Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu po léčení :)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
kejikl
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 03 dub 2007 00:35
Kontaktovat uživatele:

Prosím o kontrolu logu po léčení :)

#1 Příspěvek od kejikl »

Dobry den vsem,
prosim o kontrolu logu. Pocitacv byl napaden podle Eset Smart Security 4.xx virem Win32/Daonol.DQ a mazal neustale soubor vptko.old.
Byl tam neaktualizovany NOD32 a winXP firewal. Prejel jsem to Eset Smart Security 4.xx a CCleanerem, ted uz mi to nic nenajde. Je to opravdu v poradku?
Dekuji.
-----------------------------------------------------------------------------------------

Logfile of random's system information tool 1.08 (written by random/random)
Run by Kejikovi at 2010-12-27 08:53:18
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 41 GB (51%) free of 80 GB
Total RAM: 767 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:53:18, on 27.12.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Documents and Settings\Kejikovi\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Kejikovi.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint - Náhled - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Přidat na seznam k tisku - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint - Tisk - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Vysokorychlostní tisk - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {813A45F9-744F-435F-A815-19E2DF35A9D8} (O2C-Player - area constructor view (ELECO Software GmbH)) - http://www.o2c.de/download/o2cplayerac.cab
O16 - DPF: {CCA0B877-CB5E-4ADC-AD30-457C379512DD} (Gif89 Lite Class) - http://kamera1.okrouhla.cz/xplugLite.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

--
End of file - 11128 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Norton Security Scan for Kejikovi.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-08-11 1443112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}]
EWPBrowseObject Class - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 34304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-04 256112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
AcroIEToolbarHelper Class - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll [2010-09-30 842296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2010-02-04 458736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2006-04-18 552960]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-04 256112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-03-01 577536]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2003-09-29 155648]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [2006-03-21 69632]
"Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [2005-06-06 57344]
"Acrobat Assistant 7.0"=C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]
"Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2005-10-26 159744]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-04-09 2029640]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2004-06-29 88363]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-09-25 68856]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2008-08-11 21741864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3325656.exe]
C:\WINDOWS\Temp\3325656.exe [2010-12-26 64912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-07-13 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-09-25 68856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Acrobat Speed Launcher.lnk]
C:\WINDOWS\INSTAL~1\{AC76B~1\SC_ACR~1.EXE [2010-04-03 25214]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe

C:\Documents and Settings\Kejikovi\Nabídka Start\Programy\Po spuštění
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoResolveTrack"=1
"NoResolveSearch"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-12-27 08:52:27 ----D---- C:\rsit
2010-12-27 08:52:27 ----D---- C:\Program Files\trend micro
2010-12-26 23:11:44 ----D---- C:\Program Files\CCleaner
2010-12-26 23:01:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$
2010-12-26 23:01:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
2010-12-26 23:01:03 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-12-26 23:00:57 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-12-26 22:52:27 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-12-26 22:52:06 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-12-26 22:51:48 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-12-26 22:51:36 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-12-26 22:51:26 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-12-26 22:51:19 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-12-26 22:51:12 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-12-26 22:51:04 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-12-26 22:50:32 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-12-26 22:49:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-12-26 22:48:57 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-12-26 22:48:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-12-26 22:48:10 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-12-26 22:48:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-12-26 22:47:52 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-12-26 22:47:44 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-12-26 22:47:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2296199$
2010-12-26 22:47:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-12-26 22:47:06 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-12-26 22:46:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-12-26 22:46:33 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-12-26 22:46:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2443105$
2010-12-26 22:46:15 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-12-26 22:46:05 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-12-26 22:44:33 ----D---- C:\WINDOWS\ie8updates
2010-12-26 22:43:55 ----D---- C:\WINDOWS\WBEM
2010-12-26 22:43:34 ----HDC---- C:\WINDOWS\ie8
2010-12-26 22:37:11 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-12-26 22:37:05 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-12-26 22:36:57 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-12-26 22:36:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2440591$
2010-12-26 22:36:42 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-12-26 22:36:34 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-12-26 22:36:27 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-12-26 22:36:21 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-12-26 22:36:16 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-12-26 22:36:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-12-26 22:36:04 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-12-26 22:35:55 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-12-26 22:35:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-12-26 22:35:40 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-12-26 22:35:32 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-12-26 22:35:24 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-12-26 22:35:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2443685$
2010-12-26 22:35:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-12-26 22:35:03 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-12-26 22:34:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-12-26 22:34:49 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-12-26 22:34:43 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-12-26 22:34:32 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-12-26 22:34:18 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-12-26 22:34:12 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-12-26 22:34:04 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-12-26 22:33:59 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-12-26 22:33:33 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-12-26 22:33:27 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-12-26 22:33:21 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-12-26 22:33:15 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-12-26 22:33:09 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-12-26 22:33:03 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-12-26 22:32:57 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-12-26 22:32:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2436673$
2010-12-26 22:32:45 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-12-26 22:32:39 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-12-26 22:32:33 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-12-26 22:32:26 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-12-26 22:32:20 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-12-26 22:32:11 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-12-26 22:32:05 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-12-26 22:31:59 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-12-26 22:31:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-12-26 22:31:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2467659$
2010-12-26 22:31:35 ----HDC---- C:\WINDOWS\$NtUninstallKB2416400$
2010-12-26 22:31:27 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-12-26 22:31:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-12-26 22:31:14 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-12-26 22:31:08 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-12-26 22:31:02 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-12-26 22:30:55 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-12-26 22:30:49 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-12-26 22:30:43 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-12-26 22:30:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-12-26 22:30:31 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-12-26 22:30:25 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-12-26 22:30:16 ----SHD---- C:\Config.Msi
2010-12-26 22:28:58 ----A---- C:\WINDOWS\system32\MRT.exe
2010-12-26 22:28:53 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-12-26 22:28:47 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-12-26 22:28:41 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-12-26 22:28:35 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-12-26 22:28:29 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-12-26 22:28:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2423089$
2010-12-26 22:28:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-12-26 22:24:09 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2010-12-26 22:07:29 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-12-26 22:04:39 ----A---- C:\WINDOWS\system32\wpa.bak
2010-12-26 22:04:35 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-12-26 22:04:33 ----A---- C:\WINDOWS\system32\pidgen.dll.wga
2010-12-26 22:04:33 ----A---- C:\WINDOWS\system32\dpcdll.dll.wga
2010-12-26 22:02:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2010-12-26 22:00:18 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-12-26 22:00:18 ----D---- C:\WINDOWS\system32\PreInstall
2010-12-26 22:00:18 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-12-26 22:00:17 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-12-26 22:00:17 ----HD---- C:\WINDOWS\$hf_mig$
2010-12-26 21:24:44 ----ASH---- C:\hiberfil.sys
2010-12-26 19:55:51 ----D---- C:\Documents and Settings\Kejikovi\Data aplikací\ESET
2010-12-26 19:54:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2010-12-26 19:01:35 ----D---- C:\WINDOWS\pss

======List of files/folders modified in the last 1 months======

2010-12-27 08:52:39 ----D---- C:\WINDOWS\Temp
2010-12-27 08:52:27 ----RD---- C:\Program Files
2010-12-27 08:50:29 ----D---- C:\Program Files\Mozilla Firefox
2010-12-27 08:49:33 ----A---- C:\WINDOWS\NeroDigital.ini
2010-12-27 08:48:04 ----D---- C:\WINDOWS
2010-12-27 08:46:45 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-12-27 08:45:52 ----D---- C:\WINDOWS\Debug
2010-12-27 08:42:06 ----D---- C:\WINDOWS\Prefetch
2010-12-27 08:40:27 ----D---- C:\Documents and Settings\Kejikovi\Data aplikací\Skype
2010-12-27 08:00:59 ----D---- C:\Documents and Settings\Kejikovi\Data aplikací\skypePM
2010-12-26 23:04:08 ----D---- C:\WINDOWS\system32
2010-12-26 23:04:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-12-26 23:01:29 ----HD---- C:\WINDOWS\inf
2010-12-26 23:01:28 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-26 23:01:28 ----D---- C:\WINDOWS\system32\drivers
2010-12-26 22:59:04 ----D---- C:\WINDOWS\SoftwareDistribution
2010-12-26 22:56:56 ----SD---- C:\WINDOWS\Tasks
2010-12-26 22:55:29 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-26 22:55:06 ----D---- C:\WINDOWS\system32\cs-cz
2010-12-26 22:55:06 ----D---- C:\WINDOWS\Help
2010-12-26 22:55:06 ----D---- C:\WINDOWS\AppPatch
2010-12-26 22:55:06 ----D---- C:\Program Files\Internet Explorer
2010-12-26 22:55:05 ----D---- C:\WINDOWS\system32\wbem
2010-12-26 22:51:37 ----D---- C:\Program Files\Messenger
2010-12-26 22:50:37 ----D---- C:\WINDOWS\WinSxS
2010-12-26 22:43:51 ----D---- C:\WINDOWS\Media
2010-12-26 22:31:29 ----D---- C:\Program Files\Outlook Express
2010-12-26 22:30:57 ----D---- C:\Program Files\Movie Maker
2010-12-26 22:30:22 ----SHD---- C:\WINDOWS\Installer
2010-12-26 22:29:47 ----A---- C:\WINDOWS\RtlRack.ini
2010-12-26 22:03:10 ----SHD---- C:\System Volume Information
2010-12-26 22:02:55 ----D---- C:\WINDOWS\system32\Restore
2010-12-26 20:06:20 ----D---- C:\Program Files\ESET
2010-12-26 19:02:19 ----SH---- C:\boot.ini
2010-12-26 19:02:19 ----A---- C:\WINDOWS\win.ini
2010-12-26 19:02:19 ----A---- C:\WINDOWS\system.ini
2010-12-26 19:00:54 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-12-26 19:00:37 ----D---- C:\Program Files\Norton Security Scan

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nv_agp;NVIDIA nForce AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\nv_agp.sys [2003-10-29 21120]
R0 nvatabus;nvatabus; C:\WINDOWS\system32\DRIVERS\nvatabus.sys [2004-06-03 79360]
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-04-09 107256]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-04-09 55768]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-04-09 113960]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-04-09 133000]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2004-06-29 1268204]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-05-10 3964736]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2006-06-07 329901]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2006-06-07 855018]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-04-09 33096]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-29 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-04-13 1897408]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2004-05-17 33280]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2004-05-17 12928]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2006-06-07 30459]
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2006-06-07 149028]
S3 btwhid;btwhid; C:\WINDOWS\system32\DRIVERS\btwhid.sys [2006-06-07 47811]
S3 btwmodem;Bluetooth Modem; C:\WINDOWS\system32\DRIVERS\btwmodem.sys [2006-06-07 30285]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2006-06-07 67384]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\WINDOWS\system32\DRIVERS\k750bus.sys [2005-07-07 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\k750mdfl.sys [2010-02-11 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\WINDOWS\system32\DRIVERS\k750mdm.sys [2010-02-11 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\WINDOWS\system32\DRIVERS\k750mgmt.sys [2010-02-11 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\WINDOWS\system32\DRIVERS\k750obex.sys [2010-02-11 79488]
S3 MSICPL;MSICPL; \??\E:\install4\MSICPL.sys []
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2006-06-07 266295]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-04-09 731840]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-04-09 20680]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-02-04 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------
Obrázek

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Prosím o kontrolu logu po léčení :)

#2 Příspěvek od cernohous13 »

Zdravím,
Stáhni OTM z jednoho odkazu a rozbal nejlépe na plochu.
http://oldtimer.geekstogo.com/OTM.exe
http://www.itxassociates.com/OT-Tools/OTM.exe

Spusť program „OTM.exe“ (pro Vistu a Win7 – pravým a „Run As Administrator“).
Do okna pod žlutou čáru vlož celý text zeleným písmem ze „Scriptu“

Klikni na červené „Moveit!“

Při nabídce restartu „YES“
a log potom najdeš v C:\_OTM\MovedFiles\
Script OTM

Kód: Vybrat vše

:Processes
explorer.exe

:Reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3325656.exe]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=-
"SSBkgdUpdate"=-

:Files
C:\WINDOWS\Temp\3325656.exe
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp /s

:Commands
[PURITY]
[RESETHOSTS]
[EMPTYTEMP]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[REBOOT]
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

kejikl
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 03 dub 2007 00:35
Kontaktovat uživatele:

Re: Prosím o kontrolu logu po léčení :)

#3 Příspěvek od kejikl »

Dekuji za bleskovou a profesionalni odpoved :)
LOG z OTM:

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3325656.exe\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SSBkgdUpdate deleted successfully.
========== FILES ==========
C:\WINDOWS\Temp\3325656.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll moved successfully.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
C:\WINDOWS\Temp\NOD7DE7.tmp moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Kejikovi
->Temp folder emptied: 3152719 bytes
->Temporary Internet Files folder emptied: 268358 bytes
->FireFox cache emptied: 46987871 bytes
->Flash cache emptied: 1550 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 37065546 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 84,00 mb


Restore points cleared and new OTM Restore Point set!

OTM by OldTimer - Version 3.1.17.2 log created on 12272010_103554

Files moved on Reboot...

Registry entries deleted on Reboot...
Obrázek

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Prosím o kontrolu logu po léčení :)

#4 Příspěvek od cernohous13 »

:arrow: Spusť opět OTM -> CleanUp! - odinstaluje a vyčistí po sobě.

:arrow: Mohu doporučit kontrolu a vyčištění Ccleanerem
Stáhni Ccleaner - http://www.slunecnice.cz/sw/ccleaner/
Při instalaci vyhodit fajfku u "Instalovat Yahoo! Toolbar" (pokud bude v nabídce)

zavřít Internetový prohlížeč a
spustit "Čistič" > "Spustit Ccleaner" - odstraní nepotřebné
spustit "Registry" > "Hledej problémy" > "Opravit vybrané problémy"
souhlas se zálohou registrů - opakovat dokud nebudou registry čisté.
spustit "Nástroje" > "Start" - tady můžeš zkusit deaktivovat procesy, které při spuštění nepotřebuješ (pokud by ti potom něco nechodilo, stejným způsobem je povolíš)
Návod:http://jnp.zive.cz/Clanky/Prirucka-do-k ... fault.aspx
Ten si můžeš nechat i na budoucí občasné čištění.

:arrow: Po vyčištění by se hodila defragmentace
doporučuji http://www.slunecnice.cz/sw/defraggler/ + čeština

:arrow: máš to čisté - ode mne by to mohlo být vše :wink:
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

kejikl
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 03 dub 2007 00:35
Kontaktovat uživatele:

Re: Prosím o kontrolu logu po léčení :)

#5 Příspěvek od kejikl »

:worship: dekuji :worship:
Obrázek

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Prosím o kontrolu logu po léčení :)

#6 Příspěvek od cernohous13 »

Nemáš zač - rádo se stalo a jsme tady i příště Obrázek
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Odpovědět