Stránka 1 z 4

nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 11:26
od Foxtrot
Zdravím, na pc jsem měl eset SS a chtěl jsem vyzkoušet i ostatní antiviry jako 1. jsem nainstaloval kaspersky IS, ktery mi nepovolil ani otevrit firefox, takže jsem ho odinstaloval, další šel norton 360, stáhl jsem ho nainstaloval a vyzkoušel jsem na něj keygen

Kód: Vybrat vše

link
(doufám že link nevadí), poté se mi restartovalo pc, několikrát jsem obnovil systém a když zrovna pc nespadlo, jsem pc prohledal nortonem, který něco našel a vymazal to, dále nešly spustit prohlížeče a celkový start byl zpomalený (načítal se dlouho a ze začátku mi naskočila nejdříve plocha a až za několik sekund ikony), teď mi pc po obnovení nespadlo a vypadá to že zatím funguje normálně a znovu nainstalovaný eset SS mi zatím nic při kontrole nenašel.
Prosím jen o kontrolu, jestli je to už v pořádku.
Děkuji.

EDIT: Omlouvám se nespustil jsem jako správce, znou daný log.


Logfile of random's system information tool 1.08 (written by random/random)
Run by Ondřej at 2011-02-04 11:28:44
Microsoft Windows 7 Home Premium
System drive C: has 214 GB (23%) free of 919 GB
Total RAM: 6142 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:28:50, on 4.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Windows\DAODx.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\ASUS\TurboV EVO\TurboVHELP.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Ondřej.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {7757CBCC-0975-4b79-A519-90B142CA3A23} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0SrcAs.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Toolbar BHO - {EFA17361-CDC0-4927-9AFC-BAAD1F96B2AE} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll
O3 - Toolbar: IObit Toolbar - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O15 - Trusted IP range: http://5.0.0.1
O15 - ESC Trusted IP range: http://5.0.0.1
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AMD Reservation Manager - Advanced Micro Devices - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: IObit Toolbar Service (IObitBarService) - IObit - C:\PROGRA~2\IObitBar\toolbar\1.bin\i0barsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @C:\Windows\Microsoft.NET\Framework64\v4.0.21006\WPF\WPFFontCache_v0400.exe,-100 (WPFFontCache_v0400) - Unknown owner - C:\Windows\Microsoft.NET\Framework64\v4.0.21006\WPF\WPFFontCache_v0400.exe (file missing)

--
End of file - 10543 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe"
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-3a41ecc8-15a2-48c8-b689-f7e0025be8d9 -SystemEventPortName:HostProcess-2bd17e05-9d77-463e-aa4b-de589e30c4d7 -IoCancelEventPortName:HostProcess-fd47a826-6fbb-42cf-b075-937b1cafda88 -NonStateChangingEventPortName:HostProcess-87019d7a-8bd2-4854-a2ce-b2e4fd6f7152 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6ae3ac2a-685e-44c5-bd67-08de378e975c
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-aa536e82-73b7-4060-94f2-d87e74ce51b8 -SystemEventPortName:HostProcess-b9b72dd3-3f03-447f-b596-4d82d5b2e8ea -IoCancelEventPortName:HostProcess-c85335c7-d979-4dd6-9839-2c1b5e328e05 -NonStateChangingEventPortName:HostProcess-4ba76db6-da21-46a6-9250-ba2c25880ce3 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:ca448d43-effb-4989-9c7f-bc2f640a09e0
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\svchost.exe -k Akamai
"C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\PROGRA~2\IObitBar\toolbar\1.bin\i0barsvc.exe
C:\Windows\Explorer.EXE
taskeng.exe {3BBBB75A-13BF-47DF-B078-A7025B9FB626}
"C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe"
C:\Windows\DAODx.exe
"C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe" /startup
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\CNAC4RPD.EXE
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\ASUS\TurboV EVO\TurboVHELP.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
WLIDSvcM.exe 2368
"C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /SkipFUE /RemoteOCXLaunch
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe"
"C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
"C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"taskhost.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe" /SILENT
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\SysWOW64\DllHost.exe /Processid:{B366DEBE-645B-43A5-B865-DDD82C345492}
"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:1260 CREDAT:79873
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=2524.7d1c3c0.1354469531 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" 2524 plugin \\.\pipe\gecko-crash-server-pipe.2524
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\ostatni\stažené soubory (Firefox)\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

======Scheduled tasks folder======

C:\Windows\tasks\AWC AutoSweep.job
C:\Windows\tasks\AWC Startup.job
C:\Windows\tasks\AWC Update.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-11-24 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EFA17361-CDC0-4927-9AFC-BAAD1F96B2AE}]
Toolbar BHO - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll [2010-09-21 638976]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - IObit Toolbar - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll [2010-09-21 638976]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-07-02 2903688]
"Launch LgDeviceAgent"=C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe [2010-08-03 415816]
"Launch LCDMon"=C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe [2010-08-03 2412616]
"Launch LGDCore"=C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe [2010-08-03 4725320]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-11-16 500208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2010-10-11 14940040]
"Steam"=c:\program files (x86)\steam\steam.exe [2010-11-16 1242448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe [2010-03-04 311296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CtaMon]
Rundll32 CtaMon.dll,RunMonitor []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EvtMgr6]
C:\Program Files\Logitech\SetPointP\SetPoint.exe [2010-06-26 1609296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObitBar Browser Plugin Loader]
C:\PROGRA~2\IObitBar\toolbar\1.bin\i0brmon.exe [2010-09-21 20480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-01-25 421160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\Windows\RaidTool\xInsIDE.exe [2010-01-19 43632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [2010-09-17 57928]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2010-12-06 1910152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NUSB3MON]
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-01-22 106496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-01-29 10038304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Six Engine]
C:\Program Files (x86)\ASUS\EPU\EPU.exe [2010-03-16 5309056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartRAM]
C:\Program Files (x86)\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe [2010-07-21 198864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-01-04 336384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TurboV EVO]
C:\Program Files\ASUS\TurboV EVO\TurboV_EVO.exe [2010-04-07 9919104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
C:\Program Files (x86)\Creative\SB Arena Surround Headset\Volume Panel\VolPanlu.exe [2009-05-04 241789]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Canon LBP5000 Status Window.lnk]
C:\Windows\System32\spool\drivers\x64\3\CNAC4LAD.EXE [2010-02-04 60384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Ondřej^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Registrace produktu.lnk]
C:\PROGRA~2\COMMON~1\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Ondřej^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~2\MICROS~1\Office12\ONENOTEM.EXE [2009-02-26 97680]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2010-05-06 66640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe","%1"
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2011-02-04 10:38:51 ----D---- C:\rsit
2011-02-04 10:38:51 ----D---- C:\Program Files\trend micro
2011-02-04 08:37:34 ----D---- C:\Windows\system32\drivers\N360x64
2011-02-03 21:55:00 ----D---- C:\Program Files (x86)\Norton 360
2011-02-03 21:53:07 ----D---- C:\Program Files (x86)\NortonInstaller
2011-02-03 21:45:00 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-02-03 21:43:09 ----D---- C:\Program Files (x86)\Symantec
2011-02-03 21:43:08 ----D---- C:\ProgramData\Symantec
2011-02-03 21:28:34 ----D---- C:\ProgramData\Norton
2011-02-03 21:22:15 ----D---- C:\ProgramData\NortonInstaller
2011-02-03 19:36:30 ----D---- C:\ProgramData\Kaspersky Lab
2011-02-03 18:20:11 ----D---- C:\rafazon
2011-02-03 17:57:04 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2011-02-02 16:43:24 ----D---- C:\Windows\Roaming
2011-02-02 16:43:24 ----D---- C:\ProgramData\Motive
2011-02-01 13:28:53 ----D---- C:\Program Files (x86)\PFPortChecker
2011-02-01 13:19:33 ----D---- C:\Windows\Simple Port Forwarding
2011-02-01 13:19:33 ----D---- C:\Program Files (x86)\Simple Port Forwarding
2011-02-01 13:19:27 ----A---- C:\Windows\Simple Port Forwarding Setup Log.txt
2011-01-31 17:22:35 ----D---- C:\mineserver
2011-01-31 11:18:27 ----A---- C:\Windows\system32\LMIRfsClientNP.dll
2011-01-31 11:18:27 ----A---- C:\Windows\system32\LMIport.dll
2011-01-31 11:18:27 ----A---- C:\Windows\system32\drivers\LMIRfsDriver.sys
2011-01-31 11:18:22 ----A---- C:\Windows\system32\LMIinit.dll
2011-01-31 11:18:02 ----D---- C:\Program Files (x86)\LogMeIn
2011-01-31 11:12:07 ----AH---- C:\Windows\system32\hamachi.sys
2011-01-31 11:12:05 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-01-29 16:22:39 ----D---- C:\Users\Ondřej\AppData\Roaming\.minecraft
2011-01-29 15:26:40 ----D---- C:\Users\Ondřej\AppData\Roaming\minecraft záloha
2011-01-29 14:44:59 ----D---- C:\Users\Ondřej\AppData\Roaming\.minecraft – kopie
2011-01-29 13:22:29 ----D---- C:\ProgramData\ATI
2011-01-29 13:21:55 ----D---- C:\Program Files (x86)\ATI Stream
2011-01-29 13:21:41 ----D---- C:\ProgramData\AMD
2011-01-29 13:21:39 ----A---- C:\Windows\system32\drivers\amdiox64.sys
2011-01-29 13:21:37 ----D---- C:\Program Files (x86)\ATI Technologies
2011-01-28 17:43:49 ----D---- C:\Program Files\iPod
2011-01-28 17:43:48 ----D---- C:\Program Files\iTunes
2011-01-28 17:43:48 ----D---- C:\Program Files (x86)\iTunes
2011-01-28 15:00:52 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-01-28 14:58:32 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2011-01-28 14:41:41 ----D---- C:\Program Files (x86)\MagicISO
2011-01-28 14:34:23 ----D---- C:\Program Files (x86)\Pixbyte
2011-01-28 13:23:58 ----D---- C:\Users\Ondřej\AppData\Roaming\X-Chat 2
2011-01-28 13:23:40 ----D---- C:\Program Files (x86)\X-Chat 2
2011-01-27 20:58:53 ----D---- C:\Program Files (x86)\CDex
2011-01-27 15:59:30 ----D---- C:\Program Files (x86)\EOM
2011-01-22 19:15:20 ----D---- C:\NST
2011-01-22 19:06:13 ----D---- C:\Program Files (x86)\NeoSmart Technologies
2011-01-22 16:27:21 ----D---- C:\Program Files (x86)\1C
2011-01-22 16:27:21 ----A---- C:\Windows\setup_rangers_2.exe
2011-01-21 17:43:52 ----D---- C:\Users\Ondřej\AppData\Roaming\2.minecraft- starý minecraft
2011-01-19 16:58:29 ----D---- C:\Program Files (x86)\Charles Forsyth
2011-01-18 21:08:19 ----D---- C:\Users\Ondřej\AppData\Roaming\SynthMaker
2011-01-18 21:06:28 ----D---- C:\Users\Ondřej\AppData\Roaming\Acoustica
2011-01-18 21:06:27 ----A---- C:\Windows\SYSWOW64\Wnaspint.dll
2011-01-18 21:05:19 ----D---- C:\Program Files (x86)\Acoustica Shared Effects
2011-01-18 21:00:05 ----D---- C:\Program Files (x86)\VST
2011-01-18 20:09:01 ----D---- C:\Users\Ondřej\AppData\Roaming\PACE Anti-Piracy
2011-01-18 20:09:01 ----D---- C:\ProgramData\PACE Anti-Piracy
2011-01-18 16:00:51 ----D---- C:\ProgramData\PaceAP
2011-01-16 18:22:27 ----D---- C:\Users\Ondřej\AppData\Roaming\CyberLink
2011-01-16 18:22:08 ----D---- C:\ProgramData\CyberLink
2011-01-16 18:18:42 ----D---- C:\ProgramData\SmartSound Software Inc
2011-01-16 18:18:41 ----D---- C:\ProgramData\eSellerate
2011-01-16 18:18:41 ----D---- C:\Program Files (x86)\SmartSound Software
2011-01-16 18:18:21 ----D---- C:\Program Files (x86)\Cyberlink
2011-01-16 18:17:28 ----D---- C:\Program Files\CyberLink
2011-01-16 18:16:20 ----D---- C:\ProgramData\Temp
2011-01-16 18:16:20 ----D---- C:\ProgramData\CLSK
2011-01-15 21:17:21 ----D---- C:\Program Files (x86)\Lame For Audacity
2011-01-15 21:17:02 ----D---- C:\Program Files (x86)\Audacity
2011-01-15 21:15:56 ----D---- C:\Users\Ondřej\AppData\Roaming\Audacity
2011-01-15 21:15:31 ----D---- C:\Program Files (x86)\Audacity 1.3 Beta (Unicode)
2011-01-15 20:51:38 ----D---- C:\Program Files (x86)\MP4Converter
2011-01-15 17:32:05 ----D---- C:\test
2011-01-12 14:30:07 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-01-12 14:30:07 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-01-12 14:30:07 ----A---- C:\Windows\system32\XpsPrint.dll
2011-01-12 14:30:07 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-01-12 14:30:07 ----A---- C:\Windows\system32\mf.dll
2011-01-12 14:30:07 ----A---- C:\Windows\system32\DWrite.dll
2011-01-12 14:30:07 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-12 14:30:07 ----A---- C:\Windows\system32\d2d1.dll
2011-01-12 14:30:06 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-01-12 14:30:06 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-01-12 14:30:06 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-01-12 14:30:06 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-01-12 14:30:06 ----A---- C:\Windows\system32\FntCache.dll
2011-01-12 14:30:05 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-01-12 14:30:05 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-01-12 14:30:05 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-01-12 14:30:05 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-01-12 14:30:05 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-01-12 14:30:05 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-12 14:30:05 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-01-12 14:30:05 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-12 14:30:05 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-01-12 14:30:05 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-12 14:30:04 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-01-12 14:30:04 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-01-12 14:30:04 ----A---- C:\Windows\system32\mfps.dll
2011-01-12 14:30:04 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-01-12 14:30:04 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-12 14:30:04 ----A---- C:\Windows\system32\cdd.dll
2011-01-12 14:30:02 ----A---- C:\Windows\system32\odbc32.dll
2011-01-12 14:30:01 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-01-08 12:33:24 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-01-07 21:48:48 ----D---- C:\ProgramData\Pinnacle Studio Ultimate Collection
2011-01-07 21:39:15 ----D---- C:\ProgramData\Pinnacle
2011-01-07 18:32:44 ----D---- C:\Program Files (x86)\uTorrent
2011-01-07 18:32:02 ----D---- C:\Users\Ondřej\AppData\Roaming\uTorrent
2011-01-05 04:37:14 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2011-01-05 04:22:46 ----A---- C:\Windows\system32\atio6axx.dll
2011-01-05 04:03:34 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2011-01-05 04:02:40 ----A---- C:\Windows\system32\atiapfxx.exe
2011-01-05 03:58:42 ----A---- C:\Windows\system32\ATIDEMGX.dll
2011-01-05 03:58:22 ----A---- C:\Windows\system32\atieclxx.exe
2011-01-05 03:57:44 ----A---- C:\Windows\system32\atiesrxx.exe
2011-01-05 03:56:30 ----A---- C:\Windows\system32\atitmm64.dll
2011-01-05 03:56:10 ----A---- C:\Windows\system32\atipdl64.dll
2011-01-05 03:56:02 ----A---- C:\Windows\SYSWOW64\atipdlxx.dll
2011-01-05 03:55:50 ----A---- C:\Windows\SYSWOW64\Oemdspif.dll
2011-01-05 03:55:46 ----A---- C:\Windows\system32\atimuixx.dll
2011-01-05 03:55:40 ----A---- C:\Windows\system32\atiedu64.dll
2011-01-05 03:55:34 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2011-01-05 03:52:20 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2011-01-05 03:33:30 ----A---- C:\Windows\system32\aticalrt64.dll
2011-01-05 03:33:28 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2011-01-05 03:33:20 ----A---- C:\Windows\system32\aticalcl64.dll
2011-01-05 03:33:16 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2011-01-05 03:33:08 ----A---- C:\Windows\system32\aticaldd64.dll
2011-01-05 03:32:56 ----A---- C:\Windows\system32\atiumd6v.dll
2011-01-05 03:32:22 ----A---- C:\Windows\system32\atiumd6a.dll
2011-01-05 03:31:52 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2011-01-05 03:27:06 ----A---- C:\Windows\system32\atiumd64.dll
2011-01-05 03:20:20 ----A---- C:\Windows\system32\atiadlxx.dll
2011-01-05 03:20:10 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2011-01-05 03:19:58 ----A---- C:\Windows\system32\atig6pxx.dll
2011-01-05 03:19:54 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2011-01-05 03:19:54 ----A---- C:\Windows\system32\atiglpxx.dll
2011-01-05 03:19:52 ----A---- C:\Windows\system32\atig6txx.dll
2011-01-05 03:19:44 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2011-01-05 03:19:38 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2011-01-05 03:18:46 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2011-01-05 03:17:20 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2011-01-05 03:11:10 ----A---- C:\Windows\system32\atimpc64.dll
2011-01-05 03:11:10 ----A---- C:\Windows\system32\amdpcom64.dll
2011-01-05 03:11:00 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2011-01-05 03:11:00 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll

======List of files/folders modified in the last 1 months======

2011-02-04 11:28:50 ----D---- C:\Windows\Temp
2011-02-04 11:14:44 ----D---- C:\Users\Ondřej\AppData\Roaming\Skype
2011-02-04 10:38:51 ----RD---- C:\Program Files
2011-02-04 10:35:46 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-02-04 09:42:11 ----D---- C:\Windows\system32\config
2011-02-04 09:39:41 ----D---- C:\Program Files (x86)\TNod User & Password Finder
2011-02-04 09:32:50 ----SHD---- C:\System Volume Information
2011-02-04 09:30:39 ----D---- C:\Program Files (x86)\Steam
2011-02-04 09:22:12 ----RSD---- C:\Windows\Media
2011-02-04 09:22:12 ----RSD---- C:\Windows\assembly
2011-02-04 09:22:12 ----RD---- C:\Users
2011-02-04 09:22:12 ----RD---- C:\Program Files (x86)
2011-02-04 09:22:12 ----D---- C:\Windows\Tasks
2011-02-04 09:22:12 ----D---- C:\Windows\SYSWOW64\drivers
2011-02-04 09:22:12 ----D---- C:\Windows\SysWOW64
2011-02-04 09:22:12 ----D---- C:\Windows\system32\wfp
2011-02-04 09:22:12 ----D---- C:\Windows\system32\restore
2011-02-04 09:22:12 ----D---- C:\Windows\system32\NDF
2011-02-04 09:22:12 ----D---- C:\Windows\system32\DriverStore
2011-02-04 09:22:12 ----D---- C:\Windows\system32\drivers
2011-02-04 09:22:12 ----D---- C:\Windows\system32\catroot2
2011-02-04 09:22:12 ----D---- C:\Windows\System32
2011-02-04 09:22:12 ----D---- C:\Windows\Offline Web Pages
2011-02-04 09:22:12 ----D---- C:\Windows\Downloaded Program Files
2011-02-04 09:22:12 ----D---- C:\Windows
2011-02-04 09:22:12 ----D---- C:\Program Files\Windows Mail
2011-02-04 09:22:12 ----D---- C:\Program Files (x86)\Windows Mail
2011-02-04 09:22:11 ----D---- C:\Windows\system32\CodeIntegrity
2011-02-04 09:22:10 ----SHD---- C:\Windows\Installer
2011-02-04 09:22:10 ----D---- C:\Windows\RaidTool
2011-02-04 09:22:06 ----RSD---- C:\Windows\Fonts
2011-02-04 09:22:06 ----D---- C:\Windows\inf
2011-02-04 09:22:04 ----D---- C:\Users\Ondřej\AppData\Roaming\vlc
2011-02-04 09:22:04 ----D---- C:\Users\Ondřej\AppData\Roaming\LangSoft
2011-02-04 09:22:01 ----D---- C:\ProgramData\Microsoft Help
2011-02-04 09:22:01 ----D---- C:\ProgramData\FLEXnet
2011-02-04 09:22:00 ----D---- C:\Program Files\ESET
2011-02-04 09:22:00 ----D---- C:\Program Files\AutoCAD 2010
2011-02-04 09:21:59 ----D---- C:\Program Files (x86)\WinZip
2011-02-04 09:21:57 ----RD---- C:\Program Files (x86)\Skype
2011-02-04 09:21:55 ----D---- C:\Program Files (x86)\Realtek
2011-02-04 09:21:55 ----D---- C:\Program Files (x86)\OpenAL
2011-02-04 09:21:55 ----D---- C:\Program Files (x86)\Microsoft Works
2011-02-04 09:21:49 ----D---- C:\Program Files (x86)\Common Files
2011-02-04 09:21:48 ----D---- C:\Program Files (x86)\Bonjour
2011-02-04 09:21:48 ----D---- C:\Program Files (x86)\ASUS
2011-02-04 09:21:46 ----SHD---- C:\$Recycle.Bin
2011-02-04 09:21:26 ----D---- C:\Windows\registration
2011-02-04 09:21:23 ----D---- C:\Windows\system32\Tasks
2011-02-04 09:21:22 ----DC---- C:\Windows\system32\DRVSTORE
2011-02-04 09:21:15 ----D---- C:\Windows\system32\catroot
2011-02-04 09:18:09 ----HD---- C:\ProgramData
2011-02-04 09:18:07 ----D---- C:\ProgramData\ESET
2011-02-04 09:17:59 ----D---- C:\Program Files\Common Files
2011-02-04 09:17:43 ----D---- C:\Program Files (x86)\JDownloader
2011-02-04 08:56:45 ----D---- C:\Windows\Prefetch
2011-02-04 08:22:33 ----D---- C:\Users\Ondřej\AppData\Roaming\skypePM
2011-02-04 07:45:50 ----D---- C:\Windows\system32\LogFiles
2011-02-02 18:56:38 ----A---- C:\LOGFILE.TXT
2011-02-02 17:11:20 ----N---- C:\Windows\system32\MpSigStub.exe
2011-01-31 11:11:21 ----D---- C:\Users\Ondřej\AppData\Roaming\Hamachi
2011-01-29 17:59:06 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-01-29 13:21:47 ----D---- C:\Program Files\ATI Technologies
2011-01-28 13:41:12 ----D---- C:\Users\Ondřej\AppData\Roaming\Mumble
2011-01-28 13:40:51 ----D---- C:\Program Files (x86)\Mumble
2011-01-26 20:16:10 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-01-24 21:49:40 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-01-20 17:59:29 ----D---- C:\ostatni
2011-01-18 20:54:51 ----ASD---- C:\ProgramData\Microsoft
2011-01-18 20:00:20 ----D---- C:\Windows\winsxs
2011-01-16 18:18:44 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-01-15 14:43:23 ----D---- C:\Program Files (x86)\Any DWG to Image Converter
2011-01-12 14:30:59 ----A---- C:\Windows\system32\MRT.exe
2011-01-09 16:29:08 ----D---- C:\Program Files (x86)\Warcraft III
2011-01-08 18:17:19 ----D---- C:\Windows\system32\wbem
2011-01-08 18:01:19 ----D---- C:\Windows\system
2011-01-08 17:13:35 ----D---- C:\Program Files\Creative
2011-01-08 17:13:32 ----HD---- C:\Program Files (x86)\Creative Installation Information
2011-01-08 17:13:21 ----N---- C:\Windows\SYSWOW64\wrap_oal.dll
2011-01-08 17:13:21 ----N---- C:\Windows\SYSWOW64\OpenAL32.dll
2011-01-08 17:13:21 ----A---- C:\Windows\system32\wrap_oal.dll
2011-01-08 17:13:21 ----A---- C:\Windows\system32\OpenAL32.dll
2011-01-08 17:11:56 ----A---- C:\CTSUFile.txt
2011-01-06 19:18:33 ----D---- C:\Windows\system32\wdi
2011-01-05 04:02:28 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2011-01-05 04:01:12 ----A---- C:\Windows\system32\aticfx64.dll
2011-01-05 03:43:20 ----A---- C:\Windows\system32\atidxx64.dll
2011-01-05 03:33:20 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2011-01-05 03:28:08 ----A---- C:\Windows\system32\coinst.dll
2011-01-05 03:25:04 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2011-01-05 03:18:52 ----A---- C:\Windows\system32\atiuxp64.dll
2011-01-05 03:18:34 ----A---- C:\Windows\system32\atiu9p64.dll
2011-01-05 03:18:26 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-01-11 115824]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-31 834544]
R0 Tpkd;Tpkd; C:\Windows\system32\drivers\Tpkd.sys [2010-09-30 105592]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-28 254528]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-04-28 139704]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-08-02 314016]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-06-24 166984]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-04-28 169592]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-04-28 50600]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-08-02 43680]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [2010-09-17 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2010-09-17 72216]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-01-05 8283136]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-01-05 294400]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-11-17 115216]
R3 Ctafiltv;Ctafiltv; C:\Windows\system32\drivers\Ctafiltv.sys [2008-08-14 24064]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-04-28 33608]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-02-03 33856]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-01-29 2260256]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\LGBusEnum.sys [2009-11-23 22408]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver; C:\Windows\system32\drivers\LGVirHid.sys [2009-11-23 16008]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2010-03-18 63568]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2010-09-17 11552]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2010-03-18 57936]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-01-22 77824]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-01-22 180224]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-10-19 39480]
S3 ALSysIO;ALSysIO; \??\C:\Users\ONDEJ~1\AppData\Local\Temp\ALSysIO64.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
S3 cmudaxp;ASUS Xonar DX Audio Interface; C:\Windows\system32\drivers\cmudaxp.sys []
S3 cpuz130;cpuz130; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys []
S3 ENTECH64;ENTECH64; \??\C:\Windows\system32\DRIVERS\ENTECH64.sys [2008-09-17 12744]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2010-09-28 51712]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-01-05 203776]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-01-04 354304]
R2 AMD Reservation Manager;AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-01-05 37664]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-12-28 96896]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-07-27 345376]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2009-02-23 307200]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2010-07-02 810144]
R2 IObitBarService;IObit Toolbar Service; C:\PROGRA~2\IObitBar\toolbar\1.bin\i0barsvc.exe [2010-09-21 28766]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-12-08 373640]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-01-24 75136]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2010-08-19 386344]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-09-29 136176]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2010-12-06 2101640]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-08-03 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-08-03 79360]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-07-02 42360]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-11-03 1030600]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-08-19 654848]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-01-25 933664]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2010-05-06 357456]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-01-23 407336]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-07-22 1255736]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework64\v4.0.21006\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.21006\WPF\WPFFontCache_v0400.exe []
S4 AODService;AODService; C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [2010-07-01 136616]
S4 LMIMaint;LogMeIn Maintenance Service; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [2010-12-08 147336]
S4 LogMeIn;LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [2010-11-08 407424]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.21006\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.21006\SMSvcHost.exe -NetMsmqActivator []
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.21006\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.21006\SMSvcHost.exe []
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.21006\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.21006\SMSvcHost.exe []

-----------------EOF-----------------

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 11:59
od Caroprd111
Zdravím :)

Podle pravidel fóra se zde nelegálním softwarem nezabýváme (nelegální programy představují bezpečnostní hrozbu).
Obstarejte si legální zabezpečení PC (antivir, firewall), poté sem vložte nový log z RSIT a log z CKScanner a WVCheck.

Vyberte si třeba free Aviru nebo Avast + nějaký firewall (doporučuji ZoneAlarm) http://www.viry.cz/forum/viewtopic.php?f=29&t=6152 + http://www.viry.cz/forum/viewtopic.php?f=41&t=6523

Obrázek Stáhněte na plochu CKScanner http://downloads.malwareremoval.com/CKScanner.exe
  • Spusťte a klikněte na "Search For Files", po dokončení skenu klikněte na "Save List to File" -> "OK"
  • Log s názvem ckfiles.txt bude uložený na ploše, obsah tohoto souboru sem vložte.

Obrázek Stáhněte a spusťte WVCheck.exe nebo WVCheck.zip
  • Stiskněte "Enter".
  • Program začne prohledávat PC, délka skenu závisí na množství(velikosti) souborů, ale obvykle netrvá déle, než 5 minut.
  • Po dokončení skenu na Vás vyskočí log, ten vložte do topicu. Log je také uložený na ploše.

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 15:49
od Foxtrot
Teď mám trial NOD32 a ZoneAlarm free.



Log z RSIT:

Logfile of random's system information tool 1.08 (written by random/random)
Run by Ondřej at 2011-02-04 15:45:02
Microsoft Windows 7 Home Premium
System drive C: has 209 GB (23%) free of 919 GB
Total RAM: 6142 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:45:04, on 4.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Windows\DAODx.exe
C:\Program Files\ASUS\TurboV EVO\TurboVHELP.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Ondřej.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {7757CBCC-0975-4b79-A519-90B142CA3A23} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0SrcAs.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Toolbar BHO - {EFA17361-CDC0-4927-9AFC-BAAD1F96B2AE} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll
O3 - Toolbar: IObit Toolbar - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O15 - Trusted IP range: http://5.0.0.1
O15 - ESC Trusted IP range: http://5.0.0.1
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AMD Reservation Manager - Advanced Micro Devices - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: IObit Toolbar Service (IObitBarService) - IObit - C:\PROGRA~2\IObitBar\toolbar\1.bin\i0barsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @C:\Windows\Microsoft.NET\Framework64\v4.0.21006\WPF\WPFFontCache_v0400.exe,-100 (WPFFontCache_v0400) - Unknown owner - C:\Windows\Microsoft.NET\Framework64\v4.0.21006\WPF\WPFFontCache_v0400.exe (file missing)

--
End of file - 10444 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe"
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-48623e4a-b2c0-460f-873c-9bb6618c85fc -SystemEventPortName:HostProcess-59126f5d-bb1d-4457-9c7f-65a3cf6e5805 -IoCancelEventPortName:HostProcess-4acb2e86-f158-4024-b1b4-86f407569ff4 -NonStateChangingEventPortName:HostProcess-9210f8ad-c8c5-4416-9e4a-c52863b7bab3 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:71dcd475-80c6-4ec5-801b-39f21253947f
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0606e828-5678-46ef-8949-47f414355a8d -SystemEventPortName:HostProcess-23c58211-b310-4e5e-9f05-8f302eded121 -IoCancelEventPortName:HostProcess-03767cf0-9f27-4b68-9acc-07322e35050a -NonStateChangingEventPortName:HostProcess-11881ec8-140e-4e0e-b7b6-3ca6d8aed0ef -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:80f5fa24-61ba-4d04-beec-81182de88464
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\SysWOW64\ZoneLabs\vsmon.exe -service
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\svchost.exe -k Akamai
"C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe"
taskeng.exe {3B7989C7-DFCC-4DEF-A729-3E9B014F95CD}
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe"
C:\Windows\DAODx.exe
"C:\Program Files\ASUS\TurboV EVO\TurboVHELP.exe"
"C:\Program Files (x86)\Bonjour\mDNSResponder.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
C:\PROGRA~2\IObitBar\toolbar\1.bin\i0barsvc.exe
"C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\Windows\system32\CNAC4RPD.EXE
C:\Windows\system32\SearchIndexer.exe /Embedding
WLIDSvcM.exe 2728
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\WMPSideShowGadget.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /SkipFUE /RemoteOCXLaunch
"taskhost.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3880.d3f8fa0.1409182866 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" 3880 plugin \\.\pipe\gecko-crash-server-pipe.3880
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\ostatni\stažené soubory (Firefox)\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

======Scheduled tasks folder======

C:\Windows\tasks\AWC AutoSweep.job
C:\Windows\tasks\AWC Update.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-11-24 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EFA17361-CDC0-4927-9AFC-BAAD1F96B2AE}]
Toolbar BHO - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll [2010-09-21 638976]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - IObit Toolbar - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll [2010-09-21 638976]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-11-16 500208]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2011-01-12 2918656]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-07-22 402432]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe [2010-03-04 311296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CtaMon]
Rundll32 CtaMon.dll,RunMonitor []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EvtMgr6]
C:\Program Files\Logitech\SetPointP\SetPoint.exe [2010-06-26 1609296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IObitBar Browser Plugin Loader]
C:\PROGRA~2\IObitBar\toolbar\1.bin\i0brmon.exe [2010-09-21 20480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-01-25 421160]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\Windows\RaidTool\xInsIDE.exe [2010-01-19 43632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCDMon]
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe [2010-08-03 2412616]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LGDCore]
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe [2010-08-03 4725320]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LgDeviceAgent]
C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe [2010-08-03 415816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [2010-09-17 57928]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2010-12-06 1910152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NUSB3MON]
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-01-22 106496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OutpostFeedBack]
C:\Program Files\Agnitum\Outpost Firewall Pro\feedback.exe /dump:os_startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OutpostMonitor]
C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe /tray /noservice []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-01-29 10038304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Six Engine]
C:\Program Files (x86)\ASUS\EPU\EPU.exe [2010-03-16 5309056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2010-10-11 14940040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartRAM]
C:\Program Files (x86)\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe /m []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-01-04 336384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\program files (x86)\steam\steam.exe [2010-11-16 1242448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TurboV EVO]
C:\Program Files\ASUS\TurboV EVO\TurboV_EVO.exe [2010-04-07 9919104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
C:\Program Files (x86)\Creative\SB Arena Surround Headset\Volume Panel\VolPanlu.exe [2009-05-04 241789]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Canon LBP5000 Status Window.lnk]
C:\Windows\System32\spool\drivers\x64\3\CNAC4LAD.EXE [2010-02-04 60384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Ondřej^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Registrace produktu.lnk]
C:\PROGRA~2\COMMON~1\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Ondřej^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~2\MICROS~1\Office12\ONENOTEM.EXE [2009-02-26 97680]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"ZoneAlarm Client"=C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe [2010-11-16 1043968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2010-05-06 66640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe","%1"
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2011-02-04 14:22:38 ----A---- C:\Windows\SYSWOW64\vsregexp.dll
2011-02-04 14:22:33 ----A---- C:\Windows\SYSWOW64\zlcommdb.dll
2011-02-04 14:22:32 ----A---- C:\Windows\SYSWOW64\zlcomm.dll
2011-02-04 14:22:29 ----A---- C:\Windows\SYSWOW64\vswmi.dll
2011-02-04 14:22:28 ----A---- C:\Windows\SYSWOW64\zpeng25.dll
2011-02-04 14:22:28 ----A---- C:\Windows\SYSWOW64\vsxml.dll
2011-02-04 14:22:27 ----D---- C:\Windows\SYSWOW64\ZoneLabs
2011-02-04 14:22:27 ----A---- C:\Windows\SYSWOW64\vspubapi.dll
2011-02-04 14:22:27 ----A---- C:\Windows\SYSWOW64\vsmonapi.dll
2011-02-04 14:22:27 ----A---- C:\Windows\SYSWOW64\vsdata.dll
2011-02-04 14:22:27 ----A---- C:\Windows\system32\drivers\~GLH0024.TMP
2011-02-04 14:22:20 ----N---- C:\Windows\system32\drivers\vsdatant.sys
2011-02-04 14:22:20 ----D---- C:\Program Files (x86)\Zone Labs
2011-02-04 14:21:55 ----A---- C:\Windows\SYSWOW64\vsutil.dll
2011-02-04 14:21:55 ----A---- C:\Windows\SYSWOW64\vsinit.dll
2011-02-04 13:50:39 ----D---- C:\Windows\Internet Logs
2011-02-04 13:27:50 ----D---- C:\Users\Ondřej\AppData\Roaming\CheckPoint
2011-02-04 13:27:07 ----D---- C:\Program Files (x86)\Conduit
2011-02-04 13:26:53 ----D---- C:\Program Files\CheckPoint
2011-02-04 13:25:47 ----A---- C:\Windows\system32\drivers\netio.sys
2011-02-04 13:24:29 ----A---- C:\Windows\system32\drivers\~GLH0023.TMP
2011-02-04 13:23:56 ----D---- C:\ProgramData\CheckPoint
2011-02-04 12:21:40 ----D---- C:\ProgramData\ESET
2011-02-04 12:21:40 ----D---- C:\Program Files\ESET
2011-02-04 12:05:04 ----A---- C:\Windows\ntbtlog.txt
2011-02-04 10:38:51 ----D---- C:\rsit
2011-02-04 10:38:51 ----D---- C:\Program Files\trend micro
2011-02-04 08:37:34 ----D---- C:\Windows\system32\drivers\N360x64
2011-02-03 21:55:00 ----D---- C:\Program Files (x86)\Norton 360
2011-02-03 21:53:07 ----D---- C:\Program Files (x86)\NortonInstaller
2011-02-03 21:45:00 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-02-03 21:43:09 ----D---- C:\Program Files (x86)\Symantec
2011-02-03 21:43:08 ----D---- C:\ProgramData\Symantec
2011-02-03 21:28:34 ----D---- C:\ProgramData\Norton
2011-02-03 21:22:15 ----D---- C:\ProgramData\NortonInstaller
2011-02-03 19:36:30 ----D---- C:\ProgramData\Kaspersky Lab
2011-02-03 18:20:11 ----D---- C:\rafazon
2011-02-03 17:57:04 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2011-02-02 16:43:24 ----D---- C:\Windows\Roaming
2011-02-02 16:43:24 ----D---- C:\ProgramData\Motive
2011-02-01 13:28:53 ----D---- C:\Program Files (x86)\PFPortChecker
2011-02-01 13:19:33 ----D---- C:\Windows\Simple Port Forwarding
2011-02-01 13:19:33 ----D---- C:\Program Files (x86)\Simple Port Forwarding
2011-02-01 13:19:27 ----A---- C:\Windows\Simple Port Forwarding Setup Log.txt
2011-01-31 17:22:35 ----D---- C:\mineserver
2011-01-31 11:18:27 ----A---- C:\Windows\system32\LMIRfsClientNP.dll
2011-01-31 11:18:27 ----A---- C:\Windows\system32\LMIport.dll
2011-01-31 11:18:27 ----A---- C:\Windows\system32\drivers\LMIRfsDriver.sys
2011-01-31 11:18:22 ----A---- C:\Windows\system32\LMIinit.dll
2011-01-31 11:18:02 ----D---- C:\Program Files (x86)\LogMeIn
2011-01-31 11:12:07 ----AH---- C:\Windows\system32\hamachi.sys
2011-01-31 11:12:05 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-01-29 16:22:39 ----D---- C:\Users\Ondřej\AppData\Roaming\.minecraft
2011-01-29 15:26:40 ----D---- C:\Users\Ondřej\AppData\Roaming\minecraft záloha
2011-01-29 14:44:59 ----D---- C:\Users\Ondřej\AppData\Roaming\.minecraft – kopie
2011-01-29 13:22:29 ----D---- C:\ProgramData\ATI
2011-01-29 13:21:55 ----D---- C:\Program Files (x86)\ATI Stream
2011-01-29 13:21:41 ----D---- C:\ProgramData\AMD
2011-01-29 13:21:39 ----A---- C:\Windows\system32\drivers\amdiox64.sys
2011-01-29 13:21:37 ----D---- C:\Program Files (x86)\ATI Technologies
2011-01-28 17:43:49 ----D---- C:\Program Files\iPod
2011-01-28 17:43:48 ----D---- C:\Program Files\iTunes
2011-01-28 17:43:48 ----D---- C:\Program Files (x86)\iTunes
2011-01-28 15:00:52 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-01-28 14:58:32 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2011-01-28 14:41:41 ----D---- C:\Program Files (x86)\MagicISO
2011-01-28 14:34:23 ----D---- C:\Program Files (x86)\Pixbyte
2011-01-28 13:23:58 ----D---- C:\Users\Ondřej\AppData\Roaming\X-Chat 2
2011-01-28 13:23:40 ----D---- C:\Program Files (x86)\X-Chat 2
2011-01-27 20:58:53 ----D---- C:\Program Files (x86)\CDex
2011-01-27 15:59:30 ----D---- C:\Program Files (x86)\EOM
2011-01-22 19:15:20 ----D---- C:\NST
2011-01-22 19:06:13 ----D---- C:\Program Files (x86)\NeoSmart Technologies
2011-01-22 16:27:21 ----D---- C:\Program Files (x86)\1C
2011-01-22 16:27:21 ----A---- C:\Windows\setup_rangers_2.exe
2011-01-21 17:43:52 ----D---- C:\Users\Ondřej\AppData\Roaming\2.minecraft- starý minecraft
2011-01-19 16:58:29 ----D---- C:\Program Files (x86)\Charles Forsyth
2011-01-18 21:08:19 ----D---- C:\Users\Ondřej\AppData\Roaming\SynthMaker
2011-01-18 21:06:28 ----D---- C:\Users\Ondřej\AppData\Roaming\Acoustica
2011-01-18 21:06:27 ----A---- C:\Windows\SYSWOW64\Wnaspint.dll
2011-01-18 21:05:19 ----D---- C:\Program Files (x86)\Acoustica Shared Effects
2011-01-18 21:00:05 ----D---- C:\Program Files (x86)\VST
2011-01-18 20:09:01 ----D---- C:\Users\Ondřej\AppData\Roaming\PACE Anti-Piracy
2011-01-18 20:09:01 ----D---- C:\ProgramData\PACE Anti-Piracy
2011-01-18 16:00:51 ----D---- C:\ProgramData\PaceAP
2011-01-16 18:22:27 ----D---- C:\Users\Ondřej\AppData\Roaming\CyberLink
2011-01-16 18:22:08 ----D---- C:\ProgramData\CyberLink
2011-01-16 18:18:42 ----D---- C:\ProgramData\SmartSound Software Inc
2011-01-16 18:18:41 ----D---- C:\ProgramData\eSellerate
2011-01-16 18:18:41 ----D---- C:\Program Files (x86)\SmartSound Software
2011-01-16 18:18:21 ----D---- C:\Program Files (x86)\Cyberlink
2011-01-16 18:17:28 ----D---- C:\Program Files\CyberLink
2011-01-16 18:16:20 ----D---- C:\ProgramData\Temp
2011-01-16 18:16:20 ----D---- C:\ProgramData\CLSK
2011-01-15 21:17:21 ----D---- C:\Program Files (x86)\Lame For Audacity
2011-01-15 21:17:02 ----D---- C:\Program Files (x86)\Audacity
2011-01-15 21:15:56 ----D---- C:\Users\Ondřej\AppData\Roaming\Audacity
2011-01-15 21:15:31 ----D---- C:\Program Files (x86)\Audacity 1.3 Beta (Unicode)
2011-01-15 20:51:38 ----D---- C:\Program Files (x86)\MP4Converter
2011-01-15 17:32:05 ----D---- C:\test
2011-01-12 14:30:07 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-01-12 14:30:07 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-01-12 14:30:07 ----A---- C:\Windows\system32\XpsPrint.dll
2011-01-12 14:30:07 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-01-12 14:30:07 ----A---- C:\Windows\system32\mf.dll
2011-01-12 14:30:07 ----A---- C:\Windows\system32\DWrite.dll
2011-01-12 14:30:07 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-12 14:30:07 ----A---- C:\Windows\system32\d2d1.dll
2011-01-12 14:30:06 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-01-12 14:30:06 ----A---- C:\Windows\SYSWOW64\mf.dll
2011-01-12 14:30:06 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-01-12 14:30:06 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-01-12 14:30:06 ----A---- C:\Windows\system32\FntCache.dll
2011-01-12 14:30:05 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-01-12 14:30:05 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2011-01-12 14:30:05 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2011-01-12 14:30:05 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-01-12 14:30:05 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-01-12 14:30:05 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-12 14:30:05 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-01-12 14:30:05 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-12 14:30:05 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-01-12 14:30:05 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-12 14:30:04 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-01-12 14:30:04 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-01-12 14:30:04 ----A---- C:\Windows\system32\mfps.dll
2011-01-12 14:30:04 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-01-12 14:30:04 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-12 14:30:04 ----A---- C:\Windows\system32\cdd.dll
2011-01-12 14:30:02 ----A---- C:\Windows\system32\odbc32.dll
2011-01-12 14:30:01 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-01-08 12:33:24 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-01-07 21:48:48 ----D---- C:\ProgramData\Pinnacle Studio Ultimate Collection
2011-01-07 21:39:15 ----D---- C:\ProgramData\Pinnacle
2011-01-07 18:32:44 ----D---- C:\Program Files (x86)\uTorrent
2011-01-07 18:32:02 ----D---- C:\Users\Ondřej\AppData\Roaming\uTorrent
2011-01-05 04:37:14 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2011-01-05 04:22:46 ----A---- C:\Windows\system32\atio6axx.dll
2011-01-05 04:03:34 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2011-01-05 04:02:40 ----A---- C:\Windows\system32\atiapfxx.exe
2011-01-05 03:58:42 ----A---- C:\Windows\system32\ATIDEMGX.dll
2011-01-05 03:58:22 ----A---- C:\Windows\system32\atieclxx.exe
2011-01-05 03:57:44 ----A---- C:\Windows\system32\atiesrxx.exe
2011-01-05 03:56:30 ----A---- C:\Windows\system32\atitmm64.dll
2011-01-05 03:56:10 ----A---- C:\Windows\system32\atipdl64.dll
2011-01-05 03:56:02 ----A---- C:\Windows\SYSWOW64\atipdlxx.dll
2011-01-05 03:55:50 ----A---- C:\Windows\SYSWOW64\Oemdspif.dll
2011-01-05 03:55:46 ----A---- C:\Windows\system32\atimuixx.dll
2011-01-05 03:55:40 ----A---- C:\Windows\system32\atiedu64.dll
2011-01-05 03:55:34 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2011-01-05 03:52:20 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2011-01-05 03:33:30 ----A---- C:\Windows\system32\aticalrt64.dll
2011-01-05 03:33:28 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2011-01-05 03:33:20 ----A---- C:\Windows\system32\aticalcl64.dll
2011-01-05 03:33:16 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2011-01-05 03:33:08 ----A---- C:\Windows\system32\aticaldd64.dll
2011-01-05 03:32:56 ----A---- C:\Windows\system32\atiumd6v.dll
2011-01-05 03:32:22 ----A---- C:\Windows\system32\atiumd6a.dll
2011-01-05 03:31:52 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2011-01-05 03:27:06 ----A---- C:\Windows\system32\atiumd64.dll
2011-01-05 03:20:20 ----A---- C:\Windows\system32\atiadlxx.dll
2011-01-05 03:20:10 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2011-01-05 03:19:58 ----A---- C:\Windows\system32\atig6pxx.dll
2011-01-05 03:19:54 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2011-01-05 03:19:54 ----A---- C:\Windows\system32\atiglpxx.dll
2011-01-05 03:19:52 ----A---- C:\Windows\system32\atig6txx.dll
2011-01-05 03:19:44 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2011-01-05 03:19:38 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2011-01-05 03:18:46 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2011-01-05 03:17:20 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2011-01-05 03:11:10 ----A---- C:\Windows\system32\atimpc64.dll
2011-01-05 03:11:10 ----A---- C:\Windows\system32\amdpcom64.dll
2011-01-05 03:11:00 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2011-01-05 03:11:00 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll

======List of files/folders modified in the last 1 months======

2011-02-04 15:45:02 ----D---- C:\Windows\Temp
2011-02-04 15:44:34 ----D---- C:\Windows\Tasks
2011-02-04 15:41:12 ----RD---- C:\Program Files (x86)
2011-02-04 14:28:59 ----D---- C:\Windows\system32\config
2011-02-04 14:25:29 ----RD---- C:\Program Files
2011-02-04 14:24:32 ----D---- C:\Windows\system32\catroot
2011-02-04 14:22:38 ----D---- C:\Windows\SysWOW64
2011-02-04 14:22:35 ----D---- C:\Windows
2011-02-04 14:22:27 ----D---- C:\Windows\SYSWOW64\drivers
2011-02-04 14:22:27 ----D---- C:\Windows\system32\drivers
2011-02-04 14:22:25 ----D---- C:\Windows\inf
2011-02-04 14:22:22 ----D---- C:\Windows\system32\DriverStore
2011-02-04 14:21:31 ----HD---- C:\ProgramData
2011-02-04 14:21:30 ----D---- C:\Windows\System32
2011-02-04 14:19:58 ----SHD---- C:\System Volume Information
2011-02-04 14:19:26 ----D---- C:\Users\Ondřej\AppData\Roaming\Skype
2011-02-04 14:17:58 ----D---- C:\Program Files (x86)\Steam
2011-02-04 13:57:23 ----D---- C:\Windows\system32\catroot2
2011-02-04 13:57:09 ----SHD---- C:\Windows\Installer
2011-02-04 13:51:16 ----D---- C:\Windows\Prefetch
2011-02-04 13:50:59 ----D---- C:\Users\Ondřej\AppData\Roaming\skypePM
2011-02-04 13:26:06 ----D---- C:\Windows\winsxs
2011-02-04 12:03:02 ----D---- C:\Users\Ondřej\AppData\Roaming\ESET
2011-02-04 10:35:46 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-02-04 09:22:12 ----RSD---- C:\Windows\Media
2011-02-04 09:22:12 ----RSD---- C:\Windows\assembly
2011-02-04 09:22:12 ----RD---- C:\Users
2011-02-04 09:22:12 ----D---- C:\Windows\system32\wfp
2011-02-04 09:22:12 ----D---- C:\Windows\system32\restore
2011-02-04 09:22:12 ----D---- C:\Windows\system32\NDF
2011-02-04 09:22:12 ----D---- C:\Windows\Offline Web Pages
2011-02-04 09:22:12 ----D---- C:\Windows\Downloaded Program Files
2011-02-04 09:22:12 ----D---- C:\Program Files\Windows Mail
2011-02-04 09:22:12 ----D---- C:\Program Files (x86)\Windows Mail
2011-02-04 09:22:11 ----D---- C:\Windows\system32\CodeIntegrity
2011-02-04 09:22:10 ----D---- C:\Windows\RaidTool
2011-02-04 09:22:06 ----RSD---- C:\Windows\Fonts
2011-02-04 09:22:04 ----D---- C:\Users\Ondřej\AppData\Roaming\vlc
2011-02-04 09:22:04 ----D---- C:\Users\Ondřej\AppData\Roaming\LangSoft
2011-02-04 09:22:01 ----D---- C:\ProgramData\Microsoft Help
2011-02-04 09:22:01 ----D---- C:\ProgramData\FLEXnet
2011-02-04 09:22:00 ----D---- C:\Program Files\AutoCAD 2010
2011-02-04 09:21:59 ----D---- C:\Program Files (x86)\WinZip
2011-02-04 09:21:57 ----RD---- C:\Program Files (x86)\Skype
2011-02-04 09:21:55 ----D---- C:\Program Files (x86)\Realtek
2011-02-04 09:21:55 ----D---- C:\Program Files (x86)\OpenAL
2011-02-04 09:21:55 ----D---- C:\Program Files (x86)\Microsoft Works
2011-02-04 09:21:49 ----D---- C:\Program Files (x86)\Common Files
2011-02-04 09:21:48 ----D---- C:\Program Files (x86)\Bonjour
2011-02-04 09:21:48 ----D---- C:\Program Files (x86)\ASUS
2011-02-04 09:21:46 ----SHD---- C:\$Recycle.Bin
2011-02-04 09:21:26 ----D---- C:\Windows\registration
2011-02-04 09:21:23 ----D---- C:\Windows\system32\Tasks
2011-02-04 09:21:22 ----DC---- C:\Windows\system32\DRVSTORE
2011-02-04 09:17:59 ----D---- C:\Program Files\Common Files
2011-02-04 09:17:43 ----D---- C:\Program Files (x86)\JDownloader
2011-02-04 07:45:50 ----D---- C:\Windows\system32\LogFiles
2011-02-02 18:56:38 ----A---- C:\LOGFILE.TXT
2011-02-02 17:11:20 ----N---- C:\Windows\system32\MpSigStub.exe
2011-01-31 11:11:21 ----D---- C:\Users\Ondřej\AppData\Roaming\Hamachi
2011-01-29 17:59:06 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-01-29 13:21:47 ----D---- C:\Program Files\ATI Technologies
2011-01-28 13:41:12 ----D---- C:\Users\Ondřej\AppData\Roaming\Mumble
2011-01-28 13:40:51 ----D---- C:\Program Files (x86)\Mumble
2011-01-26 20:16:10 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-01-24 21:49:40 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-01-20 17:59:29 ----D---- C:\ostatni
2011-01-18 20:54:51 ----ASD---- C:\ProgramData\Microsoft
2011-01-16 18:18:44 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-01-15 14:43:23 ----D---- C:\Program Files (x86)\Any DWG to Image Converter
2011-01-12 14:30:59 ----A---- C:\Windows\system32\MRT.exe
2011-01-09 16:29:08 ----D---- C:\Program Files (x86)\Warcraft III
2011-01-08 18:17:19 ----D---- C:\Windows\system32\wbem
2011-01-08 18:01:19 ----D---- C:\Windows\system
2011-01-08 17:13:35 ----D---- C:\Program Files\Creative
2011-01-08 17:13:32 ----HD---- C:\Program Files (x86)\Creative Installation Information
2011-01-08 17:13:21 ----N---- C:\Windows\SYSWOW64\wrap_oal.dll
2011-01-08 17:13:21 ----N---- C:\Windows\SYSWOW64\OpenAL32.dll
2011-01-08 17:13:21 ----A---- C:\Windows\system32\wrap_oal.dll
2011-01-08 17:13:21 ----A---- C:\Windows\system32\OpenAL32.dll
2011-01-08 17:11:56 ----A---- C:\CTSUFile.txt
2011-01-06 19:18:33 ----D---- C:\Windows\system32\wdi
2011-01-05 04:02:28 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2011-01-05 04:01:12 ----A---- C:\Windows\system32\aticfx64.dll
2011-01-05 03:43:20 ----A---- C:\Windows\system32\atidxx64.dll
2011-01-05 03:33:20 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2011-01-05 03:28:08 ----A---- C:\Windows\system32\coinst.dll
2011-01-05 03:25:04 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2011-01-05 03:18:52 ----A---- C:\Windows\system32\atiuxp64.dll
2011-01-05 03:18:34 ----A---- C:\Windows\system32\atiu9p64.dll
2011-01-05 03:18:26 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-01-11 115824]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-31 834544]
R0 Tpkd;Tpkd; C:\Windows\system32\drivers\Tpkd.sys [2010-09-30 105592]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-28 254528]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 141264]
R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2010-05-15 458840]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-08-02 314016]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 170640]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2010-12-21 125296]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-08-02 43680]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [2010-09-17 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2010-09-17 72216]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-01-05 8283136]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-01-05 294400]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-11-17 115216]
R3 Ctafiltv;Ctafiltv; C:\Windows\system32\drivers\Ctafiltv.sys [2008-08-14 24064]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-02-03 33856]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-01-29 2260256]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\LGBusEnum.sys [2009-11-23 22408]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2010-03-18 63568]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2010-09-17 11552]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2010-03-18 57936]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-01-22 77824]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-01-22 180224]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-10-19 39480]
S3 ALSysIO;ALSysIO; \??\C:\Users\ONDEJ~1\AppData\Local\Temp\ALSysIO64.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
S3 cmudaxp;ASUS Xonar DX Audio Interface; C:\Windows\system32\drivers\cmudaxp.sys []
S3 cpuz130;cpuz130; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys []
S3 ENTECH64;ENTECH64; \??\C:\Windows\system32\DRIVERS\ENTECH64.sys [2008-09-17 12744]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver; C:\Windows\system32\drivers\LGVirHid.sys [2009-11-23 16008]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2010-09-28 51712]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-01-05 203776]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-01-04 354304]
R2 AMD Reservation Manager;AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-01-05 37664]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-12-28 96896]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-07-27 345376]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2009-02-23 307200]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2011-01-12 810144]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2010-12-06 2101640]
R2 IObitBarService;IObit Toolbar Service; C:\PROGRA~2\IObitBar\toolbar\1.bin\i0barsvc.exe [2010-09-21 28766]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-12-08 373640]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-01-24 75136]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2010-08-19 386344]
R2 vsmon;TrueVector Internet Monitor; C:\Windows\SysWOW64\ZoneLabs\vsmon.exe [2010-11-16 2435592]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-09-29 136176]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-08-03 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-08-03 79360]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2011-01-12 42360]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-11-03 1030600]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-08-19 654848]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-01-25 933664]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2010-05-06 357456]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-01-23 407336]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-07-22 1255736]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework64\v4.0.21006\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.21006\WPF\WPFFontCache_v0400.exe []
S4 AODService;AODService; C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [2010-07-01 136616]
S4 LMIMaint;LogMeIn Maintenance Service; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [2010-12-08 147336]
S4 LogMeIn;LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [2010-11-08 407424]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.21006\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.21006\SMSvcHost.exe -NetMsmqActivator []
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.21006\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.21006\SMSvcHost.exe []
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.21006\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.21006\SMSvcHost.exe []

-----------------EOF-----------------



Log z CKScanner:

CKScanner - Additional Security Risks - These are not necessarily bad
c:\ostatni\archiv\oblivion\oblivion\oblivion\the elder scrolls 4 oblivion\crack\oblivion.exe
c:\program files (x86)\adobe\adobe dreamweaver cs5\configuration\taglibraries\html\keygen.vtm
c:\program files (x86)\jdownloader\jd\plugins\hoster\crackedcom.class
c:\program files (x86)\rockstar games\gta san andreas\data\decision\craig\crack1.ped
c:\program files (x86)\steam\steamapps\common\call of duty black ops\zone\common\mp_cracked.ff
c:\program files (x86)\steam\steamapps\common\call of duty black ops\zone\english\en_mp_cracked.ff
c:\program files (x86)\steam\steamapps\fire16\garrysmod\garrysmod\addons\ls_petrol\lua\entities\crackingtower\cl_init.lua
c:\program files (x86)\steam\steamapps\fire16\garrysmod\garrysmod\addons\ls_petrol\lua\entities\crackingtower\init.lua
c:\program files (x86)\steam\steamapps\fire16\garrysmod\garrysmod\addons\ls_petrol\lua\entities\crackingtower\shared.lua
c:\program files (x86)\steam\steamapps\fire16\garrysmod\garrysmod\addons\pcmod2\lua\weapons\pcmod_pwcrack\shared.lua
c:\program files (x86)\steam\steamapps\fire16\garrysmod\garrysmod\addons\sbep_models\models\slyfo\rover1_glasscrack.dx80.vtx
c:\program files (x86)\steam\steamapps\fire16\garrysmod\garrysmod\addons\sbep_models\models\slyfo\rover1_glasscrack.dx90.vtx
c:\program files (x86)\steam\steamapps\fire16\garrysmod\garrysmod\addons\sbep_models\models\slyfo\rover1_glasscrack.mdl
c:\program files (x86)\steam\steamapps\fire16\garrysmod\garrysmod\addons\sbep_models\models\slyfo\rover1_glasscrack.phy
c:\program files (x86)\steam\steamapps\fire16\garrysmod\garrysmod\addons\sbep_models\models\slyfo\rover1_glasscrack.sw.vtx
c:\program files (x86)\steam\steamapps\fire16\garrysmod\garrysmod\addons\sbep_models\models\slyfo\rover1_glasscrack.vvd
c:\program files (x86)\steam\steamapps\fire16\garrysmod\garrysmod\spawnicons\slyfo\rover1_glasscrack.si0
c:\program files (x86)\valve\half-life 2\hl2\materials\glass\glasswindow018a_cracked.vmt
c:\program files (x86)\valve\half-life 2\hl2\materials\glass\glasswindow018a_cracked.vtf
c:\users\ondřej\documents\electronic arts\the sims 3\downloads\bh_crackly bathtub.sims3pack
c:\users\ondřej\documents\electronic arts\the sims 3\downloads\crackizzati muro.sims3pack
c:\users\ondřej\documents\imtoo software studio\video converter ultimate\crack.js
c:\users\ondřej\downloads\pinnacle studio 14 hd ultimate collection - by mick (full version)\pinnacle studio 14 hd ultimate collection - by mick\pinnacle studio 14 hd ultimate collection - by mick\crack\pinnacle pixie activation 470.exe
hosts 127.0.0.1 activate.adobe.com
scanner sequence 3.ZZ.11
----- EOF -----



Log z WVCheck:

Windows Validation Check
Version: 1.9.11.4
Log Created On: 1545_04-02-2011
-----------------------

Windows Information
-----------------------
Windows Version: Windows 7
Windows Mode: Normal
Systemroot Path: C:\Windows

WVCheck's Auto Update Check
-----------------------
Auto-Update Option: Download updates and install them automatically.
-----------------------
Last Success Time for Update Detection: 2011-02-04 08:32:09
Last Success Time for Update Download: 2011-02-04 08:32:10
Last Success Time for Update Installation: 2011-02-04 08:33:41


WVCheck's Registry Check Check
-----------------------
Antiwpa: Not Found
-----------------------
Chew7Hale: Not Found
-----------------------


WVCheck's File Dump
-----------------------
WVCheck found no known bad files.


WVCheck's Dir Dump
-----------------------
WVCheck found no known bad directories.


WVCheck's Missing File Check
-----------------------
WVCheck found no missing Windows files.


WVCheck's HOSTS File Check
-----------------------
WVCheck found no bad lines in the hosts file.


WVCheck's MD5 Check
EXPERIMENTAL!!
-----------------------
user32.dll - e8b0ffc209e504cb7e79fc24e6c085f0


-------- End of File, program close at 1548_04-02-2011 --------


Error z WVCheck:

Traceback (most recent call last):
File "<string>", line 358, in <module>
File "<string>", line 256, in main
UnicodeEncodeError: 'ascii' codec can't encode character u'\u0159' in position 30: ordinal not in range(128)

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 15:54
od Caroprd111
V logu pořád nevidím legální zabezpečení. Dokud se nezbavíte nelegálního softwaru, tak odmítám pokračovat.

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 16:02
od Foxtrot
Omlouvám se, ale nevím přesně jaké zabezpečení myslíte.

Předtím jsem měl nelegální zabezpečení (ESS), ale odinstaloval jsem ho, stáhl si trial verzi NOD32 a ZoneAlarm a k NODu32 objednal legální licenci.
Pár programů tu s nelegalni licenci mám,ale ty se netýkají zabezpečení PC.

Pokud mi napíšete programy, které mám odinstalovat a smazat, tak to ihned udělám. (myslím to nelegální zabezpečení)
Děkuji.

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 17:03
od Caroprd111
V tom případě je to OK, ale upozornění se týká i další nelegálních programů, které se zabezpečením nesouvisí :!:


Obrázek Stáhněte OTL http://oldtimer.geekstogo.com/OTL.exe na plochu
  • Spusťte, poté do spodního políčka vložte následující skript.

Kód: Vybrat vše

 netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys 
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys 
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
tcpip.sys
cryptsvc.dll
Changer.sys
JakNDis.sys
isapnp.sys 
cdrom.sys
autochk.exe 
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav 
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
CREATERESTOREPOINT 
  • Označte položku Pro všechny uživatele.
  • Označte položky Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
  • Klikněte na tlačítko Prohledat
  • Po dokončení, sem vložte logy OTL.Txt a Extras.txt

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 18:10
od Foxtrot
Když vše udělám a do programu zkopíruju skript, tak mi po delší kontrole program u souboru zpeng25.dll otevře okno s hláškou Cannot create file C:\Users\Ondřej\Desktop\cmd.bat.

Zastaví se na: Manual File Scan - Looking at file: C:\Windows\system32\zpeng25.dll...

Když jsem ho zapnul poprvé a zapoměl vložit ten script, tak program doběhl v pořádku.

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 18:55
od Caroprd111
Umažte ze skriptu následující řádky, v řámečku "Specifické registry" zaškrtněte "Vše" a spusťte sken znovu.

Kód: Vybrat vše

reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 19:24
od Foxtrot
Po smazání těch řádků se to povedlo, skenování se sice u toho souboru zastavilo, pak složku system32 oskenoval program znovu, znovu se u zpeng25.dll zastavil, ale skenování pak za několik sekund dokončil.

Do přílohy přidávám zabalené logy.
OTL_a_Extras.zip
(261.94 KiB) Staženo 73 x

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 19:34
od Caroprd111
Logy vložte normálně do příspěvku, případně je rozdělte do více příspěvků.

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 19:44
od Foxtrot
OTL logfile created on: 4.2.2011 19:06:42 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Ondřej\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

6,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 54,00% Memory free
12,00 Gb Paging File | 10,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 897,23 Gb Total Space | 202,44 Gb Free Space | 22,56% Space Free | Partition Type: NTFS
Drive G: | 34,18 Gb Total Space | 34,09 Gb Free Space | 99,74% Space Free | Partition Type: NTFS

Computer Name: ONDŘEJ-PC | User Name: Ondřej | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011.02.04 17:47:58 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Ondřej\Desktop\OTL.exe
PRC - [2011.01.24 21:49:40 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011.01.12 16:41:42 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
PRC - [2011.01.05 11:59:50 | 000,037,664 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010.12.16 16:19:34 | 002,402,512 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe
PRC - [2010.12.06 08:31:52 | 001,910,152 | ---- | M] (LogMeIn Inc.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2010.12.03 20:39:33 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2010.12.03 20:39:33 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
PRC - [2010.11.16 17:47:56 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
PRC - [2010.11.16 17:46:04 | 001,043,968 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2010.09.21 19:27:43 | 000,028,766 | ---- | M] (IObit) -- C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0barsvc.exe
PRC - [2010.09.01 05:26:04 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
PRC - [2010.04.02 14:21:50 | 001,109,632 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\ASUS\TurboV EVO\TurboVHelp.exe
PRC - [2009.12.28 14:33:02 | 000,096,896 | R--- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
PRC - [2009.03.30 07:32:40 | 000,032,768 | R--- | M] () -- C:\Windows\DAODx.exe
PRC - [2009.02.23 11:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe


========== Modules (SafeList) ==========

MOD - [2011.02.04 17:47:58 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Ondřej\Desktop\OTL.exe
MOD - [2010.08.21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2010.02.08 16:19:52 | 000,053,248 | ---- | M] () -- C:\Program Files\ASUS\TurboV EVO\HookKey32.dll
MOD - [2009.07.14 02:15:31 | 000,154,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imagehlp.dll
MOD - [2009.07.14 02:09:00 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\normaliz.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011.01.12 16:44:02 | 000,042,360 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV:64bit: - [2011.01.12 16:41:42 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
SRV:64bit: - [2011.01.05 03:57:44 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011.01.04 22:07:10 | 000,354,304 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2010.11.03 21:30:12 | 001,030,600 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2010.08.19 17:43:23 | 000,386,344 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\Shared files\RichVideo64.exe -- (RichVideo64)
SRV:64bit: - [2010.06.17 05:23:36 | 000,194,496 | ---- | M] (Advanced Micro Devices) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe -- (AMD Reservation Manager)
SRV:64bit: - [2010.05.06 10:30:22 | 000,357,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011.01.24 21:49:40 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011.01.23 11:16:40 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.01.06 14:08:57 | 003,129,432 | ---- | M] () [Auto | Running] -- c:\Program Files (x86)\Common Files\Akamai\netsession_win_dbc0250.dll -- (Akamai)
SRV - [2011.01.05 11:59:50 | 000,037,664 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010.12.08 13:12:10 | 000,147,336 | ---- | M] (LogMeIn, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe -- (LMIMaint)
SRV - [2010.12.08 13:12:04 | 000,373,640 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2010.12.06 08:31:50 | 002,101,640 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2010.11.16 17:47:56 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Windows\SysWOW64\ZoneLabs\vsmon.exe -- (vsmon)
SRV - [2010.11.08 12:04:20 | 000,407,424 | ---- | M] (LogMeIn, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe -- (LogMeIn)
SRV - [2010.09.21 19:27:43 | 000,028,766 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0barsvc.exe -- (IObitBarService)
SRV - [2010.08.19 11:17:28 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.08.03 12:06:04 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2010.08.03 11:08:30 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2010.07.01 03:45:02 | 000,136,616 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe -- (AODService)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.12.28 14:33:02 | 000,096,896 | R--- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe -- (AsSysCtrlService)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.02.23 11:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011.01.28 15:00:52 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011.01.05 04:37:14 | 008,283,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011.01.05 03:19:38 | 000,294,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.12.21 15:04:06 | 000,170,640 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:64bit: - [2010.12.21 15:04:06 | 000,141,264 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2010.12.21 13:47:38 | 000,125,296 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:64bit: - [2010.12.08 13:12:30 | 000,087,456 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV:64bit: - [2010.11.17 13:04:32 | 000,115,216 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010.09.28 15:44:52 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010.09.17 15:40:06 | 000,072,216 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV:64bit: - [2010.09.17 15:39:58 | 000,011,552 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lmimirr.sys -- (lmimirr)
DRV:64bit: - [2010.08.31 10:24:05 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010.08.02 15:31:45 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2010.08.02 15:31:45 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2010.05.15 16:30:52 | 000,458,840 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vsdatant.sys -- (Vsdatant)
DRV:64bit: - [2010.05.06 10:21:46 | 000,125,456 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010.03.18 10:00:16 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2010.03.18 10:00:00 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2010.03.04 14:43:00 | 000,346,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2010.02.03 15:56:56 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:64bit: - [2010.01.22 11:22:22 | 000,180,224 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010.01.22 11:22:18 | 000,077,824 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010.01.11 12:28:35 | 000,115,824 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID)
DRV:64bit: - [2009.11.23 16:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:64bit: - [2009.11.23 16:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009.10.19 13:45:54 | 000,039,480 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2009.07.16 04:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2008.09.17 13:14:00 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Entech64.sys -- (ENTECH64)
DRV:64bit: - [2008.08.14 07:48:33 | 000,024,064 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Ctafiltv.sys -- (Ctafiltv)
DRV - [2010.09.17 15:40:06 | 000,015,928 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\rainfo.sys -- (LMIInfo)
DRV - [2004.06.22 14:44:50 | 000,005,632 | ---- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\Entech64.sys -- (ENTECH64)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
IE - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DB C1 D0 17 97 39 CB 01 [binary data]
IE - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\..\URLSearchHook: {7757CBCC-0975-4b79-A519-90B142CA3A23} - Reg Error: Value error. File not found
IE - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "chrome://speeddial/content/speeddial.xul"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: DeviceDetection@logitech.com:1.20.0.66
FF - prefs.js..extensions.enabledItems: jayakrishnan@gmail.com:1.3.2
FF - prefs.js..extensions.enabledItems: smarterwiki@wikiatic.com:4.1.8
FF - prefs.js..extensions.enabledItems: support@auto-hide-ip.com:1.0
FF - prefs.js..extensions.enabledItems: youtube2mp3@mondayx.de:1.0.7
FF - prefs.js..extensions.enabledItems: {003D3EDC-99B9-4a34-9C20-60CB94F7E829}:2010.25.36
FF - prefs.js..extensions.enabledItems: {097d3191-e6fa-4728-9826-b533d755359d}:0.7.12
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.8.1
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.2
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.0
FF - prefs.js..extensions.enabledItems: i0ffxtbr@IObitBar.com:1.1
FF - prefs.js..extensions.enabledItems: {91da5e8a-3318-4f8c-b67e-5964de3ab546}:2.6.0.15
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\i0ffxtbr@IObitBar.com: C:\Program Files (x86)\IObitBar\toolbar\1.bin [2011.02.04 16:58:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.02.04 10:35:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.02.04 10:35:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011.02.04 12:21:40 | 000,000,000 | ---D | M]

[2010.07.22 16:48:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Extensions
[2011.02.04 13:38:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions
[2010.09.16 15:57:43 | 000,000,000 | ---D | M] (WebTran) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\{003D3EDC-99B9-4a34-9C20-60CB94F7E829}
[2010.11.18 16:58:43 | 000,000,000 | ---D | M] (All-in-One Sidebar) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d}
[2011.01.26 14:37:48 | 000,000,000 | ---D | M] (FlashGot) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2010.07.22 17:16:14 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.12.10 14:49:07 | 000,000,000 | ---D | M] (Speed Dial) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2011.02.04 13:27:23 | 000,000,000 | ---D | M] (ZoneAlarm Security Toolbar) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\{91da5e8a-3318-4f8c-b67e-5964de3ab546}
[2011.01.10 18:13:42 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.12.11 10:57:33 | 000,000,000 | ---D | M] (Easy Youtube Video Downloader) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
[2010.09.22 20:49:13 | 000,000,000 | ---D | M] (Разпознаване на устройство Logitech) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\DeviceDetection@logitech.com
[2010.09.16 16:28:56 | 000,000,000 | ---D | M] (Translate) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\jayakrishnan@gmail.com
[2010.11.09 19:42:06 | 000,000,000 | ---D | M] (FastestFox) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\smarterwiki@wikiatic.com
[2010.07.27 11:58:02 | 000,000,000 | ---D | M] (Auto Hide IP) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\support@auto-hide-ip.com
[2010.07.22 17:16:14 | 000,000,000 | ---D | M] (YouTube to MP3) -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\extensions\youtube2mp3@mondayx.de
[2011.02.04 13:38:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010.07.22 17:00:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.07.22 17:03:39 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.08.16 16:21:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.10.16 10:43:01 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010.12.28 16:32:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.02.03 22:07:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{003D3EDC-99B9-4A34-9C20-60CB94F7E829}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{097D3191-E6FA-4728-9826-B533D755359D}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{20A82645-C095-46ED-80E3-08825760534B}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{64161300-E22B-11DB-8314-0800200C9A66}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{B9DB16A4-6EDC-47EC-A1F4-B86292ED211D}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\DEVICEDETECTION@LOGITECH.COM
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\JAYAKRISHNAN@GMAIL.COM
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\SMARTERWIKI@WIKIATIC.COM
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\SUPPORT@AUTO-HIDE-IP.COM
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\YOUTUBE2MP3@MONDAYX.DE
[2008.11.11 08:38:54 | 000,663,552 | ---- | M] (BitComet) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npBitCometAgent.dll
[2009.02.11 20:16:16 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npbittorrent.dll
[2010.11.12 18:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.03.30 11:57:04 | 000,098,304 | ---- | M] (NHN USA Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
[2009.01.29 04:08:04 | 000,132,528 | ---- | M] (NHN USA Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npijjiCHPlugin.dll
[2009.08.17 06:42:14 | 000,073,728 | ---- | M] (NHN USA Inc. ) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
[2009.10.06 10:40:40 | 000,098,304 | ---- | M] (OGPlanet Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npOGPPlugin.dll
[2010.12.03 19:08:29 | 000,000,638 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.12.03 19:08:29 | 000,001,687 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.12.03 19:08:29 | 000,001,367 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.12.03 19:08:29 | 000,000,654 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.12.03 19:08:29 | 000,001,179 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2010.11.08 19:37:35 | 000,000,945 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 http://www.langsoft.cz
O1 - Hosts: 127.0.0.1 iws.intranet.cz
O1 - Hosts: 127.0.0.1 http://www.pctranslator.cz
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2 - BHO: (Toolbar BHO) - {EFA17361-CDC0-4927-9AFC-BAAD1F96B2AE} - C:\Program Files (x86)\IObitBar\toolbar\1.bin\i0bar.dll (IObit)
O3 - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\..\Toolbar\WebBrowser: (no name) - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\..Trusted Domains: mojebanka.cz ([www] https in Důvěryhodné servery)
O15 - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\..Trusted Ranges: Range1979 ([http] in Důvěryhodné servery)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://ccfiles.creative.com/Web/softwar ... TSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwar ... /CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{e5861290-93d8-11df-9f7a-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{e5861290-93d8-11df-9f7a-806e6f6e6963}\Shell\AutoRun\command - "" = D:\O2ADSLCD.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (http://www.helixcommunity.org)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (http://www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011.02.04 17:48:40 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Users\Ondřej\Desktop\OTL.exe
[2011.02.04 16:59:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 3
[2011.02.04 16:51:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011.02.04 16:51:46 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.02.04 14:22:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZoneAlarm
[2011.02.04 14:22:38 | 000,058,368 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysWow64\vsregexp.dll
[2011.02.04 14:22:33 | 000,104,448 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysWow64\zlcommdb.dll
[2011.02.04 14:22:32 | 000,069,120 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysWow64\zlcomm.dll
[2011.02.04 14:22:29 | 000,043,008 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysWow64\vswmi.dll
[2011.02.04 14:22:28 | 001,238,528 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysWow64\zpeng25.dll
[2011.02.04 14:22:28 | 000,110,080 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysWow64\vsxml.dll
[2011.02.04 14:22:27 | 000,302,592 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysWow64\vspubapi.dll
[2011.02.04 14:22:27 | 000,112,128 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysWow64\vsdata.dll
[2011.02.04 14:22:27 | 000,108,032 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysWow64\vsmonapi.dll
[2011.02.04 14:22:27 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ZoneLabs
[2011.02.04 14:22:20 | 000,458,840 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysNative\drivers\vsdatant.sys
[2011.02.04 14:22:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Zone Labs
[2011.02.04 14:21:55 | 000,715,264 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysWow64\vsutil.dll
[2011.02.04 14:21:55 | 000,228,864 | ---- | C] (Check Point Software Technologies LTD) -- C:\Windows\SysWow64\vsinit.dll
[2011.02.04 13:50:39 | 000,000,000 | ---D | C] -- C:\Windows\Internet Logs
[2011.02.04 13:27:56 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\Documents\ForceField Shared Files
[2011.02.04 13:27:50 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\CheckPoint
[2011.02.04 13:27:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2011.02.04 13:26:53 | 000,000,000 | ---D | C] -- C:\Program Files\CheckPoint
[2011.02.04 13:25:47 | 000,374,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
[2011.02.04 13:23:56 | 000,000,000 | ---D | C] -- C:\ProgramData\CheckPoint
[2011.02.04 12:21:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2011.02.04 12:21:40 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
[2011.02.04 12:21:40 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011.02.04 10:38:51 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.02.04 10:35:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011.02.04 08:37:34 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\N360x64
[2011.02.04 08:37:34 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\N360x64\0401000.020
[2011.02.04 08:37:32 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
[2011.02.03 21:55:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton 360
[2011.02.03 21:53:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller
[2011.02.03 21:45:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2011.02.03 21:43:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Symantec
[2011.02.03 21:43:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2011.02.03 21:35:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared
[2011.02.03 21:28:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2011.02.03 21:22:15 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2011.02.03 19:36:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2011.02.03 18:20:11 | 000,000,000 | ---D | C] -- C:\rafazon
[2011.02.03 17:57:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab Setup Files
[2011.02.02 16:43:24 | 000,000,000 | ---D | C] -- C:\Windows\Roaming
[2011.02.02 16:43:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Motive
[2011.02.02 13:33:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011.02.01 13:28:53 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Portforward.com
[2011.02.01 13:28:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PFPortChecker
[2011.02.01 13:19:35 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Simple Port Forwarding
[2011.02.01 13:19:33 | 000,000,000 | ---D | C] -- C:\Windows\Simple Port Forwarding
[2011.02.01 13:19:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Simple Port Forwarding
[2011.01.31 17:22:35 | 000,000,000 | ---D | C] -- C:\mineserver
[2011.01.31 11:18:31 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Local\LogMeIn
[2011.01.31 11:18:27 | 000,087,456 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIRfsClientNP.dll
[2011.01.31 11:18:27 | 000,072,216 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys
[2011.01.31 11:18:27 | 000,033,152 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIport.dll
[2011.01.31 11:18:22 | 000,080,768 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIinit.dll
[2011.01.31 11:18:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn
[2011.01.31 11:12:07 | 000,033,856 | -H-- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\hamachi.sys
[2011.01.31 11:12:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011.01.31 11:12:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
[2011.01.31 11:11:28 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Local\LogMeIn Hamachi
[2011.01.29 16:22:39 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\.minecraft
[2011.01.29 15:26:40 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\minecraft záloha
[2011.01.29 14:44:59 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\.minecraft – kopie
[2011.01.29 13:22:32 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Local\AMD
[2011.01.29 13:22:29 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2011.01.29 13:21:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATI Stream SDK v2
[2011.01.29 13:21:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Stream
[2011.01.29 13:21:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2011.01.29 13:21:41 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2011.01.29 13:21:39 | 000,046,136 | ---- | C] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\amdiox64.sys
[2011.01.29 13:21:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2011.01.28 17:44:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.01.28 17:43:49 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.01.28 17:43:48 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011.01.28 17:43:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011.01.28 15:00:52 | 000,254,528 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2011.01.28 14:58:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite
[2011.01.28 14:41:42 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MagicISO
[2011.01.28 14:41:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicISO
[2011.01.28 14:41:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MagicISO
[2011.01.28 14:34:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pixbyte
[2011.01.28 13:41:12 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Local\Mumble
[2011.01.28 13:40:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
[2011.01.28 13:23:58 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\X-Chat 2
[2011.01.28 13:23:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\X-Chat 2
[2011.01.28 13:23:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\X-Chat 2
[2011.01.27 20:58:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CDex
[2011.01.27 16:02:07 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Empire of Magic
[2011.01.27 15:59:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EOM
[2011.01.24 21:19:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDex
[2011.01.22 22:38:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Empire of Magic
[2011.01.22 19:15:20 | 000,000,000 | ---D | C] -- C:\NST
[2011.01.22 19:06:40 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Local\NeoSmart_Technologies
[2011.01.22 19:06:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies
[2011.01.22 19:06:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NeoSmart Technologies
[2011.01.22 16:38:57 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1C
[2011.01.22 16:27:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\1C
[2011.01.21 17:43:52 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\2.minecraft- starý minecraft
[2011.01.19 16:58:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Charles Forsyth
[2011.01.19 16:58:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Charles Forsyth
[2011.01.18 21:10:22 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\Documents\My Recordings
[2011.01.18 21:08:19 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\SynthMaker
[2011.01.18 21:06:28 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\Acoustica
[2011.01.18 21:06:27 | 000,057,344 | ---- | C] (NexiTech, Inc.) -- C:\Windows\SysWow64\Wnaspint.dll
[2011.01.18 21:05:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Acoustica Shared Effects
[2011.01.18 21:00:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VST
[2011.01.18 20:09:01 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\PACE Anti-Piracy
[2011.01.18 20:09:01 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Local\PACE Anti-Piracy
[2011.01.18 20:09:01 | 000,000,000 | ---D | C] -- C:\ProgramData\PACE Anti-Piracy
[2011.01.18 20:09:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PACE Anti-Piracy
[2011.01.18 16:00:51 | 000,000,000 | ---D | C] -- C:\ProgramData\PaceAP
[2011.01.18 15:25:40 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnalogX
[2011.01.16 18:22:50 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\Documents\CyberLink
[2011.01.16 18:22:27 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\CyberLink
[2011.01.16 18:22:08 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2011.01.16 18:18:42 | 000,000,000 | ---D | C] -- C:\ProgramData\SmartSound Software Inc
[2011.01.16 18:18:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SmartSound Software
[2011.01.16 18:18:41 | 000,000,000 | ---D | C] -- C:\ProgramData\eSellerate
[2011.01.16 18:18:28 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector
[2011.01.16 18:18:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cyberlink
[2011.01.16 18:17:28 | 000,000,000 | ---D | C] -- C:\Program Files\CyberLink
[2011.01.16 18:16:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp
[2011.01.16 18:16:20 | 000,000,000 | ---D | C] -- C:\ProgramData\CLSK
[2011.01.15 21:17:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lame For Audacity
[2011.01.15 21:17:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity
[2011.01.15 21:15:56 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\Audacity
[2011.01.15 21:15:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity 1.3 Beta (Unicode)
[2011.01.15 20:51:38 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP4Converter
[2011.01.15 20:51:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP4Converter
[2011.01.15 20:51:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MP4Converter
[2011.01.15 17:32:05 | 000,000,000 | ---D | C] -- C:\test
[2011.01.12 14:30:07 | 004,068,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2011.01.12 14:30:07 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2011.01.12 14:30:07 | 001,837,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2011.01.12 14:30:07 | 001,540,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2011.01.12 14:30:07 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10warp.dll
[2011.01.12 14:30:07 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2011.01.12 14:30:07 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d2d1.dll
[2011.01.12 14:30:07 | 000,662,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2011.01.12 14:30:06 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2011.01.12 14:30:06 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DWrite.dll
[2011.01.12 14:30:06 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2011.01.12 14:30:06 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2011.01.12 14:30:05 | 001,863,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2011.01.12 14:30:05 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2011.01.12 14:30:05 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2011.01.12 14:30:05 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll
[2011.01.12 14:30:05 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2011.01.12 14:30:05 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll
[2011.01.12 14:30:05 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll
[2011.01.12 14:30:05 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1core.dll
[2011.01.12 14:30:05 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll
[2011.01.12 14:30:04 | 000,258,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2011.01.12 14:30:04 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2011.01.12 14:30:04 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll
[2011.01.12 14:30:04 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1.dll
[2011.01.12 14:30:04 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2011.01.12 14:30:04 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll
[2011.01.12 14:30:02 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbc32.dll
[2011.01.12 14:30:01 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbc32.dll
[2011.01.08 12:33:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2011.01.07 21:50:34 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Local\Pinnacle
[2011.01.07 21:48:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Pinnacle Studio Ultimate Collection
[2011.01.07 21:47:28 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\My Projects
[2011.01.07 21:39:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Pinnacle
[2011.01.07 18:32:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2011.01.07 18:32:02 | 000,000,000 | ---D | C] -- C:\Users\Ondřej\AppData\Roaming\uTorrent
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 19:45
od Foxtrot
========== Files - Modified Within 30 Days ==========

[2011.02.04 18:40:00 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.02.04 17:47:58 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Ondřej\Desktop\OTL.exe
[2011.02.04 17:40:00 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.02.04 16:59:14 | 000,000,396 | ---- | M] () -- C:\Windows\tasks\AWC Startup.job
[2011.02.04 16:59:02 | 000,001,221 | ---- | M] () -- C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2011.02.04 16:51:47 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.02.04 14:33:11 | 000,014,832 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.02.04 14:33:11 | 000,014,832 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.02.04 14:26:40 | 000,000,402 | ---- | M] () -- C:\Windows\tasks\AWC AutoSweep.job
[2011.02.04 14:25:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.02.04 14:25:30 | 535,437,311 | -HS- | M] () -- C:\hiberfil.sys
[2011.02.04 14:22:51 | 000,420,800 | ---- | M] () -- C:\Windows\SysNative\drivers\vsconfig.xml
[2011.02.04 14:22:39 | 000,001,066 | ---- | M] () -- C:\Users\Ondřej\Desktop\ZoneAlarm Security.lnk
[2011.02.04 10:35:47 | 000,001,939 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.02.01 20:16:57 | 000,000,414 | ---- | M] () -- C:\Windows\tasks\AWC Update.job
[2011.02.01 17:01:30 | 013,138,607 | ---- | M] () -- C:\mineserver.zip
[2011.01.31 11:18:17 | 000,001,024 | ---- | M] () -- C:\.rnd
[2011.01.31 11:12:05 | 000,000,926 | ---- | M] () -- C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2011.01.29 17:59:06 | 001,577,412 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.01.29 17:59:06 | 000,666,408 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2011.01.29 17:59:06 | 000,652,150 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.01.29 17:59:06 | 000,140,102 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2011.01.29 17:59:06 | 000,121,082 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.01.29 12:42:50 | 000,001,151 | ---- | M] () -- C:\Users\Public\Desktop\CyberLink PowerDirector.lnk
[2011.01.29 12:32:54 | 110,771,477 | ---- | M] () -- C:\Users\Ondřej\Desktop\20110128-21-1.png
[2011.01.28 17:44:18 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.01.28 15:00:52 | 000,254,528 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2011.01.28 15:00:27 | 005,282,760 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.01.28 13:23:45 | 000,001,010 | ---- | M] () -- C:\Users\Ondřej\Desktop\X-Chat 2.lnk
[2011.01.26 21:11:44 | 000,867,349 | ---- | M] () -- C:\Users\Ondřej\Desktop\Foxtrot-plocha.jpg
[2011.01.26 20:16:10 | 000,270,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2011.01.26 20:16:10 | 000,270,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011.01.26 20:14:49 | 000,215,128 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2011.01.24 21:49:40 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011.01.24 21:42:45 | 000,001,732 | ---- | M] () -- C:\Users\Ondřej\Desktop\BFBC2Game.exe – zástupce.lnk
[2011.01.24 21:10:19 | 000,195,420 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
[2011.01.23 21:08:46 | 000,000,000 | ---- | M] () -- C:\Windows\XXLGSC
[2011.01.21 17:33:40 | 000,232,501 | ---- | M] () -- C:\Users\Ondřej\Desktop\Minecraft.exe
[2011.01.18 20:48:16 | 000,900,015 | ---- | M] () -- C:\Windows\SysWow64\TmpA2656790
[2011.01.18 20:32:29 | 000,900,015 | ---- | M] () -- C:\Windows\SysWow64\TmpA1709661
[2011.01.17 19:15:21 | 000,198,565 | ---- | M] () -- C:\Users\Ondřej\Documents\Jinonická vyhlídka.docx
[2011.01.16 15:45:58 | 000,016,896 | ---- | M] () -- C:\Users\Ondřej\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.01.12 21:52:47 | 000,016,871 | ---- | M] () -- C:\Users\Ondřej\Documents\Důsledky 1.docx
[2011.01.12 19:56:27 | 015,080,482 | ---- | M] () -- C:\Users\Ondřej\Desktop\minecraft – kopie – kopie – kopie (2).jar
[2011.01.10 16:30:20 | 000,000,684 | ---- | M] () -- C:\Users\Ondřej\Desktop\ostatní.lnk
[2011.01.09 22:29:20 | 000,007,605 | ---- | M] () -- C:\Users\Ondřej\AppData\Local\Resmon.ResmonCfg
[2011.01.08 17:13:47 | 000,000,383 | RH-- | M] () -- C:\Windows\ctfile.rfc
[2011.01.08 17:13:21 | 000,466,520 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2011.01.08 17:13:21 | 000,445,016 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2011.01.08 17:13:21 | 000,123,480 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysNative\OpenAL32.dll
[2011.01.08 17:13:21 | 000,109,144 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.02.04 16:59:14 | 000,000,396 | ---- | C] () -- C:\Windows\tasks\AWC Startup.job
[2011.02.04 16:59:02 | 000,001,221 | ---- | C] () -- C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2011.02.04 16:51:47 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011.02.04 14:22:39 | 000,001,066 | ---- | C] () -- C:\Users\Ondřej\Desktop\ZoneAlarm Security.lnk
[2011.02.04 14:22:27 | 000,420,800 | ---- | C] () -- C:\Windows\SysNative\drivers\vsconfig.xml
[2011.02.04 10:35:47 | 000,001,939 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011.02.01 16:59:59 | 013,138,607 | ---- | C] () -- C:\mineserver.zip
[2011.01.31 11:18:17 | 000,001,024 | ---- | C] () -- C:\.rnd
[2011.01.31 11:18:04 | 000,000,988 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn.lnk
[2011.01.31 11:11:23 | 000,000,926 | ---- | C] () -- C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2011.01.29 12:29:43 | 110,771,477 | ---- | C] () -- C:\Users\Ondřej\Desktop\20110128-21-1.png
[2011.01.28 17:44:18 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.01.28 13:23:45 | 000,001,010 | ---- | C] () -- C:\Users\Ondřej\Desktop\X-Chat 2.lnk
[2011.01.26 21:11:44 | 000,867,349 | ---- | C] () -- C:\Users\Ondřej\Desktop\Foxtrot-plocha.jpg
[2011.01.24 21:42:47 | 000,001,732 | ---- | C] () -- C:\Users\Ondřej\Desktop\BFBC2Game.exe – zástupce.lnk
[2011.01.22 16:27:21 | 001,963,520 | ---- | C] () -- C:\Windows\setup_rangers_2.exe
[2011.01.21 17:33:30 | 000,232,501 | ---- | C] () -- C:\Users\Ondřej\Desktop\Minecraft.exe
[2011.01.18 20:48:16 | 000,900,015 | ---- | C] () -- C:\Windows\SysWow64\TmpA2656790
[2011.01.18 20:32:29 | 000,900,015 | ---- | C] () -- C:\Windows\SysWow64\TmpA1709661
[2011.01.17 19:14:57 | 000,198,565 | ---- | C] () -- C:\Users\Ondřej\Documents\Jinonická vyhlídka.docx
[2011.01.16 18:18:28 | 000,001,151 | ---- | C] () -- C:\Users\Public\Desktop\CyberLink PowerDirector.lnk
[2011.01.13 18:49:50 | 015,080,482 | ---- | C] () -- C:\Users\Ondřej\Desktop\minecraft – kopie – kopie – kopie (2).jar
[2011.01.12 21:52:47 | 000,016,871 | ---- | C] () -- C:\Users\Ondřej\Documents\Důsledky 1.docx
[2010.12.05 20:29:20 | 001,555,466 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.11.20 15:56:22 | 000,000,132 | ---- | C] () -- C:\Users\Ondřej\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
[2010.11.12 20:28:23 | 000,016,896 | ---- | C] () -- C:\Users\Ondřej\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.11.12 20:17:41 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2010.10.14 01:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010.10.09 15:56:33 | 000,001,154 | ---- | C] () -- C:\Users\Ondřej\AppData\Roaming\MTUpdate.txt
[2010.09.09 13:52:07 | 000,001,189 | ---- | C] () -- C:\Users\Ondřej\AppData\Roaming\vso_ts_preview.xml
[2010.09.06 17:26:01 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2010.08.31 10:33:39 | 000,217,088 | ---- | C] () -- C:\Windows\SysWow64\libmySQL.dll
[2010.08.31 10:33:39 | 000,102,400 | ---- | C] () -- C:\Windows\SysWow64\TrackerNET.dll
[2010.08.31 10:29:29 | 000,000,471 | ---- | C] () -- C:\Windows\SIERRA.INI
[2010.08.25 10:23:31 | 000,000,297 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2010.08.03 12:21:20 | 000,000,061 | ---- | C] () -- C:\Windows\sbwin.ini
[2010.08.03 11:09:33 | 000,000,504 | ---- | C] () -- C:\Windows\CtaMCcfg.ini
[2010.08.03 11:09:28 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2010.08.03 11:09:28 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2010.07.27 12:05:39 | 000,000,302 | ---- | C] () -- C:\ProgramData\Setting.dat
[2010.07.27 12:05:39 | 000,000,022 | ---- | C] () -- C:\Users\Ondřej\AppData\Roaming\UserFlag.ini
[2010.07.25 15:24:02 | 000,000,034 | ---- | C] () -- C:\Windows\WTRDCTM.INI
[2010.07.23 12:16:25 | 000,007,605 | ---- | C] () -- C:\Users\Ondřej\AppData\Local\Resmon.ResmonCfg
[2010.07.20 10:11:43 | 000,003,972 | ---- | C] () -- C:\Windows\SysWow64\drivers\PciBus.sys
[2010.07.20 09:41:50 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2010.07.20 09:41:50 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2010.07.20 09:41:49 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2010.07.20 09:41:49 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2010.07.20 09:36:11 | 000,044,252 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2010.07.20 09:35:48 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2010.07.20 09:35:44 | 000,030,662 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.04.02 13:30:14 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2008.09.18 08:45:54 | 000,001,515 | ---- | C] () -- C:\Windows\Ctacfg.ini

========== LOP Check ==========

[2011.01.29 16:42:29 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\.minecraft
[2011.01.29 14:45:03 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\.minecraft – kopie
[2011.01.28 10:29:13 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\2.minecraft- starý minecraft
[2011.01.18 21:06:28 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Acoustica
[2010.10.26 17:58:48 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\AnvSoft
[2011.01.28 15:02:13 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Audacity
[2010.11.04 19:20:23 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Autodesk
[2010.07.27 11:57:56 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\AutoHideIP
[2010.10.18 17:02:25 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\avidemux
[2010.11.13 12:53:54 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011.02.04 13:27:50 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\CheckPoint
[2010.08.31 11:32:52 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\DAEMON Tools Lite
[2011.02.04 12:03:02 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\ESET
[2010.12.06 12:42:21 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\FileZilla
[2010.09.05 13:04:35 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\FreeCommander
[2010.12.05 20:23:42 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\GetRightToGo
[2010.07.27 11:57:21 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Hide IP NG
[2011.02.04 17:48:05 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\IObit
[2011.02.04 09:22:04 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\LangSoft
[2010.07.25 14:03:31 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Leadertech
[2010.07.25 10:12:27 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\MAXON
[2011.01.29 15:26:48 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\minecraft záloha
[2011.01.28 13:41:12 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Mumble
[2011.01.18 20:09:02 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\PACE Anti-Piracy
[2010.07.25 20:45:22 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Sinvise Systems
[2010.10.04 20:07:04 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Subversion
[2011.01.18 21:08:19 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\SynthMaker
[2010.09.28 17:06:12 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\TS3Client
[2010.12.05 16:27:12 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Tunngle
[2011.01.23 11:05:27 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\uTorrent
[2010.09.09 14:32:20 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Vso
[2011.02.04 19:04:05 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\X-Chat 2
[2010.08.03 17:33:39 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\XRay Engine
[2011.02.04 14:26:40 | 000,000,402 | ---- | M] () -- C:\Windows\Tasks\AWC AutoSweep.job
[2011.02.04 16:59:14 | 000,000,396 | ---- | M] () -- C:\Windows\Tasks\AWC Startup.job
[2011.02.01 20:16:57 | 000,000,414 | ---- | M] () -- C:\Windows\Tasks\AWC Update.job
[2010.12.27 06:49:44 | 000,032,604 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]
"" =

< c:\windows\*.* /U >
[1 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2011.01.29 16:42:29 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\.minecraft
[2011.01.29 14:45:03 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\.minecraft – kopie
[2011.01.28 10:29:13 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\2.minecraft- starý minecraft
[2011.01.18 21:06:28 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Acoustica
[2010.11.23 15:55:32 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Adobe
[2010.10.26 17:58:48 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\AnvSoft
[2010.07.25 13:25:50 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Apple Computer
[2010.07.22 16:31:57 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\ATI
[2011.01.28 15:02:13 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Audacity
[2010.11.04 19:20:23 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Autodesk
[2010.07.27 11:57:56 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\AutoHideIP
[2010.10.18 17:02:25 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\avidemux
[2010.11.13 12:53:54 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011.02.04 13:27:50 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\CheckPoint
[2010.08.03 12:18:59 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Creative
[2011.01.16 18:22:27 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\CyberLink
[2010.08.31 11:32:52 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\DAEMON Tools Lite
[2011.02.04 12:03:02 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\ESET
[2010.12.06 12:42:21 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\FileZilla
[2010.09.05 13:04:35 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\FreeCommander
[2010.12.05 20:23:42 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\GetRightToGo
[2011.01.31 11:11:21 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Hamachi
[2010.07.27 11:57:21 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Hide IP NG
[2010.07.22 16:31:40 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Identities
[2011.02.04 17:48:05 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\IObit
[2011.02.04 09:22:04 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\LangSoft
[2010.07.25 14:03:31 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Leadertech
[2010.07.25 14:02:30 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Logishrd
[2010.07.25 14:03:36 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Logitech
[2010.07.22 16:32:16 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Macromedia
[2010.07.25 10:12:27 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\MAXON
[2009.07.14 16:36:31 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Media Center Programs
[2010.10.09 15:58:13 | 000,000,000 | --SD | M] -- C:\Users\Ondřej\AppData\Roaming\Microsoft
[2011.01.29 15:26:48 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\minecraft záloha
[2010.07.22 16:48:54 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Mozilla
[2011.01.28 13:41:12 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Mumble
[2011.01.18 20:09:02 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\PACE Anti-Piracy
[2010.08.01 15:57:23 | 000,000,000 | RH-D | M] -- C:\Users\Ondřej\AppData\Roaming\SecuROM
[2010.07.25 20:45:22 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Sinvise Systems
[2011.02.04 14:19:26 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Skype
[2011.02.04 13:50:59 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\skypePM
[2010.10.04 20:07:04 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Subversion
[2011.01.18 21:08:19 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\SynthMaker
[2010.09.28 17:06:12 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\TS3Client
[2010.12.05 16:27:12 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Tunngle
[2011.01.23 11:05:27 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\uTorrent
[2011.02.04 16:10:18 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\vlc
[2010.09.09 14:32:20 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\Vso
[2011.01.03 19:12:27 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\WinRAR
[2011.02.04 19:04:05 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\X-Chat 2
[2010.08.03 17:33:39 | 000,000,000 | ---D | M] -- C:\Users\Ondřej\AppData\Roaming\XRay Engine

< %APPDATA%\*.exe /s >
[2010.07.25 14:03:31 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Ondřej\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2010.08.31 12:44:48 | 000,069,632 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Ondřej\AppData\Roaming\Microsoft\Installer\{675C161A-889A-4D35-8361-EA74BADCE0E6}\Launcher.exe_D45EC2594A194656B588C2C360DD18EA_2.exe
[2010.08.31 12:44:48 | 000,069,632 | R--- | M] (InstallShield Software Corp.) -- C:\Users\Ondřej\AppData\Roaming\Microsoft\Installer\{675C161A-889A-4D35-8361-EA74BADCE0E6}\srcds.exe_D45EC2594A194656B588C2C360DD18EA.exe
[2010.12.24 20:03:04 | 000,010,134 | R--- | M] () -- C:\Users\Ondřej\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2011.02.04 14:28:49 | 000,188,152 | ---- | M] () -- C:\Users\Ondřej\AppData\Roaming\Mozilla\Firefox\Profiles\5163027y.default\FlashGot.exe


< MD5 for: AGP440.SYS >
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009.07.14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\SysWOW64\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\SysNative\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe

< MD5 for: CDROM.SYS >
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\drivers\cdrom.sys
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_8363d00ecae4322d\cdrom.sys
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys

< MD5 for: CNGAUDIT.DLL >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 02:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: CRYPTSVC.DLL >
[2009.07.14 02:40:24 | 000,175,104 | ---- | M] (Microsoft Corporation) MD5=8C57411B66282C01533CB776F98AD384 -- C:\Windows\SysNative\cryptsvc.dll
[2009.07.14 02:40:24 | 000,175,104 | ---- | M] (Microsoft Corporation) MD5=8C57411B66282C01533CB776F98AD384 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_d1f48b0bb4805490\cryptsvc.dll
[2009.07.14 02:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\Windows\SysWOW64\cryptsvc.dll
[2009.07.14 02:15:07 | 000,135,680 | ---- | M] (Microsoft Corporation) MD5=9C231178CE4FB385F4B54B0A9080B8A4 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7600.16385_none_75d5ef87fc22e35a\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2010.03.12 23:47:22 | 000,006,440 | ---- | M] () MD5=ACD301711FC165ED77A8D364D407BAF9 -- C:\Program Files\CyberLink\PowerDirector\EventLog.dll

< MD5 for: EXPLORER.EXE >
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\SysWOW64\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2009.08.03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2009.10.31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\explorer.exe
[2009.10.31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2009.10.31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2009.08.03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: HAL.DLL >
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\SysNative\hal.dll
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll

< MD5 for: IASTORV.SYS >
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009.07.14 02:48:04 | 000,410,688 | ---- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: ISAPNP.SYS >
[2009.07.14 02:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\drivers\isapnp.sys
[2009.07.14 02:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\isapnp.sys
[2009.07.14 02:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\isapnp.sys

< MD5 for: LSASS.EXE >
[2009.07.14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\SysNative\lsass.exe
[2009.07.14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16385_none_023f7c69767c3edd\lsass.exe
[2009.07.14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.16484_none_023e7e05767d22ad\lsass.exe
[2009.07.14 02:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7600.20594_none_02bd4ae48fa2de68\lsass.exe

< MD5 for: NDIS.SYS >
[2009.07.14 02:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\SysNative\drivers\ndis.sys
[2009.07.14 02:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_03bc1d6e35c013bf\ndis.sys

< MD5 for: NETLOGON.DLL >
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\SysNative\netlogon.dll
[2009.07.14 02:41:52 | 000,692,736 | ---- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\SysWOW64\netlogon.dll
[2009.07.14 02:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVRAID.SYS >
[2009.07.14 02:48:27 | 000,149,056 | ---- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D -- C:\Windows\SysNative\drivers\nvraid.sys
[2009.07.14 02:48:27 | 000,149,056 | ---- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvraid.sys
[2009.07.14 02:48:27 | 000,149,056 | ---- | M] (NVIDIA Corporation) MD5=3E38712941E9BB4DDBEE00AFFE3FED3D -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvraid.sys

< MD5 for: NVSTOR.SYS >
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\drivers\nvstor.sys
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009.07.14 02:45:45 | 000,167,488 | ---- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< MD5 for: SMSS.EXE >
[2009.07.14 02:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\SysNative\smss.exe
[2009.07.14 02:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_082f99a432e2a661\smss.exe

< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: TCPIP.SYS >
[2010.06.14 07:39:16 | 001,889,152 | ---- | M] (Microsoft Corporation) MD5=542C6767C68C9D6AAACA59436B0D15C2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20733_none_0fd0b57e990e2079\tcpip.sys
[2010.04.09 12:06:28 | 001,898,376 | ---- | M] (Microsoft Corporation) MD5=7FC877A25796D8ADF539E64703FCA7E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16569_none_0f2ca8c580036f65\tcpip.sys
[2010.06.14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\SysNative\drivers\tcpip.sys
[2010.06.14 07:37:36 | 001,896,832 | ---- | M] (Microsoft Corporation) MD5=90A2D722CF64D911879D6C4A4F802A4D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16610_none_0f59b7ad7fe2fcc8\tcpip.sys
[2009.07.14 02:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
[2010.04.09 08:56:29 | 001,892,232 | ---- | M] (Microsoft Corporation) MD5=A9C0F786AC1F736891D05CE0A1D29DEB -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.20687_none_0f9ea52499331463\tcpip.sys

< MD5 for: USERINIT.EXE >
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WS2_32.DLL >
[2009.07.14 02:41:58 | 000,296,448 | ---- | M] (Microsoft Corporation) MD5=7083F463788CB34FCC42F565D56F89E8 -- C:\Windows\SysNative\ws2_32.dll
[2009.07.14 02:41:58 | 000,296,448 | ---- | M] (Microsoft Corporation) MD5=7083F463788CB34FCC42F565D56F89E8 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_4eaca269e8070c6b\ws2_32.dll
[2009.07.14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\SysWOW64\ws2_32.dll
[2009.07.14 02:16:20 | 000,206,336 | ---- | M] (Microsoft Corporation) MD5=DAAE8A9B8C0ACC7F858454132553C30D -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7600.16385_none_f28e06e62fa99b35\ws2_32.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2010.09.01 05:29:28 | 011,406,848 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysWOW64\wmp.dll
[4 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >
[2010.09.01 05:29:28 | 011,406,848 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\SysWOW64\wmp.dll
[4 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[4 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

========== Alternate Data Streams ==========

@Alternate Data Stream - 1259 bytes -> C:\ProgramData\Microsoft:ReHoWL3hwwQBJ9vi6RM2pm
@Alternate Data Stream - 1220 bytes -> C:\ProgramData\Microsoft:86F0wUQNRpKOQeLjCRQkFsG
@Alternate Data Stream - 1145 bytes -> C:\Program Files (x86)\Common Files\System:uyiQ563I7E353dofi6itvMwno
@Alternate Data Stream - 1111 bytes -> C:\ProgramData\Microsoft:3X4CaH1h3XU4p3LIZbRz8AR1EPzO

< End of report >

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 19:45
od Foxtrot
OTL Extras logfile created on: 4.2.2011 19:06:42 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Ondřej\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

6,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 54,00% Memory free
12,00 Gb Paging File | 10,00 Gb Available in Paging File | 79,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 897,23 Gb Total Space | 202,44 Gb Free Space | 22,56% Space Free | Partition Type: NTFS
Drive G: | 34,18 Gb Total Space | 34,09 Gb Free Space | 99,74% Space Free | Partition Type: NTFS

Computer Name: ONDŘEJ-PC | User Name: Ondřej | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html[@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = jsfile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = jsfile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3662217667-1811486626-224088579-1001\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.scr [@ = AutoCADScriptFile] -- C:\Windows\SysWow64\notepad.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %* File not found
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %* File not found
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [RapidShareManagerMail] -- C:\Program Files (x86)\RapidShareManager\RapidShareManager.exe -mailto "%1" (RapidShare AG)
Directory [RapidShareManagerUpload] -- C:\Program Files (x86)\RapidShareManager\RapidShareManager.exe -sendto "%1" (RapidShare AG)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [RapidShareManagerMail] -- C:\Program Files (x86)\RapidShareManager\RapidShareManager.exe -mailto "%1" (RapidShare AG)
Directory [RapidShareManagerUpload] -- C:\Program Files (x86)\RapidShareManager\RapidShareManager.exe -sendto "%1" (RapidShare AG)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0CC57810-C996-4C24-99C5-6BB09C3FACDA}" = Shutdown Timer
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{22441735-5983-AD2A-5CC5-FA2CCD7EF732}" = ATI Stream SDK v2 Developer
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{25613C10-27D2-410B-942B-D922D5C3A7BE}" = Interlok driver setup x64
"{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B55F339-396E-29A9-B6D0-24B6D251C90A}" = AMD Drag and Drop Transcoding
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5783F2D7-8001-0405-0102-0060B0CE6BBA}" = AutoCAD 2010 - česky
"{5783F2D7-8001-0405-1102-0060B0CE6BBA}" = Jazykový balíček aplikace AutoCAD 2010 - čeština
"{6448F0A8-6813-11D6-A77B-00B0D0150220}" = J2SE Runtime Environment 5.0 Update 22
"{65CCE260-0877-4DC2-9432-AFA29FB8534E}" = ESET NOD32 Antivirus
"{73BA9A8F-6B40-BF79-541E-464156FBA764}" = ccc-utility64
"{77B8B4A5-EE79-4907-A318-2DA86325B8D7}" = iTunes
"{790E02A1-145A-3843-8C13-A4F41C9B48B7}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0405-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Czech) 2007
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{A1E85B9A-AFAD-4D38-AF01-6B020DD5213A}" = Logitech GamePanel Software 3.06.109
"{A324DC11-FF02-3CE8-9D6F-67EBC006D970}" = Microsoft .NET Framework 4 Extended CSY Language Pack
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B361F88B-D513-9D45-E7F2-871B61C46D32}" = WMV9/VC-1 Video Playback
"{C2E0D3FE-12C4-BF5B-FC4E-052CB8833424}" = AMD Fuel
"{C5970161-E13E-6661-BBDA-A08268313C83}" = ATI Catalyst Install Manager
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{E5C95CA5-4565-4B9D-97ED-05088D775614}" = Apple Mobile Device Support
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AutoCAD 2010 - česky" = AutoCAD 2010 - česky
"AutoCAD 2010 - česky Version 3" = AutoCAD 2010 - česky Version 3
"Canon LBP5000" = Canon LBP5000
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended CSY Language Pack" = Microsoft .NET Framework 4 Extended CSY Language Pack
"SP6" = Logitech SetPoint 6.15
"TeamSpeak 3 Client" = TeamSpeak 3 Client

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{08B3869E-D282-424C-9AFC-870E04A4BA14}" = Rockstar Games Social Club
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{14C87AA7-08E6-419F-A165-998EBE5023D7}" = Oblivion - Knights of the Nine
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{16D919E6-F019-4E15-BFBE-4A85EF19DA57}" = Oblivion - Spell Tomes
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
"{26A24AE4-039D-4CA4-87B4-2F83216018F0}" = Java(TM) 6 Update 18
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 23
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2CB61EE3-E31F-4CAE-9FA8-3FCDB1CE4839}" = Charles Forsyth's Mask Converter
"{2D9F8079-7D50-3EFD-B3BD-ED642E4EE756}" = Microsoft Visual Basic PowerPacks 10.0
"{2F2E3D62-8B8C-448F-8900-451325E50948}" = Oblivion - Wizard's Tower
"{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{3ABEBD00-299D-4DCA-967F-B912163AB5EA}" = Oblivion - Horse Armor Pack
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{3FAD68D9-1FA1-4871-9ADF-9151D969E943}" = Activision(R)
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = The Sims™ 3 Po setmění
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{491D92A9-69CA-4EB4-81D3-0106F9337957}" = TurboV EVO
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{520F4B09-3A51-47A2-82B0-9FF1DC2D20FA}" = Oblivion - Vile Lair
"{5454083B-1308-4485-BF17-1110000D8301}" = Grand Theft Auto IV
"{5454083B-1308-4485-BF17-1110000D8302}" = Grand Theft Auto IV
"{5454083B-1308-4485-BF17-1110000D8303}" = Grand Theft Auto IV
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{5BDA2F58-1F21-4D10-9910-92B01EBCC958}" = AMD USB Filter Driver
"{5FD89EA1-99C2-40EE-BBF5-20F8991ED756}" = Catalyst Control Center - Branding
"{6331C6C0-3754-E910-7113-5013355C8E47}" = CCC Help English
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{652F3200-5E12-4CAD-BA2E-88EFE0113BCD}" = AMD OverDrive
"{675C161A-889A-4D35-8361-EA74BADCE0E6}" = Half-Life(R) 2
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}" = Adobe Flash Player 10 ActiveX
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = The Sims™ 3 Luxusní bydlení – Kolekce
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86A4C6D9-29EE-4719-AFA1-BA3341862B83}" = Microsoft Games for Windows - LIVE
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89CB9F02-F392-45AD-B429-B9373E6B7BE0}" = Activision
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{8D20B4D7-3422-4099-9332-39F27E617A6F}" = Autodesk Design Review 2011
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_HOMESTUDENTR_{294B4278-CF7B-40B9-86A1-2D3FF0C2C524}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_HOMESTUDENTR_{10EC59E5-9BCE-4884-BB1A-E28627220232}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0405-1000-0000000FF1CE}_HOMESTUDENTR_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_HOMESTUDENTR_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims™ 3 Povolání snů
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{95C3927C-C899-C5D8-0EA7-67895FC979B2}" = ccc-core-static
"{99E66BC9-E4B6-485F-ABFC-31EFCE36DFDF}" = Microsoft Keyboard Layout Creator 1.4
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C2AC00C-0C06-4B7E-97A4-A833808D54D6}" = EPU
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{A0A20753-92DF-4631-82B4-9CACE2FCED6A}" = Oblivion - The Fighter's Stronghold
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A31DA9F4-1108-412A-A89D-F0AC4EA12D75}" = Mumble 1.2.3
"{A3B42EE5-AEDA-47C9-9A3D-066445362E1D}" = S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0006]
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1029-7B44-A94000000001}" = Adobe Reader 9.4.1 - Czech
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3DFF4C8-50BA-463D-8334-4BAFE7172EA6}" = SB Arena Headset
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = The Sims™ 3 Cestovní horečka
"{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}" = Adobe Flash Player 10 Plugin
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C79312BD-3E76-4474-A10C-1435D1856A4B}" = Adobe Dreamweaver CS5
"{C9EAEE6B-741F-421D-B9CE-9FA300DA92AD}_is1" = Super Mario Bros. X version 1.3
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE4A3D0F-D1B0-47D1-BF99-3E957C548D12}" = LogMeIn Hamachi
"{CFC9F871-7C40-40B6-BE4A-B98A5B309716}" = Adobe Flash Professional CS5
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D3AE96EE-2876-4B3F-847C-D3A4AD689E43}" = LogMeIn
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D7BF3B76-EEF9-4868-9B2B-42ABF60B279A}" = Microsoft_VC80_CRT_x86
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.1.334
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{EC425CFC-EE78-4A91-AA25-3BFA65B75364}" = Oblivion - Orrery
"{ED4B50B7-C06B-57FE-7985-AA83DDBEEEF5}" = Catalyst Control Center Graphics Previews Common
"{EE531675-A09C-51DD-F356-ECA9D6857039}" = Adobe Community Help
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EF295F5C-7B57-47AA-8889-6B3E8E214E89}" = Oblivion - Mehrunes Razor
"{F01A9563-2A27-6ABC-2E04-03B7873DF7E0}" = Catalyst Control Center InstallProxy
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F138762F-5A1F-4CF0-A5E1-1588EF6088A4}" = Zaklínač
"{F38759F8-02B5-4829-B27A-20E2F0E269B2}" = S.T.A.L.K.E.R. - Shadow of Chernobyl
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFFFFD17-B460-41EB-93F1-C48ABAD63828}" = Oblivion - Thieves Den
"7-Zip" = 7-Zip 4.65
"Acoustica Effects Pack" = Acoustica Effects Pack
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Akamai" = Akamai NetSession Interface
"ALchemy" = Creative ALchemy
"Anti-Twin 2010-08-18 17.25.59" = Anti-Twin (Installation 26.8.2010)
"Any DWG to Image Converter_is1" = Any DWG to Image Converter 2010
"Any Video Converter_is1" = Any Video Converter 3.0.7
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"AudioCS" = Creative Audio Control Panel
"Autodesk Design Review 2011" = Autodesk Design Review 2011
"Avidemux 2.5" = Avidemux 2.5
"CDex" = CDex - Open Source Digital Audio CD Extractor
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition
"DAEMON Tools Lite" = DAEMON Tools Lite
"EADM" = EA Download Manager
"EasyBCD" = EasyBCD 2.0
"Emicsoft Video Converter_is1" = Emicsoft Video Converter
"Fraps" = Fraps
"Free MOV to AVI Converter_is1" = Free MOV to AVI Converter 1.2
"FreeCommander_is1" = FreeCommander 2009.02a
"Game Booster_is1" = Game Booster
"Google Chrome" = Google Chrome
"Half-Life" = Half-Life
"Half-Life 2 Episode One" = Half-Life 2 Episode One
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"InstallShield_{3FAD68D9-1FA1-4871-9ADF-9151D969E943}" = Singularity(TM)
"InstallShield_{89CB9F02-F392-45AD-B429-B9373E6B7BE0}" = Singularity(TM) 1.1 Patch
"InstallShield_{A3B42EE5-AEDA-47C9-9A3D-066445362E1D}" = S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0006]
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"InstallShield_{F38759F8-02B5-4829-B27A-20E2F0E269B2}" = S.T.A.L.K.E.R. - Shadow of Chernobyl
"JDownloader" = JDownloader
"LADSPA_plugins-win_is1" = LADSPA_plugins-win-0.4.15
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"lgooblivionshiveringislesczech_is1" = Lightning Oblivion Shivering Isles Czech
"LogMeIn Hamachi" = LogMeIn Hamachi
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MP4 to MP3 Converter 3" = MP4 to MP3 Converter 3
"Oblivion mod manager_is1" = Oblivion mod manager 1.1.12
"OCCT_is1" = OCCT Perestroika 3.1.0
"OpenAL" = OpenAL
"PC Translator" = PC Translator
"PFPortChecker" = PFPortChecker 1.0.39
"PunkBusterSvc" = PunkBuster Services
"RADVideo" = RAD Video Tools
"RapidShare Manager" = RapidShare Manager
"Sierra Utilities" = Sierra Utilities
"Simple Port Forwarding" = Simple Port Forwarding
"Space Rangers 2" = 1C\Space Rangers 2
"Steam App 10" = Counter-Strike
"Steam App 10190" = Call of Duty: Modern Warfare 2 - Multiplayer
"Steam App 13210" = Unreal Tournament 3: Black Edition
"Steam App 21970" = R.U.S.E
"Steam App 220" = Half-Life 2
"Steam App 240" = Counter-Strike: Source
"Steam App 400" = Portal
"Steam App 4000" = Garry's Mod
"Steam App 42700" = Call of Duty: Black Ops
"Steam App 42710" = Call of Duty: Black Ops - Multiplayer
"Steam App 43110" = Metro 2033
"Steam App 440" = Team Fortress 2
"Steam App 500" = Left 4 Dead
"Steam App 550" = Left 4 Dead 2
"Steam App 560" = Left 4 Dead 2 Dedicated Server
"Steam App 564" = Left 4 Dead 2 Add-on Support
"SUPER ©" = SUPER © Version 2010.bld.42 (Nov 7, 2010)
"SysInfo" = Creative System Information
"TiMoC1.2" = TiMoC
"Unofficial Oblivion Patch_is1" = Unofficial Oblivion Patch v3.2.0
"Unofficial Official Mods Patch_is1" = Unofficial Official Mods Patch v15
"Unofficial Shivering Isles Patch_is1" = Unofficial Shivering Isles Patch v1.4.0
"uTorrent" = µTorrent
"VideoCutter_is1" = Kate's Video Cutter
"VLC media player" = VLC media player 1.1.7
"Warcraft III" = Warcraft III
"X-Chat 2_is1" = X-Chat 2.8.6-2
"ZoneAlarm" = ZoneAlarm

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3662217667-1811486626-224088579-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Empire of Magic" = Empire of Magic - uninstall only
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 18.1.2011 16:36:49 | Computer Name = Ondřej-PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Služba Šifrování selhala při volání OnIdentity() v objektu System
Writer. Details: AddLegacyDriverFiles: Unable to back up image of binary Tpkd. System
Error: Systém nemůže nalézt uvedený soubor. .

Error - 18.1.2011 16:38:17 | Computer Name = Ondřej-PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Služba Šifrování selhala při volání OnIdentity() v objektu System
Writer. Details: AddLegacyDriverFiles: Unable to back up image of binary Tpkd. System
Error: Systém nemůže nalézt uvedený soubor. .

Error - 21.1.2011 7:07:22 | Computer Name = Ondřej-PC | Source = Windows Search Service | ID = 7040
Description =

Error - 21.1.2011 7:07:22 | Computer Name = Ondřej-PC | Source = Windows Search Service | ID = 7042
Description =

Error - 23.1.2011 13:31:22 | Computer Name = Ondřej-PC | Source = SideBySide | ID = 16842815
Description = Generování kontextu aktivace pro c:\program files (x86)\freecommander\DelZip179.dll
se nezdařilo. Chyba v souboru manifestu nebo zásady c:\program files (x86)\freecommander\DelZip179.dll
na řádku 8. Hodnota * atributu language v prvku assemblyIdentity je neplatná.

Error - 24.1.2011 16:00:15 | Computer Name = Ondřej-PC | Source = Bonjour Service | ID = 100
Description = 516: ERROR: read_msg errno 10054 (Stávající připojení bylo vynuceně
ukončeno vzdáleným hostitelem.)

Error - 27.1.2011 11:10:04 | Computer Name = Ondřej-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: score.exe, verze: 0.0.0.0, časové razítko:
0x2a425e19 Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7600.16385, časové
razítko: 0x4a5bdbdf Kód výjimky: 0x0eedfade Posun chyby: 0x0000b727 ID chybujícího
procesu: 0x136c Čas spuštění chybující aplikace: 0x01cbbe3278405032 Cesta k chybující
aplikaci: D:\score.exe Cesta k chybujícímu modulu: C:\Windows\syswow64\KERNELBASE.dll
ID
zprávy: 84362393-2a27-11e0-9586-485b39b3c58d

Error - 31.1.2011 13:55:55 | Computer Name = Ondřej-PC | Source = SideBySide | ID = 16842815
Description = Generování kontextu aktivace pro c:\program files (x86)\freecommander\DelZip179.dll
se nezdařilo. Chyba v souboru manifestu nebo zásady c:\program files (x86)\freecommander\DelZip179.dll
na řádku 8. Hodnota * atributu language v prvku assemblyIdentity je neplatná.

Error - 1.2.2011 18:28:49 | Computer Name = Ondřej-PC | Source = SideBySide | ID = 16842815
Description = Generování kontextu aktivace pro c:\program files (x86)\freecommander\DelZip179.dll
se nezdařilo. Chyba v souboru manifestu nebo zásady c:\program files (x86)\freecommander\DelZip179.dll
na řádku 8. Hodnota * atributu language v prvku assemblyIdentity je neplatná.

Error - 3.2.2011 13:49:54 | Computer Name = Ondřej-PC | Source = MsiInstaller | ID = 1013
Description =

[ System Events ]
Error - 4.2.2011 9:14:52 | Computer Name = Ondřej-PC | Source = EventLog | ID = 6008
Description = Předchozí vypnutí systému (14:13:10, ?4.?2.?2011) bylo neočekávané.

Error - 4.2.2011 9:14:40 | Computer Name = Ondřej-PC | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.

Error - 4.2.2011 9:16:49 | Computer Name = Ondřej-PC | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.

Error - 4.2.2011 9:17:06 | Computer Name = Ondřej-PC | Source = EventLog | ID = 6008
Description = Předchozí vypnutí systému (14:15:33, ?4.?2.?2011) bylo neočekávané.

Error - 4.2.2011 9:16:55 | Computer Name = Ondřej-PC | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.

Error - 4.2.2011 9:18:34 | Computer Name = Ondřej-PC | Source = Service Control Manager | ID = 7001
Description = Služba Zprostředkovatel domácích skupin závisí na službě Publikování
prostředků rozpoznávání funkcí, která neuspěla při spuštění v důsledku následující
chyby: %%1058

Error - 4.2.2011 9:22:30 | Computer Name = Ondřej-PC | Source = Service Control Manager | ID = 7030
Description = Služba TrueVector Internet Monitor je označena jako interaktivní služba.
Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby.
Tato služba nebude fungovat správně.

Error - 4.2.2011 9:25:28 | Computer Name = Ondřej-PC | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.

Error - 4.2.2011 9:25:40 | Computer Name = Ondřej-PC | Source = volmgr | ID = 262190
Description = Inicializace výpisu stavu systému se nezdařila.

Error - 4.2.2011 9:26:37 | Computer Name = Ondřej-PC | Source = Service Control Manager | ID = 7001
Description = Služba Zprostředkovatel domácích skupin závisí na službě Publikování
prostředků rozpoznávání funkcí, která neuspěla při spuštění v důsledku následující
chyby: %%1058


< End of report >

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 21:30
od Caroprd111
Obrázek Doporučuji odinstalovat Advanced SystemCare 3.


Obrázek Spusťte OTL a do spodního okna vložte následující skript.

Kód: Vybrat vše

:Commands
[EMPTYTEMP] 
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[RESETHOSTS] 

:OTL
IE - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\..\URLSearchHook: {7757CBCC-0975-4b79-A519-90B142CA3A23} - Reg Error: Value error. File not found
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{003D3EDC-99B9-4A34-9C20-60CB94F7E829}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{097D3191-E6FA-4728-9826-B533D755359D}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{20A82645-C095-46ED-80E3-08825760534B}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{64161300-E22B-11DB-8314-0800200C9A66}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{B9DB16A4-6EDC-47EC-A1F4-B86292ED211D}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\DEVICEDETECTION@LOGITECH.COM
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\JAYAKRISHNAN@GMAIL.COM
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\SMARTERWIKI@WIKIATIC.COM
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\SUPPORT@AUTO-HIDE-IP.COM
File not found (No name found) -- C:\USERS\ONDřEJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\5163027Y.DEFAULT\EXTENSIONS\YOUTUBE2MP3@MONDAYX.DE
O3 - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\..\Toolbar\WebBrowser: (no name) - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - No CLSID value found.
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\..Trusted Domains: mojebanka.cz ([www] https in Důvěryhodné servery)
O15 - HKU\S-1-5-21-3662217667-1811486626-224088579-1001\..Trusted Ranges: Range1979 ([http] in Důvěryhodné servery)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
@Alternate Data Stream - 1259 bytes -> C:\ProgramData\Microsoft:ReHoWL3hwwQBJ9vi6RM2pm
@Alternate Data Stream - 1220 bytes -> C:\ProgramData\Microsoft:86F0wUQNRpKOQeLjCRQkFsG
@Alternate Data Stream - 1145 bytes -> C:\Program Files (x86)\Common Files\System:uyiQ563I7E353dofi6itvMwno
@Alternate Data Stream - 1111 bytes -> C:\ProgramData\Microsoft:3X4CaH1h3XU4p3LIZbRz8AR1EPzO

:Files
c:\ostatni\archiv\oblivion\oblivion\oblivion\the elder scrolls 4 oblivion\crack
c:\program files (x86)\adobe\adobe dreamweaver cs5\configuration\taglibraries\html\keygen.vtm
c:\users\ondřej\downloads\pinnacle studio 14 hd ultimate collection - by mick (full version)\pinnacle studio 14 hd ultimate collection - by mick\pinnacle studio 14 hd ultimate collection - by mick\crack
Klikněte na Opravit, PC se restartuje, log vložte sem.

Re: nekolikrat restart pc, pomale nacitani

Napsal: 04 úno 2011 22:03
od Foxtrot
Program jsem nastavil, jak jste mi řekl v předchozích příspěvcích (i když to při opravě asi nemá žádný vliv), vložil tam ten skript, dal opravit a pc se restartovalo.

Poprvé se pc dostal k načítání windows 7 a předtím kdy tam má být ta modrá plocha a měly by se poté volit uživ. účty, to spadlo a pc se restartoval znovu,
podruhé se vyrestartoval a naběhla plocha, poté se chvíli spouštěli programy a pc zase spadlo,
potřetí jsem už nastavil bios na výchozí nastavení, jestli to není tím (nic se z biosu myslím stejně nezměnilo, protože jsem tam měl výchozí nastavení nastavené už měsíce předtím, když jsem neuspěl s taktováním procesoru), poté naběhla plocha a pc nespadlo, bohužel zamrzlo, takže jsem byl nucen restartovat ručně,
napočtvrté již se pc spustilo normálně.

Zjistil jsem že z plochy OTL zmizel a jsou tam teď dva soubory desktop.ini.
To jsou ty logy ? Nebo se něco pokazilo ?
Děkuji.

PS: Ještě předtím jsem na vaše doporučení odinstaloval Advanced SystemCare 3 a všechno co k němu patřilo.


Pokud ty dva soubory desktop.ini jsou ty logy, tak zde je co mi napsali:

1.soubor:

[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799
[LocalizedFileNames]
CyberLink PowerDirector.lnk=@C:\PROGRA~1\CYBERL~1\POWERD~1\MUITRA~1\PDRMUI~1.DLL,-101



2.soubor:

[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
IconResource=%SystemRoot%\system32\imageres.dll,-183