS\minidump se nám vytvořil soubor? Pokud ano, dejte ho do raru a vložte zde jako přílohu.
Bsod nastala při čem?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

roskild
Návštěvník
Návštěvník
Příspěvky: 299
Registrován: 05 říj 2008 08:57

Re: Zamrzne PC

#24 Příspěvek od roskild »

tu je súbor:http://www.upnito.sk/subor/6616990a5036 ... bcd5b.html

Mal som spustenú Operu,Winamp a Any Video Converter,zrazu reštart . . . no ale zatial nič,teraz všetko šlape tak neviem :o

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Zamrzne PC

#25 Příspěvek od motji »

Zkuste přeinstalovat Eset
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

roskild
Návštěvník
Návštěvník
Příspěvky: 299
Registrován: 05 říj 2008 08:57

Re: Zamrzne PC

#26 Příspěvek od roskild »

motji píše:Zkuste přeinstalovat Eset
OK :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Zamrzne PC

#27 Příspěvek od motji »

A pak dejte vědět, kdyby se BSOD zase objevila. Z minidumpu jsem vyčetla, že pád mohl způsobit právě ovladač od Esetu. Ale nedokážu říct, proč. Bud je vada přímo na něj, nebo máte v pc stále nějaké malware a mohlo to být v konfliktu s ním. Ale protože jsme počítač čistili, přikláním se spíše k možnosti, že si driver s něčím nesedl :D
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

roskild
Návštěvník
Návštěvník
Příspěvky: 299
Registrován: 05 říj 2008 08:57

Re: Zamrzne PC

#28 Příspěvek od roskild »

Neviem či som spravil dobre,odinštaloval som Eset,nainštaloval Avast,dal som cez Avast skontrolovat pC,všetko OK.Potom som dal reštart a odvtedy mi ide PC len v nudzovom režime.Nenačíta Windows,blikne modra obrazovka,niečo vypíše a reštart . . . ach jaj :?:

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Zamrzne PC

#29 Příspěvek od motji »

:o nefunguje Vám ani poslední známá funkční konfigurace nebo nouzový režim?
Avast nic nemazal?

Můžete tu Bsod nafotit, co se tam píše?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15694
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Zamrzne PC

#30 Příspěvek od JaRon »

len doplnim kolegynu:
ak ide nudzovy rezim treba tam odinstalovat AVAST
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět