Re: Prosim o radu a omrknuti logu... diky
Napsal: 05 srp 2010 21:17
OTL
OTL logfile created on: 5. 8. 2010 22:13:00 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = G:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d. M. yyyy
1 022,00 Mb Total Physical Memory | 838,00 Mb Available Physical Memory | 82,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 97,00% Paging File free
Paging file location(s): C:\pagefile.sys 2048 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143,42 Gb Total Space | 121,22 Gb Free Space | 84,52% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 7,67 Gb Total Space | 0,08 Gb Free Space | 0,99% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LENOVO3000N200
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: SafeMode
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.08.05 22:03:00 | 000,574,976 | ---- | M] (OldTimer Tools) -- G:\OTL.exe
PRC - [2008.07.07 08:15:18 | 000,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2008.04.14 16:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010.08.05 22:03:00 | 000,574,976 | ---- | M] (OldTimer Tools) -- G:\OTL.exe
MOD - [2008.04.14 16:00:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2010.08.05 22:11:26 | 000,017,408 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\rpcnetp.exe -- (rpcnetp)
SRV - [2009.11.25 01:51:35 | 000,138,680 | ---- | M] (ALWIL Software) [Auto | Stopped] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2009.11.25 01:51:21 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009.11.25 01:48:48 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009.11.25 01:43:56 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Stopped] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2009.09.18 17:48:28 | 000,009,216 | ---- | M] (Vodafone) [Auto | Stopped] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2008.07.29 19:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008.07.07 08:15:18 | 000,611,664 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice)
SRV - [2007.04.16 12:33:18 | 000,647,168 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2007.04.16 12:21:20 | 000,983,040 | ---- | M] (Intel Corporation ) [Auto | Stopped] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel(R)
SRV - [2007.04.16 12:14:24 | 000,327,680 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2007.04.09 11:24:32 | 000,054,832 | ---- | M] (Lenovo.) [Auto | Stopped] -- C:\Program Files\Lenovo\HOTKEY\FnF5svc.exe -- (FNF5SVC)
SRV - [2007.03.16 06:26:22 | 000,057,344 | ---- | M] (Lenovo) [Auto | Stopped] -- C:\Program Files\Lenovo\PM Driver\PMSveH.exe -- (PMSveH)
SRV - [2007.01.19 16:16:46 | 000,061,440 | ---- | M] (AuthenTec,Inc) [Auto | Stopped] -- C:\WINDOWS\system32\FpLogonServ.exe -- (FingerprintServer)
SRV - [2006.12.19 17:53:46 | 000,024,072 | ---- | M] (TuneUp Software GmbH) [Auto | Stopped] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2006.11.11 22:56:18 | 000,266,295 | ---- | M] (Broadcom Corporation.) [Auto | Stopped] -- C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe -- (btwdins)
SRV - [2006.11.06 14:21:10 | 000,210,432 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2005.07.08 18:24:46 | 000,871,424 | ---- | M] (Nero AG) [Auto | Stopped] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
SRV - [2005.06.14 23:40:54 | 000,491,520 | ---- | M] () [On_Demand | Stopped] -- C:\WINDOWS\System32\LMabcoms.exe -- (lmab_device)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\pcdrndisuio.sys -- (PcdrNdisuio)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lmimirr.sys -- (lmimirr)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\TEMP\INSTB32.SYS -- (INSTB32)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\Temp\EverestDriver.sys -- (EverestDriver)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Veronika\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010.08.04 22:36:06 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010.04.29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2009.11.25 01:50:59 | 000,094,160 | ---- | M] (ALWIL Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2009.11.25 01:50:12 | 000,114,768 | ---- | M] (ALWIL Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2009.11.25 01:50:00 | 000,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009.11.25 01:49:07 | 000,048,560 | ---- | M] (ALWIL Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2009.11.25 01:48:57 | 000,023,120 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2009.11.25 01:47:54 | 000,027,408 | ---- | M] (ALWIL Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009.07.23 11:57:22 | 000,112,640 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009.07.23 11:57:22 | 000,102,528 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2009.07.23 11:57:22 | 000,100,480 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbfake.sys -- (hwusbfake)
DRV - [2009.06.19 13:59:10 | 000,012,928 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgvmodem.sys -- (LGVMODEM)
DRV - [2009.06.19 13:59:04 | 000,012,032 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgbtport.sys -- (LgBttPort)
DRV - [2009.06.19 13:59:02 | 000,010,496 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lgbtbus.sys -- (lgbusenum)
DRV - [2009.05.14 18:12:45 | 000,277,784 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2008.04.14 16:00:00 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007.08.07 21:48:33 | 000,025,160 | ---- | M] (Elaborate Bytes AG) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2007.04.30 07:37:20 | 002,206,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Ovladač adaptéru Intel(R)
DRV - [2007.04.10 16:55:28 | 000,140,808 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atswpdrv.sys -- (ATSWPDRV) (****DEBUG****) AuthenTec TruePrint USB Driver (SwipeSensor)
DRV - [2007.03.29 16:19:36 | 000,012,416 | ---- | M] (Intel Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2007.03.21 22:31:32 | 003,684,512 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2007.02.24 15:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007.02.16 16:46:00 | 000,160,256 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2007.01.30 19:57:00 | 004,474,368 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.01.23 18:03:28 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007.01.23 17:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006.11.13 11:41:20 | 000,862,922 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2006.10.30 11:52:04 | 000,329,901 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2006.10.30 11:51:40 | 000,067,672 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2006.10.30 11:51:30 | 000,149,123 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2006.10.30 11:51:24 | 000,030,459 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2006.10.10 08:54:34 | 000,138,240 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (Nokia USB Phone Parent)
DRV - [2006.10.10 08:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcj.sys -- (Nokia USB Port)
DRV - [2006.10.10 08:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (Nokia USB Modem)
DRV - [2006.10.10 08:54:32 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (Nokia USB Generic)
DRV - [2006.08.30 15:53:00 | 001,161,152 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.07.12 11:58:02 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)
DRV - [2006.05.24 12:48:14 | 000,010,240 | ---- | M] (Lenovo ) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\PMHler.sys -- (PMHler)
DRV - [2006.05.19 15:24:20 | 000,193,088 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2005.07.08 18:17:54 | 000,099,584 | ---- | M] (Nero AG) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005.07.08 18:17:36 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2004.08.22 17:31:48 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\d347prt.sys -- (d347prt)
DRV - [2004.08.22 17:31:10 | 000,155,136 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\d347bus.sys -- (d347bus)
DRV - [2002.11.28 16:18:04 | 000,015,360 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2002.11.28 12:43:49 | 000,022,016 | ---- | M] (Elaborate Bytes AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys -- (ElbyVCD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1202660629-1844823847-839522115-500\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1202660629-1844823847-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.07.01 15:06:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.07.15 11:48:45 | 000,000,000 | ---D | M]
[2010.08.05 13:13:58 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.10.26 18:43:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.05.10 20:55:09 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.05.08 21:15:02 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.05.08 21:15:02 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.05.08 21:15:02 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.05.08 21:15:02 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.05.08 21:15:02 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2010.08.04 22:24:17 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe File not found
O4 - HKLM..\Run: [FingerPrintSoftware] C:\Program Files\Lenovo Fingerprint Software\fpapp.exe (Authentec,Inc)
O4 - HKLM..\Run: [Lexmark X6100 Series] C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PMHandler] C:\Program Files\Lenovo\PM Driver\PMHandler.exe (Lenovo)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk = C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1202660629-1844823847-839522115-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1202660629-1844823847-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-1202660629-1844823847-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-21-1202660629-1844823847-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} http://www-307.ibm.com/pc/support/acpir.cab (IASRunner Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ATFUS: DllName - C:\WINDOWS\system32\FpWinLogonNp.dll - C:\WINDOWS\system32\FpWinlogonNp.dll (AuthenTec,Inc)
O20 - Winlogon\Notify\tphotkey: DllName - C:\Program Files\Lenovo\HOTKEY\tphklock.dll - C:\Program Files\Lenovo\HOTKEY\tphklock.dll (Lenovo Group Limited)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010.08.05 21:48:06 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.08.05 16:20:22 | 001,204,586 | ---- | C] (C_XX & El Desaparecido) -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\UsbFix.exe
[2010.08.04 23:34:07 | 000,000,000 | ---D | C] -- C:\Intel
[2010.08.04 23:03:58 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.08.04 22:52:52 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.08.04 22:36:06 | 000,691,696 | ---- | C] (Duplex Secure Ltd.) -- C:\WINDOWS\System32\drivers\sptd.sys
[2010.08.04 22:35:59 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2010.08.04 22:35:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.08.04 22:21:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010.08.04 22:14:49 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.08.04 19:54:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\VDLL.DLL
[2010.08.04 19:54:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\RUNDL132.EXE
[2010.08.04 19:54:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\logo1_.exe
[2010.08.04 19:54:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\runouce.exe
[2010.08.04 19:54:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\rundll16.exe
[2010.08.04 19:54:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\logo_1.exe
[2010.08.04 19:53:07 | 000,632,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2010.08.04 19:53:06 | 000,554,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2010.08.04 19:53:04 | 000,034,048 | ---- | C] (MicroWorld Technologies Inc.) -- C:\WINDOWS\System32\eEmpty.exe
[2010.08.04 19:53:02 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\R.COM
[2010.08.04 19:53:02 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\T.COM
[2010.08.04 19:53:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MicroWorld
[2010.08.04 19:52:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2010.08.04 19:25:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Data aplikací\GRETECH
[2010.08.04 19:25:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Data aplikací\Adobe
[2010.08.04 19:06:25 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.08.04 19:06:25 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.08.04 19:06:25 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.08.04 19:06:25 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe.mwt
[2010.08.04 19:06:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.08.04 19:05:29 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.08.04 18:24:14 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.08.04 18:23:22 | 000,000,000 | ---D | C] -- C:\ComboFix23459C
[2010.08.04 18:21:10 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\PrivacIE
[2010.08.04 18:15:39 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2010.08.04 18:08:26 | 000,000,000 | ---D | C] -- C:\ComboFix2
[2010.08.04 17:59:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Data aplikací\Malwarebytes
[2010.08.04 17:59:30 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.08.04 17:59:29 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.08.04 17:59:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.08.04 17:23:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2010.08.04 16:28:23 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010.08.04 08:32:47 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\IETldCache
[2010.08.04 08:32:25 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Data aplikací\Microsoft
[2010.08.04 08:32:25 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\SendTo
[2010.08.04 08:32:25 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Data aplikací
[2010.08.04 08:32:25 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Nabídka Start
[2010.08.04 08:32:25 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Cookies
[2010.08.04 08:32:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Šablony
[2010.08.04 08:32:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Recent
[2010.08.04 08:32:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Okolní tiskárny
[2010.08.04 08:32:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Okolní síť
[2010.08.04 08:32:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Local Settings
[2010.08.04 08:32:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha
[2010.08.04 08:32:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Oblíbené položky
[2010.08.04 08:32:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Local Settings\Data aplikací\Microsoft
[2010.08.04 08:32:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Dokumenty
[2010.08.02 22:01:54 | 000,000,000 | ---D | C] -- C:\Program Files\GRETECH
[2010.08.02 21:20:31 | 000,000,000 | ---D | C] -- C:\found.001
[2010.08.02 21:16:41 | 000,232,448 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\WINDOWS\System32\mp3fhg.acm
[2010.08.02 21:16:41 | 000,217,088 | ---- | C] (www.helixcommunity.org) -- C:\WINDOWS\System32\yv12vfw.dll
[2010.08.02 21:16:41 | 000,151,552 | ---- | C] (fccHandler) -- C:\WINDOWS\System32\ac3acm.acm
[2010.08.02 21:16:40 | 000,720,384 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\divx.dll
[2010.08.02 21:16:40 | 000,094,208 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\dpl100.dll
[2010.08.02 21:16:35 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack
[2010.07.22 18:56:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Vodafone
[2010.07.22 18:56:27 | 000,000,000 | ---D | C] -- C:\Program Files\Vodafone
[2010.07.15 12:38:00 | 000,000,000 | ---D | C] -- C:\Program Files\Trans
[2009.01.13 13:40:32 | 000,155,136 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347bus.sys
[2009.01.13 13:40:32 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys
[2008.04.02 13:31:36 | 000,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\lexlog.dll
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.08.05 22:11:56 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.08.05 22:11:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.08.05 22:11:33 | 000,000,000 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2010.08.05 22:11:26 | 000,017,408 | ---- | M] () -- C:\WINDOWS\System32\rpcnetp.exe
[2010.08.05 22:08:00 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{752B43E6-B86D-40EC-A2D7-1CADB49EE03A}.job
[2010.08.05 21:56:46 | 000,051,048 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010.08.05 21:56:34 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.08.05 21:54:06 | 000,000,940 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.08.05 21:51:59 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.08.05 21:44:25 | 000,017,408 | ---- | M] () -- C:\WINDOWS\System32\rpcnetp.dll
[2010.08.05 21:39:17 | 000,786,432 | -H-- | M] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\NTUSER.DAT
[2010.08.05 21:39:17 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\ntuser.ini
[2010.08.05 21:39:16 | 004,240,656 | -H-- | M] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\Local Settings\Data aplikací\IconCache.db
[2010.08.05 21:36:16 | 000,442,873 | ---- | M] () -- C:\WINDOWS\System32\drivers\fwdrv.err
[2010.08.05 08:45:02 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.08.05 08:44:50 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\agremove.exe
[2010.08.04 22:48:40 | 001,204,586 | ---- | M] (C_XX & El Desaparecido) -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\UsbFix.exe
[2010.08.04 22:36:08 | 000,001,613 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\DAEMON Tools Lite.lnk
[2010.08.04 22:36:06 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) -- C:\WINDOWS\System32\drivers\sptd.sys
[2010.08.04 22:32:52 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.08.04 22:25:56 | 000,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.08.04 22:24:48 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.08.04 22:24:17 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.08.04 21:44:08 | 000,000,569 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.08.04 19:53:22 | 000,000,028 | ---- | M] () -- C:\WINDOWS\Lic.xxx
[2010.08.04 19:53:06 | 000,632,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2010.08.04 19:53:05 | 000,554,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2010.08.04 19:53:03 | 000,034,048 | ---- | M] (MicroWorld Technologies Inc.) -- C:\WINDOWS\System32\eEmpty.exe
[2010.08.04 19:25:17 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.08.04 18:04:28 | 003,749,693 | R--- | M] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\ComboFix2.exe
[2010.08.04 17:03:52 | 005,153,350 | ---- | M] () -- C:\WINDOWS\REGBK00.ZIP
[2010.08.04 16:28:24 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\HijackThis.lnk
[2010.08.03 11:30:13 | 000,000,156 | ---- | M] () -- C:\WINDOWS\z.reg
[2010.08.02 22:02:02 | 000,000,762 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\GOM Player.lnk
[2010.08.02 21:44:00 | 000,002,557 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Vodafone Mobile Connect.lnk
[2010.08.02 12:25:00 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\Vyčištění disku.job
[2010.07.29 14:56:15 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
[2010.07.27 08:30:31 | 008,466,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shell32.dll
[2010.07.25 21:03:41 | 000,002,511 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Vodafone SMS.lnk
[2010.07.15 11:48:46 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Adobe Reader 9.lnk
[2010.07.15 10:06:05 | 000,000,642 | ---- | M] () -- C:\WINDOWS\lexstat.ini
[2010.07.14 10:00:00 | 000,108,032 | ---- | M] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.07.14 10:00:00 | 000,000,038 | ---- | M] () -- C:\WINDOWS\avisplitter.ini
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.08.05 08:41:13 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\rpcnetp.dll
[2010.08.05 08:40:31 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\rpcnetp.exe
[2010.08.04 22:36:08 | 000,001,613 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\DAEMON Tools Lite.lnk
[2010.08.04 22:25:56 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.08.04 19:53:22 | 000,000,028 | ---- | C] () -- C:\WINDOWS\Lic.xxx
[2010.08.04 19:06:25 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.08.04 19:06:25 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.08.04 19:06:25 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.08.04 19:06:25 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.08.04 19:06:25 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.08.04 18:24:20 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.08.04 18:24:16 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.08.04 18:16:59 | 003,749,693 | R--- | C] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\ComboFix2.exe
[2010.08.04 17:03:21 | 005,153,350 | ---- | C] () -- C:\WINDOWS\REGBK00.ZIP
[2010.08.04 16:55:49 | 000,000,522 | ---- | C] () -- C:\WINDOWS\System32\Microsoft.VC80.CRT.manifest
[2010.08.04 16:28:24 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\HijackThis.lnk
[2010.08.04 08:32:28 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\ntuser.ini
[2010.08.04 08:32:25 | 000,786,432 | -H-- | C] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\NTUSER.DAT
[2010.08.04 08:32:25 | 000,073,728 | -H-- | C] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\NtUser.dat.LOG
[2010.08.03 11:30:03 | 000,000,156 | ---- | C] () -- C:\WINDOWS\z.reg
[2010.08.02 22:02:02 | 000,000,762 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\GOM Player.lnk
[2010.08.02 21:16:43 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010.08.02 21:16:42 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010.08.02 21:16:40 | 000,790,528 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010.08.02 21:16:40 | 000,134,144 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.08.02 21:16:39 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.08.02 21:16:39 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010.07.22 18:56:33 | 000,002,557 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Vodafone Mobile Connect.lnk
[2010.07.22 18:56:33 | 000,002,511 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Vodafone SMS.lnk
[2008.04.30 09:36:16 | 000,000,641 | ---- | C] () -- C:\WINDOWS\SESTDLL.INI
[2008.04.03 09:41:39 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxbfvs.dll
[2008.04.03 09:41:07 | 000,000,188 | ---- | C] () -- C:\WINDOWS\System32\lxbfcoin.ini
[2008.04.03 09:35:40 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\LXBFLCNP.DLL
[2008.04.02 13:46:47 | 000,000,642 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2008.04.02 13:33:04 | 000,000,507 | ---- | C] () -- C:\WINDOWS\LMABB2DD.ini
[2008.04.02 13:31:12 | 001,134,592 | ---- | C] () -- C:\WINDOWS\System32\LMabusb1.dll
[2008.04.02 13:31:12 | 000,630,784 | ---- | C] () -- C:\WINDOWS\System32\LMabpmui.dll
[2008.04.02 13:31:11 | 001,183,744 | ---- | C] () -- C:\WINDOWS\System32\LMabserv.dll
[2008.04.02 13:31:10 | 000,507,904 | ---- | C] () -- C:\WINDOWS\System32\LMabpar1.dll
[2008.04.02 13:31:10 | 000,491,520 | ---- | C] () -- C:\WINDOWS\System32\LMablmpm.dll
[2008.04.02 13:31:10 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\LMabprox.dll
[2008.04.02 13:31:10 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\LMabpplc.dll
[2008.04.02 13:31:09 | 000,733,184 | ---- | C] () -- C:\WINDOWS\System32\LMabip1.dll
[2008.04.02 13:31:09 | 000,413,696 | ---- | C] () -- C:\WINDOWS\System32\LMabcomm.dll
[2008.04.02 13:31:08 | 000,704,512 | ---- | C] () -- C:\WINDOWS\System32\LMabcomc.dll
[2008.03.29 18:41:23 | 000,000,101 | ---- | C] () -- C:\WINDOWS\DVDIdlePro.INI
[2008.03.29 16:35:13 | 000,000,140 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2008.03.29 15:55:22 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.03.29 15:33:23 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008.03.29 11:46:13 | 000,000,135 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.03.25 16:58:41 | 000,004,672 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2008.03.25 16:46:18 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2007.03.21 23:31:34 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007.03.21 23:31:34 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007.03.21 23:31:32 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007.03.21 23:31:32 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2007.03.21 23:31:32 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007.03.21 23:31:32 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006.11.11 22:50:38 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2006.03.02 13:00:00 | 000,002,048 | ---- | C] () -- C:\WINDOWS\System32\syscvchk.dll
[2005.02.17 12:41:32 | 000,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005.02.17 12:41:30 | 000,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2001.11.14 13:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
========== LOP Check ==========
[2010.02.07 22:03:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
[2010.08.04 22:35:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.04.12 17:47:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DivoGames
[2010.04.12 10:53:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Downloaded Installations
[2008.06.09 11:32:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Grisoft
[2009.10.26 18:43:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2009.01.03 12:38:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IMSIDesign
[2008.06.20 08:09:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\LogMeIn
[2010.08.04 19:53:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2008.04.04 11:43:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2008.03.25 18:30:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC-Doctor
[2008.03.29 15:59:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2009.01.03 12:41:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TurboFLOORPLAN Dum & Interiér & Zahrada Pro
[2010.07.22 18:56:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Vodafone
[2008.03.30 12:37:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\Elaborate Bytes
[2010.02.15 13:45:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\MAXON
[2008.04.04 11:45:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\Nokia
[2008.04.04 11:33:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\PC Suite
[2010.08.03 14:04:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\RST
[2008.03.29 15:59:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\TuneUp Software
[2010.06.16 19:31:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\Vodafone
[2010.04.27 19:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Vodafone
[2008.10.05 13:23:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\AVGTOOLBAR
[2010.08.04 22:40:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\DAEMON Tools Lite
[2009.10.26 18:44:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\ICQ
[2009.11.13 15:34:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\LG Electronics
[2009.02.20 17:06:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\Nokia
[2009.02.20 17:03:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\PC Suite
[2010.04.12 17:17:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\Retriever
[2010.07.15 12:38:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\RST
[2009.11.26 21:46:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\TMInc
[2008.11.04 16:38:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\TuneUp Software
[2010.04.27 19:05:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\Vodafone
[2009.11.13 15:34:33 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Veronika\Data aplikací\{D94BA408-F110-488B-A65E-3AE7945F79E6}
[2010.01.01 18:15:00 | 000,000,390 | ---- | M] () -- C:\WINDOWS\Tasks\1-Click Maintenance.job
[2010.08.05 22:08:00 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{752B43E6-B86D-40EC-A2D7-1CADB49EE03A}.job
[2010.08.02 12:25:00 | 000,000,266 | ---- | M] () -- C:\WINDOWS\Tasks\Vyčištění disku.job
========== Purity Check ==========
< End of report >
OTL logfile created on: 5. 8. 2010 22:13:00 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = G:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d. M. yyyy
1 022,00 Mb Total Physical Memory | 838,00 Mb Available Physical Memory | 82,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 97,00% Paging File free
Paging file location(s): C:\pagefile.sys 2048 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143,42 Gb Total Space | 121,22 Gb Free Space | 84,52% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 7,67 Gb Total Space | 0,08 Gb Free Space | 0,99% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LENOVO3000N200
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: SafeMode
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.08.05 22:03:00 | 000,574,976 | ---- | M] (OldTimer Tools) -- G:\OTL.exe
PRC - [2008.07.07 08:15:18 | 000,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2008.04.14 16:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010.08.05 22:03:00 | 000,574,976 | ---- | M] (OldTimer Tools) -- G:\OTL.exe
MOD - [2008.04.14 16:00:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2010.08.05 22:11:26 | 000,017,408 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\rpcnetp.exe -- (rpcnetp)
SRV - [2009.11.25 01:51:35 | 000,138,680 | ---- | M] (ALWIL Software) [Auto | Stopped] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2009.11.25 01:51:21 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009.11.25 01:48:48 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009.11.25 01:43:56 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Stopped] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2009.09.18 17:48:28 | 000,009,216 | ---- | M] (Vodafone) [Auto | Stopped] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2008.07.29 19:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008.07.07 08:15:18 | 000,611,664 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice)
SRV - [2007.04.16 12:33:18 | 000,647,168 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2007.04.16 12:21:20 | 000,983,040 | ---- | M] (Intel Corporation ) [Auto | Stopped] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel(R)
SRV - [2007.04.16 12:14:24 | 000,327,680 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2007.04.09 11:24:32 | 000,054,832 | ---- | M] (Lenovo.) [Auto | Stopped] -- C:\Program Files\Lenovo\HOTKEY\FnF5svc.exe -- (FNF5SVC)
SRV - [2007.03.16 06:26:22 | 000,057,344 | ---- | M] (Lenovo) [Auto | Stopped] -- C:\Program Files\Lenovo\PM Driver\PMSveH.exe -- (PMSveH)
SRV - [2007.01.19 16:16:46 | 000,061,440 | ---- | M] (AuthenTec,Inc) [Auto | Stopped] -- C:\WINDOWS\system32\FpLogonServ.exe -- (FingerprintServer)
SRV - [2006.12.19 17:53:46 | 000,024,072 | ---- | M] (TuneUp Software GmbH) [Auto | Stopped] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2006.11.11 22:56:18 | 000,266,295 | ---- | M] (Broadcom Corporation.) [Auto | Stopped] -- C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe -- (btwdins)
SRV - [2006.11.06 14:21:10 | 000,210,432 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2005.07.08 18:24:46 | 000,871,424 | ---- | M] (Nero AG) [Auto | Stopped] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
SRV - [2005.06.14 23:40:54 | 000,491,520 | ---- | M] () [On_Demand | Stopped] -- C:\WINDOWS\System32\LMabcoms.exe -- (lmab_device)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\pcdrndisuio.sys -- (PcdrNdisuio)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\lmimirr.sys -- (lmimirr)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\TEMP\INSTB32.SYS -- (INSTB32)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ADMINI~1.LEN\LOCALS~1\Temp\EverestDriver.sys -- (EverestDriver)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Veronika\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010.08.04 22:36:06 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010.04.29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2009.11.25 01:50:59 | 000,094,160 | ---- | M] (ALWIL Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2009.11.25 01:50:12 | 000,114,768 | ---- | M] (ALWIL Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2009.11.25 01:50:00 | 000,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009.11.25 01:49:07 | 000,048,560 | ---- | M] (ALWIL Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2009.11.25 01:48:57 | 000,023,120 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2009.11.25 01:47:54 | 000,027,408 | ---- | M] (ALWIL Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009.07.23 11:57:22 | 000,112,640 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009.07.23 11:57:22 | 000,102,528 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2009.07.23 11:57:22 | 000,100,480 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbfake.sys -- (hwusbfake)
DRV - [2009.06.19 13:59:10 | 000,012,928 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgvmodem.sys -- (LGVMODEM)
DRV - [2009.06.19 13:59:04 | 000,012,032 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgbtport.sys -- (LgBttPort)
DRV - [2009.06.19 13:59:02 | 000,010,496 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lgbtbus.sys -- (lgbusenum)
DRV - [2009.05.14 18:12:45 | 000,277,784 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2008.04.14 16:00:00 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007.08.07 21:48:33 | 000,025,160 | ---- | M] (Elaborate Bytes AG) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2007.04.30 07:37:20 | 002,206,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Ovladač adaptéru Intel(R)
DRV - [2007.04.10 16:55:28 | 000,140,808 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atswpdrv.sys -- (ATSWPDRV) (****DEBUG****) AuthenTec TruePrint USB Driver (SwipeSensor)
DRV - [2007.03.29 16:19:36 | 000,012,416 | ---- | M] (Intel Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2007.03.21 22:31:32 | 003,684,512 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2007.02.24 15:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007.02.16 16:46:00 | 000,160,256 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2007.01.30 19:57:00 | 004,474,368 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.01.23 18:03:28 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007.01.23 17:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006.11.13 11:41:20 | 000,862,922 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2006.10.30 11:52:04 | 000,329,901 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2006.10.30 11:51:40 | 000,067,672 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2006.10.30 11:51:30 | 000,149,123 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2006.10.30 11:51:24 | 000,030,459 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2006.10.10 08:54:34 | 000,138,240 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (Nokia USB Phone Parent)
DRV - [2006.10.10 08:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcj.sys -- (Nokia USB Port)
DRV - [2006.10.10 08:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (Nokia USB Modem)
DRV - [2006.10.10 08:54:32 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (Nokia USB Generic)
DRV - [2006.08.30 15:53:00 | 001,161,152 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006.07.12 11:58:02 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)
DRV - [2006.05.24 12:48:14 | 000,010,240 | ---- | M] (Lenovo ) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\PMHler.sys -- (PMHler)
DRV - [2006.05.19 15:24:20 | 000,193,088 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2005.07.08 18:17:54 | 000,099,584 | ---- | M] (Nero AG) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005.07.08 18:17:36 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2004.08.22 17:31:48 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\d347prt.sys -- (d347prt)
DRV - [2004.08.22 17:31:10 | 000,155,136 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\d347bus.sys -- (d347bus)
DRV - [2002.11.28 16:18:04 | 000,015,360 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2002.11.28 12:43:49 | 000,022,016 | ---- | M] (Elaborate Bytes AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys -- (ElbyVCD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1202660629-1844823847-839522115-500\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1202660629-1844823847-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.07.01 15:06:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.07.15 11:48:45 | 000,000,000 | ---D | M]
[2010.08.05 13:13:58 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.10.26 18:43:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.05.10 20:55:09 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.05.08 21:15:02 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.05.08 21:15:02 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.05.08 21:15:02 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.05.08 21:15:02 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.05.08 21:15:02 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2010.08.04 22:24:17 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe File not found
O4 - HKLM..\Run: [FingerPrintSoftware] C:\Program Files\Lenovo Fingerprint Software\fpapp.exe (Authentec,Inc)
O4 - HKLM..\Run: [Lexmark X6100 Series] C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PMHandler] C:\Program Files\Lenovo\PM Driver\PMHandler.exe (Lenovo)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk = C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1202660629-1844823847-839522115-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1202660629-1844823847-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-1202660629-1844823847-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-21-1202660629-1844823847-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} http://www-307.ibm.com/pc/support/acpir.cab (IASRunner Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ATFUS: DllName - C:\WINDOWS\system32\FpWinLogonNp.dll - C:\WINDOWS\system32\FpWinlogonNp.dll (AuthenTec,Inc)
O20 - Winlogon\Notify\tphotkey: DllName - C:\Program Files\Lenovo\HOTKEY\tphklock.dll - C:\Program Files\Lenovo\HOTKEY\tphklock.dll (Lenovo Group Limited)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010.08.05 21:48:06 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.08.05 16:20:22 | 001,204,586 | ---- | C] (C_XX & El Desaparecido) -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\UsbFix.exe
[2010.08.04 23:34:07 | 000,000,000 | ---D | C] -- C:\Intel
[2010.08.04 23:03:58 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.08.04 22:52:52 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.08.04 22:36:06 | 000,691,696 | ---- | C] (Duplex Secure Ltd.) -- C:\WINDOWS\System32\drivers\sptd.sys
[2010.08.04 22:35:59 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2010.08.04 22:35:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.08.04 22:21:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010.08.04 22:14:49 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.08.04 19:54:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\VDLL.DLL
[2010.08.04 19:54:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\RUNDL132.EXE
[2010.08.04 19:54:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\logo1_.exe
[2010.08.04 19:54:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\runouce.exe
[2010.08.04 19:54:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\rundll16.exe
[2010.08.04 19:54:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\logo_1.exe
[2010.08.04 19:53:07 | 000,632,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2010.08.04 19:53:06 | 000,554,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2010.08.04 19:53:04 | 000,034,048 | ---- | C] (MicroWorld Technologies Inc.) -- C:\WINDOWS\System32\eEmpty.exe
[2010.08.04 19:53:02 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\R.COM
[2010.08.04 19:53:02 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\T.COM
[2010.08.04 19:53:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MicroWorld
[2010.08.04 19:52:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2010.08.04 19:25:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Data aplikací\GRETECH
[2010.08.04 19:25:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Data aplikací\Adobe
[2010.08.04 19:06:25 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.08.04 19:06:25 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.08.04 19:06:25 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.08.04 19:06:25 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe.mwt
[2010.08.04 19:06:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.08.04 19:05:29 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.08.04 18:24:14 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.08.04 18:23:22 | 000,000,000 | ---D | C] -- C:\ComboFix23459C
[2010.08.04 18:21:10 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\PrivacIE
[2010.08.04 18:15:39 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2010.08.04 18:08:26 | 000,000,000 | ---D | C] -- C:\ComboFix2
[2010.08.04 17:59:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Data aplikací\Malwarebytes
[2010.08.04 17:59:30 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.08.04 17:59:29 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.08.04 17:59:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.08.04 17:23:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2010.08.04 16:28:23 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010.08.04 08:32:47 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\IETldCache
[2010.08.04 08:32:25 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Data aplikací\Microsoft
[2010.08.04 08:32:25 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\SendTo
[2010.08.04 08:32:25 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Data aplikací
[2010.08.04 08:32:25 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Nabídka Start
[2010.08.04 08:32:25 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Cookies
[2010.08.04 08:32:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Šablony
[2010.08.04 08:32:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Recent
[2010.08.04 08:32:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Okolní tiskárny
[2010.08.04 08:32:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Okolní síť
[2010.08.04 08:32:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Local Settings
[2010.08.04 08:32:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha
[2010.08.04 08:32:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Oblíbené položky
[2010.08.04 08:32:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Local Settings\Data aplikací\Microsoft
[2010.08.04 08:32:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.LENOVO3000N200\Dokumenty
[2010.08.02 22:01:54 | 000,000,000 | ---D | C] -- C:\Program Files\GRETECH
[2010.08.02 21:20:31 | 000,000,000 | ---D | C] -- C:\found.001
[2010.08.02 21:16:41 | 000,232,448 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\WINDOWS\System32\mp3fhg.acm
[2010.08.02 21:16:41 | 000,217,088 | ---- | C] (www.helixcommunity.org) -- C:\WINDOWS\System32\yv12vfw.dll
[2010.08.02 21:16:41 | 000,151,552 | ---- | C] (fccHandler) -- C:\WINDOWS\System32\ac3acm.acm
[2010.08.02 21:16:40 | 000,720,384 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\divx.dll
[2010.08.02 21:16:40 | 000,094,208 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\dpl100.dll
[2010.08.02 21:16:35 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack
[2010.07.22 18:56:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Vodafone
[2010.07.22 18:56:27 | 000,000,000 | ---D | C] -- C:\Program Files\Vodafone
[2010.07.15 12:38:00 | 000,000,000 | ---D | C] -- C:\Program Files\Trans
[2009.01.13 13:40:32 | 000,155,136 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347bus.sys
[2009.01.13 13:40:32 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys
[2008.04.02 13:31:36 | 000,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\lexlog.dll
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.08.05 22:11:56 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.08.05 22:11:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.08.05 22:11:33 | 000,000,000 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2010.08.05 22:11:26 | 000,017,408 | ---- | M] () -- C:\WINDOWS\System32\rpcnetp.exe
[2010.08.05 22:08:00 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{752B43E6-B86D-40EC-A2D7-1CADB49EE03A}.job
[2010.08.05 21:56:46 | 000,051,048 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010.08.05 21:56:34 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.08.05 21:54:06 | 000,000,940 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.08.05 21:51:59 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.08.05 21:44:25 | 000,017,408 | ---- | M] () -- C:\WINDOWS\System32\rpcnetp.dll
[2010.08.05 21:39:17 | 000,786,432 | -H-- | M] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\NTUSER.DAT
[2010.08.05 21:39:17 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\ntuser.ini
[2010.08.05 21:39:16 | 004,240,656 | -H-- | M] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\Local Settings\Data aplikací\IconCache.db
[2010.08.05 21:36:16 | 000,442,873 | ---- | M] () -- C:\WINDOWS\System32\drivers\fwdrv.err
[2010.08.05 08:45:02 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.08.05 08:44:50 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\agremove.exe
[2010.08.04 22:48:40 | 001,204,586 | ---- | M] (C_XX & El Desaparecido) -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\UsbFix.exe
[2010.08.04 22:36:08 | 000,001,613 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\DAEMON Tools Lite.lnk
[2010.08.04 22:36:06 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) -- C:\WINDOWS\System32\drivers\sptd.sys
[2010.08.04 22:32:52 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.08.04 22:25:56 | 000,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.08.04 22:24:48 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.08.04 22:24:17 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.08.04 21:44:08 | 000,000,569 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.08.04 19:53:22 | 000,000,028 | ---- | M] () -- C:\WINDOWS\Lic.xxx
[2010.08.04 19:53:06 | 000,632,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2010.08.04 19:53:05 | 000,554,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2010.08.04 19:53:03 | 000,034,048 | ---- | M] (MicroWorld Technologies Inc.) -- C:\WINDOWS\System32\eEmpty.exe
[2010.08.04 19:25:17 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.08.04 18:04:28 | 003,749,693 | R--- | M] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\ComboFix2.exe
[2010.08.04 17:03:52 | 005,153,350 | ---- | M] () -- C:\WINDOWS\REGBK00.ZIP
[2010.08.04 16:28:24 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\HijackThis.lnk
[2010.08.03 11:30:13 | 000,000,156 | ---- | M] () -- C:\WINDOWS\z.reg
[2010.08.02 22:02:02 | 000,000,762 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\GOM Player.lnk
[2010.08.02 21:44:00 | 000,002,557 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Vodafone Mobile Connect.lnk
[2010.08.02 12:25:00 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\Vyčištění disku.job
[2010.07.29 14:56:15 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
[2010.07.27 08:30:31 | 008,466,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shell32.dll
[2010.07.25 21:03:41 | 000,002,511 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Vodafone SMS.lnk
[2010.07.15 11:48:46 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Adobe Reader 9.lnk
[2010.07.15 10:06:05 | 000,000,642 | ---- | M] () -- C:\WINDOWS\lexstat.ini
[2010.07.14 10:00:00 | 000,108,032 | ---- | M] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.07.14 10:00:00 | 000,000,038 | ---- | M] () -- C:\WINDOWS\avisplitter.ini
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.08.05 08:41:13 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\rpcnetp.dll
[2010.08.05 08:40:31 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\rpcnetp.exe
[2010.08.04 22:36:08 | 000,001,613 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\DAEMON Tools Lite.lnk
[2010.08.04 22:25:56 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.08.04 19:53:22 | 000,000,028 | ---- | C] () -- C:\WINDOWS\Lic.xxx
[2010.08.04 19:06:25 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.08.04 19:06:25 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.08.04 19:06:25 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.08.04 19:06:25 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.08.04 19:06:25 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.08.04 18:24:20 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.08.04 18:24:16 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.08.04 18:16:59 | 003,749,693 | R--- | C] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\ComboFix2.exe
[2010.08.04 17:03:21 | 005,153,350 | ---- | C] () -- C:\WINDOWS\REGBK00.ZIP
[2010.08.04 16:55:49 | 000,000,522 | ---- | C] () -- C:\WINDOWS\System32\Microsoft.VC80.CRT.manifest
[2010.08.04 16:28:24 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\Plocha\HijackThis.lnk
[2010.08.04 08:32:28 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\ntuser.ini
[2010.08.04 08:32:25 | 000,786,432 | -H-- | C] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\NTUSER.DAT
[2010.08.04 08:32:25 | 000,073,728 | -H-- | C] () -- C:\Documents and Settings\Administrator.LENOVO3000N200\NtUser.dat.LOG
[2010.08.03 11:30:03 | 000,000,156 | ---- | C] () -- C:\WINDOWS\z.reg
[2010.08.02 22:02:02 | 000,000,762 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\GOM Player.lnk
[2010.08.02 21:16:43 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010.08.02 21:16:42 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010.08.02 21:16:40 | 000,790,528 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010.08.02 21:16:40 | 000,134,144 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.08.02 21:16:39 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.08.02 21:16:39 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010.07.22 18:56:33 | 000,002,557 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Vodafone Mobile Connect.lnk
[2010.07.22 18:56:33 | 000,002,511 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Vodafone SMS.lnk
[2008.04.30 09:36:16 | 000,000,641 | ---- | C] () -- C:\WINDOWS\SESTDLL.INI
[2008.04.03 09:41:39 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxbfvs.dll
[2008.04.03 09:41:07 | 000,000,188 | ---- | C] () -- C:\WINDOWS\System32\lxbfcoin.ini
[2008.04.03 09:35:40 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\LXBFLCNP.DLL
[2008.04.02 13:46:47 | 000,000,642 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2008.04.02 13:33:04 | 000,000,507 | ---- | C] () -- C:\WINDOWS\LMABB2DD.ini
[2008.04.02 13:31:12 | 001,134,592 | ---- | C] () -- C:\WINDOWS\System32\LMabusb1.dll
[2008.04.02 13:31:12 | 000,630,784 | ---- | C] () -- C:\WINDOWS\System32\LMabpmui.dll
[2008.04.02 13:31:11 | 001,183,744 | ---- | C] () -- C:\WINDOWS\System32\LMabserv.dll
[2008.04.02 13:31:10 | 000,507,904 | ---- | C] () -- C:\WINDOWS\System32\LMabpar1.dll
[2008.04.02 13:31:10 | 000,491,520 | ---- | C] () -- C:\WINDOWS\System32\LMablmpm.dll
[2008.04.02 13:31:10 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\LMabprox.dll
[2008.04.02 13:31:10 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\LMabpplc.dll
[2008.04.02 13:31:09 | 000,733,184 | ---- | C] () -- C:\WINDOWS\System32\LMabip1.dll
[2008.04.02 13:31:09 | 000,413,696 | ---- | C] () -- C:\WINDOWS\System32\LMabcomm.dll
[2008.04.02 13:31:08 | 000,704,512 | ---- | C] () -- C:\WINDOWS\System32\LMabcomc.dll
[2008.03.29 18:41:23 | 000,000,101 | ---- | C] () -- C:\WINDOWS\DVDIdlePro.INI
[2008.03.29 16:35:13 | 000,000,140 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2008.03.29 15:55:22 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.03.29 15:33:23 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008.03.29 11:46:13 | 000,000,135 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.03.25 16:58:41 | 000,004,672 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2008.03.25 16:46:18 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2007.03.21 23:31:34 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007.03.21 23:31:34 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007.03.21 23:31:32 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007.03.21 23:31:32 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2007.03.21 23:31:32 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007.03.21 23:31:32 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006.11.11 22:50:38 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2006.03.02 13:00:00 | 000,002,048 | ---- | C] () -- C:\WINDOWS\System32\syscvchk.dll
[2005.02.17 12:41:32 | 000,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005.02.17 12:41:30 | 000,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2001.11.14 13:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
========== LOP Check ==========
[2010.02.07 22:03:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
[2010.08.04 22:35:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.04.12 17:47:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DivoGames
[2010.04.12 10:53:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Downloaded Installations
[2008.06.09 11:32:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Grisoft
[2009.10.26 18:43:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2009.01.03 12:38:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IMSIDesign
[2008.06.20 08:09:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\LogMeIn
[2010.08.04 19:53:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2008.04.04 11:43:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2008.03.25 18:30:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC-Doctor
[2008.03.29 15:59:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2009.01.03 12:41:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TurboFLOORPLAN Dum & Interiér & Zahrada Pro
[2010.07.22 18:56:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Vodafone
[2008.03.30 12:37:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\Elaborate Bytes
[2010.02.15 13:45:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\MAXON
[2008.04.04 11:45:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\Nokia
[2008.04.04 11:33:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\PC Suite
[2010.08.03 14:04:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\RST
[2008.03.29 15:59:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\TuneUp Software
[2010.06.16 19:31:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Honza\Data aplikací\Vodafone
[2010.04.27 19:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Vodafone
[2008.10.05 13:23:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\AVGTOOLBAR
[2010.08.04 22:40:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\DAEMON Tools Lite
[2009.10.26 18:44:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\ICQ
[2009.11.13 15:34:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\LG Electronics
[2009.02.20 17:06:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\Nokia
[2009.02.20 17:03:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\PC Suite
[2010.04.12 17:17:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\Retriever
[2010.07.15 12:38:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\RST
[2009.11.26 21:46:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\TMInc
[2008.11.04 16:38:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\TuneUp Software
[2010.04.27 19:05:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Data aplikací\Vodafone
[2009.11.13 15:34:33 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Veronika\Data aplikací\{D94BA408-F110-488B-A65E-3AE7945F79E6}
[2010.01.01 18:15:00 | 000,000,390 | ---- | M] () -- C:\WINDOWS\Tasks\1-Click Maintenance.job
[2010.08.05 22:08:00 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{752B43E6-B86D-40EC-A2D7-1CADB49EE03A}.job
[2010.08.02 12:25:00 | 000,000,266 | ---- | M] () -- C:\WINDOWS\Tasks\Vyčištění disku.job
========== Purity Check ==========
< End of report >