Je tento výsledek OK? Ten svinec je po restartu stále mezi procesy.
OTL logfile created on: 11.5.2010 15:49:26 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = c:\_DOC\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
495,00 Mb Total Physical Memory | 183,00 Mb Available Physical Memory | 37,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): S:\pagefile.sys 1280 2048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 7,84 Gb Total Space | 4,01 Gb Free Space | 51,14% Space Free | Partition Type: NTFS
Drive D: | 355,65 Gb Total Space | 5,49 Gb Free Space | 1,54% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive M: | 7,81 Gb Total Space | 0,44 Gb Free Space | 5,65% Space Free | Partition Type: NTFS
Drive S: | 2,01 Gb Total Space | 0,75 Gb Free Space | 37,33% Space Free | Partition Type: NTFS
Drive T: | 4,88 Gb Total Space | 4,82 Gb Free Space | 98,70% Space Free | Partition Type: NTFS
Drive X: | 14,94 Gb Total Space | 2,11 Gb Free Space | 14,12% Space Free | Partition Type: NTFS
Drive Z: | 465,76 Gb Total Space | 0,86 Gb Free Space | 0,18% Space Free | Partition Type: NTFS
Computer Name: C2D
Current User Name: Thales
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.05.11 15:49:06 | 000,117,760 | ---- | M] () -- C:\Profiles\Thales\Local Settings\Temp\gtk6B.tmp
PRC - [2010.05.11 15:48:20 | 000,570,880 | ---- | M] (OldTimer Tools) -- c:\_DOC\Downloads\OTL.exe
PRC - [2010.04.26 19:13:25 | 000,531,440 | ---- | M] (Google Inc.) -- C:\Profiles\Thales\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
PRC - [2008.11.19 02:12:53 | 000,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\bin\jqs.exe
PRC - [2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006.10.23 07:55:02 | 000,851,664 | ---- | M] (C. Ghisler & Co.) -- C:\Program Files\TotalCommander\TOTALCMD.EXE
PRC - [2005.12.14 19:06:00 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe
PRC - [2005.05.11 04:09:54 | 000,225,280 | ---- | M] (O&O Software GmbH) -- C:\WINDOWS\system32\oodag.exe
========== Modules (SafeList) ==========
MOD - [2010.05.11 15:48:20 | 000,570,880 | ---- | M] (OldTimer Tools) -- c:\_DOC\Downloads\OTL.exe
MOD - [2008.04.14 07:49:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2010.05.10 14:18:32 | 000,048,128 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\mssrv32.exe -- (msupdate)
SRV - [2008.11.19 02:12:53 | 000,152,984 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2005.05.11 04:09:54 | 000,225,280 | ---- | M] (O&O Software GmbH) [Auto | Running] -- C:\WINDOWS\system32\oodag.exe -- (O&O Defrag)
========== Driver Services (SafeList) ==========
DRV - [2010.05.11 11:55:51 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF) WinPcap Packet Driver (NPF)
DRV - [2010.05.09 01:07:48 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2008.11.19 19:39:33 | 000,639,224 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2006.09.24 15:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2005.12.16 14:50:00 | 003,842,560 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005.02.11 18:55:32 | 000,061,440 | ---- | M] (Kerio Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\kvpndrv.sys -- (kvpndev)
DRV - [2004.05.05 22:48:40 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2002.05.06 12:01:14 | 000,016,512 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
DRV - [1996.04.03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchURL\g, =
http://www.google.com/search?q=%s
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchURL\g, =
http://www.google.com/search?q=%s
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchURL\g, =
http://www.google.com/search?q=%s
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchURL\g, =
http://www.google.com/search?q=%s
IE - HKU\S-1-5-21-1214440339-1935655697-1417001333-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-1214440339-1935655697-1417001333-500\Software\Microsoft\Internet Explorer\SearchURL\g, =
http://www.google.com/search?q=%s
IE - HKU\S-1-5-21-1214440339-1935655697-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\
jqs@sun.com: C:\Program Files\Java\lib\deploy\jqs\ff [2008.11.19 02:12:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Plugins: C:\Program Files\K-Meleon\Plugins [2010.03.04 18:55:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\K-Meleon\Extensions\\Components: C:\Program Files\K-Meleon\Components [2010.03.20 20:51:26 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2010.05.09 00:54:32 | 000,393,065 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1
http://www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1
http://www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1
http://www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1
http://www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
http://www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1
http://www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1
http://www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1
http://www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1
http://www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1
http://www.10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1
http://www.1-2005-search.com
O1 - Hosts: 13576 more lines...
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe Acrobat Reader\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [MsXSLT] C:\WINDOWS\system32\msxslt3.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-21-1214440339-1935655697-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1214440339-1935655697-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O9 - Extra Button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe (ICQ Inc.)
O9 - Extra 'Tools' menuitem : ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe (ICQ Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/windows ... 4222579453 (WUWebControl Class)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\msupdt.exe) - C:\WINDOWS\system32\msupdt.exe ()
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\wzrd_1: DllName - wzrd_1.dll - C:\WINDOWS\System32\wzrd_1.dll ()
O21 - SSODL: GootkitSSO - {FA805C68-F6BD-4C85-A677-218F56E8EBFE} - C:\WINDOWS\system32\msxsltsso.dll ()
O21 - SSODL: LGootkitSSO - {A1BB9624-4730-4BDF-B9E3-DE39806EDBEA} - C:\WINDOWS\system32\lmsxsltsso.dll ()
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Profiles\Thales\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Profiles\Thales\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O Software GmbH)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009.05.16 22:06:57 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: plzwls - C:\WINDOWS\system32\uyfqavbj.dll ()
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\WINDOWS\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS
http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\WINDOWS\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (
http://www.helixcommunity.org)
Unable to start service SrService!
========== Files/Folders - Created Within 30 Days ==========
[2010.05.11 15:05:08 | 000,000,000 | ---D | C] -- C:\rsit
[2010.05.11 15:01:07 | 000,000,000 | RH-D | C] -- C:\Profiles\Thales\Recent
[2010.05.11 14:39:58 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.05.11 13:46:53 | 000,000,000 | ---D | C] -- C:\Profiles\Thales\Local Settings\Data aplikací\Downloaded Installations
[2010.05.11 13:40:41 | 000,000,000 | ---D | C] -- C:\_DOC\Downloads
[2010.05.11 13:38:17 | 000,000,000 | ---D | C] -- C:\Profiles\Thales\Local Settings\Data aplikací\Temp
[2010.05.11 13:38:14 | 000,000,000 | ---D | C] -- C:\Profiles\Thales\Local Settings\Data aplikací\Google
[2010.05.11 11:55:51 | 000,281,104 | ---- | C] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\wpcap.dll
[2010.05.11 11:55:51 | 000,100,880 | ---- | C] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\Packet.dll
[2010.05.11 11:55:51 | 000,050,704 | ---- | C] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\drivers\npf.sys
[2010.05.09 18:47:35 | 000,000,000 | ---D | C] -- C:\Profiles\Thales\Data aplikací\K-Meleon
[2010.05.09 00:59:08 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
========== Files - Modified Within 30 Days ==========
[2010.05.11 15:43:00 | 000,001,002 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1935655697-1417001333-500UA.job
[2010.05.11 15:42:56 | 000,004,063 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.05.11 15:03:10 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.05.11 15:03:09 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.05.11 15:03:08 | 000,036,375 | ---- | M] () -- C:\WINDOWS\System32\OODBS.lor
[2010.05.11 15:02:38 | 000,000,178 | -HS- | M] () -- C:\Profiles\Thales\ntuser.ini
[2010.05.11 15:02:37 | 006,553,600 | -H-- | M] () -- C:\Profiles\Thales\NTUSER.DAT
[2010.05.11 15:02:36 | 003,712,656 | -H-- | M] () -- C:\Profiles\Thales\Local Settings\Data aplikací\IconCache.db
[2010.05.11 14:28:41 | 000,781,909 | ---- | M] () -- C:\Profiles\Thales\Plocha\RSIT.exe
[2010.05.11 13:43:00 | 000,000,950 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1935655697-1417001333-500Core.job
[2010.05.11 13:39:06 | 000,002,174 | ---- | M] () -- C:\Profiles\Thales\Plocha\Google Chrome.lnk
[2010.05.11 11:55:51 | 000,281,104 | ---- | M] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\wpcap.dll
[2010.05.11 11:55:51 | 000,100,880 | ---- | M] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\Packet.dll
[2010.05.11 11:55:51 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) -- C:\WINDOWS\System32\drivers\npf.sys
[2010.05.11 11:43:55 | 000,000,052 | ---- | M] () -- C:\WINDOWS\System32\msxslt.dat
[2010.05.10 14:18:32 | 000,048,128 | ---- | M] () -- C:\WINDOWS\System32\mssrv32.exe
[2010.05.09 01:07:48 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\gdrv.sys
[2010.05.09 01:07:43 | 000,005,632 | ---- | M] () -- C:\WINDOWS\System32\wzrd_1.dll
[2010.05.09 00:54:32 | 000,393,065 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.05.09 00:49:58 | 000,041,472 | ---- | M] () -- C:\WINDOWS\System32\msxsltsso.dll
[2010.05.09 00:49:57 | 000,006,144 | ---- | M] () -- C:\WINDOWS\System32\lmsxsltsso.dll
[2010.05.09 00:42:22 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.05.08 12:35:47 | 000,001,455 | ---- | M] () -- C:\WINDOWS\wcx_ftp.ini
[2010.05.08 11:36:33 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.04.12 13:19:51 | 000,000,558 | ---- | M] () -- C:\WINDOWS\win.ini
========== Files Created - No Company Name ==========
[2010.05.11 14:40:18 | 000,781,909 | ---- | C] () -- C:\Profiles\Thales\Plocha\RSIT.exe
[2010.05.11 13:39:06 | 000,002,174 | ---- | C] () -- C:\Profiles\Thales\Plocha\Google Chrome.lnk
[2010.05.11 13:38:16 | 000,001,002 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1935655697-1417001333-500UA.job
[2010.05.11 13:38:15 | 000,000,950 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1214440339-1935655697-1417001333-500Core.job
[2010.05.10 14:18:33 | 000,048,128 | ---- | C] () -- C:\WINDOWS\System32\mssrv32.exe
[2010.05.09 01:07:43 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\wzrd_1.dll
[2010.05.09 00:49:58 | 000,041,472 | ---- | C] () -- C:\WINDOWS\System32\msxsltsso.dll
[2010.05.09 00:49:58 | 000,000,052 | ---- | C] () -- C:\WINDOWS\System32\msxslt.dat
[2010.05.09 00:49:57 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\lmsxsltsso.dll
[2010.01.23 07:41:18 | 000,000,093 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2010.01.20 09:39:19 | 000,000,121 | ---- | C] () -- C:\WINDOWS\Winchat.ini
[2009.05.27 21:28:44 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009.05.11 22:15:00 | 000,001,455 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.12.04 01:06:43 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008.12.04 01:06:42 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2008.12.04 01:06:41 | 002,283,027 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2008.12.04 01:06:40 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008.12.04 01:06:40 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008.12.04 01:06:40 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008.12.04 01:06:38 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008.12.04 01:06:38 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008.11.20 23:12:16 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.11.19 19:39:33 | 000,639,224 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008.11.19 03:18:25 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008.11.19 01:45:26 | 000,004,063 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2008.04.14 07:51:46 | 000,213,974 | RHS- | C] () -- C:\WINDOWS\System32\uyfqavbj.dll
[1996.04.03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2009.03.30 22:00:21 | 000,000,000 | ---D | M] -- C:\Profiles\All Users\Data aplikací\BVRP Software
[2009.08.13 22:18:05 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Foxit
[2009.11.27 20:19:06 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Foxit Software
[2009.04.14 21:32:28 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\ICQ
[2010.05.09 18:47:35 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\K-Meleon
[2009.03.31 00:11:22 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Kerio
[2008.11.19 02:22:44 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\OpenOffice.org
[2008.11.19 02:14:45 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Opera
[2009.12.31 05:38:34 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Thinstall
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Google Update" = "C:\Profiles\Thales\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c -- [2010.05.11 13:38:14 | 000,136,176 | ---- | M] (Google Inc.)
< c:\windows\*.* /U >
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2009.03.30 23:00:28 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Adobe
[2008.11.20 23:12:31 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Ahead
[2009.08.13 22:18:05 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Foxit
[2009.11.27 20:19:06 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Foxit Software
[2009.10.02 03:07:15 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Help
[2009.04.14 21:32:28 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\ICQ
[2008.11.19 01:47:55 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Identities
[2010.05.09 18:47:35 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\K-Meleon
[2009.03.31 00:11:22 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Kerio
[2009.03.30 23:00:28 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Macromedia
[2008.12.04 05:25:03 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Media Player Classic
[2009.09.21 01:51:12 | 000,000,000 | --SD | M] -- C:\Profiles\Thales\Data aplikací\Microsoft
[2008.11.19 02:22:44 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\OpenOffice.org
[2008.11.19 02:14:45 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Opera
[2009.06.25 02:45:25 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Real
[2008.11.19 02:12:30 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Sun
[2009.12.31 05:38:34 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\Thinstall
[2008.11.19 02:17:29 | 000,000,000 | ---D | M] -- C:\Profiles\Thales\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
< MD5 for: AGP440.SYS >
[2008.11.06 01:03:48 | 017,813,288 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: AHCIX86.SYS >
[2008.11.06 00:57:25 | 000,176,136 | ---- | M] (AMD Technologies Inc.) MD5=B6E729A575F84938A08D367E8352EB86 -- C:\WINDOWS\NLDRV\003\ahcix86.sys
< MD5 for: ATAPI.SYS >
[2008.11.06 01:03:48 | 017,813,288 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
< MD5 for: CDROM.SYS >
[2008.11.06 01:03:48 | 017,813,288 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.05.02 12:49:39 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\Driver Cache\i386\cdrom.sys
[2008.05.02 12:49:39 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\system32\dllcache\cdrom.sys
[2008.05.02 11:49:39 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2008.04.14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
< MD5 for: HAL.DLL >
[2008.11.06 01:03:48 | 017,813,288 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.13 23:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2008.11.06 01:03:48 | 017,813,288 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
< MD5 for: IASTOR.SYS >
[2008.11.06 00:57:35 | 000,305,176 | ---- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 -- C:\WINDOWS\NLDRV\005\iastor.sys
[2008.11.06 00:57:26 | 000,327,192 | ---- | M] (Intel Corporation) MD5=8EF427C54497C5F8A7A645990E4278C7 -- C:\WINDOWS\NLDRV\004\iastor.sys
< MD5 for: ISAPNP.SYS >
[2008.11.06 01:03:48 | 017,813,288 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\isapnp.sys
< MD5 for: LSASS.EXE >
[2008.04.14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.11.06 00:56:40 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=B5B1080D35974C0E718D64280761BCD5 -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.11.06 00:56:03 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=B3D65E8F4D9EC988FA17060F21AC445B -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NVGTS.SYS >
[2008.11.06 00:57:47 | 000,102,400 | ---- | M] (NVIDIA Corporation) MD5=1F790624AB1619CAE0C78597BD33615B -- C:\WINDOWS\NLDRV\008\nvgts.sys
[2008.11.06 00:57:48 | 000,102,400 | ---- | M] (NVIDIA Corporation) MD5=1F790624AB1619CAE0C78597BD33615B -- C:\WINDOWS\NLDRV\009\nvgts.sys
[2008.11.06 00:57:44 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=37954CD1D0AFC11BECD149F7C3EC88C2 -- C:\WINDOWS\NLDRV\007\nvgts.sys
[2008.11.06 00:57:42 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E -- C:\WINDOWS\NLDRV\006\nvgts.sys
< MD5 for: NVRD32.SYS >
[2008.11.06 00:57:48 | 000,128,000 | ---- | M] (NVIDIA Corporation) MD5=3802044AD8385654C620488DA8C9F0D9 -- C:\WINDOWS\NLDRV\009\nvrd32.sys
[2008.11.06 00:57:46 | 000,133,152 | ---- | M] (NVIDIA Corporation) MD5=BEF704AA9E17D176A46DDF77C6A52194 -- C:\WINDOWS\NLDRV\007\nvrd32.sys
< MD5 for: SCECLI.DLL >
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2008.04.14 07:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.11.06 00:57:15 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=E88631E21A9CACA06104802F9E915115 -- C:\WINDOWS\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: VIAMRAID.SYS >
[2008.11.06 00:58:00 | 000,117,248 | ---- | M] (VIA Technologies inc,.ltd) MD5=00046AA2E396EDC2238556E740A8E5AF -- C:\WINDOWS\NLDRV\024\viamraid.sys
< MD5 for: WINLOGON.EXE >
[2008.04.14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009.03.21 16:09:02 | 000,213,974 | RHS- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\uyfqavbj.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2008.11.19 19:39:33 | 000,639,224 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2008.11.19 02:03:41 | 000,102,400 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2008.11.19 02:03:41 | 001,093,632 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2008.11.19 02:03:41 | 000,471,040 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[2009.03.21 16:09:02 | 000,213,974 | RHS- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\uyfqavbj.dll
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< %systemroot%\system32\drivers\*.sys /3 >
[2010.05.11 11:55:51 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) -- C:\WINDOWS\system32\drivers\npf.sys
< %systemroot%\system32\*.* /3 >
[2010.05.09 00:49:57 | 000,006,144 | ---- | M] () -- C:\WINDOWS\system32\lmsxsltsso.dll
[2010.05.10 14:18:32 | 000,048,128 | ---- | M] () -- C:\WINDOWS\system32\mssrv32.exe
[2010.05.11 11:43:55 | 000,000,052 | ---- | M] () -- C:\WINDOWS\system32\msxslt.dat
[2010.05.09 00:49:58 | 000,041,472 | ---- | M] () -- C:\WINDOWS\system32\msxsltsso.dll
[2010.05.11 15:03:08 | 000,036,375 | ---- | M] () -- C:\WINDOWS\system32\OODBS.lor
[2010.05.11 11:55:51 | 000,100,880 | ---- | M] (CACE Technologies, Inc.) -- C:\WINDOWS\system32\Packet.dll
[2010.05.11 15:49:46 | 000,188,280 | ---- | M] () -- C:\WINDOWS\system32\sblog.txt
[2010.05.09 00:42:22 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2010.05.11 11:55:51 | 000,281,104 | ---- | M] (CACE Technologies, Inc.) -- C:\WINDOWS\system32\wpcap.dll
[2010.05.09 01:07:43 | 000,005,632 | ---- | M] () -- C:\WINDOWS\system32\wzrd_1.dll
< End of report >
------------------------
OTL Extras logfile created on: 11.5.2010 15:49:26 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = c:\_DOC\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
495,00 Mb Total Physical Memory | 183,00 Mb Available Physical Memory | 37,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): S:\pagefile.sys 1280 2048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 7,84 Gb Total Space | 4,01 Gb Free Space | 51,14% Space Free | Partition Type: NTFS
Drive D: | 355,65 Gb Total Space | 5,49 Gb Free Space | 1,54% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive M: | 7,81 Gb Total Space | 0,44 Gb Free Space | 5,65% Space Free | Partition Type: NTFS
Drive S: | 2,01 Gb Total Space | 0,75 Gb Free Space | 37,33% Space Free | Partition Type: NTFS
Drive T: | 4,88 Gb Total Space | 4,82 Gb Free Space | 98,70% Space Free | Partition Type: NTFS
Drive X: | 14,94 Gb Total Space | 2,11 Gb Free Space | 14,12% Space Free | Partition Type: NTFS
Drive Z: | 465,76 Gb Total Space | 0,86 Gb Free Space | 0,18% Space Free | Partition Type: NTFS
Computer Name: C2D
Current User Name: Thales
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)
.ini [@ = GetDiz.Document] -- C:\Program Files\GetDiz\GetDiz.exe (Outer Technologies -
http://outertech.com)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Opera\Opera.exe" (Opera Software)
https [open] -- "C:\Program Files\Opera\Opera.exe" (Opera Software)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /k "cd %L" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallDisableNotify" = 1
"FirewallOverride" = 0
"UpdatesDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"4665:TCP" = 4665:TCP:*:Enabled:xbmwf
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\ICQ6\ICQ.exe" = C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6 -- File not found
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)
"C:\WINDOWS\TEMP\tmp7778.tmp" = C:\WINDOWS\TEMP\tmp7778.tmp:*:Enabled:tmp7778 -- File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{21DBBDD6-93A5-4326-9A04-C9A5C9148502}" = Norton PartitionMagic
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java(TM) 6 Update 10
"{293C9DF5-7669-4826-BBB2-E1F182D71029}" = Nero 7 Ultra Edition
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3D699C53-96C8-42E0-9767-B2D352F7A837}_is1" = Sundaze (theme)
"{53480370-6CA2-47EC-BC05-02B4B9271C31}" = O&O Defrag Professional Edition
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{6855CCDD-BDF9-48E4-B80A-80DFB96FE36C}" = CmdHere Powertoy For Windows XP
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7A4CFCAC-68DC-4A56-AFCB-DA236E8B363F}_is1" = Angel Writer 3.2
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Extreme Graphics 2 Driver
"{90840405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Excel Viewer 2003
"{90850405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{90AF0405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{AC76BA86-7AD7-1029-7B44-A93000000001}" = Adobe Reader 9.3.2 - Czech
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS Ver.2.03
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BBBF4CFE-9D26-4D93-A869-B2B021B3CA85}" = Intel(R) PRO Network Connections 12.2.41.0
"{BE8BE32F-F595-4693-9F82-1E0A5A047BB6}" = OpenOffice.org 3.0
"{E20C5E13-DE01-4938-A776-E7563FDA86B4}" = RAMBooster.Net
"{F18E8A0F-BE99-4305-96A5-6C0FD9D7D999}" = mobile PhoneTools
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FB8148DD-C575-4B0A-9F6C-0CFC46937930}" = Opera 10.10
"7-Zip" = 7-Zip 4.65
"ACDSee" = ACDSee
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"ArtaSoftware_is1" = Arta Software version 1.4.1
"ASIO4ALL" = ASIO4ALL
"CCleaner" = CCleaner (remove only)
"DameK UltraBluever. 1.5" = DameK UltraBlue
"Foxit Reader" = Foxit Reader
"GetDiz 3.0" = GetDiz 3.0
"HD Tach 2.61" = HD Tach 2.61
"HijackThis" = HijackThis 2.0.2
"ICQ" = ICQ
"InstallShield_{21DBBDD6-93A5-4326-9A04-C9A5C9148502}" = Norton PartitionMagic 8.0
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.3.4
"K-Meleon" = K-Meleon 1.5.4 en-US (remove only)
"Longhorn Theme 4" = Longhorn Theme 4
"MetallicShades" = Metallic Shades 2.0 Visual Style
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"R-Studio 4.5NSIS" = R-Studio 4.5
"SpeedFan" = SpeedFan (remove only)
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinISO_is1" = WinISO 5.3
"WinRAR archiver" = WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XBOX" = XBOX
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1214440339-1935655697-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8.2.2010 22:10:20 | Computer Name = C2D | Source = PerfNet | ID = 2005
Description = Nelze číst data o výkonu ze služby serveru. V tomto vzorku nebudou
vrácena žádná data o výkonu serveru. Vrácený chybový kód je v datech DWORD 0, IOSB.Status
je DWORD 1 a IOSB.Information je DWORD 2.
Error - 8.2.2010 22:10:20 | Computer Name = C2D | Source = PerfNet | ID = 2006
Description = Nelze číst data o výkonu fronty ze služby serveru. V tomto vzorku nebudou
vrácena žádná data o výkonu fronty serveru. Vrácený chybový kód je v datech DWORD
0, IOSB.Status je DWORD 1 a IOSB.Information je DWORD 2.
Error - 8.5.2010 19:07:31 | Computer Name = C2D | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 9.5.2010 11:48:08 | Computer Name = C2D | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 10.5.2010 10:43:33 | Computer Name = C2D | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 11.5.2010 7:14:43 | Computer Name = C2D | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 11.5.2010 8:32:25 | Computer Name = C2D | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 11.5.2010 8:41:31 | Computer Name = C2D | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 11.5.2010 8:48:38 | Computer Name = C2D | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 11.5.2010 9:03:16 | Computer Name = C2D | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
[ System Events ]
Error - 16.5.2009 16:04:39 | Computer Name = C2D | Source = Service Control Manager | ID = 7001
Description = Služba Prohledávání počítačů závisí na službě Server, která neuspěla
při spuštění v důsledku následující chyby: %%5
Error - 16.5.2009 16:04:39 | Computer Name = C2D | Source = Service Control Manager | ID = 7023
Description = Služba Server byla ukončena s následující chybou: %%5
Error - 16.5.2009 16:05:03 | Computer Name = C2D | Source = Service Control Manager | ID = 7023
Description = Služba Server byla ukončena s následující chybou: %%5
Error - 16.5.2009 16:16:44 | Computer Name = C2D | Source = NETLOGON | ID = 3095
Description = Tento počítač je nakonfigurován jako člen pracovní skupiny, nikoliv
jako člen domény. Přihlašovací služba Netlogon nepotřebuje být spuštěna v této konfiguraci.
Error - 16.5.2009 16:30:40 | Computer Name = C2D | Source = W32Time | ID = 39452689
Description = Klient NTP zprostředkovatele časových údajů: Při vyhledávání DNS ručně
nakonfigurovaného partnera time.windows.com,0x1 došlo k chybě. Klient NTP se pokusí
o vyhledání pomocí služby DNS znovu za 15 minut. Chyba: Došlo k pokusu o operaci
se soketem v okamžiku nedosažitelnosti hostitele. (0x80072751)
Error - 16.5.2009 16:30:40 | Computer Name = C2D | Source = W32Time | ID = 39452701
Description = Klient NTP zprostředkovatele časových údajů je konfigurován pro získávání
časových údajů z jednoho nebo více zdrojů času. Žádný z těchto zdrojů však není
aktuálně k dispozici. Po dobu 14 minut nebude proveden žádný pokus o kontaktování
zdroje. Klient NTP nemá k dispozici žádný zdroj času.
Error - 16.5.2009 16:30:44 | Computer Name = C2D | Source = W32Time | ID = 39452689
Description = Klient NTP zprostředkovatele časových údajů: Při vyhledávání DNS ručně
nakonfigurovaného partnera time.windows.com,0x1 došlo k chybě. Klient NTP se pokusí
o vyhledání pomocí služby DNS znovu za 15 minut. Chyba: Došlo k pokusu o operaci
se soketem v okamžiku nedosažitelnosti hostitele. (0x80072751)
Error - 16.5.2009 16:30:44 | Computer Name = C2D | Source = W32Time | ID = 39452701
Description = Klient NTP zprostředkovatele časových údajů je konfigurován pro získávání
časových údajů z jednoho nebo více zdrojů času. Žádný z těchto zdrojů však není
aktuálně k dispozici. Po dobu 15 minut nebude proveden žádný pokus o kontaktování
zdroje. Klient NTP nemá k dispozici žádný zdroj času.
Error - 16.5.2009 16:33:41 | Computer Name = C2D | Source = W32Time | ID = 39452689
Description = Klient NTP zprostředkovatele časových údajů: Při vyhledávání DNS ručně
nakonfigurovaného partnera time.windows.com,0x1 došlo k chybě. Klient NTP se pokusí
o vyhledání pomocí služby DNS znovu za 15 minut. Chyba: Došlo k pokusu o operaci
se soketem v okamžiku nedosažitelnosti hostitele. (0x80072751)
Error - 16.5.2009 16:33:41 | Computer Name = C2D | Source = W32Time | ID = 39452701
Description = Klient NTP zprostředkovatele časových údajů je konfigurován pro získávání
časových údajů z jednoho nebo více zdrojů času. Žádný z těchto zdrojů však není
aktuálně k dispozici. Po dobu 15 minut nebude proveden žádný pokus o kontaktování
zdroje. Klient NTP nemá k dispozici žádný zdroj času.
< End of report >