Stránka 2 z 2

Re: policejní vír

Napsal: 01 črc 2013 22:26
od zeleninka100
OTL logfile created on: 1.7.2013 23:02:08 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\michal\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,25 Gb Total Physical Memory | 0,50 Gb Available Physical Memory | 40,05% Memory free
1,85 Gb Paging File | 1,25 Gb Available in Paging File | 67,54% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 36,20 Gb Total Space | 16,36 Gb Free Space | 45,18% Space Free | Partition Type: FAT32
Drive D: | 36,35 Gb Total Space | 36,07 Gb Free Space | 99,22% Space Free | Partition Type: FAT32

Computer Name: ASER | User Name: michal | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2013.07.01 22:55:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\michal\Plocha\OTL.exe
PRC - [2013.05.09 10:58:36 | 006,583,664 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\Setup\avast.setup
PRC - [2013.05.09 10:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.12.25 17:54:40 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre1.7.0_07\bin\jqs.exe
PRC - [2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.04.25 15:36:26 | 000,835,584 | ---- | M] () -- C:\WINDOWS\vsnp325.exe
PRC - [2007.04.21 09:30:54 | 000,270,336 | ---- | M] () -- C:\WINDOWS\tsnp325.exe
PRC - [2007.02.12 14:50:40 | 000,020,480 | ---- | M] () -- C:\WINDOWS\FixCamera.exe
PRC - [2007.01.21 13:51:02 | 000,488,448 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Documents and Settings\michal\Local Settings\Temp\RtkBtMnt.EXE
PRC - [2006.11.17 05:42:52 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe
PRC - [2005.11.08 02:31:48 | 000,278,528 | ---- | M] (InterVideo Inc.) -- C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
PRC - [2005.07.25 12:00:56 | 000,876,032 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2005.03.28 13:52:08 | 000,360,448 | ---- | M] (acer Inc.) -- C:\Program Files\acer\eRecovery\Monitor.exe
PRC - [2005.01.31 08:05:50 | 000,253,952 | ---- | M] (Atheros Communications, Inc.) -- C:\Program Files\Atheros\ACU.exe
PRC - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
PRC - [2004.08.05 17:23:10 | 000,308,352 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
PRC - [2004.05.17 14:57:00 | 000,184,320 | ---- | M] (O&O Software GmbH) -- C:\WINDOWS\system32\oodag.exe
PRC - [2002.12.20 16:18:40 | 000,200,704 | ---- | M] (FUJI PHOTO FILM CO., LTD.) -- C:\Program Files\FinePixViewer\QuickDCF.exe


========== Modules (No Company Name) ==========

MOD - [2013.05.09 10:58:26 | 000,240,448 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\Setup\setiface.dll
MOD - [2013.05.09 10:49:30 | 002,085,376 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\13050900\algo.dll
MOD - [2007.04.25 15:36:26 | 000,835,584 | ---- | M] () -- C:\WINDOWS\vsnp325.exe
MOD - [2007.04.21 09:30:54 | 000,270,336 | ---- | M] () -- C:\WINDOWS\tsnp325.exe
MOD - [2007.02.12 14:50:40 | 000,020,480 | ---- | M] () -- C:\WINDOWS\FixCamera.exe
MOD - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe


========== Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013.03.14 12:56:56 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.12.25 17:54:40 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre1.7.0_07\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012.12.23 15:18:20 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.03.20 13:08:30 | 000,008,704 | ---- | M] (Vodafone) [Auto | Stopped] -- C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe -- (VmbService)
SRV - [2005.07.25 12:00:56 | 000,876,032 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
SRV - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)
SRV - [2004.08.05 17:23:10 | 000,308,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- (SymWSC)
SRV - [2004.05.17 14:57:00 | 000,184,320 | ---- | M] (O&O Software GmbH) [Auto | Running] -- C:\WINDOWS\system32\oodag.exe -- (O&O Defrag)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Launch Manager\POWERKEY.sys -- (POWERKEY)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\PhTVTune.sys -- (PhTVTune)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\PCASp50.sys -- (PCASp50)
DRV - File not found [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\osanbm.sys -- (osanbm)
DRV - File not found [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\osaio.sys -- (osaio)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Cap7134.sys -- (Cap7134)
DRV - [2013.07.01 22:53:18 | 000,770,344 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2013.07.01 22:53:18 | 000,369,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2013.07.01 22:53:18 | 000,175,176 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2013.05.09 10:59:10 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2013.05.09 10:59:10 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2013.05.09 10:59:10 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2013.05.09 10:59:10 | 000,049,376 | ---- | M] () [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013.05.09 10:59:08 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.03.16 14:55:26 | 000,239,488 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2012.03.16 14:55:26 | 000,195,200 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2012.03.16 14:55:26 | 000,102,784 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2012.03.16 14:55:26 | 000,089,856 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - [2012.03.16 14:55:26 | 000,073,984 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2012.03.16 14:55:26 | 000,066,688 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_jucdcecm.sys -- (huawei_cdcecm)
DRV - [2012.03.16 14:55:26 | 000,026,624 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl)
DRV - [2012.03.16 14:55:26 | 000,011,136 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter)
DRV - [2007.04.26 11:03:12 | 010,343,168 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snp325.sys -- (SNP325)
DRV - [2007.01.14 16:28:36 | 000,034,760 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2006.12.29 14:48:06 | 004,026,112 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM)
DRV - [2006.07.20 20:40:00 | 000,332,800 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AG120.sys -- (AG120(ZyXEL)
DRV - [2005.07.25 11:53:30 | 000,008,704 | ---- | M] (Nero AG) [Recognizer | System | Unknown] -- C:\WINDOWS\System32\drivers\InCDrec.sys -- (InCDrec)
DRV - [2005.07.25 11:53:28 | 000,101,504 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005.07.25 11:53:04 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2005.07.25 11:53:00 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)
DRV - [2005.02.08 16:33:06 | 000,970,240 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005.01.13 14:46:16 | 000,069,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\acer\eRecovery\int15.sys -- (int15.sys)
DRV - [2005.01.10 15:47:14 | 000,449,888 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2004.12.21 03:32:12 | 000,369,024 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2004.12.15 15:18:30 | 000,200,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWATI.sys -- (HSFHWATI)
DRV - [2004.12.15 15:18:28 | 000,703,232 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2004.12.15 15:18:26 | 001,038,208 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2004.12.01 18:36:08 | 000,070,912 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)
DRV - [2004.09.14 02:40:56 | 000,146,304 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2004.08.03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)
DRV - [2004.03.02 16:37:50 | 000,125,184 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\imagesrv.sys -- (imagesrv)
DRV - [2004.03.02 16:37:48 | 000,005,504 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\imagedrv.sys -- (imagedrv)
DRV - [2003.12.05 18:46:36 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy.karneval.cz:3128

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://www.centrum.cz/"
FF - prefs.js..extensions.enabledAddons: centrumpomocnik%40centrum.cz:1.1
FF - prefs.js..extensions.enabledAddons: %7B800b5000-a755-47e1-992b-48a1c1357f07%7D:1.5.3
FF - prefs.js..extensions.enabledAddons: %7Bea614400-e918-4741-9a97-7a972ff7c30b%7D:2.5.15
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..network.proxy.ftp: "proxy.karneval.cz"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "proxy.karneval.cz"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "proxy.karneval.cz"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "proxy.karneval.cz"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "proxy.karneval.cz"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre1.7.0_07\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2088: C:\Program Files\K-Lite Codec Pack\real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1069: C:\Program Files\K-Lite Codec Pack\real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/Acrobat,version=5.1: C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.07.01 22:52:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.14 12:56:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2010.10.23 21:20:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Extensions
[2005.10.31 14:32:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\extensions
[2013.04.29 10:56:52 | 000,000,000 | ---D | M] (Seznam lištiÄŤka) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[2012.01.01 12:11:22 | 000,000,000 | ---D | M] (Centrum domĂ©novĂ˝ pomocnĂ­k) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\extensions\centrumpomocnik@centrum.cz
[2011.11.10 11:26:50 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-11.xml
[2012.01.01 12:11:28 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-12.xml
[2012.01.01 14:11:54 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-13.xml
[2012.01.20 20:50:28 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-14.xml
[2012.01.20 22:52:22 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-15.xml
[2012.04.24 22:49:30 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-16.xml
[2012.04.25 08:50:12 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-17.xml
[2012.08.02 21:59:54 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-18.xml
[2013.02.18 09:53:52 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-19.xml
[2013.02.18 09:57:42 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-20.xml
[2013.04.10 08:55:14 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-21.xml
[2013.03.14 12:56:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013.03.14 12:56:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\distribution\extensions
[2013.03.14 12:56:22 | 000,000,000 | ---D | M] (Seznam lištička) -- C:\Program Files\Mozilla Firefox\distribution\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\{EA614400-E918-4741-9A97-7A972FF7C30B}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\CENTRUMPOMOCNIK@CENTRUM.CZ
[2013.03.14 12:56:58 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013.03.14 12:56:52 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
[2013.03.14 12:56:52 | 000,000,867 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2013.03.14 12:56:52 | 000,001,580 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2013.03.14 12:56:52 | 000,000,851 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2013.03.14 12:56:52 | 000,002,421 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml

O1 HOSTS File: ([2004.08.18 05:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.7.0_07\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.7.0_07\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [ACU] C:\Program Files\Atheros\ACU.exe (Atheros Communications, Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [eRecoveryService] C:\WINDOWS\system32\Check.exe (acer Inc.)
O4 - HKLM..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe ()
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [preload] C:\WINDOWS\RUNXMLPL.EXE (Wistron)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [snp325] C:\WINDOWS\vsnp325.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [tsnp325] C:\WINDOWS\tsnp325.exe ()
O4 - HKCU..\Run: [DefaultScope] File not found
O4 - HKLM..\RunOnce: [SymInstallStub] C:\WINDOWS\System32\Adobe\Shockwave 12\SymInstallStub.exe (Symantec Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe (FUJI PHOTO FILM CO., LTD.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O12 - Plugin for: .mov - C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll (Apple Computer, Inc.)
O12 - Plugin for: .spop - Reg Error: Value error. File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/wind ... 6275069656 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C331F4CA-1704-4B66-8B58-02813C76C8E7}: DhcpNameServer = 192.168.1.2
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{0a6b2edc-8197-11e2-9ff7-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{0a6b2edc-8197-11e2-9ff7-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{108d712c-4d0c-11e2-9fcf-000ae4e102c4}\Shell\AutoRun\command - "" = F:\Toshiba\Launcher\start.exe
O33 - MountPoints2\{1f374922-5a2d-11e2-9fde-000ae4e102c4}\Shell - "" = AutoRun
O33 - MountPoints2\{1f374922-5a2d-11e2-9fde-000ae4e102c4}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{1f374923-5a2d-11e2-9fde-000ae4e102c4}\Shell - "" = AutoRun
O33 - MountPoints2\{1f374923-5a2d-11e2-9fde-000ae4e102c4}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{431be504-7c16-11e2-9ff6-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{431be504-7c16-11e2-9ff6-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{45a9bf54-8bce-11e2-a001-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{45a9bf54-8bce-11e2-a001-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{4904b514-69eb-11e2-9fe4-001e101fcbdc}\Shell - "" = AutoRun
O33 - MountPoints2\{4904b514-69eb-11e2-9fe4-001e101fcbdc}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{7b6b6e54-8a3d-11e2-9fff-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{7b6b6e54-8a3d-11e2-9fff-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{a5022804-7109-11e2-9feb-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{a5022804-7109-11e2-9feb-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{b6354008-71df-11e2-9fec-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{b6354008-71df-11e2-9fec-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{bb5ea302-8a3b-11e2-9ffe-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{bb5ea302-8a3b-11e2-9ffe-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{c09951f2-69dc-11e2-9fe1-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{c09951f2-69dc-11e2-9fe1-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{e49b5bca-69d4-11e2-9fe0-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{e49b5bca-69d4-11e2-9fe0-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (OODBS)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Ligos Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.3iv2 - C:\WINDOWS\System32\3ivxVfWCodec.dll (3ivx.com)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: VIDC.IV40 - C:\WINDOWS\System32\Ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv41 - C:\WINDOWS\System32\Ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\Ir50_32.dll (Ligos Corporation)
Drivers32: VIDC.VP31 - C:\WINDOWS\System32\vp31vfw.dll (On2.com)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.wmv3 - C:\WINDOWS\System32\WMV9VCM.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2013.07.01 22:55:32 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\michal\Plocha\OTL.exe
[2013.07.01 22:53:11 | 000,029,816 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2013.07.01 22:53:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\avast! Free Antivirus
[2013.07.01 22:53:10 | 000,369,584 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2013.07.01 22:53:09 | 000,049,760 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2013.07.01 22:53:08 | 000,770,344 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2013.07.01 22:53:08 | 000,056,080 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2013.07.01 22:53:06 | 000,229,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2013.07.01 22:53:06 | 000,066,336 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys
[2013.07.01 22:52:06 | 000,041,664 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2013.07.01 22:51:27 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2013.07.01 22:50:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2013.07.01 22:11:46 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2013.07.01 22:11:45 | 000,000,000 | ---D | C] -- C:\rsit
[2013.07.01 21:19:29 | 000,000,000 | ---D | C] -- C:\FRST
[2013.07.01 21:18:49 | 001,371,463 | ---- | C] (Farbar) -- C:\Documents and Settings\michal\Plocha\FRST.exe
[2013.07.01 02:27:08 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.06.25 15:10:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2007.01.21 13:31:48 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\michal\Data aplikací\pcouffin.sys
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2013.07.01 23:06:48 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013.07.01 22:55:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\michal\Plocha\OTL.exe
[2013.07.01 22:53:18 | 000,770,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2013.07.01 22:53:18 | 000,369,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2013.07.01 22:53:18 | 000,175,176 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013.07.01 22:53:18 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum
[2013.07.01 22:53:18 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum
[2013.07.01 22:53:18 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum
[2013.07.01 22:53:12 | 000,001,597 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2013.07.01 22:53:08 | 000,002,504 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2013.07.01 22:53:08 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013.07.01 22:41:48 | 000,000,692 | ---- | M] () -- C:\WINDOWS\System32\eRLog.ini
[2013.07.01 22:41:46 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.07.01 22:40:20 | 000,000,096 | ---- | M] () -- C:\WINDOWS\ComponentList.xml
[2013.07.01 22:40:06 | 000,000,636 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Product InstallerIdle.job
[2013.07.01 22:40:06 | 000,000,628 | ---- | M] () -- C:\WINDOWS\tasks\Norton Product Installer.job
[2013.07.01 22:39:34 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.07.01 22:39:26 | 1340,313,600 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.01 22:39:22 | 000,363,750 | ---- | M] () -- C:\WINDOWS\System32\OODBS.lor
[2013.07.01 22:18:28 | 000,648,201 | ---- | M] () -- C:\Documents and Settings\michal\Plocha\adwcleaner.exe
[2013.07.01 22:10:48 | 000,781,383 | ---- | M] () -- C:\Documents and Settings\michal\Plocha\RSIT.exe
[2013.07.01 21:27:02 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013.07.01 21:18:20 | 000,000,714 | ---- | M] () -- C:\Documents and Settings\michal\wincmd.ini
[2013.06.28 21:54:14 | 001,371,463 | ---- | M] (Farbar) -- C:\Documents and Settings\michal\Plocha\FRST.exe
[2013.06.28 21:32:24 | 095,023,320 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\eej88.pad
[2013.06.25 15:25:18 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013.06.25 15:09:54 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\michal\Nabídka Start\Programy\Po spuštění\regmonstd.lnk
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013.07.01 23:00:50 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2013.07.01 22:53:17 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum
[2013.07.01 22:53:17 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum
[2013.07.01 22:53:17 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum
[2013.07.01 22:53:11 | 000,001,597 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2013.07.01 22:53:08 | 000,175,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013.07.01 22:53:07 | 000,049,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2013.07.01 22:53:07 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013.07.01 22:19:09 | 000,648,201 | ---- | C] () -- C:\Documents and Settings\michal\Plocha\adwcleaner.exe
[2013.07.01 22:11:39 | 000,781,383 | ---- | C] () -- C:\Documents and Settings\michal\Plocha\RSIT.exe
[2013.07.01 21:17:23 | 000,000,692 | ---- | C] () -- C:\WINDOWS\System32\eRLog.ini
[2013.07.01 21:15:38 | 000,000,096 | ---- | C] () -- C:\WINDOWS\ComponentList.xml
[2013.06.25 15:19:02 | 000,000,628 | ---- | C] () -- C:\WINDOWS\tasks\Norton Product Installer.job
[2013.06.25 15:19:01 | 000,000,636 | -H-- | C] () -- C:\WINDOWS\tasks\Norton Product InstallerIdle.job
[2013.06.25 15:09:52 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\michal\Nabídka Start\Programy\Po spuštění\regmonstd.lnk
[2013.06.25 15:09:31 | 095,023,320 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\eej88.pad
[2013.02.03 15:29:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.04.20 20:55:40 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.03.16 14:55:44 | 000,286,678 | R--- | C] () -- C:\Documents and Settings\All Users\Data aplikací\DeviceManager.xml.rc4
[2007.01.21 13:31:48 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\ezpinst.exe
[2007.01.21 13:31:48 | 000,007,824 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\pcouffin.cat
[2007.01.21 13:31:48 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\pcouffin.inf
[2007.01.21 13:09:22 | 000,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\.zreglib
[2006.02.02 12:41:12 | 000,000,714 | ---- | C] () -- C:\Documents and Settings\michal\wincmd.ini
[2005.08.01 21:38:32 | 000,000,083 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\sversion.ini
[2005.07.19 03:01:41 | 000,078,848 | ---- | C] () -- C:\Documents and Settings\michal\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005.07.15 22:24:44 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\michal\Local Settings\Data aplikací\fusioncache.dat
[2005.04.11 18:47:34 | 000,001,648 | ---- | C] () -- C:\Program Files\Adobe Reader 6.0.lnk

========== ZeroAccess Check ==========

[2005.07.15 22:10:52 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 04:21:56 | 001,499,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 11:56:06 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 04:22:06 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2005.07.15 22:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Autodesk
[2005.11.20 13:13:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NtiDvdCopy
[2007.01.21 14:10:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ACD Systems
[2010.08.20 21:14:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg9
[2011.03.16 21:18:56 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2011.06.15 13:01:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2012.02.01 19:52:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2013.01.29 06:31:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Vodafone
[2013.07.01 22:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2005.07.15 22:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Autodesk
[2005.07.19 02:56:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\FUJIFILM
[2005.10.08 10:50:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ
[2006.06.03 15:39:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterTrust
[2006.11.26 19:50:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\PC Suite
[2007.01.21 13:31:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vso
[2007.01.21 15:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterVideo
[2007.01.31 19:49:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ACD Systems
[2007.04.24 22:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ Toolbar
[2013.01.29 06:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vodafone
[2013.02.17 15:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz
[2013.04.29 10:41:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\TuneUp Software

========== Purity Check ==========



========== Custom Scans ==========

< >
[1980.01.01 00:00:00 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2004.09.17 12:16:27 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2012.12.23 15:18:23 | 000,000,914 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2013.06.25 15:19:01 | 000,000,636 | -H-- | C] () -- C:\WINDOWS\Tasks\Norton Product InstallerIdle.job
[2013.06.25 15:19:02 | 000,000,628 | ---- | C] () -- C:\WINDOWS\Tasks\Norton Product Installer.job
[2013.07.01 22:53:07 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job

< >

< MD5 for: ATAPI.SYS >
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2004.08.18 05:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\I386\AUTOCHK.EXE
[2004.08.18 05:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe

< MD5 for: CDROM.SYS >
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\I386\sp2.cab:cdrom.sys
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2004.08.18 05:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004.08.18 05:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: HAL.DLL >
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\I386\sp2.cab:hal.dll
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.13 19:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.13 19:31:28 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL
[2004.08.18 05:00:00 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll

< MD5 for: SCECLI.DLL >
[2004.08.18 05:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2009.02.09 10:54:36 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=33081FED75032291EE0E008D5385E86F -- C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe
[2009.02.09 12:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009.02.09 11:11:38 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=4F9F7B567970B524F31D9970A23F7C24 -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2004.08.18 05:00:00 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=6E401E61F952FBBF708AFBECEFAFAE81 -- C:\WINDOWS\$NtUninstallKB956572_0$\services.exe
[2009.02.09 12:25:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009.02.09 12:25:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 12:25:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\services.exe
[2008.04.14 04:22:46 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008.04.14 04:22:46 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\ServicePackFiles\i386\services.exe

< MD5 for: SVCHOST.EXE >
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004.08.18 05:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: TCPIP.SYS >
[2006.04.20 13:51:50 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=1DBF125862891817F374F407626967F4 -- C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
[2008.06.20 11:45:14 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2006.01.13 18:07:08 | 000,360,448 | ---- | M] (Microsoft Corporation) MD5=5562CC0A47B2AEF06D3417B733F3C195 -- C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[2006.01.13 03:28:14 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=583E063FDC888CA30D05C2724B0D7EF4 -- C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
[2005.05.25 20:07:12 | 000,359,936 | ---- | M] (Microsoft Corporation) MD5=63FDFEA54EB53DE2D863EE454937CE1E -- C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[2008.06.20 11:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2005.05.25 20:04:02 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=88763A98A4C26C409741B4AA162720C9 -- C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.18 05:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2006.04.20 14:18:36 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004.08.18 05:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004.08.18 05:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 04:22:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:22:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< >

< %systemroot%*.* /U /s >
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[22 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[1 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2004.09.17 12:16:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Identities
[2004.09.17 12:03:12 | 000,000,000 | --SD | M] -- C:\Documents and Settings\michal\Data aplikací\Microsoft
[2005.07.11 17:51:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Adobe
[2005.07.11 17:51:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\AdobeUM
[2005.07.11 17:53:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\CyberLink
[2005.07.15 04:19:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Help
[2005.07.15 21:46:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Symantec
[2005.07.15 22:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Autodesk
[2005.07.19 02:56:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\FUJIFILM
[2005.08.01 21:43:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Media Player Classic
[2005.09.13 14:12:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Macromedia
[2005.09.13 23:41:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Real
[2005.09.14 21:26:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Corel
[2005.09.20 20:30:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Sun
[2005.10.08 10:50:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ
[2005.10.30 18:00:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Mozilla
[2006.04.29 17:09:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Ahead
[2006.06.03 15:39:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterTrust
[2006.11.26 19:50:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\PC Suite
[2007.01.21 12:52:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Winamp
[2007.01.21 13:31:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vso
[2007.01.21 15:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterVideo
[2007.01.31 19:49:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ACD Systems
[2007.04.24 22:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ Toolbar
[2007.05.06 21:28:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Skype
[2007.07.06 10:40:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InstallShield
[2010.09.05 21:27:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\skypePM
[2013.01.29 06:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vodafone
[2013.02.17 15:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz
[2013.02.17 15:39:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\vlc
[2013.04.29 10:41:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\TuneUp Software

< %APPDATA%\*.exe /s >
[2007.01.21 13:31:50 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\ezpinst.exe
[2012.09.14 14:06:28 | 002,515,592 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz\sznsetup.exe
[2012.09.13 15:24:48 | 001,009,288 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz\szninstall.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job >
[2012.12.23 15:18:24 | 000,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2013.07.01 22:40:06 | 000,000,636 | -H-- | M] () -- C:\WINDOWS\Tasks\Norton Product InstallerIdle.job
[2013.07.01 22:40:06 | 000,000,628 | ---- | M] () -- C:\WINDOWS\Tasks\Norton Product Installer.job
[2013.07.01 22:53:08 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2004.09.17 12:02:34 | 000,471,040 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
[2004.09.17 12:02:34 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2004.09.17 12:02:34 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.sys /3 >
[2013.07.01 22:53:18 | 000,175,176 | ---- | M] () -- C:\WINDOWS\system32\drivers\aswVmm.sys
[2013.07.01 22:53:18 | 000,770,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswSnx.sys
[2013.07.01 22:53:18 | 000,369,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswSP.sys

< %systemroot%\system32\*.* /3 >
[2013.07.01 22:41:46 | 000,001,158 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2013.07.01 22:41:48 | 000,000,692 | ---- | M] () -- C:\WINDOWS\system32\eRLog.ini
[2013.07.01 21:27:12 | 073,381,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MRT.exe
[2013.07.01 22:53:08 | 000,002,504 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT
[2013.07.01 22:39:22 | 000,363,750 | ---- | M] () -- C:\WINDOWS\system32\OODBS.lor
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 04:22:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
"DefaultScope" =

< >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2013.03.14 12:56:58 | 000,917,400 | ---- | M] (Mozilla Corporation) MD5=BF2F2717C13A4BD4FD73F2788534E86B -- C:\Program Files\Mozilla Firefox\firefox.exe

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2009.03.08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\Program Files\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Opera\opera.exe /md5 >

< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.07.01 23:06:48 | 000,000,512 | ---- | M] () MD5=A411D0C8A13CFABEAC5C3BB0608F94F4 -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[1999.06.02 06:41:58 | 000,003,504 | ---- | M] () -- \TOOLS\UEDIT\!crack.exe

< *keygen* /s >

< *loader* /s >
[2013.01.21 15:03:44 | 000,030,608 | ---- | M] () -- \Documents and Settings\michal\Data aplikací\Seznam.cz\install\cz.seznam.software.libfoxloader-3.0.0-win32.zip
[2013.07.01 22:48:40 | 000,003,705 | ---- | M] () -- \Documents and Settings\michal\Local Settings\Temporary Internet Files\Content.IE5\MV7MGVT2\lang_loader[2].gif
[2004.08.18 05:00:00 | 000,017,423 | ---- | M] () -- \I386\DMLOADER.DL_
[2004.08.18 05:00:00 | 000,115,153 | ---- | M] () -- \I386\OSLOADER.EX_
[2004.08.18 05:00:00 | 000,132,757 | ---- | M] () -- \I386\OSLOADER.NT_
[2002.09.25 21:05:38 | 000,113,664 | ---- | M] () -- \Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[2004.08.18 05:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll
[2005.07.27 20:01:00 | 000,000,894 | ---- | M] () -- \WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[2008.04.13 19:31:48 | 000,230,912 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe
[2008.04.14 04:21:40 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll
[2008.04.13 19:31:48 | 000,278,528 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd
[2008.04.14 04:21:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2013.04.26 11:45:20 | 000,012,532 | ---- | M] () -- \WINDOWS\system32\Adobe\Shockwave 12\shockwave_Projector_Loader.dcr
[2013.04.04 06:47:00 | 000,009,622 | ---- | M] () -- \WINDOWS\system32\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr

< End of report >

Re: policejní vír

Napsal: 01 črc 2013 22:28
od zeleninka100
OTL Extras logfile created on: 1.7.2013 23:02:08 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\michal\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,25 Gb Total Physical Memory | 0,50 Gb Available Physical Memory | 40,05% Memory free
1,85 Gb Paging File | 1,25 Gb Available in Paging File | 67,54% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 36,20 Gb Total Space | 16,36 Gb Free Space | 45,18% Space Free | Partition Type: FAT32
Drive D: | 36,35 Gb Total Space | 36,07 Gb Free Space | 99,22% Space Free | Partition Type: FAT32

Computer Name: ASER | User Name: michal | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] -- "C:\Program Files\ACD Systems\ACDSee\5.0\ACDSee5.exe" "%1" (ACD Systems, Ltd.)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] -- "C:\Program Files\FinePixViewer\FinePixViewer.exe" "%1" (FUJI PHOTO FILM CO.,LTD.)
Directory [FinePixPrint] -- "C:\Program Files\FinePixViewer\FinePixViewer.exe" /p "%1" (FUJI PHOTO FILM CO.,LTD.)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager -- (Skype Technologies)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath -- (Skype Technologies S.A.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\AVG\AVG2013\avgmfapx.exe" = C:\Program Files\AVG\AVG2013\avgmfapx.exe:*:Enabled:Instalátor AVG


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{13CCF6F8-A34F-437C-AFA4-69E10C891D21}" = Nokia Lifeblog
"{1526D87C-A955-4FAB-BF18-697BA457E352}" = Norton WMI Update
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1E5F3CC6-D390-4393-A2AA-6CEC04F1705A}" = Image Resizer Powertoy Clone for Windows
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.4.0
"{26A24AE4-039D-4CA4-87B4-2F83217007F0}" = Java 7 Update 7
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 10
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3ECED7D1-E469-4BC6-8A93-5CB0FFE5EBF5}" = Nokia Connectivity Cable Driver
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5058B085-AA79-41E5-A726-681B4C4B846E}" = ACDSee 5.0 PowerPack
"{53480520-7555-470E-8C69-750B0472B4BB}" = O&O Defrag Professional Edition
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}" = Vodafone Mobile Broadband
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9012E9AD-0183-4FAD-A379-BCC5B6C62098}" = Nokia PC Suite
"{90280405-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional s aplikací FrontPage
"{92F31257-15BA-46EE-887D-3C18C0790ACE}" = Atheros Client Installation Program
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1029-7B44-AB0000000001}" = Adobe Reader XI (11.0.03) - Czech
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D3AA158A-9421-4883-8767-E771B0964A1D}" = ImageMixer VCD for FinePix
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F9466082-90E9-4BE4-92F0-CF0AF195B0CF}" = 325 USB PC Camera
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop 7.0 CE" = Adobe Photoshop 7.0 CE
"Adobe Shockwave Player" = Adobe Shockwave Player 12.0
"All ATI Software" = Softarová utilita ATI - Odinstalovat
"ATI Display Driver" = ATI Display Driver
"avast" = avast! Free Antivirus
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Network Adapter
"CCleaner" = CCleaner
"CDex" = CDex extraction audio
"CloneCD" = CloneCD
"CNXT_MODEM_PCI_VEN_1002&DEV_4378&SUBSYS_00801025" = SoftV90 Data Fax Modem with SmartCP
"DVDFab Decrypter_is1" = DVDFab Decrypter 2.9.7.0
"DVDFab Platinum_is1" = DVDFab Platinum 3.0.5.5
"ie8" = Windows Internet Explorer 8
"InCD!UninstallKey" = InCD
"InstallShield_{3ECED7D1-E469-4BC6-8A93-5CB0FFE5EBF5}" = Nokia Connectivity Cable Driver
"InstallShield_{9012E9AD-0183-4FAD-A379-BCC5B6C62098}" = Nokia PC Suite
"InterActual Player" = InterActual Player
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 1.14
"Language Teacher 98 Eng-Cze" = Language Teacher 98 Eng-Cze
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 19.0.2 (x86 cs)" = Mozilla Firefox 19.0.2 (x86 cs)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"O&O Defrag V6.5" = O&O Defrag V6.5
"QuickTime" = QuickTime
"RAM Saver Pro" = RAM Saver Pro
"Registry Mechanic_is1" = Registry Mechanic 6.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 2.0.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Winamp" = Winamp (remove only)
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"OpenOffice.org 1.1.4" = OpenOffice.org 1.1.4
"SeznamInstall" = Seznam Software

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 29.1.2013 2:23:54 | Computer Name = KŘÍŽOVI | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 29.1.2013 2:26:37 | Computer Name = KŘÍŽOVI | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 29.1.2013 2:26:58 | Computer Name = KŘÍŽOVI | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 29.1.2013 2:27:56 | Computer Name = KŘÍŽOVI | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 3.2.2013 6:39:21 | Computer Name = ASER | Source = COM+ | ID = 135894
Description = Vznikl stav, který naznačuje, že tato aplikace modelu COM+ je nestabilní
nebo nefunguje správně. Chyba výrazu: SUCCEEDED(hr) ID serverové aplikace: {02D4B3F1-FD88-11D1-960D-00805FC79235}
ID
instance serverové aplikace: {46412804-14C9-47BB-9A76-8D1D3034C758} Název serverové
aplikace: System Application Tato závažná chyba způsobila ukončení procesu. Kód chyby
= 0x8000ffff : Katastrofální selhání Interní informace služby COM+: soubor: d:\qxp_slp\com\com1x\src\comsvcs\tracker\trksvr\trksvrimpl.cpp,
řádek: 3000 Verze souboru Comsvcs.dll: ENU 2001.12.4414.308 s

Error - 3.2.2013 6:39:22 | Computer Name = ASER | Source = System.EnterpriseServices | ID = 0
Description = System.EnterpriseServices failed to install. Please fix the problem
(see exception below) and run 'regasm System.EnterpriseServices.dll' again to install
System.EnterpriseServices. Exception: 'System.Runtime.InteropServices.COMException
(0x80080005): Provádění serveru selhalo at System.EnterpriseServices.Admin.ICatalog2.CurrentPartition(String
bstrPartitionIDOrName) at System.EnterpriseServices.RegistrationHelperTx.InstallUtilityApplication(Type
t)'

Error - 3.2.2013 6:39:23 | Computer Name = ASER | Source = COM+ | ID = 135894
Description = Vznikl stav, který naznačuje, že tato aplikace modelu COM+ je nestabilní
nebo nefunguje správně. Chyba výrazu: SUCCEEDED(hr) ID serverové aplikace: {02D4B3F1-FD88-11D1-960D-00805FC79235}
ID
instance serverové aplikace: {D8915E18-6507-4A84-865C-866EFB75EF4C} Název serverové
aplikace: System Application Tato závažná chyba způsobila ukončení procesu. Kód chyby
= 0x8000ffff : Katastrofální selhání Interní informace služby COM+: soubor: d:\qxp_slp\com\com1x\src\comsvcs\tracker\trksvr\trksvrimpl.cpp,
řádek: 3000 Verze souboru Comsvcs.dll: ENU 2001.12.4414.308 s

Error - 3.2.2013 6:39:29 | Computer Name = ASER | Source = COM+ | ID = 135894
Description = Vznikl stav, který naznačuje, že tato aplikace modelu COM+ je nestabilní
nebo nefunguje správně. Chyba výrazu: SUCCEEDED(hr) ID serverové aplikace: {02D4B3F1-FD88-11D1-960D-00805FC79235}
ID
instance serverové aplikace: {ED1EDFC5-AD15-49FF-A673-3482DB912DB1} Název serverové
aplikace: System Application Tato závažná chyba způsobila ukončení procesu. Kód chyby
= 0x8000ffff : Katastrofální selhání Interní informace služby COM+: soubor: d:\qxp_slp\com\com1x\src\comsvcs\tracker\trksvr\trksvrimpl.cpp,
řádek: 3000 Verze souboru Comsvcs.dll: ENU 2001.12.4414.308 s

Error - 11.3.2013 7:31:41 | Computer Name = ASER | Source = MsiInstaller | ID = 11704
Description = Produkt: Adobe Reader XI (11.0.02) - Czech -- Chyba 1704.Instalace
Vodafone Mobile Broadband je právě pozastavená. Chcete-li pokračovat, musíte vrátit
změny provedené danou instalací. Chcete vrátit dané změny?

Error - 11.3.2013 7:47:30 | Computer Name = ASER | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Failed to compile: C:\Program Files\Vodafone\Vodafone Mobile Broadband\bin\SMS.exe
. Error code = 0x80131047

[ System Events ]
Error - 1.7.2013 16:45:42 | Computer Name = ASER | Source = Service Control Manager | ID = 7009
Description = Vypršel časový limit (30000 milisekund) čekání na připojení služby
Vodafone Mobile Connect Service.

Error - 1.7.2013 16:45:49 | Computer Name = ASER | Source = Service Control Manager | ID = 7031
Description = Služba Vodafone Mobile Connect Service byla nečekaně ukončena. Stalo
se to 8 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat
službu.

Error - 1.7.2013 16:46:49 | Computer Name = ASER | Source = Service Control Manager | ID = 7031
Description = Služba Vodafone Mobile Connect Service byla nečekaně ukončena. Stalo
se to 9 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat
službu.

Error - 1.7.2013 16:47:54 | Computer Name = ASER | Source = Service Control Manager | ID = 7031
Description = Služba Vodafone Mobile Connect Service byla nečekaně ukončena. Stalo
se to 10 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat
službu.

Error - 1.7.2013 16:48:54 | Computer Name = ASER | Source = Service Control Manager | ID = 7031
Description = Služba Vodafone Mobile Connect Service byla nečekaně ukončena. Stalo
se to 11 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat
službu.

Error - 1.7.2013 16:49:54 | Computer Name = ASER | Source = Service Control Manager | ID = 7031
Description = Služba Vodafone Mobile Connect Service byla nečekaně ukončena. Stalo
se to 12 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat
službu.

Error - 1.7.2013 16:50:54 | Computer Name = ASER | Source = Service Control Manager | ID = 7031
Description = Služba Vodafone Mobile Connect Service byla nečekaně ukončena. Stalo
se to 13 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat
službu.

Error - 1.7.2013 16:51:54 | Computer Name = ASER | Source = Service Control Manager | ID = 7031
Description = Služba Vodafone Mobile Connect Service byla nečekaně ukončena. Stalo
se to 14 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat
službu.

Error - 1.7.2013 16:52:54 | Computer Name = ASER | Source = Service Control Manager | ID = 7031
Description = Služba Vodafone Mobile Connect Service byla nečekaně ukončena. Stalo
se to 15 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat
službu.

Error - 1.7.2013 16:53:57 | Computer Name = ASER | Source = Service Control Manager | ID = 7009
Description = Vypršel časový limit (30000 milisekund) čekání na připojení služby
Vodafone Mobile Connect Service.


< End of report >

Re: policejní vír

Napsal: 02 črc 2013 06:27
od vyosek
:arrow: Spustte znovu OTL
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :otl
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Launch Manager\POWERKEY.sys -- (POWERKEY)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\PhTVTune.sys -- (PhTVTune)
    DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\PCASp50.sys -- (PCASp50)
    DRV - File not found [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\osanbm.sys -- (osanbm)
    DRV - File not found [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\osaio.sys -- (osaio)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Cap7134.sys -- (Cap7134)
    IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
    FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
    [2011.11.10 11:26:50 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-11.xml
    [2012.01.01 12:11:28 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-12.xml
    [2012.01.01 14:11:54 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-13.xml
    [2012.01.20 20:50:28 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-14.xml
    [2012.01.20 22:52:22 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-15.xml
    [2012.04.24 22:49:30 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-16.xml
    [2012.04.25 08:50:12 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-17.xml
    [2012.08.02 21:59:54 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-18.xml
    [2013.02.18 09:53:52 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-19.xml
    [2013.02.18 09:57:42 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-20.xml
    [2013.04.10 08:55:14 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-21.xml
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\{EA614400-E918-4741-9A97-7A972FF7C30B}
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\CENTRUMPOMOCNIK@CENTRUM.CZ
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O4 - HKCU..\Run: [DefaultScope] File not found
    [2013.06.28 21:32:24 | 095,023,320 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\eej88.pad
    [2013.06.25 15:25:18 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2013.06.25 15:09:54 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\michal\Nabídka Start\Programy\Po spuštění\regmonstd.lnk
    [2007.04.24 22:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ Toolbar
    [2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [22 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
    [2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
    [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
    [1 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
    [2012.12.23 15:18:24 | 000,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
    [2013.07.01 22:40:06 | 000,000,636 | -H-- | M] () -- C:\WINDOWS\Tasks\Norton Product InstallerIdle.job
    [2013.07.01 22:40:06 | 000,000,628 | ---- | M] () -- C:\WINDOWS\Tasks\Norton Product Installer.job
    
    :files
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [EMPTYJAVA]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: policejní vír

Napsal: 02 črc 2013 11:22
od zeleninka100
All processes killed
========== OTL ==========
Service POWERKEY stopped successfully!
Service POWERKEY deleted successfully!
File C:\Program Files\Launch Manager\POWERKEY.sys not found.
Service PhTVTune stopped successfully!
Service PhTVTune deleted successfully!
File system32\DRIVERS\PhTVTune.sys not found.
Service PCASp50 stopped successfully!
Service PCASp50 deleted successfully!
File System32\Drivers\PCASp50.sys not found.
Service osanbm stopped successfully!
Service osanbm deleted successfully!
File C:\WINDOWS\system32\drivers\osanbm.sys not found.
Service osaio stopped successfully!
Service osaio deleted successfully!
File C:\WINDOWS\system32\drivers\osaio.sys not found.
Service Cap7134 stopped successfully!
Service Cap7134 deleted successfully!
File system32\DRIVERS\Cap7134.sys not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "ICQ Search" removed from browser.search.selectedEngine
C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-11.xml moved successfully.
C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-12.xml moved successfully.
C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-13.xml moved successfully.
C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-14.xml moved successfully.
C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-15.xml moved successfully.
C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-16.xml moved successfully.
C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-17.xml moved successfully.
C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-18.xml moved successfully.
C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-19.xml moved successfully.
C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-20.xml moved successfully.
C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-21.xml moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DefaultScope deleted successfully.
C:\Documents and Settings\All Users\Data aplikací\eej88.pad moved successfully.
C:\WINDOWS\system32\d3d9caps.dat moved successfully.
C:\Documents and Settings\michal\Nabídka Start\Programy\Po spuštění\regmonstd.lnk moved successfully.
C:\Documents and Settings\michal\Data aplikací\ICQ Toolbar folder moved successfully.
C:\WINDOWS\002644_.tmp deleted successfully.
C:\WINDOWS\DUMP2735.tmp deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1E.tmp\System.Runtime.Remoting.dll deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1E.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP31.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPC3.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP13.tmp\Infragistics2.Win.UltraWinToolbars.v9.2.dll deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP13.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP323.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP18F.tmp\mscorlib.dll deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP18F.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP297.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP338.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP23E.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP31F.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP345.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP37A.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP451.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP46A.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP566.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP57E.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5BA.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP6AE.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP6C7.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP6D9.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP707.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7E4.tmp folder deleted successfully.
C:\WINDOWS\Installer\MSI4.tmp deleted successfully.
C:\WINDOWS\Installer\MSI8.tmp deleted successfully.
C:\WINDOWS\system32\CONFIG.TMP deleted successfully.
C:\WINDOWS\Temp\avg-0e25cc1f-2bdd-4509-afb1-bb3b13a0314d.tmp deleted successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job moved successfully.
C:\WINDOWS\Tasks\Norton Product InstallerIdle.job moved successfully.
C:\WINDOWS\Tasks\Norton Product Installer.job moved successfully.
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 36052 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: michal
->Temp folder emptied: 22323069 bytes
->Temporary Internet Files folder emptied: 36693261 bytes
->Java cache emptied: 195026 bytes
->FireFox cache emptied: 41943022 bytes
->Flash cache emptied: 2996 bytes

User: Default User
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 34967387 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 132618616 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 256,00 mb


[EMPTYFLASH]

User: All Users

User: NetworkService

User: LocalService

User: michal
->Flash cache emptied: 0 bytes

User: Default User

Total Flash Files Cleaned = 0,00 mb


[EMPTYJAVA]

User: All Users

User: NetworkService

User: LocalService

User: michal
->Java cache emptied: 0 bytes

User: Default User

Total Java Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 07022013_121142

Files\Folders moved on Reboot...
C:\Documents and Settings\michal\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Documents and Settings\michal\Local Settings\Temporary Internet Files\Content.IE5\2CFP8P36\zrt_lookup[1].html moved successfully.
C:\Documents and Settings\michal\Local Settings\Temporary Internet Files\Content.IE5\2CFP8P36\afr[1].htm moved successfully.
C:\Documents and Settings\michal\Local Settings\Temporary Internet Files\Content.IE5\2CFP8P36\ads[4].htm moved successfully.
C:\Documents and Settings\michal\Local Settings\Temporary Internet Files\Content.IE5\R8NTTHR4\viewtopic[1].htm moved successfully.
C:\Documents and Settings\michal\Local Settings\Temporary Internet Files\Content.IE5\OAJ6IRTL\iframe[1].htm moved successfully.
File\Folder C:\WINDOWS\temp\_asw_aisI.tm~a02740\setup.lok not found!
File\Folder C:\WINDOWS\temp\_avast_\Webshlock.txt not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Re: policejní vír

Napsal: 02 črc 2013 18:42
od vyosek
Jak se chova PC :???:

Re: policejní vír

Napsal: 02 črc 2013 20:11
od zeleninka100
Je ted rychlejší. Moc děkuji.

Re: policejní vír

Napsal: 02 črc 2013 20:12
od vyosek
Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|

Re: policejní vír

Napsal: 02 črc 2013 20:37
od zeleninka100
Ještě jednou moc děkuji.

Re: policejní vír

Napsal: 02 črc 2013 20:37
od vyosek
Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek

A na zaklade Pravidla o zamykani temat :lock: