Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Zavirované PC, spousta trojanů

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Danstein
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 09 led 2006 16:31

Zavirované PC, spousta trojanů

#1 Příspěvek od Danstein »

Známý mi přinesl svoje PC, u kterého docházelo několik minut po zapnutí ke spuštění vypínacího procesu. Po spuštění měl řadu nesmyslů (desítky, možná stovky), které odkazovaly na neexistující soubory v Tempu. Na net chodil přes IE, antivirem se neobtěžoval. :arcisit: Když problémy začaly, syn mu nainstaloval McAfee on line scanner, který toho moc nenašel (a PC se vždy stačilo vypnout). Já jsem vymazal tempy, něco muselo být mimo prostředí OS, odinstaloval McAfee, nainstaloval AVG Free, které našlo přes 250 trojanů :roll:. To jsem musel spustit v nouzovém režimu Windows (kvůli vypínání PC ve standardním režimu). Po kontrole ještě Spybot našel nějakých 15 kousků, včetně nějakých věcí zasahujících do IE a aktualizací. Teď už se PC nevypíná, ale zbytky bordelu v OS beztak budou.

Log zde:

Logfile of random's system information tool 1.08 (written by random/random)
Run by taťka at 2010-12-03 08:08:40
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 37 GB (32%) free of 114 GB
Total RAM: 1535 MB (25% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:10:00, on 3.12.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17091)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\oracle\product\10.2.0\db_4\bin\isqlplussvc.exe
C:\oracle\product\10.2.0\db_4\jdk\bin\java.exe
c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE
c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE
c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\totalcmd_7.55a\TOTALCMD.EXE
c:\0Instal\RSIT.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\a49d784415582d2f98c84ceb0a75d898\update\update.exe
C:\Program Files\trend micro\taťka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\1003211037\ICQToolBar.dll
O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll (file missing)
O3 - Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - (no file)
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NVIDIA driver monitor] C:\WINDOWS\nvsvc32.exe
O4 - HKLM\..\Run: [Windows Firewall] C:\DOCUME~1\TAKA~1\LOCALS~1\Temp\lsass.exe
O4 - HKLM\..\Run: [MFARestart] "C:\Documents and Settings\All Users\Data aplikací\MFAData\pack\avgrunasx.exe" /usereg
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIDIA driver monitor] C:\WINDOWS\nvsvc32.exe
O4 - HKCU\..\Run: [Windows Firewall] C:\DOCUME~1\TAKA~1\LOCALS~1\Temp\lsass.exe
O4 - HKCU\..\Run: [userini] C:\WINDOWS\explorer.exe:userini.exe
O4 - HKLM\..\Policies\Explorer\Run: [userini] C:\WINDOWS\system32\userini.exe
O4 - HKCU\..\Policies\Explorer\Run: [userini] C:\WINDOWS\explorer.exe:userini.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game01.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OracleDBConsolejirka - Oracle Corporation - C:\oracle\product\10.2.0\db_4\bin\nmesrvc.exe
O23 - Service: OracleOraDb10g_home1iSQL*Plus - Oracle - C:\oracle\product\10.2.0\db_4\bin\isqlplussvc.exe
O23 - Service: OracleOraDb10g_home1TNSListener - Unknown owner - C:\oracle\product\10.2.0\db_4\BIN\TNSLSNR.exe
O23 - Service: OracleServiceJIRKA - Oracle Corporation - c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE
O23 - Service: OracleServiceSKTENIS - Oracle Corporation - c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE
O23 - Service: OracleServiceTENIS - Oracle Corporation - c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
O23 - Service: Ati HotKey Poller (oubaiisj6i2au) - Unknown owner - C:\Documents and Settings\taťka\Data aplikací\Microsoft\fofu.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 12388 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2007-09-13 1312040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG10\avgssie.dll [2010-11-04 2731360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-29 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll [2010-10-25 2475336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-11-23 297648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-11-23 843832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\1003211037\ICQToolBar.dll [2010-01-03 1019128]
{ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - Alcohol Toolbar - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll []
{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}
{D4027C7F-154A-4066-A1AD-4243D8127440}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-11-23 297648]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll [2010-10-25 2475336]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-29 266240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-08-11 7630848]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-08-11 86016]
"EPSON Stylus Photo R300 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE [2003-05-27 99840]
"WINDVDPatch"=C:\WINDOWS\system32\CTHELPER.EXE [2002-07-02 24576]
"CTStartup"=C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE [2001-12-20 28672]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"NVIDIA driver monitor"=C:\WINDOWS\nvsvc32.exe []
"Windows Firewall"=C:\DOCUME~1\TAKA~1\LOCALS~1\Temp\lsass.exe []
"MFARestart"=C:\Documents and Settings\All Users\Data aplikací\MFAData\pack\avgrunasx.exe /usereg []
"AVG_TRAY"=C:\Program Files\AVG\AVG10\avgtray.exe [2010-10-22 2745696]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"userini"=C:\WINDOWS\system32\userini.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"NVIDIA driver monitor"=C:\WINDOWS\nvsvc32.exe []
"Windows Firewall"=C:\DOCUME~1\TAKA~1\LOCALS~1\Temp\lsass.exe []
"userini"=C:\WINDOWS\explorer.exe [2010-12-03 1034240]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"userini"=C:\WINDOWS\explorer.exe [2010-12-03 1034240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Detector]
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE [2002-12-09 208896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
C:\Program Files\D-Tools\daemon.exe [2004-03-12 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe [2001-11-29 28672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
C:\Documents and Settings\taťka\uuywov.exe \u []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe [2007-03-23 227328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rewolaj]
C:\Documents and Settings\taťka\Data aplikací\Microsoft\tyrinika.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SessionInit]
C:\Documents and Settings\taťka\init.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-02-04 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\userini]
C:\WINDOWS\system32\userini.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Rychlé spuštění aplikace HP Image Zone.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [2005-05-12 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0hdyy6k.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\0hdyy6k.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0rnii6u.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\0rnii6u.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0yytkkf.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\0yytkkf.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0zvqq6c.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\0zvqq6c.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0zzqvb0.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\0zzqvb0.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1cyytpv.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1cyytpv.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1ieezqq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1ieezqq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1mh0dtz.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1mh0dtz.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1qmmhyy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1qmmhyy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1up0llc.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1up0llc.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1wssnee.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1wssnee.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^275yt0p.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\275yt0p.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2jee6qq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\2jee6qq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2nii6uu.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\2nii6uu.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2pkk6ww.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\2pkk6ww.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2rmm6yy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\2rmm6yy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2zuu6gg.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\2zuu6gg.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3ggbssn.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\3ggbssn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3uuaa3m.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\3uuaa3m.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3uupggb.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\3uupggb.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^69g1cyy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\69g1cyy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^6gg6ss6.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\6gg6ss6.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^9a1wssn.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\9a1wssn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^9k1lccx.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\9k1lccx.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^a1wssneezq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\a1wssneezq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^a6mm6yy6.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\a6mm6yy6.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^aa6rss1te6v.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\aa6rss1te6v.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^aavmmhyy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\aavmmhyy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^avmmhyyt.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\avmmhyyt.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^b0hdyy6kk.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\b0hdyy6kk.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bm6x6jzk.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\bm6x6jzk.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bssneezq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\bssneezq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\bssneezqqlc.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bxnnjzzvll.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\bxnnjzzvll.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^d0jfaa6mm.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\d0jfaa6mm.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ddzpplbbxnn.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\ddzpplbbxnn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ddzpplbh.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\ddzpplbh.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^di86u81gr.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\di86u81gr.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\dzpplbbxnn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^e1awwrii.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\e1awwrii.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^eaavmmhyyt.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\eaavmmhyyt.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^faa6mm6yy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\faa6mm6yy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^g1cyytkk.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\g1cyytkk.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^g1cyytkkfw.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\g1cyytkkfw.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^gbssneezqq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\gbssneezqq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ggbssneezq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\ggbssneezq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^h0njee6qq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\h0njee6qq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^hdttpffb.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\hdttpffb.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^hyytkkfwwri.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\hyytkkfwwri.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^i1eaavmmhy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\i1eaavmmhy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jaavbxss6ee.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\jaavbxss6ee.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jzzva6rs.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\jzzva6rs.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jzzvllhm.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\jzzvllhm.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^kfwwriiduu.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\kfwwriiduu.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^kggbssneez.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\kggbssneez.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^lccxooja.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\lccxooja.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^llhxxtjjfvv.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\llhxxtjjfvv.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^m70nyo9vq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\m70nyo9vq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^mhyyt8qvwm.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\mhyyt8qvwm.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ndyjfqg7.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\ndyjfqg7.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\neezqqlccxo.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^nii1e9a1w.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\nii1e9a1w.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o1kggbssne.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\o1kggbssne.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o6aa6mm6.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\o6aa6mm6.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o9k1gccxoo.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\o9k1gccxoo.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^oo6aa6mm7.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\oo6aa6mm7.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^oojaa5b0.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\oojaa5b0.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pavww6ii6u.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\pavww6ii6u.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pffqbxid.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\pffqbxid.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pggbssne.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\pggbssne.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pggbssneezq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\pggbssneezq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^plbbxnnj.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\plbbxnnj.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pplbbxnnjzz.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\pplbbxnnjzz.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^q6cc6oo6.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\q6cc6oo6.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^qb609y1uqq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\qb609y1uqq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^riiduupg.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\riiduupg.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rmm6yy6kk.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\rmm6yy6kk.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rmm6yy6kk6w.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\rmm6yy6kk6w.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rnddzppl.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\rnddzppl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rnddzpplbb.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\rnddzpplbb.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rs70tpkk6w.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\rs70tpkk6w.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^s5ypav6g1c.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\s5ypav6g1c.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^s9o1kggbss.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\s9o1kggbss.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^too6aa6mm.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\too6aa6mm.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^tu70vrhx9y.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\tu70vrhx9y.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^u1qmmhyytk.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\u1qmmhyytk.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^u9q1miiduu.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\u9q1miiduu.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^upflbmsi.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\upflbmsi.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^upggbssn.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\upggbssn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^uuf26cxx.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\uuf26cxx.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^uupggbhdyy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\uupggbhdyy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^v081c2dez.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\v081c2dez.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^vllhxxde.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\vllhxxde.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^vmmhyytkkfw.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\vmmhyytkkfw.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^w3yytkkfwwr.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\w3yytkkfwwr.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^wcc9ypaa.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\wcc9ypaa.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ww6ii6ukl.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\ww6ii6ukl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^xoojaavm.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\xoojaavm.exe []

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\fqpxsgsg.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\fvepjyrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\fqpxsgsg.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\fvepjyrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
"NoDriveTypeAutoRun"=0x5F000000
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe"="C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:*:Enabled:Football Manager 2008"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\eDonkey2000\gdonkey.exe"="C:\Program Files\eDonkey2000\gdonkey.exe:*:Enabled:eDonkey2000 GUI"
"C:\Program Files\eDonkey2000\edonkey2000.exe"="C:\Program Files\eDonkey2000\edonkey2000.exe:*:Enabled:edonkey2000"
"C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-03-28_07-22-43AM\jdk\jre\bin\javaw.exe"="C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-03-28_07-22-43AM\jdk\jre\bin\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
"C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-03-28_08-40-04PM\jdk\jre\bin\javaw.exe"="C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-03-28_08-40-04PM\jdk\jre\bin\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
"C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-04-03_03-42-28PM\jre\1.4.2\bin\javaw.exe"="C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-04-03_03-42-28PM\jre\1.4.2\bin\javaw.exe:*:Enabled:javaw"
"C:\oracle\product\10.2.0\db_2\jdk\jre\bin\java.exe"="C:\oracle\product\10.2.0\db_2\jdk\jre\bin\java.exe:*:Enabled:java"
"C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-04-03_05-16-48PM\jre\1.4.2\bin\javaw.exe"="C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-04-03_05-16-48PM\jre\1.4.2\bin\javaw.exe:*:Enabled:javaw"
"C:\oracle\product\10.2.0\db_3\jdk\jre\bin\java.exe"="C:\oracle\product\10.2.0\db_3\jdk\jre\bin\java.exe:*:Enabled:java"
"C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-04-03_07-27-58PM\jre\1.4.2\bin\javaw.exe"="C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-04-03_07-27-58PM\jre\1.4.2\bin\javaw.exe:*:Enabled:javaw"
"C:\oracle\product\10.2.0\db_1\jdk\jre\bin\java.exe"="C:\oracle\product\10.2.0\db_1\jdk\jre\bin\java.exe:*:Enabled:java"
"C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-04-25_11-07-40PM\jre\1.4.2\bin\javaw.exe"="C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-04-25_11-07-40PM\jre\1.4.2\bin\javaw.exe:*:Enabled:javaw"
"C:\oracle\product\10.2.0\tenis\jdk\jre\bin\java.exe"="C:\oracle\product\10.2.0\tenis\jdk\jre\bin\java.exe:*:Enabled:java"
"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VWDExpress.exe"="C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VWDExpress.exe:*:Enabled:Microsoft Visual Web Developer 2005 Express Edition"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-06-24_12-31-05AM\jre\1.4.2\bin\javaw.exe"="C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-06-24_12-31-05AM\jre\1.4.2\bin\javaw.exe:*:Enabled:javaw"
"C:\oracle\product\10.2.0\db_4\jdk\jre\bin\java.exe"="C:\oracle\product\10.2.0\db_4\jdk\jre\bin\java.exe:*:Enabled:java"
"C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-06-24_06-17-40AM\jre\1.4.2\bin\javaw.exe"="C:\Documents and Settings\Jiří Heider\Local Settings\Temp\OraInstall2008-06-24_06-17-40AM\jre\1.4.2\bin\javaw.exe:*:Enabled:javaw"
"C:\DevSuiteHome_1\jdk\bin\java.exe"="C:\DevSuiteHome_1\jdk\bin\java.exe:*:Enabled:java"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Documents and Settings\taťka\Local Settings\Temporary Internet Files\Content.IE5\L2PTZ142\P17535732.JPG-www.facebook[1].exe"="C:\WINDOWS\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
"C:\Documents and Settings\taťka\init.exe"="C:\Documents and Settings\taťka\init.exe:*:Enabled:ENABLE"
"C:\Program Files\AVG\AVG10\avgdiagex.exe"="C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostika 2011"
"C:\Program Files\AVG\AVG10\avgnsx.exe"="C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Webový štít"
"C:\Program Files\AVG\AVG10\avgmfapx.exe"="C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\AVG\AVG10\avgemcx.exe"="C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Obecná kontrola pošty"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Danstein
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 09 led 2006 16:31

Re: Zavirované PC, spousta trojanů

#2 Příspěvek od Danstein »

2. část logu, najednou se to nevešlo:

======File associations======

.scr - open - "%1" /S "%3"

======List of files/folders created in the last 1 months======

2011-01-01 15:52:35 ----D---- C:\Program Files\Mozilla Firefox
2011-01-01 15:50:49 ----D---- C:\0Instal
2010-12-14 17:40:04 ----A---- C:\t6.exe
2010-12-13 14:46:42 ----A---- C:\QuickTime1.exe
2010-12-12 15:49:00 ----A---- C:\21.exe
2010-12-11 17:26:29 ----A---- C:\WINDOWS\system32\drivers\fqpxsgsg.sys
2010-12-11 09:14:39 ----A---- C:\jshd.exe
2010-12-03 08:08:44 ----D---- C:\Program Files\trend micro
2010-12-03 08:08:40 ----D---- C:\rsit
2010-12-03 08:08:25 ----D---- C:\WINDOWS\LastGood
2010-12-02 16:34:03 ----D---- C:\Program Files\ToniArts
2010-12-02 14:47:35 ----A---- C:\WINDOWS\EEventManager.INI
2010-12-02 14:29:44 ----D---- C:\Documents and Settings\taťka\Data aplikací\Epson
2010-12-02 14:25:31 ----D---- C:\Program Files\Common Files\EPSON
2010-12-02 14:25:11 ----A---- C:\WINDOWS\system32\E_FLBGDE.DLL
2010-12-02 14:25:11 ----A---- C:\WINDOWS\system32\E_FD4BGDE.DLL
2010-12-02 14:21:18 ----D---- C:\Documents and Settings\taťka\Data aplikací\InstallShield
2010-12-02 14:20:38 ----D---- C:\Program Files\Epson Software
2010-12-02 14:14:01 ----D---- C:\Program Files\Common Files\ABBYY
2010-12-02 14:14:01 ----D---- C:\Program Files\ABBYY FineReader 9.0 Sprint
2010-12-02 14:14:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\ABBYY
2010-12-02 14:11:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\EPSON
2010-12-02 11:24:09 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-12-02 11:24:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-12-02 08:52:45 ----HD---- C:\$AVG
2010-12-02 08:51:56 ----D---- C:\Documents and Settings\taťka\Data aplikací\AVG10
2010-12-02 08:35:18 ----HD---- C:\Documents and Settings\All Users\Data aplikací\Common Files
2010-12-02 08:35:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG Security Toolbar
2010-12-02 08:33:40 ----D---- C:\WINDOWS\system32\drivers\AVG
2010-12-02 08:33:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG10
2010-12-02 08:32:58 ----D---- C:\Program Files\AVG
2010-12-02 08:26:33 ----A---- C:\WINDOWS\ntbtlog.txt
2010-12-01 16:43:23 ----D---- C:\totalcmd_7.55a
2010-12-01 16:43:23 ----A---- C:\WINDOWS\d.ini
2010-12-01 16:02:39 ----D---- C:\WINDOWS\pss
2010-12-01 15:57:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2010-12-01 11:52:25 ----D---- C:\Documents and Settings\taťka\Data aplikací\Sony Corporation
2010-11-28 11:14:47 ----D---- C:\Documents and Settings\taťka\Data aplikací\Nokia
2010-11-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-11-13 08:39:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2279986$
2010-11-13 08:38:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2010-11-13 08:38:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-11-13 08:38:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-11-13 08:37:54 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-11-13 08:37:18 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-11-13 08:33:55 ----HDC---- C:\WINDOWS\$NtUninstallKB981957$
2010-11-13 08:32:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-11-09 22:20:58 ----A---- C:\WINDOWS\system32\drivers\avgtdix.sys
2010-11-05 20:41:39 ----D---- C:\Documents and Settings\taťka\Data aplikací\MSN6

======List of files/folders modified in the last 1 months======

2011-01-01 15:52:50 ----D---- C:\Documents and Settings\taťka\Data aplikací\Mozilla
2010-12-18 17:27:37 ----D---- C:\WINDOWS\network diagnostic
2010-12-11 17:26:30 ----D---- C:\Program Files\Ask.com
2010-12-03 08:09:53 ----A---- C:\WINDOWS\wincmd.ini
2010-12-03 08:08:44 ----RD---- C:\Program Files
2010-12-03 08:08:41 ----D---- C:\WINDOWS
2010-12-03 08:08:35 ----HD---- C:\WINDOWS\inf
2010-12-03 08:05:53 ----AD---- C:\WINDOWS\Temp
2010-12-03 07:57:30 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-03 07:57:16 ----D---- C:\WINDOWS\system32
2010-12-03 07:57:05 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-03 07:57:03 ----A---- C:\WINDOWS\explorer.exe
2010-12-03 07:56:00 ----A---- C:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-00521102}.BAK
2010-12-02 16:53:41 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-12-02 16:36:13 ----D---- C:\WINDOWS\Prefetch
2010-12-02 16:34:03 ----HD---- C:\Program Files\InstallShield Installation Information
2010-12-02 16:32:55 ----D---- C:\WINDOWS\SoftwareDistribution
2010-12-02 14:57:43 ----SHD---- C:\WINDOWS\Installer
2010-12-02 14:57:43 ----HD---- C:\Config.Msi
2010-12-02 14:54:26 ----D---- C:\Program Files\EPSON
2010-12-02 14:47:25 ----D---- C:\WINDOWS\twain_32
2010-12-02 14:25:31 ----D---- C:\Program Files\Common Files
2010-12-02 14:23:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\UDL
2010-12-02 14:21:52 ----D---- C:\WINDOWS\WinSxS
2010-12-02 14:11:59 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-12-02 13:18:53 ----D---- C:\WINDOWS\system32\drivers\etc
2010-12-02 11:26:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-12-02 11:11:41 ----RASH---- C:\boot.ini
2010-12-02 11:11:41 ----A---- C:\WINDOWS\win.ini
2010-12-02 11:11:41 ----A---- C:\WINDOWS\system.ini
2010-12-02 11:05:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-12-02 09:51:56 ----SD---- C:\Documents and Settings\taťka\Data aplikací\Microsoft
2010-12-02 09:07:07 ----SHD---- C:\RECYCLER
2010-12-02 09:07:03 ----D---- C:\WINDOWS\system32\drivers
2010-12-02 09:00:41 ----A---- C:\WINDOWS\system32\MRT.exe
2010-12-02 08:50:52 ----D---- C:\WINDOWS\Minidump
2010-12-01 12:07:57 ----A---- C:\Documents and Settings\taťka\Data aplikací\varicad-work.ini
2010-12-01 11:51:08 ----A---- C:\WINDOWS\ChssBase.ini
2010-11-24 20:17:35 ----D---- C:\Program Files\Common Files\Adobe
2010-11-24 20:17:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-11-22 11:36:28 ----D---- C:\WINDOWS\system32\wbem
2010-11-14 15:47:45 ----SD---- C:\WINDOWS\Tasks
2010-11-14 15:47:35 ----D---- C:\Program Files\Google
2010-11-13 15:25:27 ----D---- C:\Documents and Settings\taťka\Data aplikací\Google
2010-11-13 08:39:08 ----HD---- C:\WINDOWS\$hf_mig$
2010-11-13 08:39:05 ----A---- C:\WINDOWS\imsins.BAK
2010-11-13 08:38:32 ----D---- C:\WINDOWS\system32\cs-cz
2010-11-13 08:38:32 ----D---- C:\Program Files\Internet Explorer
2010-11-08 13:54:52 ----D---- C:\WINDOWS\Microsoft.NET
2010-11-08 13:54:49 ----RSD---- C:\WINDOWS\assembly
2010-11-05 20:54:47 ----D---- C:\Program Files\ICQ6Toolbar

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\System32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2010-09-07 26064]
R0 d346bus;d346bus; C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 156800]
R0 d346prt;d346prt; C:\WINDOWS\System32\Drivers\d346prt.sys [2004-03-12 5248]
R0 fqpxsgsg;fqpxsgsg; C:\WINDOWS\System32\Drivers\fqpxsgsg.sys [2010-12-11 40128]
R0 PxHelp20;PxHelp20; C:\WINDOWS\system32\Drivers\PxHelp20.sys [2006-11-02 36624]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2007-11-15 685816]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-15 76544]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2010-09-07 249424]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2010-09-07 34384]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2010-11-09 299984]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 vmm;Virtual Machine Monitor; \??\C:\WINDOWS\system32\Drivers\vmm.sys []
R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2009-11-16 50704]
R3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys [2010-08-19 123472]
R3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys [2010-08-19 30288]
R3 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys [2010-08-19 26192]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\System32\drivers\ctac32k.sys [2002-07-19 127948]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2002-07-19 837548]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\System32\drivers\ctprxy2k.sys [2002-07-19 11068]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\drivers\ctsfm2k.sys [2002-07-19 213860]
R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2003-03-04 145408]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\System32\drivers\emupia2k.sys [2002-07-19 156604]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2002-07-24 998004]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-08-11 3958496]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2002-07-19 195432]
R3 SMBios;Intel (R) System Management BIOS Service; C:\WINDOWS\system32\DRIVERS\SMBios.sys [2003-10-14 36484]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys [2007-01-29 59280]
S1 hsrad6d;hsrad6d; C:\WINDOWS\System32\drivers\hsrad6d.sys []
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S1 sbm2827;sbm2827; C:\WINDOWS\System32\drivers\sbm2827.sys []
S1 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-14 31744]
S2 fvepjyrv;fvepjyrv; C:\WINDOWS\system32\drivers\fvepjyrv.sys []
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2007-02-22 137216]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2007-02-22 8320]
S3 nmwcdcj;Nokia USB Port; C:\WINDOWS\system32\drivers\nmwcdcj.sys [2007-02-22 12288]
S3 nmwcdcm;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2007-02-22 12288]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-11-10 6127184]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
R2 MSSQL$TENIS;SQL Server (TENIS); c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-08-11 155715]
R2 OracleOraDb10g_home1iSQL*Plus;OracleOraDb10g_home1iSQL*Plus; C:\oracle\product\10.2.0\db_4\bin\isqlplussvc.exe [2005-08-16 53248]
R2 OracleServiceJIRKA;OracleServiceJIRKA; c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE [2005-08-29 59027456]
R2 OracleServiceSKTENIS;OracleServiceSKTENIS; c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE [2005-08-29 59027456]
R2 OracleServiceTENIS;OracleServiceTENIS; c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE [2005-08-29 59027456]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R2 WMDM PMSP Service;WMDM PMSP Service; C:\WINDOWS\system32\MsPMSPSv.exe [2000-06-26 53520]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-14 135664]
S2 OracleDBConsolejirka;OracleDBConsolejirka; C:\oracle\product\10.2.0\db_4\bin\nmesrvc.exe [2005-08-16 24064]
S2 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener; C:\oracle\product\10.2.0\db_4\BIN\TNSLSNR []
S2 oubaiisj6i2au;Ati HotKey Poller; C:\Documents and Settings\taťka\Data aplikací\Microsoft\fofu.exe []
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2007-08-09 73728]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-02-03 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe [2010-10-25 517448]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-11-13 182768]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Macromedia Licensing Service;Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [2007-12-15 68096]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 OracleJobSchedulerJIRKA;OracleJobSchedulerJIRKA; c:\oracle\product\10.2.0\db_4\Bin\extjob.exe [2005-08-29 102400]
S4 OracleJobSchedulerSKTENIS;OracleJobSchedulerSKTENIS; c:\oracle\product\10.2.0\db_3\Bin\extjob.exe SKTENIS []
S4 OracleJobSchedulerTENIS;OracleJobSchedulerTENIS; c:\oracle\product\10.2.0\db_1\Bin\extjob.exe TENIS []

-----------------EOF-----------------

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Zavirované PC, spousta trojanů

#3 Příspěvek od cernohous13 »

Zdravím,

je tam ještě spousta hnoje :o

Odinstaluj:
C:\Program Files\Spybot - Search & Destroy - dnes už je k ničemu
C:\Program Files\AVG - taky trochu slabší

Můžeš použít REVO
Stáhni a nainstaluj
http://www.stahuj.centrum.cz/utility_a_ ... staller/?g
Odinstaluj program - .......
označ vše co najde a dej smazat (postupně přes "Další").
při problémech zkus v nouzovém režimu

:arrow: dej tam Avast5 - http://www.slunecnice.cz/sw/avast-free-antivirus/

:arrow: Pusť na to ComboFix
Stáhni si Obrázek ComboFix
a ulož ho na plochu.
návod na použití: http://www.bleepingcomputer.com/combofi ... t-combofix
Ukonči všechna aktivní okna,vypni Antispy a Antivir a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna a nic nespouštěj
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Kdyby ti po použití ComboFixu systém nenaběhl - při restartu F8 a poslední známá funkční konfigurace
:arrow: dej mi logy ComboFixu + nový RSIT a připravím postup likvidace a čištění :wink:
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Danstein
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 09 led 2006 16:31

Re: Zavirované PC, spousta trojanů

#4 Příspěvek od Danstein »

Combo fix:

ComboFix 10-12-02.05 - taťka 03.12.2010 15:09:57.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1535.713 [GMT 1:00]
Spuštěný z: c:\documents and settings\taťka\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus Free Edition 2011 *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\21.exe
c:\documents and settings\Jiří Heider\Data aplikací\ACD Systems\ACDSee\ImageDB.ddf
c:\documents and settings\taťka\Data aplikací\ACD Systems\ACDSee\ImageDB.ddf
c:\program files\Internet Explorer\SET18F.tmp
c:\program files\Internet Explorer\SETD4.tmp
c:\program files\Internet Explorer\SETD9.tmp
C:\Thumbs.db
c:\windows\d.ini
c:\windows\daemon.dll
c:\windows\prefetch\explorer.exe
c:\windows\system32\Drivers\fqpxsgsg.sys
c:\windows\system32\secupdat.dat

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_USNJSVC
-------\Service_usnjsvc
-------\Legacy_fqpxsgsg
-------\Service_fqpxsgsg


((((((((((((((((((((((((( Soubory vytvořené od 2010-11-03 do 2010-12-03 )))))))))))))))))))))))))))))))
.

2011-01-01 14:52 . 2011-01-01 14:52 -------- d-----w- c:\documents and settings\taťka\Local Settings\Data aplikací\Mozilla
2011-01-01 14:50 . 2010-12-03 09:44 -------- d-----w- C:\0Instal
2010-12-14 16:40 . 2010-12-15 20:50 90 ----a-w- C:\t6.exe
2010-12-13 13:46 . 2010-12-13 13:46 41 ----a-w- C:\QuickTime1.exe
2010-12-11 08:14 . 2010-12-11 13:21 258 ----a-w- C:\jshd.exe
2010-12-03 10:18 . 2010-09-07 15:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-12-03 10:18 . 2010-09-07 15:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-12-03 10:18 . 2010-09-07 15:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-12-03 10:18 . 2010-09-07 15:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-12-03 10:18 . 2010-09-07 15:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-12-03 10:18 . 2010-09-07 15:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-12-03 10:18 . 2010-09-07 15:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-12-03 10:18 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
2010-12-03 10:18 . 2010-09-07 16:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-12-03 10:18 . 2010-12-03 10:18 -------- d-----w- c:\program files\Alwil Software
2010-12-03 10:18 . 2010-12-03 10:18 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Alwil Software
2010-12-03 09:42 . 2010-12-03 09:42 -------- d-----w- c:\program files\VS Revo Group
2010-12-03 08:16 . 2010-12-03 08:16 -------- d-----w- c:\windows\system32\winrm
2010-12-03 08:16 . 2010-12-03 08:16 -------- d-----w- c:\windows\system32\GroupPolicy
2010-12-03 08:16 . 2010-12-03 08:16 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2010-12-03 08:15 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-12-03 08:14 . 2010-09-10 05:52 916480 ------w- c:\windows\system32\SET17E.tmp
2010-12-03 08:14 . 2010-09-10 05:52 1210880 ------w- c:\windows\system32\SET17F.tmp
2010-12-03 08:14 . 2010-09-10 05:52 66560 ------w- c:\windows\system32\SET182.tmp
2010-12-03 08:14 . 2010-09-10 05:52 5957120 ------w- c:\windows\system32\SET183.tmp
2010-12-03 08:14 . 2010-09-10 05:52 602112 ------w- c:\windows\system32\SET185.tmp
2010-12-03 08:14 . 2010-09-10 05:52 55296 ------w- c:\windows\system32\SET184.tmp
2010-12-03 08:14 . 2010-09-10 05:52 25600 ------w- c:\windows\system32\SET187.tmp
2010-12-03 08:14 . 2010-09-10 05:52 1986560 ------w- c:\windows\system32\SET189.tmp
2010-12-03 08:14 . 2010-09-10 05:52 184320 ------w- c:\windows\system32\SET18A.tmp
2010-12-03 08:14 . 2010-09-10 05:52 11080192 ------w- c:\windows\system32\SET18B.tmp
2010-12-03 08:13 . 2010-09-10 05:52 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-12-03 08:12 . 2010-09-10 05:52 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-12-03 08:12 . 2010-09-10 05:52 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-12-03 08:10 . 2010-12-03 08:12 -------- dc-h--w- c:\windows\ie8
2010-12-03 07:08 . 2010-12-03 07:09 -------- d-----w- c:\program files\trend micro
2010-12-03 07:08 . 2010-12-03 07:11 -------- d-----w- C:\rsit
2010-12-02 15:34 . 2010-12-02 15:34 -------- d-----w- c:\program files\ToniArts
2010-12-02 15:28 . 2010-12-02 15:28 -------- d-----w- c:\documents and settings\taťka\Local Settings\Data aplikací\AVG Security Toolbar
2010-12-02 13:29 . 2010-12-02 13:29 -------- d-----w- c:\documents and settings\taťka\Data aplikací\Epson
2010-12-02 13:25 . 2010-12-02 13:25 -------- d-----w- c:\documents and settings\LocalService\Plocha
2010-12-02 13:25 . 2010-12-02 13:25 -------- d-----w- c:\program files\Common Files\EPSON
2010-12-02 13:25 . 2009-10-01 03:01 63488 ----a-w- c:\windows\system32\E_FD4BGDE.DLL
2010-12-02 13:25 . 2008-11-12 03:00 93696 ----a-w- c:\windows\system32\E_FLBGDE.DLL
2010-12-02 13:21 . 2010-12-02 13:21 -------- d-----w- c:\documents and settings\taťka\Data aplikací\InstallShield
2010-12-02 13:20 . 2010-12-02 13:57 -------- d-----w- c:\program files\Epson Software
2010-12-02 13:19 . 2010-12-02 13:19 -------- d-----w- c:\documents and settings\taťka\Local Settings\Data aplikací\ABBYY
2010-12-02 13:14 . 2010-12-02 13:19 -------- d-----w- c:\program files\ABBYY FineReader 9.0 Sprint
2010-12-02 13:14 . 2010-12-02 13:14 -------- d-----w- c:\program files\Common Files\ABBYY
2010-12-02 13:14 . 2010-12-02 13:14 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ABBYY
2010-12-02 13:11 . 2010-12-02 13:25 -------- d-----w- c:\documents and settings\All Users\Data aplikací\EPSON
2010-12-02 10:24 . 2010-12-03 08:58 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-12-02 10:24 . 2010-12-03 08:56 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-12-02 07:52 . 2010-12-02 07:52 -------- d-----w- C:\$AVG
2010-12-02 07:35 . 2010-12-02 07:35 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\Common Files
2010-12-02 07:35 . 2010-12-03 08:42 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG Security Toolbar
2010-12-02 07:33 . 2010-12-03 07:03 -------- d-----w- c:\windows\system32\drivers\AVG
2010-12-01 15:44 . 2010-12-01 15:44 -------- d-----w- c:\documents and settings\taťka\Local Settings\Data aplikací\GHISLER
2010-12-01 15:43 . 2010-12-01 15:43 -------- d-----w- C:\totalcmd_7.55a
2010-12-01 14:57 . 2010-12-02 07:33 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MFAData
2010-12-01 10:52 . 2010-12-01 10:52 -------- d-----w- c:\documents and settings\taťka\Data aplikací\Sony Corporation
2010-11-28 10:14 . 2010-11-28 10:14 -------- d-----w- c:\documents and settings\taťka\Data aplikací\Nokia
2010-11-17 12:36 . 2010-11-17 12:36 -------- d-----w- c:\documents and settings\taťka\Local Settings\Data aplikací\Temp
2010-11-14 19:05 . 2010-11-14 19:05 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Google
2010-11-14 19:05 . 2010-11-14 19:05 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Google
2010-11-13 07:19 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-11-13 07:19 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-11-13 07:16 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-11-09 21:20 . 2010-11-09 21:20 299984 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-11-06 18:52 . 2010-11-06 18:52 -------- d-----w- c:\documents and settings\taťka\Phone Browser
2010-11-06 10:37 . 2010-11-06 10:37 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2010-11-05 19:41 . 2010-11-11 12:13 -------- d-----w- c:\documents and settings\taťka\Data aplikací\MSN6

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-03 09:00 . 2002-09-23 12:00 1034240 ----a-w- c:\windows\explorer.exe
2010-09-18 11:23 . 2002-09-23 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2002-09-23 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2002-09-23 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2002-09-23 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-13 14:27 . 2010-09-13 14:27 25680 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2010-09-10 05:52 . 2002-09-23 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2010-09-10 05:52 . 2002-09-23 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-09 13:34 . 2002-09-23 12:00 832512 ------w- c:\windows\system32\wininet.dll
2010-09-09 13:34 . 2002-09-23 12:00 17408 ------w- c:\windows\system32\corpol.dll
2010-09-08 15:57 . 2007-10-14 20:34 389120 ------w- c:\windows\system32\html.iec
2010-09-07 02:48 . 2010-09-07 02:48 34384 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-09-07 02:48 . 2010-09-07 02:48 249424 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-09-07 02:48 . 2010-09-07 02:48 26064 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
.

------- Sigcheck -------

[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-13 18:40 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"nwiz"="nwiz.exe" [2006-08-11 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
"EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2003-05-27 99840]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 24576]
"CTStartup"="c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" [2001-12-20 28672]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

c:\documents and settings\Jiýˇ Heider\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-12-11 344064]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Rychlé spuštění aplikace HP Image Zone.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Rychlé spuštění aplikace HP Image Zone.lnk
backup=c:\windows\pss\Rychlé spuštění aplikace HP Image Zone.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0hdyy6k.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\0hdyy6k.exe
backup=c:\windows\pss\0hdyy6k.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0rnii6u.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\0rnii6u.exe
backup=c:\windows\pss\0rnii6u.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0yytkkf.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\0yytkkf.exe
backup=c:\windows\pss\0yytkkf.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0zvqq6c.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\0zvqq6c.exe
backup=c:\windows\pss\0zvqq6c.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0zzqvb0.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\0zzqvb0.exe
backup=c:\windows\pss\0zzqvb0.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1cyytpv.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\1cyytpv.exe
backup=c:\windows\pss\1cyytpv.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1ieezqq.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\1ieezqq.exe
backup=c:\windows\pss\1ieezqq.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1mh0dtz.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\1mh0dtz.exe
backup=c:\windows\pss\1mh0dtz.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1qmmhyy.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\1qmmhyy.exe
backup=c:\windows\pss\1qmmhyy.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1up0llc.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\1up0llc.exe
backup=c:\windows\pss\1up0llc.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1wssnee.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\1wssnee.exe
backup=c:\windows\pss\1wssnee.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^275yt0p.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\275yt0p.exe
backup=c:\windows\pss\275yt0p.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2jee6qq.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\2jee6qq.exe
backup=c:\windows\pss\2jee6qq.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2nii6uu.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\2nii6uu.exe
backup=c:\windows\pss\2nii6uu.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2pkk6ww.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\2pkk6ww.exe
backup=c:\windows\pss\2pkk6ww.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2rmm6yy.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\2rmm6yy.exe
backup=c:\windows\pss\2rmm6yy.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2zuu6gg.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\2zuu6gg.exe
backup=c:\windows\pss\2zuu6gg.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3ggbssn.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\3ggbssn.exe
backup=c:\windows\pss\3ggbssn.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3uuaa3m.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\3uuaa3m.exe
backup=c:\windows\pss\3uuaa3m.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3uupggb.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\3uupggb.exe
backup=c:\windows\pss\3uupggb.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^69g1cyy.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\69g1cyy.exe
backup=c:\windows\pss\69g1cyy.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^6gg6ss6.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\6gg6ss6.exe
backup=c:\windows\pss\6gg6ss6.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^9a1wssn.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\9a1wssn.exe
backup=c:\windows\pss\9a1wssn.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^9k1lccx.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\9k1lccx.exe
backup=c:\windows\pss\9k1lccx.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^a1wssneezq.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\a1wssneezq.exe
backup=c:\windows\pss\a1wssneezq.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^a6mm6yy6.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\a6mm6yy6.exe
backup=c:\windows\pss\a6mm6yy6.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^aa6rss1te6v.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\aa6rss1te6v.exe
backup=c:\windows\pss\aa6rss1te6v.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^aavmmhyy.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\aavmmhyy.exe
backup=c:\windows\pss\aavmmhyy.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^avmmhyyt.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\avmmhyyt.exe
backup=c:\windows\pss\avmmhyyt.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^b0hdyy6kk.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\b0hdyy6kk.exe
backup=c:\windows\pss\b0hdyy6kk.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bm6x6jzk.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\bm6x6jzk.exe
backup=c:\windows\pss\bm6x6jzk.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bssneezq.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\bssneezq.exe
backup=c:\windows\pss\bssneezq.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\bssneezqqlc.exe
backup=c:\windows\pss\bssneezqqlc.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bxnnjzzvll.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\bxnnjzzvll.exe
backup=c:\windows\pss\bxnnjzzvll.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^d0jfaa6mm.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\d0jfaa6mm.exe
backup=c:\windows\pss\d0jfaa6mm.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ddzpplbbxnn.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\ddzpplbbxnn.exe
backup=c:\windows\pss\ddzpplbbxnn.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ddzpplbh.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\ddzpplbh.exe
backup=c:\windows\pss\ddzpplbh.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^di86u81gr.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\di86u81gr.exe
backup=c:\windows\pss\di86u81gr.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\dzpplbbxnn.exe
backup=c:\windows\pss\dzpplbbxnn.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^e1awwrii.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\e1awwrii.exe
backup=c:\windows\pss\e1awwrii.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^eaavmmhyyt.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\eaavmmhyyt.exe
backup=c:\windows\pss\eaavmmhyyt.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^faa6mm6yy.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\faa6mm6yy.exe
backup=c:\windows\pss\faa6mm6yy.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^g1cyytkk.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\g1cyytkk.exe
backup=c:\windows\pss\g1cyytkk.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^g1cyytkkfw.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\g1cyytkkfw.exe
backup=c:\windows\pss\g1cyytkkfw.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^gbssneezqq.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\gbssneezqq.exe
backup=c:\windows\pss\gbssneezqq.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ggbssneezq.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\ggbssneezq.exe
backup=c:\windows\pss\ggbssneezq.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^h0njee6qq.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\h0njee6qq.exe
backup=c:\windows\pss\h0njee6qq.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^hdttpffb.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\hdttpffb.exe
backup=c:\windows\pss\hdttpffb.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^hyytkkfwwri.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\hyytkkfwwri.exe
backup=c:\windows\pss\hyytkkfwwri.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^i1eaavmmhy.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\i1eaavmmhy.exe
backup=c:\windows\pss\i1eaavmmhy.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jaavbxss6ee.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\jaavbxss6ee.exe
backup=c:\windows\pss\jaavbxss6ee.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jzzva6rs.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\jzzva6rs.exe
backup=c:\windows\pss\jzzva6rs.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jzzvllhm.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\jzzvllhm.exe
backup=c:\windows\pss\jzzvllhm.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^kfwwriiduu.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\kfwwriiduu.exe
backup=c:\windows\pss\kfwwriiduu.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^kggbssneez.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\kggbssneez.exe
backup=c:\windows\pss\kggbssneez.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^lccxooja.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\lccxooja.exe
backup=c:\windows\pss\lccxooja.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^llhxxtjjfvv.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\llhxxtjjfvv.exe
backup=c:\windows\pss\llhxxtjjfvv.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^m70nyo9vq.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\m70nyo9vq.exe
backup=c:\windows\pss\m70nyo9vq.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^mhyyt8qvwm.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\mhyyt8qvwm.exe
backup=c:\windows\pss\mhyyt8qvwm.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ndyjfqg7.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\ndyjfqg7.exe
backup=c:\windows\pss\ndyjfqg7.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\neezqqlccxo.exe
backup=c:\windows\pss\neezqqlccxo.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^nii1e9a1w.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\nii1e9a1w.exe
backup=c:\windows\pss\nii1e9a1w.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o1kggbssne.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\o1kggbssne.exe
backup=c:\windows\pss\o1kggbssne.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o6aa6mm6.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\o6aa6mm6.exe
backup=c:\windows\pss\o6aa6mm6.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o9k1gccxoo.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\o9k1gccxoo.exe
backup=c:\windows\pss\o9k1gccxoo.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^oo6aa6mm7.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\oo6aa6mm7.exe
backup=c:\windows\pss\oo6aa6mm7.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^oojaa5b0.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\oojaa5b0.exe
backup=c:\windows\pss\oojaa5b0.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pavww6ii6u.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\pavww6ii6u.exe
backup=c:\windows\pss\pavww6ii6u.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pffqbxid.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\pffqbxid.exe
backup=c:\windows\pss\pffqbxid.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pggbssne.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\pggbssne.exe
backup=c:\windows\pss\pggbssne.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pggbssneezq.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\pggbssneezq.exe
backup=c:\windows\pss\pggbssneezq.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^plbbxnnj.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\plbbxnnj.exe
backup=c:\windows\pss\plbbxnnj.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pplbbxnnjzz.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\pplbbxnnjzz.exe
backup=c:\windows\pss\pplbbxnnjzz.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^q6cc6oo6.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\q6cc6oo6.exe
backup=c:\windows\pss\q6cc6oo6.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^qb609y1uqq.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\qb609y1uqq.exe
backup=c:\windows\pss\qb609y1uqq.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^riiduupg.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\riiduupg.exe
backup=c:\windows\pss\riiduupg.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rmm6yy6kk.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\rmm6yy6kk.exe
backup=c:\windows\pss\rmm6yy6kk.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rmm6yy6kk6w.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\rmm6yy6kk6w.exe
backup=c:\windows\pss\rmm6yy6kk6w.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rnddzppl.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\rnddzppl.exe
backup=c:\windows\pss\rnddzppl.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rnddzpplbb.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\rnddzpplbb.exe
backup=c:\windows\pss\rnddzpplbb.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rs70tpkk6w.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\rs70tpkk6w.exe
backup=c:\windows\pss\rs70tpkk6w.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^s5ypav6g1c.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\s5ypav6g1c.exe
backup=c:\windows\pss\s5ypav6g1c.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^s9o1kggbss.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\s9o1kggbss.exe
backup=c:\windows\pss\s9o1kggbss.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^too6aa6mm.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\too6aa6mm.exe
backup=c:\windows\pss\too6aa6mm.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^tu70vrhx9y.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\tu70vrhx9y.exe
backup=c:\windows\pss\tu70vrhx9y.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^u1qmmhyytk.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\u1qmmhyytk.exe
backup=c:\windows\pss\u1qmmhyytk.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^u9q1miiduu.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\u9q1miiduu.exe
backup=c:\windows\pss\u9q1miiduu.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^upflbmsi.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\upflbmsi.exe
backup=c:\windows\pss\upflbmsi.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^upggbssn.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\upggbssn.exe
backup=c:\windows\pss\upggbssn.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^uuf26cxx.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\uuf26cxx.exe
backup=c:\windows\pss\uuf26cxx.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^uupggbhdyy.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\uupggbhdyy.exe
backup=c:\windows\pss\uupggbhdyy.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^v081c2dez.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\v081c2dez.exe
backup=c:\windows\pss\v081c2dez.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^vllhxxde.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\vllhxxde.exe
backup=c:\windows\pss\vllhxxde.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^vmmhyytkkfw.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\vmmhyytkkfw.exe
backup=c:\windows\pss\vmmhyytkkfw.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^w3yytkkfwwr.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\w3yytkkfwwr.exe
backup=c:\windows\pss\w3yytkkfwwr.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^wcc9ypaa.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\wcc9ypaa.exe
backup=c:\windows\pss\wcc9ypaa.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ww6ii6ukl.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\ww6ii6ukl.exe
backup=c:\windows\pss\ww6ii6ukl.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^xoojaavm.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\xoojaavm.exe
backup=c:\windows\pss\xoojaavm.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^xoojaavmmhy.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\xoojaavmmhy.exe
backup=c:\windows\pss\xoojaavmmhy.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^xss6ee6qq6c.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\xss6ee6qq6c.exe
backup=c:\windows\pss\xss6ee6qq6c.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^y1uqqlcc.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\y1uqqlcc.exe
backup=c:\windows\pss\y1uqqlcc.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^y1uqqlccxo.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\y1uqqlccxo.exe
backup=c:\windows\pss\y1uqqlccxo.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^y70zvqq6c.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\y70zvqq6c.exe
backup=c:\windows\pss\y70zvqq6c.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^yjjpfwwm9o.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\yjjpfwwm9o.exe
backup=c:\windows\pss\yjjpfwwm9o.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ytkkfwwr.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\ytkkfwwr.exe
backup=c:\windows\pss\ytkkfwwr.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^yuuaa3mm6o.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\yuuaa3mm6o.exe
backup=c:\windows\pss\yuuaa3mm6o.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^yuupggbssn.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\yuupggbssn.exe
backup=c:\windows\pss\yuupggbssn.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^zflhm10e.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\zflhm10e.exe
backup=c:\windows\pss\zflhm10e.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^zvllhxdyez.exe]
path=c:\documents and settings\taťka\Nabídka Start\Programy\Po spuštění\zvllhxdyez.exe
backup=c:\windows\pss\zvllhxdyez.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
c:\documents and settings\taťka\uuywov.exe \u [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 03:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Detector]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
2004-03-12 20:43 81920 ----a-w- c:\program files\D-Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
2001-11-29 00:00 28672 ----a-w- c:\program files\Creative\SBAudigy\Program\ADGJDet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2007-01-19 10:55 5674352 ----a-w- c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ----a-r- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
2007-03-23 11:20 227328 ----a-w- c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2010-02-04 12:23 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 00:00 90112 ------w- c:\windows\Updreg.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Microsoft Visual Studio 8\\Common7\\IDE\\VWDExpress.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\oracle\\product\\10.2.0\\db_4\\jdk\\jre\\bin\\java.exe"=
"c:\\DevSuiteHome_1\\jdk\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [13.9.2010 15:27 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [7.9.2010 3:48 26064]
R0 d346bus;d346bus;c:\windows\system32\drivers\d346bus.sys [6.5.2008 10:15 156800]
R0 d346prt;d346prt;c:\windows\system32\drivers\d346prt.sys [6.5.2008 10:15 5248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.11.2007 13:41 685816]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3.12.2010 11:18 165584]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7.9.2010 3:48 249424]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [9.11.2010 22:20 299984]
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [14.5.2009 17:07 759048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3.12.2010 11:18 17744]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [24.9.2009 19:45 246520]
R2 MSSQL$TENIS;SQL Server (TENIS);c:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe [27.5.2009 2:27 29262680]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [16.11.2009 17:33 50704]
R2 OracleServiceJIRKA;OracleServiceJIRKA;c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE JIRKA --> c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE JIRKA [?]
R2 OracleServiceSKTENIS;OracleServiceSKTENIS;c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE SKTENIS --> c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE SKTENIS [?]
R2 OracleServiceTENIS;OracleServiceTENIS;c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE TENIS --> c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE TENIS [?]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [19.8.2010 20:42 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [19.8.2010 20:42 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [19.8.2010 20:42 26192]
S1 hsrad6d;hsrad6d;c:\windows\system32\drivers\hsrad6d.sys --> c:\windows\system32\drivers\hsrad6d.sys [?]
S1 sbm2827;sbm2827;c:\windows\system32\drivers\sbm2827.sys --> c:\windows\system32\drivers\sbm2827.sys [?]
S2 AVGIDSAgent;AVGIDSAgent;"c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe" --> c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [?]
S2 avgwd;AVG WatchDog;"c:\program files\AVG\AVG10\avgwdsvc.exe" --> c:\program files\AVG\AVG10\avgwdsvc.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 fvepjyrv;fvepjyrv; [x]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [14.11.2010 15:47 135664]
S2 OracleDBConsolejirka;OracleDBConsolejirka;c:\oracle\product\10.2.0\db_4\BIN\nmesrvc.exe [23.6.2008 23:34 24064]
S2 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener;c:\oracle\product\10.2.0\db_4\BIN\TNSLSNR --> c:\oracle\product\10.2.0\db_4\BIN\TNSLSNR [?]
S2 oubaiisj6i2au;Ati HotKey Poller;c:\documents and settings\taťka\Data aplikací\Microsoft\fofu.exe --> c:\documents and settings\taťka\Data aplikací\Microsoft\fofu.exe [?]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe --> c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [23.9.2002 13:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S4 OracleJobSchedulerJIRKA;OracleJobSchedulerJIRKA;c:\oracle\product\10.2.0\db_4\Bin\extjob.exe JIRKA --> c:\oracle\product\10.2.0\db_4\Bin\extjob.exe JIRKA [?]
S4 OracleJobSchedulerSKTENIS;OracleJobSchedulerSKTENIS;c:\oracle\product\10.2.0\db_3\Bin\extjob.exe SKTENIS --> c:\oracle\product\10.2.0\db_3\Bin\extjob.exe SKTENIS [?]
S4 OracleJobSchedulerTENIS;OracleJobSchedulerTENIS;c:\oracle\product\10.2.0\db_1\Bin\extjob.exe TENIS --> c:\oracle\product\10.2.0\db_1\Bin\extjob.exe TENIS [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Obsah adresáře 'Naplánované úlohy'

2010-12-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-14 14:47]

2010-12-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-14 14:47]

2010-12-03 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-04 14:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game01.zylom.com/activex/zylomgamesplayer.cab
FF - ProfilePath - c:\documents and settings\taťka\Data aplikací\Mozilla\Firefox\Profiles\sbg0gq0l.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.webhledani.cz/results.aspx?i=39&tp=ab&q=
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Extension: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\documents and settings\taťka\Data aplikací\Mozilla\Firefox\Profiles\sbg0gq0l.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-userini - c:\windows\explorer.exe:userini.exe
HKLM-Run-MFARestart - c:\documents and settings\All Users\Data aplikací\MFAData\pack\avgrunasx.exe
HKLM-Explorer_Run-userini - c:\windows\system32\userini.exe
SafeBoot-fqpxsgsg.sys
SafeBoot-fvepjyrv
MSConfigStartUp-rewolaj - c:\documents and settings\taťka\Data aplikací\Microsoft\tyrinika.exe
MSConfigStartUp-SessionInit - c:\documents and settings\taťka\init.exe
MSConfigStartUp-userini - c:\windows\system32\userini.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-03 15:21
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTStartup = c:\program files\Creative\Splash Screen\CTEaxSpl.EXE /run???h???\????????\?w? ?w???????w???w4???????.??w4???????4????>?s4???4?????8?????\??? ??? ???\???\???????????5?7~e?7~\???\???????x?a??????C@?\???\??????s4???\??????s\???x?8?5??sx?8??C@?x???`|?w\?????@

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OracleOraDb10g_home1TNSListener]
"ImagePath"="c:\oracle\product\10.2.0\db_4\BIN\TNSLSNR "
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(3244)
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\program files\Microsoft Virtual PC\VPCShExH.DLL
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\oracle\product\10.2.0\db_4\bin\isqlplussvc.exe
c:\oracle\product\10.2.0\db_4\jdk\bin\java.exe
c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE
c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE
c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Celkový čas: 2010-12-03 15:28:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-12-03 14:28

Před spuštěním: Volných bajtů: 41 710 575 616
Po spuštění: Volných bajtů: 41 737 129 984

WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - B17D609ED7A17C72414353B925CABF59

Danstein
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 09 led 2006 16:31

Re: Zavirované PC, spousta trojanů

#5 Příspěvek od Danstein »

RSIT:

Logfile of random's system information tool 1.08 (written by random/random)
Run by taťka at 2010-12-03 15:38:12
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 40 GB (35%) free of 114 GB
Total RAM: 1535 MB (50% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:38:32, on 3.12.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17091)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\oracle\product\10.2.0\db_4\bin\isqlplussvc.exe
C:\oracle\product\10.2.0\db_4\jdk\bin\java.exe
c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE
c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE
c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\explorer.exe
C:\totalcmd_7.55a\TOTALCMD.EXE
C:\Program Files\ToniArts\EasyCleaner\EasyClea.exe
c:\0Instal\RSIT.exe
C:\Program Files\trend micro\taťka.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\1003211037\ICQToolBar.dll
O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll (file missing)
O3 - Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game01.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe (file missing)
O23 - Service: AVGIDSAgent - Unknown owner - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (file missing)
O23 - Service: AVG WatchDog (avgwd) - Unknown owner - C:\Program Files\AVG\AVG10\avgwdsvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OracleDBConsolejirka - Oracle Corporation - C:\oracle\product\10.2.0\db_4\bin\nmesrvc.exe
O23 - Service: OracleOraDb10g_home1iSQL*Plus - Oracle - C:\oracle\product\10.2.0\db_4\bin\isqlplussvc.exe
O23 - Service: OracleOraDb10g_home1TNSListener - Unknown owner - C:\oracle\product\10.2.0\db_4\BIN\TNSLSNR.exe
O23 - Service: OracleServiceJIRKA - Oracle Corporation - c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE
O23 - Service: OracleServiceSKTENIS - Oracle Corporation - c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE
O23 - Service: OracleServiceTENIS - Oracle Corporation - c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
O23 - Service: Ati HotKey Poller (oubaiisj6i2au) - Unknown owner - C:\Documents and Settings\taťka\Data aplikací\Microsoft\fofu.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 9698 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2007-09-13 1312040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-29 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-11-23 297648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-11-23 843832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\1003211037\ICQToolBar.dll [2010-01-03 1019128]
{ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - Alcohol Toolbar - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll []
{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-11-23 297648]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-29 266240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-08-11 7630848]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-08-11 86016]
"EPSON Stylus Photo R300 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE [2003-05-27 99840]
"WINDVDPatch"=C:\WINDOWS\system32\CTHELPER.EXE [2002-07-02 24576]
"CTStartup"=C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE [2001-12-20 28672]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Detector]
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE [2002-12-09 208896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
C:\Program Files\D-Tools\daemon.exe [2004-03-12 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe [2001-11-29 28672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
C:\Documents and Settings\taťka\uuywov.exe \u []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe [2007-03-23 227328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-02-04 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Rychlé spuštění aplikace HP Image Zone.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [2005-05-12 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0hdyy6k.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\0hdyy6k.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0rnii6u.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\0rnii6u.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0yytkkf.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\0yytkkf.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0zvqq6c.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\0zvqq6c.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0zzqvb0.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\0zzqvb0.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1cyytpv.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1cyytpv.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1ieezqq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1ieezqq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1mh0dtz.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1mh0dtz.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1qmmhyy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1qmmhyy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1up0llc.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1up0llc.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1wssnee.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\1wssnee.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^275yt0p.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\275yt0p.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2jee6qq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\2jee6qq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2nii6uu.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\2nii6uu.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2pkk6ww.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\2pkk6ww.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2rmm6yy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\2rmm6yy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2zuu6gg.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\2zuu6gg.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3ggbssn.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\3ggbssn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3uuaa3m.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\3uuaa3m.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3uupggb.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\3uupggb.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^69g1cyy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\69g1cyy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^6gg6ss6.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\6gg6ss6.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^9a1wssn.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\9a1wssn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^9k1lccx.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\9k1lccx.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^a1wssneezq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\a1wssneezq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^a6mm6yy6.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\a6mm6yy6.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^aa6rss1te6v.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\aa6rss1te6v.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^aavmmhyy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\aavmmhyy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^avmmhyyt.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\avmmhyyt.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^b0hdyy6kk.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\b0hdyy6kk.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bm6x6jzk.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\bm6x6jzk.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bssneezq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\bssneezq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\bssneezqqlc.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bxnnjzzvll.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\bxnnjzzvll.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^d0jfaa6mm.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\d0jfaa6mm.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ddzpplbbxnn.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\ddzpplbbxnn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ddzpplbh.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\ddzpplbh.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^di86u81gr.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\di86u81gr.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\dzpplbbxnn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^e1awwrii.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\e1awwrii.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^eaavmmhyyt.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\eaavmmhyyt.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^faa6mm6yy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\faa6mm6yy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^g1cyytkk.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\g1cyytkk.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^g1cyytkkfw.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\g1cyytkkfw.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^gbssneezqq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\gbssneezqq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ggbssneezq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\ggbssneezq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^h0njee6qq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\h0njee6qq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^hdttpffb.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\hdttpffb.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^hyytkkfwwri.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\hyytkkfwwri.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^i1eaavmmhy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\i1eaavmmhy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jaavbxss6ee.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\jaavbxss6ee.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jzzva6rs.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\jzzva6rs.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jzzvllhm.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\jzzvllhm.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^kfwwriiduu.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\kfwwriiduu.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^kggbssneez.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\kggbssneez.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^lccxooja.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\lccxooja.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^llhxxtjjfvv.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\llhxxtjjfvv.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^m70nyo9vq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\m70nyo9vq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^mhyyt8qvwm.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\mhyyt8qvwm.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ndyjfqg7.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\ndyjfqg7.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\neezqqlccxo.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^nii1e9a1w.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\nii1e9a1w.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o1kggbssne.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\o1kggbssne.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o6aa6mm6.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\o6aa6mm6.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o9k1gccxoo.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\o9k1gccxoo.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^oo6aa6mm7.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\oo6aa6mm7.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^oojaa5b0.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\oojaa5b0.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pavww6ii6u.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\pavww6ii6u.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pffqbxid.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\pffqbxid.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pggbssne.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\pggbssne.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pggbssneezq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\pggbssneezq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^plbbxnnj.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\plbbxnnj.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pplbbxnnjzz.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\pplbbxnnjzz.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^q6cc6oo6.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\q6cc6oo6.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^qb609y1uqq.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\qb609y1uqq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^riiduupg.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\riiduupg.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rmm6yy6kk.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\rmm6yy6kk.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rmm6yy6kk6w.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\rmm6yy6kk6w.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rnddzppl.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\rnddzppl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rnddzpplbb.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\rnddzpplbb.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rs70tpkk6w.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\rs70tpkk6w.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^s5ypav6g1c.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\s5ypav6g1c.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^s9o1kggbss.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\s9o1kggbss.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^too6aa6mm.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\too6aa6mm.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^tu70vrhx9y.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\tu70vrhx9y.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^u1qmmhyytk.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\u1qmmhyytk.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^u9q1miiduu.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\u9q1miiduu.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^upflbmsi.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\upflbmsi.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^upggbssn.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\upggbssn.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^uuf26cxx.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\uuf26cxx.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^uupggbhdyy.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\uupggbhdyy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^v081c2dez.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\v081c2dez.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^vllhxxde.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\vllhxxde.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^vmmhyytkkfw.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\vmmhyytkkfw.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^w3yytkkfwwr.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\w3yytkkfwwr.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^wcc9ypaa.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\wcc9ypaa.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ww6ii6ukl.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\ww6ii6ukl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^xoojaavm.exe]
C:\Documents and Settings\taťka\Nabídka Start\Programy\Po spuštění\xoojaavm.exe []

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
"NoDriveTypeAutoRun"=323
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe"="C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:*:Enabled:Football Manager 2008"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VWDExpress.exe"="C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VWDExpress.exe:*:Enabled:Microsoft Visual Web Developer 2005 Express Edition"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\oracle\product\10.2.0\db_4\jdk\jre\bin\java.exe"="C:\oracle\product\10.2.0\db_4\jdk\jre\bin\java.exe:*:Enabled:java"
"C:\DevSuiteHome_1\jdk\bin\java.exe"="C:\DevSuiteHome_1\jdk\bin\java.exe:*:Enabled:java"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

======List of files/folders created in the last 1 months======

2011-01-01 15:52:35 ----D---- C:\Program Files\Mozilla Firefox
2011-01-01 15:50:49 ----D---- C:\0Instal
2010-12-14 17:40:04 ----A---- C:\t6.exe
2010-12-13 14:46:42 ----A---- C:\QuickTime1.exe
2010-12-11 09:14:39 ----A---- C:\jshd.exe
2010-12-03 15:30:09 ----SHD---- C:\RECYCLER
2010-12-03 15:28:15 ----A---- C:\ComboFix.txt
2010-12-03 15:02:36 ----A---- C:\Boot.bak
2010-12-03 15:02:29 ----RASHD---- C:\cmdcons
2010-12-03 14:57:22 ----A---- C:\WINDOWS\zip.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\SWSC.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\SWREG.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\sed.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\PEV.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\NIRCMD.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\MBR.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\grep.exe
2010-12-03 14:19:56 ----D---- C:\WINDOWS\ERDNT
2010-12-03 14:09:35 ----D---- C:\Qoobox
2010-12-03 11:18:46 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2010-12-03 11:18:46 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2010-12-03 11:18:44 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2010-12-03 11:18:43 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2010-12-03 11:18:41 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2010-12-03 11:18:41 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2010-12-03 11:18:40 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2010-12-03 11:18:21 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-12-03 11:18:07 ----D---- C:\Program Files\Alwil Software
2010-12-03 11:18:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-12-03 10:42:39 ----D---- C:\Program Files\VS Revo Group
2010-12-03 09:16:20 ----D---- C:\WINDOWS\system32\WindowsPowerShell
2010-12-03 09:16:18 ----D---- C:\WINDOWS\system32\winrm
2010-12-03 09:16:18 ----D---- C:\WINDOWS\system32\GroupPolicy
2010-12-03 09:16:13 ----HDC---- C:\WINDOWS\$968930Uinstall_KB968930$
2010-12-03 09:16:10 ----D---- C:\WINDOWS\$NtUninstallKB968930$
2010-12-03 09:15:53 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2010-12-03 09:14:54 ----N---- C:\WINDOWS\system32\SET17F.tmp
2010-12-03 09:14:54 ----N---- C:\WINDOWS\system32\SET17E.tmp
2010-12-03 09:14:53 ----N---- C:\WINDOWS\system32\SET187.tmp
2010-12-03 09:14:53 ----N---- C:\WINDOWS\system32\SET185.tmp
2010-12-03 09:14:53 ----N---- C:\WINDOWS\system32\SET184.tmp
2010-12-03 09:14:53 ----N---- C:\WINDOWS\system32\SET183.tmp
2010-12-03 09:14:53 ----N---- C:\WINDOWS\system32\SET182.tmp
2010-12-03 09:14:52 ----N---- C:\WINDOWS\system32\SET18A.tmp
2010-12-03 09:14:52 ----N---- C:\WINDOWS\system32\SET189.tmp
2010-12-03 09:14:50 ----N---- C:\WINDOWS\system32\SET18B.tmp
2010-12-03 09:14:23 ----D---- C:\WINDOWS\ie8updates
2010-12-03 09:10:24 ----HDC---- C:\WINDOWS\ie8
2010-12-03 09:04:28 ----HDC---- C:\WINDOWS\$NtUninstallbasecsp$
2010-12-03 08:37:19 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2010-12-03 08:08:44 ----D---- C:\Program Files\trend micro
2010-12-03 08:08:40 ----D---- C:\rsit
2010-12-02 16:34:03 ----D---- C:\Program Files\ToniArts
2010-12-02 14:47:35 ----A---- C:\WINDOWS\EEventManager.INI
2010-12-02 14:29:44 ----D---- C:\Documents and Settings\taťka\Data aplikací\Epson
2010-12-02 14:25:31 ----D---- C:\Program Files\Common Files\EPSON
2010-12-02 14:25:11 ----A---- C:\WINDOWS\system32\E_FLBGDE.DLL
2010-12-02 14:25:11 ----A---- C:\WINDOWS\system32\E_FD4BGDE.DLL
2010-12-02 14:21:18 ----D---- C:\Documents and Settings\taťka\Data aplikací\InstallShield
2010-12-02 14:20:38 ----D---- C:\Program Files\Epson Software
2010-12-02 14:14:01 ----D---- C:\Program Files\Common Files\ABBYY
2010-12-02 14:14:01 ----D---- C:\Program Files\ABBYY FineReader 9.0 Sprint
2010-12-02 14:14:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\ABBYY
2010-12-02 14:11:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\EPSON
2010-12-02 11:24:09 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-12-02 11:24:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-12-02 08:35:18 ----HD---- C:\Documents and Settings\All Users\Data aplikací\Common Files
2010-12-02 08:33:40 ----D---- C:\WINDOWS\system32\drivers\AVG
2010-12-02 08:26:33 ----A---- C:\WINDOWS\ntbtlog.txt
2010-12-01 16:43:23 ----D---- C:\totalcmd_7.55a
2010-12-01 16:02:39 ----D---- C:\WINDOWS\pss
2010-12-01 15:57:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2010-12-01 11:52:25 ----D---- C:\Documents and Settings\taťka\Data aplikací\Sony Corporation
2010-11-28 11:14:47 ----D---- C:\Documents and Settings\taťka\Data aplikací\Nokia
2010-11-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-11-13 08:39:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2279986$
2010-11-13 08:38:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2010-11-13 08:38:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-11-13 08:38:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-11-13 08:37:54 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-11-13 08:37:18 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-11-13 08:33:55 ----HDC---- C:\WINDOWS\$NtUninstallKB981957$
2010-11-13 08:32:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-11-09 22:20:58 ----A---- C:\WINDOWS\system32\drivers\avgtdix.sys
2010-11-05 20:41:39 ----D---- C:\Documents and Settings\taťka\Data aplikací\MSN6

======List of files/folders modified in the last 1 months======

2011-01-01 15:52:50 ----D---- C:\Documents and Settings\taťka\Data aplikací\Mozilla
2010-12-18 17:27:37 ----D---- C:\WINDOWS\network diagnostic
2010-12-11 17:26:30 ----D---- C:\Program Files\Ask.com
2010-12-03 15:52:02 ----RD---- C:\Program Files
2010-12-03 15:37:17 ----D---- C:\WINDOWS
2010-12-03 15:33:39 ----AD---- C:\WINDOWS\Temp
2010-12-03 15:29:55 ----A---- C:\WINDOWS\wincmd.ini
2010-12-03 15:28:18 ----D---- C:\WINDOWS\system32\drivers
2010-12-03 15:26:23 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-03 15:21:21 ----A---- C:\WINDOWS\system.ini
2010-12-03 15:21:19 ----A---- C:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-00521102}.BAK
2010-12-03 15:21:08 ----D---- C:\WINDOWS\system32\drivers\etc
2010-12-03 15:19:35 ----D---- C:\WINDOWS\system32
2010-12-03 15:17:06 ----D---- C:\WINDOWS\system32\config
2010-12-03 15:15:45 ----D---- C:\WINDOWS\Prefetch
2010-12-03 15:15:44 ----D---- C:\Program Files\Internet Explorer
2010-12-03 15:13:27 ----D---- C:\WINDOWS\AppPatch
2010-12-03 15:13:19 ----D---- C:\Program Files\Common Files
2010-12-03 15:02:36 ----RASH---- C:\boot.ini
2010-12-03 14:57:46 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-12-03 11:18:36 ----SHD---- C:\WINDOWS\Installer
2010-12-03 11:18:36 ----D---- C:\Config.Msi
2010-12-03 11:18:34 ----D---- C:\WINDOWS\WinSxS
2010-12-03 10:15:13 ----RSD---- C:\WINDOWS\assembly
2010-12-03 10:15:13 ----D---- C:\WINDOWS\Microsoft.NET
2010-12-03 10:01:17 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-03 10:00:27 ----A---- C:\WINDOWS\explorer.exe
2010-12-03 09:32:44 ----D---- C:\WINDOWS\security
2010-12-03 09:27:45 ----D---- C:\WINDOWS\system32\cs-cz
2010-12-03 09:26:29 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-12-03 09:19:05 ----D---- C:\WINDOWS\system32\en-us
2010-12-03 09:18:41 ----D---- C:\Program Files\Microsoft.NET
2010-12-03 09:16:52 ----HD---- C:\WINDOWS\inf
2010-12-03 09:16:52 ----A---- C:\WINDOWS\imsins.BAK
2010-12-03 09:16:27 ----D---- C:\WINDOWS\Help
2010-12-03 09:16:18 ----D---- C:\WINDOWS\system32\wbem
2010-12-03 09:16:11 ----D---- C:\WINDOWS\system32\CatRoot
2010-12-03 09:15:40 ----HD---- C:\WINDOWS\$hf_mig$
2010-12-03 09:12:04 ----D---- C:\WINDOWS\Media
2010-12-03 08:36:52 ----D---- C:\WINDOWS\system32\XPSViewer
2010-12-02 16:34:03 ----HD---- C:\Program Files\InstallShield Installation Information
2010-12-02 16:32:55 ----D---- C:\WINDOWS\SoftwareDistribution
2010-12-02 14:54:26 ----D---- C:\Program Files\EPSON
2010-12-02 14:47:25 ----D---- C:\WINDOWS\twain_32
2010-12-02 14:23:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\UDL
2010-12-02 14:11:59 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-12-02 11:26:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-12-02 11:11:41 ----A---- C:\WINDOWS\win.ini
2010-12-02 09:51:56 ----SD---- C:\Documents and Settings\taťka\Data aplikací\Microsoft
2010-12-02 09:00:41 ----A---- C:\WINDOWS\system32\MRT.exe
2010-12-02 08:50:52 ----D---- C:\WINDOWS\Minidump
2010-12-01 12:07:57 ----A---- C:\Documents and Settings\taťka\Data aplikací\varicad-work.ini
2010-12-01 11:51:08 ----A---- C:\WINDOWS\ChssBase.ini
2010-11-24 20:17:35 ----D---- C:\Program Files\Common Files\Adobe
2010-11-24 20:17:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-11-14 15:47:45 ----SD---- C:\WINDOWS\Tasks
2010-11-14 15:47:35 ----D---- C:\Program Files\Google
2010-11-13 15:25:27 ----D---- C:\Documents and Settings\taťka\Data aplikací\Google
2010-11-05 20:54:47 ----D---- C:\Program Files\ICQ6Toolbar

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\System32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2010-09-07 26064]
R0 d346bus;d346bus; C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 156800]
R0 d346prt;d346prt; C:\WINDOWS\System32\Drivers\d346prt.sys [2004-03-12 5248]
R0 PxHelp20;PxHelp20; C:\WINDOWS\system32\Drivers\PxHelp20.sys [2006-11-02 36624]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2007-11-15 685816]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-15 76544]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-09-07 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2010-09-07 249424]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2010-09-07 34384]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2010-11-09 299984]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 vmm;Virtual Machine Monitor; \??\C:\WINDOWS\system32\Drivers\vmm.sys []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-09-07 100176]
R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2009-11-16 50704]
R3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys [2010-08-19 123472]
R3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys [2010-08-19 30288]
R3 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys [2010-08-19 26192]
R3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\System32\drivers\ctac32k.sys [2002-07-19 127948]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2002-07-19 837548]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\System32\drivers\ctprxy2k.sys [2002-07-19 11068]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\drivers\ctsfm2k.sys [2002-07-19 213860]
R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2003-03-04 145408]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\System32\drivers\emupia2k.sys [2002-07-19 156604]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2002-07-24 998004]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-08-11 3958496]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2002-07-19 195432]
R3 SMBios;Intel (R) System Management BIOS Service; C:\WINDOWS\system32\DRIVERS\SMBios.sys [2003-10-14 36484]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys [2007-01-29 59280]
S1 hsrad6d;hsrad6d; C:\WINDOWS\System32\drivers\hsrad6d.sys []
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S1 sbm2827;sbm2827; C:\WINDOWS\System32\drivers\sbm2827.sys []
S1 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-14 31744]
S2 fvepjyrv;fvepjyrv; C:\WINDOWS\system32\drivers\fvepjyrv.sys []
S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-09-07 23376]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 mbr;mbr; \??\C:\DOCUME~1\TAKA~1\LOCALS~1\Temp\mbr.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2007-02-22 137216]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2007-02-22 8320]
S3 nmwcdcj;Nokia USB Port; C:\WINDOWS\system32\drivers\nmwcdcj.sys [2007-02-22 12288]
S3 nmwcdcm;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2007-02-22 12288]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

Danstein
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 09 led 2006 16:31

Re: Zavirované PC, spousta trojanů

#6 Příspěvek od Danstein »

2. část:

R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
R2 MSSQL$TENIS;SQL Server (TENIS); c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-08-11 155715]
R2 OracleOraDb10g_home1iSQL*Plus;OracleOraDb10g_home1iSQL*Plus; C:\oracle\product\10.2.0\db_4\bin\isqlplussvc.exe [2005-08-16 53248]
R2 OracleServiceJIRKA;OracleServiceJIRKA; c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE [2005-08-29 59027456]
R2 OracleServiceSKTENIS;OracleServiceSKTENIS; c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE [2005-08-29 59027456]
R2 OracleServiceTENIS;OracleServiceTENIS; c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE [2005-08-29 59027456]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R2 WMDM PMSP Service;WMDM PMSP Service; C:\WINDOWS\system32\MsPMSPSv.exe [2000-06-26 53520]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe []
S2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG10\avgwdsvc.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-14 135664]
S2 OracleDBConsolejirka;OracleDBConsolejirka; C:\oracle\product\10.2.0\db_4\bin\nmesrvc.exe [2005-08-16 24064]
S2 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener; C:\oracle\product\10.2.0\db_4\BIN\TNSLSNR []
S2 oubaiisj6i2au;Ati HotKey Poller; C:\Documents and Settings\taťka\Data aplikací\Microsoft\fofu.exe []
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2007-08-09 73728]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-02-03 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe []
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-11-13 182768]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Macromedia Licensing Service;Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [2007-12-15 68096]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 OracleJobSchedulerJIRKA;OracleJobSchedulerJIRKA; c:\oracle\product\10.2.0\db_4\Bin\extjob.exe [2005-08-29 102400]
S4 OracleJobSchedulerSKTENIS;OracleJobSchedulerSKTENIS; c:\oracle\product\10.2.0\db_3\Bin\extjob.exe SKTENIS []
S4 OracleJobSchedulerTENIS;OracleJobSchedulerTENIS; c:\oracle\product\10.2.0\db_1\Bin\extjob.exe TENIS []

-----------------EOF-----------------

AVAST nic nenašel, stejně jako AVG. Nevím, jestli je AVG slabší, dosud jsem nenašel nějaký testík verze 2011. Mě se zdá být účinnost vyší, než u verze 9 o větší optimalizaci ve vztahu k vytížení počítače ani nemluvě.

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Zavirované PC, spousta trojanů

#7 Příspěvek od cernohous13 »

:???: Jaký máš systémový čas

:???: Co obsahují složky
2011-01-01 14:52 . 2011-01-01 14:52 -------- d-----w- c:\documents and settings\taťka\Local Settings\Data aplikací\Mozilla
2011-01-01 14:50 . 2010-12-03 09:44 -------- d-----w- C:\0Instal

:arrow: v systému nemohou být dva AV - mohou si překážet :(
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Danstein
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 09 led 2006 16:31

Re: Zavirované PC, spousta trojanů

#8 Příspěvek od Danstein »

Systémový čas je OK, ten jsem opravil, ale když mi to předal, tak ukazoval něco v roce 2011.

c:\documents and settings\taťka\Local Settings\Data aplikací\Mozilla bude něco s Firefoxem, čas odpovídá instalaci MF v Program Files. Byla to první věc, co jsem instaloval, nesprávný čas jsem zaznamenal až po té. Instaloval jsem to pod uživatelem taťka.

C:\0Instal je OK, mnou vytvořená složka na instalačky.

Revo se tvářil, že AVG odinstaloval, ale složky zůstaly (v Program Files a Documents and Settings), které jsem ručně smazal, můžu ještě použít nějaký SW na vyčištění registrů a jestli je něco ve Win, tak to tam mohlo zůstat. Zajímalo by mě, jak může být spuštěný rezidentní štít, když v procesech nic s AVG není a instalační složka neexistuje. Pokud budu vědět, kde jsou rozesety jednotlivé soubory AVG, mohu je ručně pomazat.

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Zavirované PC, spousta trojanů

#9 Příspěvek od cernohous13 »

Pracuji na scriptu a odstraním i AVG :wink:
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Zavirované PC, spousta trojanů

#10 Příspěvek od cernohous13 »

Stáhni OTM z jednoho odkazu a rozbal nejlépe na plochu.
http://oldtimer.geekstogo.com/OTM.exe
http://www.itxassociates.com/OT-Tools/OTM.exe

Spusť program „OTM.exe“
Do okna pod žlutou čáru vlož celý text zeleným písmem ze „Scriptu“

Klikni na červené „Moveit!“

Při nabídce restartu „YES“
a log potom najdeš v C:\_OTM\MovedFiles\
Script OTM

Kód: Vybrat vše

:Processes
explorer.exe

:Files
c:\windows\system32\*.tmp.dll /s
c:\windows\system32\SET*.tmp /s
c:\windows\*.tmp /s
C:\t6.exe
C:\QuickTime1.exe
C:\jshd.exe
C:\Program Files\Spybot - Search & Destroy
C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
C:\WINDOWS\system32\drivers\AVG
C:\WINDOWS\system32\drivers\avgtdix.sys
C:\Program Files\Ask.com
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=-
"ISUSPM Startup"=-
"ISUSScheduler"=-
"Adobe ARM"=-
"SunJavaUpdateSched"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0hdyy6k.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0rnii6u.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0yytkkf.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0zvqq6c.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0zzqvb0.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1cyytpv.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1ieezqq.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1mh0dtz.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1qmmhyy.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1up0llc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1wssnee.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^275yt0p.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2jee6qq.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2nii6uu.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2pkk6ww.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2rmm6yy.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2zuu6gg.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3ggbssn.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3uuaa3m.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3uupggb.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^69g1cyy.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^6gg6ss6.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^9a1wssn.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^9k1lccx.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^a1wssneezq.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^a6mm6yy6.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^aa6rss1te6v.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^aavmmhyy.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^avmmhyyt.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^b0hdyy6kk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bm6x6jzk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bssneezq.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bxnnjzzvll.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^d0jfaa6mm.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ddzpplbbxnn.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ddzpplbh.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^di86u81gr.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^e1awwrii.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^eaavmmhyyt.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^faa6mm6yy.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^g1cyytkk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^g1cyytkkfw.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^gbssneezqq.exe
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ggbssneezq.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^h0njee6qq.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^hdttpffb.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^hyytkkfwwri.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^i1eaavmmhy.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jaavbxss6ee.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jzzva6rs.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jzzvllhm.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^kfwwriiduu.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^kggbssneez.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^lccxooja.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^llhxxtjjfvv.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^m70nyo9vq.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^mhyyt8qvwm.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ndyjfqg7.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^nii1e9a1w.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o1kggbssne.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o6aa6mm6.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o9k1gccxoo.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^oo6aa6mm7.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^oojaa5b0.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pavww6ii6u.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pffqbxid.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pggbssne.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pggbssneezq.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^plbbxnnj.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pplbbxnnjzz.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^q6cc6oo6.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^qb609y1uqq.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^riiduupg.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rmm6yy6kk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rmm6yy6kk6w.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rnddzppl.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rs70tpkk6w.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^s5ypav6g1c.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^s9o1kggbss.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^too6aa6mm.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^tu70vrhx9y.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^u1qmmhyytk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^u9q1miiduu.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^upflbmsi.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^upggbssn.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^uuf26cxx.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^uupggbhdyy.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^v081c2dez.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^vllhxxde.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^vmmhyytkkfw.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^w3yytkkfwwr.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^wcc9ypaa.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ww6ii6ukl.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^xoojaavm.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]

:Services
AVGIDSEH
Avgrkx86
Avgldx86
Avgmfx86
Avgtdix
AVGIDSDriver
AVGIDSDriver
AVGIDSShim
hsrad6d
fvepjyrv
sbm2827
mbr
ICQ Service
JavaQuickStarterService
AVGIDSAgent
avgwd
gupdate
oubaiisj6i2au
AVG Security Toolbar Service
gusvc

:Commands
[PURITY]
[RESETHOSTS]
[EMPTYTEMP]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[REBOOT]
Stáhni a nainstaluj MBAM zde http://www.download.com/Malwarebytes-An ... tag=button
Spustit > na 3.záložce "Aktualizace" > Kontrola aktualizací
následně na 1.záložce "Skener" > Provést rychlý sken > Skenovat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení
Klikni na https://www.virustotal.com/cs/
klik "Procházet" > do zadávacího pole "Název souboru" jen zkopíruj:

C:\WINDOWS\explorer.exe

"Send file" (pokud byl již testován, nech testovat znovu - Reanalyse)
Trpělivě vyčkej dokončení scanu dokud se neobjeví konečný výsledek např.0/41
Do fóra zkopíruj výsledný log. nebo odkaz z adresního řádku na stránku.
Pokud nebude nález stačí jen oznámit
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Danstein
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 09 led 2006 16:31

Re: Zavirované PC, spousta trojanů

#11 Příspěvek od Danstein »

Log OTM:

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder c:\windows\system32\*.tmp.dll not found.
c:\windows\system32\SET102.tmp moved successfully.
c:\windows\system32\SET104.tmp moved successfully.
c:\windows\system32\SET106.tmp moved successfully.
c:\windows\system32\SET107.tmp moved successfully.
c:\windows\system32\SET108.tmp moved successfully.
c:\windows\system32\SET109.tmp moved successfully.
c:\windows\system32\SET10B.tmp moved successfully.
c:\windows\system32\SET10C.tmp moved successfully.
c:\windows\system32\SET111.tmp moved successfully.
c:\windows\system32\SET112.tmp moved successfully.
c:\windows\system32\SET115.tmp moved successfully.
c:\windows\system32\SET117.tmp moved successfully.
c:\windows\system32\SET118.tmp moved successfully.
c:\windows\system32\SET119.tmp moved successfully.
c:\windows\system32\SET11D.tmp moved successfully.
c:\windows\system32\SET11E.tmp moved successfully.
c:\windows\system32\SET11F.tmp moved successfully.
c:\windows\system32\SET121.tmp moved successfully.
c:\windows\system32\SET122.tmp moved successfully.
c:\windows\system32\SET123.tmp moved successfully.
c:\windows\system32\SET17E.tmp moved successfully.
c:\windows\system32\SET17F.tmp moved successfully.
c:\windows\system32\SET182.tmp moved successfully.
c:\windows\system32\SET183.tmp moved successfully.
c:\windows\system32\SET184.tmp moved successfully.
c:\windows\system32\SET185.tmp moved successfully.
c:\windows\system32\SET187.tmp moved successfully.
c:\windows\system32\SET189.tmp moved successfully.
c:\windows\system32\SET18A.tmp moved successfully.
c:\windows\system32\SET18B.tmp moved successfully.
c:\windows\system32\SET1BD.tmp moved successfully.
c:\windows\system32\SET1BE.tmp moved successfully.
c:\windows\system32\SET1BF.tmp moved successfully.
c:\windows\system32\SET93.tmp moved successfully.
c:\windows\system32\SET99.tmp moved successfully.
c:\windows\system32\SETEF.tmp moved successfully.
c:\windows\system32\SETF0.tmp moved successfully.
c:\windows\system32\SETF1.tmp moved successfully.
c:\windows\system32\SETF2.tmp moved successfully.
c:\windows\system32\SETF3.tmp moved successfully.
c:\windows\system32\SETF4.tmp moved successfully.
c:\windows\system32\SETF5.tmp moved successfully.
c:\windows\system32\SETF6.tmp moved successfully.
c:\windows\system32\SETFA.tmp moved successfully.
c:\windows\system32\SETFB.tmp moved successfully.
c:\windows\system32\SETFC.tmp moved successfully.
c:\windows\system32\SETFD.tmp moved successfully.
c:\windows\system32\SETFE.tmp moved successfully.
c:\windows\system32\cs-cz\SET125.tmp moved successfully.
c:\windows\system32\cs-cz\SET126.tmp moved successfully.
c:\windows\system32\cs-cz\SET127.tmp moved successfully.
c:\windows\system32\cs-cz\SET128.tmp moved successfully.
c:\windows\system32\cs-cz\SET129.tmp moved successfully.
c:\windows\system32\cs-cz\SET12A.tmp moved successfully.
c:\windows\system32\cs-cz\SET12B.tmp moved successfully.
c:\windows\system32\cs-cz\SET12C.tmp moved successfully.
c:\windows\system32\cs-cz\SET12D.tmp moved successfully.
c:\windows\system32\cs-cz\SET12E.tmp moved successfully.
c:\windows\system32\cs-cz\SET12F.tmp moved successfully.
c:\windows\system32\cs-cz\SET131.tmp moved successfully.
c:\windows\system32\cs-cz\SET132.tmp moved successfully.
c:\windows\system32\cs-cz\SET133.tmp moved successfully.
c:\windows\system32\cs-cz\SET134.tmp moved successfully.
c:\windows\system32\cs-cz\SET135.tmp moved successfully.
c:\windows\system32\cs-cz\SET136.tmp moved successfully.
c:\windows\system32\cs-cz\SET137.tmp moved successfully.
c:\windows\system32\cs-cz\SET138.tmp moved successfully.
c:\windows\system32\cs-cz\SET139.tmp moved successfully.
c:\windows\system32\cs-cz\SET13A.tmp moved successfully.
c:\windows\system32\cs-cz\SET13B.tmp moved successfully.
c:\windows\system32\cs-cz\SET13C.tmp moved successfully.
c:\windows\system32\cs-cz\SET13D.tmp moved successfully.
c:\windows\system32\cs-cz\SET13E.tmp moved successfully.
c:\windows\system32\cs-cz\SET13F.tmp moved successfully.
c:\windows\system32\cs-cz\SET140.tmp moved successfully.
c:\windows\system32\cs-cz\SET141.tmp moved successfully.
c:\windows\system32\dllcache\SET1C0.tmp moved successfully.
c:\windows\system32\dllcache\SET1C1.tmp moved successfully.
c:\windows\system32\dllcache\SET9C.tmp moved successfully.
c:\windows\system32\dllcache\SET9D.tmp moved successfully.
c:\windows\system32\dllcache\SET9E.tmp moved successfully.
c:\windows\system32\dllcache\SETA0.tmp moved successfully.
c:\windows\system32\dllcache\SETA4.tmp moved successfully.
c:\windows\system32\dllcache\SETA5.tmp moved successfully.
c:\windows\system32\dllcache\SETA7.tmp moved successfully.
c:\windows\system32\dllcache\SETA8.tmp moved successfully.
c:\windows\system32\dllcache\SETA9.tmp moved successfully.
c:\windows\system32\dllcache\SETAA.tmp moved successfully.
c:\windows\system32\dllcache\SETAC.tmp moved successfully.
c:\windows\system32\dllcache\SETAD.tmp moved successfully.
c:\windows\system32\dllcache\SETAE.tmp moved successfully.
c:\windows\system32\dllcache\SETB1.tmp moved successfully.
c:\windows\system32\dllcache\SETB2.tmp moved successfully.
c:\windows\system32\dllcache\SETB3.tmp moved successfully.
c:\windows\system32\dllcache\SETB4.tmp moved successfully.
c:\windows\system32\dllcache\SETB6.tmp moved successfully.
c:\windows\system32\dllcache\SETB7.tmp moved successfully.
c:\windows\system32\dllcache\SETBA.tmp moved successfully.
c:\windows\system32\dllcache\SETBC.tmp moved successfully.
c:\windows\system32\dllcache\SETBE.tmp moved successfully.
c:\windows\system32\dllcache\SETBF.tmp moved successfully.
c:\windows\system32\dllcache\SETC0.tmp moved successfully.
c:\windows\system32\dllcache\SETC3.tmp moved successfully.
c:\windows\system32\dllcache\SETC6.tmp moved successfully.
c:\windows\system32\dllcache\SETC7.tmp moved successfully.
c:\windows\system32\dllcache\SETC9.tmp moved successfully.
c:\windows\system32\dllcache\SETCA.tmp moved successfully.
c:\windows\system32\dllcache\SETCB.tmp moved successfully.
c:\windows\002038_.tmp moved successfully.
c:\windows\005386_.tmp moved successfully.
c:\windows\SET3.tmp moved successfully.
c:\windows\SETA.tmp moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP29E.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2E3.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP374.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP38F.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3F2.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP46E.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP4A8.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP4B8.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP592.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP652.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP674.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP694.tmp folder moved successfully.
c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP713.tmp folder moved successfully.
c:\windows\Help\SETCD.tmp moved successfully.
c:\windows\Help\SETCE.tmp moved successfully.
c:\windows\Help\SETCF.tmp moved successfully.
c:\windows\Help\SETD0.tmp moved successfully.
c:\windows\inf\SETD1.tmp moved successfully.
c:\windows\inf\IEM\0405\SETD2.tmp moved successfully.
c:\windows\Installer\MSIED.tmp moved successfully.
c:\windows\Installer\MSIF4.tmp moved successfully.
c:\windows\Media\SETEA.tmp moved successfully.
c:\windows\Media\SETEB.tmp moved successfully.
c:\windows\Media\SETEC.tmp moved successfully.
c:\windows\Media\SETED.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\ahojajax\0b23b848\61c37ebe\axmi0e0u.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\ahojajax\8f1f2e19\a4b7d86c\f5fvbb7t.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\1bka0g3v.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\ahgkpeje.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\i0a2bfd7.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\asp.netwebadminfiles\9d4caaa4\c2ae7372\pgrbmdiu.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\classifieds1\310e0b96\731bf922\uunxz0bx.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\classifieds1\c39d1f9f\b0a36c6a\g25n60da.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\classifieds1\c39d1f9f\b0a36c6a\hrt6_byf.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\classifieds1\c39d1f9f\b0a36c6a\kx2ziusv.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\classifieds1\c39d1f9f\b0a36c6a\ouhe5vxq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\classifieds1\c39d1f9f\b0a36c6a\quekg-7y.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\classifieds1\c39d1f9f\b0a36c6a\s_yvxhzj.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\classifieds1\c39d1f9f\b0a36c6a\vsxg3j-h.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\classifieds1\c39d1f9f\b0a36c6a\xe-0fana.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubsite\4f3e88de\b072d657\0gr44uzq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubsite\4f3e88de\b072d657\ehs5cv_v.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubsite\4f3e88de\b072d657\pdvoedt4.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubsite\4f3e88de\b072d657\t6rc8w-9.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubsite\4f3e88de\b072d657\vvvpux9q.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubsite\a4930099\966e066a\4hpv0tww.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubsite\a4930099\966e066a\lbqliedh.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubsite\a4930099\966e066a\o895gas1.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubsite\a4930099\966e066a\r1zu86wt.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubsite\a4930099\966e066a\zizu8pll.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\472bfa1c\9f034fae\0ishhhae.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\472bfa1c\9f034fae\4um6rrkr.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\a09e397d\fe40710d\1mcg17vz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\a09e397d\fe40710d\caw-bx3i.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\a09e397d\fe40710d\dqhu1ixi.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\a09e397d\fe40710d\fp7akguj.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\a09e397d\fe40710d\nefk7o4g.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\a09e397d\fe40710d\r16xqesx.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\a09e397d\fe40710d\wyujiars.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\c17b4357\be24f394\0f4bldu1.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\c17b4357\be24f394\kyuivx3m.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\c17b4357\be24f394\lubsdq1h.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\c17b4357\be24f394\nay-rpnd.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\c17b4357\be24f394\pi_7b9we.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\c17b4357\be24f394\wfgiwdul.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\c17b4357\be24f394\zrnblol8.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\clubwebsite1\db5f91ab\c98ca1e5\c3l6fcm7.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\9b959bfc\830cd1b9\6ghkjcfd.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\9b959bfc\830cd1b9\imnx68wx.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\9b959bfc\830cd1b9\nfa23unc.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\9b959bfc\830cd1b9\ojr8vptd.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\9b959bfc\830cd1b9\pqsaq7-f.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\9b959bfc\830cd1b9\sjodjt22.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\91ftbudz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\9ri1m3_r.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\btcon_wg.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\cdfidwo5.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\celbyzyn.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\djfcgimf.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\jcabvpsi.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\l4kme_pz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\n3_dkbn3.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\pqtvxxgl.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\rs7knvga.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\thrlrcoi.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\u4nf4lsa.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\vomfpyuk.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\xmgo3v7i.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\ybdazill.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\yyqyivgc.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\express (vb)\e1da95e3\22dd0a10\_5y52dhu.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\0tmynkb1.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\alylsuwq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\bigolaza.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\eus6x6jz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\kgkf3ni7.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\lkof1cow.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\m4jev6qs.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\pdzncq87.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\qcpzs3qw.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\scdzhox1.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\sfafghxh.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\vz7vsdvs.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\w5bwhq5-.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\wxwleypl.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\5ef0a785\1036817c\_njuhtf0.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\3ycts1q5.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\5slhqnlf.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\8kxspesp.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\9piz4tvv.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\9tiq-kt2.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\as-bm8ww.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\awppbz6x.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\cqd5du1p.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\crtjfcmx.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\d5adzjy6.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\dxijde3n.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\gpqkfpb7.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\l3jdhdpq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\nizbmsq2.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\ro_zfkc5.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\sdhvoutq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\sx-f57x8.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\toihfj1x.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\u4qso72v.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\ulq817zq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\vruwpjf0.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\vtv67cfv.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\x1mpvh4j.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\x7vhsozy.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\yj2vkik6.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\yvy-9l49.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\zek_iaa9.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\final\6e57cfe4\ba54e0fd\_fwbxpjl.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\2b30fa97\1bb9f02c\dfnqbga8.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\2b30fa97\1bb9f02c\kexi7tvl.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\2b30fa97\1bb9f02c\ozsdwmvy.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\2b30fa97\1bb9f02c\u94s7qh_.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\2b30fa97\1bb9f02c\vhykp0e_.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\34b739e2\a4439b0d\mv7e8br0.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\34b739e2\a4439b0d\re6ixfqw.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\34b739e2\a4439b0d\t_gpbvtb.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\34b739e2\a4439b0d\z-9wlkey.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\45d637c6\511665d3\mjhsjykx.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\45d637c6\511665d3\qemxdryi.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\59ea9ef1\430a2939\hoz4tsyi.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky1\59ea9ef1\430a2939\t1mbcwco.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\2zseywuc.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\cdwozkbo.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\fc6ruaft.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\g2mauiwo.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\kcfvattu.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\kdarvwgq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\lnoviy8z.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\obs7dmx7.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\qpxzxc0c.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\qwh7kazr.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\sni5qbqu.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\tkxpwunb.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\v2lj0nhu.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\0db39fb3\a27d6134\_xw9ywam.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\d2923ca7\4f2ddb9c\3yfhlt1m.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky2\d2923ca7\4f2ddb9c\ycu6eyg4.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky3\59c8ceac\dd2d4584\9hfjjnej.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky3\59c8ceac\dd2d4584\ocsu-pxv.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky3\59c8ceac\dd2d4584\sgbtlkvb.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky3\59c8ceac\dd2d4584\ubndfuja.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky3\59c8ceac\dd2d4584\udbhoyah.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky3\d3b8be57\df620c1b\7vqqfcgc.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky3\d3b8be57\df620c1b\fh0wvops.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky3\d3b8be57\df620c1b\hbo8ivis.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky3\d3b8be57\df620c1b\qnb4z481.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky3\d3b8be57\df620c1b\sx32gx68.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\klubové stránky3\d3b8be57\df620c1b\y1izufla.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\6ofclbcz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\eovl09hh.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\giqkzlfj.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\ickrx703.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\ir-z5d2i.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\k5e2ev-h.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\llczuxsd.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\rgyikl1t.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\t9tp3unr.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\xyqjml5d.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\yjo7_hf6.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3a0b1c3c\b067ff46\_ny5hqzl.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\0bktyo11.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\0msuhvqd.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\4mio0bvb.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\5lqqmqjg.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\7fwcbe8e.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\ahvy9fht.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\d4juc_cw.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\dbvzj4uq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\f-kveanq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\fv4ef0bb.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\gj4g4gb7.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\huf476k5.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\i5gbazzt.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\ikwwrb0k.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\jrb6mkrh.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\jsznb6j2.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\l5c-mgnz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\leh-sk_t.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\lsn7caoa.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\mfsltf3p.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\murrygaz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\n3ql2xc_.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\ndrlzmn9.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\noxvwzl2.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\nrfdokj6.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\o8agugmx.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\qgcyz_q9.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\rcbevox-.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\r_otbg-s.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\s21oooca.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\tb7remzy.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\uxgs5_bz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\u_ko4j57.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\v2ruvvg3.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\vknvn8iz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\we__w1l9.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\xktoow-k.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\3ed8200b\f7f2e422\zw1pl7pr.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\62361917\ec689499\1w7s3v2v.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\62361917\ec689499\1_wzkpwv.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\62361917\ec689499\219426ci.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\62361917\ec689499\8iqsrcsq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\62361917\ec689499\bm8eysvq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\62361917\ec689499\bu-e2irv.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\62361917\ec689499\f4en14vr.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\62361917\ec689499\g0u2ey4x.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\62361917\ec689499\t35xzefd.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\62361917\ec689499\vy0ivrzj.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\bm9_eq7b.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\f7caiq-k.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\hw__zpcs.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\kgqscimn.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\lznxxpe0.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\mwkxup1k.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\okygejhq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\pa6tyjfu.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\pciiluwq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\qowgkncg.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\uhgqbvrz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\vg-6yuj-.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\vmqehkpf.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\mywebpagesstarterkit_1.1.4\e4b6f7c9\f2e0ee37\w78i4icl.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress1\03dbb2d9\5e5a56d8\3rrpt40z.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress1\03dbb2d9\5e5a56d8\krtjo-og.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress1\03dbb2d9\5e5a56d8\lh7nzslu.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress1\03dbb2d9\5e5a56d8\olf1lyrk.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress1\03dbb2d9\5e5a56d8\pvhr0mea.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress1\03dbb2d9\5e5a56d8\rfa0rp_r.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress1\03dbb2d9\5e5a56d8\vibwxgqj.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress1\03dbb2d9\5e5a56d8\wv9kuyui.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress1\03dbb2d9\5e5a56d8\zbkcbch0.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress1\03dbb2d9\5e5a56d8\zssz8nol.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress1\3ad6458d\efc8c30f\p8wts-iv.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress2\25d33235\867c47ba\6vsfj9by.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress2\25d33235\867c47ba\9wyrixsk.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nemesisgalleryexpress2\25d33235\867c47ba\zfsed2x7.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nezavislepanely.aspx\8cad15f4\bd0f5fc\ou4bo9ld.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\nezavislepanely.aspx\ef4a43df\e059f7e4\dke-itym.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\osobní stránky1\f767d83b\6e4ca48d\8yoiswyq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\osobní stránky1\f767d83b\6e4ca48d\bhrxliav.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\osobní stránky1\f767d83b\6e4ca48d\sgphshwa.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\285482f8\16faf4a2\0v-awl2g.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\285482f8\16faf4a2\5riirx1e.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\285482f8\16faf4a2\bvl22yp6.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\285482f8\16faf4a2\jvvsiwnz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\285482f8\16faf4a2\mapsylrx.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\285482f8\16faf4a2\nyijclqa.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\285482f8\16faf4a2\wugwmnvm.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\af14e3ee\e5134966\aqtznn3l.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\af14e3ee\e5134966\bdugiica.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\af14e3ee\e5134966\jyv_trgm.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\af14e3ee\e5134966\sp105e7u.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis\af14e3ee\e5134966\tiou18qx.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\07dcb931\2d80f4ae\0zitmimu.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\07dcb931\2d80f4ae\6wrozamn.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\07dcb931\2d80f4ae\fdpayswa.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\07dcb931\2d80f4ae\hwzyqwyz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\07dcb931\2d80f4ae\kdpppzju.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\07dcb931\2d80f4ae\q6gndmlx.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\07dcb931\2d80f4ae\wcls46ns.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\07dcb931\2d80f4ae\zbsuzxfv.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\0a8ca5d9\27fa091f\i-0eomwx.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\0a8ca5d9\27fa091f\qmfxu2i4.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\0a8ca5d9\27fa091f\tedycv04.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skhradec-tenis.cz\0a8ca5d9\27fa091f\uuns2wx5.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skloram.com\3ac5bcbb\f650cd39\gh9f53dn.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skloram.com\3ac5bcbb\f650cd39\q_oyplkh.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skloram.com\3ac5bcbb\f650cd39\tkjj4ud9.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skloram.com\adfc6346\f12728f3\8snhb7ba.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skloram.com\adfc6346\f12728f3\g27krazo.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\skloram.com\adfc6346\f12728f3\zkgae227.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\34475b61\2b8aecbf\-uyr6oko.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\34475b61\2b8aecbf\0iyc7qt2.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\34475b61\2b8aecbf\is-17qjl.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\34475b61\2b8aecbf\lviatog5.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\34475b61\2b8aecbf\_0gkutiw.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\5e105aff\25cb32ab\8dtc8rto.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\5e105aff\25cb32ab\apf-grsq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\5e105aff\25cb32ab\j6r8naso.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\5e105aff\25cb32ab\jguknwhg.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\5e105aff\25cb32ab\wp4rp-bh.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\5e105aff\25cb32ab\zufxwhiu.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\d81ebeaa\a3ef1fad\ppciyxmk.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\d81ebeaa\a3ef1fad\rnvujois.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\d81ebeaa\a3ef1fad\rrkgxw4t.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\d81ebeaa\a3ef1fad\ten2agz2.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\d81ebeaa\a3ef1fad\vx0brgr2.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\d81ebeaa\a3ef1fad\xoexnz32.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\d81ebeaa\a3ef1fad\xxof6rcy.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\d81ebeaa\a3ef1fad\ynd3pkfi.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\e9fc3f57\8f55cfec\p_iafykt.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\e9fc3f57\8f55cfec\rj3lah7y.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\e9fc3f57\8f55cfec\v04dqfyx.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec\e9fc3f57\8f55cfec\x9mxbide.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec.cz\46bd377a\731743d1\1b997lbt.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec.cz\46bd377a\731743d1\py9whq4q.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec.cz\46bd377a\731743d1\s1i9e_bo.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec.cz\46bd377a\731743d1\v5q-lejb.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec.cz\7c28c9e1\982f6986\diovsedt.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec.cz\7c28c9e1\982f6986\jeywxfhz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec.cz\7c28c9e1\982f6986\j_bumghm.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\sktenis-hradec.cz\7c28c9e1\982f6986\mdtlxrpv.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\smallbusiness_vb1\2a80f95d\9f9b96d\dr-ynw3c.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\smallbusiness_vb1\2a80f95d\9f9b96d\ivqeo9pe.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\smallbusiness_vb1\2a80f95d\9f9b96d\ktf2enaj.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\smallbusiness_vb1\2a80f95d\9f9b96d\tjj7j_4m.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\smallbusiness_vb1\8cacab86\eafe071f\mdf0xkm_.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\smallbusiness_vb1\98971673\176a8047\a4gnrvhk.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\smallbusiness_vb1\98971673\176a8047\rakfd9en.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\53bab095\5897d9ae\5mnelayq.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\53bab095\5897d9ae\6prccnlk.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\53bab095\5897d9ae\arekbnud.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\53bab095\5897d9ae\wyptezgc.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\53bab095\5897d9ae\zpu8mkhp.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\862dcc24\a1d1c187\0x8ugzdg.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\862dcc24\a1d1c187\4xo8ofwn.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\862dcc24\a1d1c187\5km-m5hw.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\862dcc24\a1d1c187\5yl3owri.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\862dcc24\a1d1c187\c20eckoi.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\862dcc24\a1d1c187\jqx7f5ty.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\862dcc24\a1d1c187\kwpiofm_.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\862dcc24\a1d1c187\mevjkaza.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\862dcc24\a1d1c187\x2tarvnz.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\web 1\862dcc24\a1d1c187\_ykv0nlk.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\9eed5738\14c40a64\u8lfbqef.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\website1\c4ebc48d\991a41ee\5yq0bbbu.tmp moved successfully.
c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\websktenis\3f8791e7\ebfbd689\qecruzs8.tmp moved successfully.
c:\windows\system32\CONFIG.TMP moved successfully.
c:\windows\twain_32\hpqgnds2.tmp moved successfully.
C:\t6.exe moved successfully.
C:\QuickTime1.exe moved successfully.
C:\jshd.exe moved successfully.
C:\Program Files\Spybot - Search & Destroy\Help folder moved successfully.
C:\Program Files\Spybot - Search & Destroy folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy\Recovery folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy\Logs folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy folder moved successfully.
C:\WINDOWS\system32\drivers\AVG folder moved successfully.
C:\WINDOWS\system32\drivers\avgtdix.sys moved successfully.
C:\Program Files\Ask.com folder moved successfully.
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\HP Software Update deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ISUSPM Startup deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ISUSScheduler deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0hdyy6k.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0rnii6u.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0yytkkf.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0zvqq6c.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^0zzqvb0.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1cyytpv.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1ieezqq.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1mh0dtz.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1qmmhyy.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1up0llc.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^1wssnee.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^275yt0p.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2jee6qq.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2nii6uu.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2pkk6ww.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2rmm6yy.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^2zuu6gg.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3ggbssn.exe\ deleted successfully.

Danstein
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 09 led 2006 16:31

Re: Zavirované PC, spousta trojanů

#12 Příspěvek od Danstein »

2. část:

Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3uuaa3m.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^3uupggb.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^69g1cyy.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^6gg6ss6.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^9a1wssn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^9k1lccx.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^a1wssneezq.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^a6mm6yy6.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^aa6rss1te6v.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^aavmmhyy.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^avmmhyyt.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^b0hdyy6kk.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bm6x6jzk.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bssneezq.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bssneezqqlc.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^bxnnjzzvll.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^d0jfaa6mm.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ddzpplbbxnn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ddzpplbh.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^di86u81gr.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^dzpplbbxnn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^e1awwrii.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^eaavmmhyyt.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^faa6mm6yy.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^g1cyytkk.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^g1cyytkkfw.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^gbssneezqq.ex\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ggbssneezq.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^h0njee6qq.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^hdttpffb.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^hyytkkfwwri.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^i1eaavmmhy.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jaavbxss6ee.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jzzva6rs.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^jzzvllhm.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^kfwwriiduu.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^kggbssneez.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^lccxooja.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^llhxxtjjfvv.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^m70nyo9vq.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^mhyyt8qvwm.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ndyjfqg7.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^neezqqlccxo.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^nii1e9a1w.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o1kggbssne.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o6aa6mm6.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^o9k1gccxoo.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^oo6aa6mm7.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^oojaa5b0.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pavww6ii6u.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pffqbxid.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pggbssne.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pggbssneezq.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^plbbxnnj.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^pplbbxnnjzz.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^q6cc6oo6.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^qb609y1uqq.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^riiduupg.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rmm6yy6kk.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rmm6yy6kk6w.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rnddzppl.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^rs70tpkk6w.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^s5ypav6g1c.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^s9o1kggbss.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^too6aa6mm.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^tu70vrhx9y.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^u1qmmhyytk.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^u9q1miiduu.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^upflbmsi.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^upggbssn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^uuf26cxx.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^uupggbhdyy.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^v081c2dez.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^vllhxxde.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^vmmhyytkkfw.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^w3yytkkfwwr.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^wcc9ypaa.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^ww6ii6ukl.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^taťka^Nabídka Start^Programy^Po spuštění^xoojaavm.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig\ deleted successfully.
========== SERVICES/DRIVERS ==========
Error: Unable to stop service AVGIDSEH!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVGIDSEH deleted successfully.
Error: Unable to stop service Avgrkx86!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgrkx86 deleted successfully.
Service Avgldx86 stopped successfully!
Service Avgldx86 deleted successfully!
Service Avgmfx86 stopped successfully!
Service Avgmfx86 deleted successfully!
Error: Unable to stop service Avgtdix!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avgtdix deleted successfully.
Error: Unable to stop service AVGIDSDriver!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVGIDSDriver deleted successfully.
Error: Unable to stop service AVGIDSDriver!
Service\Driver key AVGIDSDriver not found.
Error: Unable to stop service AVGIDSShim!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVGIDSShim deleted successfully.
Service hsrad6d stopped successfully!
Service hsrad6d deleted successfully!
Service fvepjyrv stopped successfully!
Service fvepjyrv deleted successfully!
Service sbm2827 stopped successfully!
Service sbm2827 deleted successfully!
Error: No service named mbr was found to stop!
Service\Driver key mbr not found.
Service ICQ Service stopped successfully!
Service ICQ Service deleted successfully!
Service JavaQuickStarterService stopped successfully!
Service JavaQuickStarterService deleted successfully!
Service AVGIDSAgent stopped successfully!
Service AVGIDSAgent deleted successfully!
Service avgwd stopped successfully!
Service avgwd deleted successfully!
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service oubaiisj6i2au stopped successfully!
Service oubaiisj6i2au deleted successfully!
Service AVG Security Toolbar Service stopped successfully!
Service AVG Security Toolbar Service deleted successfully!
Service gusvc stopped successfully!
Service gusvc deleted successfully!
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56504 bytes

User: Jiýˇ Heider
->Temporary Internet Files folder emptied: 160978 bytes

User: Jiří Heider
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 397967 bytes
->Java cache emptied: 55682149 bytes
->Flash cache emptied: 1566128 bytes

User: Ji�Heider

User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 32768 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: taťka
->Temp folder emptied: 75188 bytes
->Temporary Internet Files folder emptied: 5715614 bytes
->Java cache emptied: 38617281 bytes
->FireFox cache emptied: 62489833 bytes
->Flash cache emptied: 32482 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 2494712 bytes

Total Files Cleaned = 160,00 mb


Restore points cleared and new OTM Restore Point set!

OTM by OldTimer - Version 3.1.17.2 log created on 12062010_081209

Files moved on Reboot...
File C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_5ac.dat not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_630.dat not found!

Registry entries deleted on Reboot...





Log MBAM:

Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Verze databáze: 5253

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

6.12.2010 8:43:09
mbam-log-2010-12-06 (08-42-58).txt

Typ kontroly: Rychlý test
Testované objekty: 162471
Uplynulý čas: 6 minut, 35 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 3

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\documents and settings\all users\data aplikací\common.data (Malware.Trace) -> No action taken.
c:\documents and settings\jiří heider\secupdat.dat (Worm.Autorun) -> No action taken.
c:\documents and settings\taťka\secupdat.dat (Worm.Autorun) -> No action taken.



Na VirusTotal nebylo nic nalezeno.

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Zavirované PC, spousta trojanů

#13 Příspěvek od cernohous13 »

MBAM spustit znovu - dát Kompletní kontrola
:arrow: po ukončení -> Zobrazit výsledky -> zkontrolovat zda je vše označeno -> Odstranit označené
vyběhne log, ve kterém budou záznamy tohoto typu:
Infikované adresáře:
C:\Program Files\xxxxxx -> Quarantined and deleted successfully.
ten bych taky rád viděl :)
:arrow: Mohu doporučit kontrolu a vyčištění Ccleanerem
Stáhni Ccleaner - http://www.slunecnice.cz/sw/ccleaner/
Při instalaci vyhodit fajfku u "Instalovat Yahoo! Toolbar"

zavřít Internetový prohlížeč a
spustit "Čistič" > "Spustit Ccleaner" - odstraní nepotřebné
spustit "Registry" > "Hledej problémy" > "Opravit vybrané problémy"
souhlas se zálohou registrů - opakovat dokud nebudou registry čisté.
spustit "Nástroje" > "Obnova systému" - 1.řádek zachovej, ostatní "Odstranit"
spustit "Nástroje" > "Start" - tady můžeš zkusit deaktivovat procesy, které při spuštění nepotřebuješ (pokud by ti potom něco nechodilo, stejným způsobem je povolíš)
Návod:http://jnp.zive.cz/Clanky/Prirucka-do-k ... fault.aspx
Ten si můžeš nechat i na budoucí občasné čištění.

:arrow: dej aktuální RSIT a popiš současné problémy - možná už budu po sobě jen uklízet :wink:
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Danstein
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 09 led 2006 16:31

Re: Zavirované PC, spousta trojanů

#14 Příspěvek od Danstein »

1. log:

Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Verze databáze: 5253

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

6.12.2010 14:23:23
mbam-log-2010-12-06 (14-23-23).txt

Typ kontroly: Úplný test (C:\|)
Testované objekty: 341011
Uplynulý čas: 1 hodin, 40 minut, 37 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 3

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\documents and settings\all users\data aplikací\common.data (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\jiří heider\secupdat.dat (Worm.Autorun) -> Quarantined and deleted successfully.
c:\documents and settings\taťka\secupdat.dat (Worm.Autorun) -> Quarantined and deleted successfully.

Danstein
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 09 led 2006 16:31

Re: Zavirované PC, spousta trojanů

#15 Příspěvek od Danstein »

RSIT:

Logfile of random's system information tool 1.08 (written by random/random)
Run by taťka at 2010-12-06 14:48:18
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 45 GB (39%) free of 114 GB
Total RAM: 1535 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:48:39, on 6.12.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17091)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\oracle\product\10.2.0\db_4\bin\isqlplussvc.exe
C:\oracle\product\10.2.0\db_4\jdk\bin\java.exe
c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE
c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE
c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
C:\totalcmd_7.55a\TOTALCMD.EXE
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
c:\0Instal\RSIT.exe
C:\Program Files\trend micro\taťka.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\1003211037\ICQToolBar.dll
O3 - Toolbar: (no name) - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - (no file)
O3 - Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game01.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OracleDBConsolejirka - Oracle Corporation - C:\oracle\product\10.2.0\db_4\bin\nmesrvc.exe
O23 - Service: OracleOraDb10g_home1iSQL*Plus - Oracle - C:\oracle\product\10.2.0\db_4\bin\isqlplussvc.exe
O23 - Service: OracleOraDb10g_home1TNSListener - Unknown owner - C:\oracle\product\10.2.0\db_4\BIN\TNSLSNR.exe
O23 - Service: OracleServiceJIRKA - Oracle Corporation - c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE
O23 - Service: OracleServiceSKTENIS - Oracle Corporation - c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE
O23 - Service: OracleServiceTENIS - Oracle Corporation - c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8003 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2007-09-13 1312040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-29 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-11-23 297648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-11-23 843832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\1003211037\ICQToolBar.dll [2010-01-03 1019128]
{ED4BD629-C1B6-4399-8A34-02CCAA921DC9}
{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-11-23 297648]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-29 266240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-08-11 7630848]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-08-11 86016]
"EPSON Stylus Photo R300 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE [2003-05-27 99840]
"WINDVDPatch"=C:\WINDOWS\system32\CTHELPER.EXE [2002-07-02 24576]
"CTStartup"=C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE [2001-12-20 28672]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Detector]
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE [2002-12-09 208896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
C:\Program Files\D-Tools\daemon.exe [2004-03-12 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe [2001-11-29 28672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe [2007-03-23 227328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-02-04 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Rychlé spuštění aplikace HP Image Zone.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [2005-05-12 73728]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
"NoDriveTypeAutoRun"=323
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe"="C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:*:Enabled:Football Manager 2008"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VWDExpress.exe"="C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VWDExpress.exe:*:Enabled:Microsoft Visual Web Developer 2005 Express Edition"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\oracle\product\10.2.0\db_4\jdk\jre\bin\java.exe"="C:\oracle\product\10.2.0\db_4\jdk\jre\bin\java.exe:*:Enabled:java"
"C:\DevSuiteHome_1\jdk\bin\java.exe"="C:\DevSuiteHome_1\jdk\bin\java.exe:*:Enabled:java"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

======List of files/folders created in the last 1 months======

2011-01-01 15:52:35 ----D---- C:\Program Files\Mozilla Firefox
2011-01-01 15:50:49 ----D---- C:\0Instal
2010-12-06 14:42:39 ----A---- C:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-00521102}.BAK
2010-12-06 14:36:33 ----D---- C:\Program Files\CCleaner
2010-12-06 08:34:26 ----D---- C:\Documents and Settings\taťka\Data aplikací\Malwarebytes
2010-12-06 08:33:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-12-06 08:33:34 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-12-06 08:33:29 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-12-06 08:33:29 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2010-12-06 08:12:09 ----D---- C:\_OTM
2010-12-03 15:30:09 ----SHD---- C:\RECYCLER
2010-12-03 15:28:15 ----A---- C:\ComboFix.txt
2010-12-03 15:02:36 ----A---- C:\Boot.bak
2010-12-03 15:02:29 ----RASHD---- C:\cmdcons
2010-12-03 14:57:22 ----A---- C:\WINDOWS\zip.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\SWSC.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\SWREG.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\sed.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\PEV.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\NIRCMD.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\MBR.exe
2010-12-03 14:57:22 ----A---- C:\WINDOWS\grep.exe
2010-12-03 14:19:56 ----D---- C:\WINDOWS\ERDNT
2010-12-03 14:09:35 ----D---- C:\Qoobox
2010-12-03 11:18:46 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2010-12-03 11:18:46 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2010-12-03 11:18:44 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2010-12-03 11:18:43 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2010-12-03 11:18:41 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2010-12-03 11:18:41 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2010-12-03 11:18:40 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2010-12-03 11:18:21 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-12-03 11:18:07 ----D---- C:\Program Files\Alwil Software
2010-12-03 11:18:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-12-03 10:42:39 ----D---- C:\Program Files\VS Revo Group
2010-12-03 09:16:20 ----D---- C:\WINDOWS\system32\WindowsPowerShell
2010-12-03 09:16:18 ----D---- C:\WINDOWS\system32\winrm
2010-12-03 09:16:18 ----D---- C:\WINDOWS\system32\GroupPolicy
2010-12-03 09:16:13 ----HDC---- C:\WINDOWS\$968930Uinstall_KB968930$
2010-12-03 09:16:10 ----D---- C:\WINDOWS\$NtUninstallKB968930$
2010-12-03 09:15:53 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2010-12-03 09:14:23 ----D---- C:\WINDOWS\ie8updates
2010-12-03 09:10:24 ----HDC---- C:\WINDOWS\ie8
2010-12-03 09:04:28 ----HDC---- C:\WINDOWS\$NtUninstallbasecsp$
2010-12-03 08:37:19 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2010-12-03 08:08:44 ----D---- C:\Program Files\trend micro
2010-12-03 08:08:40 ----D---- C:\rsit
2010-12-02 16:34:03 ----D---- C:\Program Files\ToniArts
2010-12-02 14:47:35 ----A---- C:\WINDOWS\EEventManager.INI
2010-12-02 14:29:44 ----D---- C:\Documents and Settings\taťka\Data aplikací\Epson
2010-12-02 14:25:31 ----D---- C:\Program Files\Common Files\EPSON
2010-12-02 14:25:11 ----A---- C:\WINDOWS\system32\E_FLBGDE.DLL
2010-12-02 14:25:11 ----A---- C:\WINDOWS\system32\E_FD4BGDE.DLL
2010-12-02 14:21:18 ----D---- C:\Documents and Settings\taťka\Data aplikací\InstallShield
2010-12-02 14:20:38 ----D---- C:\Program Files\Epson Software
2010-12-02 14:14:01 ----D---- C:\Program Files\Common Files\ABBYY
2010-12-02 14:14:01 ----D---- C:\Program Files\ABBYY FineReader 9.0 Sprint
2010-12-02 14:14:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\ABBYY
2010-12-02 14:11:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\EPSON
2010-12-02 08:35:18 ----HD---- C:\Documents and Settings\All Users\Data aplikací\Common Files
2010-12-01 16:43:23 ----D---- C:\totalcmd_7.55a
2010-12-01 16:02:39 ----D---- C:\WINDOWS\pss
2010-12-01 15:57:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2010-12-01 11:52:25 ----D---- C:\Documents and Settings\taťka\Data aplikací\Sony Corporation
2010-11-28 11:14:47 ----D---- C:\Documents and Settings\taťka\Data aplikací\Nokia
2010-11-13 08:39:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-11-13 08:39:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2279986$
2010-11-13 08:38:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2010-11-13 08:38:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-11-13 08:38:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-11-13 08:37:54 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-11-13 08:37:18 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-11-13 08:33:55 ----HDC---- C:\WINDOWS\$NtUninstallKB981957$
2010-11-13 08:32:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$

======List of files/folders modified in the last 1 months======

2011-01-01 15:52:50 ----D---- C:\Documents and Settings\taťka\Data aplikací\Mozilla
2010-12-18 17:27:37 ----D---- C:\WINDOWS\network diagnostic
2010-12-06 14:48:27 ----D---- C:\WINDOWS\Prefetch
2010-12-06 14:44:09 ----AD---- C:\WINDOWS\Temp
2010-12-06 14:43:26 ----D---- C:\WINDOWS
2010-12-06 14:43:19 ----D---- C:\WINDOWS\system32
2010-12-06 14:43:07 ----A---- C:\WINDOWS\wincmd.ini
2010-12-06 14:41:37 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-12-06 14:38:14 ----D---- C:\WINDOWS\Debug
2010-12-06 14:38:11 ----D---- C:\WINDOWS\Minidump
2010-12-06 14:36:33 ----RD---- C:\Program Files
2010-12-06 14:24:27 ----D---- C:\WINDOWS\system32\drivers
2010-12-06 08:20:59 ----SHD---- C:\System Volume Information
2010-12-06 08:20:59 ----D---- C:\WINDOWS\system32\Restore
2010-12-06 08:19:27 ----D---- C:\WINDOWS\system32\drivers\etc
2010-12-06 08:13:15 ----SD---- C:\WINDOWS\Tasks
2010-12-06 08:13:13 ----D---- C:\WINDOWS\twain_32
2010-12-06 08:12:51 ----D---- C:\WINDOWS\Media
2010-12-06 08:12:49 ----SHD---- C:\WINDOWS\Installer
2010-12-06 08:12:49 ----HD---- C:\WINDOWS\inf
2010-12-06 08:12:48 ----D---- C:\WINDOWS\Help
2010-12-06 08:12:19 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-06 08:12:18 ----D---- C:\WINDOWS\system32\cs-cz
2010-12-03 16:58:11 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-03 15:21:21 ----A---- C:\WINDOWS\system.ini
2010-12-03 15:17:06 ----D---- C:\WINDOWS\system32\config
2010-12-03 15:15:44 ----D---- C:\Program Files\Internet Explorer
2010-12-03 15:13:27 ----D---- C:\WINDOWS\AppPatch
2010-12-03 15:13:19 ----D---- C:\Program Files\Common Files
2010-12-03 15:02:36 ----RASH---- C:\boot.ini
2010-12-03 11:18:36 ----D---- C:\Config.Msi
2010-12-03 11:18:34 ----D---- C:\WINDOWS\WinSxS
2010-12-03 10:15:13 ----RSD---- C:\WINDOWS\assembly
2010-12-03 10:15:13 ----D---- C:\WINDOWS\Microsoft.NET
2010-12-03 10:00:27 ----A---- C:\WINDOWS\explorer.exe
2010-12-03 09:32:44 ----D---- C:\WINDOWS\security
2010-12-03 09:26:29 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-12-03 09:19:05 ----D---- C:\WINDOWS\system32\en-us
2010-12-03 09:18:41 ----D---- C:\Program Files\Microsoft.NET
2010-12-03 09:16:18 ----D---- C:\WINDOWS\system32\wbem
2010-12-03 09:16:11 ----D---- C:\WINDOWS\system32\CatRoot
2010-12-03 09:15:40 ----HD---- C:\WINDOWS\$hf_mig$
2010-12-03 08:36:52 ----D---- C:\WINDOWS\system32\XPSViewer
2010-12-02 16:34:03 ----HD---- C:\Program Files\InstallShield Installation Information
2010-12-02 16:32:55 ----D---- C:\WINDOWS\SoftwareDistribution
2010-12-02 14:54:26 ----D---- C:\Program Files\EPSON
2010-12-02 14:23:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\UDL
2010-12-02 14:11:59 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-12-02 11:26:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-12-02 11:11:41 ----A---- C:\WINDOWS\win.ini
2010-12-02 09:51:56 ----SD---- C:\Documents and Settings\taťka\Data aplikací\Microsoft
2010-12-02 09:00:41 ----A---- C:\WINDOWS\system32\MRT.exe
2010-12-01 12:07:57 ----A---- C:\Documents and Settings\taťka\Data aplikací\varicad-work.ini
2010-12-01 11:51:08 ----A---- C:\WINDOWS\ChssBase.ini
2010-11-24 20:17:35 ----D---- C:\Program Files\Common Files\Adobe
2010-11-24 20:17:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-11-14 15:47:35 ----D---- C:\Program Files\Google
2010-11-13 15:25:27 ----D---- C:\Documents and Settings\taťka\Data aplikací\Google
2010-11-11 13:13:11 ----D---- C:\Documents and Settings\taťka\Data aplikací\MSN6

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\System32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 d346bus;d346bus; C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 156800]
R0 d346prt;d346prt; C:\WINDOWS\System32\Drivers\d346prt.sys [2004-03-12 5248]
R0 PxHelp20;PxHelp20; C:\WINDOWS\system32\Drivers\PxHelp20.sys [2006-11-02 36624]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2007-11-15 685816]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-15 76544]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-09-07 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 vmm;Virtual Machine Monitor; \??\C:\WINDOWS\system32\Drivers\vmm.sys []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-09-07 100176]
R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2009-11-16 50704]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\System32\drivers\ctac32k.sys [2002-07-19 127948]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2002-07-19 837548]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\System32\drivers\ctprxy2k.sys [2002-07-19 11068]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\drivers\ctsfm2k.sys [2002-07-19 213860]
R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2003-03-04 145408]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\System32\drivers\emupia2k.sys [2002-07-19 156604]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2002-07-24 998004]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-08-11 3958496]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2002-07-19 195432]
R3 SMBios;Intel (R) System Management BIOS Service; C:\WINDOWS\system32\DRIVERS\SMBios.sys [2003-10-14 36484]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys [2007-01-29 59280]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S1 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-14 31744]
S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-09-07 23376]
S3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys [2010-08-19 30288]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2007-02-22 137216]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2007-02-22 8320]
S3 nmwcdcj;Nokia USB Port; C:\WINDOWS\system32\drivers\nmwcdcj.sys [2007-02-22 12288]
S3 nmwcdcm;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2007-02-22 12288]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
R2 MSSQL$TENIS;SQL Server (TENIS); c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-08-11 155715]
R2 OracleOraDb10g_home1iSQL*Plus;OracleOraDb10g_home1iSQL*Plus; C:\oracle\product\10.2.0\db_4\bin\isqlplussvc.exe [2005-08-16 53248]
R2 OracleServiceJIRKA;OracleServiceJIRKA; c:\oracle\product\10.2.0\db_4\bin\ORACLE.EXE [2005-08-29 59027456]
R2 OracleServiceSKTENIS;OracleServiceSKTENIS; c:\oracle\product\10.2.0\db_3\bin\ORACLE.EXE [2005-08-29 59027456]
R2 OracleServiceTENIS;OracleServiceTENIS; c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE [2005-08-29 59027456]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R2 WMDM PMSP Service;WMDM PMSP Service; C:\WINDOWS\system32\MsPMSPSv.exe [2000-06-26 53520]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 OracleDBConsolejirka;OracleDBConsolejirka; C:\oracle\product\10.2.0\db_4\bin\nmesrvc.exe [2005-08-16 24064]
S2 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener; C:\oracle\product\10.2.0\db_4\BIN\TNSLSNR []
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2007-08-09 73728]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-02-03 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Macromedia Licensing Service;Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [2007-12-15 68096]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-03-26 292864]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 OracleJobSchedulerJIRKA;OracleJobSchedulerJIRKA; c:\oracle\product\10.2.0\db_4\Bin\extjob.exe [2005-08-29 102400]
S4 OracleJobSchedulerSKTENIS;OracleJobSchedulerSKTENIS; c:\oracle\product\10.2.0\db_3\Bin\extjob.exe SKTENIS []
S4 OracleJobSchedulerTENIS;OracleJobSchedulerTENIS; c:\oracle\product\10.2.0\db_1\Bin\extjob.exe TENIS []

-----------------EOF-----------------

PC se chová normálně, i na internetu, ale je problém s bodem obnovení. Konkrétně při ručním vytváření se dostanu do okna, kam zadávám název bodu obnovení, ale do příslušné kolonky nejde nic napsat. Taktéž seznam bodů obnovení je prázný, ani kalendář tam není vidět. Možná to souvisí se změnou systémového času.

Odpovědět