Stránka 7 z 8

Re: Neskutečně zasekané a spomalené PC

Napsal: 12 říj 2011 11:43
od WiZARD_
< MD5 for: TCPIP.SYS >
[2002.08.29 01:58:12 | 000,332,928 | ---- | M] (Microsoft Corporation) MD5=244A2F9816BC9B593957281EF577D976 -- C:\WINDOWS\system32\drivers\tcpip.sys

< MD5 for: USERINIT.EXE >
[2009.05.26 19:47:22 | 000,040,448 | ---- | M] (NirSoft) MD5=44C4058A6EFA4EB384E6DEBB8CC9455E -- C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\userinit.exe
[2002.09.20 18:05:48 | 000,029,184 | ---- | M] (Microsoft Corporation) MD5=D7F9593829D41DEB324142D3B603E271 -- C:\WINDOWS\system32\userinit.exe
[2009.05.26 19:47:22 | 000,040,448 | ---- | M] (NirSoft) MD5=E1C6C95A4F9E85CF7D6245E030F6CD26 -- C:\Documents and Settings\Viti\Local Settings\Temp\RarSFX0\userinit.exe

< MD5 for: WINLOGON.EXE >
[2011.10.11 19:21:19 | 000,731,136 | ---- | M] () MD5=68B5FE0970FC228AD79CC8252C6543D7 -- C:\Documents and Settings\Administrator\Plocha\Winlogon.exe
[2009.05.26 19:47:22 | 000,040,448 | ---- | M] (NirSoft) MD5=9EE88C2A86E8BA205D0BAD2215D5AB85 -- C:\Documents and Settings\Viti\Local Settings\Temp\RarSFX0\winlogon.exe
[2009.05.26 19:47:22 | 000,040,448 | ---- | M] (NirSoft) MD5=F1529767185F52CC35609453581A796F -- C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\winlogon.exe
[2002.09.20 18:05:50 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=FF8857D1AF59071F172C0FAD0FD33E87 -- C:\WINDOWS\system32\winlogon.exe

< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >
[2008.10.06 15:37:30 | 000,315,392 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp083.dll
[2003.06.19 02:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\system32\drivers\*.sys /5 >
[2011.10.11 16:56:07 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys

< %systemroot%\system32\drivers\*.sys /X >
[2001.10.25 14:00:00 | 003,440,660 | ---- | M] () -- C:\WINDOWS\system32\drivers\gm.dls
[2001.10.25 14:00:00 | 000,000,646 | ---- | M] () -- C:\WINDOWS\system32\drivers\gmreadme.txt

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009.01.27 09:12:47 | 000,717,296 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\system32\*.* /5 >
[2011.10.11 18:52:48 | 000,149,503 | ---- | M] () -- C:\WINDOWS\system32\asr_01444.exe
[2011.10.11 18:52:41 | 000,000,079 | ---- | M] () -- C:\WINDOWS\system32\asr_vcuqy
[2011.10.11 19:29:21 | 000,000,664 | ---- | M] () -- C:\WINDOWS\system32\d3d9caps.dat
[2011.10.12 12:18:58 | 000,001,673 | ---- | M] () -- C:\WINDOWS\system32\eras.fon
[2011.10.11 22:24:27 | 000,000,065 | ---- | M] () -- C:\WINDOWS\system32\o
[2011.10.11 18:53:28 | 000,057,871 | R--- | M] () -- C:\WINDOWS\system32\smsc.exe
[2011.10.11 22:24:33 | 000,465,920 | ---- | M] () -- C:\WINDOWS\system32\winlolx.exe
[2011.10.09 18:43:41 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl

< %systemroot%\system32\*.dll /lockedfiles >
[2002.09.20 18:04:04 | 001,064,960 | RHS- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\xsycs.dll

< %systemroot%\system32\config\*.sav >
[2004.01.01 03:50:09 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004.01.01 03:50:09 | 000,630,784 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004.01.01 03:50:09 | 000,417,792 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\*.* /U /s >

< %systemroot%\*. /mp /s >

< %ALLUSERSPROFILE%\Data Aplikací\*.* >
[2011.05.12 18:36:44 | 000,012,576 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2004.01.01 03:51:18 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\desktop.ini
[2007.12.29 20:01:13 | 000,000,032 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\ezsid.dat
[2011.09.17 17:32:53 | 000,006,476 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\hpzinstall.log
[2009.09.03 19:39:23 | 000,002,828 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\KGyGaAvL.sys

< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
[2011.09.07 00:40:44 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758059181\thlkczve.exe
[2011.09.07 00:40:44 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758060725\thlkczve.exe
[2011.09.07 00:40:45 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1186758060903\thlkczve.exe
[2011.09.07 00:40:45 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\CT\MessageCache1\1189700787495\thlkczve.exe
[2011.09.07 00:40:46 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758059181\sjrshrre.exe
[2011.09.07 00:40:46 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758060725\sjrshrre.exe
[2011.09.07 00:40:47 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1186758060903\sjrshrre.exe
[2011.09.07 00:40:47 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\DE\MessageCache1\1189700787495\sjrshrre.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758059181\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060725\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060903\snrjlbjn.exe
[2011.09.07 00:40:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1189700787495\snrjlbjn.exe
[2011.09.07 00:40:50 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758059181\eevjjlll.exe
[2011.09.07 00:40:51 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758060725\eevjjlll.exe
[2011.09.07 00:40:53 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1186758060903\eevjjlll.exe
[2011.09.07 00:40:54 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\ES\MessageCache1\1189700787495\eevjjlll.exe
[2011.09.07 00:40:56 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758059181\ljrkvtwh.exe
[2011.09.07 00:40:56 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758060725\ljrkvtwh.exe
[2011.09.07 00:40:57 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1186758060903\ljrkvtwh.exe
[2011.09.07 00:40:57 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\FR\MessageCache1\1189700787495\ljrkvtwh.exe
[2011.09.07 00:40:58 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758059181\brwrlskz.exe
[2011.09.07 00:40:58 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758060725\brwrlskz.exe
[2011.09.07 00:40:59 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1186758060903\brwrlskz.exe
[2011.09.07 00:40:59 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\IT\MessageCache1\1189700787495\brwrlskz.exe
[2011.09.07 00:41:00 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758059181\hnrhllzh.exe
[2011.09.07 00:41:00 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758060725\hnrhllzh.exe
[2011.09.07 00:41:01 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1186758060903\hnrhllzh.exe
[2011.09.07 00:41:02 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Corel\Messages\540241476_410003\PL\MessageCache1\1189700787495\hnrhllzh.exe
[2011.09.07 00:41:14 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\cbrkrrqh.exe
[2011.09.07 00:41:17 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\ejjkrtsn.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\etskskkb.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\ewkknejq.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\hetqxlxk.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\nnteklcs.exe
[2011.09.07 00:41:15 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\srewjcqe.exe
[2011.09.07 00:41:14 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\thncexre.exe
[2011.09.07 00:41:16 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT 2.0\data\templates\xnrzjqkk.exe
[2011.09.07 00:41:13 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\lwjsbskq.exe
[2011.09.07 00:41:12 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\nxrvjrhs.exe
[2011.09.07 00:41:12 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\HP\LGT\Data\Templates\srehhqvr.exe
[2011.09.07 00:41:23 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\ICQ\ICQNewTab\lhnllvjb.exe
[2011.09.07 00:41:26 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\MAGIX\Common\Online Services Info\jehckswh.exe
[2011.09.07 00:41:26 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\MAGIX\Common\Online Services Info\wthhxtzs.exe
[2011.09.21 22:06:30 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\All Users\Data Aplikací\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
[2007.01.14 19:39:39 | 005,535,448 | ---- | M] (InstallShield Software Corporation) -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\7B5560BB781B40259A06350E9B643B6E\CT4SkypePlugin10_Multi_Lite.exe
[2007.01.14 19:39:39 | 000,040,960 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\7B5560BB781B40259A06350E9B643B6E\RLLauncher.exe
[2007.01.14 19:42:07 | 001,371,136 | ---- | M] (EasyBits Software Corp.) -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\F35E193DC3E84933B83DE961D9AC33BF\SketchPad.exe
[2011.09.07 00:41:38 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Skype\Plugins\Plugins\F57B48ADF2224F088EDD1A2B9BAD84E8\kxllttje.exe

< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >

< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >

< %APPDATA%\*. >
[2011.09.17 23:04:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Adobe
[2007.01.13 18:43:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\AdobeUM
[2007.01.31 22:36:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Apple Computer
[2009.08.07 14:24:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Atari
[2010.05.17 17:21:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Audacity
[2009.06.21 18:28:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\AVG8
[2011.04.09 13:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Canneverbe Limited
[2007.06.30 15:49:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Change
[2010.03.12 18:59:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Corel
[2007.01.14 20:05:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\COWON
[2010.03.31 19:20:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Facebook
[2008.07.13 18:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FinalBurner Audio CD
[2009.06.23 19:37:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FMZilla
[2007.01.05 20:47:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\FreeCall
[2007.08.28 16:04:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\GetRightToGo
[2007.01.13 18:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Google
[2007.03.16 22:15:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Hamachi
[2007.02.15 17:37:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Help
[2010.06.20 12:44:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\HP
[2011.09.17 22:18:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\HPAppData
[2011.07.09 21:01:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQ
[2006.12.27 19:26:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\ICQLite
[2006.12.27 16:38:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Identities
[2009.07.01 14:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\InstallShield
[2007.02.16 22:23:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\InstallShield Installation Information
[2009.09.25 18:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Juce VST Host
[2011.05.12 19:59:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Lavasoft
[2006.12.27 19:41:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Leadertech
[2007.08.18 18:19:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Macromedia
[2009.11.29 18:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\MAGIX
[2011.09.16 21:47:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Malwarebytes
[2008.11.22 12:24:01 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Viti\Data aplikací\Microsoft
[2008.06.20 20:30:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Mozilla
[2007.07.30 15:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\MSN6
[2008.07.11 21:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NCH Swift Sound
[2007.01.26 22:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\NetMedia Providers
[2010.01.07 16:33:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Panasonic
[2010.05.17 17:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Publish Providers
[2009.09.24 16:01:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\QIP
[2010.01.07 16:27:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Real
[2007.01.14 19:39:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Reallusion
[2009.11.29 18:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Serif
[2009.09.25 20:10:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Skype
[2009.09.25 20:03:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\skypePM
[2007.01.26 22:57:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sonic Foundry
[2007.11.04 12:26:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony
[2007.11.04 13:05:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup
[2008.01.16 18:14:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Styler
[2007.07.16 13:16:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Sun
[2007.03.24 19:52:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\teamspeak2
[2010.05.04 21:30:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\U3
[2008.06.20 20:58:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Uniblue
[2011.05.12 19:59:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\uTorrent
[2010.05.16 19:41:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\yamaha
[2007.11.24 00:08:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Viti\Data aplikací\Zoner

< *crack* /s >
[2010.05.17 16:55:47 | 000,016,743 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\FL.Studio.9.XXL.mit.Crack.und.VSTi.Cracks.torrent
[2010.05.19 12:22:12 | 000,015,879 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Fruity_Loops_Studio_9_&_Crack.torrent
[2010.05.19 12:22:34 | 000,015,879 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Fruity_Loops_Studio_9_&_Crack[0].torrent
[2009.03.11 17:51:46 | 000,013,171 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Sony Acid Music Studio 7.0a and crack.torrent
[2009.03.11 17:51:46 | 000,013,171 | R--- | M] () -- \_OTL\MovedFiles\09182011_195226\Program Files\BitLord\Torrents\Sony Acid Music Studio 7.0a and crack[0].torrent
[2007.02.17 13:17:32 | 001,059,939 | ---- | M] () -- \Documents and Settings\Viti\Dokumenty\Texty\GrandTheftAutoViceCity - CRACK.rar
[2008.08.27 10:46:18 | 000,000,310 | ---- | M] () -- \Program Files\BitLord\Downloads\Native Instruments Traktor 3.4.0.210\crack.bat
[2008.08.27 10:46:18 | 000,000,327 | ---- | M] () -- \Program Files\BitLord\Downloads\Native Instruments Traktor 3.4.0.210\crackTS.bat
[1999.06.11 20:18:36 | 000,092,827 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Bumpmap\Cracks.cpt
[2002.01.30 18:31:34 | 000,016,068 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Canvas\cracks2c.pcx
[2002.01.30 19:15:38 | 000,010,560 | ---- | M] () -- \Program Files\Corel\Corel Graphics 11\Custom Data\Tiles\CRACKS2M.CPT
[2001.07.10 11:03:00 | 000,028,276 | ---- | M] () -- \Program Files\Serif\DrawPlus\7.0\Borders\Crackerc.wmf
[2001.07.10 11:02:18 | 000,032,558 | ---- | M] () -- \Program Files\Serif\DrawPlus\7.0\Borders\Crackers.wmf
[1995.07.03 18:24:04 | 000,125,094 | ---- | M] () -- \WINDOWS\Fonts\Newcrack.ttf

< *keygen* /s >
[2007.08.09 16:54:17 | 381,145,088 | ---- | M] () -- \Documents and Settings\Viti\Dokumenty\Adobe Photoshop Pro CS2 v9.0 Full ISO + WORKING Keygen\Adobe Photoshop Pro CS2 v9.0 Full ISO + WORKING Keygen.iso

< %APPDATA%\*.* >
[2011.10.11 18:00:29 | 000,000,052 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\AVSDVDPlayer.m3u
[2011.08.23 08:52:05 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Bh8HEGhGffH2.txJgIfiKafIij1.txt
[2004.01.01 03:51:18 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Viti\Data aplikací\desktop.ini

< %APPDATA%\*.exe /s >
[2011.09.07 00:52:48 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758059181\xthzqbbn.exe
[2011.09.07 00:52:50 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060725\xthzqbbn.exe
[2011.09.07 00:52:52 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1186758060903\xthzqbbn.exe
[2011.09.07 00:52:54 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1189700787495\ntjlbqlw.exe
[2011.09.07 00:52:56 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache1\1218560040918\nvnhsscj.exe
[2011.09.07 00:52:59 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1186758059181\ntbttzcq.exe
[2011.09.07 00:53:01 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1186758060725\ntbttzcq.exe
[2011.09.07 00:53:05 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1186758060903\ntbttzcq.exe
[2011.09.07 00:53:22 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1189700787495\swntnjqb.exe
[2011.09.07 00:53:24 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Corel\Messages\540241476_410003\EN\MessageCache2\1218560040918\snenqhhb.exe
[2011.09.07 00:53:26 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\COWON\JetAudio\hhxzkcse.exe
[2010.03.31 19:20:34 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Documents and Settings\Viti\Data aplikací\Facebook\uninstall.exe
[2010.05.16 19:55:56 | 000,004,286 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{271A659B-A7D3-405E-AE31-3086133BE0B7}\ARPPRODUCTICON.exe
[2008.11.22 12:24:01 | 000,000,766 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_28b42f11.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_3344702d.exe
[2008.11.22 12:24:01 | 000,000,766 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_3a4d46e7.exe
[2008.11.22 12:24:01 | 000,000,478 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_49c45178.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_4e244cd.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_54f16447.exe
[2008.11.22 12:24:01 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_6038279.exe
[2008.11.22 12:24:01 | 000,000,894 | R--- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Microsoft\Installer\{3F9D3AF5-BB74-474A-92C8-410839303DB5}\_6ca2753e.exe
[2007.11.04 13:05:46 | 023,510,720 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup\09063B41-0916-4360-A80D-0C2A2B89D300\dotnetfx.exe
[2007.11.04 13:05:04 | 002,585,872 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Viti\Data aplikací\Sony Setup\CF356349-4782-4F9D-AE42-7E3C6AD74B9C\WindowsInstaller-KB893803-v2-x86.exe
[2006.12.14 10:00:02 | 000,118,784 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\U3\temp\cleanup.exe
[2007.02.12 17:46:54 | 003,104,768 | -H-- | M] (SanDisk Corporation) -- C:\Documents and Settings\Viti\Data aplikací\U3\temp\Launchpad Removal.exe
[2011.09.08 22:19:52 | 001,015,808 | ---- | M] () -- C:\Documents and Settings\Viti\Data aplikací\Uniblue\Registry Booster2\sqhvzklx.exe

< %SYSTEMDRIVE%\*.exe >
[2011.10.03 21:33:38 | 000,073,000 | ---- | M] () -- C:\aecae.exe
[2011.09.25 12:33:02 | 000,297,472 | ---- | M] (SteelWerX) -- C:\swreg.exe

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSucces >

< sTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\ProgID\\: MSTIME.TIMEMotionAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0019A09D-1A81-41C5-89EC-D9E737811303}\VersionIndependentProgID\\: MSTIME.TIMEMotionAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\ProgID\\: MSTIME.SMILAnimCompSiteFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{16911A65-D41D-4431-87F7-E757F4D03BD8}\VersionIndependentProgID\\: MSTIME.SMILAnimCompSiteFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\ProgID\\: MSTIME.TIMEFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17237A20-3ADB-48EC-B182-35291F115790}\VersionIndependentProgID\\: MSTIME.TIMEFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\ProgID\\: MSTIME.SMILAnimDefaultCompFactory.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{332B2A56-F86C-47E7-8602-FC42AC8B9920}\VersionIndependentProgID\\: MSTIME.SMILAnimDefaultCompFactory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\ProgID\\: MSTIME.TIMEColorAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F75052-F3EC-4A64-84FB-AB18E0746ED8}\VersionIndependentProgID\\: MSTIME.TIMEColorAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A951B11A-C712-45B3-B884-2469A6243368}\InProcServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\ProgID\\: MSTIME.TIMESetAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BA91CE53-BAEB-4F05-861C-0A2A0934F82E}\VersionIndependentProgID\\: MSTIME.TIMESetAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\ProgID\\: MSTIME.TIMEFilterAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}\VersionIndependentProgID\\: MSTIME.TIMEFilterAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\InprocServer32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\ProgID\\: MSTIME.TIMEAnimation.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F99D135A-C07C-449E-965C-7DBB7C554A51}\VersionIndependentProgID\\: MSTIME.TIMEAnimation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B2F5A901-4080-11D1-A3AC-00C04FB950DC}\\: IADsTimestamp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory\CLSID\\: {16911A65-D41D-4431-87F7-E757F4D03BD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimCompSiteFactory.1\CLSID\\: {16911A65-D41D-4431-87F7-E757F4D03BD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory\CLSID\\: {332B2A56-F86C-47E7-8602-FC42AC8B9920}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.SMILAnimDefaultCompFactory.1\CLSID\\: {332B2A56-F86C-47E7-8602-FC42AC8B9920}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation\CLSID\\: {F99D135A-C07C-449E-965C-7DBB7C554A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEAnimation.1\CLSID\\: {F99D135A-C07C-449E-965C-7DBB7C554A51}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation\CLSID\\: {62F75052-F3EC-4A64-84FB-AB18E0746ED8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEColorAnimation.1\CLSID\\: {62F75052-F3EC-4A64-84FB-AB18E0746ED8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory\CLSID\\: {17237A20-3ADB-48EC-B182-35291F115790}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFactory.1\CLSID\\: {17237A20-3ADB-48EC-B182-35291F115790}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation\CLSID\\: {C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEFilterAnimation.1\CLSID\\: {C54515D0-F2E5-4BDD-AA86-1E4F23E480E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation\CLSID\\: {0019A09D-1A81-41C5-89EC-D9E737811303}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMEMotionAnimation.1\CLSID\\: {0019A09D-1A81-41C5-89EC-D9E737811303}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation\CLSID\\: {BA91CE53-BAEB-4F05-861C-0A2A0934F82E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation.1\\:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSTIME.TIMESetAnimation.1\CLSID\\: {BA91CE53-BAEB-4F05-861C-0A2A0934F82E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{87C96271-ADDB-4745-B2E8-DF88A8472FD1}\1.0\\: MSTIME [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{87C96271-ADDB-4745-B2E8-DF88A8472FD1}\1.0\0\win32\\: C:\WINDOWS\System32\mstime.dll [2002.09.20 18:04:32 | 000,496,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Asr\\ProcessTimeOut: 3600
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\HP Photosmart C4600 series\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft Office Document Image Writer\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers\HP Photosmart C4600 series\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers\Microsoft Office Document Image Writer\\dnsTimeout: 15000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}\\LeaseTerminatesTime: 1318418318
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{667C3BD9-0A91-4F1C-89A3-09254A60E60A}\Parameters\Tcpip\\LeaseTerminatesTime: 1318418318
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar\Settings\General\\LastUpdateGamesTime: 1304845938

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %fystemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %fystemRoot%\System32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0\0

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER

========== Alternate Data Streams ==========

@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:58B11540

< End of report >

Re: Neskutečně zasekané a spomalené PC

Napsal: 12 říj 2011 11:44
od WiZARD_
Extras.txt se neobjevil

Re: Neskutečně zasekané a spomalené PC

Napsal: 12 říj 2011 15:03
od chodnik74
Tak jdeme na to...a pokud uvidím příště cracky jak teď na photoshop,tak naposledy,co vám pomáhám :evil:

:arrow: Stáhneme si na Plochu program OTLObrázek
  • Spustíme soubor OTL.exe (pokud máte Windows Vista nebo Windows 7,tak na soubor klikněte pravým tlačítkem myši a dejte ,,Spustit jako správce,,)
  • Do dolního okna Vlastní skenování/opravy vložíme následující skript a stiskneme tlačítko Opravit

    Kód: Vybrat vše

    :OTL
    PRC - [2002.09.20 18:05:24 | 000,468,992 | RHS- | M] () -- C:\WINDOWS\system32\cxmoagb.exe
    MOD - [2002.09.20 18:05:24 | 000,468,992 | RHS- | M] () -- C:\WINDOWS\system32\cxmoagb.exe
    SRV - File not found [Auto | Stopped] -- -- (MSDisk)
    SRV - File not found [Auto | Stopped] -- -- (hpqddsvc)
    SRV - File not found [On_Demand | Stopped] -- -- (hpqcxs08)
    SRV - [2002.09.20 18:04:04 | 001,064,960 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (uhabyhp)
    SRV - [2002.09.20 18:04:04 | 001,064,960 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (hszvrfa)
    SRV - [2002.09.20 18:04:04 | 001,064,960 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\xsycs.dll -- (bqyvckklk)
    IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Bar = http://search.qip.ru/ie
    IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://search.qip.ru
    IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
    IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..\URLSearchHook: - No CLSID value found
    IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - No CLSID value found
    IE - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
    FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
    FF - prefs.js..browser.search.defaulturl: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.3&q="
    FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
    FF - prefs.js..browser.search.suggest.enabled: false
    FF - prefs.js..browser.startup.homepage: "http://start.icq.com/"
    FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.3&q="
    O2 - BHO: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - No CLSID value found.
    O4 - HKLM..\Run: [Windows LoL Layer] C:\WINDOWS\System32\cxmoagb.exe ()
    O4 - HKU\.DEFAULT..\Run: [Windows LoL Layer] C:\WINDOWS\System32\cxmoagb.exe ()
    O4 - HKU\S-1-5-18..\Run: [Windows LoL Layer] C:\WINDOWS\System32\cxmoagb.exe ()
    O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [FreeCall] "C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe" -nosplash -minimized File not found
    O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [LClock] C:\Program Files\LClock\lclock.exe File not found
    O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [mxClock] C:\DOCUME~1\Viti\LOCALS~1\Temp\Rar$EX00.375\maydesign mxClock\mxClock.exe File not found
    O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [Start WingMan Profiler] File not found
    O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [ViOrb] C:\Program Files\ViOrb\ViOrb.exe File not found
    O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [ViStart] C:\Program Files\ViStart\ViStart.exe File not found
    O4 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003..\Run: [Windows LoL Layer] C:\WINDOWS\System32\cxmoagb.exe ()
    O4 - HKLM..\RunServices: [Windows LoL Layer] C:\WINDOWS\System32\cxmoagb.exe ()
    O15 - HKU\S-1-5-21-2052111302-507921405-1801674531-1003\..Trusted Domains: ([]msn in Tento počítač)
    O20 - Winlogon\Notify\dimsntfy: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
    [2011.10.11 22:24:33 | 000,465,920 | ---- | M] () -- C:\WINDOWS\System32\winlolx.exe
    [2011.10.11 18:52:48 | 000,149,503 | ---- | M] () -- C:\WINDOWS\System32\asr_01444.exe
    [2011.10.11 18:52:41 | 000,000,079 | ---- | M] () -- C:\WINDOWS\System32\asr_vcuqy
    [2011.10.11 22:24:27 | 000,465,920 | ---- | C] () -- C:\WINDOWS\System32\winlolx.exe
    [2011.10.11 18:52:49 | 000,149,503 | RHS- | C] () -- C:\WINDOWS\Fonts\unwise_.exe
    [2011.09.18 18:44:47 | 001,064,960 | RHS- | C] () -- C:\WINDOWS\System32\xsycs.dll
    [2011.05.08 11:09:57 | 000,012,576 | -HS- | C] () -- C:\Documents and Settings\Viti\Local Settings\Data aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
    [2011.05.08 11:09:57 | 000,012,576 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
    [2008.01.16 18:09:46 | 000,468,992 | RHS- | C] () -- C:\WINDOWS\System32\cxmoagb.exe
    [2007.01.26 22:35:45 | 000,610,304 | -H-- | C] () -- C:\WINDOWS\System32\dfxg115.dll
    [2011.05.17 15:45:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Avg7
    [2011.05.12 18:36:44 | 000,012,576 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
    @Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
    @Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:58B11540
    
    :Files
    c:\_OTL\MovedFiles\ /d
    C:\Documents and Settings\Viti\Dokumenty\Texty\GrandTheftAutoViceCity - CRACK.rar /d
    c:\Program Files\BitLord\Downloads\ /d
    C:\Documents and Settings\Viti\Dokumenty\Adobe Photoshop Pro CS2 v9.0 Full ISO + WORKING Keygen\ /d
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :Commands
    [ClearAllRestorePoints]
    [EmptyFlash]
    [EmptyTemp]
    [Purity]
    [ResetHosts]
    
    
  • Po restartu pc se vám objeví log z OTL,ten mi sem prosím vložte..


:arrow: Ověřte tento soubor na VIRUSTOTAL Obrázek
  • klikneme na "Procházet" a do zadávacího pole "Název souboru" jen zkopírujeme(pokud nepůjde tak najdeme tento soubor):

    Kód: Vybrat vše

    C:\PhysicalMBR.bin
    
  • soubor odešleme tak,že klikneme na "Send file" (pokud byl již testován, nechte testovat znovu - Reanalyse)
  • Trpělivě vyčkej dokončení scanu dokud se neobjeví konečný výsledek např.0/41
  • Do fóra zkopíruj výsledný log. nebo odkaz z adresního řádku na stránku.
:arrow: Najděte Malwarebytes a dejte rychlý test a vše co najde smazat... :!:

Re: Neskutečně zasekané a spomalené PC

Napsal: 12 říj 2011 15:12
od chodnik74
a poprosím zkuste nainstalovat nějaký antivir,protože se nám z někama vrací či objevuje nová havěť..Zvolil bych Avast...


http://www.stahuj.centrum.cz/utility_a_ ... tni/avast/

Re: Neskutečně zasekané a spomalené PC

Napsal: 14 říj 2011 16:10
od WiZARD_
Tak máme tu další problém. Při prohledávání počítače v GMERu mi počítač nejspíš vyhořel. Prostě teď jde zapnout, ale nenastartuje se. S tím už mi asi neporadíte že? Zkusím se obrátit někam na servis, abych vůbec veděl co vyhořelo a pak se ozvu a doufám že to vyřešíme. Zatím moc děkuji :)

Re: Neskutečně zasekané a spomalené PC

Napsal: 14 říj 2011 16:21
od chodnik74
Ou, to může být cokoliv... pokud něco vyhořelo, tak nadálku vám opravdu nepomohu.. když stisknete tlačítko zapínání děje se něco?

Re: Neskutečně zasekané a spomalené PC

Napsal: 18 říj 2011 13:19
od WiZARD_
Počítač se jakoby zapne ale nenaběhne. Je slyšet že běží, ale nenaběhne obrazovka a nic. Jen doufám že mi neodešel harddisk. Ten interní je starý už spostu let... :(

Re: Neskutečně zasekané a spomalené PC

Napsal: 18 říj 2011 15:21
od chodnik74
Pokud by odešel HDD, tak by jste na monitoru viděl úvodní hlášení a post testy..ty jsou vidět nebo ne? pokud ne, tak je v háji grafika či základka, pokud ano tak buď ramky nebo HDD :)

Re: Neskutečně zasekané a spomalené PC

Napsal: 18 říj 2011 17:39
od WiZARD_
Prave nic videt neni, ale to s tou zakladkou mate mozna pravdu, ta je tam o dost dyl nez grafika. zkusim se tedy poptat v nejakej servisu a pak se ozvu. Zatim moc dekuji.

Re: Neskutečně zasekané a spomalené PC

Napsal: 19 říj 2011 14:31
od chodnik74
První bych zkontroloval monitor a jeho přívodní kabel, poté grafiku :) pak se ozvěte :)

Re: Neskutečně zasekané a spomalené PC

Napsal: 20 říj 2011 16:24
od WiZARD_
Tak prý jde o základní desku a rovnou se prý vyplatí celý nový počítač a zřejmně se bude přeistalovávat i systém, takže tím to všechno asi končí. Uvidím ještě jak to dopadne, ale zatím chci moc poděkovat za pomoc a Váš čas :) i tak jste mi moc pomohl!

Re: Neskutečně zasekané a spomalené PC

Napsal: 21 říj 2011 11:31
od chodnik74
Dobře :) dejte mi pak vědět, jak to dopadlo :) Rád jsem pomohl.. když budete mít příště problém, tak jsme tu pro Vás :bye:

Re: Neskutečně zasekané a spomalené PC

Napsal: 31 říj 2011 16:59
od WiZARD_
Tak, základní deska vyměněna, toť vše... Počítač běží celkem bez problémů, ale asi uplně vyčištěn ještě nebude. Co navrhujete? :)

Re: Neskutečně zasekané a spomalené PC

Napsal: 31 říj 2011 17:11
od chodnik74
Vložte mi nový RSIT :) uvidíme co dále ;-)

Re: Neskutečně zasekané a spomalené PC

Napsal: 04 lis 2011 00:43
od WiZARD_
,