Stránka 1 z 1

Zavirovaná stranka

Napsal: 21 dub 2010 17:26
od Koldas
Zdravim..
Pri hledání informací do referátu jsem najel na nebezpecnou stránku kde se me to zeptalo, jestli chci pokracovat. Klikl sem na pokracovat a vyskocilo mi okno kde sem videl jek mi to rychle haze trojany do komplu (myslim ze na disk C) a rychle to pribyvalo nez sem se vzpamatoval, rychle sem dal restart ale uz tam bylo kolem 80 trojanů.. nikdy sem to nezazil. Posílám Hijack test a prosím o radu.. ( i jestli sezenu dobry antivir zadarmo ke stazeni)
predem dekuju

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:18:47, on 21.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Jirka\Plocha\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=15161&l=dis
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Jirka\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Jirka\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Centrum.cz Toolbar - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\Canon\OpwareSE4.exe"
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Easy-WebPrint - Náhled - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Přidat na seznam k tisku - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint - Tisk - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Vysokorychlostní tisk - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Služba Google Update (gupdate1cad95dd02c98d0) (gupdate1cad95dd02c98d0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

--
End of file - 6952 bytes

Re: Zavirovaná stranka

Napsal: 21 dub 2010 17:48
od Caroprd111
Zdravím :)


Obrázek Přečtěte si pravidla fóra a dejte log z RSIT.


Obrázek Osobně doporučuji Aviru nebo Avast + ZoneAlarm.

Re: Zavirovaná stranka

Napsal: 21 dub 2010 17:55
od Koldas
Logfile of random's system information tool 1.06 (written by random/random)
Run by Jirka at 2010-04-21 18:46:28
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 86 GB (86%) free of 100 GB
Total RAM: 767 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:46:31, on 21.4.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jirka\Plocha\RSIT.exe
C:\Documents and Settings\Jirka\Plocha\Jirka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=15161&l=dis
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Jirka\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Jirka\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Centrum.cz Toolbar - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\Canon\OpwareSE4.exe"
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Easy-WebPrint - Náhled - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Přidat na seznam k tisku - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint - Tisk - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Vysokorychlostní tisk - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Služba Google Update (gupdate1cad95dd02c98d0) (gupdate1cad95dd02c98d0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

--
End of file - 6720 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1606980848-2111687655-725345543-1003.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1606980848-2111687655-725345543-1003.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-04-11 341600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}]
CentrumczToolbar BHO - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}]
EWPBrowseObject Class - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 34304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\Jirka\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2006-04-18 552960]
{D5D47440-0750-463D-BAEF-A47D02414806} - Centrum.cz Toolbar - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"=C:\WINDOWS\system32\Ati2mdxx.exe [2007-02-02 26112]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2003-09-30 155648]
"OpwareSE4"=C:\Program Files\Canon\OpwareSE4.exe []
"SoundMan"=C:\WINDOWS\soundman.exe [2001-05-29 124416]
"Media Codec Update Service"=C:\Program Files\Essentials Codec Pack\update.exe [2007-04-08 303104]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]
"DAEMON Tools-1033"=C:\Program Files\D-Tools\daemon.exe [2004-08-22 81920]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-04-11 202256]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2010-03-24 319792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-02-02 110592]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Virgin Interactive\Original War\OwarFull.DLL"="C:\Program Files\Virgin Interactive\Original War\OwarFull.DLL:*:Enabled:OwarFull"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-04-21 18:46:28 ----D---- C:\rsit
2010-04-19 15:49:49 ----D---- C:\Program Files\HERI Editor
2010-04-18 21:41:55 ----A---- C:\LOG_JIRI_sail.txt_3_.txt
2010-04-15 11:21:12 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-15 10:58:37 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-15 10:58:29 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-15 10:58:22 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9$
2010-04-15 10:58:18 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-04-15 10:58:11 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-15 10:58:05 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-15 10:57:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-15 10:57:49 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-11 13:39:22 ----D---- C:\Program Files\Total Video Converter
2010-04-11 12:44:15 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Apple Computer
2010-04-11 12:02:49 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2010-04-11 12:02:44 ----A---- C:\WINDOWS\system32\pndx5032.dll
2010-04-11 12:02:44 ----A---- C:\WINDOWS\system32\pndx5016.dll
2010-04-11 12:02:33 ----D---- C:\Program Files\Common Files\xing shared
2010-04-11 12:02:05 ----D---- C:\Program Files\Real
2010-04-11 12:02:05 ----A---- C:\WINDOWS\system32\pncrt.dll
2010-04-11 12:02:03 ----D---- C:\Program Files\Common Files\Real
2010-04-11 12:02:03 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2010-04-11 12:02:00 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Real
2010-04-11 12:00:22 ----D---- C:\Program Files\Google
2010-04-11 10:18:04 ----D---- C:\Program Files\DVDVIDEOSOFT
2010-04-09 14:29:34 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Unity
2010-04-07 22:33:13 ----D---- C:\Program Files\Microsoft Office
2010-04-07 22:32:57 ----D---- C:\Program Files\MSECache
2010-04-07 22:03:23 ----D---- C:\Documents and Settings\Jirka\Data aplikací\XnView
2010-04-07 22:02:59 ----D---- C:\Program Files\XnView
2010-04-05 12:03:01 ----D---- C:\Program Files\QuickTime
2010-04-05 12:03:00 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2010-04-05 12:02:40 ----D---- C:\Program Files\Common Files\Apple
2010-04-05 12:02:23 ----D---- C:\Program Files\Apple Software Update
2010-04-05 12:02:22 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2010-04-02 11:16:00 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2010-03-31 18:22:35 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-03-31 18:22:26 ----HDC---- C:\WINDOWS\$NtUninstallKB980182$
2010-03-31 16:53:08 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Hamachi
2010-03-31 16:52:46 ----D---- C:\Program Files\Hamachi
2010-03-31 13:05:32 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-03-30 20:56:34 ----D---- C:\Documents and Settings\Jirka\Data aplikací\WinRAR
2010-03-30 20:56:09 ----D---- C:\Program Files\WinRAR
2010-03-30 17:24:38 ----D---- C:\Program Files\Virgin Interactive
2010-03-30 15:51:01 ----A---- C:\WINDOWS\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.0.1600.22.dll
2010-03-30 15:50:46 ----A---- C:\WINDOWS\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.0.1600.22.dll
2010-03-30 15:49:37 ----D---- C:\WINDOWS\system32\RsFx
2010-03-30 15:48:30 ----D---- C:\Program Files\MSXML 6.0
2010-03-30 15:42:17 ----D---- C:\Program Files\D-Tools
2010-03-30 15:42:03 ----D---- C:\WINDOWS\Downloaded Installations
2010-03-30 15:07:39 ----HDC---- C:\WINDOWS\$NtUninstallKB942288-v3$
2010-03-30 15:07:07 ----D---- C:\Program Files\Microsoft SQL Server
2010-03-30 15:06:59 ----D---- C:\Program Files\Microsoft Synchronization Services
2010-03-30 15:06:58 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2010-03-30 15:03:21 ----D---- C:\Program Files\Microsoft.NET
2010-03-30 15:03:21 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2010-03-30 15:03:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-03-30 15:02:57 ----D---- C:\Program Files\Microsoft SDKs
2010-03-30 15:01:39 ----D---- C:\WINDOWS\system32\XPSViewer
2010-03-30 15:01:35 ----D---- C:\Program Files\MSBuild
2010-03-30 15:01:34 ----D---- C:\WINDOWS\system32\en-US
2010-03-30 15:01:24 ----D---- C:\Program Files\Reference Assemblies
2010-03-30 15:00:36 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-03-30 15:00:35 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-03-30 15:00:35 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-03-30 15:00:35 ----HD---- C:\f52bb255a4a1289952eff155ee13
2010-03-30 15:00:01 ----RSD---- C:\WINDOWS\assembly
2010-03-30 14:59:32 ----D---- C:\WINDOWS\Microsoft.NET
2010-03-30 14:32:33 ----D---- C:\Program Files\PokerStars
2010-03-28 18:34:01 ----A---- C:\WINDOWS\NeroDigital.ini
2010-03-28 16:38:16 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2010-03-28 16:38:16 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2010-03-28 16:38:12 ----D---- C:\WINDOWS\Logs
2010-03-28 16:37:31 ----D---- C:\WINDOWS\RegisteredPackages
2010-03-28 16:36:31 ----N---- C:\WINDOWS\system32\vxblock.dll
2010-03-28 16:36:31 ----N---- C:\WINDOWS\system32\pxwave.dll
2010-03-28 16:36:31 ----N---- C:\WINDOWS\system32\pxsfs.dll
2010-03-28 16:36:31 ----N---- C:\WINDOWS\system32\pxmas.dll
2010-03-28 16:36:31 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2010-03-28 16:36:31 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2010-03-28 16:36:31 ----N---- C:\WINDOWS\system32\pxdrv.dll
2010-03-28 16:36:31 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2010-03-28 16:36:31 ----N---- C:\WINDOWS\system32\pxafs.dll
2010-03-28 16:36:31 ----N---- C:\WINDOWS\system32\px.dll
2010-03-28 16:36:31 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Winamp
2010-03-28 15:13:18 ----N---- C:\WINDOWS\system32\TwnLib4.dll
2010-03-28 15:13:18 ----A---- C:\WINDOWS\system32\TwnLib20.dll
2010-03-28 15:13:17 ----N---- C:\WINDOWS\system32\ImagXRA7.dll
2010-03-28 15:13:17 ----N---- C:\WINDOWS\system32\ImagXR7.dll
2010-03-28 15:13:17 ----N---- C:\WINDOWS\system32\ImagXpr7.dll
2010-03-28 15:13:17 ----N---- C:\WINDOWS\system32\ImagX7.dll
2010-03-28 15:13:17 ----A---- C:\WINDOWS\system32\NeroCheck.exe
2010-03-28 15:13:16 ----D---- C:\Program Files\Common Files\Ahead
2010-03-28 15:13:16 ----D---- C:\Program Files\Ahead
2010-03-28 14:42:44 ----D---- C:\Program Files\totalcmd
2010-03-28 14:42:44 ----D---- C:\Documents and Settings\Jirka\Data aplikací\GHISLER
2010-03-28 12:59:12 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-03-28 12:59:02 ----D---- C:\Program Files\Common Files\Adobe
2010-03-28 12:59:02 ----D---- C:\Program Files\Adobe
2010-03-27 21:37:03 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-03-27 21:36:58 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-03-27 21:36:48 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-03-27 21:36:41 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-03-27 21:36:37 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-03-27 17:43:16 ----N---- C:\WINDOWS\system32\iyvu9_32.dll
2010-03-27 17:43:16 ----A---- C:\WINDOWS\system32\iacenc.dll
2010-03-27 17:43:15 ----D---- C:\Program Files\Ligos
2010-03-27 17:42:48 ----A---- C:\WINDOWS\IsUninst.exe
2010-03-27 17:42:24 ----D---- C:\Program Files\Disney Interactive
2010-03-27 17:42:03 ----A---- C:\WINDOWS\disney.ini
2010-03-27 17:41:59 ----A---- C:\WINDOWS\disneysy.ini
2010-03-27 17:17:58 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Nero
2010-03-27 17:15:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\Nero
2010-03-27 17:07:56 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Media Player Classic
2010-03-27 17:07:44 ----D---- C:\Program Files\Essentials Codec Pack
2010-03-27 03:54:12 ----D---- C:\Program Files\Webteh
2010-03-25 23:59:38 ----D---- C:\WINDOWS\Prefetch
2010-03-25 23:42:11 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-03-25 23:41:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-03-25 23:41:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978207$
2010-03-25 23:41:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-03-25 23:41:24 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-03-25 23:41:11 ----HDC---- C:\WINDOWS\$NtUninstallKB977165-v2$
2010-03-25 23:41:01 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-03-25 23:40:53 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-03-25 23:40:43 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-03-25 23:40:35 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-03-25 23:40:27 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-03-25 23:40:19 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-03-25 23:40:10 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-03-25 23:40:02 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-03-25 23:39:54 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-03-25 23:39:44 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-03-25 23:39:35 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-03-25 23:39:27 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-03-25 23:39:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-03-25 23:39:12 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-03-25 23:39:04 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-03-25 23:38:50 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-03-25 23:38:42 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-03-25 23:38:29 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-03-25 23:38:21 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-03-25 23:38:12 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-03-25 23:38:03 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-03-25 23:37:52 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-03-25 23:37:40 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-03-25 23:37:31 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-03-25 23:37:21 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-03-25 23:37:14 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-03-25 23:37:07 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-03-25 23:37:00 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-03-25 23:36:53 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-03-25 23:36:46 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-03-25 23:36:38 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-03-25 23:36:27 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-03-25 23:36:19 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-03-25 23:36:11 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2010-03-25 23:36:04 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-03-25 23:35:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-03-25 23:35:49 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-03-25 23:35:42 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-03-25 23:35:34 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-03-25 23:35:27 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-03-25 23:35:18 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-03-25 23:35:10 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-03-25 23:35:02 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-03-25 23:34:53 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-03-25 23:34:38 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-03-25 23:30:31 ----D---- C:\WINDOWS\system32\cs-cz
2010-03-25 23:30:30 ----D---- C:\WINDOWS\system32\cs
2010-03-25 23:30:30 ----D---- C:\WINDOWS\system32\bits
2010-03-25 23:30:30 ----D---- C:\WINDOWS\l2schemas
2010-03-25 23:26:20 ----D---- C:\WINDOWS\network diagnostic
2010-03-25 23:15:16 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-03-25 22:03:33 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-03-25 22:03:26 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2010-03-25 22:03:19 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2010-03-25 22:03:11 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2010-03-25 22:03:03 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2010-03-25 22:02:55 ----HDC---- C:\WINDOWS\$NtUninstallKB960859_0$
2010-03-25 22:02:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971468_0$
2010-03-25 22:02:29 ----HDC---- C:\WINDOWS\$NtUninstallKB978207_0$
2010-03-25 22:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-03-25 22:02:12 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-03-25 22:02:06 ----HDC---- C:\WINDOWS\$NtUninstallKB955759_0$
2010-03-25 22:01:57 ----HDC---- C:\WINDOWS\$NtUninstallKB969059_0$
2010-03-25 22:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2010-03-25 22:01:41 ----HDC---- C:\WINDOWS\$NtUninstallKB978037_0$
2010-03-25 22:01:34 ----HDC---- C:\WINDOWS\$NtUninstallKB975713_0$
2010-03-25 22:01:26 ----HDC---- C:\WINDOWS\$NtUninstallKB971657_0$
2010-03-25 22:01:15 ----HDC---- C:\WINDOWS\$NtUninstallKB977165-v2_0$
2010-03-25 22:01:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2010-03-25 22:00:57 ----HDC---- C:\WINDOWS\$NtUninstallKB972270_0$
2010-03-25 22:00:49 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_0$
2010-03-25 22:00:41 ----HDC---- C:\WINDOWS\$NtUninstallKB956844_0$
2010-03-25 22:00:34 ----HDC---- C:\WINDOWS\$NtUninstallKB961501_0$
2010-03-25 22:00:26 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-03-25 22:00:20 ----HDC---- C:\WINDOWS\$NtUninstallKB975561_0$
2010-03-25 22:00:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-03-25 22:00:06 ----HDC---- C:\WINDOWS\$NtUninstallKB978251_0$
2010-03-25 21:59:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973869_0$
2010-03-25 21:59:49 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2010-03-25 21:59:42 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2010-03-25 21:59:34 ----HDC---- C:\WINDOWS\$NtUninstallKB974571_0$
2010-03-25 21:59:25 ----HDC---- C:\WINDOWS\$NtUninstallKB975560_0$
2010-03-25 21:59:14 ----HDC---- C:\WINDOWS\$NtUninstallKB973507_0$
2010-03-25 21:59:06 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_0$
2010-03-25 21:58:58 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2010-03-25 21:58:47 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2010-03-25 21:58:38 ----HDC---- C:\WINDOWS\$NtUninstallKB973354_0$
2010-03-25 21:58:29 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-03-25 21:58:18 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2010-03-25 21:58:09 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-03-25 21:58:01 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2010-03-25 21:57:54 ----HDC---- C:\WINDOWS\$NtUninstallKB974392_0$
2010-03-25 21:57:42 ----HDC---- C:\WINDOWS\$NtUninstallKB977914_0$
2010-03-25 21:57:29 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2010-03-25 21:57:20 ----HDC---- C:\WINDOWS\$NtUninstallKB970238_0$
2010-03-25 21:57:12 ----HDC---- C:\WINDOWS\$NtUninstallKB978706_0$
2010-03-25 21:57:01 ----D---- C:\WINDOWS\ServicePackFiles
2010-03-25 21:56:59 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2010-03-25 21:56:51 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2010-03-25 21:56:43 ----HDC---- C:\WINDOWS\$NtUninstallKB973815_0$
2010-03-25 21:56:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971032$
2010-03-25 21:56:15 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2010-03-25 21:56:01 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2010-03-25 21:55:54 ----D---- C:\Program Files\MSXML 4.0
2010-03-25 21:55:44 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-03-25 21:55:18 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2010-03-25 21:54:53 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2010-03-25 21:54:33 ----HDC---- C:\WINDOWS\$NtUninstallKB975467_0$
2010-03-25 21:54:25 ----HDC---- C:\WINDOWS\$NtUninstallKB968389_0$
2010-03-25 21:54:15 ----HDC---- C:\WINDOWS\$NtUninstallKB969947_0$
2010-03-25 12:09:41 ----D---- C:\Program Files\Eidos Interactive
2010-03-25 12:09:29 ----A---- C:\WINDOWS\uninst.exe
2010-03-25 11:47:13 ----D---- C:\WINDOWS\pss
2010-03-24 22:32:19 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Canon
2010-03-24 20:16:32 ----D---- C:\Program Files\QIP
2010-03-24 20:11:36 ----D---- C:\Koldas
2010-03-24 19:19:54 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-03-24 19:19:50 ----D---- C:\Program Files\Avance Sound Manager
2010-03-24 19:19:46 ----D---- C:\Program Files\AvRack
2010-03-24 19:19:46 ----A---- C:\WINDOWS\avrack.ini
2010-03-24 19:19:45 ----N---- C:\WINDOWS\soundman.exe
2010-03-24 19:19:45 ----N---- C:\WINDOWS\alcupd.exe
2010-03-24 19:19:45 ----N---- C:\WINDOWS\alcrmv.exe
2010-03-24 19:16:43 ----A---- C:\WINDOWS\rtport.tmp
2010-03-24 09:18:46 ----D---- C:\Program Files\Ask.com
2010-03-24 09:18:18 ----D---- C:\Program Files\uTorrent
2010-03-24 09:17:52 ----D---- C:\Documents and Settings\Jirka\Data aplikací\uTorrent
2010-03-24 09:04:14 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Mozilla
2010-03-24 09:04:03 ----D---- C:\Program Files\Mozilla Firefox
2010-03-24 09:03:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\CentrumczToolbar
2010-03-24 09:03:56 ----D---- C:\Program Files\CentrumczToolbar
2010-03-23 22:31:00 ----D---- C:\Documents and Settings\All Users\Data aplikací\InstallShield
2010-03-23 22:31:00 ----A---- C:\WINDOWS\MAXLINK.INI
2010-03-23 22:30:59 ----D---- C:\Documents and Settings\Jirka\Data aplikací\ScanSoft
2010-03-23 22:30:55 ----D---- C:\Program Files\Common Files\ScanSoft Shared
2010-03-23 22:30:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\ScanSoft
2010-03-23 22:29:22 ----D---- C:\Program Files\ArcSoft
2010-03-23 22:29:22 ----A---- C:\WINDOWS\PCDLIB32.DLL
2010-03-23 22:28:17 ----D---- C:\Program Files\Common Files\CANON
2010-03-23 22:27:40 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-03-23 22:27:40 ----A---- C:\WINDOWS\system32\msvcp71.dll
2010-03-23 22:27:40 ----A---- C:\WINDOWS\system32\MFC71.dll
2010-03-23 22:27:39 ----A---- C:\WINDOWS\IsUn0405.exe
2010-03-23 22:27:13 ----HD---- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
2010-03-23 22:27:09 ----A---- C:\WINDOWS\system32\CNMLM83.DLL
2010-03-23 22:27:07 ----HD---- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2010-03-23 22:27:03 ----A---- C:\WINDOWS\system32\cnco160.dll
2010-03-23 22:27:02 ----A---- C:\WINDOWS\system32\CNCL160.DLL
2010-03-23 22:27:02 ----A---- C:\WINDOWS\system32\CNCI160.DLL
2010-03-23 22:27:02 ----A---- C:\WINDOWS\system32\CNCC160.DLL
2010-03-23 22:26:57 ----HD---- C:\Program Files\CanonBJ
2010-03-23 22:23:55 ----D---- C:\Program Files\Canon
2010-03-23 22:06:45 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2010-03-23 22:06:35 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-03-23 22:06:34 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-23 22:06:21 ----D---- C:\Program Files\Common Files\InstallShield
2010-03-23 22:05:20 ----D---- C:\ATI
2010-03-23 21:47:01 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Macromedia
2010-03-23 21:47:01 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Adobe
2010-03-23 21:17:12 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-03-23 21:11:55 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2010-03-23 21:11:50 ----HDC---- C:\WINDOWS\$NtUninstallKB974318_0$
2010-03-23 21:11:42 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2010-03-23 21:11:20 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2010-03-23 21:11:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975025_0$
2010-03-23 21:11:12 ----D---- C:\WINDOWS\system32\PreInstall
2010-03-23 21:11:12 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-03-23 21:11:10 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-03-23 21:11:07 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-03-23 21:10:56 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-03-23 21:10:55 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2010-03-23 21:10:55 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-23 20:54:40 ----SHD---- C:\RECYCLER
2010-03-23 20:38:34 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-03-23 00:25:55 ----A---- C:\WINDOWS\system32\h323log.txt
2010-03-23 00:22:19 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2010-03-23 00:22:19 ----A---- C:\WINDOWS\system32\ati3duag.dll
2010-03-23 00:22:19 ----A---- C:\WINDOWS\system32\ati3d1ag.dll
2010-03-23 00:22:19 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2010-03-23 00:22:18 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2010-03-23 00:21:47 ----A---- C:\WINDOWS\system32\usbui.dll
2010-03-23 00:20:47 ----A---- C:\WINDOWS\imsins.BAK
2010-03-23 00:20:44 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-23 00:20:43 ----SHD---- C:\WINDOWS\Installer
2010-03-23 00:20:43 ----D---- C:\Program Files\Common Files\ODBC
2010-03-23 00:20:43 ----A---- C:\WINDOWS\ODBCINST.INI
2010-03-23 00:20:40 ----RD---- C:\Program Files
2010-03-23 00:20:40 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-03-23 00:20:40 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-23 00:20:40 ----D---- C:\Program Files\Common Files
2010-03-23 00:20:36 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2010-03-23 00:20:36 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2010-03-23 00:20:36 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbdur.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbdru.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2010-03-23 00:20:34 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2010-03-23 00:20:32 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2010-03-23 00:20:32 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2010-03-23 00:20:32 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2010-03-23 00:20:32 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2010-03-23 00:20:32 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2010-03-23 00:20:32 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2010-03-23 00:20:32 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2010-03-23 00:20:31 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2010-03-23 00:20:31 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2010-03-23 00:20:31 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2010-03-23 00:20:31 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2010-03-23 00:20:31 ----RA---- C:\WINDOWS\system32\kbdest.dll
2010-03-23 00:20:27 ----A---- C:\WINDOWS\system32\kbdycl.dll
2010-03-23 00:20:27 ----A---- C:\WINDOWS\system32\kbdsl1.dll
2010-03-23 00:20:27 ----A---- C:\WINDOWS\system32\kbdsl.dll
2010-03-23 00:20:27 ----A---- C:\WINDOWS\system32\kbdro.dll
2010-03-23 00:20:27 ----A---- C:\WINDOWS\system32\kbdpl1.dll
2010-03-23 00:20:27 ----A---- C:\WINDOWS\system32\kbdpl.dll
2010-03-23 00:20:27 ----A---- C:\WINDOWS\system32\kbdhu1.dll
2010-03-23 00:20:27 ----A---- C:\WINDOWS\system32\kbdhu.dll
2010-03-23 00:20:27 ----A---- C:\WINDOWS\system32\kbdcr.dll
2010-03-23 00:20:27 ----A---- C:\WINDOWS\system32\KBDAL.DLL
2010-03-23 00:20:26 ----A---- C:\WINDOWS\system32\irclass.dll
2010-03-23 00:20:26 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-03-23 00:20:25 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-03-23 00:20:25 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-03-23 00:20:25 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-03-23 00:20:23 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2010-03-23 00:20:23 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-03-23 00:20:23 ----A---- C:\WINDOWS\system32\batt.dll
2010-03-23 00:20:22 ----A---- C:\WINDOWS\notepad.exe
2010-03-23 00:20:21 ----A---- C:\WINDOWS\system32\storprop.dll
2010-03-23 00:20:14 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2010-03-23 00:20:09 ----RA---- C:\WINDOWS\SET8.tmp
2010-03-23 00:20:07 ----RA---- C:\WINDOWS\SET4.tmp
2010-03-23 00:20:06 ----RA---- C:\WINDOWS\SET3.tmp
2010-03-23 00:20:00 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-23 00:20:00 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-23 00:19:55 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-03-23 00:19:40 ----A---- C:\WINDOWS\setuplog.txt
2010-03-23 00:19:38 ----D---- C:\Documents and Settings
2010-03-23 00:19:37 ----SHD---- C:\System Volume Information
2010-03-23 00:18:23 ----SH---- C:\boot.ini
2010-03-23 00:14:36 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-23 00:14:36 ----RSD---- C:\WINDOWS\Fonts
2010-03-23 00:14:36 ----RD---- C:\WINDOWS\Web
2010-03-23 00:14:36 ----HD---- C:\WINDOWS\inf
2010-03-23 00:14:36 ----D---- C:\WINDOWS\WinSxS
2010-03-23 00:14:36 ----D---- C:\WINDOWS\twain_32
2010-03-23 00:14:36 ----D---- C:\WINDOWS\Temp
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\wins
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\wbem
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\usmt
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\spool
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\ShellExt
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\Setup
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\ras
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\oobe
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\npp
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\mui
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\inetsrv
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\IME
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\icsxml
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\ias
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\export
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\drivers
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\dhcp
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\config
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\3com_dmi
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\3076
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\2052
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\1054
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\1042
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\1041
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\1037
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\1033
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\1031
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\1029
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\1028
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32\1025
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system32
2010-03-23 00:14:36 ----D---- C:\WINDOWS\system
2010-03-23 00:14:36 ----D---- C:\WINDOWS\security
2010-03-23 00:14:36 ----D---- C:\WINDOWS\Resources
2010-03-23 00:14:36 ----D---- C:\WINDOWS\repair
2010-03-23 00:14:36 ----D---- C:\WINDOWS\Provisioning
2010-03-23 00:14:36 ----D---- C:\WINDOWS\pchealth
2010-03-23 00:14:36 ----D---- C:\WINDOWS\PeerNet
2010-03-23 00:14:36 ----D---- C:\WINDOWS\mui
2010-03-23 00:14:36 ----D---- C:\WINDOWS\msapps
2010-03-23 00:14:36 ----D---- C:\WINDOWS\msagent
2010-03-23 00:14:36 ----D---- C:\WINDOWS\Media
2010-03-23 00:14:36 ----D---- C:\WINDOWS\java
2010-03-23 00:14:36 ----D---- C:\WINDOWS\ime
2010-03-23 00:14:36 ----D---- C:\WINDOWS\Help
2010-03-23 00:14:36 ----D---- C:\WINDOWS\ehome
2010-03-23 00:14:36 ----D---- C:\WINDOWS\Driver Cache
2010-03-23 00:14:36 ----D---- C:\WINDOWS\Debug
2010-03-23 00:14:36 ----D---- C:\WINDOWS\Cursors
2010-03-23 00:14:36 ----D---- C:\WINDOWS\Connection Wizard
2010-03-23 00:14:36 ----D---- C:\WINDOWS\Config
2010-03-23 00:14:36 ----D---- C:\WINDOWS\AppPatch
2010-03-23 00:14:36 ----D---- C:\WINDOWS\addins
2010-03-23 00:14:36 ----D---- C:\WINDOWS
2010-03-23 00:14:08 ----D---- C:\MP3 PAJA
2010-03-22 23:37:02 ----D---- C:\Documents and Settings\Jirka\Data aplikací\Identities
2010-03-22 23:37:00 ----HD---- C:\Program Files\Uninstall Information
2010-03-22 23:36:54 ----ASH---- C:\Documents and Settings\Jirka\Data aplikací\desktop.ini
2010-03-22 23:36:53 ----SD---- C:\Documents and Settings\Jirka\Data aplikací\Microsoft
2010-03-22 23:36:03 ----D---- C:\WINDOWS\SoftwareDistribution
2010-03-22 23:36:02 ----SD---- C:\WINDOWS\system32\Microsoft
2010-03-22 23:36:02 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-22 23:31:24 ----D---- C:\WINDOWS\system32\xircom
2010-03-22 23:31:24 ----D---- C:\Program Files\xerox
2010-03-22 23:31:24 ----D---- C:\Program Files\microsoft frontpage
2010-03-22 23:31:03 ----A---- C:\WINDOWS\control.ini
2010-03-22 23:31:03 ----A---- C:\AUTOEXEC.BAT
2010-03-22 23:30:49 ----A---- C:\WINDOWS\OEWABLog.txt
2010-03-22 23:30:45 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-03-22 23:29:56 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-03-22 23:29:56 ----RD---- C:\WINDOWS\Offline Web Pages
2010-03-22 23:29:56 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-03-22 23:29:50 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-03-22 23:29:45 ----HD---- C:\Program Files\WindowsUpdate
2010-03-22 23:29:43 ----D---- C:\Program Files\Online Services
2010-03-22 23:29:29 ----D---- C:\WINDOWS\system32\DirectX
2010-03-22 23:29:09 ----A---- C:\WINDOWS\system32\atrace.dll
2010-03-22 23:29:07 ----A---- C:\WINDOWS\system32\desktop.ini
2010-03-22 23:29:07 ----A---- C:\WINDOWS\desktop.ini
2010-03-22 23:29:00 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-03-22 23:28:59 ----A---- C:\WINDOWS\system32\acctres.dll
2010-03-22 23:28:58 ----D---- C:\Program Files\Common Files\Services
2010-03-22 23:28:55 ----SD---- C:\WINDOWS\Tasks
2010-03-22 23:28:55 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-03-22 23:28:54 ----D---- C:\Program Files\Common Files\MSSoap
2010-03-22 23:28:51 ----D---- C:\WINDOWS\srchasst
2010-03-22 23:28:50 ----D---- C:\WINDOWS\system32\Macromed
2010-03-22 23:28:48 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-03-22 23:28:48 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-03-22 23:28:48 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-03-22 23:28:48 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-03-22 23:28:47 ----A---- C:\WINDOWS\system32\wups.dll
2010-03-22 23:28:47 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-03-22 23:28:47 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-03-22 23:28:47 ----A---- C:\WINDOWS\system32\wuauclt.exe
2010-03-22 23:28:47 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-03-22 23:28:47 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-03-22 23:28:47 ----A---- C:\WINDOWS\system32\qmgr.dll
2010-03-22 23:28:47 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-03-22 23:28:47 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-03-22 23:28:43 ----D---- C:\Program Files\Movie Maker
2010-03-22 23:28:39 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-03-22 23:28:39 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-03-22 23:28:39 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-03-22 23:28:39 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-03-22 23:28:36 ----A---- C:\WINDOWS\system32\fltmc.exe
2010-03-22 23:28:36 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-03-22 23:28:35 ----D---- C:\WINDOWS\system32\Restore
2010-03-22 23:28:35 ----A---- C:\WINDOWS\system32\srsvc.dll
2010-03-22 23:28:35 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-03-22 23:28:35 ----A---- C:\WINDOWS\system32\srclient.dll
2010-03-22 23:28:35 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-03-22 23:28:35 ----A---- C:\WINDOWS\system32\ils.dll
2010-03-22 23:28:34 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-03-22 23:28:34 ----A---- C:\WINDOWS\system32\msconf.dll
2010-03-22 23:28:34 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-03-22 23:28:34 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-03-22 23:28:32 ----D---- C:\Program Files\NetMeeting
2010-03-22 23:28:32 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-03-22 23:28:32 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-03-22 23:28:31 ----A---- C:\WINDOWS\system32\inetres.dll
2010-03-22 23:28:31 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-03-22 23:28:29 ----D---- C:\Program Files\Outlook Express
2010-03-22 23:28:29 ----A---- C:\WINDOWS\system32\schedsvc.dll
2010-03-22 23:28:29 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-03-22 23:28:29 ----A---- C:\WINDOWS\system32\mstask.dll
2010-03-22 23:28:28 ----A---- C:\WINDOWS\system32\isign32.dll
2010-03-22 23:28:28 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-03-22 23:28:28 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-03-22 23:28:28 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-03-22 23:28:23 ----D---- C:\Program Files\Common Files\System
2010-03-22 23:28:18 ----D---- C:\Program Files\Internet Explorer
2010-03-22 23:27:43 ----D---- C:\Program Files\ComPlus Applications
2010-03-22 23:27:41 ----A---- C:\WINDOWS\vbaddin.ini
2010-03-22 23:27:41 ----A---- C:\WINDOWS\vb.ini
2010-03-22 23:27:38 ----D---- C:\WINDOWS\Registration
2010-03-22 23:27:32 ----D---- C:\Program Files\Windows Media Player
2010-03-22 23:27:27 ----D---- C:\Program Files\Messenger
2010-03-22 23:27:23 ----D---- C:\Program Files\MSN Gaming Zone
2010-03-22 23:27:23 ----A---- C:\WINDOWS\system32\write.exe
2010-03-22 23:27:15 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-03-22 23:27:14 ----A---- C:\WINDOWS\system32\winchat.exe
2010-03-22 23:27:14 ----A---- C:\WINDOWS\system32\hticons.dll
2010-03-22 23:27:14 ----A---- C:\WINDOWS\system32\avwav.dll
2010-03-22 23:27:14 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-03-22 23:27:14 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-03-22 23:27:03 ----A---- C:\WINDOWS\system32\sol.exe
2010-03-22 23:27:03 ----A---- C:\WINDOWS\system32\charmap.exe
2010-03-22 23:27:03 ----A---- C:\WINDOWS\system32\getuname.dll
2010-03-22 23:27:03 ----A---- C:\WINDOWS\system32\calc.exe
2010-03-22 23:27:02 ----A---- C:\WINDOWS\system32\winmine.exe
2010-03-22 23:27:02 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-03-22 23:27:02 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-03-22 23:27:02 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-03-22 23:27:02 ----A---- C:\WINDOWS\system32\tskill.exe
2010-03-22 23:27:02 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-03-22 23:27:02 ----A---- C:\WINDOWS\system32\tscon.exe
2010-03-22 23:27:02 ----A---- C:\WINDOWS\system32\reset.exe
2010-03-22 23:27:02 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-03-22 23:27:02 ----A---- C:\WINDOWS\system32\freecell.exe
2010-03-22 23:27:01 ----A---- C:\WINDOWS\system32\shadow.exe
2010-03-22 23:27:01 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-03-22 23:27:01 ----A---- C:\WINDOWS\system32\regini.exe
2010-03-22 23:27:01 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-03-22 23:27:01 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-03-22 23:27:01 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-03-22 23:27:01 ----A---- C:\WINDOWS\system32\msg.exe
2010-03-22 23:27:01 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-03-22 23:27:01 ----A---- C:\WINDOWS\system32\logoff.exe
2010-03-22 23:27:01 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-03-22 23:27:00 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-03-22 23:27:00 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-03-22 23:27:00 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-03-22 23:27:00 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-03-22 23:27:00 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-03-22 23:27:00 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-03-22 23:26:59 ----A---- C:\WINDOWS\system32\stclient.dll
2010-03-22 23:26:59 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-03-22 23:26:54 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-03-22 23:26:53 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-03-22 23:26:53 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-03-22 23:26:53 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-03-22 23:26:53 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-03-22 23:26:52 ----D---- C:\Program Files\Windows NT
2010-03-22 23:26:52 ----A---- C:\WINDOWS\system32\spider.exe
2010-03-22 23:26:52 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-03-22 23:26:52 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-03-22 23:26:51 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-03-22 23:26:51 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-03-22 23:26:51 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-03-22 23:26:51 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-03-22 23:26:51 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-03-22 23:26:51 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-03-22 23:26:51 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-03-22 23:26:50 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2010-03-22 23:26:50 ----A---- C:\WINDOWS\system32\termsrv.dll
2010-03-22 23:26:50 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-03-22 23:26:50 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-03-22 23:26:50 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-03-22 23:26:50 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-03-22 23:26:50 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-03-22 23:26:50 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-03-22 23:26:50 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-03-22 23:26:49 ----D---- C:\WINDOWS\system32\MsDtc
2010-03-22 23:26:49 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-03-22 23:26:49 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-03-22 23:26:49 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-03-22 23:26:49 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-03-22 23:26:49 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-03-22 23:26:49 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-03-22 23:26:49 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-03-22 23:26:48 ----D---- C:\WINDOWS\system32\Com
2010-03-22 23:26:48 ----A---- C:\WINDOWS\system32\colbact.dll
2010-03-22 23:26:48 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-03-22 23:26:48 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-03-22 23:26:48 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-03-22 23:26:48 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-03-22 23:26:47 ----A---- C:\WINDOWS\system32\comuid.dll
2010-03-22 23:26:47 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-03-22 23:26:47 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-03-22 23:26:42 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-03-22 23:26:42 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-03-22 23:26:41 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-03-22 23:26:41 ----A---- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2010-03-25 11:48:02 ----A---- C:\WINDOWS\win.ini
2010-03-25 11:48:02 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R3 ALCXWDM;Service for Avance AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2001-11-01 243964]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-02-02 1975296]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-03-31 25280]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 rtport;rtport; \??\C:\WINDOWS\system32\drivers\rtport.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 RsFx0102;RsFx0102 Driver; C:\WINDOWS\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-02-02 446464]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2008-07-11 40999448]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2007-02-02 520192]
S2 gupdate1cad95dd02c98d0;Služba Google Update (gupdate1cad95dd02c98d0); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-04-11 133104]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-07-10 258072]

-----------------EOF-----------------

Re: Zavirovaná stranka

Napsal: 21 dub 2010 18:00
od Caroprd111
Obrázek Doporučuji odinstalovat:
C:\Program Files\uTorrent\uTorrent.exe

P2P sítě a jejich klienti jsou potenciálním bezpečnostním rizikem, prakticky neustále jsou zdrojem virů, zbytečně se vystavujete riziku.


Obrázek Stáhněte a uložte, nejlépe na plochu http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypněte všechny rezidentní bezpečnostní programy - firewally, antiviry, antispywary
  • Spusťte aplikaci pod účtem s oprávněním Administrátora (Správce), ihned po startu se zobrazí stránka s licenčními podmínkami, pokračujte stisknutím tlačítka "Ano"
  • Dále postupujte dle pokynů, během scanu nespouštějte jiné aplikace a neklikejte do zobrazujícího se okna :!:
  • Scan by měl trvat okolo 5 - 10 minut, po dokončení Combofix zobrazí log C:\ComboFix.txt , který sem vložte.
  • Během skenování může být počítač restartován.

Re: Zavirovaná stranka

Napsal: 21 dub 2010 18:18
od Koldas
ComboFix 10-04-20.04 - Jirka 21.04.2010 19:12:13.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.767.565 [GMT 2:00]
Spuštěný z: c:\documents and settings\Jirka\Plocha\ComboFix.exe
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-03-21 do 2010-04-21 )))))))))))))))))))))))))))))))
.

2010-04-21 16:46 . 2010-04-21 16:46 -------- d-----w- C:\rsit
2010-04-19 13:49 . 2010-04-19 13:49 -------- d-----w- c:\program files\HERI Editor
2010-04-11 11:39 . 2010-04-11 11:39 -------- d-----w- c:\program files\Total Video Converter
2010-04-11 10:02 . 2010-04-11 10:02 -------- d-----w- c:\program files\Common Files\xing shared
2010-04-11 10:02 . 2010-04-11 10:02 -------- d-----w- c:\program files\Real
2010-04-11 10:02 . 2010-04-11 10:02 -------- d-----w- c:\program files\Common Files\Real
2010-04-11 10:00 . 2010-04-11 10:00 -------- d-----w- c:\program files\Google
2010-04-11 08:18 . 2010-04-11 08:18 -------- d-----w- c:\program files\DVDVIDEOSOFT
2010-04-07 20:32 . 2010-04-07 20:32 -------- d-----w- c:\program files\MSECache
2010-04-07 20:02 . 2010-04-07 20:03 -------- d-----w- c:\program files\XnView
2010-04-05 10:03 . 2010-04-05 10:03 -------- d-----w- c:\program files\QuickTime
2010-04-05 10:02 . 2010-04-05 10:02 -------- d-----w- c:\program files\Common Files\Apple
2010-04-05 10:02 . 2010-04-05 10:02 -------- d-----w- c:\program files\Apple Software Update
2010-04-02 09:16 . 2010-04-02 09:16 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-03-31 14:52 . 2010-03-31 14:52 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2010-03-31 14:52 . 2010-04-20 21:04 -------- d-----w- c:\program files\Hamachi
2010-03-30 15:24 . 2010-03-30 16:51 -------- d-----w- c:\program files\Virgin Interactive
2010-03-30 13:51 . 2008-07-11 00:28 50200 ----a-w- c:\windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.0.1600.22.dll
2010-03-30 13:50 . 2008-07-11 00:28 79896 ----a-w- c:\windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.0.1600.22.dll
2010-03-30 13:49 . 2010-03-30 13:49 -------- d-----w- c:\windows\system32\RsFx
2010-03-30 13:48 . 2010-03-30 13:48 -------- d-----w- c:\program files\MSXML 6.0
2010-03-30 13:42 . 2004-08-22 14:31 5248 ----a-w- c:\windows\system32\drivers\d347prt.sys
2010-03-30 13:42 . 2004-08-22 14:31 155136 ----a-w- c:\windows\system32\drivers\d347bus.sys
2010-03-30 13:42 . 2010-03-30 13:42 -------- d-----w- c:\program files\D-Tools
2010-03-30 13:42 . 2010-03-30 13:42 -------- d-----w- c:\windows\Downloaded Installations
2010-03-30 13:07 . 2010-03-30 13:49 -------- d-----w- c:\program files\Microsoft SQL Server
2010-03-30 13:06 . 2010-03-30 13:06 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-03-30 13:06 . 2010-03-30 13:06 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-03-30 13:03 . 2010-03-30 13:48 -------- d-----w- c:\program files\Microsoft.NET
2010-03-30 13:03 . 2010-03-30 13:05 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2010-03-30 13:02 . 2010-03-30 13:02 -------- d-----w- c:\program files\Microsoft SDKs
2010-03-30 13:01 . 2010-03-30 13:01 -------- d-----w- c:\windows\system32\XPSViewer
2010-03-30 13:01 . 2010-03-30 13:01 -------- d-----w- c:\program files\MSBuild
2010-03-30 13:01 . 2010-03-30 13:01 -------- d-----w- c:\program files\Reference Assemblies
2010-03-30 13:01 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-03-30 13:00 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-30 13:00 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-03-30 13:00 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-30 13:00 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-03-30 13:00 . 2010-03-30 13:01 -------- d-----w- C:\f52bb255a4a1289952eff155ee13
2010-03-30 13:00 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-30 13:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-03-30 13:00 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-03-30 13:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-03-30 12:32 . 2010-04-20 19:40 -------- d-----w- c:\program files\PokerStars
2010-03-28 14:38 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-03-28 14:38 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2010-03-28 14:38 . 2010-03-28 14:38 -------- d-----w- c:\windows\Logs
2010-03-28 13:13 . 2005-09-01 10:03 5888 ------w- c:\windows\system32\drivers\imagedrv.sys
2010-03-28 13:13 . 2005-09-01 10:03 127488 ------w- c:\windows\system32\drivers\imagesrv.sys
2010-03-28 13:13 . 2004-07-09 07:43 364544 ------w- c:\windows\system32\TwnLib4.dll
2010-03-28 13:13 . 2000-06-26 09:45 106496 ----a-w- c:\windows\system32\TwnLib20.dll
2010-03-28 13:13 . 2006-01-12 14:40 155648 ----a-w- c:\windows\system32\NeroCheck.exe
2010-03-28 13:13 . 2004-07-26 15:16 476320 ------w- c:\windows\system32\ImagXpr7.dll
2010-03-28 13:13 . 2004-07-26 15:16 471040 ------w- c:\windows\system32\ImagXRA7.dll
2010-03-28 13:13 . 2004-07-26 15:16 262144 ------w- c:\windows\system32\ImagXR7.dll
2010-03-28 13:13 . 2004-07-26 15:16 1568768 ------w- c:\windows\system32\ImagX7.dll
2010-03-28 13:13 . 2010-03-28 13:13 -------- d-----w- c:\program files\Ahead
2010-03-28 13:13 . 2010-03-28 13:13 -------- d-----w- c:\program files\Common Files\Ahead
2010-03-28 12:42 . 2009-09-24 05:50 545 ----a-w- c:\windows\UC.PIF
2010-03-28 12:42 . 2009-09-24 05:50 545 ----a-w- c:\windows\RAR.PIF
2010-03-28 12:42 . 2009-09-24 05:50 545 ----a-w- c:\windows\PKZIP.PIF
2010-03-28 12:42 . 2009-09-24 05:50 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-03-28 12:42 . 2009-09-24 05:50 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-03-28 12:42 . 2009-09-24 05:50 545 ----a-w- c:\windows\LHA.PIF
2010-03-28 12:42 . 2009-09-24 05:50 545 ----a-w- c:\windows\ARJ.PIF
2010-03-28 12:42 . 2010-03-28 12:44 -------- d-----w- c:\program files\totalcmd
2010-03-28 10:59 . 2010-03-28 10:59 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-27 15:43 . 2000-06-23 13:05 136704 ----a-w- c:\windows\system32\iacenc.dll
2010-03-27 15:43 . 2000-06-22 12:09 56320 ------w- c:\windows\system32\iyvu9_32.dll
2010-03-27 15:43 . 2010-03-27 15:43 -------- d-----w- c:\program files\Ligos
2010-03-27 15:42 . 1998-10-29 18:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-03-27 15:42 . 2010-03-27 15:42 -------- d-----w- c:\program files\Disney Interactive
2010-03-27 15:07 . 2010-03-27 15:07 -------- d-----w- c:\program files\Essentials Codec Pack
2010-03-27 01:54 . 2010-03-27 01:54 -------- d-----w- c:\program files\Webteh
2010-03-26 15:35 . 2008-04-13 18:45 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2010-03-26 09:23 . 2009-08-13 15:24 512000 -c----w- c:\windows\system32\dllcache\jscript.dll
2010-03-25 21:30 . 2010-03-25 21:30 -------- d-----w- c:\windows\system32\cs-cz
2010-03-25 21:30 . 2010-03-25 21:30 -------- d-----w- c:\windows\l2schemas
2010-03-25 21:30 . 2010-03-25 21:30 -------- d-----w- c:\windows\system32\cs
2010-03-25 21:30 . 2010-03-25 21:30 -------- d-----w- c:\windows\system32\bits
2010-03-25 19:57 . 2010-03-25 21:28 -------- d-----w- c:\windows\ServicePackFiles
2010-03-25 19:55 . 2010-03-25 19:55 -------- d-----w- c:\program files\MSXML 4.0
2010-03-25 10:09 . 2010-03-25 10:09 -------- d-----w- c:\program files\Eidos Interactive
2010-03-25 10:09 . 1996-01-09 09:38 283648 ----a-w- c:\windows\uninst.exe
2010-03-25 10:07 . 2010-03-25 10:07 -------- d-----w- c:\documents and settings\Jirka\WINDOWS
2010-03-24 18:16 . 2010-03-24 18:17 -------- d-----w- c:\program files\QIP
2010-03-24 18:11 . 2010-04-02 21:46 -------- d-----w- C:\Koldas
2010-03-24 17:20 . 2008-04-13 18:45 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2010-03-24 17:20 . 2008-04-13 19:17 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2010-03-24 17:20 . 2008-04-13 18:45 52864 ----a-w- c:\windows\system32\drivers\dmusic.sys
2010-03-24 17:20 . 2008-04-13 18:45 56576 ----a-w- c:\windows\system32\drivers\swmidi.sys
2010-03-24 17:20 . 2008-04-13 16:39 142592 ----a-w- c:\windows\system32\drivers\aec.sys
2010-03-24 17:20 . 2008-04-13 18:45 172416 ----a-w- c:\windows\system32\drivers\kmixer.sys
2010-03-24 17:20 . 2008-04-13 18:45 2944 ----a-w- c:\windows\system32\drivers\drmkaud.sys
2010-03-24 17:20 . 2008-04-13 19:15 60800 ----a-w- c:\windows\system32\drivers\sysaudio.sys
2010-03-24 17:20 . 2008-04-13 18:39 7552 ----a-w- c:\windows\system32\drivers\mskssrv.sys
2010-03-24 17:20 . 2008-04-13 18:39 4992 ----a-w- c:\windows\system32\drivers\mspqm.sys
2010-03-24 17:19 . 2008-04-13 18:39 5376 ----a-w- c:\windows\system32\drivers\mspclock.sys
2010-03-24 17:19 . 2008-04-14 03:21 4096 ----a-w- c:\windows\system32\ksuser.dll
2010-03-24 17:19 . 2008-04-13 19:19 146048 ----a-w- c:\windows\system32\drivers\portcls.sys
2010-03-24 17:19 . 2008-04-13 18:45 60160 ----a-w- c:\windows\system32\drivers\drmk.sys
2010-03-24 17:19 . 2010-03-24 17:19 -------- d-----w- c:\program files\Avance Sound Manager
2010-03-24 17:19 . 2010-03-24 17:19 -------- d-----w- c:\program files\AvRack
2010-03-24 17:19 . 2001-11-07 10:07 584 ------w- c:\windows\system32\drivers\alcxinit.dat
2010-03-24 17:19 . 2001-11-01 00:52 243964 ----a-w- c:\windows\system32\drivers\ALCXWDM.SYS
2010-03-24 17:19 . 2001-06-28 01:21 217088 ------w- c:\windows\alcupd.exe
2010-03-24 17:19 . 2001-06-13 03:49 151552 ------w- c:\windows\alcrmv.exe
2010-03-24 17:19 . 2001-05-29 09:02 124416 ------w- c:\windows\soundman.exe
2010-03-24 17:16 . 2010-03-24 17:16 4261 ----a-w- c:\windows\system32\drivers\rtport.sys
2010-03-24 07:18 . 2010-03-24 07:18 -------- d-----w- c:\program files\Ask.com
2010-03-24 07:18 . 2010-03-24 07:18 -------- d-----w- c:\program files\uTorrent
2010-03-24 07:04 . 2010-03-24 07:04 0 ----a-w- c:\windows\nsreg.dat
2010-03-24 07:03 . 2010-03-24 07:03 -------- d-----w- c:\program files\CentrumczToolbar
2010-03-23 20:32 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-03-23 20:32 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-03-23 20:30 . 2010-03-23 20:30 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2010-03-23 20:29 . 2010-03-23 20:29 -------- d-----w- c:\program files\ArcSoft
2010-03-23 20:29 . 1995-08-01 03:44 212480 ----a-w- c:\windows\PCDLIB32.DLL
2010-03-23 20:28 . 2010-03-23 20:28 -------- d-----w- c:\program files\Common Files\CANON
2010-03-23 20:27 . 2010-04-11 10:02 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-23 20:27 . 2010-04-11 10:02 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-03-23 20:27 . 2003-09-18 13:32 1060864 ----a-w- c:\windows\system32\MFC71.dll
2010-03-23 20:27 . 1998-11-13 11:58 307200 ----a-w- c:\windows\IsUn0405.exe
2010-03-23 20:27 . 2006-03-26 20:00 65024 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP83.DLL

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-08 06:13 . 2001-10-25 14:00 494056 ----a-w- c:\windows\system32\perfh005.dat
2010-04-08 06:13 . 2001-10-25 14:00 102252 ----a-w- c:\windows\system32\perfc005.dat
2010-03-25 21:33 . 2010-03-22 21:30 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-25 21:33 . 2010-03-22 21:30 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-03-24 17:16 . 2010-03-24 17:16 4261 ----a-w- c:\windows\rtport.tmp
2010-03-24 07:47 . 2010-03-22 21:30 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-03-22 21:31 . 2010-03-22 21:31 -------- d-----w- c:\program files\microsoft frontpage
2010-03-22 21:27 . 2010-03-22 21:27 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2010-03-09 11:11 . 2004-08-17 13:49 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-02-26 05:43 . 2004-08-17 13:49 668160 ----a-w- c:\windows\system32\wininet.dll
2010-02-26 05:43 . 2004-08-17 13:49 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-02-24 13:11 . 2004-08-03 21:15 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 12:09 . 2004-08-17 13:45 2192128 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:09 . 2004-08-17 15:45 2068992 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 10:03 . 2001-12-31 22:05 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:35 . 2004-08-17 13:49 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-03 21:07 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-09-02 13:56 1175944 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-03-24 319792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"="Ati2mdxx.exe" [2007-02-02 26112]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 155648]
"SoundMan"="soundman.exe" [2001-05-29 124416]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\update.exe" [2007-04-08 303104]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-11 202256]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 03:22 1695232 ------w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Virgin Interactive\\Original War\\OwarFull.DLL"=

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [30.3.2010 15:42 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [30.3.2010 15:42 5248]
S2 gupdate1cad95dd02c98d0;Služba Google Update (gupdate1cad95dd02c98d0);c:\program files\Google\Update\GoogleUpdate.exe [11.4.2010 12:00 133104]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [11.7.2008 2:28 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [10.7.2008 2:49 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [11.7.2008 2:28 369688]
.
Obsah adresáře 'Naplánované úlohy'

2010-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-04-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-11 10:00]

2010-04-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-11 10:00]

2010-04-21 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1606980848-2111687655-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]

2010-04-21 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1606980848-2111687655-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 20:09]

2010-04-21 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-09-02 13:56]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com?o=15161&l=dis
uDefault_Search_URL = hxxp://search.qip.ru
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: Easy-WebPrint - Náhled - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint - Přidat na seznam k tisku - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint - Tisk - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
IE: Easy-WebPrint - Vysokorychlostní tisk - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\Jirka\Data aplikací\Mozilla\Firefox\Profiles\x3h0vcmj.default\
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\documents and settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-Run-OpwareSE4 - c:\program files\Canon\OpwareSE4.exe
AddRemove-HijackThis - c:\documents and settings\Jirka\Plocha\HijackThis.exe
AddRemove-{1725993d-0199-4a13-a179-07b08459e86a} - c:\program files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-21 19:15
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x82CA53C0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7573f28
\Driver\ACPI -> ACPI.sys @ 0xf74c0cb8
\Driver\atapi -> 0x82ca53c0
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0615
ParseProcedure -> ntoskrnl.exe @ 0x8056c3ac
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0615
ParseProcedure -> ntoskrnl.exe @ 0x8056c3ac
NDIS: VIA PCI 10/100Mb Fast Ethernet Adapter -> SendCompleteHandler -> NDIS.sys @ 0xf7346bb0
PacketIndicateHandler -> NDIS.sys @ 0xf7353a21
SendHandler -> NDIS.sys @ 0xf733187b
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(724)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-04-21 19:17:13
ComboFix-quarantined-files.txt 2010-04-21 17:17

Před spuštěním: Volných bajtů: 90 346 242 048
Po spuštění: Volných bajtů: 90 871 472 128

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 69125A8408E63657A25620B2622B2024

Re: Zavirovaná stranka

Napsal: 21 dub 2010 18:23
od Caroprd111
Obrázek Odinstalujte všechny emulátory virtuálních mechanik.

Obrázek Stáhněte SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte verzi podle svého operačního systému (64 & 32b). Uložte na plochu a spusťte.
  • zvolte možnost Uninstall a restartujte PC.

Obrázek Stáhněte a spusťte http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Klikněte na "Disable" a restartujte PC.

Obrázek Stáhněte MBR na plochu http://www2.gmer.net/mbr/mbr.exe

Obrázek Start > Spustit (Win + R)
  • Vyskočí okénko, zkopírujte do něj:

Kód: Vybrat vše

"%userprofile%\plocha\mbr" -t
  • Klikněte na OK
  • Vytvoří se log s názvem mbr.log, vložte ho sem.


Obrázek Dejte log z Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878

Re: Zavirovaná stranka

Napsal: 21 dub 2010 18:39
od Koldas
U programku SPTD mam v nabidce install, uninstal a samozdrejme cancel, ale na uninstal nejde kliknout.. a pise to: No SPTD version was detected. Select action to be performed. Nemam dat instalovat?

Re: Zavirovaná stranka

Napsal: 21 dub 2010 18:40
od Caroprd111
SPTD vynechte a pokračujte dalšími kroky.

Re: Zavirovaná stranka

Napsal: 21 dub 2010 19:45
od Koldas
MBR:
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys viaide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK

Log 1 (kratsi):
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-04-21 19:48:12
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Jirka\LOCALS~1\Temp\pxtdypod.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

Log 2 (delsi):
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-21 20:43:44
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Jirka\LOCALS~1\Temp\pxtdypod.sys


---- Kernel code sections - GMER 1.0.15 ----

? C:\DOCUME~1\Jirka\LOCALS~1\Temp\mbr.sys Systém nemůže nalézt uvedený soubor. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Mozilla Firefox\firefox.exe[304] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

Re: Zavirovaná stranka

Napsal: 21 dub 2010 19:47
od Caroprd111
Ok, ještě druhý log z Gmer.