OTL Extras logfile created on: 10.2.2011 14:07:14 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\vf\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
511,00 Mb Total Physical Memory | 266,00 Mb Available Physical Memory | 52,00% Memory free
982,00 Mb Paging File | 719,00 Mb Available in Paging File | 73,00% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55,88 Gb Total Space | 13,58 Gb Free Space | 24,29% Space Free | Partition Type: FAT32
Drive E: | 74,53 Gb Total Space | 13,94 Gb Free Space | 18,70% Space Free | Partition Type: NTFS
Computer Name: VIT | User Name: vf | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] -- C:\Program Files\Opera\opera.exe (Opera Software)
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_USERS\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software)
https [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software)
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\IncrediMail\bin\ImApp.exe" = C:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail -- (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\bin\IncMail.exe" = C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail -- (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\bin\ImpCnt.exe" = C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail -- (IncrediMail, Ltd.)
"C:\WINDOWS\System32\usmt\migwiz.exe" = C:\WINDOWS\System32\usmt\migwiz.exe:*:Enabled:Průvodce přenesením souborů a nastavení -- (Microsoft Corporation)
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe" = C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Disabled:CoD2MP_s -- ()
"C:\WINDOWS\System32\mmc.exe" = C:\WINDOWS\System32\mmc.exe:*:Enabled:Konzola Microsoft Management Console -- (Microsoft Corporation)
"C:\WINDOWS\System32\dpvsetup.exe" = C:\WINDOWS\System32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{076A6FD8-EE45-4A83-B3C9-C7C34E7CAFDD}" = Lineage II
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21040472-F8DF-48A9-A093-2986C1495670}" = Lineage® II: The Chaotic Throne - Freya
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7339E7E7-FB6A-46EC-8303-D31E655EF617}" = Toddler Keys
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D972536-8F2A-4B02-B3B3-5D19A57420C6}_is1" = DustBuster Standard Edition
"{A20A58C4-6784-4B4B-86CC-94E2E3671029}" = Nero 7 Ultra Edition
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1029-7B44-A91000000001}" = Adobe Reader 9.1 - Czech
"{ADE3CACC-EC31-480C-83A0-587EE60CE8DF}" = RamBooster
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B80CC46C-5839-4A48-B051-3CACF23A2718}_is1" = Eraser 5.82
"{C72D7008-266D-4DD8-BF3C-296B736127F6}" = Mafia
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"{E1BBBAC5-2857-4155-82A6-54492CE88620}" = Opera 9.64
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F94C1BE0-1B72-4077-9F84-51256BB3ABCB}" = AceReader Pro
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AvantBrowser" = Avant Browser (remove only)
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CCleaner" = CCleaner (remove only)
"CDCheck" = CDCheck
"CoD 2 čeština_is1" = CoD 2 čeština 1.1
"conduitEngine" = Conduit Engine
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"Game Booster_is1" = Game Booster
"HijackThis" = HijackThis 2.0.2
"IncrediMail" = IncrediMail
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"IsoBuster Toolbar" = IsoBuster Toolbar
"IsoBuster_is1" = IsoBuster 2.8
"LegWinTym 1.26 Free (22.2.2008)" = LegWinTym 1.26 Free (22.2.2008)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McDonald's Dragons " = McDonald's Dragons
"NeoPaint for Windows" = NeoPaint for Windows
"NSS" = Norton Security Scan
"Pohadka" = Pohádka o Mrazíkovi, Ivanovi a Nastěnce
"PowerISO" = PowerISO
"RadarSync2 Toolbar" = RadarSync2 Toolbar
"RegCure" = RegCure 1.5.1.3
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"The KMPlayer" = The KMPlayer (remove only)
"Totalcmd" = Total Commander (Remove or Repair)
"Unknown Device Identifier_is1" = Unknown Device Identifier 6.01
"VLC media player" = VideoLAN VLC media player 0.8.6i
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinRAR archiver" = WinRAR
"YouTube Downloader_is1" = YouTube Downloader 2.5
"Ziacik v2.7" = Ziacik v2.7
"Zkušební testy elektro DEMOVERZE 4.0_is1" = Zkušební testy elektro DEMOVERZE 4.0
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Memorium Easy Installer - Freya Rev 4" = Memorium Easy Installer - Freya Rev 4
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9.4.2010 7:34:52 | Computer Name = VIT | Source = Application Error | ID = 1000
Description = Chybující aplikace l2.exe, verze 0.0.0.0, chybující modul defopenal32.dll,
verze 0.9.5.1, adresa chyby 0x00007a74.
Error - 9.4.2010 16:25:58 | Computer Name = VIT | Source = Application Error | ID = 1000
Description = Chybující aplikace totalcmd.exe, verze 7.0.1.0, chybující modul divxdec.ax,
verze 7.0.0.31, adresa chyby 0x00069ba9.
Error - 10.4.2010 6:21:24 | Computer Name = VIT | Source = Application Error | ID = 1000
Description = Chybující aplikace l2.exe, verze 0.0.0.0, chybující modul defopenal32.dll,
verze 0.9.5.1, adresa chyby 0x00007a74.
Error - 10.4.2010 13:08:40 | Computer Name = VIT | Source = Application Error | ID = 1000
Description = Chybující aplikace l2.exe, verze 0.0.0.0, chybující modul defopenal32.dll,
verze 0.9.5.1, adresa chyby 0x00007a74.
Error - 11.4.2010 12:18:41 | Computer Name = VIT | Source = Application Error | ID = 1000
Description = Chybující aplikace l2.exe, verze 0.0.0.0, chybující modul defopenal32.dll,
verze 0.9.5.1, adresa chyby 0x00007a74.
Error - 12.4.2010 10:58:30 | Computer Name = VIT | Source = Application Error | ID = 1000
Description = Chybující aplikace l2.exe, verze 0.0.0.0, chybující modul defopenal32.dll,
verze 0.9.5.1, adresa chyby 0x00007a74.
Error - 12.4.2010 11:27:25 | Computer Name = VIT | Source = Application Error | ID = 1000
Description = Chybující aplikace l2.exe, verze 0.0.0.0, chybující modul defopenal32.dll,
verze 0.9.5.1, adresa chyby 0x00007a74.
Error - 15.4.2010 8:15:40 | Computer Name = VIT | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
[ DriverScanne Events ]
Error - 9.4.2010 7:34:52 | Computer Name = VIT | Source = Application Error | ID = 1000
Description =
Error - 9.4.2010 16:25:58 | Computer Name = VIT | Source = Application Error | ID = 1000
Description =
Error - 10.4.2010 6:21:24 | Computer Name = VIT | Source = Application Error | ID = 1000
Description =
Error - 10.4.2010 13:08:40 | Computer Name = VIT | Source = Application Error | ID = 1000
Description =
Error - 11.4.2010 12:18:41 | Computer Name = VIT | Source = Application Error | ID = 1000
Description =
Error - 12.4.2010 10:58:30 | Computer Name = VIT | Source = Application Error | ID = 1000
Description =
Error - 12.4.2010 11:27:25 | Computer Name = VIT | Source = Application Error | ID = 1000
Description =
Error - 15.4.2010 8:15:40 | Computer Name = VIT | Source = PerfNet | ID = 2004
Description =
[ System Events ]
Error - 7.2.2011 13:09:01 | Computer Name = VIT | Source = Service Control Manager | ID = 7000
Description = Služba Služba Google Update (gupdate) neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.2.2011 4:59:55 | Computer Name = VIT | Source = Service Control Manager | ID = 7000
Description = Služba Služba Google Update (gupdate) neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.2.2011 5:05:29 | Computer Name = VIT | Source = Service Control Manager | ID = 7000
Description = Služba Služba Google Update (gupdate) neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.2.2011 7:38:00 | Computer Name = VIT | Source = Service Control Manager | ID = 7000
Description = Služba Služba Google Update (gupdate) neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.2.2011 7:45:31 | Computer Name = VIT | Source = Service Control Manager | ID = 7000
Description = Služba Služba Google Update (gupdate) neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 8.2.2011 8:35:45 | Computer Name = VIT | Source = Dhcp | ID = 1002
Description = Zapůjčení adresy IP 10.0.0.3 pro síťovou kartu s adresou 0007952FD3C4
byla serverem DHCP 10.0.0.138 odmítnuta. (Server DHCP odeslal zprávu DHCPNACK).
Error - 8.2.2011 8:36:17 | Computer Name = VIT | Source = Service Control Manager | ID = 7000
Description = Služba Služba Google Update (gupdate) neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 9.2.2011 8:57:42 | Computer Name = VIT | Source = Service Control Manager | ID = 7000
Description = Služba Služba Google Update (gupdate) neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 9.2.2011 12:53:11 | Computer Name = VIT | Source = Service Control Manager | ID = 7000
Description = Služba Služba Google Update (gupdate) neuspěla při spuštění v důsledku
následující chyby: %%3
Error - 10.2.2011 9:01:17 | Computer Name = VIT | Source = Service Control Manager | ID = 7000
Description = Služba Služba Google Update (gupdate) neuspěla při spuštění v důsledku
následující chyby: %%3
< End of report >

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Motji pls help
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Motji pls help
Máš ten skript nějakej divnej
, prosím tě spust OTL bez skriptu

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Motji pls help
Bez scriptu
OTL logfile created on: 10.2.2011 15:21:16 - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\vf\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
511,00 Mb Total Physical Memory | 306,00 Mb Available Physical Memory | 60,00% Memory free
982,00 Mb Paging File | 714,00 Mb Available in Paging File | 73,00% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55,88 Gb Total Space | 13,95 Gb Free Space | 24,96% Space Free | Partition Type: FAT32
Drive E: | 74,53 Gb Total Space | 13,94 Gb Free Space | 18,70% Space Free | Partition Type: NTFS
Computer Name: VIT | User Name: vf | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.02.10 14:05:30 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\vf\Plocha\OTL.exe
PRC - [2011.02.06 13:56:20 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.01.20 16:20:34 | 000,426,840 | ---- | M] (IObit) -- C:\Program Files\IObit\Game Booster\gbtray.exe
PRC - [2010.08.02 16:10:02 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010.08.02 16:09:56 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.03.18 22:25:56 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) -- C:\WINDOWS\system32\Crypserv.exe
PRC - [2010.01.14 22:11:02 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.02.26 10:49:18 | 000,099,328 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.05.28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2006.11.17 06:42:52 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
========== Modules (SafeList) ==========
MOD - [2011.02.10 14:05:30 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\vf\Plocha\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (gupdate) Služba Google Update (gupdate)
SRV - [2011.02.06 13:56:20 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010.08.02 16:10:02 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.03.18 22:25:56 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Auto | Running] -- C:\WINDOWS\system32\Crypserv.exe -- (CrypKey License)
SRV - [2007.05.28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
========== Driver Services (SafeList) ==========
DRV - [2011.02.06 13:56:24 | 000,135,096 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.02.06 13:56:22 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.06.17 15:27:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.06.17 15:27:14 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2010.04.12 10:44:34 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2010.03.23 12:35:48 | 000,053,312 | -H-- | M] (microOLAP Technologies LTD) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pssdklbf.sys -- (PsSdkLBF)
DRV - [2010.03.23 12:35:48 | 000,036,928 | -H-- | M] (microOLAP Technologies LTD) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pssdk40.sys -- (PsSdk40)
DRV - [2010.03.19 01:11:12 | 000,023,360 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\ckldrv.sys -- (NetworkX)
DRV - [2009.12.30 11:20:54 | 000,027,064 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009.12.28 17:24:12 | 000,721,904 | -H-- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2008.04.14 00:15:30 | 000,010,624 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008.04.14 00:06:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2007.05.16 18:19:52 | 000,133,168 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\imagesrv.sys -- (imagesrv)
DRV - [2007.05.16 18:19:50 | 000,011,568 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\imagedrv.sys -- (imagedrv)
DRV - [2007.03.08 15:34:46 | 004,027,840 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004.08.03 22:31:36 | 000,032,768 | -H-- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisnic.sys -- (SISNIC)
DRV - [2004.08.03 22:29:56 | 001,897,408 | -H-- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2001.08.17 22:00:04 | 000,002,944 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
DRV - [2001.08.17 20:19:34 | 000,040,704 | -H-- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371) Creative AudioPCI (ES1371,ES1373) (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz
IE - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2011.02.07 18:06:46 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskBar = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSecCpl = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoProfilePage = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoConfigPage = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDevMgrPage = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoFileSysPage = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVirtMemPage = 0
O8 - Extra context menu item: Blokovat všechny obrázky ze stejného serveru - C:\Program Files\Avant Browser\AddAllToADBlackList.htm ()
O8 - Extra context menu item: Hledat - C:\Program Files\Avant Browser\Search.htm ()
O8 - Extra context menu item: Otevřít v nové instanci programu - C:\Program Files\Avant Browser\OpenInNewBrowser.htm ()
O8 - Extra context menu item: Otevřít všechny odkazy na této stránce... - C:\Program Files\Avant Browser\OpenAllLinks.htm ()
O8 - Extra context menu item: Přidat do seznamu blokovaných reklam - C:\Program Files\Avant Browser\AddToADBlackList.htm ()
O8 - Extra context menu item: Zvýraznit - C:\Program Files\Avant Browser\Highlight.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_17.dll (Sun Microsystems, Inc.)
O15 - HKLM\..Trusted Domains: mojebanka.cz ([*] https in Důvěryhodné servery)
O15 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\..Trusted Domains: mojebanka.cz ([*] https in Důvěryhodné servery)
O15 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\..Trusted Domains: mojebanka.cz ([www] https in Důvěryhodné servery)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\vf\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\vf\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.02.10 14:05:29 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\vf\Plocha\OTL.exe
[2011.02.08 10:07:01 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.02.08 10:07:00 | 000,000,000 | ---D | C] -- C:\rsit
[2011.02.05 09:24:35 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
[2011.02.05 09:18:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\vf\Local Settings\Data aplikací\VS Revo Group
[2011.02.05 09:18:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Revo Uninstaller Pro
[2011.02.05 09:18:28 | 000,027,064 | ---- | C] (VS Revo Group) -- C:\WINDOWS\System32\drivers\revoflt.sys
[2011.02.05 09:18:23 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2011.02.05 08:35:37 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\vf\Recent
[2011.02.04 23:16:57 | 000,000,000 | -HSD | C] -- C:\Recycled
[2011.02.04 20:25:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2011.02.04 20:17:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\vf\Data aplikací\Avira
[2011.02.04 19:56:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Avira
[2011.02.04 19:56:21 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011.02.04 19:56:20 | 000,135,096 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011.02.04 19:56:20 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011.02.04 19:56:20 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2011.02.04 19:56:20 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011.02.04 19:56:19 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011.02.04 19:56:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Avira
[2011.02.04 17:16:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\vf\Data aplikací\Malwarebytes
[2011.02.04 17:15:51 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.02.04 17:15:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.02.04 17:15:47 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.02.04 17:15:47 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.02.04 14:30:55 | 000,000,000 | ---D | C] -- C:\Josef_Alois_Nahlovsky_-_Krusnohorske_pohadky
[2011.02.04 13:15:23 | 006,932,152 | ---- | C] (Xceed Software Inc. 1-450-442-2626 info@xceedsoft.com www.xceedsoft.com) -- C:\diktaty.exe
[2011.01.29 14:11:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Mafia
[2011.01.29 14:11:54 | 000,000,000 | ---D | C] -- C:\Program Files\Cenega Czech
[2011.01.19 15:58:02 | 000,000,000 | ---D | C] -- C:\system
[2011.01.17 17:28:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Game Booster
[2011.01.17 17:28:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\IObit
========== Files - Modified Within 30 Days ==========
[2011.02.10 14:05:30 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\vf\Plocha\OTL.exe
[2011.02.10 14:00:54 | 000,000,432 | -H-- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2011.02.10 14:00:50 | 000,000,242 | ---- | M] () -- C:\WINDOWS\tasks\Game_Booster_Startup.job
[2011.02.10 14:00:44 | 000,002,048 | -H-- | M] () -- C:\WINDOWS\bootstat.dat
[2011.02.10 14:00:40 | 536,399,872 | -HS- | M] () -- C:\hiberfil.sys
[2011.02.09 13:57:24 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.02.08 16:31:40 | 000,005,893 | -H-- | M] () -- C:\WINDOWS\WINCMD.INI
[2011.02.08 16:31:32 | 000,000,888 | ---- | M] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader.nast
[2011.02.08 16:18:00 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for vf.job
[2011.02.08 16:03:20 | 826,992,640 | ---- | M] () -- C:\uptup.avi
[2011.02.08 14:59:42 | 833,396,736 | ---- | M] () -- C:\Upis.avi
[2011.02.08 14:48:34 | 722,670,080 | ---- | M] () -- C:\Unik z okovu_2001_czdub.avi
[2011.02.08 14:19:22 | 741,986,860 | ---- | M] () -- C:\Pan Včelka(dvd rip-CZ Dubing).avi
[2011.02.08 11:14:22 | 737,295,226 | ---- | M] () -- C:\Cervený.trpaslík.Dvdrip.xvid.zpatky na zemi.avi
[2011.02.08 11:01:38 | 842,089,041 | ---- | M] () -- C:\Projekt Falcon_czdub.mp4
[2011.02.08 10:04:54 | 000,095,864 | -H-- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.02.06 13:56:24 | 000,135,096 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011.02.06 13:56:22 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011.02.05 21:35:46 | 000,000,069 | -H-- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011.02.05 09:24:40 | 000,000,496 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.02.05 09:18:32 | 000,000,829 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Revo Uninstaller Pro.lnk
[2011.02.05 08:33:02 | 000,210,944 | ---- | M] () -- C:\Documents and Settings\vf\Plocha\T-Cleaner.exe
[2011.02.04 19:56:42 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Avira AntiVir Control Center.lnk
[2011.02.04 17:15:52 | 000,000,688 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.02.04 14:50:38 | 000,014,256 | ---- | M] () -- C:\Documents and Settings\vf\Dokumenty\default (12).htm
[2011.01.29 14:11:58 | 000,000,591 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Mafia.lnk
[2011.01.29 07:31:26 | 000,000,083 | ---- | M] () -- C:\WINDOWS\0x.ini
[2011.01.24 18:11:34 | 698,651,760 | ---- | M] () -- C:\moulové.avi
[2011.01.24 17:50:54 | 000,011,035 | ---- | M] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader.err
[2011.01.24 15:43:40 | 712,628,736 | ---- | M] () -- C:\7 Trpasliku - upload by Dodos PCE.avi
[2011.01.24 15:28:04 | 873,873,842 | ---- | M] () -- C:\Sněhurka a sedm trpaslíků (1937).avi
[2011.01.24 14:38:00 | 734,027,776 | ---- | M] () -- C:\snehurka.jak.to.bylo.dal.xvid.CZ.1993.avi
[2011.01.24 13:56:40 | 886,789,632 | ---- | M] () -- C:\invaze_2002.avi
[2011.01.24 13:30:04 | 730,139,510 | ---- | M] () -- C:\Knih.prez.avi
[2011.01.24 13:13:58 | 734,552,064 | ---- | M] () -- C:\Centurion.2010.DVDRip.XviD.CZ.MY.avi
[2011.01.24 13:02:44 | 832,834,810 | ---- | M] () -- C:\Punisher.War.Zone.2008.DVDrip.XviD.xXx.CZ.avi
[2011.01.24 13:01:40 | 730,339,470 | ---- | M] () -- C:\Andele.a.slunce.2006.DVDRip.XviD.CZ-CiBULATOR679-up.by.pablos.avi
[2011.01.24 11:51:46 | 749,498,368 | ---- | M] () -- C:\Blbec k veceri.avi
[2011.01.21 15:41:34 | 000,051,712 | ---- | M] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.01.17 17:28:44 | 000,000,725 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Switch to Gaming Mode.lnk
[2011.01.17 17:28:44 | 000,000,713 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Game Booster.lnk
========== Files Created - No Company Name ==========
[2011.02.08 15:35:32 | 826,992,640 | ---- | C] () -- C:\uptup.avi
[2011.02.08 14:19:21 | 833,396,736 | ---- | C] () -- C:\Upis.avi
[2011.02.08 14:03:31 | 722,670,080 | ---- | C] () -- C:\Unik z okovu_2001_czdub.avi
[2011.02.08 13:47:29 | 741,986,860 | ---- | C] () -- C:\Pan Včelka(dvd rip-CZ Dubing).avi
[2011.02.08 10:41:35 | 737,295,226 | ---- | C] () -- C:\Cervený.trpaslík.Dvdrip.xvid.zpatky na zemi.avi
[2011.02.08 10:24:18 | 842,089,041 | ---- | C] () -- C:\Projekt Falcon_czdub.mp4
[2011.02.05 09:24:39 | 000,000,502 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Opera.lnk
[2011.02.05 09:24:39 | 000,000,496 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.02.05 09:18:30 | 000,000,829 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Revo Uninstaller Pro.lnk
[2011.02.05 08:33:01 | 000,210,944 | ---- | C] () -- C:\Documents and Settings\vf\Plocha\T-Cleaner.exe
[2011.02.04 19:56:41 | 000,001,611 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Avira AntiVir Control Center.lnk
[2011.02.04 17:15:51 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.02.04 14:50:36 | 000,014,256 | ---- | C] () -- C:\Documents and Settings\vf\Dokumenty\default (12).htm
[2011.01.29 14:11:57 | 000,000,591 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Mafia.lnk
[2011.01.24 18:00:47 | 698,651,760 | ---- | C] () -- C:\moulové.avi
[2011.01.24 15:33:23 | 712,628,736 | ---- | C] () -- C:\7 Trpasliku - upload by Dodos PCE.avi
[2011.01.24 15:14:11 | 873,873,842 | ---- | C] () -- C:\Sněhurka a sedm trpaslíků (1937).avi
[2011.01.24 14:27:26 | 734,027,776 | ---- | C] () -- C:\snehurka.jak.to.bylo.dal.xvid.CZ.1993.avi
[2011.01.24 13:43:22 | 886,789,632 | ---- | C] () -- C:\invaze_2002.avi
[2011.01.24 13:18:23 | 730,139,510 | ---- | C] () -- C:\Knih.prez.avi
[2011.01.24 13:01:40 | 734,552,064 | ---- | C] () -- C:\Centurion.2010.DVDRip.XviD.CZ.MY.avi
[2011.01.24 12:41:02 | 730,339,470 | ---- | C] () -- C:\Andele.a.slunce.2006.DVDRip.XviD.CZ-CiBULATOR679-up.by.pablos.avi
[2011.01.24 12:39:36 | 832,834,810 | ---- | C] () -- C:\Punisher.War.Zone.2008.DVDrip.XviD.xXx.CZ.avi
[2011.01.24 11:40:34 | 749,498,368 | ---- | C] () -- C:\Blbec k veceri.avi
[2011.01.17 17:28:54 | 000,000,242 | ---- | C] () -- C:\WINDOWS\tasks\Game_Booster_Startup.job
[2010.12.26 05:07:57 | 000,008,989 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader (2).err
[2010.12.26 04:40:30 | 000,000,864 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader (2).nast
[2010.12.04 17:14:21 | 000,000,880 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader (1).nast
[2010.10.30 19:35:09 | 000,000,832 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\13.nast
[2010.10.30 19:35:01 | 000,000,046 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\13.err
[2010.10.17 10:46:33 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2010.10.17 10:46:28 | 000,056,320 | R--- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[2010.10.16 08:08:44 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2010.09.25 15:22:00 | 000,011,035 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader.err
[2010.09.25 15:17:14 | 000,000,888 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader.nast
[2010.09.11 12:20:13 | 000,000,083 | ---- | C] () -- C:\WINDOWS\0x.ini
[2010.08.29 16:51:41 | 000,000,047 | ---- | C] () -- C:\WINDOWS\Crypkey.ini
[2010.08.29 16:51:39 | 000,023,360 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys
[2010.07.08 13:20:13 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2010.05.01 09:54:09 | 000,005,079 | ---- | C] () -- C:\WINDOWS\l2control.ini
[2010.04.09 08:24:07 | 000,000,330 | ---- | C] () -- C:\WINDOWS\l2net.ini
[2010.01.05 09:38:31 | 000,020,611 | -H-- | C] () -- C:\WINDOWS\System32\mvastnet.dll
[2009.12.24 05:44:08 | 000,057,344 | -H-- | C] () -- C:\WINDOWS\System32\wmsprog.dll
[2009.11.07 10:12:32 | 000,000,112 | -H-- | C] () -- C:\WINDOWS\ActiveSkin.INI
[2009.09.25 12:45:36 | 000,000,287 | -H-- | C] () -- C:\WINDOWS\game.ini
[2009.09.25 07:41:23 | 001,806,336 | ---- | C] () -- C:\Program Files\HellShare.exe
[2009.09.24 13:07:07 | 000,000,069 | -H-- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009.09.24 08:01:30 | 000,000,092 | -H-- | C] () -- C:\WINDOWS\CMISETUP.INI
[2009.09.24 08:01:29 | 000,000,026 | -H-- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2009.09.24 08:01:26 | 000,000,054 | -H-- | C] () -- C:\WINDOWS\Wininit.ini
[2009.09.24 08:01:20 | 000,028,672 | -H-- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2009.09.22 16:23:08 | 000,051,712 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.09.22 11:12:00 | 000,004,249 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2003.08.14 08:46:30 | 000,000,504 | -H-- | C] () -- C:\WINDOWS\mamba.ini
[2003.08.13 05:45:50 | 000,000,028 | -H-- | C] () -- C:\WINDOWS\boxworld.ini
[2003.08.13 05:44:05 | 000,000,131 | -H-- | C] () -- C:\WINDOWS\chess.ini
[2003.08.13 05:38:54 | 000,000,298 | -H-- | C] () -- C:\WINDOWS\pent.ini
[2003.08.13 05:33:51 | 000,000,020 | -H-- | C] () -- C:\WINDOWS\entpack.ini
[2003.08.13 05:31:03 | 000,000,163 | -H-- | C] () -- C:\WINDOWS\games.ini
[2003.08.13 05:30:43 | 000,000,062 | -H-- | C] () -- C:\WINDOWS\soko.ini
[2003.08.11 00:10:28 | 000,005,893 | -H-- | C] () -- C:\WINDOWS\WINCMD.INI
[2003.02.19 01:26:28 | 000,028,672 | -H-- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
========== LOP Check ==========
[2003.08.11 00:26:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2003.08.11 00:57:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IM
[2003.08.11 00:58:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.09.24 07:40:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DriverScanner
[2009.10.05 11:34:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IncrediMail
[2009.12.24 05:39:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.01.05 08:47:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2010.06.30 06:58:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{66E2F539-12B6-4870-A500-7689CDE75C5E}
[2010.08.29 16:51:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AceReader Pro
[2011.01.17 17:28:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IObit
[2009.09.22 12:23:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\Opera
[2009.09.24 07:40:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\Uniblue
[2010.09.04 14:27:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\com.youneedabudget.YNAB3.Live.9C763150EFAB05FD2A2B78705C7A54E2FCDDE07D.1
[2010.10.11 09:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\IObit
[2010.10.18 11:24:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\TS3Client
[2010.12.29 11:05:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\Avant Browser
[2003.08.16 05:13:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\Opera
[2010.03.15 09:35:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\ESET
[2010.12.26 03:45:42 | 000,000,366 | -H-- | M] () -- C:\WINDOWS\Tasks\RegCure.job
[2011.02.10 14:00:54 | 000,000,432 | -H-- | M] () -- C:\WINDOWS\Tasks\RegCure Program Check.job
[2011.02.10 14:00:50 | 000,000,242 | ---- | M] () -- C:\WINDOWS\Tasks\Game_Booster_Startup.job
========== Purity Check ==========
< End of report >
OTL logfile created on: 10.2.2011 15:21:16 - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\vf\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
511,00 Mb Total Physical Memory | 306,00 Mb Available Physical Memory | 60,00% Memory free
982,00 Mb Paging File | 714,00 Mb Available in Paging File | 73,00% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55,88 Gb Total Space | 13,95 Gb Free Space | 24,96% Space Free | Partition Type: FAT32
Drive E: | 74,53 Gb Total Space | 13,94 Gb Free Space | 18,70% Space Free | Partition Type: NTFS
Computer Name: VIT | User Name: vf | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.02.10 14:05:30 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\vf\Plocha\OTL.exe
PRC - [2011.02.06 13:56:20 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.01.20 16:20:34 | 000,426,840 | ---- | M] (IObit) -- C:\Program Files\IObit\Game Booster\gbtray.exe
PRC - [2010.08.02 16:10:02 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010.08.02 16:09:56 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010.03.18 22:25:56 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) -- C:\WINDOWS\system32\Crypserv.exe
PRC - [2010.01.14 22:11:02 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009.02.26 10:49:18 | 000,099,328 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.05.28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2006.11.17 06:42:52 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
========== Modules (SafeList) ==========
MOD - [2011.02.10 14:05:30 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\vf\Plocha\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (gupdate) Služba Google Update (gupdate)
SRV - [2011.02.06 13:56:20 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010.08.02 16:10:02 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010.03.18 22:25:56 | 000,126,976 | ---- | M] (CrypKey (Canada) Ltd.) [Auto | Running] -- C:\WINDOWS\system32\Crypserv.exe -- (CrypKey License)
SRV - [2007.05.28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
========== Driver Services (SafeList) ==========
DRV - [2011.02.06 13:56:24 | 000,135,096 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.02.06 13:56:22 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010.06.17 15:27:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010.06.17 15:27:14 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2010.04.12 10:44:34 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2010.03.23 12:35:48 | 000,053,312 | -H-- | M] (microOLAP Technologies LTD) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pssdklbf.sys -- (PsSdkLBF)
DRV - [2010.03.23 12:35:48 | 000,036,928 | -H-- | M] (microOLAP Technologies LTD) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pssdk40.sys -- (PsSdk40)
DRV - [2010.03.19 01:11:12 | 000,023,360 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\ckldrv.sys -- (NetworkX)
DRV - [2009.12.30 11:20:54 | 000,027,064 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009.12.28 17:24:12 | 000,721,904 | -H-- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2008.04.14 00:15:30 | 000,010,624 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008.04.14 00:06:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2007.05.16 18:19:52 | 000,133,168 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\imagesrv.sys -- (imagesrv)
DRV - [2007.05.16 18:19:50 | 000,011,568 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\imagedrv.sys -- (imagedrv)
DRV - [2007.03.08 15:34:46 | 004,027,840 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004.08.03 22:31:36 | 000,032,768 | -H-- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisnic.sys -- (SISNIC)
DRV - [2004.08.03 22:29:56 | 001,897,408 | -H-- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2001.08.17 22:00:04 | 000,002,944 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
DRV - [2001.08.17 20:19:34 | 000,040,704 | -H-- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371) Creative AudioPCI (ES1371,ES1373) (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz
IE - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2011.02.07 18:06:46 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskBar = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSecCpl = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoProfilePage = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoConfigPage = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDevMgrPage = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoFileSysPage = 0
O7 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVirtMemPage = 0
O8 - Extra context menu item: Blokovat všechny obrázky ze stejného serveru - C:\Program Files\Avant Browser\AddAllToADBlackList.htm ()
O8 - Extra context menu item: Hledat - C:\Program Files\Avant Browser\Search.htm ()
O8 - Extra context menu item: Otevřít v nové instanci programu - C:\Program Files\Avant Browser\OpenInNewBrowser.htm ()
O8 - Extra context menu item: Otevřít všechny odkazy na této stránce... - C:\Program Files\Avant Browser\OpenAllLinks.htm ()
O8 - Extra context menu item: Přidat do seznamu blokovaných reklam - C:\Program Files\Avant Browser\AddToADBlackList.htm ()
O8 - Extra context menu item: Zvýraznit - C:\Program Files\Avant Browser\Highlight.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_17.dll (Sun Microsystems, Inc.)
O15 - HKLM\..Trusted Domains: mojebanka.cz ([*] https in Důvěryhodné servery)
O15 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\..Trusted Domains: mojebanka.cz ([*] https in Důvěryhodné servery)
O15 - HKU\S-1-5-21-1960408961-1060284298-1460758035-1003\..Trusted Domains: mojebanka.cz ([www] https in Důvěryhodné servery)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\vf\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\vf\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.02.10 14:05:29 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\vf\Plocha\OTL.exe
[2011.02.08 10:07:01 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.02.08 10:07:00 | 000,000,000 | ---D | C] -- C:\rsit
[2011.02.05 09:24:35 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
[2011.02.05 09:18:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\vf\Local Settings\Data aplikací\VS Revo Group
[2011.02.05 09:18:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Revo Uninstaller Pro
[2011.02.05 09:18:28 | 000,027,064 | ---- | C] (VS Revo Group) -- C:\WINDOWS\System32\drivers\revoflt.sys
[2011.02.05 09:18:23 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2011.02.05 08:35:37 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\vf\Recent
[2011.02.04 23:16:57 | 000,000,000 | -HSD | C] -- C:\Recycled
[2011.02.04 20:25:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2011.02.04 20:17:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\vf\Data aplikací\Avira
[2011.02.04 19:56:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Avira
[2011.02.04 19:56:21 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011.02.04 19:56:20 | 000,135,096 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011.02.04 19:56:20 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011.02.04 19:56:20 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2011.02.04 19:56:20 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011.02.04 19:56:19 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011.02.04 19:56:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Avira
[2011.02.04 17:16:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\vf\Data aplikací\Malwarebytes
[2011.02.04 17:15:51 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.02.04 17:15:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.02.04 17:15:47 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.02.04 17:15:47 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.02.04 14:30:55 | 000,000,000 | ---D | C] -- C:\Josef_Alois_Nahlovsky_-_Krusnohorske_pohadky
[2011.02.04 13:15:23 | 006,932,152 | ---- | C] (Xceed Software Inc. 1-450-442-2626 info@xceedsoft.com www.xceedsoft.com) -- C:\diktaty.exe
[2011.01.29 14:11:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Mafia
[2011.01.29 14:11:54 | 000,000,000 | ---D | C] -- C:\Program Files\Cenega Czech
[2011.01.19 15:58:02 | 000,000,000 | ---D | C] -- C:\system
[2011.01.17 17:28:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Game Booster
[2011.01.17 17:28:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\IObit
========== Files - Modified Within 30 Days ==========
[2011.02.10 14:05:30 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\vf\Plocha\OTL.exe
[2011.02.10 14:00:54 | 000,000,432 | -H-- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2011.02.10 14:00:50 | 000,000,242 | ---- | M] () -- C:\WINDOWS\tasks\Game_Booster_Startup.job
[2011.02.10 14:00:44 | 000,002,048 | -H-- | M] () -- C:\WINDOWS\bootstat.dat
[2011.02.10 14:00:40 | 536,399,872 | -HS- | M] () -- C:\hiberfil.sys
[2011.02.09 13:57:24 | 000,002,206 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.02.08 16:31:40 | 000,005,893 | -H-- | M] () -- C:\WINDOWS\WINCMD.INI
[2011.02.08 16:31:32 | 000,000,888 | ---- | M] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader.nast
[2011.02.08 16:18:00 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for vf.job
[2011.02.08 16:03:20 | 826,992,640 | ---- | M] () -- C:\uptup.avi
[2011.02.08 14:59:42 | 833,396,736 | ---- | M] () -- C:\Upis.avi
[2011.02.08 14:48:34 | 722,670,080 | ---- | M] () -- C:\Unik z okovu_2001_czdub.avi
[2011.02.08 14:19:22 | 741,986,860 | ---- | M] () -- C:\Pan Včelka(dvd rip-CZ Dubing).avi
[2011.02.08 11:14:22 | 737,295,226 | ---- | M] () -- C:\Cervený.trpaslík.Dvdrip.xvid.zpatky na zemi.avi
[2011.02.08 11:01:38 | 842,089,041 | ---- | M] () -- C:\Projekt Falcon_czdub.mp4
[2011.02.08 10:04:54 | 000,095,864 | -H-- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.02.06 13:56:24 | 000,135,096 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011.02.06 13:56:22 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011.02.05 21:35:46 | 000,000,069 | -H-- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011.02.05 09:24:40 | 000,000,496 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.02.05 09:18:32 | 000,000,829 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Revo Uninstaller Pro.lnk
[2011.02.05 08:33:02 | 000,210,944 | ---- | M] () -- C:\Documents and Settings\vf\Plocha\T-Cleaner.exe
[2011.02.04 19:56:42 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Avira AntiVir Control Center.lnk
[2011.02.04 17:15:52 | 000,000,688 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.02.04 14:50:38 | 000,014,256 | ---- | M] () -- C:\Documents and Settings\vf\Dokumenty\default (12).htm
[2011.01.29 14:11:58 | 000,000,591 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Mafia.lnk
[2011.01.29 07:31:26 | 000,000,083 | ---- | M] () -- C:\WINDOWS\0x.ini
[2011.01.24 18:11:34 | 698,651,760 | ---- | M] () -- C:\moulové.avi
[2011.01.24 17:50:54 | 000,011,035 | ---- | M] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader.err
[2011.01.24 15:43:40 | 712,628,736 | ---- | M] () -- C:\7 Trpasliku - upload by Dodos PCE.avi
[2011.01.24 15:28:04 | 873,873,842 | ---- | M] () -- C:\Sněhurka a sedm trpaslíků (1937).avi
[2011.01.24 14:38:00 | 734,027,776 | ---- | M] () -- C:\snehurka.jak.to.bylo.dal.xvid.CZ.1993.avi
[2011.01.24 13:56:40 | 886,789,632 | ---- | M] () -- C:\invaze_2002.avi
[2011.01.24 13:30:04 | 730,139,510 | ---- | M] () -- C:\Knih.prez.avi
[2011.01.24 13:13:58 | 734,552,064 | ---- | M] () -- C:\Centurion.2010.DVDRip.XviD.CZ.MY.avi
[2011.01.24 13:02:44 | 832,834,810 | ---- | M] () -- C:\Punisher.War.Zone.2008.DVDrip.XviD.xXx.CZ.avi
[2011.01.24 13:01:40 | 730,339,470 | ---- | M] () -- C:\Andele.a.slunce.2006.DVDRip.XviD.CZ-CiBULATOR679-up.by.pablos.avi
[2011.01.24 11:51:46 | 749,498,368 | ---- | M] () -- C:\Blbec k veceri.avi
[2011.01.21 15:41:34 | 000,051,712 | ---- | M] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.01.17 17:28:44 | 000,000,725 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Switch to Gaming Mode.lnk
[2011.01.17 17:28:44 | 000,000,713 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Game Booster.lnk
========== Files Created - No Company Name ==========
[2011.02.08 15:35:32 | 826,992,640 | ---- | C] () -- C:\uptup.avi
[2011.02.08 14:19:21 | 833,396,736 | ---- | C] () -- C:\Upis.avi
[2011.02.08 14:03:31 | 722,670,080 | ---- | C] () -- C:\Unik z okovu_2001_czdub.avi
[2011.02.08 13:47:29 | 741,986,860 | ---- | C] () -- C:\Pan Včelka(dvd rip-CZ Dubing).avi
[2011.02.08 10:41:35 | 737,295,226 | ---- | C] () -- C:\Cervený.trpaslík.Dvdrip.xvid.zpatky na zemi.avi
[2011.02.08 10:24:18 | 842,089,041 | ---- | C] () -- C:\Projekt Falcon_czdub.mp4
[2011.02.05 09:24:39 | 000,000,502 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Opera.lnk
[2011.02.05 09:24:39 | 000,000,496 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.02.05 09:18:30 | 000,000,829 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Revo Uninstaller Pro.lnk
[2011.02.05 08:33:01 | 000,210,944 | ---- | C] () -- C:\Documents and Settings\vf\Plocha\T-Cleaner.exe
[2011.02.04 19:56:41 | 000,001,611 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Avira AntiVir Control Center.lnk
[2011.02.04 17:15:51 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.02.04 14:50:36 | 000,014,256 | ---- | C] () -- C:\Documents and Settings\vf\Dokumenty\default (12).htm
[2011.01.29 14:11:57 | 000,000,591 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Mafia.lnk
[2011.01.24 18:00:47 | 698,651,760 | ---- | C] () -- C:\moulové.avi
[2011.01.24 15:33:23 | 712,628,736 | ---- | C] () -- C:\7 Trpasliku - upload by Dodos PCE.avi
[2011.01.24 15:14:11 | 873,873,842 | ---- | C] () -- C:\Sněhurka a sedm trpaslíků (1937).avi
[2011.01.24 14:27:26 | 734,027,776 | ---- | C] () -- C:\snehurka.jak.to.bylo.dal.xvid.CZ.1993.avi
[2011.01.24 13:43:22 | 886,789,632 | ---- | C] () -- C:\invaze_2002.avi
[2011.01.24 13:18:23 | 730,139,510 | ---- | C] () -- C:\Knih.prez.avi
[2011.01.24 13:01:40 | 734,552,064 | ---- | C] () -- C:\Centurion.2010.DVDRip.XviD.CZ.MY.avi
[2011.01.24 12:41:02 | 730,339,470 | ---- | C] () -- C:\Andele.a.slunce.2006.DVDRip.XviD.CZ-CiBULATOR679-up.by.pablos.avi
[2011.01.24 12:39:36 | 832,834,810 | ---- | C] () -- C:\Punisher.War.Zone.2008.DVDrip.XviD.xXx.CZ.avi
[2011.01.24 11:40:34 | 749,498,368 | ---- | C] () -- C:\Blbec k veceri.avi
[2011.01.17 17:28:54 | 000,000,242 | ---- | C] () -- C:\WINDOWS\tasks\Game_Booster_Startup.job
[2010.12.26 05:07:57 | 000,008,989 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader (2).err
[2010.12.26 04:40:30 | 000,000,864 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader (2).nast
[2010.12.04 17:14:21 | 000,000,880 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader (1).nast
[2010.10.30 19:35:09 | 000,000,832 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\13.nast
[2010.10.30 19:35:01 | 000,000,046 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\13.err
[2010.10.17 10:46:33 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2010.10.17 10:46:28 | 000,056,320 | R--- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[2010.10.16 08:08:44 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2010.09.25 15:22:00 | 000,011,035 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader.err
[2010.09.25 15:17:14 | 000,000,888 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\SRDownloader.nast
[2010.09.11 12:20:13 | 000,000,083 | ---- | C] () -- C:\WINDOWS\0x.ini
[2010.08.29 16:51:41 | 000,000,047 | ---- | C] () -- C:\WINDOWS\Crypkey.ini
[2010.08.29 16:51:39 | 000,023,360 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys
[2010.07.08 13:20:13 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2010.05.01 09:54:09 | 000,005,079 | ---- | C] () -- C:\WINDOWS\l2control.ini
[2010.04.09 08:24:07 | 000,000,330 | ---- | C] () -- C:\WINDOWS\l2net.ini
[2010.01.05 09:38:31 | 000,020,611 | -H-- | C] () -- C:\WINDOWS\System32\mvastnet.dll
[2009.12.24 05:44:08 | 000,057,344 | -H-- | C] () -- C:\WINDOWS\System32\wmsprog.dll
[2009.11.07 10:12:32 | 000,000,112 | -H-- | C] () -- C:\WINDOWS\ActiveSkin.INI
[2009.09.25 12:45:36 | 000,000,287 | -H-- | C] () -- C:\WINDOWS\game.ini
[2009.09.25 07:41:23 | 001,806,336 | ---- | C] () -- C:\Program Files\HellShare.exe
[2009.09.24 13:07:07 | 000,000,069 | -H-- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009.09.24 08:01:30 | 000,000,092 | -H-- | C] () -- C:\WINDOWS\CMISETUP.INI
[2009.09.24 08:01:29 | 000,000,026 | -H-- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2009.09.24 08:01:26 | 000,000,054 | -H-- | C] () -- C:\WINDOWS\Wininit.ini
[2009.09.24 08:01:20 | 000,028,672 | -H-- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2009.09.22 16:23:08 | 000,051,712 | ---- | C] () -- C:\Documents and Settings\vf\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.09.22 11:12:00 | 000,004,249 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2003.08.14 08:46:30 | 000,000,504 | -H-- | C] () -- C:\WINDOWS\mamba.ini
[2003.08.13 05:45:50 | 000,000,028 | -H-- | C] () -- C:\WINDOWS\boxworld.ini
[2003.08.13 05:44:05 | 000,000,131 | -H-- | C] () -- C:\WINDOWS\chess.ini
[2003.08.13 05:38:54 | 000,000,298 | -H-- | C] () -- C:\WINDOWS\pent.ini
[2003.08.13 05:33:51 | 000,000,020 | -H-- | C] () -- C:\WINDOWS\entpack.ini
[2003.08.13 05:31:03 | 000,000,163 | -H-- | C] () -- C:\WINDOWS\games.ini
[2003.08.13 05:30:43 | 000,000,062 | -H-- | C] () -- C:\WINDOWS\soko.ini
[2003.08.11 00:10:28 | 000,005,893 | -H-- | C] () -- C:\WINDOWS\WINCMD.INI
[2003.02.19 01:26:28 | 000,028,672 | -H-- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
========== LOP Check ==========
[2003.08.11 00:26:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2003.08.11 00:57:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IM
[2003.08.11 00:58:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.09.24 07:40:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DriverScanner
[2009.10.05 11:34:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IncrediMail
[2009.12.24 05:39:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.01.05 08:47:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2010.06.30 06:58:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{66E2F539-12B6-4870-A500-7689CDE75C5E}
[2010.08.29 16:51:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AceReader Pro
[2011.01.17 17:28:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IObit
[2009.09.22 12:23:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\Opera
[2009.09.24 07:40:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\Uniblue
[2010.09.04 14:27:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\com.youneedabudget.YNAB3.Live.9C763150EFAB05FD2A2B78705C7A54E2FCDDE07D.1
[2010.10.11 09:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\IObit
[2010.10.18 11:24:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\TS3Client
[2010.12.29 11:05:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\vf\Data aplikací\Avant Browser
[2003.08.16 05:13:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\Opera
[2010.03.15 09:35:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\ESET
[2010.12.26 03:45:42 | 000,000,366 | -H-- | M] () -- C:\WINDOWS\Tasks\RegCure.job
[2011.02.10 14:00:54 | 000,000,432 | -H-- | M] () -- C:\WINDOWS\Tasks\RegCure Program Check.job
[2011.02.10 14:00:50 | 000,000,242 | ---- | M] () -- C:\WINDOWS\Tasks\Game_Booster_Startup.job
========== Purity Check ==========
< End of report >
Re: Motji pls help
To je mi teda záhada
. Máš skryté zobrazování skrytých a systémových souborů a složek?

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Motji pls help
Tak to ani netuším kde nastavit 

Re: Motji pls help
Vřešeno na těchto stránkách jsem našel návod. http://support.microsoft.com/kb/330132/cs Použil jsem metodu 2
Tím by měl být PC v pořádku už běží dobře Dík za pomoc.

Tím by měl být PC v pořádku už běží dobře Dík za pomoc.

Re: Motji pls help


Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.