Security master AV
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Re: Security master AV
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4fe6-8A56-BBB695989046} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
========== COMMANDS ==========
OTM by OldTimer - Version 3.1.15.0 log created on 08172010_130715
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4fe6-8A56-BBB695989046} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
========== COMMANDS ==========
OTM by OldTimer - Version 3.1.15.0 log created on 08172010_130715
Re: Security master AV
Je snad jeste porad videt v Internet Exploreru
Procistete registry CCleanerem..
Procistete registry CCleanerem..
Re: Security master AV
v exploreru není, v mozille ano, ale on časem zmizí 
Re: Security master AV
Ja myslel ze je porad jen v IE, nevadi na moozilu si posvitime taky
Stahnete OTL (viz muj podpis) a ulozte jej na plochu
- Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
- Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
- Zaskrtnete okenko Pro vsechny uzivatele
- Zaskrtnete okenko Kontrola na havet "LOP"
- Zaskrtnete okenko Kontrola na havet "Purity"
- Stari souboru zmente z 30 dnu na 7 dnu
- Kliknete na tlacitko Prohledat
- Po dokonceni skenu (cca 5 az 10 min) se objevi logy OTL.txt a Extras.txt, sem vlozte jen ten OTL.txt
Re: Security master AV
OTL logfile created on: 17.8.2010 13:26:53 - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Pepa\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
997,00 Mb Total Physical Memory | 466,00 Mb Available Physical Memory | 47,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 83,00% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 117,19 Gb Total Space | 96,25 Gb Free Space | 82,13% Space Free | Partition Type: NTFS
Drive D: | 31,86 Gb Total Space | 28,48 Gb Free Space | 89,38% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KANCL1
Current User Name: Pepa
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 7 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.08.17 13:22:13 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pepa\Plocha\OTL.exe
PRC - [2010.03.31 11:58:32 | 000,307,672 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009.09.29 14:03:46 | 000,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2009.09.29 14:02:52 | 002,054,360 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2008.10.31 07:24:28 | 001,365,288 | ---- | M] (Sunbelt Software, Inc.) -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
PRC - [2008.10.31 07:24:28 | 000,095,528 | ---- | M] (Sunbelt Software, Inc.) -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
PRC - [2008.10.31 07:24:26 | 001,705,256 | ---- | M] (Sunbelt Software, Inc.) -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.02.04 12:02:14 | 000,079,400 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
========== Modules (SafeList) ==========
MOD - [2010.08.17 13:22:13 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pepa\Plocha\OTL.exe
MOD - [2008.04.14 05:19:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2007.02.05 09:29:04 | 000,139,264 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4\OpHookSE4.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2009.09.29 14:11:10 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009.09.29 14:03:46 | 000,735,960 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2008.10.31 07:24:28 | 001,365,288 | ---- | M] (Sunbelt Software, Inc.) [Auto | Running] -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe -- (SPF4)
SRV - [2008.10.31 07:24:28 | 000,095,528 | ---- | M] (Sunbelt Software, Inc.) [Auto | Running] -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe -- (SbPF.Launcher)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010.05.10 20:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010.02.17 20:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009.09.29 14:05:54 | 000,096,408 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2009.09.29 14:02:58 | 000,108,792 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009.09.29 13:56:32 | 000,116,008 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2008.10.31 07:09:06 | 000,270,888 | R--- | M] (Sunbelt Software, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SbFw.sys -- (SbFw)
DRV - [2008.06.21 04:54:54 | 000,066,600 | R--- | M] (Sunbelt Software, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sbhips.sys -- (sbhips)
DRV - [2008.06.21 04:54:54 | 000,065,576 | ---- | M] (Sunbelt Software, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SbFwIm.sys -- (SBFWIMCL)
DRV - [2008.04.13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007.11.15 16:58:33 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\timntr.sys -- (timounter)
DRV - [2007.11.15 16:58:33 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2007.08.28 17:55:10 | 004,609,024 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.08.24 12:22:56 | 005,776,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2007.06.15 06:07:39 | 000,254,872 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1e5132.sys -- (e1express) Intel(R)
DRV - [2007.03.13 14:05:30 | 000,044,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (HECI) Intel(R)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1801674531-329068152-839522115-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 04 F7 FA AB FD 3D CB 01 [binary data]
IE - HKU\S-1-5-21-1801674531-329068152-839522115-1005\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1801674531-329068152-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.06.08 08:01:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.17 09:54:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009.11.30 18:38:11 | 000,000,000 | ---D | M]
[2009.05.06 16:53:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Extensions
[2010.08.17 11:34:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\extensions
[2010.08.16 09:31:20 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.08.16 09:02:59 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-3.xml
[2009.10.30 09:40:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-4.xml
[2009.12.16 14:08:27 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-5.xml
[2010.01.07 09:09:18 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-6.xml
[2010.02.22 14:06:01 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-7.xml
[2010.04.06 10:02:07 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-8.xml
[2010.05.12 18:40:06 | 000,001,042 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin.xml
[2010.08.17 11:34:22 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.07.23 13:49:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.08.17 09:54:12 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.08.17 09:53:54 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.02.22 14:05:42 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.02.22 14:05:42 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.02.22 14:05:42 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.02.22 14:05:42 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.02.22 14:05:42 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2010.08.16 11:15:23 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Podpora odkazu pro Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\..\Toolbar\WebBrowser: (no name) - {2C688203-7EB3-4327-9995-1CB417BA23F9} - No CLSID value found.
O3 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windows ... 6101226437 (WUWebControl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Pepa\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Pepa\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 7 Days ==========
[2010.08.17 13:21:35 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pepa\Plocha\OTL.exe
[2010.08.17 13:19:10 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Pepa\Recent
[2010.08.17 12:44:10 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Pepa\IECompatCache
[2010.08.17 11:55:54 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Pepa\PrivacIE
[2010.08.17 11:54:23 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Pepa\IETldCache
[2010.08.17 11:49:18 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010.08.17 11:45:11 | 000,065,576 | ---- | C] (Sunbelt Software, Inc.) -- C:\WINDOWS\System32\drivers\SbFwIm.sys
[2010.08.17 11:45:10 | 000,270,888 | R--- | C] (Sunbelt Software, Inc.) -- C:\WINDOWS\System32\drivers\SbFw.sys
[2010.08.17 11:44:50 | 000,000,000 | ---D | C] -- C:\Program Files\Sunbelt Software
[2010.08.17 09:54:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Sun
[2010.08.17 09:54:09 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010.08.17 09:54:08 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.08.17 09:54:08 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.08.17 09:54:08 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.08.17 08:54:36 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.08.16 14:04:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Pepa\Data aplikací\SUPERAntiSpyware.com
[2010.08.16 14:04:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
[2010.08.16 14:04:33 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010.08.16 13:43:34 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.08.16 13:12:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010.08.16 11:01:00 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.08.16 10:45:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Pepa\Dokumenty\fotky
[2010.08.16 10:11:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Pepa\Data aplikací\Malwarebytes
[2010.08.16 10:11:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.08.16 09:25:46 | 000,000,000 | ---D | C] -- C:\_OTM
[2010.08.16 08:59:36 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
========== Files - Modified Within 7 Days ==========
[2010.08.17 13:28:08 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Pepa\Plocha\~$tní dvoudenní zážitkový pobyt.doc
[2010.08.17 13:22:13 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pepa\Plocha\OTL.exe
[2010.08.17 13:12:05 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.08.17 13:08:27 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.08.17 13:08:26 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.08.17 13:07:27 | 005,505,024 | -H-- | M] () -- C:\Documents and Settings\Pepa\NTUSER.DAT
[2010.08.17 13:07:27 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Pepa\ntuser.ini
[2010.08.17 13:07:22 | 005,365,160 | -H-- | M] () -- C:\Documents and Settings\Pepa\Local Settings\Data aplikací\IconCache.db
[2010.08.17 11:39:27 | 000,000,377 | ---- | M] () -- C:\Documents and Settings\Pepa\Dokumenty\oprava.reg
[2010.08.17 11:33:30 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\Pepa\Plocha\Letní dvoudenní zážitkový pobyt.doc
[2010.08.17 09:53:51 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.08.17 09:53:51 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.08.17 09:53:50 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.08.17 09:53:50 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010.08.17 09:53:49 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010.08.17 08:54:37 | 000,001,554 | ---- | M] () -- C:\Documents and Settings\Pepa\Plocha\CCleaner.lnk
[2010.08.17 08:44:39 | 000,268,600 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.08.16 14:04:37 | 000,001,684 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\SUPERAntiSpyware Free Edition.lnk
[2010.08.16 13:10:08 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.08.16 11:15:23 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.08.16 11:01:06 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.08.16 10:51:44 | 000,035,840 | ---- | M] () -- C:\Documents and Settings\Pepa\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.16 08:46:34 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
========== Files Created - No Company Name ==========
[2010.08.17 13:28:08 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Pepa\Plocha\~$tní dvoudenní zážitkový pobyt.doc
[2010.08.17 11:39:27 | 000,000,377 | ---- | C] () -- C:\Documents and Settings\Pepa\Dokumenty\oprava.reg
[2010.08.17 11:33:29 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\Pepa\Plocha\Letní dvoudenní zážitkový pobyt.doc
[2010.08.17 08:54:37 | 000,001,554 | ---- | C] () -- C:\Documents and Settings\Pepa\Plocha\CCleaner.lnk
[2010.08.16 14:04:37 | 000,001,684 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\SUPERAntiSpyware Free Edition.lnk
[2010.08.16 11:01:06 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.08.16 11:01:03 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.03.02 13:08:50 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010.03.02 13:08:49 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010.03.02 13:08:40 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010.03.02 13:08:33 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.03.02 13:08:33 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010.01.11 13:56:16 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2008.10.30 11:34:53 | 027,550,368 | ---- | C] () -- C:\Program Files\setupczepro.exe
[2008.08.12 18:35:11 | 000,000,412 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008.08.11 19:09:14 | 009,660,770 | ---- | C] () -- C:\Program Files\webguru-publisher-cms-2.0.4-install.zip
[2008.08.11 18:44:23 | 008,337,533 | ---- | C] () -- C:\Program Files\nvu-1.0-cs-CZ.win32.installer.exe
[2008.07.16 12:49:26 | 018,222,080 | ---- | C] () -- C:\Program Files\eav_nt32_csy.msi
[2008.05.05 14:43:44 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\Pepa\Data aplikací\AVSDVDPlayer.m3u
[2008.05.05 14:18:03 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008.05.05 14:18:03 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008.04.25 12:28:59 | 000,035,840 | ---- | C] () -- C:\Documents and Settings\Pepa\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.03.06 13:37:03 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\SystemInfo32.sys
[2008.01.03 13:33:02 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007.12.17 16:12:32 | 000,000,132 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.11.26 19:09:26 | 000,000,838 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2007.11.26 18:58:49 | 000,204,800 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4833.dll
[2007.11.12 19:37:09 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4864.dll
========== LOP Check ==========
[2008.08.20 18:28:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Canon
[2008.08.11 18:53:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ICQ
[2008.08.18 20:12:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ICQ Toolbar
[2008.08.11 18:44:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Nvu
[2008.08.12 18:35:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ScanSoft
[2007.11.26 19:25:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Acronis
[2010.06.11 14:53:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\akcnicestinashw
[2008.03.06 13:36:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DVD X Studios
[2007.11.26 19:21:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.06.15 10:34:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2009.07.23 16:44:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Rising
[2008.08.12 18:35:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ScanSoft
[2010.07.27 11:13:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2008.10.23 11:51:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\ICQ Toolbar
[2007.11.26 19:26:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Acronis
[2008.10.13 10:25:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\akcnicestinashw
[2009.04.22 16:58:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\BSplayer
[2009.04.22 15:08:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\BSplayer Pro
[2010.03.02 13:44:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\Desktopicon
[2010.08.17 11:47:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\ICQ
[2008.02.20 13:53:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\ICQ Toolbar
[2009.11.23 19:17:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\TeamViewer
[2008.03.25 15:24:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zuzka\Data aplikací\ICQ Toolbar
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
< End of report >
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Pepa\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
997,00 Mb Total Physical Memory | 466,00 Mb Available Physical Memory | 47,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 83,00% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 117,19 Gb Total Space | 96,25 Gb Free Space | 82,13% Space Free | Partition Type: NTFS
Drive D: | 31,86 Gb Total Space | 28,48 Gb Free Space | 89,38% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KANCL1
Current User Name: Pepa
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 7 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.08.17 13:22:13 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pepa\Plocha\OTL.exe
PRC - [2010.03.31 11:58:32 | 000,307,672 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009.09.29 14:03:46 | 000,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2009.09.29 14:02:52 | 002,054,360 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2008.10.31 07:24:28 | 001,365,288 | ---- | M] (Sunbelt Software, Inc.) -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
PRC - [2008.10.31 07:24:28 | 000,095,528 | ---- | M] (Sunbelt Software, Inc.) -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
PRC - [2008.10.31 07:24:26 | 001,705,256 | ---- | M] (Sunbelt Software, Inc.) -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.02.04 12:02:14 | 000,079,400 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
========== Modules (SafeList) ==========
MOD - [2010.08.17 13:22:13 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pepa\Plocha\OTL.exe
MOD - [2008.04.14 05:19:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2007.02.05 09:29:04 | 000,139,264 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4\OpHookSE4.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2009.09.29 14:11:10 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009.09.29 14:03:46 | 000,735,960 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2008.10.31 07:24:28 | 001,365,288 | ---- | M] (Sunbelt Software, Inc.) [Auto | Running] -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe -- (SPF4)
SRV - [2008.10.31 07:24:28 | 000,095,528 | ---- | M] (Sunbelt Software, Inc.) [Auto | Running] -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe -- (SbPF.Launcher)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010.05.10 20:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010.02.17 20:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009.09.29 14:05:54 | 000,096,408 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2009.09.29 14:02:58 | 000,108,792 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009.09.29 13:56:32 | 000,116,008 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2008.10.31 07:09:06 | 000,270,888 | R--- | M] (Sunbelt Software, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SbFw.sys -- (SbFw)
DRV - [2008.06.21 04:54:54 | 000,066,600 | R--- | M] (Sunbelt Software, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sbhips.sys -- (sbhips)
DRV - [2008.06.21 04:54:54 | 000,065,576 | ---- | M] (Sunbelt Software, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SbFwIm.sys -- (SBFWIMCL)
DRV - [2008.04.13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007.11.15 16:58:33 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\timntr.sys -- (timounter)
DRV - [2007.11.15 16:58:33 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2007.08.28 17:55:10 | 004,609,024 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.08.24 12:22:56 | 005,776,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2007.06.15 06:07:39 | 000,254,872 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1e5132.sys -- (e1express) Intel(R)
DRV - [2007.03.13 14:05:30 | 000,044,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (HECI) Intel(R)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1801674531-329068152-839522115-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 04 F7 FA AB FD 3D CB 01 [binary data]
IE - HKU\S-1-5-21-1801674531-329068152-839522115-1005\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1801674531-329068152-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.06.08 08:01:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.17 09:54:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009.11.30 18:38:11 | 000,000,000 | ---D | M]
[2009.05.06 16:53:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Extensions
[2010.08.17 11:34:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\extensions
[2010.08.16 09:31:20 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.08.16 09:02:59 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-3.xml
[2009.10.30 09:40:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-4.xml
[2009.12.16 14:08:27 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-5.xml
[2010.01.07 09:09:18 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-6.xml
[2010.02.22 14:06:01 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-7.xml
[2010.04.06 10:02:07 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-8.xml
[2010.05.12 18:40:06 | 000,001,042 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin.xml
[2010.08.17 11:34:22 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.07.23 13:49:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.08.17 09:54:12 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.08.17 09:53:54 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.02.22 14:05:42 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.02.22 14:05:42 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.02.22 14:05:42 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.02.22 14:05:42 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.02.22 14:05:42 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2010.08.16 11:15:23 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Podpora odkazu pro Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\..\Toolbar\WebBrowser: (no name) - {2C688203-7EB3-4327-9995-1CB417BA23F9} - No CLSID value found.
O3 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windows ... 6101226437 (WUWebControl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Pepa\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Pepa\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 7 Days ==========
[2010.08.17 13:21:35 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pepa\Plocha\OTL.exe
[2010.08.17 13:19:10 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Pepa\Recent
[2010.08.17 12:44:10 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Pepa\IECompatCache
[2010.08.17 11:55:54 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Pepa\PrivacIE
[2010.08.17 11:54:23 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Pepa\IETldCache
[2010.08.17 11:49:18 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010.08.17 11:45:11 | 000,065,576 | ---- | C] (Sunbelt Software, Inc.) -- C:\WINDOWS\System32\drivers\SbFwIm.sys
[2010.08.17 11:45:10 | 000,270,888 | R--- | C] (Sunbelt Software, Inc.) -- C:\WINDOWS\System32\drivers\SbFw.sys
[2010.08.17 11:44:50 | 000,000,000 | ---D | C] -- C:\Program Files\Sunbelt Software
[2010.08.17 09:54:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Sun
[2010.08.17 09:54:09 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010.08.17 09:54:08 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.08.17 09:54:08 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.08.17 09:54:08 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.08.17 08:54:36 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.08.16 14:04:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Pepa\Data aplikací\SUPERAntiSpyware.com
[2010.08.16 14:04:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
[2010.08.16 14:04:33 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010.08.16 13:43:34 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.08.16 13:12:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010.08.16 11:01:00 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.08.16 10:45:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Pepa\Dokumenty\fotky
[2010.08.16 10:11:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Pepa\Data aplikací\Malwarebytes
[2010.08.16 10:11:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.08.16 09:25:46 | 000,000,000 | ---D | C] -- C:\_OTM
[2010.08.16 08:59:36 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
========== Files - Modified Within 7 Days ==========
[2010.08.17 13:28:08 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Pepa\Plocha\~$tní dvoudenní zážitkový pobyt.doc
[2010.08.17 13:22:13 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pepa\Plocha\OTL.exe
[2010.08.17 13:12:05 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.08.17 13:08:27 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.08.17 13:08:26 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.08.17 13:07:27 | 005,505,024 | -H-- | M] () -- C:\Documents and Settings\Pepa\NTUSER.DAT
[2010.08.17 13:07:27 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Pepa\ntuser.ini
[2010.08.17 13:07:22 | 005,365,160 | -H-- | M] () -- C:\Documents and Settings\Pepa\Local Settings\Data aplikací\IconCache.db
[2010.08.17 11:39:27 | 000,000,377 | ---- | M] () -- C:\Documents and Settings\Pepa\Dokumenty\oprava.reg
[2010.08.17 11:33:30 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\Pepa\Plocha\Letní dvoudenní zážitkový pobyt.doc
[2010.08.17 09:53:51 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.08.17 09:53:51 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.08.17 09:53:50 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.08.17 09:53:50 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010.08.17 09:53:49 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010.08.17 08:54:37 | 000,001,554 | ---- | M] () -- C:\Documents and Settings\Pepa\Plocha\CCleaner.lnk
[2010.08.17 08:44:39 | 000,268,600 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.08.16 14:04:37 | 000,001,684 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\SUPERAntiSpyware Free Edition.lnk
[2010.08.16 13:10:08 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.08.16 11:15:23 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.08.16 11:01:06 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.08.16 10:51:44 | 000,035,840 | ---- | M] () -- C:\Documents and Settings\Pepa\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.16 08:46:34 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
========== Files Created - No Company Name ==========
[2010.08.17 13:28:08 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Pepa\Plocha\~$tní dvoudenní zážitkový pobyt.doc
[2010.08.17 11:39:27 | 000,000,377 | ---- | C] () -- C:\Documents and Settings\Pepa\Dokumenty\oprava.reg
[2010.08.17 11:33:29 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\Pepa\Plocha\Letní dvoudenní zážitkový pobyt.doc
[2010.08.17 08:54:37 | 000,001,554 | ---- | C] () -- C:\Documents and Settings\Pepa\Plocha\CCleaner.lnk
[2010.08.16 14:04:37 | 000,001,684 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\SUPERAntiSpyware Free Edition.lnk
[2010.08.16 11:01:06 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.08.16 11:01:03 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.03.02 13:08:50 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010.03.02 13:08:49 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010.03.02 13:08:40 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010.03.02 13:08:33 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.03.02 13:08:33 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010.01.11 13:56:16 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2008.10.30 11:34:53 | 027,550,368 | ---- | C] () -- C:\Program Files\setupczepro.exe
[2008.08.12 18:35:11 | 000,000,412 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008.08.11 19:09:14 | 009,660,770 | ---- | C] () -- C:\Program Files\webguru-publisher-cms-2.0.4-install.zip
[2008.08.11 18:44:23 | 008,337,533 | ---- | C] () -- C:\Program Files\nvu-1.0-cs-CZ.win32.installer.exe
[2008.07.16 12:49:26 | 018,222,080 | ---- | C] () -- C:\Program Files\eav_nt32_csy.msi
[2008.05.05 14:43:44 | 000,000,020 | ---- | C] () -- C:\Documents and Settings\Pepa\Data aplikací\AVSDVDPlayer.m3u
[2008.05.05 14:18:03 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008.05.05 14:18:03 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008.04.25 12:28:59 | 000,035,840 | ---- | C] () -- C:\Documents and Settings\Pepa\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.03.06 13:37:03 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\SystemInfo32.sys
[2008.01.03 13:33:02 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007.12.17 16:12:32 | 000,000,132 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.11.26 19:09:26 | 000,000,838 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2007.11.26 18:58:49 | 000,204,800 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4833.dll
[2007.11.12 19:37:09 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4864.dll
========== LOP Check ==========
[2008.08.20 18:28:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Canon
[2008.08.11 18:53:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ICQ
[2008.08.18 20:12:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ICQ Toolbar
[2008.08.11 18:44:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Nvu
[2008.08.12 18:35:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ScanSoft
[2007.11.26 19:25:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Acronis
[2010.06.11 14:53:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\akcnicestinashw
[2008.03.06 13:36:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DVD X Studios
[2007.11.26 19:21:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.06.15 10:34:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2009.07.23 16:44:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Rising
[2008.08.12 18:35:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ScanSoft
[2010.07.27 11:13:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2008.10.23 11:51:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\ICQ Toolbar
[2007.11.26 19:26:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Acronis
[2008.10.13 10:25:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\akcnicestinashw
[2009.04.22 16:58:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\BSplayer
[2009.04.22 15:08:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\BSplayer Pro
[2010.03.02 13:44:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\Desktopicon
[2010.08.17 11:47:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\ICQ
[2008.02.20 13:53:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\ICQ Toolbar
[2009.11.23 19:17:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\TeamViewer
[2008.03.25 15:24:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zuzka\Data aplikací\ICQ Toolbar
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
< End of report >
Re: Security master AV
- Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
- Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
Kód: Vybrat vše
:otl SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ) SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy) IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found IE - HKU\.DEFAULT\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\URLSearchHook: - Reg Error: Key error. File not found IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found IE - HKU\S-1-5-21-1801674531-329068152-839522115-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 04 F7 FA AB FD 3D CB 01 [binary data] IE - HKU\S-1-5-21-1801674531-329068152-839522115-1005\..\URLSearchHook: - Reg Error: Key error. File not found FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Ask.com" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.selectedEngine: "Ask.com" [2010.08.16 09:02:59 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-3.xml [2009.10.30 09:40:06 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-4.xml [2009.12.16 14:08:27 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-5.xml [2010.01.07 09:09:18 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-6.xml [2010.02.22 14:06:01 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-7.xml [2010.04.06 10:02:07 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-8.xml [2010.05.12 18:40:06 | 000,001,042 | ---- | M] () -- C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin.xml O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.) [2008.02.20 13:53:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pepa\Data aplikací\ICQ Toolbar [2008.03.25 15:24:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zuzka\Data aplikací\ICQ Toolbar [2008.10.23 11:51:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\ICQ Toolbar [2008.08.18 20:12:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ICQ Toolbar @Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8 @Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2 [2010.02.22 14:05:42 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml [2010.02.22 14:05:42 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml O3 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\..\Toolbar\WebBrowser: (no name) - {2C688203-7EB3-4327-9995-1CB417BA23F9} - No CLSID value found. O3 - HKU\S-1-5-21-1801674531-329068152-839522115-1005\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found. :files C:\WINDOWS\system32\*.tmp.dll /s C:\WINDOWS\system32\SET*.tmp /s C:\WINDOWS\*.tmp /s :commands [RESETHOSTS] [EMPTYTEMP] [EMPTYFLASH] [CLEARALLRESTOREPOINTS]- Nasledne kliknete na Opravit
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: Security master AV
All processes killed
========== OTL ==========
Service HidServ stopped successfully!
Service HidServ deleted successfully!
File C:\WINDOWS\System32\hidserv.dll not found.
Service AppMgmt stopped successfully!
Service AppMgmt deleted successfully!
File C:\WINDOWS\System32\appmgmts.dll not found.
Service MBAMSwissArmy stopped successfully!
Service MBAMSwissArmy deleted successfully!
File C:\WINDOWS\System32\drivers\mbamswissarmy.sys not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
HKU\S-1-5-21-1801674531-329068152-839522115-1005\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-1801674531-329068152-839522115-1005\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "Ask.com" removed from browser.search.selectedEngine
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-3.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-4.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-5.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-6.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-7.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-8.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin.xml moved successfully.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
C:\Documents and Settings\Pepa\Data aplikací\ICQ Toolbar folder moved successfully.
C:\Documents and Settings\Zuzka\Data aplikací\ICQ Toolbar folder moved successfully.
C:\Documents and Settings\Guest\Data aplikací\ICQ Toolbar folder moved successfully.
C:\Documents and Settings\Admin\Data aplikací\ICQ Toolbar folder moved successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8 deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2 deleted successfully.
C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml moved successfully.
Registry value HKEY_USERS\S-1-5-21-1801674531-329068152-839522115-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2C688203-7EB3-4327-9995-1CB417BA23F9} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C688203-7EB3-4327-9995-1CB417BA23F9}\ not found.
Registry value HKEY_USERS\S-1-5-21-1801674531-329068152-839522115-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Pepa
->Temp folder emptied: 613097 bytes
->Temporary Internet Files folder emptied: 50310 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 29442742 bytes
->Flash cache emptied: 405 bytes
User: Zuzka
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 29,00 mb
[EMPTYFLASH]
User: Admin
->Flash cache emptied: 0 bytes
User: All Users
User: Default User
User: Guest
->Flash cache emptied: 0 bytes
User: LocalService
User: NetworkService
User: Pepa
->Flash cache emptied: 0 bytes
User: Zuzka
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
Restore points cleared and new OTL Restore Point set!
OTL by OldTimer - Version 3.2.10.0 log created on 08172010_133919
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
========== OTL ==========
Service HidServ stopped successfully!
Service HidServ deleted successfully!
File C:\WINDOWS\System32\hidserv.dll not found.
Service AppMgmt stopped successfully!
Service AppMgmt deleted successfully!
File C:\WINDOWS\System32\appmgmts.dll not found.
Service MBAMSwissArmy stopped successfully!
Service MBAMSwissArmy deleted successfully!
File C:\WINDOWS\System32\drivers\mbamswissarmy.sys not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
HKU\S-1-5-21-1801674531-329068152-839522115-1005\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-1801674531-329068152-839522115-1005\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "Ask.com" removed from browser.search.selectedEngine
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-3.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-4.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-5.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-6.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-7.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin-8.xml moved successfully.
C:\Documents and Settings\Pepa\Data aplikací\Mozilla\Firefox\Profiles\j4blexzj.default\searchplugins\icqplugin.xml moved successfully.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
C:\Documents and Settings\Pepa\Data aplikací\ICQ Toolbar folder moved successfully.
C:\Documents and Settings\Zuzka\Data aplikací\ICQ Toolbar folder moved successfully.
C:\Documents and Settings\Guest\Data aplikací\ICQ Toolbar folder moved successfully.
C:\Documents and Settings\Admin\Data aplikací\ICQ Toolbar folder moved successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8 deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2 deleted successfully.
C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml moved successfully.
Registry value HKEY_USERS\S-1-5-21-1801674531-329068152-839522115-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2C688203-7EB3-4327-9995-1CB417BA23F9} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C688203-7EB3-4327-9995-1CB417BA23F9}\ not found.
Registry value HKEY_USERS\S-1-5-21-1801674531-329068152-839522115-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Pepa
->Temp folder emptied: 613097 bytes
->Temporary Internet Files folder emptied: 50310 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 29442742 bytes
->Flash cache emptied: 405 bytes
User: Zuzka
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 29,00 mb
[EMPTYFLASH]
User: Admin
->Flash cache emptied: 0 bytes
User: All Users
User: Default User
User: Guest
->Flash cache emptied: 0 bytes
User: LocalService
User: NetworkService
User: Pepa
->Flash cache emptied: 0 bytes
User: Zuzka
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
Restore points cleared and new OTL Restore Point set!
OTL by OldTimer - Version 3.2.10.0 log created on 08172010_133919
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
Re: Security master AV
Opet mu staly dotaz: zmizel icq z FF
Jedu na nocni, takze tu budu az nekdy nad ranem...klidne v preventivkach zalozte novy topic kam dejte log z RSITu ze sveho ntb a ja ne naj kouknu (do predmetu hodte "pro vyosek")
Zatim se mejte a tesim se na dalsi spolupraci, je s Vami skvela
Pak Vam povim jednu milou vec

Jedu na nocni, takze tu budu az nekdy nad ranem...klidne v preventivkach zalozte novy topic kam dejte log z RSITu ze sveho ntb a ja ne naj kouknu (do predmetu hodte "pro vyosek")
Zatim se mejte a tesim se na dalsi spolupraci, je s Vami skvela
Re: Security master AV
Nezmizel
A děkuji, s Vámi se též spolupracuje skvěle, až se vrátíte z práce, tak na Vás bude čekat log
Přeji příjemnou a rychlou pracovní dobu
A jsem zvědavá, co mi chcete říct 
Re: Security master AV
Spustte Firefox, Klik nahote na Nastroje, nasledne Spravce doplnku.
Zde by mel ten ICQ Toolbar byt, kliknete na Odinstalovat
To tajne sdeleni mate v SZ 
Zde by mel ten ICQ Toolbar byt, kliknete na Odinstalovat
Re: Security master AV
ani tak se mu nechce 
Re: Security master AV
Provedte odinstalaci firefoxu. Pri odinstalaci zaskrtnete Odstranit osobní data a nastavení aplikace Firefox - tim by se mely odinstalovat i doplnky...Pak FF znovu nainstalujte.
Re: Security master AV
a je pryč, moc děkuji

Re: Security master AV
Uklidime po utilitach
OTC http://oldtimer.geekstogo.com/OTC.exe
Projedte PC CCleanerem
Melo by byt z me strany hotovo
Nemate zac, rad jsem pomohl
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
Nemate zac, rad jsem pomohl
Re: Security master AV
tak a už je vše v pořádku, ještě jednou mockrát děkuji:)



Přispějete na provoz fóra?