Stránka 2 z 4

Re: prosba o kontrolu logu

Napsal: 17 pro 2012 20:41
od vyosek
:arrow: Stahnete Malwarebytes Anti-Rootkit http://www.bleepingcomputer.com/downloa ... i-rootkit/
  • Ulozte nejlepe na Plochu a rozbalte
  • Spustte kliknutim na mbanr
  • Nyni postupne kliknete na Next a Update
  • Po dokonceni update (aktualizace) databaze kliknete opet na Next
  • Nechte zaskrtnute vsechny tri moznosti a klinete na Scan cimz spustite prohledavani PC
  • Po dokonceni skenu (cca 5 minutek) zkontrolujte, zda-li je u vsech nalezu (samozrejme pokud budou) zatrzitko
  • Tez zkontrolujte, jetsli je zatrzitko u Create Restore point
  • Nyni kliknete na CleanUp cimz nalezenou infekci odstranime
  • PC bude restartovan
  • Slozka mbar by mela obsahovat log (a zrejme se i sam otevre) mbar-log-rok-mesic-den (hodina-minuta-sekunda).txt, ten mi sem dejte

Re: prosba o kontrolu logu

Napsal: 18 pro 2012 20:58
od Ivon
tady je:
Malwarebytes Anti-Rootkit 1.01.0.1011
www.malwarebytes.org

Database version: v2012.12.18.07

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Ivona :: DOMA-QO9I0VR7RQ [administrator]

18.12.2012 20:39:13
mbar-log-2012-12-18 (20-39-13).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 33220
Time elapsed: 52 minute(s), 58 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 2
HKCU\CONTROL PANEL\DON'T LOAD|scui.cpl (Hijack.SecurityCenter) -> Data: No -> Delete on reboot.
HKCU\CONTROL PANEL\DON'T LOAD|wscui.cpl (Hijack.SecurityCenter) -> Data: No -> Delete on reboot.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 3
C:\Documents and Settings\Ivona\Data aplikací\SearchToolbarCorp (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Ivona\Data aplikací\SearchToolbarCorp\Toolbar Vision (Trojan.Agent) -> Delete on reboot.
C:\Program Files\VSAdd-in (Trojan.Agent) -> Delete on reboot.

Files Detected: 5
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Start Menu\Programs\Startup\xD.exe (Trojan.Dropper) -> Delete on reboot.
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\9.tmp (Trojan.Generic) -> Delete on reboot.
C:\Documents and Settings\Ivona\Data aplikací\SearchToolbarCorp\Toolbar Vision\PageHistory.txt (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Ivona\Data aplikací\SearchToolbarCorp\Toolbar Vision\WebHistory.txt (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\winlogon.Del (Heuristics.Reserved.Word.Exploit) -> Delete on reboot.

(end)

Re: prosba o kontrolu logu

Napsal: 18 pro 2012 22:54
od vyosek
:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) http://forum.viry.cz/viewtopic.php?f=29&t=115222
  • Provedte aktualizaci
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni

Re: prosba o kontrolu logu

Napsal: 21 pro 2012 16:34
od Ivon
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 679224
Uplynulý čas: 24 minut, 47 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Re: prosba o kontrolu logu

Napsal: 21 pro 2012 17:51
od vyosek
To je rychla kontrola, ja chtel kompletni (uplny) sken...Takze jej prosim udelejte

Re: prosba o kontrolu logu

Napsal: 10 led 2013 20:54
od Ivon
Omlouvám se,že to trvalo.
log:
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.70.0.1100
www.malwarebytes.org

Verze: v2013.01.10.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Ivona :: DOMA-QO9I0VR7RQ [administrátor]

Ochrana: Povolena

10.1.2013 17:26:47
MBAM-log-2013-01-10 (20-48-46).txt

Typ: Kompletní kontrola (C:\|G:\|H:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 1136015
Uplynulý čas: 3 hodin, 13 minut, 3 sekund

Nalezené procesy v paměti: 2
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe (Trojan.Dropper) -> 3656 -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe (Trojan.Dropper) -> 1444 -> Nebyla provedena žádná instrukce.

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WINSXS32 (Trojan.Dropper) -> Data: C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe -> Nebyla provedena žádná instrukce.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 19
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe (Trojan.Dropper) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\3.exe (Trojan.Dropper) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\8.exe (Trojan.Dropper) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\A.exe (Trojan.Dropper) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{3CE778F7-E5FE-4173-ABF9-20DC7DBB5542}\RP15\A0007182.exe (Adware.WhenU) -> Nebyla provedena žádná instrukce.
C:\UsbFix\Quarantine\C\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\4.exe.vir (Trojan.Dropper) -> Nebyla provedena žádná instrukce.
C:\UsbFix\Quarantine\C\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\6.exe.vir (Trojan.Dropper) -> Nebyla provedena žádná instrukce.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0176130.exe (Trojan.Inject) -> Nebyla provedena žádná instrukce.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0176428.exe (Trojan.Inject) -> Nebyla provedena žádná instrukce.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0176829.exe (Trojan.FakeMS) -> Nebyla provedena žádná instrukce.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0177307.exe (Trojan.FakeMS) -> Nebyla provedena žádná instrukce.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0177411.exe (Trojan.FakeMS) -> Nebyla provedena žádná instrukce.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0179427.exe (Trojan.FakeMS) -> Nebyla provedena žádná instrukce.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0181187.exe (Trojan.Agent) -> Nebyla provedena žádná instrukce.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0181275.exe (Malware.Packer.Gen) -> Nebyla provedena žádná instrukce.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0181311.exe (RiskWare.Tool.CK) -> Nebyla provedena žádná instrukce.
G:\Dokumenty\Download\My ebook\F_Reader.8.0_Arkas_upload\ABBYY.FineReader.8.0\ABBYY.FineReader.Professional.v8.0.0.706.Incl.Keymaker-CORE\keygen.exe (Malware.Packer.Gen) -> Nebyla provedena žádná instrukce.
G:\Dokumenty\Download\My ebook\F_Reader.8.0_Arkas_upload\ABBYY.FineReader.8.0\ABBYY.FineReader.Professional.v8.0.0.706.Incl.Keymaker-CORE\Keygen_a.exe (Riskware.Took.CK) -> Nebyla provedena žádná instrukce.
G:\Dokumenty\stahování\Office 2007\Office 2007 KeyGen.exe (RiskWare.Tool.CK) -> Nebyla provedena žádná instrukce.

(konec)

Re: prosba o kontrolu logu

Napsal: 11 led 2013 21:25
od vyosek
:arrow: Nalezy MBAMu smazte, objevi se log, ten rad uvidim

Re: prosba o kontrolu logu

Napsal: 14 led 2013 20:36
od Ivon
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.70.0.1100
www.malwarebytes.org

Verze: v2013.01.14.06

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Ivona :: DOMA-QO9I0VR7RQ [administrátor]

Ochrana: Povolena

14.1.2013 16:37:25
mbam-log-2013-01-14 (16-37-25).txt

Typ: Kompletní kontrola (C:\|G:\|H:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 1095037
Uplynulý čas: 3 hodin, 32 minut, 4 sekund

Nalezené procesy v paměti: 2
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe (Trojan.Dropper) -> 476 -> Bude smazán při restartu.
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe (Trojan.Dropper) -> 3016 -> Bude smazán při restartu.

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WINSXS32 (Trojan.Dropper) -> Data: C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe -> Přesun do karantény a smazání se zdařilo.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 21
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe (Trojan.Dropper) -> Bude smazán při restartu.
C:\Documents and Settings\Ivona\Dokumenty\My eBooks\Windows XP Crack (WGA Notification).exe (PUP.RemoveWGA) -> Přesun do karantény a smazání se zdařilo.
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\3.exe (Trojan.Dropper) -> Přesun do karantény a smazání se zdařilo.
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\8.exe (Trojan.Dropper) -> Přesun do karantény a smazání se zdařilo.
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\A.exe (Trojan.Dropper) -> Přesun do karantény a smazání se zdařilo.
C:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP862\A0183431.exe (Trojan.Dropper) -> Přesun do karantény a smazání se zdařilo.
C:\System Volume Information\_restore{3CE778F7-E5FE-4173-ABF9-20DC7DBB5542}\RP15\A0007182.exe (Adware.WhenU) -> Přesun do karantény a smazání se zdařilo.
C:\UsbFix\Quarantine\C\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\4.exe.vir (Trojan.Dropper) -> Přesun do karantény a smazání se zdařilo.
C:\UsbFix\Quarantine\C\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\6.exe.vir (Trojan.Dropper) -> Přesun do karantény a smazání se zdařilo.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0176130.exe (Trojan.Inject) -> Přesun do karantény a smazání se zdařilo.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0176428.exe (Trojan.Inject) -> Přesun do karantény a smazání se zdařilo.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0176829.exe (Trojan.FakeMS) -> Přesun do karantény a smazání se zdařilo.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0177307.exe (Trojan.FakeMS) -> Přesun do karantény a smazání se zdařilo.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0177411.exe (Trojan.FakeMS) -> Přesun do karantény a smazání se zdařilo.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0179427.exe (Trojan.FakeMS) -> Přesun do karantény a smazání se zdařilo.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0181187.exe (Trojan.Agent) -> Přesun do karantény a smazání se zdařilo.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0181275.exe (Malware.Packer.Gen) -> Přesun do karantény a smazání se zdařilo.
G:\System Volume Information\_restore{358001EF-91EC-4F38-8478-3BA4A091B63D}\RP855\A0181311.exe (RiskWare.Tool.CK) -> Přesun do karantény a smazání se zdařilo.
G:\Dokumenty\Download\My ebook\F_Reader.8.0_Arkas_upload\ABBYY.FineReader.8.0\ABBYY.FineReader.Professional.v8.0.0.706.Incl.Keymaker-CORE\keygen.exe (Malware.Packer.Gen) -> Přesun do karantény a smazání se zdařilo.
G:\Dokumenty\Download\My ebook\F_Reader.8.0_Arkas_upload\ABBYY.FineReader.8.0\ABBYY.FineReader.Professional.v8.0.0.706.Incl.Keymaker-CORE\Keygen_a.exe (Riskware.Took.CK) -> Přesun do karantény a smazání se zdařilo.
G:\Dokumenty\stahování\Office 2007\Office 2007 KeyGen.exe (RiskWare.Tool.CK) -> Přesun do karantény a smazání se zdařilo.

(konec)

Re: prosba o kontrolu logu

Napsal: 14 led 2013 20:46
od vyosek
:arrow: Ty nelegalni windows tu nebudeme tolerovat a priste bude pomoc odmitnuta :evil:

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
    
    netsvcs
    drivers32
    savembr:0
    
    /md5start
    atapi.sys
    autochk.exe
    cdrom.sys
    explorer.exe
    hal.dll
    scecli.dll
    services.exe
    svchost.exe
    tcpip.sys
    userinit.exe
    winlogon.exe
    /md5stop
    
    %systemroot%*.* /U /s
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    %SYSTEMDRIVE%\*.exe
    
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    
    %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
    %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
    %PROGRAMFILES%\Opera\opera.exe /md5
    %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5
    
    %SystemDrive%\PhysicalMBR.bin /md5 
    
    *crack* /s
    *keygen* /s
    *loader* /s
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
  • Pokud budou logy dlouhe (forum bude kricet o prekroceni maximalniho poctu znaku), tak je rozdelte do vice prispevku

Re: prosba o kontrolu logu

Napsal: 19 led 2013 20:23
od Ivon
Windows mám legální. Je pravda, že jsem na jejich aktivaci použila keygen, protože jsem měla několikrát rozbitý a hodněkrát zavirovaný PC a překročila jsem počet aktivací. Musela bych proto volat na tu jejich linku. Proto jsem raději použila aktivátor. Asi vám to takhle nijak nedokážu, ale opravdu je mám legálně.

k tomu logu: OTL:
OTL logfile created on: 19.1.2013 17:07:23 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

511,17 Mb Total Physical Memory | 25,96 Mb Available Physical Memory | 5,08% Memory free
1,22 Gb Paging File | 0,29 Gb Available in Paging File | 24,09% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149,05 Gb Total Space | 44,50 Gb Free Space | 29,86% Space Free | Partition Type: NTFS
Drive G: | 931,28 Gb Total Space | 820,12 Gb Free Space | 88,06% Space Free | Partition Type: FAT32
Drive H: | 983,72 Mb Total Space | 657,63 Mb Free Space | 66,85% Space Free | Partition Type: FAT

Computer Name: DOMA-QO9I0VR7RQ | User Name: Ivona | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2013.01.15 20:25:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Plocha\OTL.exe
PRC - [2013.01.14 20:21:40 | 000,318,976 | ---- | M] (PowerBASIC, Inc.) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe
PRC - [2012.12.14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.12.14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.06.16 03:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Engine\19.9.0.9\ccsvchst.exe
PRC - [2012.02.17 20:40:08 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012.01.06 12:47:18 | 000,781,824 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\SELPHY Photo Print\CIC_SPPhelper.exe
PRC - [2011.06.28 20:28:06 | 000,496,128 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2010.10.27 18:17:52 | 000,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010.08.25 10:27:44 | 000,309,824 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010.03.18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009.05.05 13:28:08 | 000,192,784 | ---- | M] (MSBoost) -- C:\Program Files\Smart PC Solutions\Magic Speed\MagicSpeedBooster.exe
PRC - [2009.03.31 09:39:36 | 000,233,472 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2008.11.07 20:38:26 | 000,025,824 | ---- | M] (Memeo) -- C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
PRC - [2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005.10.28 16:25:44 | 000,094,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2005.08.06 01:07:30 | 000,061,440 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe


========== Modules (No Company Name) ==========

MOD - [2012.08.17 14:58:38 | 009,465,032 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
MOD - [2012.02.17 20:40:08 | 001,911,768 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011.10.17 19:08:13 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_f5e82abf\mscorlib.dll
MOD - [2011.10.17 19:08:01 | 000,835,584 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_dd213123\system.drawing.dll
MOD - [2011.10.17 19:07:05 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_d3fcdcd5\system.xml.dll
MOD - [2011.10.17 19:06:51 | 003,018,752 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_bb70cc20\system.windows.forms.dll
MOD - [2011.10.17 19:06:20 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_557eed5a\system.dll
MOD - [2011.10.17 19:05:21 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2011.10.17 19:05:17 | 001,265,664 | ---- | M] () -- c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
MOD - [2010.06.13 22:02:16 | 000,771,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\2077ce69bd24a095dd54683ae26454d4\System.Runtime.Remoting.ni.dll
MOD - [2010.06.13 21:58:05 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll
MOD - [2010.06.13 21:57:35 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll
MOD - [2010.06.13 21:57:33 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5adb0f89d469632511aed9d88cfe05c4\System.ServiceProcess.ni.dll
MOD - [2010.06.13 21:57:27 | 007,949,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll
MOD - [2009.10.17 13:15:08 | 011,486,720 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll
MOD - [2009.06.14 15:06:40 | 000,040,960 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_cs_b03f5f7f11d50a3a\System.ServiceProcess.resources.dll
MOD - [2007.12.02 14:37:18 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2007.12.02 14:37:18 | 000,372,736 | ---- | M] () -- c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
MOD - [2007.12.02 14:37:17 | 000,466,944 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2007.12.02 14:37:17 | 000,323,584 | ---- | M] () -- c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
MOD - [2007.12.02 14:37:16 | 002,052,096 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2007.02.23 17:11:47 | 000,229,376 | ---- | M] () -- c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_cs_b77a5c561934e089\mscorlib.resources.dll
MOD - [2007.02.23 17:11:47 | 000,180,224 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms.resources\1.0.5000.0_cs_b77a5c561934e089\system.windows.forms.resources.dll
MOD - [2007.02.23 17:11:47 | 000,081,920 | ---- | M] () -- c:\windows\assembly\gac\system.resources\1.0.5000.0_cs_b77a5c561934e089\system.resources.dll
MOD - [2006.10.31 17:53:00 | 000,270,336 | ---- | M] () -- C:\Program Files\Canon\SELPHY Photo Print\EnoJPEG4.dll
MOD - [2001.07.26 11:27:28 | 000,024,576 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan LTX\hpgihps.dll
MOD - [1998.06.11 20:08:06 | 000,095,232 | ---- | M] () -- C:\WINDOWS\system32\Lfkodak.dll
MOD - [1998.06.11 20:08:04 | 000,306,688 | ---- | M] () -- C:\WINDOWS\system32\Lffpx7.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Plánovač automatické aktualizace LiveUpdate)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2012.12.14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.12.14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.06.16 03:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe -- (NIS)
SRV - [2011.06.28 20:28:06 | 000,496,128 | ---- | M] (Crawler.com) [Auto | Running] -- C:\Program Files\Spyware Terminator\sp_rsser.exe -- (sp_rssrv)
SRV - [2010.03.18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010.02.19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.03.31 09:39:36 | 000,233,472 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2008.11.07 20:38:26 | 000,025,824 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe -- (MemeoBackgroundService)
SRV - [2008.04.07 09:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2007.08.13 17:17:40 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2003.03.09 21:31:02 | 000,065,795 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\MOBILE~1\bin\SPAInfoDrv.sys -- (SPAInfoDrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDRm.sys -- (InCDRm)
DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDPass.sys -- (InCDPass)
DRV - File not found [File_System | Disabled | Stopped] -- system32\drivers\InCDFs.sys -- (InCDFs)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\MediaCoder\SysInfo.sys -- (CrystalSysInfo)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\IVONA~2.DOM\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (asw8ve1m)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\adiusbaw.sys -- (adiusbaw)
DRV - File not found [Kernel | Auto | Stopped] -- System32\Drivers\adildr.sys -- (ADILOADER)
DRV - [2013.01.14 16:32:51 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2012.12.14 16:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.07.06 03:17:57 | 000,574,112 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NIS\1309000.009\srtsp.sys -- (SRTSP)
DRV - [2012.07.06 03:17:57 | 000,032,928 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1309000.009\srtspx.sys -- (SRTSPX)
DRV - [2012.06.07 05:43:43 | 000,132,768 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1309000.009\ccsetx86.sys -- (ccSet_NIS)
DRV - [2012.05.22 02:37:12 | 000,924,320 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\NIS\1309000.009\symefa.sys -- (SymEFA)
DRV - [2012.04.18 03:13:32 | 000,388,216 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1309000.009\symtdi.sys -- (SYMTDI)
DRV - [2012.04.18 02:42:14 | 000,149,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NIS\1309000.009\ironx86.sys -- (SymIRON)
DRV - [2012.03.25 19:43:20 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011.11.14 20:28:02 | 000,819,320 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20111123.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2011.11.12 15:58:01 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20111209.003\NAVEX15.SYS -- (NAVEX15)
DRV - [2011.11.12 15:57:59 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20111209.003\NAVENG.SYS -- (NAVENG)
DRV - [2011.11.12 15:57:58 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011.11.12 15:57:58 | 000,106,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011.11.11 16:47:24 | 000,356,280 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20111208.001\IDSXpx86.sys -- (IDSxpx86)
DRV - [2011.07.26 03:18:36 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\NIS\1309000.009\symds.sys -- (SymDS)
DRV - [2011.06.28 20:28:03 | 000,142,592 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys -- (sp_rsdrv2)
DRV - [2010.02.08 10:45:06 | 000,019,328 | ---- | M] (WiFi Media Connect) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wfmcvad.sys -- (WFMC_VAD)
DRV - [2009.11.22 17:05:58 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2009.03.31 09:39:36 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009.03.20 10:01:26 | 000,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2009.03.20 10:01:26 | 000,090,112 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bbus.sys -- (ss_bbus)
DRV - [2009.03.20 10:01:26 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys -- (ss_bmdfl)
DRV - [2008.04.13 19:46:22 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE)
DRV - [2007.09.17 15:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007.07.28 10:50:36 | 000,517,632 | R--- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt2870.sys -- (rt2870)
DRV - [2006.04.07 16:06:38 | 000,038,496 | ---- | M] (OLYMPUS IMAGING CORP.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VNUSB.sys -- (VNUSB)
DRV - [2006.03.18 03:24:59 | 000,026,844 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2005.08.04 04:10:18 | 001,273,344 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005.05.04 10:18:26 | 002,951,680 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2004.12.03 14:55:12 | 000,969,728 | ---- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\3xHybrid.sys -- (3xHybrid)
DRV - [2004.08.13 03:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004.04.28 10:30:02 | 000,078,848 | ---- | M] (Siemens AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\actvcomm.sys -- (actvcomm)
DRV - [2004.03.08 11:55:50 | 000,013,567 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)
DRV - [2004.01.28 13:11:02 | 000,022,912 | ---- | M] (Siemens AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\actser.sys -- (actser)
DRV - [2003.05.07 17:07:58 | 000,041,472 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2002.11.11 19:52:54 | 000,006,400 | ---- | M] (Pinnacle Systems) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pctvvbi.sys -- (pctvvbi)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchT ... urceid=ie7


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Bar = http://google.icq.com/search/search_frame.php
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://google.icq.com
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\${searchCLSID}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... orm=IE8SRC
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" = http://www.crawler.com/search/dispatche ... tbid=60076
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://www.icq.com/search/results.php?q ... &ch_id=osd
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchT ... urceid=ie7
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{88C19A03-DC0C-424D-B538-A846A8891C48}: "URL" = http://search.yahoo.com/search?p={searc ... 8&fr=b1ie7
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{BE9654C9-9D79-42ec-B55A-3CAEB12DBF58}: "URL" = http://www.icq.com/search/result.php?q= ... &ch_id=osd
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{D6A8875F-7916-4732-B6B4-BA0FB5CF0C07}: "URL" = http://www.heureka.cz/?h[fraze]={searchTerms}
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledAddons: {b2509cd4-17cd-45ed-8146-a82af038f493}:2.02
FF - prefs.js..extensions.enabledAddons: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20120910
FF - prefs.js..extensions.enabledAddons: smarterwiki@wikiatic.com:5.0.9
FF - prefs.js..extensions.enabledAddons: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:5.0.3
FF - prefs.js..extensions.enabledAddons: {ea614400-e918-4741-9a97-7a972ff7c30b}:2.5.12
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.0
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.0
FF - prefs.js..extensions.enabledItems: {b2509cd4-17cd-45ed-8146-a82af038f493}:1.60
FF - prefs.js..extensions.enabledItems: gmailbutton@mozdeveloper.com:0.1
FF - prefs.js..extensions.enabledItems: smarterwiki@wikiatic.com:4.3.5
FF - prefs.js..extensions.enabledItems: fastYoutubeDownloader@yevgenyandrov.net:1.2.2
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110323
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.1.400
FF - prefs.js..extensions.enabledItems: {340c2bbc-ce74-4362-90b5-7c26312808ef}:1.7
FF - prefs.js..extensions.enabledItems: {ea614400-e918-4741-9a97-7a972ff7c30b}:2.1.14
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: KavAntiBanner@Kaspersky.ru:11.0.1.400
FF - prefs.js..keyword.URL: "http://search.seznam.cz/?sourceid=FFlisticka_1&q="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files\ArcSoft\Media Converter for Philips\Internet Video Downloader\Plugin_FireFox [2009.06.22 12:39:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPlgn\ [2011.11.12 16:24:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\ [2013.01.19 16:50:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.02.17 20:40:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.10.10 20:51:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{92ef1ad0-8b11-11db-b606-0800200c9a66}: C:\Program Files\FileFactory Turbo\Plugins\Firefox

[2010.07.31 21:31:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Extensions
[2009.06.23 14:55:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Extensions\MediaCoder
[2009.06.20 13:07:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Extensions\postbox@postbox-inc.com
[2013.01.14 20:25:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\extensions
[2010.08.03 19:26:42 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.10.14 19:46:51 | 000,000,000 | ---D | M] (WOT) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013.01.14 20:25:45 | 000,000,000 | ---D | M] (Seznam lištiÄŤka) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[2010.07.31 21:58:56 | 000,000,000 | ---D | M] (Fast Youtube Downloader) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\extensions\fastYoutubeDownloader@yevgenyandrov.net
[2010.07.31 21:59:14 | 000,000,000 | ---D | M] ("Gmail Button") -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\extensions\gmailbutton@mozdeveloper.com
[2012.12.03 19:57:06 | 000,363,832 | ---- | M] () (No name found) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\extensions\smarterwiki@wikiatic.com.xpi
[2012.12.09 11:43:36 | 000,109,804 | ---- | M] () (No name found) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
[2012.01.15 20:57:34 | 000,038,752 | ---- | M] () (No name found) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\extensions\{b2509cd4-17cd-45ed-8146-a82af038f493}.xpi
[2012.08.31 17:11:03 | 000,199,396 | ---- | M] () (No name found) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2010.10.31 20:34:01 | 000,002,051 | ---- | M] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\searchplugins\firmycz.xml
[2010.10.31 20:34:01 | 000,002,046 | ---- | M] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\searchplugins\mapycz.xml
[2010.10.31 20:34:04 | 000,002,212 | ---- | M] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\searchplugins\zbocz.xml
[2012.02.17 20:41:00 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.06.12 21:13:24 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\Program Files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
[2011.03.26 22:30:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\distribution\extensions
[2011.03.26 22:30:44 | 000,000,000 | ---D | M] (Seznam lištička) -- C:\Program Files\Mozilla Firefox\distribution\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVONA.DOMA-QO9I0VR7RQ\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\1X8KOTTW.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVONA.DOMA-QO9I0VR7RQ\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\1X8KOTTW.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVONA.DOMA-QO9I0VR7RQ\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\1X8KOTTW.DEFAULT\EXTENSIONS\{B2509CD4-17CD-45ED-8146-A82AF038F493}.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVONA.DOMA-QO9I0VR7RQ\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\1X8KOTTW.DEFAULT\EXTENSIONS\{EA614400-E918-4741-9A97-7A972FF7C30B}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVONA.DOMA-QO9I0VR7RQ\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\1X8KOTTW.DEFAULT\EXTENSIONS\SMARTERWIKI@WIKIATIC.COM.XPI
[2012.02.17 20:40:09 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.11.10 05:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012.02.17 20:40:05 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2012.02.17 20:40:05 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2012.02.17 20:40:05 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2012.02.17 20:40:05 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2012.02.17 20:40:05 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

========== Chrome ==========

CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.seznam.cz/
CHR - Extension: Google Translate = C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\1.2.3.1\

O1 HOSTS File: ([2012.12.17 20:15:46 | 000,000,727 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files\ArcSoft\Media Converter for Philips\Internet Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
O2 - BHO: (WebTransBHO Class) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\TRANSLAT\WEBIE.DLL ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll File not found
O2 - BHO: (no name) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - No CLSID value found.
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.9.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {E33CF602-D945-461A-83F0-819F76A199F8} - No CLSID value found.
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Alive Text to Speech) - {954F618B-0DEC-4D1A-9317-E0FC96F87865} - C:\Program Files\AliveMedia\Text to Speech\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (WebTranslator) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\TRANSLAT\WEBIE.DLL ()
O3 - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.9.0.9\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-21-1993962763-606747145-725345543-1003..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\S-1-5-21-1993962763-606747145-725345543-1003..\Run: [MagicSpeedBooster] C:\Program Files\Smart PC Solutions\Magic Speed\MagicSpeedBooster.exe (MSBoost)
O4 - HKU\S-1-5-21-1993962763-606747145-725345543-1003..\Run: [Sexmxe] C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Sexmxe.exe File not found
O4 - HKU\S-1-5-21-1993962763-606747145-725345543-1003..\Run: [SpywareTerminatorUpdate] C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe (Crawler.com)
O4 - HKU\S-1-5-21-1993962763-606747145-725345543-1003..\Run: [WINSXS32] C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe (PowerBASIC, Inc.)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění\Hlavní panel ATI CATALYST.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění\SELPHY Photo Print Launcher.lnk = C:\Program Files\Canon\SELPHY Photo Print\CIC_SPPhelper.exe (Canon Inc.)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění\Wi-Fi MediaConnect.lnk = C:\Program Files\Philips\Wi-Fi MediaConnect\Wi-Fi MediaConnect.exe (Koninklijke Philips Electronics N.V.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: WikiKomentáře Google... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\TRANSLAT\WEBIE.DLL ()
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra Button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\TRANSLAT\WEBIE.DLL ()
O9 - Extra 'Tools' menuitem : Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\TRANSLAT\WEBIE.DLL ()
O9 - Extra 'Tools' menuitem : Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\TRANSLAT\WEBIE.DLL ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupda ... 5008663953 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/Shar ... /cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crl ... crlocx.ocx (CRLDownloadWrapper Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CE0B4D3F-F867-4F9A-97D8-0037FA9CE3CC}: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D1634E7C-F26E-4E0E-9269-48492DE51CB4}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\Userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - File not found
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.05.05 14:53:10 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2012.12.09 12:11:42 | 000,000,000 | RHSD | M] - C:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012.12.09 12:11:44 | 000,000,000 | ---D | M] - G:\Autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2009.04.06 16:50:20 | 000,000,000 | -HSD | M] - G:\autorun -- [ FAT32 ]
O32 - AutoRun File - [2009.04.06 16:50:20 | 000,000,000 | -HSD | M] - G:\autorun -- [ FAT32 ]
O32 - AutoRun File - [2012.12.09 12:11:44 | 000,000,000 | ---D | M] - H:\Autorun.inf -- [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: VIDC.MJPG - C:\WINDOWS\System32\Pvmjpg21.dll (Pegasus Imaging Corporation)
Drivers32: VIDC.PIM1 - PCLEPIM1.dll File not found
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2013.01.15 20:24:39 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Plocha\OTL.exe
[2013.01.15 20:14:58 | 000,318,976 | ---- | C] (PowerBASIC, Inc.) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\3.exe
[2013.01.14 20:21:39 | 000,318,976 | ---- | C] (PowerBASIC, Inc.) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe
[2013.01.14 16:32:51 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\*.tmp files -> C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2013.01.19 17:32:01 | 000,001,058 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-606747145-725345543-1003UA.job
[2013.01.19 17:22:01 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{7CB0F1A3-DCEE-4579-A3BA-497C7A6601B5}.job
[2013.01.19 17:21:15 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013.01.19 16:50:52 | 000,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.01.19 16:50:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.01.15 20:26:47 | 000,000,424 | ---- | M] () -- C:\WINDOWS\TRNCOM.INI
[2013.01.15 20:25:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Plocha\OTL.exe
[2013.01.15 20:14:59 | 000,318,976 | ---- | M] (PowerBASIC, Inc.) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\3.exe
[2013.01.14 20:44:48 | 000,000,229 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2013.01.14 20:21:40 | 000,318,976 | ---- | M] (PowerBASIC, Inc.) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe
[2013.01.14 16:32:51 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\*.tmp files -> C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013.01.15 21:09:10 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.12.11 20:46:09 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012.12.11 20:46:09 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012.12.11 20:46:09 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012.12.11 20:46:09 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012.12.11 20:46:09 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012.08.24 19:56:45 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2011.10.15 19:16:24 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\I1kIfJMHH0fH
[2011.08.29 12:43:55 | 000,210,944 | ---- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\chrtmp
[2011.06.28 20:28:02 | 000,142,592 | ---- | C] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2011.06.09 20:41:58 | 000,000,424 | ---- | C] () -- C:\WINDOWS\TRNCOM.INI
[2010.06.22 20:38:57 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\.33a11c88
[2010.06.16 19:17:40 | 000,000,448 | ---- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\com.remotehd.RemoteHelper.plist
[2009.12.25 20:47:31 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\$_hpcst$.hpc
[2009.12.20 21:22:30 | 000,000,010 | -HS- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Local Settings\Data aplikací\systemCurUses
[2009.12.20 21:22:25 | 000,000,006 | -HS- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Local Settings\Data aplikací\systemHdID
[2009.07.01 15:11:43 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Local Settings\Data aplikací\PUTTY.RND
[2009.07.01 12:28:04 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\winscp.rnd
[2007.04.05 15:26:50 | 000,000,064 | ---- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\default.pls
[2007.03.05 17:30:01 | 000,041,472 | ---- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.02.23 17:31:24 | 000,000,141 | ---- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Local Settings\Data aplikací\fusioncache.dat

========== ZeroAccess Check ==========

[2007.02.23 17:10:47 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 04:21:55 | 001,499,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.02.09 11:56:05 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008.04.14 04:22:05 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2006.05.06 13:33:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Autodesk
[2006.05.08 13:12:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg7
[2006.05.05 15:43:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Grisoft
[2011.04.12 20:33:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AVG10
[2012.08.16 12:56:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\boost_interprocess
[2009.09.15 19:16:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Boss Media
[2012.08.24 19:56:45 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\CanonCP
[2011.04.12 20:25:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Common Files
[2009.11.22 17:04:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\DAEMON Tools Lite
[2010.08.03 20:08:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\f-secure
[2010.05.07 20:17:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\fssg
[2009.07.19 18:49:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\ICQ
[2009.11.13 14:08:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\MemeoCommon
[2011.04.12 20:37:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\MFAData
[2009.12.26 12:54:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\PC Suite
[2010.02.10 13:26:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\PCSettings
[2010.05.01 20:41:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Rapidshare Search Tool
[2010.07.06 19:30:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\regid.1986-12.com.adobe
[2012.01.06 20:59:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Spyware Terminator
[2010.07.19 20:53:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
[2011.02.20 15:27:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\tmp
[2007.12.04 13:50:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\VCOM
[2010.05.10 21:41:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009.09.12 19:01:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.06.05 12:31:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2006.11.05 12:53:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona\Data aplikací\.ABC 3.01
[2006.11.07 17:03:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona\Data aplikací\AVG7
[2006.10.17 15:53:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona\Data aplikací\BSplayer Pro
[2006.10.17 16:10:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona\Data aplikací\InterTrust
[2006.10.17 13:45:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona\Data aplikací\Thunderbird
[2006.11.12 13:41:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona\Data aplikací\uTorrent
[2006.11.03 16:50:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona\Data aplikací\Vso
[2007.04.12 14:50:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Ashampoo
[2009.11.04 20:27:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Autograph
[2009.06.25 13:11:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Broad Intelligence
[2011.02.02 22:00:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\BSplayer Pro
[2012.11.28 16:32:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\calibre
[2012.08.25 14:05:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Canon
[2010.02.06 19:53:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\DAEMON Tools Lite
[2010.03.15 14:11:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Desktopicon
[2007.08.25 13:18:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Digital Dutch
[2011.04.12 20:03:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\DVDVideoSoft
[2010.07.27 19:32:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\F-Secure
[2008.02.02 14:09:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\FFSJ
[2007.04.25 11:24:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\FileFactory Turbo
[2010.03.04 21:56:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\GetRightToGo
[2009.08.23 18:46:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Happy Foto
[2011.09.20 16:23:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\ICQ
[2007.05.03 17:43:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\ICQ Toolbar
[2007.03.30 16:44:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\ICQLite
[2007.04.05 17:17:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Image Zone Express
[2010.02.17 21:23:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Irido
[2009.11.13 13:53:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Memeo
[2008.02.20 16:52:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\MenuShrink
[2010.05.09 19:26:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Moyea
[2007.06.24 14:18:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\OLYMPUS
[2009.10.18 11:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Participatory Culture Foundation
[2009.12.25 21:23:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\PC Suite
[2011.09.17 20:34:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\PhotoFiltre Studio X
[2009.10.04 15:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Postbox
[2007.04.05 17:17:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Printer Info Cache
[2010.06.26 21:01:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\RemoteHelper
[2009.01.04 14:07:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\River Past G5
[2009.12.25 20:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Samsung
[2010.07.19 20:08:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Smart PC Solutions
[2012.11.15 20:18:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Spyware Terminator
[2010.08.16 19:49:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\The Bat!
[2007.03.27 17:26:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Thunderbird
[2010.02.20 21:03:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Tific
[2010.04.25 20:46:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\uTorrent
[2007.12.04 13:50:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\VCOM
[2012.04.23 20:18:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Vso
[2011.08.04 20:42:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\WebSurf.ru
[2006.05.05 15:43:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
[2006.09.14 17:09:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService.NT AUTHORITY\Data aplikací\AVG7
[2006.10.17 14:30:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService.NT AUTHORITY.000\Data aplikací\AVG7

========== Purity Check ==========



========== Custom Scans ==========

< >
[2007.02.21 16:32:39 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2007.02.21 16:34:29 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2007.03.01 16:38:35 | 000,000,342 | ---- | C] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1172763280.job
[2009.11.16 18:10:56 | 000,001,058 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-606747145-725345543-1003UA.job
[2010.07.07 19:41:11 | 000,000,342 | ---- | C] () -- C:\WINDOWS\Tasks\AdobeAAMUpdater-1.0-DOMA-QO9I0VR7RQ-Ivona.job
[2010.07.09 19:49:20 | 000,000,466 | -H-- | C] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{7CB0F1A3-DCEE-4579-A3BA-497C7A6601B5}.job
[2011.10.10 20:48:08 | 000,000,284 | ---- | C] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

< >

< MD5 for: ATAPI.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\31926ee518054421a61b\i386\sp2.cab:atapi.sys
[2003.04.16 13:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.10.26 13:56:59 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008.10.26 13:56:59 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2003.04.16 13:00:00 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0091\DriverFiles\i386\atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0092\DriverFiles\i386\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\31926ee518054421a61b\i386\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe

< MD5 for: CDROM.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\31926ee518054421a61b\i386\sp2.cab:cdrom.sys
[2003.04.16 13:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:cdrom.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.10.26 13:56:59 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:cdrom.sys
[2008.10.26 13:56:59 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2009.12.22 19:39:20 | 000,062,592 | ---- | M] (Microsoft Corporation) MD5=7B53584D94E9D8716B2DE91D5F1CB42D -- C:\WINDOWS\system32\dllcache\cdrom.sys
[2004.08.03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007.06.13 14:11:59 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=9B32416BD5988C97B6397CE0B02CAF97 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007.06.13 14:23:39 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=ED7B460B142A32097B8A8F6ECC941815 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: HAL.DLL >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\31926ee518054421a61b\i386\sp2.cab:hal.dll
[2003.04.16 13:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:hal.dll
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.10.26 13:56:59 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:hal.dll
[2008.10.26 13:56:59 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.13 19:31:28 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.13 19:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2004.08.03 22:59:14 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll

< MD5 for: SCECLI.DLL >
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2009.02.09 12:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2004.08.17 15:49:28 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=6E401E61F952FBBF708AFBECEFAFAE81 -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\services.exe
[2008.04.14 04:22:45 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008.04.14 04:22:45 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\ServicePackFiles\i386\services.exe

< MD5 for: SVCHOST.EXE >
[2012.12.14 16:49:28 | 000,216,424 | ---- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.06.20 11:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2007.10.30 17:53:32 | 000,360,832 | ---- | M] (Microsoft Corporation) MD5=64798ECFA43D78C7178375FCDD16D8C8 -- C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[2008.06.20 11:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2007.10.30 18:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2006.04.20 13:18:35 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[2006.04.20 12:51:50 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=B4E29943B4B04BD5E7381546848E6669 -- C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 10:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012.12.14 16:49:28 | 000,216,424 | ---- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 04:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< >

< %systemroot%*.* /U /s >
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[11 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[12 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[4 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >
[2009.09.30 19:02:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Office Genuine Advantage
[2009.01.04 14:48:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{C47EC3A5-D5BD-40F0-80E0-F8BEFF9D776F}

< %ALLUSERSPROFILE%\Application Data\*.exe /s >
[2005.02.10 23:04:33 | 002,040,218 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{C47EC3A5-D5BD-40F0-80E0-F8BEFF9D776F}\setup_bmc.exe
[2005.02.10 23:03:29 | 001,757,184 | ---- | M] (Mystik Media) -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{C47EC3A5-D5BD-40F0-80E0-F8BEFF9D776F}\offline\IFYTMEALEMICVEBCEFARETIRFFFFFF0\BMC.exe

Re: prosba o kontrolu logu

Napsal: 19 led 2013 20:39
od Ivon
log OTL pokračování:
< %APPDATA%\*. >
[2010.07.05 20:12:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Adobe
[2007.03.06 16:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\AdobeUM
[2007.04.05 15:26:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Ahead
[2010.07.23 20:25:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Apple Computer
[2009.06.22 12:48:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\ArcSoft
[2007.04.12 14:50:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Ashampoo
[2007.02.23 17:31:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\ATI
[2009.11.04 20:27:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Autograph
[2009.06.25 13:11:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Broad Intelligence
[2011.02.02 22:00:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\BSplayer Pro
[2012.11.28 16:32:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\calibre
[2012.08.25 14:05:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Canon
[2009.10.03 16:18:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\CyberLink
[2010.02.06 19:53:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\DAEMON Tools Lite
[2010.03.15 14:11:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Desktopicon
[2007.08.25 13:18:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Digital Dutch
[2011.04.12 20:03:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\DVDVideoSoft
[2009.11.22 17:24:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\ESTsoft
[2010.07.27 19:32:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\F-Secure
[2008.02.02 14:09:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\FFSJ
[2007.04.25 11:24:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\FileFactory Turbo
[2010.03.04 21:56:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\GetRightToGo
[2009.11.08 17:44:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Google
[2009.08.23 18:46:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Happy Foto
[2007.04.08 17:09:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Help
[2007.03.01 16:38:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Hewlett-Packard
[2011.09.20 16:23:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\ICQ
[2007.05.03 17:43:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\ICQ Toolbar
[2007.03.30 16:44:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\ICQLite
[2011.09.17 20:34:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Identities
[2007.04.05 17:17:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Image Zone Express
[2009.06.22 12:32:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\InstallShield
[2010.02.17 21:23:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Irido
[2009.05.06 16:42:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Macromedia
[2012.12.21 14:49:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Malwarebytes
[2009.11.13 13:53:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Memeo
[2008.02.20 16:52:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\MenuShrink
[2011.09.13 16:09:09 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Microsoft
[2010.05.09 19:26:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Moyea
[2009.06.20 13:07:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla
[2009.06.24 12:57:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Nero
[2007.06.24 14:18:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\OLYMPUS
[2007.11.30 17:33:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\OpenOffice.org2
[2009.10.18 11:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Participatory Culture Foundation
[2009.12.25 21:23:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\PC Suite
[2011.09.17 20:34:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\PhotoFiltre Studio X
[2009.10.04 15:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Postbox
[2007.04.05 17:17:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Printer Info Cache
[2010.06.26 21:01:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\RemoteHelper
[2009.01.04 14:07:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\River Past G5
[2009.12.25 20:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Samsung
[2007.06.04 16:27:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Skype
[2010.07.19 20:08:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Smart PC Solutions
[2012.11.15 20:18:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Spyware Terminator
[2009.05.19 19:17:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Sun
[2007.03.27 17:26:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Talkback
[2010.08.16 19:49:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\The Bat!
[2007.03.27 17:26:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Thunderbird
[2010.02.20 21:03:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Tific
[2010.04.25 20:46:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\uTorrent
[2007.12.04 13:50:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\VCOM
[2012.04.23 20:18:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Vso
[2011.08.04 20:42:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\WebSurf.ru
[2010.02.27 20:43:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\WinRAR

< %APPDATA%\*.exe /s >
[2013.01.14 20:21:40 | 000,318,976 | ---- | M] (PowerBASIC, Inc.) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe
[1 C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\*.tmp files -> C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\*.tmp -> ]
[2009.11.14 21:47:14 | 000,031,836 | ---- | M] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Desktopicon\uninst.exe
[2007.05.12 14:19:32 | 000,026,694 | R--- | M] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\ARPPRODUCTICON.exe
[2007.05.12 14:19:32 | 000,026,694 | R--- | M] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
[2007.05.12 14:19:32 | 000,026,694 | R--- | M] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
[2007.05.12 14:19:32 | 000,026,694 | R--- | M] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\UNINST_Uninstall_G_3DE5E7D47B88403CA3FD2017A8240C5B.exe
[2011.04.12 20:38:43 | 000,388,096 | R--- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
[2010.10.14 14:25:55 | 000,749,568 | ---- | M] (WebSurf.ru Russian Autosurf) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\WebSurf.ru\WebSurf.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job >
[2011.11.05 02:00:00 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\AdobeAAMUpdater-1.0-DOMA-QO9I0VR7RQ-Ivona.job
[2011.10.10 20:48:08 | 000,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2007.03.27 16:56:24 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1172763280.job
[2013.01.19 17:32:01 | 000,001,058 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-606747145-725345543-1003UA.job
[2013.01.19 17:52:59 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{7CB0F1A3-DCEE-4579-A3BA-497C7A6601B5}.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009.11.22 17:05:58 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2007.02.21 17:26:14 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2007.02.21 17:26:14 | 000,630,784 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2007.02.21 17:26:13 | 000,421,888 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2013.01.19 16:50:52 | 000,002,422 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 04:22:17 | 000,015,360 | ---- | M] (Microsoft Corporation)
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" -- [2005.10.28 16:25:44 | 000,094,208 | ---- | M] (Nero AG)
"MagicSpeedBooster" = C:\Program Files\Smart PC Solutions\Magic Speed\MagicSpeedBooster.exe -- [2009.05.05 13:28:08 | 000,192,784 | ---- | M] (MSBoost)
"swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -- [2009.11.08 14:29:48 | 000,039,408 | ---- | M] (Google Inc.)
"MSMSGS" = "C:\Program Files\Messenger\msmsgs.exe" /background -- [2008.04.14 04:22:36 | 001,695,232 | ---- | M] (Microsoft Corporation)
"SpywareTerminatorUpdate" = "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe" -- [2011.06.28 20:28:26 | 003,318,784 | ---- | M] (Crawler.com)
"Sexmxe" = C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Sexmxe.exe -- File not found
"WINSXS32" = C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe -- [2013.01.14 20:21:40 | 000,318,976 | ---- | M] (PowerBASIC, Inc.)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]
"" =

< >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2012.02.17 20:40:08 | 000,924,632 | ---- | M] (Mozilla Corporation) MD5=5AC757AE411CBC603C33C85F81F8657D -- C:\Program Files\Mozilla Firefox\firefox.exe

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2009.03.08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\Program Files\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Opera\opera.exe /md5 >

< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.01.19 17:21:15 | 000,000,512 | ---- | M] () MD5=25F3296C08E24215EE4A3825A578326F -- C:\PhysicalMBR.bin
[1 C:\*.tmp files -> C:\*.tmp -> ]

< >

< *crack* /s >
[2007.07.04 16:18:23 | 000,001,745 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\uTorrent\ChrisTV.v4.99.Pro.Multi.Incl.Crack-BetaMaster.rar.torrent
[2009.07.02 15:28:25 | 077,282,402 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Dokumenty\Hudba\iTunes\Mobile Applications\Castle Of Magic 1.0.1.cracked-COREPDA.ipa
[2011.09.03 20:03:49 | 000,023,446 | ---- | M] () -- \WINDOWS\Prefetch\NIS-2012-CRACK.EXE-05042546.pf
[2011.08.29 12:43:19 | 000,035,562 | ---- | M] () -- \WINDOWS\Prefetch\NIS-2012-CRACK.EXE-0CBA8DDB.pf
[2006.05.23 15:00:12 | 000,513,024 | ---- | M] () -- \WINDOWS\system32\LegitCheckControl.dll.wgacracked
[2006.06.02 16:34:42 | 000,000,101 | ---- | M] () -- \WINDOWS\system32\wgacracked.txt
[2001.10.26 19:27:00 | 000,003,584 | ---- | M] () -- \WINDOWS\system32\wgalogon.dll.wgacracked
[2001.10.26 19:29:54 | 000,003,584 | ---- | M] () -- \WINDOWS\system32\WgaTray.exe.wgacracked
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]

< *keygen* /s >
[2010.11.08 14:37:10 | 000,000,584 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Cookies\ivona@keygens[2].txt
[2007.04.03 14:21:41 | 000,000,188 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\uTorrent\Windows XP Keygen.exe.torrent

< *loader* /s >
[2004.08.17 15:49:06 | 000,017,423 | ---- | M] () -- \31926ee518054421a61b\i386\dmloader.dl_
[2004.08.03 22:59:38 | 000,115,153 | ---- | M] () -- \31926ee518054421a61b\i386\osloader.ex_
[2004.08.03 22:59:38 | 000,132,757 | ---- | M] () -- \31926ee518054421a61b\i386\osloader.nt_
[2010.01.31 20:20:19 | 000,000,052 | ---- | M] () -- \Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\MajorShare.com\Rapid Share Downloader on the Web.url
[2010.01.31 20:20:17 | 000,000,437 | ---- | M] () -- \Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\MajorShare.com\Rapid Share Downloader.lnk
[2010.01.31 20:20:19 | 000,000,450 | ---- | M] () -- \Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\MajorShare.com\Uninstall Rapid Share Downloader.lnk
[2009.06.22 12:40:08 | 000,002,018 | ---- | M] () -- \Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Media Converter for Philips\Internet Video Downloader.lnk
[2009.11.23 00:04:44 | 000,000,576 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\Mozilla\Firefox\Profiles\1x8kottw.default\extensions\fastYoutubeDownloader@yevgenyandrov.net\chrome\locale\en-US\fastYoutubeDownloader.dtd
[2010.02.19 06:33:14 | 000,002,713 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\WebSurf.ru\components\uriloader.xpt
[2012.01.17 21:20:03 | 000,000,000 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Local Settings\Temporary Internet Files\Content.IE5\BCKBXJSC\_4d722d92_Procitnuti.Gabriely.TVrip.CZ.by.mota.of.PowerUploaders[1].avi
[2010.01.30 20:22:35 | 000,000,358 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Nabídka Start\Programy\JDownloader\JDownloader Support.lnk
[2010.01.30 20:22:30 | 000,000,628 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Nabídka Start\Programy\JDownloader\JDownloader.lnk
[2010.01.30 20:23:05 | 000,000,622 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Nabídka Start\Programy\JDownloader\Uninstall JDownloader.lnk
[2009.12.18 14:16:58 | 000,000,632 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Nabídka Start\Programy\YouTube Downloader\YouTube Downloader Help.lnk
[2009.12.18 14:16:58 | 000,000,701 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Nabídka Start\Programy\YouTube Downloader\YouTube Downloader.lnk
[2010.01.30 20:22:37 | 000,000,572 | ---- | M] () -- \Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Plocha\JDownloader.lnk
[2009.03.11 16:20:40 | 000,375,296 | ---- | M] () -- \Program Files\ArcSoft\Media Converter for Philips\Internet Video Downloader\VideoDownloader.exe
[2008.12.24 16:42:36 | 000,001,086 | ---- | M] () -- \Program Files\ArcSoft\Media Converter for Philips\Internet Video Downloader\VideoDownloader.set
[2012.11.23 02:32:12 | 000,044,032 | R--- | M] () -- \Program Files\Calibre2\DLLs\PyISAPI_loader.dll
[2007.03.14 16:10:18 | 000,088,333 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\ar_AE\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:20 | 000,025,188 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\cs_CZ\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:26 | 000,032,022 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\da_DK\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:28 | 000,032,216 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\de_DE\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:30 | 000,027,655 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\el_GR\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:36 | 000,030,891 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\en_US\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:38 | 000,032,399 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\es_ES\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:42 | 000,032,333 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\fi_FI\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:42 | 000,032,393 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\fr_FR\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:46 | 000,022,871 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\he_IL\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:48 | 000,025,272 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\hu_HU\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:50 | 000,032,109 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\it_IT\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:50 | 000,032,441 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\ja_JP\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:52 | 000,032,499 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\ko_KR\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:54 | 000,032,074 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\nb_NO\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:56 | 000,032,110 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\nl_NL\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:10:58 | 000,024,996 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\pl_PL\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:11:00 | 000,031,772 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\pt_BR\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:11:02 | 000,024,463 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\ro_RO\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:11:04 | 000,025,054 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\ru_RU\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:11:06 | 000,032,171 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\sv_SE\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:11:06 | 000,024,411 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\tr_TR\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:11:08 | 000,025,525 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\uk_UA\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:11:10 | 000,032,741 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\zh_CN\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 16:11:10 | 000,032,833 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\zh_TW\Bridge\2.0\images\br_photo_downloader.png
[2007.03.08 15:35:32 | 000,004,239 | ---- | M] () -- \Program Files\Common Files\Adobe\Startup Scripts CS3\Adobe Version Cue\VersionCueSDKLoader.jsx
[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.dll
[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.tlb
[2008.10.24 09:54:36 | 000,056,416 | ---- | M] () -- \Program Files\CyberLink\MediaShow4\Koan\pyloader.dll
[2008.10.24 09:54:46 | 002,184,488 | ---- | M] () -- \Program Files\CyberLink\MediaShow4\subsys\CES\CES_3DLoaderFBX.dll
[2008.10.24 09:54:50 | 000,019,984 | ---- | M] () -- \Program Files\CyberLink\MediaShow4\subsys\DataCenter\ImageLoader.kc
[2007.08.25 23:23:02 | 000,073,728 | ---- | M] () -- \Program Files\DVDVIDEOSOFT\Free Video to iPod Converter\HttpVideoDownloader.dll
[2010.12.14 10:54:22 | 000,166,400 | ---- | M] () -- \Program Files\Fotostar\Fotostar Offline client3\CWImageLoader0.dll
[2007.05.06 10:19:12 | 000,013,824 | ---- | M] () -- \Program Files\Google\Google Earth\apiloader.dll
[2010.04.20 20:38:48 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.1\imApp\theme\IMAGES\XtraPreloader\loader.jpg
[2010.04.20 20:38:47 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.1\imApp\theme\IMAGES\XtraPreloader\loader.swf
[2010.04.20 20:38:50 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.1\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png
[2010.04.20 20:38:48 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.1\imApp\theme\MUICoreLib\xtraLoader.swf
[2011.09.20 15:32:48 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.1\Xtraz\icq\content\icq_profile\preloader.html
[2011.09.20 15:32:54 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.1\Xtraz\icq\content\profile_forms\preloader.html
[2011.09.20 15:32:52 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.1\Xtraz\icq\content\profile_lightboxs\preloader.html
[2010.04.20 20:49:51 | 000,552,798 | ---- | M] () -- \Program Files\ICQ7.1\Xtraz\icq\theme\game_center\loaderBkg.png
[2010.07.01 20:35:20 | 000,252,600 | ---- | M] () -- \UsbFix\Quarantine\C\Recycler\S-1-5-21-1993962763-606747145-725345543-1003\Dc44\Kaspersky Internet Security 2011\prloader.dll.vir
[2010.07.01 20:06:16 | 000,000,673 | ---- | M] () -- \UsbFix\Quarantine\C\Recycler\S-1-5-21-1993962763-606747145-725345543-1003\Dc44\Kaspersky Internet Security 2011\Skin\images\wtb\loader.gif.vir
[2004.08.17 15:49:06 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll
[2004.08.03 22:59:38 | 000,230,400 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\osloader.exe
[2004.08.03 22:59:38 | 000,278,016 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\osloader.ntd
[2011.02.07 21:54:07 | 000,082,784 | ---- | M] () -- \WINDOWS\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2002.12.12 00:14:32 | 000,033,280 | ---- | M] () -- \WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmloader.dll
[2008.04.14 04:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll
[2008.04.13 19:31:47 | 000,230,912 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe
[2008.04.13 19:31:48 | 000,278,528 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd
[2008.04.14 04:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2010.10.22 12:43:22 | 000,012,532 | ---- | M] () -- \WINDOWS\system32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr

========== Files - Unicode (All) ==========
[2011.06.23 20:53:03 | 000,000,000 | ---D | M](C:\WINDOWS\System32\Ä?) -- C:\WINDOWS\System32\Ä粑
[2011.06.23 20:53:03 | 000,000,000 | ---D | M](C:\WINDOWS\system32\Ä?) -- C:\WINDOWS\system32\Ä粑
[2011.06.23 20:53:03 | 000,000,000 | ---D | C](C:\WINDOWS\System32\Ä?) -- C:\WINDOWS\System32\Ä粑
[2011.04.16 19:42:20 | 000,000,000 | ---D | M](C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\???????????????????????????????????????) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\䌠尺潄畣敭瑮⁳湡⁤敓瑴湩獧䅜汬唠敳獲圮义佄南䑜瑡⁡灡楬慫썣岭態灳牥歳⁹慌屢噁ㅐ
[2011.04.16 19:42:20 | 000,000,000 | ---D | M](C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\???????????????????????????????????????) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\䌠尺潄畣敭瑮⁳湡⁤敓瑴湩獧䅜汬唠敳獲圮义佄南䑜瑡⁡灡楬慫썣岭態灳牥歳⁹慌屢噁ㅐ
[2011.04.10 19:11:35 | 000,000,000 | ---D | M](C:\WINDOWS\System32\???????????????????????????????????????) -- C:\WINDOWS\System32\䌠尺潄畣敭瑮⁳湡⁤敓瑴湩獧䅜汬唠敳獲圮义佄南䑜瑡⁡灡楬慫썣岭態灳牥歳⁹慌屢噁ㅐ
[2011.04.10 19:11:35 | 000,000,000 | ---D | M](C:\WINDOWS\system32\???????????????????????????????????????\QB) -- C:\WINDOWS\system32\䌠尺潄畣敭瑮⁳湡⁤敓瑴湩獧䅜汬唠敳獲圮义佄南䑜瑡⁡灡楬慫썣岭態灳牥歳⁹慌屢噁ㅐ\QB
[2011.04.10 19:11:35 | 000,000,000 | ---D | M](C:\WINDOWS\system32\???????????????????????????????????????) -- C:\WINDOWS\system32\䌠尺潄畣敭瑮⁳湡⁤敓瑴湩獧䅜汬唠敳獲圮义佄南䑜瑡⁡灡楬慫썣岭態灳牥歳⁹慌屢噁ㅐ
[2011.04.10 19:11:34 | 000,000,000 | ---D | M](C:\WINDOWS\system32\???????????????????????????????????????\temp) -- C:\WINDOWS\system32\䌠尺潄畣敭瑮⁳湡⁤敓瑴湩獧䅜汬唠敳獲圮义佄南䑜瑡⁡灡楬慫썣岭態灳牥歳⁹慌屢噁ㅐ\temp
[2011.04.10 19:11:34 | 000,000,000 | ---D | C](C:\WINDOWS\System32\???????????????????????????????????????) -- C:\WINDOWS\System32\䌠尺潄畣敭瑮⁳湡⁤敓瑴湩獧䅜汬唠敳獲圮义佄南䑜瑡⁡灡楬慫썣岭態灳牥歳⁹慌屢噁ㅐ
(C:\WINDOWS\system32\Ä?) -- C:\WINDOWS\system32\Ä粑
(C:\WINDOWS\system32\???????????????????????????????????????) -- C:\WINDOWS\system32\䌠尺潄畣敭瑮⁳湡⁤敓瑴湩獧䅜汬唠敳獲圮义佄南䑜瑡⁡灡楬慫썣岭態灳牥歳⁹慌屢噁ㅐ
(C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\???????????????????????????????????????) -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\䌠尺潄畣敭瑮⁳湡⁤敓瑴湩獧䅜汬唠敳獲圮义佄南䑜瑡⁡灡楬慫썣岭態灳牥歳⁹慌屢噁ㅐ

========== Alternate Data Streams ==========

@Alternate Data Stream - 6144 bytes -> C:\WINDOWS\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:0295CBF7
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP:2E7127D2

< End of report >

Re: prosba o kontrolu logu

Napsal: 19 led 2013 20:40
od Ivon
OTL Extras logfile created on: 19.1.2013 17:07:24 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

511,17 Mb Total Physical Memory | 25,96 Mb Available Physical Memory | 5,08% Memory free
1,22 Gb Paging File | 0,29 Gb Available in Paging File | 24,09% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149,05 Gb Total Space | 44,50 Gb Free Space | 29,86% Space Free | Partition Type: NTFS
Drive G: | 931,28 Gb Total Space | 820,12 Gb Free Space | 88,06% Space Free | Partition Type: FAT32
Drive H: | 983,72 Mb Total Space | 657,63 Mb Free Space | 66,85% Space Free | Partition Type: FAT

Computer Name: DOMA-QO9I0VR7RQ | User Name: Ivona | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- G:\wd_windows_tools\Photoshop\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [CEWE prezentace fotografií] -- "C:\Program Files\Fotostar\Fotostar Offline client3\CEWE prezentace fotografií.exe" -d "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Fotostar Offline client3] -- "C:\Program Files\Fotostar\Fotostar Offline client3\Fotostar Offline client3.exe" "%1" ()
Directory [Fotostar Offline client4] -- "C:\Program Files\Fotostar\Fotostar Offline client3\Fotostar Offline client4.exe" "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UacDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirstRunDisabled" = 0
"UacDisableNotify" = 0

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\ICQ7.1\ICQ.exe" = C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.1\aolload.exe" = C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\ICQLite\ICQLite.exe" = C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite
"C:\Program Files\FlashGet\flashget.exe" = C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget
"C:\Program Files\ICQ6\ICQ.exe" = C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
"C:\Program Files\River Past\Wave@MP3\WaveAtMp3.exe" = C:\Program Files\River Past\Wave@MP3\WaveAtMp3.exe:*:Enabled:River Past Wave@MP3
"C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6
"G:\wd_windows_tools\samsung5210\npsasvr.exe" = G:\wd_windows_tools\samsung5210\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server -- (PeeringPortal)
"G:\wd_windows_tools\samsung5210\npsvsvr.exe" = G:\wd_windows_tools\samsung5210\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server -- (PeeringPortal)
"C:\Program Files\ICQ7.1\ICQ.exe" = C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.1\aolload.exe" = C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
"C:\Program Files\Air Mouse\Air Mouse\Air Mouse.exe" = C:\Program Files\Air Mouse\Air Mouse\Air Mouse.exe:*:Enabled:AirMouse -- ()
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
"C:\Program Files\Java\jre6\launch4j-tmp\Stanza.exe" = C:\Program Files\Java\jre6\launch4j-tmp\Stanza.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe" = C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Spyware Terminator Update Support -- (Crawler.com)
"C:\Program Files\Philips\Wi-Fi MediaConnect\Wi-Fi MediaConnect.exe" = C:\Program Files\Philips\Wi-Fi MediaConnect\Wi-Fi MediaConnect.exe:*:Enabled:Wi-Fi MediaConnect -- (Koninklijke Philips Electronics N.V.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{083F79E4-6FE9-46FB-A6C6-4F8862742947}" = ATI HYDRAVISION
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0901FCE8-5415-4499-BBC8-1AA106DD66E2}" = Adobe Setup
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1EE9BBA1-312F-4EC0-9DEA-A8FE22BBABAA}_is1" = 20Dollars2Surf 1.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS
"{20ACB2F8-3BCA-45A8-80A2-9D3CB5C25F43}" = Safari
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 30
"{293D5729-7C01-4FA4-A4DE-BB6A1587BBB9}" = PDF Settings
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2A8E4833-F483-4074-B4DB-F295F7901A8D}" = MobileMe Control Panel
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3C02ED4F-46B0-4E9E-87F7-47AEBA4031C8}" = Pinnacle PCTV
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}" = Google Earth
"{45375017-B0F8-44EA-9D5B-2DCE7C84FFC2}" = SA21xx Device Manager
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{49FC50FC-F965-40D9-89B4-CBFF80941CSY}" = Windows Movie Maker 2.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5178C1BB-1EB1-4468-894B-7DE964DDCAA2}" = Adobe Photoshop CS3
"{53AFF171-481D-64FA-0DA4-1CA0ABF01029}" = Nero 7 Demo
"{546C143E-68DC-314D-97BC-1E454E3BA429}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5E65E94D-69F2-4850-9E93-6459C53A0F50}" = Microsoft .NET Framework 1.1 Czech Language Pack
"{6179A7D2-A668-4F1D-BC9A-DCC6A10C7871}" = Adobe Color NA Extra Settings
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6BB66126-E1B5-4DF4-8320-CAC6F8009CFA}" = Philips Digital Audio Player
"{6D12B99F-EAAA-49D8-8E2F-74FA7459CCB2}" = Adobe Asset Services CS3
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = Zpracování fotografií a obrázků HP 2.0 - All-in-One ovladač
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71BFC818-0CED-42D6-9C87-5142918957EE}" = ICQ7.1
"{75B7F766-7998-44d8-A202-F1EC76A121BA}" = Memeo AutoSync
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"{82B2DB92-98CA-4a0e-B1BD-18B6E2D320CB}" = Memeo AutoBackup
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86EC42B5-346E-4BAB-948D-58E021EA4BD1}" = ATI Catalyst Control Center
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90120000-0010-0405-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Czech) 12
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{294B4278-CF7B-40B9-86A1-2D3FF0C2C524}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{10EC59E5-9BCE-4884-BB1A-E28627220232}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0405-0000-0000000FF1CE}" = Sada Compatibility Pack pro systém Office 2007
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = Zpracování fotografií a obrázků HP 2.0 - All-in-One
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9F53AAB3-B989-4731-8635-C8F4F1050A8C}" = Adobe Setup
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2C9CD1B-2551-3AED-B244-6698FB929FA6}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AA58346A-A5D7-4659-91D6-38D07345BDCF}" = Wi-Fi MediaConnect
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-7AD7-1029-7B44-A70500000002}" = Adobe Reader 7.0.5 - Czech
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1" = ConvertXtoDVD 2.0.12
"{BD087F50-46B2-43E4-BD73-5DB3DC20B47C}" = Adobe Color EU Recommended Settings
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C3A13A35-63AC-427a-92E6-960C1D01FABB}" = Poradce pro upgrade na systém Windows 7
"{C69405BB-27AF-4940-B3DA-04910B4DFD23}_is1" = aTube Catcher 1.0
"{C900EF06-2E76-49C7-8DB0-41F629B21DC5}" = hp psc 1200 series
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC8E0363-B20C-4792-8A1C-8DF5E01B68A6}" = GoGear VIBE Device Manager
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D6BCB0B1-9AC8-407B-B679-F925A01F2B2C}" = Bonjour Print Services
"{D92B72E2-C854-4738-8ED6-4C3661CC17AE}" = Adobe Color JA Extra Settings
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D9D5A07A-F299-4741-BFE6-302324CC0BD7}" = calibre
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DCB7635D-48AD-4E86-8A1F-275169525CD8}" = Blaze MediaConvert
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E40CE517-0D42-4198-96B4-C8232B257EB5}" = Data Lifeguard Diagnostic for Windows
"{E623BB3F-F7ED-4148-BEB5-A0D1DB28B4DE}" = Media Converter for Philips
"{E6607F5B-50E7-4B54-81B7-F0600E3C8CF4}" = Belkin F5D8053 N Wireless USB Adapter
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E6C48B74-26ED-4EF8-A04C-42AFDE5E1CA3}" = Intel(R) PRO Network Connections
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F87F2E18-4720-4F97-B3E5-E930D649D92B}" = Mobile Mouse Server
"{F9263444-9913-4896-8D7C-E056C4C5FB38}_is1" = MSRSD v4.11
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FB91E774-867B-4567-ACE7-8144EF036068}" = Olympus Digital Wave Player
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Balíček ovladače systému Windows - Nokia pccsmcfd (10/12/2007 6.85.4.0)
"6194C28A8F62DD817EA1B918E6E46E806A21B452" = Balíček ovladače systému Windows - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
"65B6FE5418CE28F4D72543FB2D964C3CEC83F161" = Balíček ovladače systému Windows - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_4977c84bcdc298c444ccfbdcccb660d" = Adobe Photoshop CS3
"Adobe_f5bcf5cb0764c8ca8bbd659a1bf2b83" = Adobe Dreamweaver CS3
"Air Video Server" = Air Video Server 2.2.5
"Alive Text to Speech_is1" = Alive Text to Speech v6.0.8.6
"All ATI Software" = Softarová utilita ATI - Odinstalovat
"ALZip_is1" = ALZip
"AsusUpdate" = AsusUpdate
"ATI Display Driver" = ATI Display Driver
"aTube Catcher" = aTube Catcher
"Blaze MediaConvert" = Blaze MediaConvert
"Canon SELPHY CP810" = Canon SELPHY CP810
"CCleaner" = CCleaner
"CDXACA_is1" = CODEXIS ACADEMIA 4.66.1
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Defraggler" = Defraggler
"DivX Free Codec" = DivX Free Codec
"DVD Shrink_is1" = DVD Shrink 3.2
"eBay Icon" = eBay Icon
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FMCODEC" = FM Screen Capture Codec (Remove Only)
"Fotostar Offline client3" = Fotostar Offline client3
"Fotostar Offline client4" = Fotostar Offline client4
"Free Audio Converter_is1" = Free Audio Converter version 2.2.16.324
"Free Video to iPod Converter_is1" = Free Video to iPod Converter version 2.4
"HP PrecisionScan LTX" = HP PrecisionScan LTX
"HP PSC 1200 Series" = Zpracování fotografií a obrázkù HP 2.0 - PSC 1200 Series
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"iArt_is1" = iArt 3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{6BAA26DB-2D4E-42B6-BC3F-3B58144A64B6}" = Mobile Phone Manager
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"InstallShield_{E6607F5B-50E7-4B54-81B7-F0600E3C8CF4}" = Belkin F5D8053 N Wireless USB Adapter
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"JDownloader" = JDownloader
"Magic Speed_is1" = Magic Speed v3.6
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verze 1.70.0.1100
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 10.0.2 (x86 cs)" = Mozilla Firefox 10.0.2 (x86 cs)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NIS" = Norton Internet Security
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ParadisePoker" = ParadisePoker
"Picasa 3" = Picasa 3
"PowerISO" = PowerISO
"Project IGI" = Project IGI
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile Modem Device" = Samsung Mobile Modem Device Software
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software
"SELPHY Photo Print" = Canon Utilities SELPHY Photo Print
"SELPHY Print Contents 130" = Canon Utilities SELPHY Print Contents 1.3.0
"Seznam DVD 4.x_is1" = Seznam DVD 4.9
"Spyware Terminator_is1" = Spyware Terminator
"Stanza" = Stanza
"Totalcmd" = Total Commander (Remove or Repair)
"Uninstall_is1" = Uninstall 1.0.0.1
"Usbfix" = UsbFix By El Desaparecido
"WAV To MP3 Plus" = WAV To MP3 Plus
"Web Translator" = Web Translator
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR
"winscp3_is1" = WinSCP 4.1.9
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"PhotoFiltre Studio X" = PhotoFiltre Studio X

Error encountered while reading event logs.

< End of report >

Re: prosba o kontrolu logu

Napsal: 20 led 2013 22:04
od vyosek
:arrow: Takze misto jednoho parminutoveho hovoru radsi pak na krku trestni stihani :shock:

:arrow: A co ten cracknuty Norton, ten pujde pryc, jinak s pomoci koncime :evil: A date tam nejake free reseni (Avast, Avira ci MSE)

:arrow: Spustte znovu OTL
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :otl
    SRV - File not found [Auto | Stopped] -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Plánovač automatické aktualizace LiveUpdate)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\MOBILE~1\bin\SPAInfoDrv.sys -- (SPAInfoDrv)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
    DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
    DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
    DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDRm.sys -- (InCDRm)
    DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDPass.sys -- (InCDPass)
    DRV - File not found [File_System | Disabled | Stopped] -- system32\drivers\InCDFs.sys -- (InCDFs)
    DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
    DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\MediaCoder\SysInfo.sys -- (CrystalSysInfo)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\IVONA~2.DOM\LOCALS~1\Temp\catchme.sys -- (catchme)
    DRV - File not found [Kernel | On_Demand | Unknown] -- -- (asw8ve1m)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\adiusbaw.sys -- (adiusbaw)
    DRV - File not found [Kernel | Auto | Stopped] -- System32\Drivers\adildr.sys -- (ADILOADER)
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search bar = http://search.msn.com/spbasic.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value error.
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
    IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage
    IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage
    IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage
    IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/av ... x_homepage
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Bar = http://google.icq.com/search/search_frame.php
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://google.icq.com
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\${searchCLSID}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" = http://www.crawler.com/search/dispatche ... tp=bs&qkw={searchTerms}&tbid=60076
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rlz=1I7GZEF_cs&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{88C19A03-DC0C-424D-B538-A846A8891C48}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{BE9654C9-9D79-42ec-B55A-3CAEB12DBF58}: "URL" = http://www.icq.com/search/result.php?q={searchTerms}&ch_id=osd
    IE - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\SearchScopes\{D6A8875F-7916-4732-B6B4-BA0FB5CF0C07}: "URL" = http://www.heureka.cz/?h[fraze]={searchTerms}
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVONA.DOMA-QO9I0VR7RQ\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\1X8KOTTW.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVONA.DOMA-QO9I0VR7RQ\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\1X8KOTTW.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVONA.DOMA-QO9I0VR7RQ\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\1X8KOTTW.DEFAULT\EXTENSIONS\{B2509CD4-17CD-45ED-8146-A82AF038F493}.XPI
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVONA.DOMA-QO9I0VR7RQ\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\1X8KOTTW.DEFAULT\EXTENSIONS\{EA614400-E918-4741-9A97-7A972FF7C30B}
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVONA.DOMA-QO9I0VR7RQ\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\1X8KOTTW.DEFAULT\EXTENSIONS\SMARTERWIKI@WIKIATIC.COM.XPI
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll File not found
    O2 - BHO: (no name) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - No CLSID value found.
    O2 - BHO: (no name) - {E33CF602-D945-461A-83F0-819F76A199F8} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
    O3 - HKU\S-1-5-21-1993962763-606747145-725345543-1003\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
    O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
    O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
    O9 - Extra Button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - Reg Error: Value error. File not found
    O9 - Extra 'Tools' menuitem : ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - Reg Error: Value error. File not found
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    [2011.10.15 19:16:24 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\I1kIfJMHH0fH
    [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [11 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
    [12 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
    [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
    [4 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
    [2011.11.05 02:00:00 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\AdobeAAMUpdater-1.0-DOMA-QO9I0VR7RQ-Ivona.job
    [2011.10.10 20:48:08 | 000,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
    [2007.03.27 16:56:24 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1172763280.job
    [2013.01.19 17:32:01 | 000,001,058 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-606747145-725345543-1003UA.job
    [2013.01.19 17:52:59 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{7CB0F1A3-DCEE-4579-A3BA-497C7A6601B5}.job
    
    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "SwitchBoard"=-
    "GrooveMonitor"=-
    "AdobeAAMUpdater-1.0"=-
    "SunJavaUpdateSched"=-
    "QuickTime Task"=-
    "iTunesHelper"=-
    "PService"=-
    "WINSXS32"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
    "swg"=-
    "MSMSGS"=-
    "SpywareTerminatorUpdate"=-
    "Mexmxy"=-
    "Sexmxe"=-
    "Yexmxk"=-
    "Cexmxo"=-
    "PService"=-
    "WINSXS32"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "FlashPlayerUpdate"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteHelper]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMail]
    
    :files
    C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\*.exe
    c:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Dokumenty\Hudba\iTunes\Mobile Applications\*crack*.*
    c:\WINDOWS\Prefetch\*crack*.*
    c:\WINDOWS\system32\*crack*.*
    c:\Documents and Settings\All Users.WINDOWS\Data aplikací\{*}
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [EMPTYJAVA]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: prosba o kontrolu logu

Napsal: 22 led 2013 20:56
od Ivon
All processes killed
========== OTL ==========
Service Plánovač automatické aktualizace LiveUpdate stopped successfully!
Service Plánovač automatické aktualizace LiveUpdate deleted successfully!
File C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe not found.
Service WDICA stopped successfully!
Service WDICA deleted successfully!
Service SPAInfoDrv stopped successfully!
Service SPAInfoDrv deleted successfully!
File C:\PROGRA~1\MOBILE~1\bin\SPAInfoDrv.sys not found.
Service PDRFRAME stopped successfully!
Service PDRFRAME deleted successfully!
Service PDRELI stopped successfully!
Service PDRELI deleted successfully!
Service PDFRAME stopped successfully!
Service PDFRAME deleted successfully!
Service PDCOMP stopped successfully!
Service PDCOMP deleted successfully!
Service PCIDump stopped successfully!
Service PCIDump deleted successfully!
Service lbrtfdc stopped successfully!
Service lbrtfdc deleted successfully!
Service InCDRm stopped successfully!
Service InCDRm deleted successfully!
File system32\drivers\InCDRm.sys not found.
Service InCDPass stopped successfully!
Service InCDPass deleted successfully!
File system32\drivers\InCDPass.sys not found.
Service InCDFs stopped successfully!
Service InCDFs deleted successfully!
File system32\drivers\InCDFs.sys not found.
Service i2omgmt stopped successfully!
Service i2omgmt deleted successfully!
Service Changer stopped successfully!
Service Changer deleted successfully!
Service CrystalSysInfo stopped successfully!
Service CrystalSysInfo deleted successfully!
File C:\Program Files\MediaCoder\SysInfo.sys not found.
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\DOCUME~1\IVONA~2.DOM\LOCALS~1\Temp\catchme.sys not found.
Error: No service named asw8ve1m was found to stop!
Service\Driver key asw8ve1m not found.
Service adiusbaw stopped successfully!
Service adiusbaw deleted successfully!
File system32\DRIVERS\adiusbaw.sys not found.
Service ADILOADER stopped successfully!
Service ADILOADER deleted successfully!
File System32\Drivers\adildr.sys not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Search bar| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Secondary Start Pages| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Prev Search Bar| /E : value set successfully!
HKU\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Prev Search Page| /E : value set successfully!
HKU\S-1-5-21-1993962763-606747145-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{searchCLSID}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{searchCLSID}\ not found.
Registry key HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}\ not found.
Registry key HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found.
Registry key HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{88C19A03-DC0C-424D-B538-A846A8891C48}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88C19A03-DC0C-424D-B538-A846A8891C48}\ not found.
Registry key HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ not found.
Registry key HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{BE9654C9-9D79-42ec-B55A-3CAEB12DBF58}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BE9654C9-9D79-42ec-B55A-3CAEB12DBF58}\ not found.
Registry key HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{D6A8875F-7916-4732-B6B4-BA0FB5CF0C07}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D6A8875F-7916-4732-B6B4-BA0FB5CF0C07}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E33CF602-D945-461A-83F0-819F76A199F8}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll moved successfully.
Registry value HKEY_USERS\S-1-5-21-1993962763-606747145-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
File C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B863453A-26C3-4e1f-A54D-A2CD196348E9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B863453A-26C3-4e1f-A54D-A2CD196348E9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B863453A-26C3-4e1f-A54D-A2CD196348E9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B863453A-26C3-4e1f-A54D-A2CD196348E9}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\WINDOWS\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\I1kIfJMHH0fH moved successfully.
C:\WINDOWS\002308_.tmp deleted successfully.
C:\WINDOWS\004554_.tmp deleted successfully.
C:\WINDOWS\005630_.tmp deleted successfully.
C:\WINDOWS\DUMP6c37.tmp deleted successfully.
C:\WINDOWS\SET3.tmp deleted successfully.
C:\WINDOWS\SET7.tmp deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP11C.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP11D.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP142.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1BF.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP316.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3E0.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP4E.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP50.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7D4.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7F1.tmp\System.EnterpriseServices.dll deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7F1.tmp\System.EnterpriseServices.Wrapper.dll deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7F1.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPB1.tmp folder deleted successfully.
C:\WINDOWS\Installer\MSI3D.tmp deleted successfully.
C:\WINDOWS\Installer\MSI507.tmp deleted successfully.
C:\WINDOWS\Installer\MSI54F.tmp deleted successfully.
C:\WINDOWS\Installer\MSI550.tmp deleted successfully.
C:\WINDOWS\Installer\MSI551.tmp deleted successfully.
C:\WINDOWS\Installer\MSI60.tmp deleted successfully.
C:\WINDOWS\Installer\MSI80.tmp deleted successfully.
C:\WINDOWS\Installer\MSI82.tmp deleted successfully.
C:\WINDOWS\Installer\MSI83.tmp deleted successfully.
C:\WINDOWS\Installer\MSI9E.tmp deleted successfully.
C:\WINDOWS\Installer\MSI9F.tmp deleted successfully.
C:\WINDOWS\Installer\MSIA0.tmp deleted successfully.
C:\WINDOWS\system32\CONFIG.TMP deleted successfully.
C:\WINDOWS\Temp\c02.tmp deleted successfully.
C:\WINDOWS\Temp\c03.tmp deleted successfully.
C:\WINDOWS\Temp\c04.tmp deleted successfully.
C:\WINDOWS\Temp\ZAP99.tmp folder deleted successfully.
C:\WINDOWS\Tasks\AdobeAAMUpdater-1.0-DOMA-QO9I0VR7RQ-Ivona.job moved successfully.
C:\WINDOWS\Tasks\AppleSoftwareUpdate.job moved successfully.
C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1172763280.job moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-606747145-725345543-1003UA.job moved successfully.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{7CB0F1A3-DCEE-4579-A3BA-497C7A6601B5}.job moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SwitchBoard deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\PService not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\WINSXS32 not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\swg deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\SpywareTerminatorUpdate deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Mexmxy not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Sexmxe deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Yexmxk not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Cexmxo not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\PService not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WINSXS32 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\FlashPlayerUpdate not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteHelper\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMail\ deleted successfully.
========== FILES ==========
C:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Data aplikací\2.exe moved successfully.
c:\Documents and Settings\Ivona.DOMA-QO9I0VR7RQ\Dokumenty\Hudba\iTunes\Mobile Applications\Castle Of Magic 1.0.1.cracked-COREPDA.ipa moved successfully.
c:\WINDOWS\Prefetch\NIS-2012-CRACK.EXE-05042546.pf moved successfully.
c:\WINDOWS\Prefetch\NIS-2012-CRACK.EXE-0CBA8DDB.pf moved successfully.
c:\WINDOWS\system32\LegitCheckControl.dll.wgacracked moved successfully.
c:\WINDOWS\system32\wgacracked.txt moved successfully.
c:\WINDOWS\system32\wgalogon.dll.wgacracked moved successfully.
c:\WINDOWS\system32\WgaTray.exe.wgacracked moved successfully.
c:\Documents and Settings\All Users.WINDOWS\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\x86 folder moved successfully.
c:\Documents and Settings\All Users.WINDOWS\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86 folder moved successfully.
c:\Documents and Settings\All Users.WINDOWS\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521} folder moved successfully.
c:\Documents and Settings\All Users.WINDOWS\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD}\x86 folder moved successfully.
c:\Documents and Settings\All Users.WINDOWS\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD} folder moved successfully.
c:\Documents and Settings\All Users.WINDOWS\Data aplikací\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86 folder moved successfully.
c:\Documents and Settings\All Users.WINDOWS\Data aplikací\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} folder moved successfully.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Administrator.DOMA-QO9I0VR7RQ
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: All Users.WINDOWS

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33103 bytes
->Flash cache emptied: 0 bytes

User: Default User.WINDOWS1
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33103 bytes

User: Ivona

User: Ivona.DOMA-NOVVG4QPUF

User: Ivona.DOMA-QO9I0VR7RQ
->Temp folder emptied: 3176316 bytes
->Temporary Internet Files folder emptied: 137166079 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 122643222 bytes
->Google Chrome cache emptied: 65419138 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 145119 bytes

User: IVONA~1~D-4

User: IVONA~2

User: IVONA~2~DOM

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 137642 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService.NT AUTHORITY.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService.NT AUTHORITY.001
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService.NT AUTHORITY.002
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService.NT AUTHORITY.003
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService.NT AUTHORITY.004
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService.NT AUTHORITY.005
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService.NT AUTHORITY.006
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 840351 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: NetworkService.NT AUTHORITY.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: NetworkService.NT AUTHORITY.001
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: NetworkService.NT AUTHORITY.002
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: NetworkService.NT AUTHORITY.003
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: NetworkService.NT AUTHORITY.004
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: NetworkService.NT AUTHORITY.005
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: NetworkService.NT AUTHORITY.006
->Temp folder emptied: 9894120 bytes
->Temporary Internet Files folder emptied: 1272760 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 213475 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 1227778654 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 10060918 bytes

Total Files Cleaned = 1 506,00 mb


[EMPTYFLASH]

User: Administrator

User: Administrator.DOMA-QO9I0VR7RQ

User: All Users

User: All Users.WINDOWS

User: Default User

User: Default User.WINDOWS
->Flash cache emptied: 0 bytes

User: Default User.WINDOWS1

User: Ivona

User: Ivona.DOMA-NOVVG4QPUF

User: Ivona.DOMA-QO9I0VR7RQ
->Flash cache emptied: 0 bytes

User: IVONA~1~D-4

User: IVONA~2

User: IVONA~2~DOM

User: LocalService

User: LocalService.NT AUTHORITY

User: LocalService.NT AUTHORITY.000

User: LocalService.NT AUTHORITY.001

User: LocalService.NT AUTHORITY.002

User: LocalService.NT AUTHORITY.003

User: LocalService.NT AUTHORITY.004

User: LocalService.NT AUTHORITY.005

User: LocalService.NT AUTHORITY.006

User: NetworkService

User: NetworkService.NT AUTHORITY

User: NetworkService.NT AUTHORITY.000

User: NetworkService.NT AUTHORITY.001

User: NetworkService.NT AUTHORITY.002

User: NetworkService.NT AUTHORITY.003

User: NetworkService.NT AUTHORITY.004

User: NetworkService.NT AUTHORITY.005

User: NetworkService.NT AUTHORITY.006

Total Flash Files Cleaned = 0,00 mb


[EMPTYJAVA]

User: Administrator

User: Administrator.DOMA-QO9I0VR7RQ

User: All Users

User: All Users.WINDOWS

User: Default User

User: Default User.WINDOWS

User: Default User.WINDOWS1

User: Ivona

User: Ivona.DOMA-NOVVG4QPUF

User: Ivona.DOMA-QO9I0VR7RQ
->Java cache emptied: 0 bytes

User: IVONA~1~D-4

User: IVONA~2

User: IVONA~2~DOM

User: LocalService

User: LocalService.NT AUTHORITY

User: LocalService.NT AUTHORITY.000

User: LocalService.NT AUTHORITY.001

User: LocalService.NT AUTHORITY.002

User: LocalService.NT AUTHORITY.003

User: LocalService.NT AUTHORITY.004

User: LocalService.NT AUTHORITY.005

User: LocalService.NT AUTHORITY.006

User: NetworkService

User: NetworkService.NT AUTHORITY

User: NetworkService.NT AUTHORITY.000

User: NetworkService.NT AUTHORITY.001

User: NetworkService.NT AUTHORITY.002

User: NetworkService.NT AUTHORITY.003

User: NetworkService.NT AUTHORITY.004

User: NetworkService.NT AUTHORITY.005

User: NetworkService.NT AUTHORITY.006

Total Java Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 01222013_203456

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Re: prosba o kontrolu logu

Napsal: 22 led 2013 21:06
od vyosek
:arrow: Ten nelegalni Norton uz mate pryc a nahrazeny free resenim??