Stránka 1 z 1

Prosím o preventivku, děkuji!

Napsal: 15 bře 2011 14:36
od Ivya

Kód: Vybrat vše

Logfile of random's system information tool 1.08 (written by random/random)
Run by Iva at 2011-03-15 10:38:51
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 44 GB (51%) free of 85 GB
Total RAM: 1015 MB (36% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:39:25, on 15.3.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programy\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPSIsvc.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Programy\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Iva\Plocha\RSIT.exe
C:\Program Files\trend micro\Iva.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=antn&s={searchTerms}&f=4
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Iva\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) -  - (no file)
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Iva\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [avast5] "C:\Programy\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [PSUNMain] "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1299694414562
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Programy\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\WINDOWS\system32\HPSIsvc.exe
O23 - Service: Panda Cloud Antivirus Service (NanoServiceMain) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe

--
End of file - 8047 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3067136988-3948908401-139281464-1006Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3067136988-3948908401-139281464-1006UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Documents and Settings\Iva\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2009-02-10 119808]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-09-18 16855040]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2008-06-19 57344]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-12-19 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-12-19 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-12-19 131072]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2008-11-24 329728]
"AsusTray"=C:\Program Files\EeePC\ACPI\AsTray.exe [2008-12-04 114688]
"AsusACPIServer"=C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe [2008-12-17 622592]
"AsusEPCMonitor"=C:\Program Files\EeePC\ACPI\AsEPCMon.exe [2008-05-21 94208]
"avast5"=C:\Programy\Alwil Software\Avast5\avastUI.exe [2011-02-23 3451496]
"PSUNMain"=C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe [2011-02-24 423232]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-09-21 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe /background []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSUNMain]
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe [2011-02-24 423232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Bluetooth.lnk]
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2008-09-02 604776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Iva^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\Programy\MICROS~1\Office12\ONENOTEM.EXE []

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
SuperHybridEngine.lnk - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-08-11 267304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Programy\server\xampplite\apache\bin\httpd.exe"="C:\Programy\server\xampplite\apache\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"C:\Programy\server\xampplite\mysql\bin\mysqld.exe"="C:\Programy\server\xampplite\mysql\bin\mysqld.exe:*:Enabled:mysqld"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Programy\Skype\Phone\Skype.exe"="C:\Programy\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\Iva\Data aplikací\Dropbox\bin\Dropbox.exe"="C:\Documents and Settings\Iva\Data aplikací\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.txt - open - "C:\Programy\PSPad editor\PSPad.exe" "%1"

======List of files/folders created in the last 1 months======

2011-03-15 10:38:53 ----D---- C:\Program Files\trend micro
2011-03-15 10:38:51 ----D---- C:\rsit
2011-03-14 16:58:44 ----D---- C:\Documents and Settings\Iva\Data aplikací\SumatraPDF
2011-03-14 16:58:39 ----D---- C:\Program Files\SumatraPDF
2011-03-14 14:22:08 ----D---- C:\Program Files\Lavalys
2011-03-14 13:43:54 ----D---- C:\Hry
2011-03-13 12:13:43 ----D---- C:\Documents and Settings\Iva\Data aplikací\Malwarebytes
2011-03-13 12:13:27 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-03-13 12:13:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-03-13 12:13:20 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-03-13 12:13:19 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-03-12 19:11:12 ----ASH---- C:\hiberfil.sys
2011-03-12 13:51:31 ----D---- C:\Documents and Settings\Iva\Data aplikací\TuneUp Software
2011-03-12 13:50:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2011-03-12 13:50:07 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-03-12 00:33:52 ----D---- C:\Program Files\TGTSoft
2011-03-12 00:06:28 ----A---- C:\WINDOWS\StyleBuilder.INI
2011-03-11 14:50:37 ----D---- C:\WINDOWS\system32\NtmsData
2011-03-11 14:46:07 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2011-03-11 14:46:07 ----A---- C:\WINDOWS\system32\mucltui.dll
2011-03-09 19:01:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2479943$
2011-03-09 19:00:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2481109$
2011-03-09 16:00:49 ----D---- C:\WINDOWS\ie8updates
2011-03-09 15:57:34 ----HDC---- C:\WINDOWS\ie8
2011-03-09 15:23:02 ----D---- C:\Program Files\SpeedFan
2011-03-09 14:45:55 ----D---- C:\Program Files\ESET
2011-03-09 09:14:31 ----D---- C:\WINDOWS\system32\GroupPolicy
2011-03-08 11:19:40 ----D---- C:\Documents and Settings\Iva\Data aplikací\facemoods.com
2011-03-08 11:11:46 ----D---- C:\Documents and Settings\Iva\Data aplikací\ChemTable Software
2011-03-08 11:11:28 ----D---- C:\Program Files\Mozilla Firefox
2011-03-08 11:10:50 ----D---- C:\Program Files\Registry Life
2011-03-07 13:50:01 ----D---- C:\WINDOWS\LogOn Screen
2011-03-07 13:50:01 ----A---- C:\WINDOWS\XP ARENA.EXE
2011-03-06 22:46:53 ----D---- C:\Program Files\BookDB2
2011-03-06 18:45:06 ----D---- C:\Program Files\Microsoft Visual Studio
2011-03-06 18:45:05 ----D---- C:\Program Files\Common Files\DESIGNER
2011-03-06 18:39:44 ----D---- C:\Program Files\Microsoft.NET
2011-03-06 18:35:38 ----D---- C:\WINDOWS\SHELLNEW
2011-03-06 18:34:56 ----D---- C:\Program Files\Microsoft Office
2011-03-06 18:34:25 ----RHD---- C:\MSOCache
2011-03-06 10:25:25 ----D---- C:\Program Files\Snoworange
2011-03-06 10:22:07 ----D---- C:\Documents and Settings\Iva\Data aplikací\Apple Computer
2011-03-06 10:19:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Titanium
2011-03-06 00:30:54 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-03-06 00:09:14 ----D---- C:\Documents and Settings\Iva\Data aplikací\Softland
2011-03-06 00:08:57 ----A---- C:\WINDOWS\system32\dopdfmi7.dll
2011-03-06 00:08:56 ----A---- C:\WINDOWS\system32\dopdfmn7.dll
2011-03-06 00:08:55 ----D---- C:\Documents and Settings\Iva\Data aplikací\Panda Security
2011-03-06 00:08:47 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2011-03-06 00:08:43 ----D---- C:\Program Files\Softland
2011-03-06 00:07:51 ----A---- C:\WINDOWS\system32\temp.txt
2011-03-06 00:06:28 ----D---- C:\Program Files\Panda Security
2011-03-06 00:06:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Panda Security
2011-03-04 22:54:14 ----D---- C:\Documents and Settings\Iva\Data aplikací\Windows Live Writer
2011-03-04 22:42:59 ----D---- C:\Program Files\Common Files\SlimPDFReader
2011-03-04 22:42:58 ----D---- C:\Program Files\Investintech.com Inc
2011-03-04 21:04:13 ----D---- C:\Documents and Settings\Iva\Data aplikací\vlc
2011-03-04 21:03:01 ----D---- C:\Program Files\VideoLAN
2011-03-04 17:26:06 ----D---- C:\Documents and Settings\Iva\Data aplikací\.purple
2011-03-04 17:25:22 ----D---- C:\Program Files\Pidgin
2011-03-02 09:50:42 ----D---- C:\Program Files\aspicli
2011-02-28 11:17:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971029$
2011-02-27 21:21:01 ----A---- C:\WINDOWS\mafosav.INI
2011-02-27 21:17:44 ----D---- C:\Program Files\Mario Forever
2011-02-27 13:19:45 ----A---- C:\WINDOWS\system32\uxtheme.dll.backup
2011-02-25 22:39:23 ----A---- C:\WINDOWS\Papel.ini
2011-02-25 22:39:13 ----D---- C:\Program Files\Papel
2011-02-25 22:37:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Screentime

======List of files/folders modified in the last 1 months======

2011-03-15 10:39:09 ----D---- C:\WINDOWS\Prefetch
2011-03-15 10:38:53 ----RD---- C:\Program Files
2011-03-15 09:28:37 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-03-15 09:13:46 ----D---- C:\WINDOWS\Temp
2011-03-15 08:59:27 ----D---- C:\WINDOWS\system32\CatRoot2
2011-03-14 23:53:28 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-03-14 21:24:55 ----D---- C:\Documents and Settings\Iva\Data aplikací\Dropbox
2011-03-14 19:26:47 ----D---- C:\WINDOWS\system32\drivers
2011-03-14 12:43:42 ----D---- C:\WINDOWS\Debug
2011-03-13 15:35:02 ----D---- C:\Ikony
2011-03-13 02:22:09 ----SHD---- C:\WINDOWS\Installer
2011-03-13 02:21:21 ----D---- C:\WINDOWS\system32
2011-03-13 00:44:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2011-03-13 00:28:23 ----D---- C:\WINDOWS
2011-03-12 19:12:10 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-03-12 13:53:39 ----D---- C:\WINDOWS\system32\config
2011-03-12 01:12:39 ----RSD---- C:\WINDOWS\Fonts
2011-03-11 18:00:47 ----D---- C:\Program Files\Microsoft Silverlight
2011-03-11 17:59:00 ----D---- C:\WINDOWS\WinSxS
2011-03-11 14:46:07 ----HD---- C:\WINDOWS\inf
2011-03-09 22:44:51 ----D---- C:\Documents and Settings\Iva\Data aplikací\Skype
2011-03-09 19:13:45 ----SD---- C:\WINDOWS\Downloaded Program Files
2011-03-09 19:01:26 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-03-09 19:01:02 ----HD---- C:\WINDOWS\$hf_mig$
2011-03-09 16:03:25 ----D---- C:\WINDOWS\system32\cs-cz
2011-03-09 16:03:25 ----D---- C:\WINDOWS\Help
2011-03-09 16:03:25 ----D---- C:\Program Files\Internet Explorer
2011-03-09 15:59:26 ----D---- C:\WINDOWS\WBEM
2011-03-09 15:59:15 ----D---- C:\WINDOWS\Media
2011-03-09 15:40:42 ----D---- C:\WINDOWS\SoftwareDistribution
2011-03-07 16:07:32 ----RD---- C:\WINDOWS\Web
2011-03-06 23:54:19 ----D---- C:\Programy
2011-03-06 18:47:35 ----RSD---- C:\WINDOWS\assembly
2011-03-06 18:46:00 ----D---- C:\Program Files\Microsoft Works
2011-03-06 18:45:39 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-03-06 18:45:05 ----D---- C:\Program Files\Common Files
2011-03-06 18:17:40 ----D---- C:\Program Files\MSBuild
2011-03-06 18:12:05 ----D---- C:\Program Files\Common Files\System
2011-03-06 18:11:56 ----A---- C:\WINDOWS\win.ini
2011-03-05 00:25:04 ----D---- C:\WINDOWS\Microsoft.NET
2011-03-04 23:10:33 ----D---- C:\Program Files\Windows Live
2011-03-04 22:55:56 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-03-04 22:52:19 ----D---- C:\Program Files\Adobe
2011-03-04 22:52:14 ----D---- C:\Program Files\Common Files\Adobe
2011-03-04 22:52:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2011-03-02 19:56:50 ----A---- C:\WINDOWS\system32\MRT.exe
2011-03-01 14:17:38 ----D---- C:\WINDOWS\pss
2011-02-27 13:19:45 ----A---- C:\WINDOWS\system32\uxtheme.dll
2011-02-23 16:04:17 ----A---- C:\WINDOWS\system32\aswBoot.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-02-23 30680]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-02-23 25432]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-02-23 371544]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-02-23 301528]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-02-23 49240]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 PSINKNC;PSINKNC; C:\WINDOWS\system32\DRIVERS\psinknc.sys [2010-12-16 130376]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-02-23 19544]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-02-23 102232]
R2 PSINAflt;PSINAflt; C:\WINDOWS\system32\DRIVERS\PSINAflt.sys [2010-12-16 141768]
R2 PSINFile;PSINFile; C:\WINDOWS\system32\DRIVERS\PSINFile.sys [2010-12-16 97352]
R2 PSINProc;PSINProc; C:\WINDOWS\system32\DRIVERS\PSINProc.sys [2010-12-16 111944]
R2 PSINProt;PSINProt; C:\WINDOWS\system32\DRIVERS\PSINProt.sys [2010-12-16 113096]
R3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2008-09-18 1326528]
R3 AsusACPI;ASUS ACPI Driver; C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys [2008-04-08 10752]
R3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys [2008-02-04 37160]
R3 BTKRNL;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-08-19 991656]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-09-18 4816896]
R3 Ktp;Elantech Smart-Pad; C:\WINDOWS\system32\DRIVERS\ETD.sys [2008-11-27 25216]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-09-23 38400]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys [2008-05-30 534568]
S3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2008-07-24 156816]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-08-19 47272]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 mvusbews;USB EWS Device; C:\WINDOWS\System32\Drivers\mvusbews.sys [2009-10-26 17408]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Programy\Alwil Software\Avast5\AvastSvc.exe [2011-02-23 42184]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-09-02 346720]
R2 HPSIService;HP SI Service; C:\WINDOWS\system32\HPSIsvc.exe [2009-11-09 99896]
R2 NanoServiceMain;Panda Cloud Antivirus Service; C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe [2010-12-16 140608]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Prosím o preventivku, děkuji!

Napsal: 15 bře 2011 14:52
od vyosek
Zdravim a pekny den preji :)

:arrow: Nedavejte prosim logy do code, spatne se to cte a boli z toho oci

:arrow: Odinstalujte Panda Security - mate tam Avast, coz je dostatecna ochrana, navic dva antiviry v PC zpusobuji nestabilitu a zpomaleni - vice zde http://www.viry.cz/forum/viewtopic.php?f=29&t=2780

:arrow: Stahnete OTL (viz muj podpis) a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    netsvcs
    drivers32
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    c:\windows\*.* /U
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    /md5start
    adp3132.sys
    AGP440.sys
    ahcix86.sys
    ahcix86s.sys
    atapi.sys
    autochk.exe
    cdrom.sys
    cngaudit.dll
    cryptsvc.dll
    eNetHook.dll
    eventlog.dll
    explorer.exe
    hal.dll
    Changer.sys
    iaStor.sys
    iastorv.sys
    IdeChnDr.sys
    isapnp.sys
    JakNDis.sys
    KR10N.sys
    logevent.dll
    lsass.exe
    mv61xx.sys
    ndis.sys
    netlogon.dll
    ntelogon.dll
    nvata.sys
    nvatabus.sys
    nvgts.sys
    nvraid.sys
    nvrd32.sys
    nvstor.sys
    nvstor32.sys
    scecli.dll
    sceclt.dll
    smss.exe
    svchost.exe
    symmpi.sys
    tcpip.sys
    userinit.exe
    vaxscsi.sys
    viamraid.sys
    viasraid.sys
    ViPrt.sys
    winlogon.exe
    ws2_32.dll
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    CREATERESTOREPOINT
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 5 az 10 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte

Re: Prosím o preventivku, děkuji!

Napsal: 15 bře 2011 16:00
od Ivya
Děkuji za bleskovou odpověď, za Code se omlouvám ;)
Scan z OTL netrval 5-10 minut, ale přes půl hodiny, nicméně logy jsou zde:


OTL logfile created on: 15.3.2011 15:02:57 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Iva\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1 015,00 Mb Total Physical Memory | 561,00 Mb Available Physical Memory | 55,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 85,00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 82,82 Gb Total Space | 42,76 Gb Free Space | 51,63% Space Free | Partition Type: NTFS
Drive D: | 61,29 Gb Total Space | 50,50 Gb Free Space | 82,39% Space Free | Partition Type: NTFS

Computer Name: IVYAEEE | User Name: Iva | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2011.03.15 15:01:10 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Iva\Plocha\OTL.exe
PRC - [2011.03.11 07:50:03 | 001,004,088 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Iva\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
PRC - [2011.02.23 16:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Programy\Alwil Software\Avast5\AvastUI.exe
PRC - [2011.02.23 16:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Programy\Alwil Software\Avast5\AvastSvc.exe
PRC - [2009.11.09 19:57:54 | 000,099,896 | ---- | M] (HP) -- C:\WINDOWS\system32\HPSIsvc.exe
PRC - [2008.12.17 19:59:50 | 000,622,592 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
PRC - [2008.12.04 13:38:06 | 000,114,688 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\EeePC\ACPI\AsTray.exe
PRC - [2008.11.24 08:54:54 | 000,329,728 | ---- | M] (ELANTECH Devices Corp.) -- C:\Program Files\Elantech\ETDCTRL.EXE
PRC - [2008.11.14 14:55:56 | 000,376,832 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
PRC - [2008.05.21 01:56:24 | 000,094,208 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\EeePC\ACPI\AsEPCMon.exe
PRC - [2008.04.14 13:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2011.03.15 15:01:10 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Iva\Plocha\OTL.exe
MOD - [2011.02.23 16:04:17 | 000,197,208 | ---- | M] (AVAST Software) -- C:\Programy\Alwil Software\Avast5\snxhk.dll
MOD - [2010.08.23 17:12:33 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2008.11.21 09:24:58 | 000,264,704 | ---- | M] (ELANTECH Devices Corp.) -- C:\Program Files\Elantech\ETDAPIX.DLL


========== Win32 Services (SafeList) ==========

SRV - [2011.02.23 16:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programy\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2009.11.09 19:57:54 | 000,099,896 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPSIsvc.exe -- (HPSIService)


========== Driver Services (SafeList) ==========

DRV - [2011.02.23 15:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011.02.23 15:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011.02.23 15:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011.02.23 15:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011.02.23 15:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011.02.23 15:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011.02.23 15:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009.10.26 08:01:40 | 000,017,408 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mvusbews.sys -- (mvusbews)
DRV - [2008.09.23 18:15:00 | 000,038,400 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1e51x86.sys -- (L1e)
DRV - [2008.09.18 19:44:38 | 001,326,528 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\athw.sys -- (AR5416)
DRV - [2008.09.18 11:48:58 | 004,816,896 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008.08.19 15:16:36 | 000,991,656 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2008.08.19 15:16:28 | 000,047,272 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2008.07.24 10:37:10 | 000,156,816 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2008.05.30 04:46:12 | 000,534,568 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2008.04.08 15:59:28 | 000,010,752 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASUSACPI.SYS -- (AsusACPI)
DRV - [2008.02.04 10:57:44 | 000,037,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2006.09.24 14:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [1996.04.03 20:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=antn&s={searchTerms}&f=4


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Iva\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://seznam.cz/"
FF - prefs.js..extensions.enabledItems: testpilot@labs.mozilla.com:1.0.6

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.03.10 08:31:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.03.10 08:36:23 | 000,000,000 | ---D | M]

[2011.03.10 08:32:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Extensions
[2011.02.09 20:43:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Extensions\celtx@celtx.com
[2011.03.06 10:27:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Extensions\doit@snoworange.com
[2010.01.19 11:39:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Extensions\xulrunner@yoono.com
[2011.03.07 22:35:11 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions
[2011.03.07 22:35:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}
[2011.03.07 22:34:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\firebug@software.joehewitt.com
[2011.03.07 22:34:57 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\twitternotifier@naan.net
[2011.03.13 12:12:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions
[2011.03.13 12:11:15 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.03.13 12:28:59 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com
[2011.03.13 12:12:29 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com-trash
[2011.03.08 13:38:11 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\staged
[2011.03.10 08:34:43 | 000,000,000 | ---D | M] (Feedback) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\testpilot@labs.mozilla.com
[2011.03.10 08:30:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\T9GIZHW3.DEFAULT\EXTENSIONS\{20A82645-C095-46ED-80E3-08825760534B}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\T9GIZHW3.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM
[2011.03.08 11:11:42 | 000,002,047 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrchantn.xml
[2011.03.03 18:52:54 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2011.03.03 18:52:54 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2011.03.03 18:52:54 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2011.03.03 18:52:54 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2011.03.03 18:52:54 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2008.04.14 13:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (QIPBHO Class) - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Iva\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O3 - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [avast5] C:\Programy\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCTRL.EXE (ELANTECH Devices Corp.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\SuperHybridEngine.lnk = C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microso ... 9694414562 (MUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.200.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (%windir%\XP ARENA.exe) - C:\WINDOWS\XP ARENA.EXE (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Iva\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Iva\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.02.04 15:10:10 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{52012080-4bdf-11df-ab20-00248c4d6756}\Shell - "" = AutoRun
O33 - MountPoints2\{52012080-4bdf-11df-ab20-00248c4d6756}\Shell\AutoRun\command - "" = "E:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)

========== Files/Folders - Created Within 7 Days ==========

[2011.03.15 15:01:07 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Iva\Plocha\OTL.exe
[2011.03.15 14:55:36 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011.03.15 14:54:03 | 000,519,680 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Iva\Plocha\OTM.exe
[2011.03.15 12:03:45 | 000,017,544 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\RkPavproc1.sys
[2011.03.15 10:38:53 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.03.15 10:38:51 | 000,000,000 | ---D | C] -- C:\rsit
[2011.03.14 16:58:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Iva\Data aplikací\SumatraPDF
[2011.03.14 16:58:39 | 000,000,000 | ---D | C] -- C:\Program Files\SumatraPDF
[2011.03.14 14:22:08 | 000,000,000 | ---D | C] -- C:\Program Files\Lavalys
[2011.03.14 13:51:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Iva\Dokumenty\OpenTTD
[2011.03.14 13:50:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Iva\Nabídka Start\Programy\OpenTTD
[2011.03.14 13:43:54 | 000,000,000 | ---D | C] -- C:\Hry
[2011.03.13 12:13:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Iva\Data aplikací\Malwarebytes
[2011.03.13 12:13:27 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.03.13 12:13:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
[2011.03.13 12:13:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.03.13 12:13:20 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.03.13 12:13:19 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.03.12 13:51:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Iva\Data aplikací\TuneUp Software
[2011.03.12 13:50:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2011.03.12 13:50:07 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2011.03.12 00:33:52 | 000,000,000 | ---D | C] -- C:\Program Files\TGTSoft
[2011.03.12 00:26:41 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Iva\Recent
[2011.03.11 14:50:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2011.03.11 14:46:07 | 000,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2011.03.11 14:46:07 | 000,017,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
[2011.03.09 16:07:10 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Iva\PrivacIE
[2011.03.09 16:03:45 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Iva\IETldCache
[2011.03.09 16:00:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2011.03.09 15:59:56 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2011.03.09 15:57:34 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2011.03.09 15:23:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Iva\Nabídka Start\Programy\SpeedFan
[2011.03.09 15:23:02 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedFan
[2011.03.09 09:14:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2009.02.04 18:29:39 | 015,523,560 | ---- | C] (Macrovision Corporation) -- C:\Program Files\U1 Setup.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2011.03.15 15:01:10 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Iva\Plocha\OTL.exe
[2011.03.15 14:58:41 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.03.15 14:58:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.03.15 14:58:08 | 1064,554,496 | -HS- | M] () -- C:\hiberfil.sys
[2011.03.15 14:54:09 | 000,519,680 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Iva\Plocha\OTM.exe
[2011.03.15 14:37:01 | 000,001,018 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3067136988-3948908401-139281464-1006UA.job
[2011.03.15 14:33:56 | 000,008,972 | ---- | M] () -- C:\Documents and Settings\Iva\Dokumenty\Lakrits2.Theme
[2011.03.15 10:38:42 | 000,339,991 | ---- | M] () -- C:\Documents and Settings\Iva\Plocha\RSIT.exe
[2011.03.14 21:34:22 | 000,022,016 | ---- | M] () -- C:\Documents and Settings\Iva\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.03.14 15:17:57 | 000,000,110 | ---- | M] () -- C:\WINDOWS\Papel.ini
[2011.03.14 14:29:21 | 000,008,769 | ---- | M] () -- C:\Documents and Settings\Iva\Dokumenty\Royal Vista.Theme
[2011.03.14 13:53:15 | 000,001,404 | ---- | M] () -- C:\Documents and Settings\Iva\Plocha\OpenTTD.lnk
[2011.03.13 15:38:27 | 000,001,494 | ---- | M] () -- C:\Documents and Settings\Iva\Plocha\The Guide.lnk
[2011.03.13 15:37:41 | 000,001,902 | ---- | M] () -- C:\Documents and Settings\Iva\Plocha\GeeTeeDee.lnk
[2011.03.13 15:37:05 | 000,001,418 | ---- | M] () -- C:\Documents and Settings\Iva\Plocha\Papel.lnk
[2011.03.13 15:36:44 | 000,001,504 | ---- | M] () -- C:\Documents and Settings\Iva\Plocha\yWriter.lnk
[2011.03.13 12:30:38 | 000,019,354 | ---- | M] () -- C:\Documents and Settings\Iva\Dokumenty\cc_20110313_123033.reg
[2011.03.13 00:37:01 | 000,000,966 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3067136988-3948908401-139281464-1006Core.job
[2011.03.12 19:12:10 | 000,444,362 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.03.12 19:12:10 | 000,441,324 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2011.03.12 19:12:10 | 000,083,940 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2011.03.12 19:12:10 | 000,072,238 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.03.12 13:06:56 | 000,322,728 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.03.12 00:10:16 | 000,000,045 | ---- | M] () -- C:\TEST.XML
[2011.03.12 00:06:28 | 000,000,088 | ---- | M] () -- C:\WINDOWS\StyleBuilder.INI
[2011.03.11 18:35:24 | 000,001,805 | ---- | M] () -- C:\Documents and Settings\Iva\Plocha\Dropbox.lnk
[2011.03.09 15:23:10 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\Iva\Plocha\SpeedFan.lnk
[2011.03.09 15:23:02 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo
[2011.03.09 14:37:51 | 000,008,983 | ---- | M] () -- C:\Documents and Settings\Iva\Dokumenty\Shiftie Dark Mini.Theme
[2011.03.08 16:22:23 | 000,000,396 | ---- | M] () -- C:\Documents and Settings\Iva\Dokumenty\bluetooth.reg
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.03.15 10:38:42 | 000,339,991 | ---- | C] () -- C:\Documents and Settings\Iva\Plocha\RSIT.exe
[2011.03.14 14:29:20 | 000,008,769 | ---- | C] () -- C:\Documents and Settings\Iva\Dokumenty\Royal Vista.Theme
[2011.03.14 13:50:09 | 000,001,404 | ---- | C] () -- C:\Documents and Settings\Iva\Plocha\OpenTTD.lnk
[2011.03.13 12:30:36 | 000,019,354 | ---- | C] () -- C:\Documents and Settings\Iva\Dokumenty\cc_20110313_123033.reg
[2011.03.12 19:11:12 | 1064,554,496 | -HS- | C] () -- C:\hiberfil.sys
[2011.03.12 01:38:03 | 000,008,972 | ---- | C] () -- C:\Documents and Settings\Iva\Dokumenty\Lakrits2.Theme
[2011.03.12 00:10:16 | 000,000,045 | ---- | C] () -- C:\TEST.XML
[2011.03.12 00:06:28 | 000,000,088 | ---- | C] () -- C:\WINDOWS\StyleBuilder.INI
[2011.03.09 15:23:10 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\Iva\Plocha\SpeedFan.lnk
[2011.03.09 15:22:59 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\initdebug.nfo
[2011.03.08 16:22:23 | 000,000,396 | ---- | C] () -- C:\Documents and Settings\Iva\Dokumenty\bluetooth.reg
[2011.02.27 21:21:01 | 000,000,020 | ---- | C] () -- C:\WINDOWS\mafosav.INI
[2011.02.25 22:39:23 | 000,000,110 | ---- | C] () -- C:\WINDOWS\Papel.ini
[2010.10.26 14:23:36 | 000,000,043 | ---- | C] () -- C:\WINDOWS\aspicalc.INI
[2010.10.05 17:50:52 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\HP1100SM.EXE
[2010.10.05 17:50:51 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\HP1100LM.DLL
[2010.10.05 17:50:06 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\mvusbews.dll
[2010.10.05 17:50:01 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\HP1100SMs.dll
[2010.10.05 17:49:50 | 000,284,160 | ---- | C] () -- C:\WINDOWS\System32\mvhlewsi.dll
[2009.11.19 23:15:16 | 000,022,016 | ---- | C] () -- C:\Documents and Settings\Iva\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.10.14 21:06:54 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\sh33w32.dll
[2009.09.15 00:16:25 | 000,000,123 | ---- | C] () -- C:\Documents and Settings\Iva\Local Settings\Data aplikací\fusioncache.dat
[2009.09.14 17:11:46 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Iva\Data aplikací\wklnhst.dat
[2009.09.14 17:10:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009.04.01 09:48:16 | 000,053,478 | ---- | C] () -- C:\WINDOWS\mvtcpui.ini
[2009.02.04 18:21:11 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2009.02.04 18:19:23 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\SamSfPa.dat
[2009.02.04 16:01:14 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009.02.04 16:00:15 | 000,322,728 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009.02.04 15:53:40 | 000,005,312 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2009.02.04 15:53:35 | 000,441,324 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2009.02.04 15:53:35 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2009.02.04 15:53:35 | 000,083,940 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2009.02.04 15:53:35 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2009.02.04 15:53:29 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2009.02.04 15:53:28 | 000,444,362 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2009.02.04 15:53:28 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2009.02.04 15:53:28 | 000,072,238 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2009.02.04 15:53:28 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2009.02.04 15:53:27 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2009.02.04 15:53:27 | 000,004,562 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2009.02.04 15:53:26 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2009.02.04 15:53:25 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2009.02.04 15:53:25 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2009.02.04 15:53:22 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2009.02.04 15:53:21 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2009.02.04 15:12:54 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009.02.04 15:07:42 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009.02.04 13:22:26 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008.11.14 18:12:56 | 000,012,208 | ---- | C] () -- C:\WINDOWS\AsTrayLang.ini
[2008.09.02 07:25:26 | 002,854,912 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2008.08.28 04:10:24 | 000,000,173 | ---- | C] () -- C:\WINDOWS\explorer.exe.config
[2008.07.30 19:31:52 | 000,021,864 | ---- | C] () -- C:\WINDOWS\AsAcpiSvrLang.ini
[2001.11.14 13:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1996.04.03 20:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2010.12.11 23:19:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2011.03.06 00:06:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Panda Security
[2011.02.25 22:37:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Screentime
[2010.03.12 14:02:45 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\System Restore
[2011.03.06 10:21:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Titanium
[2011.03.13 02:22:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2011.03.12 13:50:07 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2011.03.08 19:14:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\.purple
[2011.03.08 11:11:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\ChemTable Software
[2011.03.14 21:24:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Dropbox
[2011.03.08 11:19:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\facemoods.com
[2011.01.20 20:26:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\FileZilla
[2010.03.12 13:25:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\FireShot
[2011.01.19 23:46:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\GHISLER
[2011.01.21 20:51:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\gtk-2.0
[2011.03.06 00:08:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Panda Security
[2011.01.22 12:46:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\PDM
[2009.09.14 18:07:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\QIP
[2011.03.06 00:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Softland
[2011.01.19 23:51:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Spacejock Software
[2011.03.14 16:59:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\SumatraPDF
[2011.03.12 19:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\TuneUp Software
[2011.03.04 22:54:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Windows Live Writer
[2011.03.06 00:09:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Softland

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 13:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation)

< c:\windows\*.* /U >

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2011.03.08 19:14:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\.purple
[2009.10.08 20:54:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Adobe
[2011.03.06 10:22:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Apple Computer
[2011.03.08 11:11:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\ChemTable Software
[2009.10.14 21:18:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Corel
[2009.10.22 22:39:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Creative
[2011.03.14 21:24:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Dropbox
[2011.03.08 11:19:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\facemoods.com
[2011.01.20 20:26:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\FileZilla
[2010.03.12 13:25:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\FireShot
[2011.01.19 23:46:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\GHISLER
[2011.01.21 20:51:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\gtk-2.0
[2009.10.14 21:18:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Help
[2009.02.04 15:14:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Identities
[2009.02.04 18:21:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\InstallShield
[2009.09.14 17:34:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Macromedia
[2011.03.13 12:13:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Malwarebytes
[2011.01.22 17:14:15 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Iva\Data aplikací\Microsoft
[2009.09.14 17:10:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Mozilla
[2011.03.06 00:08:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Panda Security
[2011.01.22 12:46:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\PDM
[2009.09.14 17:46:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\PSpad
[2009.09.14 18:07:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\QIP
[2011.03.09 22:44:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Skype
[2011.03.06 00:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Softland
[2011.01.19 23:51:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Spacejock Software
[2011.03.14 16:59:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\SumatraPDF
[2011.03.12 19:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\TuneUp Software
[2011.03.14 21:35:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\vlc
[2011.03.04 22:54:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\Windows Live Writer
[2009.09.20 18:34:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\WinRAR

< %APPDATA%\*.exe /s >
[2011.01.27 06:40:24 | 023,361,424 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Iva\Data aplikací\Dropbox\bin\Dropbox.exe
[2011.01.27 06:40:30 | 000,153,176 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Iva\Data aplikací\Dropbox\bin\Uninstall.exe


< MD5 for: AGP440.SYS >
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp3.cab:AGP440.sys

< MD5 for: ATAPI.SYS >
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 13:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 13:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\I386\AUTOCHK.EXE
[2008.04.14 13:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2008.04.14 13:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\dllcache\autochk.exe

< MD5 for: CDROM.SYS >
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp3.cab:cdrom.sys
[2008.04.14 13:00:00 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2008.04.14 13:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 13:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\dllcache\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2008.04.14 13:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.14 13:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 13:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 13:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: HAL.DLL >
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp3.cab:hal.dll
[2008.04.14 13:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\hal.dll

< MD5 for: CHANGER.SYS >
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp3.cab:Changer.sys

< MD5 for: ISAPNP.SYS >
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp3.cab:isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\dllcache\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 13:00:00 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\isapnp.sys

< MD5 for: LSASS.EXE >
[2008.04.14 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.14 13:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys
[2008.04.14 13:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: NETLOGON.DLL >
[2008.04.14 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008.04.14 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008.04.14 13:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 13:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SMSS.EXE >
[2008.04.14 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
[2008.04.14 13:00:00 | 000,481,792 | ---- | M] (Microsoft Corporation) MD5=F209B5C79A87A9521DC0BD88B039EEE3 -- C:\WINDOWS\I386\SYSTEM32\SMSS.EXE

< MD5 for: SVCHOST.EXE >
[2008.04.14 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.14 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.04.14 13:00:00 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 13:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 13:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008.04.14 13:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 13:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2008.04.14 13:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2008.04.14 13:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009.02.04 15:59:44 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009.02.04 15:59:44 | 001,069,056 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009.02.04 15:59:43 | 000,479,232 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2011.03.12 19:12:10 | 000,083,940 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2011.03.12 19:12:10 | 000,072,238 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2011.03.12 19:12:10 | 000,441,324 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2011.03.12 19:12:10 | 000,444,362 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2011.03.12 19:12:10 | 001,054,506 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2011.03.15 14:58:41 | 000,001,158 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< End of report >

Re: Prosím o preventivku, děkuji!

Napsal: 15 bře 2011 16:01
od Ivya
OTL Extras logfile created on: 15.3.2011 15:02:57 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Iva\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1 015,00 Mb Total Physical Memory | 561,00 Mb Available Physical Memory | 55,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 85,00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 82,82 Gb Total Space | 42,76 Gb Free Space | 51,63% Space Free | Partition Type: NTFS
Drive D: | 61,29 Gb Total Space | 50,50 Gb Free Space | 82,39% Space Free | Partition Type: NTFS

Computer Name: IVYAEEE | User Name: Iva | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Programy\server\xampplite\apache\bin\httpd.exe" = C:\Programy\server\xampplite\apache\bin\httpd.exe:*:Enabled:Apache HTTP Server -- (Apache Software Foundation)
"C:\Programy\server\xampplite\mysql\bin\mysqld.exe" = C:\Programy\server\xampplite\mysql\bin\mysqld.exe:*:Enabled:mysqld -- ()
"C:\Documents and Settings\Iva\Data aplikací\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Iva\Data aplikací\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{19F5658D-92E8-4A08-8657-D38ABB1574B2}" = Asus ACPI Driver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4EA44BA4-A708-4223-BC1A-22B6DA9E7D1C}" = Windows Live Essentials
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate for Eee PC
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6E4DAE31-7CF3-441A-B6E5-B014D63C80CD}" = Eee Instant Key
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7E1FEE27-F869-4D4B-8AA3-64C7FD99BD7C}_is1" = SlimPDF Reader
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = Software Bluetooth WIDCOMM
"{88F08F98-12BC-4613-81A2-8F9B88CFC73E}" = Super Hybrid Engine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0405-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Czech) 12
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A13DE9CB-8C84-4889-B114-C5A9661F844E}" = Windows Live Fotogalerie
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"CDXACA_is1" = CODEXIS ACADEMIA 4.78.1
"doPDF 7 printer_is1" = doPDF 7.2 printer
"Elantech" = ETDWare PS/2-x86 7.0.3.12 For XP WHQL
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FileZilla Client" = FileZilla Client 3.3.5.1
"Fliqlo" = Fliqlo Screen Saver
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HP LaserJet Professional P1100-P1560-P1600 Series" = HP LaserJet Professional P1100-P1560-P1600 Series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OpenTTD" = OpenTTD 1.0.5
"Papel_is1" = Papel 6.10.20
"Pidgin" = Pidgin
"PSPad editor_is1" = PSPad editor
"Registry Life_is1" = Registry Life version 1.26
"SpeedFan" = SpeedFan (remove only)
"SumatraPDF" = SumatraPDF
"The Guide" = The Guide
"Totalcmd" = Total Commander (Remove or Repair)
"VLC media player" = VLC media player 1.1.7
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"yWriter5_is1" = yWriter5

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"C8F31CA0-0667-467c-B205-B0A0291603E6" = GeeTeeDee
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"QIP Infium" = QIP Infium 2.0.9034

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 24.11.2010 13:50:18 | Computer Name = IVY046 | Source = avast! | ID = 33554522
Description =

Error - 24.11.2010 13:50:18 | Computer Name = IVY046 | Source = avast! | ID = 33554522
Description =

Error - 24.11.2010 13:50:19 | Computer Name = IVY046 | Source = avast! | ID = 33554522
Description =

Error - 24.11.2010 13:50:19 | Computer Name = IVY046 | Source = avast! | ID = 33554522
Description =

Error - 24.11.2010 13:50:19 | Computer Name = IVY046 | Source = avast! | ID = 33554522
Description =

Error - 24.11.2010 13:50:19 | Computer Name = IVY046 | Source = avast! | ID = 33554522
Description =

Error - 24.11.2010 13:50:19 | Computer Name = IVY046 | Source = avast! | ID = 33554522
Description =

Error - 24.11.2010 13:50:19 | Computer Name = IVY046 | Source = avast! | ID = 33554522
Description =

Error - 24.11.2010 13:50:19 | Computer Name = IVY046 | Source = avast! | ID = 33554522
Description =

Error - 24.11.2010 13:50:19 | Computer Name = IVY046 | Source = avast! | ID = 33554522
Description =

[ Application Events ]
Error - 5.3.2011 19:08:39 | Computer Name = IVY046 | Source = crypt32 | ID = 131083
Description = Extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou
aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>
se nezdařilo. Chyba: Při ověření se systémovými hodinami nebo časovým razítkem
podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.


Error - 6.3.2011 5:19:07 | Computer Name = IVY046 | Source = Application Error | ID = 1000
Description = Chybující aplikace msiexec.exe, verze 3.1.4001.5512, chybující modul
msi8.tmp, verze 0.0.0.0, adresa chyby 0x00040e2b.

Error - 8.3.2011 4:52:15 | Computer Name = IVY046 | Source = Application Error | ID = 1000
Description = Chybující aplikace chrome.exe, verze 0.0.0.0, chybující modul chrome.dll,
verze 9.0.597.107, adresa chyby 0x002a018e.

Error - 8.3.2011 4:53:13 | Computer Name = IVY046 | Source = Application Error | ID = 1000
Description = Chybující aplikace drwtsn32.exe, verze 5.1.2600.0, chybující modul
dbghelp.dll, verze 5.1.2600.5512, adresa chyby 0x0001295d.

Error - 8.3.2011 4:55:23 | Computer Name = IVY046 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace chrome.exe, verze 0.0.0.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 8.3.2011 4:55:26 | Computer Name = IVY046 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace chrome.exe, verze 0.0.0.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 8.3.2011 4:55:34 | Computer Name = IVY046 | Source = Application Hang | ID = 1001
Description = Chybný blok 35273598

Error - 12.3.2011 10:52:09 | Computer Name = IVY046 | Source = EventSystem | ID = 4614
Description = Systém událostí modelu COM+ zjistil nekonzistenci vnitřního stavu.
Výraz GetLastError() == 122L selhal na řádku 162 v d:\comxp_sp3\com\com1x\src\events\shared\sectools.cpp.
Obraťte se na služby odborné pomoci společnosti Microsoft a informujte je o této
chyb

Error - 15.3.2011 4:28:34 | Computer Name = IVYAEEE | Source = Application Error | ID = 1000
Description = Chybující aplikace chrome.exe, verze 0.0.0.0, chybující modul gcswf32.dll,
verze 10.2.154.18, adresa chyby 0x00142d05.

Error - 15.3.2011 4:34:46 | Computer Name = IVYAEEE | Source = Application Error | ID = 1000
Description = Chybující aplikace chrome.exe, verze 0.0.0.0, chybující modul gcswf32.dll,
verze 10.2.154.18, adresa chyby 0x00382100.

[ System Events ]
Error - 9.3.2011 3:03:57 | Computer Name = IVY046 | Source = Dhcp | ID = 1002
Description = Zapůjčení adresy IP 10.0.0.6 pro síťovou kartu s adresou 00224371B42F
byla serverem DHCP 192.168.200.1 odmítnuta. (Server DHCP odeslal zprávu DHCPNACK).

Error - 10.3.2011 6:56:11 | Computer Name = IVY046 | Source = Dhcp | ID = 1002
Description = Zapůjčení adresy IP 10.0.0.6 pro síťovou kartu s adresou 00224371B42F
byla serverem DHCP 192.168.200.1 odmítnuta. (Server DHCP odeslal zprávu DHCPNACK).

Error - 11.3.2011 16:39:17 | Computer Name = IVY046 | Source = Dhcp | ID = 1000
Description = Zapůjčení adresy IP počítače 192.168.1.102 pro síťovou kartu se síťovou
adresou 00224371B42F byla ukončena.

Error - 12.3.2011 8:53:35 | Computer Name = IVY046 | Source = Service Control Manager | ID = 7000
Description = Služba TuneUp Theme Extension neuspěla při spuštění v důsledku následující
chyby: %%1083

Error - 12.3.2011 18:10:06 | Computer Name = IVY046 | Source = PlugPlayManager | ID = 12
Description = Zařízení AzureWave Wireless Network Adapter (PCI\VEN_168C&DEV_002A&SUBSYS_10671A3B&REV_01\4&37028e5f&0&00E3)
se již v systému nenachází, aniž by bylo nejdříve připraveno k odstranění.

Error - 13.3.2011 15:59:02 | Computer Name = IVY046 | Source = Dhcp | ID = 1000
Description = Zapůjčení adresy IP počítače 192.168.1.102 pro síťovou kartu se síťovou
adresou 00224371B42F byla ukončena.

Error - 13.3.2011 20:35:45 | Computer Name = IVY046 | Source = Dhcp | ID = 1000
Description = Zapůjčení adresy IP počítače 192.168.1.102 pro síťovou kartu se síťovou
adresou 00224371B42F byla ukončena.

Error - 15.3.2011 6:55:01 | Computer Name = IVYAEEE | Source = Dhcp | ID = 1002
Description = Zapůjčení adresy IP 10.0.0.5 pro síťovou kartu s adresou 00224371B42F
byla serverem DHCP 192.168.200.1 odmítnuta. (Server DHCP odeslal zprávu DHCPNACK).

Error - 15.3.2011 9:58:33 | Computer Name = IVYAEEE | Source = Dhcp | ID = 1001
Description = Počítači nebyla přiřazena síťová adresa (serverem DHCP) pro síťovou
kartu se síťovou adresou 00224371B42F. Došlo k následující chybě: %%1223. Počítač
se bude pokoušet získat síťovou adresu samostatně ze serveru DHCP.

Error - 15.3.2011 10:09:00 | Computer Name = IVYAEEE | Source = PlugPlayManager | ID = 12
Description = Zařízení AzureWave Wireless Network Adapter (PCI\VEN_168C&DEV_002A&SUBSYS_10671A3B&REV_01\4&37028e5f&0&00E3)
se již v systému nenachází, aniž by bylo nejdříve připraveno k odstranění.


< End of report >

Re: Prosím o preventivku, děkuji!

Napsal: 15 bře 2011 16:15
od vyosek
:arrow: Asi se OTLku Vas PC libil, tak si tam chtel poradne zaradit :D U skenu zalezi hodne na rychlosti PC a kolika soubory se musi prodirat

:arrow: Spustte znovu OTL
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :otl
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=antn&s={searchTerms}&f=4
    IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
    IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
    IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
    IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
    IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\..\URLSearchHook: - Reg Error: Key error. File not found
    IE - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Iva\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
    [2011.02.09 20:43:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Extensions\celtx@celtx.com
    [2011.03.06 10:27:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Extensions\doit@snoworange.com
    [2010.01.19 11:39:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Extensions\xulrunner@yoono.com
    [2011.03.07 22:35:11 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions
    [2011.03.07 22:35:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}
    [2011.03.07 22:34:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\firebug@software.joehewitt.com
    [2011.03.07 22:34:57 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\twitternotifier@naan.net
    [2011.03.13 12:28:59 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com
    [2011.03.13 12:12:29 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com-trash
    [2011.03.08 13:38:11 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\staged
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\T9GIZHW3.DEFAULT\EXTENSIONS\{20A82645-C095-46ED-80E3-08825760534B}
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\IVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\T9GIZHW3.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM
    [2011.03.08 11:11:42 | 000,002,047 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrchantn.xml
    O2 - BHO: (QIPBHO Class) - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Iva\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
    O3 - HKU\S-1-5-21-3067136988-3948908401-139281464-1006\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    O33 - MountPoints2\{52012080-4bdf-11df-ab20-00248c4d6756}\Shell - "" = AutoRun
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [2011.03.12 13:50:07 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
    [2011.03.08 19:14:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Iva\Data aplikací\.purple
    
    :reg
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSUNMain]
     
    :files
    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3067136988-3948908401-139281464-1006Core.job
    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3067136988-3948908401-139281464-1006UA.job
    C:\Documents and Settings\Iva\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp /s
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: Prosím o preventivku, děkuji!

Napsal: 15 bře 2011 18:31
od Ivya
Hotovo.
...jen jsme neměli mazat tu složku ".purple", jde o icq klienta Pidgin ;)

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKU\S-1-5-21-3067136988-3948908401-139281464-1006\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-3067136988-3948908401-139281464-1006\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3067136988-3948908401-139281464-1006\Software\Microsoft\Internet Explorer\URLSearchHooks\\{95289393-33EA-4F8D-B952-483415B9C955} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95289393-33EA-4F8D-B952-483415B9C955}\ deleted successfully.
C:\Documents and Settings\Iva\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Extensions\celtx@celtx.com folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Extensions\doit@snoworange.com folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Extensions\xulrunner@yoono.com folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}\defaults\preferences folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}\defaults folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}\components folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7} folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\twitternotifier@naan.net\components folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\twitternotifier@naan.net folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\firebug@software.joehewitt.com\lite folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\firebug@software.joehewitt.com\content\firebug folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\firebug@software.joehewitt.com\content folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\firebug@software.joehewitt.com folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions folder moved successfully.
Folder C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}\ not found.
Folder C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\firebug@software.joehewitt.com\ not found.
Folder C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\np5sprpt.default\extensions\twitternotifier@naan.net\ not found.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com\defaults\preferences folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com\defaults folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com\content\preferences folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com\content folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com-trash\content\images folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com-trash\content folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com-trash\components folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\ffxtlbr@Facemoods.com-trash folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\staged\ffxtlbr@Facemoods.com folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\Mozilla\Firefox\Profiles\t9gizhw3.default\extensions\staged folder moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrchantn.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95289393-33EA-4F8D-B952-483415B9C955}\ not found.
File C:\Documents and Settings\Iva\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll not found.
Registry value HKEY_USERS\S-1-5-21-3067136988-3948908401-139281464-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{52012080-4bdf-11df-ab20-00248c4d6756}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52012080-4bdf-11df-ab20-00248c4d6756}\ not found.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\.purple\smileys folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\.purple\logs\icq\111222333\444555666 folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\.purple\logs\icq\111222333\444555666 folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\.purple\logs\icq\111222333 folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\.purple\logs\icq folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\.purple\logs folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\.purple\icons folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\.purple\certificates\x509\tls_peers folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\.purple\certificates\x509 folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\.purple\certificates folder moved successfully.
C:\Documents and Settings\Iva\Data aplikací\.purple folder moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSUNMain\ deleted successfully.
========== FILES ==========
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3067136988-3948908401-139281464-1006Core.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3067136988-3948908401-139281464-1006UA.job moved successfully.
File\Folder C:\Documents and Settings\Iva\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll not found.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP122.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP14B.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1FF.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP22C.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP236.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP24B.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP266.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP31F.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3EE.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP412.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP4E8.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP516.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP65.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9D.tmp folder moved successfully.
C:\WINDOWS\Temp\is41.tmp moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes

User: Iva
->Temp folder emptied: 167504645 bytes
->Temporary Internet Files folder emptied: 695225 bytes
->FireFox cache emptied: 15273058 bytes
->Google Chrome cache emptied: 283608555 bytes
->Flash cache emptied: 4968 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32969 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 938932 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 1876265551 bytes

Total Files Cleaned = 2 236,00 mb


[EMPTYFLASH]

User: All Users

User: Default User

User: Iva
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 03152011_180326

Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Re: Prosím o preventivku, děkuji!

Napsal: 15 bře 2011 18:34
od vyosek
:arrow: Neni problem vratit :wink:

:arrow: Zabalte mi prosim do raru slozku C:\_OTL a uploadnete se http://vyosek.ic.cz/havet/uploader.php

Re: Prosím o preventivku, děkuji!

Napsal: 15 bře 2011 18:45
od Ivya
To je v pořádku, už jsem si to vytáhla ;)
Soubor nahráván.

Re: Prosím o preventivku, děkuji!

Napsal: 15 bře 2011 18:48
od vyosek
:arrow: V tom pripade ani netreba nahravat, potreboval jsem to kvuli uplnosti cesty :wink:

:arrow: Jak se chova PC :???:

Re: Prosím o preventivku, děkuji!

Napsal: 15 bře 2011 18:53
od Ivya
Dobře ;)
Vypadá to v pořádku, snad to tak chvíli zůstane :) Děkuji mockrát!

Re: Prosím o preventivku, děkuji!

Napsal: 15 bře 2011 19:04
od vyosek
Tak jeste uklidime :James008:

:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za 14 dni

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :turned: Jinak nemate zac, rad jsem pomohl :)