Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Spravce uloh-nefunkcni, editor registru nefunkcni....

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
driedl
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 07 dub 2010 18:53

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#16 Příspěvek od driedl »

hotovo za chvili vlozim logy

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#17 Příspěvek od Caroprd111 »

OK :)
Obrázek

driedl
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 07 dub 2010 18:53

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#18 Příspěvek od driedl »

Logfile of random's system information tool 1.06 (written by random/random)
Run by Servis at 2010-04-07 22:13:49
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 9 GB (8%) free of 105 GB
Total RAM: 2047 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:14:08, on 7.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Alwil Software\Avast5\aswRunDll.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Servis\Dokumenty\Downloads\CKScanner.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Servis\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Servis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search13.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search13.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,C:\WINDOWS\system32\MPK\MPK.exe
O1 - Hosts: 216.107.250.194 nprotect.lineage2.com
O1 - Hosts: 81.0.254.162 L2authd.Lineage2.com
O2 - BHO: flashget2 urlcatch - {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\bhoCATCH.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: tom for ie - {8AA217B9-D729-4ee0-AED7-E93D695E94A2} - C:\Program Files\Stylish Profile\tom4ie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O3 - Toolbar: P2P Torrent Toolbar - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Program Files\P2P_Torrent\tbP2P_.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [FlashGet] "C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [NokiaMusic FastStart] "C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe" /command:faststart
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WoW_Hack_V2.5.exe] C:\Documents and Settings\Servis\Local Settings\Temp\
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download All by FlashGet - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\Bhoall.htm
O8 - Extra context menu item: &Download by FlashGet - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\Bholink.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm
O9 - Extra 'Tools' menuitem: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 5058088132
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: ms32clod.dll
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 12385 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{E8A609B0-FFDA-4743-8800-AB9E4BF153EF}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1F364306-AA45-47B5-9F9D-39A8B94E7EF1}]
FG2CatchUrl - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\bhoCATCH.dll [2008-08-19 104016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
ZoneAlarm Toolbar Registrar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2009-10-14 578928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8AA217B9-D729-4ee0-AED7-E93D695E94A2}]
TomBHO Class - C:\Program Files\Stylish Profile\tom4ie.dll [2009-09-24 213504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-25 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-07-25 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7c5c0f58-e061-457d-9033-77307f5ed00c} - TorrentMan Toolbar - C:\Program Files\TorrentMan\tbTorr.dll [2008-07-27 1606680]
{bc4be15d-6a34-4356-9e97-79e43da32b1d} - P2P Torrent Toolbar - C:\Program Files\P2P_Torrent\tbP2P_.dll [2009-03-10 2079256]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2009-08-25 2403392]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]
{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - ZoneAlarm Toolbar - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll [2009-10-14 578928]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-09-17 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-09-17 86016]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-05-26 413696]
"FlashGet"=C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe [2008-08-19 1795656]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-25 149280]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"NokiaMusic FastStart"=C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe [2009-11-06 2090272]
"LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2007-10-25 563984]
"LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam\Quickcam.exe [2007-10-25 2178832]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-11-22 1037192]
"ISW"=C:\Program Files\CheckPoint\ZAForceField\ForceField.exe [2009-10-14 730480]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-03-09 2769336]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-04-01 486856]
"WoW_Hack_V2.5.exe"=C:\Documents and Settings\Servis\Local Settings\Temp\ []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-04-01 486856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2006-04-13 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE [2006-10-23 40048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE [2006-10-23 734872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="ms32clod.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
"DisableRegistryTools"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\THQ\Gas Powered Games\Supreme Commander\bin\SupremeCommander.exe"="C:\Program Files\THQ\Gas Powered Games\Supreme Commander\bin\SupremeCommander.exe:*:Enabled:Supreme Commander"
"C:\Program Files\THQ\Gas Powered Games\Supreme Commander - Forged Alliance\bin\ForgedAlliance.exe"="C:\Program Files\THQ\Gas Powered Games\Supreme Commander - Forged Alliance\bin\ForgedAlliance.exe:*:Enabled:Supreme Commander - Forged Alliance"
"C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe"="C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:*:Enabled:GPGNet - Supreme Commander - Forged Alliance"
"C:\Program Files\EA GAMES\The Battle for Middle-earth (tm)\patchget.dat"="C:\Program Files\EA GAMES\The Battle for Middle-earth (tm)\patchget.dat:*:Enabled:patchgrabber"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\EA GAMES\The Battle for Middle-earth (tm)\game.dat"="C:\Program Files\EA GAMES\The Battle for Middle-earth (tm)\game.dat:*:Enabled:The Battle for Middle-earth (tm)"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Microsoft Games\Rise of Nations\thrones.exe"="C:\Program Files\Microsoft Games\Rise of Nations\thrones.exe:*:Enabled:Rise of Nations"
"C:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe"="C:\Program Files\EA GAMES\Need for Speed Most Wanted\speed.exe:*:Enabled:speed"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe"="C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Disabled:Blizzard Downloader"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Disabled:Blizzard Launcher"
"C:\Program Files\EA GAMES\Mirror's Edge\Binaries\MirrorsEdge.exe"="C:\Program Files\EA GAMES\Mirror's Edge\Binaries\MirrorsEdge.exe:*:Enabled:Mirror's Edge™"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Disabled:Microsoft DirectPlay Helper"
"C:\Program Files\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"="C:\Program Files\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Documents and Settings\Servis\Plocha\BULANCI\bulanci.exe"="C:\Documents and Settings\Servis\Plocha\BULANCI\bulanci.exe:*:Enabled:bulanci"
"C:\Program Files\A4Proxy\A4Proxy.exe"="C:\Program Files\A4Proxy\A4Proxy.exe:*:Enabled:Anonymity 4 Proxy Application"
"%windir%\explorer.exe"="%windir%\explorer.exe:*:Enabled:Explorer"
"C:\Program Files\Remote PC\RPCSER.EXE"="C:\Program Files\Remote PC\RPCSER.EXE:*:Enabled:Remote PC Server"
"C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"D:\Program Files\Sierra\FEAR\FEAR.exe"="D:\Program Files\Sierra\FEAR\FEAR.exe:*:Enabled:FEAR"
"C:\Program Files\BitLord2\BitLord.exe"="C:\Program Files\BitLord2\BitLord.exe:*:Enabled:Bitlord2"
"C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe"="C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe:*:Enabled:Flashget2"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe:*:Enabled:FGLiveUpdate"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe:*:Enabled:FGLiveUpdateEx"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\CatchTheSperm2\catchthesperm2.exe"="C:\Program Files\CatchTheSperm2\catchthesperm2.exe:*:Enabled:catchthesperm2"
"C:\Program Files\Cheat Engine\Cheat Engine Server.exe"="C:\Program Files\Cheat Engine\Cheat Engine Server.exe:*:Enabled:Cheat Engine Server"
"D:\Program Files\Activision\Call of Duty - World at War\CoDWaWmp.exe"="D:\Program Files\Activision\Call of Duty - World at War\CoDWaWmp.exe:*:Enabled:Call of Duty(R) - World at War(TM)"
"D:\Program Files\Activision\Call of Duty - World at War\CoDWaW.exe"="D:\Program Files\Activision\Call of Duty - World at War\CoDWaW.exe:*:Enabled:Call of Duty(R) - World at War(TM)"
"C:\WINDOWS\system32\MPK\Mpk.exe"="C:\WINDOWS\system32\MPK\Mpk.exe:*:Enabled:TCP\IP"
"C:\WINDOWS\system32\MPK\MpkView.exe"="C:\WINDOWS\system32\MPK\MpkView.exe:*:Enabled:TCP\IP"
"C:\Documents and Settings\Servis\Plocha\vsechno mozny\fake mail\Osa8.exe"="C:\Documents and Settings\Servis\Plocha\vsechno mozny\fake mail\Osa8.exe:*:Enabled:Osa8"
"D:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe"="D:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:*:Enabled:Crysis_32"
"D:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe"="D:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:*:Enabled:CrysisDedicatedServer_32"
"C:\Documents and Settings\Servis\Plocha\vsechno mozny\Prográmky\StrongDC.exe"="C:\Documents and Settings\Servis\Plocha\vsechno mozny\Prográmky\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Program Files\Hasbro Interactive\RollerCoaster Tycoon\rct.exe"="C:\Program Files\Hasbro Interactive\RollerCoaster Tycoon\rct.exe:*:Disabled:rct"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe"="C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f490c64-3efa-11de-b066-0018e4079ec7}]
shell\AutoRun\command - K:\browser.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f490c65-3efa-11de-b066-0018e4079ec7}]
shell\AutoRun\command - K:\browser.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae104a58-82a0-11de-b107-0018e4079ec7}]
shell\AutoRun\command - K:\browser.exe


======List of files/folders created in the last 1 months======

2011-03-08 07:38:31 ----D---- C:\Program Files\TrackMania Nations ESWC
2011-03-01 10:54:38 ----D---- C:\Documents and Settings\Servis\Data aplikací\id Software
2011-03-01 10:54:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\id Software
2011-02-23 08:00:09 ----A---- C:\WINDOWS\Čestina do SimCity 4 Rush Hour a Delux BETA Uninstaller.exe
2011-02-22 02:58:17 ----D---- C:\Program Files\Electronic Arts
2011-02-20 22:59:19 ----D---- C:\Program Files\Microsoft WSE
2011-02-20 04:38:04 ----A---- C:\WINDOWS\UniFish3.exe
2011-02-20 04:37:42 ----D---- C:\Program Files\Hasbro Interactive
2011-02-05 05:41:44 ----D---- C:\Program Files\directx
2011-02-05 05:39:49 ----D---- C:\Program Files\Empire Interactive
2011-02-03 07:42:06 ----D---- C:\Program Files\Stylish Profile
2011-01-11 09:04:19 ----D---- C:\Program Files\PowerArchiver
2011-01-11 03:43:52 ----D---- C:\Documents and Settings\Servis\Data aplikací\Canon
2010-04-07 21:59:34 ----D---- C:\Documents and Settings\Servis\Data aplikací\CheckPoint
2010-04-07 21:59:15 ----D---- C:\Program Files\CheckPoint
2010-04-07 21:59:08 ----A---- C:\WINDOWS\system32\vsregexp.dll
2010-04-07 21:59:07 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-04-07 21:58:58 ----D---- C:\Program Files\Alwil Software
2010-04-07 21:58:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-04-07 21:58:55 ----A---- C:\WINDOWS\system32\zlcommdb.dll
2010-04-07 21:58:55 ----A---- C:\WINDOWS\system32\zlcomm.dll
2010-04-07 21:58:51 ----A---- C:\WINDOWS\system32\vswmi.dll
2010-04-07 21:58:50 ----A---- C:\WINDOWS\system32\zpeng25.dll
2010-04-07 21:58:49 ----A---- C:\WINDOWS\system32\vsxml.dll
2010-04-07 21:58:48 ----D---- C:\WINDOWS\system32\ZoneLabs
2010-04-07 21:58:48 ----A---- C:\WINDOWS\system32\vspubapi.dll
2010-04-07 21:58:48 ----A---- C:\WINDOWS\system32\vsmonapi.dll
2010-04-07 21:58:45 ----D---- C:\Program Files\Zone Labs
2010-04-07 21:58:17 ----D---- C:\WINDOWS\Internet Logs
2010-04-07 21:58:12 ----A---- C:\WINDOWS\system32\vsutil.dll
2010-04-07 21:58:12 ----A---- C:\WINDOWS\system32\vsinit.dll
2010-04-07 21:58:12 ----A---- C:\WINDOWS\system32\vsdata.dll
2010-04-07 21:07:37 ----D---- C:\Program Files\trend micro
2010-04-07 21:07:36 ----D---- C:\rsit
2010-03-30 15:07:29 ----D---- C:\Program Files\Active GIF Creator 2.23
2010-03-19 16:12:28 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2010-03-17 23:38:00 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-03-17 22:16:36 ----A---- C:\WINDOWS\system32\LVUI2RC.dll
2010-03-17 22:16:36 ----A---- C:\WINDOWS\system32\LVUI2.dll
2010-03-17 22:16:36 ----A---- C:\WINDOWS\system32\lvcoinst.ini
2010-03-17 22:16:36 ----A---- C:\WINDOWS\system32\lvcodec2.dll
2010-03-17 22:16:36 ----A---- C:\WINDOWS\system32\lvci1150.dll
2010-03-17 22:14:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Logishrd
2010-03-17 22:14:50 ----D---- C:\Program Files\Common Files\LogiShrd
2010-03-17 22:14:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\Logitech
2010-03-17 22:14:45 ----D---- C:\Program Files\Logitech
2010-03-10 13:20:11 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$

======List of files/folders modified in the last 1 months======

2011-03-18 08:29:04 ----D---- C:\Documents and Settings\Servis\Data aplikací\PC Suite
2011-03-18 03:38:06 ----D---- C:\Documents and Settings\Servis\Data aplikací\Ahead
2011-03-01 10:54:33 ----A---- C:\WINDOWS\system32\pbsvc.exe
2011-02-22 13:58:16 ----D---- C:\Documents and Settings\Servis\Data aplikací\BitTorrent
2011-02-21 02:51:12 ----D---- C:\Program Files\EA GAMES
2011-01-12 23:35:24 ----D---- C:\Program Files\Flock
2010-04-07 22:08:21 ----D---- C:\Documents and Settings\Servis\Data aplikací\BITS
2010-04-07 22:07:52 ----D---- C:\WINDOWS\Temp
2010-04-07 22:06:02 ----D---- C:\Program Files\Mozilla Firefox
2010-04-07 22:05:34 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\MPK
2010-04-07 22:04:53 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-07 22:04:43 ----D---- C:\WINDOWS\system32
2010-04-07 22:04:43 ----D---- C:\WINDOWS\Config
2010-04-07 22:04:43 ----D---- C:\Program Files\vghd
2010-04-07 22:04:43 ----D---- C:\Program Files\Eset
2010-04-07 22:03:55 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-07 22:03:24 ----D---- C:\WINDOWS\system32\drivers
2010-04-07 22:02:42 ----D---- C:\Program Files\Google
2010-04-07 22:00:23 ----SHD---- C:\WINDOWS\Installer
2010-04-07 22:00:19 ----SD---- C:\WINDOWS\Tasks
2010-04-07 22:00:08 ----D---- C:\WINDOWS\Prefetch
2010-04-07 21:59:44 ----D---- C:\WINDOWS\WinSxS
2010-04-07 21:59:15 ----RD---- C:\Program Files
2010-04-07 21:58:17 ----D---- C:\WINDOWS
2010-04-07 19:52:10 ----A---- C:\WINDOWS\NeroDigital.ini
2010-04-07 17:59:13 ----D---- C:\Documents and Settings\Servis\Data aplikací\vghd
2010-04-07 17:55:10 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-04-02 12:09:08 ----HD---- C:\WINDOWS\inf
2010-04-02 12:08:59 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-02 12:08:55 ----D---- C:\Program Files\Internet Explorer
2010-04-02 12:08:39 ----D---- C:\WINDOWS\ie8updates
2010-04-02 12:07:37 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-01 08:07:58 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-03-30 15:03:37 ----D---- C:\Program Files\Zoner
2010-03-30 15:03:15 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-03-17 23:38:20 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-17 23:38:01 ----D---- C:\WINDOWS\twain_32
2010-03-17 22:16:56 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-03-17 22:14:50 ----D---- C:\Program Files\Common Files
2010-03-10 13:20:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-03-10 13:20:21 ----A---- C:\WINDOWS\imsins.BAK
2010-03-10 13:20:15 ----D---- C:\Program Files\Movie Maker
2010-03-10 13:18:47 ----A---- C:\WINDOWS\system32\MRT.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-03-09 28880]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-03-09 162640]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-03-09 46672]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2009-11-22 486280]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-03-09 19024]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-03-09 100432]
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2004-07-28 9856]
R2 ISWKL;ZoneAlarm Toolbar ISWKL; \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys []
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-03-09 23376]
R3 ElbyDelay;ElbyDelay; C:\WINDOWS\System32\Drivers\ElbyDelay.sys [2004-06-09 3968]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-01 25280]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-04-17 4707328]
R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys [2007-10-11 25624]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-09-17 6132576]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
S1 anf0100.sys;anf0100.sys; \??\C:\WINDOWS\system32\drivers\anf0100.sys []
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 atdmyuxq;atdmyuxq; C:\WINDOWS\system32\drivers\atdmyuxq.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BTHMODEM;Ovladač komunikace modemu Bluetooth; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-13 37888]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-07-09 16384]
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 HidBth;Miniport Bluetooth HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidbth.sys [2008-04-14 25600]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 LVcKap;Logitech AEC Driver; C:\WINDOWS\system32\DRIVERS\LVcKap.sys [2007-10-19 2109976]
S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys [2007-10-11 2142488]
S3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\LVUSBSta.sys [2007-10-12 41752]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-12 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-07-09 83968]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-07-09 10112]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pepifilter;Volume Adapter; C:\WINDOWS\system32\DRIVERS\lv302af.sys [2007-10-12 13848]
S3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\WINDOWS\system32\DRIVERS\LV302V32.SYS [2007-10-12 1279000]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-07-09 10880]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-07-09 14976]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2006-03-02 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 IswSvc;ZoneAlarm Toolbar IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [2009-10-14 476528]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-07-25 153376]
R2 LVCOMSer;LVCOMSer; C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [2007-10-19 186904]
R2 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2007-10-19 141848]
R2 MySQL;MySQL; C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=C:\Program Files\MySQL\MySQL Server 5.0\my.ini MySQL []
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-09-17 163908]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-09-16 75064]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2006-06-14 167936]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2009-11-22 2384240]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-04-07 133104]
S2 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [2007-10-19 141848]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-03-06 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-25 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe []
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-02-20 307968]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
Naposledy upravil(a) driedl dne 07 dub 2010 20:18, celkem upraveno 1 x.

driedl
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 07 dub 2010 18:53

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#19 Příspěvek od driedl »

CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.HK.11
----- EOF -----

driedl
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 07 dub 2010 18:53

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#20 Příspěvek od driedl »

avast mi dela rychly test zatim 44 procent ale 6 infikovanych souboru.... na 11gb

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#21 Příspěvek od Caroprd111 »

Obrázek Spusťte OTL a do spodního okna vložte následující skript.

Kód: Vybrat vše

:OTL
PRC - [2009.07.28 22:31:01 | 001,201,958 | ---- | M] () -- C:\WINDOWS\Config\csrss.exe
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search13.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search13.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search13.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search13.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search13.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search13.net/
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
FF - HKLM\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\firefox\
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKCU..\Run: [WoW_Hack_V2.5.exe] C:\Documents and Settings\Servis\Local Settings\Temp\ [2010.04.07 21:16:36 | 000,000,000 | ---D | M]
MOD - [2009.09.18 12:51:02 | 000,368,640 | ---- | M] () -- C:\WINDOWS\system32\MPK\Mpk.dll
O20 - AppInit_DLLs: (ms32clod.dll) - File not found
O32 - AutoRun File - [2009.07.14 20:59:13 | 000,000,230 | -HS- | M] () - C:\AUTORUN.inf -- [ NTFS ]
O32 - AutoRun File - [2009.07.14 20:59:13 | 000,000,230 | -HS- | M] () - D:\AUTORUN.inf -- [ NTFS ]
O33 - MountPoints2\{46a3cf43-fe8c-11dd-85e6-806d6172696f}\Shell\AutoRun\command - "" = HICHKAS.EXE Open
O33 - MountPoints2\{46a3cf43-fe8c-11dd-85e6-806d6172696f}\Shell\explore\Command - "" = HICHKAS.EXE Explorer
O33 - MountPoints2\{46a3cf43-fe8c-11dd-85e6-806d6172696f}\Shell\open\Command - "" = HICHKAS.EXE Open
O33 - MountPoints2\{5f490c64-3efa-11de-b066-0018e4079ec7}\Shell\AutoRun\command - "" = K:\browser.exe -- File not found
O33 - MountPoints2\{5f490c65-3efa-11de-b066-0018e4079ec7}\Shell\AutoRun\command - "" = K:\browser.exe -- File not found
O33 - MountPoints2\{ae104a58-82a0-11de-b107-0018e4079ec7}\Shell\AutoRun\command - "" = K:\browser.exe -- File not found
O33 - MountPoints2\{de7fad86-fe99-11dd-afc5-00218532fcc7}\Shell\AutoRun\command - "" = HICHKAS.EXE Open
O33 - MountPoints2\{de7fad86-fe99-11dd-afc5-00218532fcc7}\Shell\explore\Command - "" = HICHKAS.EXE Explorer
O33 - MountPoints2\{de7fad86-fe99-11dd-afc5-00218532fcc7}\Shell\open\Command - "" = HICHKAS.EXE Open
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
[196 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2010.04.07 21:01:00 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
@Alternate Data Stream - 88 bytes -> C:\message.vbs:SummaryInformation
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:538A295C

:Files
C:\Program Files\Ask.com
C:\WINDOWS\Config\csrss.exe
C:\WINDOWS\system32\MPK
C:\Program Files\Cheat Engine
C:\Documents and Settings\Servis\Plocha\vsechno mozny\fake mail\Osa8.exe

:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="explorer.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\WINDOWS\system32\userinit.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"DisableRegistryTools"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\MPK\Mpk.exe"=-
"C:\WINDOWS\system32\MPK\MpkView.exe"=-
"C:\Documents and Settings\Servis\Plocha\vsechno mozny\fake mail\Osa8.exe"=-
"C:\Program Files\Cheat Engine\Cheat Engine Server.exe"=-

:Commands
[PURITY] 
[EMPTYTEMP] 
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[RESETHOSTS] 
[CREATERESTOREPOINT]
[REBOOT]
Poté klikněte na Opravit, PC se restartuje, log vložte sem.
Obrázek

driedl
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 07 dub 2010 18:53

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#22 Příspěvek od driedl »

provedl jsem....vložil jsem skript a dal Opravit. objevila se modra obrazovka a hodilo to chybu ze to mam restart..ted bohuzel nevim kde ten log najít jestli vubec nejaky vznikl

driedl
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 07 dub 2010 18:53

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#23 Příspěvek od driedl »

nasel jsem ho




.daOTL logfile created on: 7.4.2010 21:17:11 - Run 1
OTL by OldTimer - Version 3.2.1.0 Folder = C:\Documents and Settings\Servis\Dokumenty\Stažené soubory
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 66,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 85,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 102,54 Gb Total Space | 9,05 Gb Free Space | 8,83% Space Free | Partition Type: NTFS
Drive D: | 195,54 Gb Total Space | 79,02 Gb Free Space | 40,41% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-814E8961C1
Current User Name: Servis
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.04.07 21:17:02 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Servis\Dokumenty\Stažené soubory\OTL.exe
PRC - [2010.04.04 13:08:20 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009.10.27 19:36:16 | 001,499,136 | ---- | M] (Nokia) -- C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
PRC - [2009.07.28 22:31:01 | 001,201,958 | ---- | M] () -- C:\WINDOWS\Config\csrss.exe
PRC - [2009.05.14 21:39:34 | 005,804,032 | ---- | M] () -- C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
PRC - [2009.02.19 17:29:08 | 000,921,600 | ---- | M] (Eset ) -- C:\Program Files\Eset\nod32kui.exe
PRC - [2009.02.19 17:29:08 | 000,507,904 | ---- | M] (Eset ) -- C:\Program Files\Eset\nod32krn.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.10.25 17:33:22 | 000,563,984 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2007.10.25 17:32:58 | 000,407,824 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2007.10.19 14:19:22 | 000,141,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2007.10.19 14:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe


========== Modules (SafeList) ==========

MOD - [2010.04.07 21:17:02 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Servis\Dokumenty\Stažené soubory\OTL.exe
MOD - [2009.09.18 12:51:02 | 000,368,640 | ---- | M] () -- C:\WINDOWS\system32\MPK\Mpk.dll
MOD - [2008.04.14 05:21:49 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp60.dll
MOD - [2007.10.19 14:19:10 | 000,109,080 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcInj.dll


========== Win32 Services (SafeList) ==========

SRV - [2009.09.17 11:33:26 | 000,651,776 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009.05.14 21:39:34 | 005,804,032 | ---- | M] () [Auto | Running] -- C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe -- (MySQL)
SRV - [2009.03.06 19:22:24 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009.02.20 09:22:47 | 000,307,968 | ---- | M] (TuneUp Software GmbH) [On_Demand | Stopped] -- C:\WINDOWS\system32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2009.02.19 17:29:08 | 000,507,904 | ---- | M] (Eset ) [Auto | Running] -- C:\Program Files\Eset\nod32krn.exe -- (NOD32krn)
SRV - [2008.07.29 19:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008.02.27 14:15:14 | 000,028,416 | ---- | M] (TuneUp Software GmbH) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2007.10.19 14:21:16 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2007.10.19 14:19:22 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2007.10.19 14:17:28 | 000,186,904 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer)


========== Driver Services (SafeList) ==========

DRV - [2009.03.01 11:56:35 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009.02.20 09:23:35 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009.02.19 17:29:08 | 000,502,368 | ---- | M] (Eset ) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\amon.sys -- (AMON)
DRV - [2009.02.09 08:37:56 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2009.02.09 08:37:48 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009.02.09 08:37:46 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009.02.09 08:37:46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008.09.17 03:55:00 | 006,132,576 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2008.08.26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.04.17 10:33:26 | 004,707,328 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008.04.13 19:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) Ovladač zvukové karty USB (WDM)
DRV - [2008.04.13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008.01.03 16:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007.10.19 14:16:30 | 002,109,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2007.10.12 04:00:42 | 000,041,752 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007.10.12 03:55:58 | 001,279,000 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2007.10.12 03:55:58 | 000,013,848 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2007.10.11 19:59:24 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2007.10.11 19:59:02 | 002,142,488 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007.07.03 19:43:56 | 000,132,904 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\imagesrv.sys -- (imagesrv)
DRV - [2007.07.03 19:43:56 | 000,011,304 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\imagedrv.sys -- (imagedrv)
DRV - [2006.07.01 23:42:58 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.11.03 16:40:07 | 000,063,488 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2005.08.10 14:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.05.16 15:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2004.12.03 12:20:41 | 000,020,544 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2004.07.28 21:59:35 | 000,009,856 | ---- | M] (Elaborate Bytes AG) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2004.06.09 00:13:49 | 000,003,968 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search13.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search13.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search13.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search13.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search13.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search13.net/
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: staff@hide-my-ip.com:1.0
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.04.27 15:59:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\firefox\
FF - HKLM\software\mozilla\Flock 2.5.2\extensions\\Components: C:\Program Files\Flock\components [2009.09.23 22:08:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Flock 2.5.2\extensions\\Plugins: C:\Program Files\Flock\plugins [2009.09.23 22:07:24 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.04 13:08:24 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.04 13:08:24 | 000,000,000 | ---D | M]

[2010.01.07 18:50:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Servis\Data aplikací\Mozilla\Extensions
[2009.09.23 22:08:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Servis\Data aplikací\Mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2010.01.07 18:47:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Servis\Data aplikací\Mozilla\Firefox\Profiles\6cm1w891.default\extensions
[2010.01.07 18:47:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Servis\Data aplikací\Mozilla\Firefox\Profiles\6cm1w891.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010.04.07 15:41:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Servis\Data aplikací\Mozilla\Firefox\Profiles\b1pwqq71.default\extensions
[2010.01.07 20:15:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Servis\Data aplikací\Mozilla\Firefox\Profiles\b1pwqq71.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.04.07 15:41:52 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.03.01 13:23:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009.07.22 15:32:56 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\staff@hide-my-ip.com
[2008.11.11 09:38:54 | 000,663,552 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2009.12.22 05:24:43 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2009.12.22 05:24:43 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2009.12.22 05:24:43 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2009.12.22 05:24:43 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2009.12.22 05:24:43 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2009.08.01 23:21:22 | 000,000,095 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 216.107.250.194 nprotect.lineage2.com
O1 - Hosts: 81.0.254.162 L2authd.Lineage2.com
O2 - BHO: (FG2CatchUrl) - {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\bhoCATCH.dll (FlashGet)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (TomBHO Class) - {8AA217B9-D729-4ee0-AED7-E93D695E94A2} - C:\Program Files\Stylish Profile\tom4ie.dll (ChameleonTom)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (TorrentMan Toolbar) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (P2P Torrent Toolbar) - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Program Files\P2P_Torrent\tbP2P_.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\ShellBrowser: (TorrentMan Toolbar) - {7C5C0F58-E061-457D-9033-77307F5ED00C} - C:\Program Files\TorrentMan\tbTorr.dll (Conduit Ltd.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [FlashGet] C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe (FLASHGET)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe (Eset )
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NokiaMusic FastStart] C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe (Nokia)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [WoW_Hack_V2.5.exe] C:\Documents and Settings\Servis\Local Settings\Temp\ [2010.04.07 21:16:36 | 000,000,000 | ---D | M]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: &Download All by FlashGet - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\Bhoall.htm ()
O8 - Extra context menu item: &Download by FlashGet - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\Bholink.htm ()
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm ()
O9 - Extra 'Tools' menuitem : StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm ()
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\imon.dll (Eset )
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\imon.dll (Eset )
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windows ... 5058088132 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/G ... meHost.cab (Oberon Flash Game Host)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (ms32clod.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\WINDOWS\Config\csrss.exe) - C:\WINDOWS\Config\csrss.exe ()
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\MPK\MPK.exe) - C:\WINDOWS\system32\MPK\MPK.exe ()
O20 - HKLM Winlogon: UIHost - (C:\Documents and Settings\All Users\Data aplikací\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe) - C:\Documents and Settings\All Users\Data aplikací\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Servis\Dokumenty\Obrázky\Bez názvu.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Servis\Dokumenty\Obrázky\Bez názvu.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.02.19 15:06:41 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009.07.14 20:59:13 | 000,000,230 | -HS- | M] () - C:\AUTORUN.inf -- [ NTFS ]
O32 - AutoRun File - [2009.07.14 20:59:13 | 000,000,230 | -HS- | M] () - D:\AUTORUN.inf -- [ NTFS ]
O33 - MountPoints2\{46a3cf43-fe8c-11dd-85e6-806d6172696f}\Shell\AutoRun\command - "" = HICHKAS.EXE Open
O33 - MountPoints2\{46a3cf43-fe8c-11dd-85e6-806d6172696f}\Shell\explore\Command - "" = HICHKAS.EXE Explorer
O33 - MountPoints2\{46a3cf43-fe8c-11dd-85e6-806d6172696f}\Shell\open\Command - "" = HICHKAS.EXE Open
O33 - MountPoints2\{5f490c64-3efa-11de-b066-0018e4079ec7}\Shell\AutoRun\command - "" = K:\browser.exe -- File not found
O33 - MountPoints2\{5f490c65-3efa-11de-b066-0018e4079ec7}\Shell\AutoRun\command - "" = K:\browser.exe -- File not found
O33 - MountPoints2\{ae104a58-82a0-11de-b107-0018e4079ec7}\Shell\AutoRun\command - "" = K:\browser.exe -- File not found
O33 - MountPoints2\{de7fad86-fe99-11dd-afc5-00218532fcc7}\Shell\AutoRun\command - "" = HICHKAS.EXE Open
O33 - MountPoints2\{de7fad86-fe99-11dd-afc5-00218532fcc7}\Shell\explore\Command - "" = HICHKAS.EXE Explorer
O33 - MountPoints2\{de7fad86-fe99-11dd-afc5-00218532fcc7}\Shell\open\Command - "" = HICHKAS.EXE Open
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011.03.08 07:38:31 | 000,000,000 | ---D | C] -- C:\Program Files\TrackMania Nations ESWC
[2011.03.01 10:54:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Servis\Data aplikací\id Software
[2011.03.01 10:54:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\id Software
[2011.02.28 03:28:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Servis\Plocha\Nová složka
[2011.02.28 03:28:00 | 004,623,962 | ---- | C] (Macromedia, Inc.) -- C:\Documents and Settings\Servis\ZlatyKalich.exe
[2011.02.23 07:57:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Servis\Dokumenty\SimCity 4
[2011.02.22 02:58:17 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2011.02.20 23:00:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Servis\Dokumenty\Electronic Arts
[2011.02.20 22:59:19 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft WSE
[2011.02.20 04:37:42 | 000,000,000 | ---D | C] -- C:\Program Files\Hasbro Interactive
[2011.02.06 04:48:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Servis\Plocha\Filmy do mp4
[2011.02.05 05:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\Ghost Master
[2011.02.05 05:41:44 | 000,000,000 | ---D | C] -- C:\Program Files\directx
[2011.02.05 05:39:49 | 000,000,000 | ---D | C] -- C:\Program Files\Empire Interactive
[2011.02.03 07:42:06 | 000,000,000 | ---D | C] -- C:\Program Files\Stylish Profile
[2011.01.11 09:04:19 | 000,000,000 | ---D | C] -- C:\Program Files\PowerArchiver
[2011.01.11 03:43:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Servis\Data aplikací\Canon
[2010.04.07 21:07:37 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.07 21:07:36 | 000,000,000 | ---D | C] -- C:\rsit
[2010.04.01 08:08:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Servis\Plocha\patches-US
[2010.03.30 15:07:29 | 000,000,000 | ---D | C] -- C:\Program Files\Active GIF Creator 2.23
[2010.03.19 16:12:28 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2010.03.17 23:38:00 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vfwwdm32.dll
[2010.03.17 23:38:00 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vfwwdm32.dll
[2010.03.17 22:16:36 | 001,279,000 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\drivers\LV302V32.SYS
[2010.03.17 22:16:36 | 000,490,008 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\LVUI2.dll
[2010.03.17 22:16:36 | 000,465,432 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\LVUI2RC.dll
[2010.03.17 22:16:36 | 000,416,280 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\lvcodec2.dll
[2010.03.17 22:16:36 | 000,195,096 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\lvci1150.dll
[2010.03.17 22:16:36 | 000,041,752 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\drivers\LVUSBSta.sys
[2010.03.17 22:16:27 | 000,013,848 | ---- | C] (Logitech Inc.) -- C:\WINDOWS\System32\drivers\lv302af.sys
[2010.03.17 22:14:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Logishrd
[2010.03.17 22:14:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LogiShrd
[2010.03.17 22:14:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Logitech
[2010.03.17 22:14:45 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
[2009.08.03 12:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\TorrentMan
[2009.08.03 12:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\P2P_Torrent
[2009.07.20 12:24:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Apple
[2009.07.08 10:25:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Google
[2009.07.08 10:11:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Google
[2009.02.19 22:55:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.02.19 15:08:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2009.02.19 15:06:39 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2009.02.19 15:06:39 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2004.11.24 20:25:52 | 000,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll
[196 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.03.20 11:05:30 | 632,949,598 | ---- | M] () -- C:\Documents and Settings\Servis\Dokumenty\clip0004.avi
[2011.03.20 10:15:40 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{E8A609B0-FFDA-4743-8800-AB9E4BF153EF}.job
[2011.03.19 14:22:57 | 037,997,592 | ---- | M] () -- C:\Documents and Settings\Servis\Dokumenty\clip0003.avi
[2011.03.19 14:16:29 | 062,334,432 | ---- | M] () -- C:\Documents and Settings\Servis\Dokumenty\clip0002.avi
[2011.03.19 14:13:12 | 001,868,894 | ---- | M] () -- C:\Documents and Settings\Servis\Dokumenty\clip0001.avi
[2011.03.18 09:08:38 | 000,000,109 | ---- | M] () -- C:\Documents and Settings\Servis\default.pls
[2011.03.14 10:58:26 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Crysis_Warhead_V1.0_Plus_10_Trainer_By_KelSat.exe
[2011.03.14 05:04:08 | 000,014,380 | ---- | M] () -- C:\WINDOWS\System32\ealregsnapshot1.reg
[2011.03.12 02:35:39 | 000,152,904 | ---- | M] () -- C:\WINDOWS\System32\vghd.scr
[2011.03.01 10:54:33 | 002,373,712 | ---- | M] () -- C:\WINDOWS\System32\pbsvc.exe
[2011.02.23 08:00:09 | 000,151,831 | ---- | M] () -- C:\WINDOWS\Čestina do SimCity 4 Rush Hour a Delux BETA Uninstaller.exe
[2011.02.23 07:46:07 | 000,000,563 | ---- | M] () -- C:\WINDOWS\eReg.dat
[2011.02.21 02:51:51 | 000,002,035 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\The Sims 2 Pro rodinnou zábavu - Kolekce.lnk
[2011.02.21 01:34:18 | 000,001,972 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 Pojďme slavit! Kolekce.lnk
[2011.02.20 10:29:49 | 000,002,006 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 Sídla a zahrady Kolekce.lnk
[2011.02.20 08:50:17 | 000,002,017 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 Pro luxusní život - Kolekce.lnk
[2011.02.20 07:54:30 | 000,001,970 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 IKEA® Domov Kolekce.lnk
[2011.02.20 05:23:00 | 000,001,988 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 Pro Teenagery Kolekce.lnk
[2011.02.20 03:55:41 | 000,002,204 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 Koupelny a kuchyně Interiérový design Kolekce.lnk
[2011.02.03 07:41:56 | 000,585,325 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\StylishProfile.exe
[2011.01.09 08:03:17 | 000,022,328 | ---- | M] () -- C:\Documents and Settings\Servis\Data aplikací\PnkBstrK.sys
[2011.01.09 08:02:10 | 000,000,834 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Crysis.lnk
[2010.04.07 21:01:00 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010.04.07 21:00:00 | 000,000,488 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2010.04.07 20:31:48 | 000,000,118 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\cokoli.reg
[2010.04.07 20:26:41 | 000,020,480 | ---- | M] () -- C:\WINDOWS\System32\perfc5932.VVdat
[2010.04.07 19:52:46 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\perfc5932.V01dat
[2010.04.07 19:52:45 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\perfc5932.V00dat
[2010.04.07 19:52:10 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.04.07 17:55:34 | 000,000,007 | ---- | M] () -- C:\WINDOWS\sbacknt.bin
[2010.04.07 17:54:57 | 000,200,712 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010.04.07 17:54:36 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.07 17:54:34 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.07 16:46:37 | 000,078,336 | ---- | M] () -- C:\Documents and Settings\Servis\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.04.07 15:53:06 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.06 15:23:05 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\Servis\NTUSER.DAT
[2010.04.02 12:20:08 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Servis\ntuser.ini
[2010.04.01 08:58:53 | 000,000,631 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Wow.lnk
[2010.03.30 20:11:49 | 007,263,744 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Tepelné motory 47.ppt
[2010.03.30 20:08:32 | 004,947,142 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Tepelné motory 46.pptx
[2010.03.30 18:51:37 | 000,364,033 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\4-Stroke-Engine.gif
[2010.03.30 15:32:30 | 000,072,870 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Obrazek.gif
[2010.03.30 15:20:57 | 000,075,336 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\engine-animation.gif
[2010.03.30 15:07:42 | 000,001,653 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Active GIF Creator 2.23.lnk
[2010.03.30 15:04:30 | 000,000,280 | ---- | M] () -- C:\WINDOWS\emm386n.dl
[2010.03.30 14:30:45 | 000,000,165 | -H-- | M] () -- C:\Documents and Settings\Servis\Plocha\~$Tepelné motory.pptx
[2010.03.21 19:15:16 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Servis\Plocha\~$rt recept.docx
[2010.03.21 19:15:12 | 000,012,466 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Dort recept.docx
[2010.03.20 12:37:51 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Servis\Plocha\~$Odklad.docx
[2010.03.20 12:33:16 | 000,011,828 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Odklad.docx
[2010.03.18 21:34:50 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Servis\Plocha\~$uhy vět vedlejších.docx
[2010.03.18 21:32:39 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Servis\Plocha\~$ěmčina.docx
[2010.03.18 18:35:28 | 000,000,760 | ---- | M] () -- C:\Documents and Settings\Servis\Data aplikací\setup_ldm.iss
[2010.03.17 22:17:35 | 000,001,781 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Logitech QuickCam.lnk
[2010.03.17 19:23:59 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Němčina.docx
[2010.03.17 19:21:43 | 000,023,040 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Sloh lyžák David Riedl 2.doc
[2010.03.17 19:21:19 | 000,023,040 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Sloh lyžák David Riedl.doc
[2010.03.17 19:19:59 | 000,010,881 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Sloh lyžák David Riedl.docx
[2010.03.14 21:50:54 | 000,012,215 | ---- | M] () -- C:\Documents and Settings\Servis\Plocha\Druhy vět vedlejších.docx
[2010.03.10 13:20:21 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.03.10 13:18:47 | 000,000,351 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2010.03.10 13:16:21 | 000,096,512 | ---- | M] () -- C:\WINDOWS\System32\drivers\atapi.VV00sys
[196 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.03.20 11:03:22 | 632,949,598 | ---- | C] () -- C:\Documents and Settings\Servis\Dokumenty\clip0004.avi
[2011.03.19 14:18:50 | 037,997,592 | ---- | C] () -- C:\Documents and Settings\Servis\Dokumenty\clip0003.avi
[2011.03.19 14:13:28 | 062,334,432 | ---- | C] () -- C:\Documents and Settings\Servis\Dokumenty\clip0002.avi
[2011.03.19 14:12:54 | 001,868,894 | ---- | C] () -- C:\Documents and Settings\Servis\Dokumenty\clip0001.avi
[2011.03.18 03:38:24 | 000,000,109 | ---- | C] () -- C:\Documents and Settings\Servis\default.pls
[2011.03.14 12:36:20 | 000,012,215 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Druhy vět vedlejších.docx
[2011.03.14 10:58:26 | 000,036,352 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Crysis_Warhead_V1.0_Plus_10_Trainer_By_KelSat.exe
[2011.02.28 03:28:00 | 000,323,072 | ---- | C] () -- C:\Documents and Settings\Servis\player.exe
[2011.02.28 03:28:00 | 000,057,444 | ---- | C] () -- C:\Documents and Settings\Servis\menu.mid
[2011.02.28 03:28:00 | 000,057,084 | ---- | C] () -- C:\Documents and Settings\Servis\rusko.mid
[2011.02.28 03:28:00 | 000,034,381 | ---- | C] () -- C:\Documents and Settings\Servis\karluvm.mid
[2011.02.28 03:28:00 | 000,032,065 | ---- | C] () -- C:\Documents and Settings\Servis\stakan.mid
[2011.02.28 03:28:00 | 000,027,998 | ---- | C] () -- C:\Documents and Settings\Servis\cesko.mid
[2011.02.28 03:28:00 | 000,020,998 | ---- | C] () -- C:\Documents and Settings\Servis\japonsko.mid
[2011.02.28 03:28:00 | 000,019,935 | ---- | C] () -- C:\Documents and Settings\Servis\usa.mid
[2011.02.28 03:28:00 | 000,016,059 | R--- | C] () -- C:\Documents and Settings\Servis\outro.mid
[2011.02.28 03:28:00 | 000,002,032 | ---- | C] () -- C:\Documents and Settings\Servis\chram.mid
[2011.02.28 03:28:00 | 000,000,734 | ---- | C] () -- C:\Documents and Settings\Servis\kalich.sav
[2011.02.28 03:27:59 | 000,087,945 | ---- | C] () -- C:\Documents and Settings\Servis\bunkr.mid
[2011.02.28 03:27:59 | 000,012,784 | ---- | C] () -- C:\Documents and Settings\Servis\casino.mid
[2011.02.23 08:00:09 | 000,151,831 | ---- | C] () -- C:\WINDOWS\Čestina do SimCity 4 Rush Hour a Delux BETA Uninstaller.exe
[2011.02.23 07:46:07 | 000,000,563 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2011.02.21 02:51:51 | 000,002,035 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\The Sims 2 Pro rodinnou zábavu - Kolekce.lnk
[2011.02.21 01:34:18 | 000,001,972 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 Pojďme slavit! Kolekce.lnk
[2011.02.20 10:29:49 | 000,002,006 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 Sídla a zahrady Kolekce.lnk
[2011.02.20 08:50:17 | 000,002,017 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 Pro luxusní život - Kolekce.lnk
[2011.02.20 07:54:30 | 000,001,970 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 IKEA® Domov Kolekce.lnk
[2011.02.20 05:23:00 | 000,001,988 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 Pro Teenagery Kolekce.lnk
[2011.02.20 04:38:04 | 000,045,568 | ---- | C] () -- C:\WINDOWS\UniFish3.exe
[2011.02.20 03:55:41 | 000,002,204 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 2 Koupelny a kuchyně Interiérový design Kolekce.lnk
[2011.02.03 07:41:53 | 000,585,325 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\StylishProfile.exe
[2011.01.11 06:25:25 | 000,663,040 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\c32-rs.exe
[2011.01.09 08:02:10 | 000,000,834 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Crysis.lnk
[2010.04.07 20:31:48 | 000,000,118 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\cokoli.reg
[2010.04.07 20:26:41 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\perfc5932.VVdat
[2010.04.07 19:52:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\perfc5932.V01dat
[2010.04.07 19:52:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\perfc5932.V00dat
[2010.04.01 08:58:53 | 000,000,631 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Wow.lnk
[2010.03.30 20:11:49 | 007,263,744 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Tepelné motory 47.ppt
[2010.03.30 20:08:31 | 004,947,142 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Tepelné motory 46.pptx
[2010.03.30 18:51:37 | 000,364,033 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\4-Stroke-Engine.gif
[2010.03.30 15:32:30 | 000,072,870 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Obrazek.gif
[2010.03.30 15:20:56 | 000,075,336 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\engine-animation.gif
[2010.03.30 15:07:42 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Active GIF Creator 2.23.lnk
[2010.03.30 15:04:30 | 000,000,280 | ---- | C] () -- C:\WINDOWS\emm386n.dl
[2010.03.30 14:30:45 | 000,000,165 | -H-- | C] () -- C:\Documents and Settings\Servis\Plocha\~$Tepelné motory.pptx
[2010.03.21 19:15:03 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Servis\Plocha\~$rt recept.docx
[2010.03.21 19:14:47 | 000,012,466 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Dort recept.docx
[2010.03.20 12:37:51 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Servis\Plocha\~$Odklad.docx
[2010.03.20 12:30:55 | 000,011,828 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Odklad.docx
[2010.03.18 21:34:50 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Servis\Plocha\~$uhy vět vedlejších.docx
[2010.03.18 21:32:39 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Servis\Plocha\~$ěmčina.docx
[2010.03.18 18:35:28 | 000,000,760 | ---- | C] () -- C:\Documents and Settings\Servis\Data aplikací\setup_ldm.iss
[2010.03.17 22:16:36 | 000,059,500 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010.03.17 22:16:36 | 000,021,138 | ---- | C] () -- C:\WINDOWS\System32\Repository.reg
[2010.03.17 22:14:57 | 000,001,781 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Logitech QuickCam.lnk
[2010.03.17 19:23:59 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Němčina.docx
[2010.03.17 19:21:43 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Sloh lyžák David Riedl 2.doc
[2010.03.17 19:21:19 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Sloh lyžák David Riedl.doc
[2010.03.17 19:07:54 | 000,010,881 | ---- | C] () -- C:\Documents and Settings\Servis\Plocha\Sloh lyžák David Riedl.docx
[2010.02.01 23:25:46 | 001,589,248 | ---- | C] () -- C:\WINDOWS\System32\libmysql_d.dll
[2010.01.13 19:58:59 | 000,000,351 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009.12.25 17:05:34 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2009.12.24 23:29:45 | 000,217,520 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2009.09.16 15:45:01 | 000,138,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009.09.08 21:01:38 | 000,000,058 | ---- | C] () -- C:\Documents and Settings\Servis\Local Settings\Data aplikací\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2009.08.30 17:30:17 | 001,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll
[2009.08.03 19:40:17 | 000,000,546 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2009.07.27 20:37:45 | 000,000,941 | ---- | C] () -- C:\WINDOWS\ARPR.INI
[2009.07.14 20:53:51 | 000,000,060 | ---- | C] () -- C:\WINDOWS\MSsetup.ini
[2009.07.14 18:57:13 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Servis\NTUSER.DAT_TU_70431.LOG
[2009.07.01 20:50:57 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\SecureNet.dll
[2009.06.02 22:52:44 | 003,156,992 | -HS- | C] () -- C:\Documents and Settings\Servis\DokumentyPjF2Ye_save2pc.exe
[2009.06.02 22:46:58 | 003,156,992 | -HS- | C] () -- C:\Documents and Settings\Servis\DokumentyUie0Kg_save2pc.exe
[2009.06.02 22:36:27 | 003,156,992 | -HS- | C] () -- C:\Documents and Settings\Servis\DokumentyRmW8Bw_save2pc.exe
[2009.06.02 22:19:16 | 003,156,992 | -HS- | C] () -- C:\Documents and Settings\Servis\DokumentyPqL0M7_save2pc.exe
[2009.06.02 22:12:08 | 003,156,992 | -HS- | C] () -- C:\Documents and Settings\Servis\DokumentyFfg7Po_save2pc.exe
[2009.06.02 22:11:42 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009.04.22 20:04:10 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2009.03.15 21:35:40 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009.03.15 21:35:39 | 000,078,336 | ---- | C] () -- C:\Documents and Settings\Servis\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.02.20 09:34:53 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Servis\Data aplikací\PnkBstrK.sys
[2009.02.20 09:23:35 | 000,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009.02.19 22:48:16 | 000,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys
[2009.02.19 17:17:35 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\Servis\ntuser.dat.LOG
[2009.02.19 17:17:35 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Servis\ntuser.ini
[2009.02.19 17:17:34 | 005,767,168 | ---- | C] () -- C:\Documents and Settings\Servis\NTUSER.DAT
[2009.02.19 17:17:34 | 004,456,448 | -H-- | C] () -- C:\Documents and Settings\Servis\NTUSER.DAT_BAK_70431
[2008.10.07 09:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008.09.17 03:55:00 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008.09.17 03:55:00 | 001,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008.09.17 03:55:00 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008.09.17 03:55:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008.09.17 03:55:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008.06.05 09:58:26 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2007.11.26 22:56:28 | 000,151,415 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2007.10.11 19:59:24 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007.03.29 22:00:40 | 000,203,264 | ---- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
[2005.10.14 12:56:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 12:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 12:56:50 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 12:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 12:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005.10.14 12:56:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 12:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 12:56:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2004.10.12 07:40:58 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2004.10.12 07:39:48 | 000,028,160 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2004.10.12 07:39:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2004.10.09 07:40:16 | 000,454,144 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2004.10.05 09:16:08 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2004.10.03 18:50:54 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\message.vbs:SummaryInformation
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:538A295C
< End of report >









antivirus nasel nejaky malware tak je kdyztak v truhle :)

driedl
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 07 dub 2010 18:53

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#24 Příspěvek od driedl »

a problem se spoustenim editoru registru a uloh stale pretrvava

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#25 Příspěvek od Caroprd111 »

Zkuste skript v nouzovém režimu.
Obrázek

driedl
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 07 dub 2010 18:53

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#26 Příspěvek od driedl »

zkusil jsem skript v nouzovem rezimu zase modra obazovka ale zadny novy log se nevytvoril, v nouzovem rezimu se na uvodni obrazovce kde je napsano ,,vítejte,, objevil novy uzivatel administrator, nema heslo kdyz se na nej prohlasim funguje vse - spravce uloh i registr vse a neobjevuje se pri prihlaseni na muj ucet hned na zacatku slozka temp

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#27 Příspěvek od Caroprd111 »

Obrázek Stáhněte a uložte, nejlépe na plochu http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypněte všechny rezidentní bezpečnostní programy - firewally, antiviry, antispywary
  • Vložte do PC všechny flash disky, které používáte.
  • Spusťte aplikaci pod účtem s oprávněním Administrátora (Správce), ihned po startu se zobrazí stránka s licenčními podmínkami, pokračujte stisknutím tlačítka "Ano"
  • Dále postupujte dle pokynů, během scanu nespouštějte jiné aplikace a neklikejte do zobrazujícího se okna :!:
  • Scan by měl trvat okolo 5 - 10 minut, po dokončení Combofix zobrazí log C:\ComboFix.txt , který sem vložte.
  • Během skenování může být počítač restartován.
Obrázek

driedl
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 07 dub 2010 18:53

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#28 Příspěvek od driedl »

muzu v nouzovem rezimu?

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#29 Příspěvek od Caroprd111 »

Ano. :)
Obrázek

driedl
Návštěvník
Návštěvník
Příspěvky: 23
Registrován: 07 dub 2010 18:53

Re: Spravce uloh-nefunkcni, editor registru nefunkcni....

#30 Příspěvek od driedl »

mam problem ten log ma 242433 znaku a tady je povolenych 60000 takze , vetsina logu je toto
ukazka:
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3277690972
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3312413194
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3347135417
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3381857639
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3416579861
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3451302083
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3486024306
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3520746528
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3555468750
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3590190972
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3624913194
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3659635417
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3694357639
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3729079861
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3763802083
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3798524306
c:\documents and settings\All Users\Data aplikací\MPK\1\I40554_3833246528
c:\documents and settings\All Users\Data aplikací\MPK\1\I40555_2329864699
c:\documents and settings\All Users\Data aplikací\MPK\1\I40555_2364586921
c:\documents and settings\All Users\Data aplikací\MPK\1\I40555_2399309144
c:\documents and settings\All Users\Data aplikací\MPK\1\I40555_2434031366
c:\documents and settings\All Users\Data aplikací\MPK\1\I40555_2468753588
c:\documents and settings\All Users\Data aplikací\MPK\1\I40555_2503475810
c:\documents and settings\All Users\Data aplikací\MPK\1\I40555_2538198032
c:\documents and settings\All Users\Data aplikací\MPK\1\I40555_2572920255
c:\documents and settings\All Users\Data aplikací\MPK\1\I40555_2607642477
c:\documents and settings\All Users\Data aplikací\MPK\1\I40555_2642364699
c:\documents and settings\All Users\Data aplikací\MPK\1\I40555_2677086921

Odpovědět