Stránka 1 z 2

Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 11:20
od matthew_tv
Zdravím.
Potreboval by som pomoc...práve som prešiel jeden PC Spyware terminatorom, nakoľko som z neho vyhodil viac ako 400 objektov smetia, no počítač stále robí problémy...
Jedná sa hlavne o pripojenie k internetu...
Pingnúť cez cmd môžem hocičo, no cez browser sa nikde nedostanem...
Niečo mi nastavuje automaticky proxy a aj keď ho vypnem, zase je buď zapnuté, alebo pripojenie proste nie je funkčné...
Nemám možnosť ani hodiť antivírak do počítača, pretože je tam údajne AVASt, ktorý nemám možnosť vôbec odinštalovať...nie je nikde v program files, nie je ani v ponuke "pridať/odinštalovať programy", ani v TuneUp utilites v odinštalátorovi nie je...
Pripojenie k internetu je z času na čas funkčné, asi pri 1 z 10 pokusov, ako dám opraviť / vypnúť a zapnúť pripojenie, prípadne aj zakázať proxy...
Hádžem log z HJT, ak by náhodou niekto....
Ďakujem.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:19:04, on 26. 9. 2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Miro Juhas\Data aplikací\dwm.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dgdersvc.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Miro Juhas\Data aplikací\Microsoft\conhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\update.5.0\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\update.2\svchost.exe
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
C:\WINDOWS\update.5.0\svchost.exe
C:\WINDOWS\update.tray-7-0\svchost.exe
C:\WINDOWS\systemup.exe
C:\WINDOWS\l1rezerv.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Ares\Ares.exe
C:\PROGRA~1\MICROS~2\wcescomm.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\WINDOWS\sysdriver32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
C:\WINDOWS\update.1\svchost.exe
C:\WINDOWS\update.2\svchost.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml ... tJ2QVpGw8Q
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/xilisoftdownl ... E2EC5DA240}
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ostpl&s={searchTerms}&f=4
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedi ... &gc=1&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:64889
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
R3 - URLSearchHook: (no name) - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVD2.dll
R3 - URLSearchHook: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA2.dll
R3 - URLSearchHook: (no name) - {ce10bf86-da68-441e-91fa-38336363e3cd} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: compliance0615 Toolbar - {31c7d459-9cc3-44f2-9dca-fc11795309b4} - C:\Program Files\IObitCom\prxtbIOb0.dll
O2 - BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVD2.dll
O2 - BHO: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA2.dll
O2 - BHO: Hunt TB Toolbar - {a6e4a4eb-d169-4e99-8988-250fcbafe767} - C:\Program Files\isoHunt\prxtbiso2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: FreeOnlineRadioPlayerRecorder - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll
O2 - BHO: SMTTB2009 Class - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Xilisoft Download Youtube Toolbar\tbcore3.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [wxpdrv] C:\WINDOWS\services32.exe
O4 - HKLM\..\Run: [tray_ico0] C:\WINDOWS\update.tray-7-0\svchost.exe
O4 - HKLM\..\Run: [1950364.exe] "C:\WINDOWS\TEMP\1950364.exe"
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\WINDOWS\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\WINDOWS\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [2107392.exe] "C:\DOCUME~1\MIROJU~1\LOCALS~1\Temp\2107392.exe"
O4 - HKLM\..\Run: [4591095.exe] "C:\WINDOWS\TEMP\4591095.exe"
O4 - HKLM\..\Run: [6765343.exe] "C:\WINDOWS\TEMP\6765343.exe"
O4 - HKLM\..\Run: [systemup] "C:\WINDOWS\systemup.exe" stand
O4 - HKLM\..\Run: [l1rezerv.exe] "C:\WINDOWS\l1rezerv.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [conhost] C:\Documents and Settings\Miro Juhas\Data aplikací\Microsoft\conhost.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~2\wcescomm.exe"
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download with Xilisoft Download YouTube Video - C:\Program Files\Xilisoft\Download YouTube Video\upod_link.HTM
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Miro Juhas\Data aplikací\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm (file missing)
O9 - Extra 'Tools' menuitem: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm (file missing)
O9 - Extra button: Eurotran XP - {230D1201-7607-4CF6-A11F-9E4BF0A333E0} - C:\Program Files\Eurotran XP\etnxp.dll
O9 - Extra button: (no name) - {2C73F784-D2DE-4422-B070-2E3332FE5744} - C:\Program Files\Eurotran XP\etnxp.dll
O9 - Extra 'Tools' menuitem: Eurotran XP... - {2C73F784-D2DE-4422-B070-2E3332FE5744} - C:\Program Files\Eurotran XP\etnxp.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (file missing)
O9 - Extra 'Tools' menuitem: PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (file missing)
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (file missing)
O9 - Extra button: Avanti! - {93119390-0D2E-4331-8511-A5B4F9EACA7C} - C:\Program Files\F.Developers\Avanti\avanti.exe (file missing)
O9 - Extra 'Tools' menuitem: Avanti! - {93119390-0D2E-4331-8511-A5B4F9EACA7C} - C:\Program Files\F.Developers\Avanti\avanti.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Device Error Recovery Service (dgdersvc) - Devguru Co., Ltd. - C:\WINDOWS\system32\dgdersvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: srvbtcclient - Unknown owner - C:\WINDOWS\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\WINDOWS\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\WINDOWS\sysdriver32.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe (file missing)
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
O23 - Service: Služba Windows Media Player Network Sharing (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)
O23 - Service: wxpdrivers - Unknown owner - C:\WINDOWS\update.1\svchost.exe

--
End of file - 12673 bytes

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 11:57
od Danstahr
Dobré odpoledne :welcome:,

:arrow: někdo se chtěl smát, což? Příště prosím nevkládejte logy do code, špatně se čtou.

:arrow: Stáhněte MBAM a vložte sem jeho log podle návodu zde, při výběru skenu zvolte Úplný sken.

Zatím nic nemažte, MBAM může mít falešné detekce!

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 12:37
od matthew_tv
V poriadku, ospravedlňujem sa za log v CODE.
Log z MBAM nemôžem vložiť, nakoľko pri cca. šiestej minúte kontroly pokračuje kontrola sekavo (dovtedy nájde 71 infiltrácií) a o dve minúty na to sa vypne s hlásením "Odoslať správu o chybe/neodoslať správu o chybe".

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 12:41
od Danstahr
Tak to zkusíme jinak.

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost 2 a potvrte enterem
  • Utilita provede svou cinnost a da log - ten sem vlozte
  • Nyni znovu, ale zvolte moznost 3 - log opet vlozte

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 13:02
od matthew_tv
Prostredníctvom Safe mode sa mi log z MBAM podarilo predsa len vytvoriť.

Kód: Vybrat vše

http://somebody.tbs.sk/mbam-log-2011-09-26(13-47-20).txt
Prvý log z RogueKiller:

Kód: Vybrat vše

http://somebody.tbs.sk/RKreport[1].txt
A druhý, po stlačení klávesy 3:

Kód: Vybrat vše

http://somebody.tbs.sk/RKreport[2].txt
(*.txt sú ukladané s kódovaním UTF-8)

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 13:40
od Danstahr
:arrow: Infekci, kterou našel MBAM, nechte smazat.

:!: Pozor! Tato utilita má velkou schopnost mazat a její použití je určeno výhradně členům týmu tohoto fóra. Svévolné použití může vést ke zboření a reinstalaci systému :!:

:arrow: Stáhněte ComboFix a uložte jej na Plochu.

:arrow: Vypněte všechny rezidentní štíty antivirů a všechny programy běžící na pozadí.
:arrow: Spusťte ComboFix s administrátorským oprávněním.
:arrow: Potvrďte licenční podmínky a případně i instalaci konzoly pro zotavení
:arrow: Během skenu nechte počítač naprosto v klidu.
:arrow: Sken trvá zhruba 15 minut, ale doba se může lišit v závislosti na stavu systému
:arrow: Po dokončení skenu se zobrazí log (pokud by se neotevřel, lze jej nalézt na systémovém disku jako ComboFix.txt), obsah logu vložte sem
:arrow: :!: ComboFixu si do dalšího pokynu nevšímejte :!:

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 14:09
od matthew_tv
V núdzovom režime sa mi podarilo napojiť sa na internet a stiahanuť akýsi program, odinštalátor avastu...následne som prebehol PC ešte raz CCleanerom, TuneUp utilities, u MBAM som vyskúšal aj "Fix Proxy", reštartoval som PC a zatiaľ šľape aj internet...
Pre istotu však aj tak skontrolujem cez ComboFix a potom hodím MS Essentials...
Až budem mať LOG z ComboFix, editnem tému.

//Z ComboFix nedokážem dostať LOG...po dokončení scanu vyhodí hlášku "Deleting files" a PC sa restartne...po restarte však nikde nemám súbor ComboFix.txt, vytvorilo mi jedine "zložku" na C:\, ktorá ma presmeruje späť na "Tento počítač".
Internet už však ide, a pomaličky odstraňujem cez MS Essentials a Spyware Terminator ostatné hrozby...Snáď to bude v poriadku. Dotyčného sa pokúsim nahovoriť predsa len na reinstal windowsu.

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 14:41
od Danstahr
Tak bránit v reinstallu vám nebudu, ale je to zbytečné.

:arrow: Stáhněte OTL.
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    netsvcs
    drivers32
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    c:\windows\*.* /U
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    /md5start
    adp3132.sys
    AGP440.sys
    ahcix86.sys
    ahcix86s.sys
    atapi.sys
    autochk.exe
    cdrom.sys
    cngaudit.dll
    cryptsvc.dll
    eNetHook.dll
    eventlog.dll
    explorer.exe
    hal.dll
    Changer.sys
    iaStor.sys
    iastorv.sys
    IdeChnDr.sys
    isapnp.sys
    JakNDis.sys
    KR10N.sys
    logevent.dll
    lsass.exe
    mv61xx.sys
    ndis.sys
    netlogon.dll
    ntelogon.dll
    nvata.sys
    nvatabus.sys
    nvgts.sys
    nvraid.sys
    nvrd32.sys
    nvstor.sys
    nvstor32.sys
    scecli.dll
    sceclt.dll
    smss.exe
    svchost.exe
    symmpi.sys
    tcpip.sys
    userinit.exe
    vaxscsi.sys
    viamraid.sys
    viasraid.sys
    ViPrt.sys
    winlogon.exe
    ws2_32.dll
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
    reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
    *crack* /s
    *keygen* /s
    CREATERESTOREPOINT
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 15:32
od matthew_tv
Robilo to pekných 20 minút aj čosi...:-X

Kód: Vybrat vše

http://somebody.tbs.sk/OTL.txt
http://somebody.tbs.sk/extras.txt

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 15:44
od Danstahr
OTL logfile created on: 26. 9. 2011 15:49:48 - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Miro Juhas\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000041B | Country: Slovensko | Language: SKY | Date Format: d. M. yyyy

2,00 Gb Total Physical Memory | 1,09 Gb Available Physical Memory | 54,64% Memory free
3,85 Gb Paging File | 2,97 Gb Available in Paging File | 77,20% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,76 Gb Total Space | 3,09 Gb Free Space | 15,64% Space Free | Partition Type: NTFS
Drive D: | 213,13 Gb Total Space | 32,54 Gb Free Space | 15,27% Space Free | Partition Type: NTFS

Computer Name: MIRO | User Name: Miro Juhas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011.09.26 15:48:28 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Miro Juhas\Plocha\OTL.exe
PRC - [2011.09.26 10:21:05 | 003,318,784 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
PRC - [2011.09.26 10:21:04 | 002,216,960 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
PRC - [2011.09.26 10:21:04 | 000,496,128 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2011.09.20 05:07:40 | 001,030,200 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
PRC - [2011.09.01 13:27:08 | 000,671,552 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
PRC - [2011.09.01 13:23:52 | 001,526,080 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
PRC - [2011.06.15 15:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011.04.27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010.11.25 01:02:36 | 015,298,416 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\SpyWareTerminator.exe
PRC - [2010.08.09 09:44:42 | 003,367,224 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
PRC - [2010.07.30 11:43:38 | 000,095,568 | ---- | M] (Devguru Co., Ltd.) -- C:\WINDOWS\system32\dgdersvc.exe
PRC - [2010.05.28 08:25:04 | 000,233,472 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2010.05.25 18:08:54 | 001,694,520 | ---- | M] (Piriform Ltd) -- C:\Program Files\CCleaner\CCleaner.exe
PRC - [2009.02.03 15:22:18 | 001,004,544 | ---- | M] (Ares Development Group) -- C:\Program Files\Ares\Ares.exe
PRC - [2004.08.17 16:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2011.09.26 10:21:42 | 001,901,570 | ---- | M] () -- C:\Program Files\Spyware Terminator\TorentDll.dll
MOD - [2011.09.20 05:07:39 | 000,412,728 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\Application\14.0.835.186\ppgooglenaclpluginchrome.dll
MOD - [2011.09.20 05:07:37 | 003,696,184 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\Application\14.0.835.186\pdf.dll
MOD - [2011.09.20 05:06:30 | 000,339,000 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\Application\14.0.835.186\Locales\cs.dll
MOD - [2011.09.20 05:06:11 | 000,142,568 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\Application\14.0.835.186\avutil-51.dll
MOD - [2011.09.20 05:06:10 | 000,253,320 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\Application\14.0.835.186\avformat-53.dll
MOD - [2011.09.20 05:06:09 | 002,403,240 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\Application\14.0.835.186\avcodec-53.dll
MOD - [2011.09.20 02:32:41 | 006,338,720 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\Application\14.0.835.186\gcswf32.dll
MOD - [2011.07.10 10:44:29 | 005,025,792 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
MOD - [2011.02.16 16:10:33 | 000,037,624 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\QuickStoresToolbar\1.0.0.0__318d21d4b0463a3b\QuickStoresToolbar.dll
MOD - [2011.01.29 08:59:20 | 000,123,904 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ajedaeoideoipodoijpbpabhhadnniac\1.3.2.61_0\chromeTray.dll
MOD - [2010.05.25 23:05:04 | 000,026,112 | ---- | M] () -- C:\Program Files\CCleaner\Lang\lang-1051.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (WMPNetworkSvc)
SRV - File not found [Auto | Stopped] -- -- (Sukoku Service)
SRV - File not found [On_Demand | Stopped] -- -- (Start BT in service)
SRV - File not found [Unknown | Stopped] -- -- (ResultDns Service)
SRV - File not found [Auto | Stopped] -- -- (hpqddsvc)
SRV - [2011.09.26 10:21:04 | 000,496,128 | ---- | M] (Crawler.com) [Auto | Running] -- C:\Program Files\Spyware Terminator\sp_rsser.exe -- (sp_rssrv)
SRV - [2011.09.01 13:23:52 | 001,526,080 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2011.09.01 13:18:56 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2011.04.27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010.07.30 11:43:38 | 000,095,568 | ---- | M] (Devguru Co., Ltd.) [Auto | Running] -- C:\WINDOWS\system32\dgdersvc.exe -- (dgdersvc)
SRV - [2010.05.28 08:25:04 | 000,233,472 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010.03.13 13:00:50 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)


========== Driver Services (SafeList) ==========

DRV - [2011.09.26 15:28:04 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2C3FAA68-C9DE-46FE-A197-9F7EE6415EEC}\MpKsla32b98c8.sys -- (MpKsla32b98c8)
DRV - [2011.09.26 15:17:54 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2C3FAA68-C9DE-46FE-A197-9F7EE6415EEC}\MpKsld43a85fb.sys -- (MpKsld43a85fb)
DRV - [2011.09.26 10:21:04 | 000,142,592 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys -- (sp_rsdrv2)
DRV - [2011.07.08 12:00:06 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2010.07.30 11:43:38 | 000,018,120 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - [2010.05.28 08:25:04 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009.10.29 19:59:08 | 000,024,064 | ---- | M] (Eltima Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\HMFAxCore46691b2fe72383a3b643d95081ef1d95.sys -- (HMFAxCore46691b2fe72383a3b643d95081ef1d95)
DRV - [2009.02.26 00:58:57 | 003,565,568 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2007.10.23 18:51:04 | 000,103,296 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007.07.18 13:26:04 | 004,547,584 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.06.13 17:47:12 | 000,048,256 | R--- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\jraid.sys -- (JRAID)
DRV - [2007.04.06 18:29:08 | 010,342,784 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)
DRV - [2005.04.12 10:41:20 | 000,004,608 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)
DRV - [2003.10.10 12:06:40 | 000,004,134 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\FlyPCI.sys -- (FlyPCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/xilisoftdownl ... E2EC5DA240}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ostpl&s={searchTerms}&f=4
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found


IE - HKU\.DEFAULT\..\URLSearchHook: - No CLSID value found
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = My Web Search
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultUrl = http://www.mywebsearch.com/jsp/cfg_redi ... earchTerms}
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml ... tJ2QVpGw8Q
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://flv.asksearch.com/?cfg=2-113-11-qNUv

IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVD2.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA2.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {ce10bf86-da68-441e-91fa-38336363e3cd} - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "FreeOnlineRadioPlayerRecorder Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.as ... earchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "My Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search13.net?clid=486"
FF - prefs.js..extensions.enabledItems: {2832ABCD-4444-1012-2D45-132D5447C445}:1.0.0
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA82}:1.0.2
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA80}:1.0.24
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA81}:1.0.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {7645f4b1-1f19-13dd-2d6b-0200600c2a56}:1.0
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA96}:1.0.7
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9
FF - prefs.js..extensions.enabledItems: {63414328-3ab4-2c84-6c41-5a473c4b2ff7}:1.0
FF - prefs.js..extensions.enabledItems: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {1A615EA8-4C56-49EE-BE83-F9A264B79997}:1.0
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.1.0.0
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
FF - prefs.js..extensions.enabledItems: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {ce10bf86-da68-441e-91fa-38336363e3cd}:2.7.1.3
FF - prefs.js..extensions.enabledItems: quickstores@quickstores.de:1.2.0
FF - prefs.js..extensions.enabledItems: {8675f4b3-2f19-11ed-2d6b-0800600c0a16}:1.0
FF - prefs.js..extensions.enabledItems: {75656794-AB59-4712-BFBC-5D816D56F3BC}:1.1.3
FF - prefs.js..extensions.enabledItems: ffxtlbr@babylon.com:1.1.3
FF - prefs.js..extensions.enabledItems: {84b24861-62f6-364b-eba5-2e5e2061d7e6}:0.9.3
FF - prefs.js..extensions.enabledItems: {f999a48b-1950-4d81-9971-79018f807b4b}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {8675f4b3-2f19-11ed-2d6b-0800600c0a17}:1.0
FF - prefs.js..keyword.URL: "http://search.mywebsearch.com/mywebsear ... searchfor="
FF - prefs.js..network.proxy.type: 0
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "http://search.conduit.com/ResultsExt.as ... earchTerms}"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://search13.net?clid=486"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.avg.com/route/?d=4cb3fe87 ... &lng=sk&q="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Data aplikací\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009.10.14 20:49:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2224E955-00E9-4613-A844-CE69FCCAAE91}: C:\Program Files\Internet Saving Optimizer\3.8.1.4690\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}: C:\Program Files\Media Access Startup\2.0.0.1050\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\1.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox 3.1 Beta 3\components [2011.03.31 17:56:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins [2011.06.01 21:05:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox 3.1 Beta 3\components [2011.03.31 17:56:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins [2011.06.01 21:05:46 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Documents and Settings\Miro Juhas\Data aplikací\IDM\idmmzcc3

[2010.09.05 20:40:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Extensions
[2010.09.05 20:40:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Extensions\home2@tomtom.com
[2011.09.26 10:53:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions
[2011.02.10 13:36:57 | 000,000,000 | ---D | M] (LongTailVideo Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{1bcec53b-aa13-4de2-814d-2d6a98e7ba79}
[2010.08.26 20:27:48 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009.10.07 18:39:53 | 000,000,000 | ---D | M] (Beemp3 Search ToolBar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{2832ABCD-4444-1012-2D45-132D5447C445}
[2010.08.26 20:27:50 | 000,000,000 | ---D | M] (Softonic-Eng7 Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
[2011.06.12 10:54:59 | 000,000,000 | ---D | M] ("Get Styles") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA80}
[2010.01.23 12:42:28 | 000,000,000 | ---D | M] ("Homepage Guard") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA81}
[2010.01.23 12:42:28 | 000,000,000 | ---D | M] ("Express Tab") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA82}
[2011.06.12 10:54:59 | 000,000,000 | ---D | M] ("Usage Stat") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA96}
[2009.12.24 11:39:12 | 000,000,000 | ---D | M] (FBFan) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA99}
[2010.06.04 13:35:39 | 000,000,000 | ---D | M] (QAssistant) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
[2011.04.02 16:25:53 | 000,000,000 | ---D | M] (Xilisoft Download Youtube Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC}
[2010.03.20 08:01:47 | 000,000,000 | ---D | M] (U Flv) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{7645f4b1-1f19-13dd-2d6b-0200600c2a56}
[2011.06.05 16:50:49 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.06.04 20:56:37 | 000,000,000 | ---D | M] (mediaplayerconnectivity) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{84b24861-62f6-364b-eba5-2e5e2061d7e6}
[2011.03.17 15:12:31 | 000,000,000 | ---D | M] (KFD Flv) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a16}
[2011.06.25 11:05:26 | 000,000,000 | ---D | M] (VFD Flv) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a17}
[2011.06.05 16:50:56 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2011.06.05 16:50:57 | 000,000,000 | ---D | M] (MyAshampoo Community Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
[2011.01.23 18:31:32 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.02.16 15:21:07 | 000,000,000 | ---D | M] (Movier-media Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{ce10bf86-da68-441e-91fa-38336363e3cd}
[2011.01.11 12:02:05 | 000,000,000 | ---D | M] (Movier-media Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{ce10bf86-da68-441e-91fa-38336363e3cd}(2)
[2010.10.23 15:03:53 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2011.06.12 15:07:17 | 000,000,000 | ---D | M] (FreeOnlineRadioPlayerRecorder Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}
[2011.06.05 16:50:38 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\engine@conduit.com
[2011.05.23 21:55:14 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\ffxtlbr@babylon.com
[2011.06.05 16:50:57 | 000,000,000 | ---D | M] (QuickStores-Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\quickstores@quickstores.de
[2010.10.12 09:05:28 | 000,001,761 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\ask.uk.xml
[2010.05.26 15:18:50 | 000,002,333 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\askcom.xml
[2010.08.11 11:56:22 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\conduit.xml
[2011.07.09 15:42:31 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin-1.xml
[2010.09.14 18:21:31 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin-2.xml
[2010.09.27 21:30:46 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin-3.xml
[2010.10.05 14:54:53 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin-4.xml
[2011.02.20 11:21:20 | 000,000,168 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin.gif
[2011.02.20 11:21:20 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin.src
[2010.05.12 18:40:48 | 000,001,042 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin.xml
[2011.07.17 17:05:17 | 000,009,987 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\mywebsearch.xml
[2010.09.23 14:42:42 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\search-the-web.xml
[2010.10.23 15:03:51 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\sweetim.xml
[2009.12.19 23:44:51 | 000,001,586 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\web-search.xml
[2009.07.16 19:04:05 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\winamp-search.xml
[2010.06.23 16:58:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{2832ABCD-4444-1012-2D45-132D5447C445}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{6236BA26-C117-4007-928C-DE0716C7FA80}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{6236BA26-C117-4007-928C-DE0716C7FA81}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{6236BA26-C117-4007-928C-DE0716C7FA82}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{6236BA26-C117-4007-928C-DE0716C7FA96}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{63414328-3AB4-2C84-6C41-5A473C4B2FF7}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{75656794-AB59-4712-BFBC-5D816D56F3BC}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{7645F4B1-1F19-13DD-2D6B-0200600C2A56}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{84B24861-62F6-364B-EBA5-2E5E2061D7E6}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{8675F4B3-2F19-11ED-2D6B-0800600C0A16}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{8675F4B3-2F19-11ED-2D6B-0800600C0A17}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{CE10BF86-DA68-441E-91FA-38336363E3CD}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\{F999A48B-1950-4D81-9971-79018F807B4B}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\ENGINE@CONDUIT.COM
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\FFXTLBR@BABYLON.COM
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIRO JUHAS\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\SGYHQTM0.DEFAULT\EXTENSIONS\QUICKSTORES@QUICKSTORES.DE
[2009.10.14 22:39:26 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010.09.18 16:13:31 | 000,000,000 | ---D | M] (ResultDns) -- C:\PROGRAM FILES\MOZILLA FIREFOX 3.1 BETA 3\EXTENSIONS\{1A615EA8-4C56-49EE-BE83-F9A264B79997}
[2009.10.14 22:39:33 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX 3.1 BETA 3\EXTENSIONS\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2009.11.24 19:05:08 | 000,000,000 | ---D | M] (Java Console) -- C:\PROGRAM FILES\MOZILLA FIREFOX 3.1 BETA 3\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2010.03.27 14:32:50 | 000,002,025 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml
[2010.07.27 10:48:38 | 000,002,039 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrchfbpage1.xml
[2011.04.05 17:24:57 | 000,002,048 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrchostpl.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\14.0.835.186\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\14.0.835.186\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\14.0.835.186\gcswf32.dll
CHR - plugin: chromeTray Dynamic Link Library (Enabled) = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikac\Google\Chrome\User Data\Default\Extensions\ajedaeoideoipodoijpbpabhhadnniac\1.2.1.53_0\chromeTray.dll
CHR - plugin: Java(TM) Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\np-mswmp.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npdeploytk.dll
CHR - plugin: Imagine Plugin (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npImagine.dll
CHR - plugin: Imikimi.com Plugin (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\npkimi.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\nppdf32.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\nppl3260.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\nprjplug.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox 3.1 Beta 3\plugins\nprpjplug.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikac\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Minimize Chrome to tray = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ajedaeoideoipodoijpbpabhhadnniac\1.3.2.61_0\
CHR - Extension: Turn Off the Lights = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.0.0.11_0\
CHR - Extension: Localizer = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\djpcpiakgdbhflcllhonidoekplebmgb\1.2\
CHR - Extension: FB Photo Zoom = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi\1.1106.17.1_0\
CHR - Extension: Fast YouTube Search = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ggkljdkflooidjlkahdnfgodflkelkai\1.2_0\
CHR - Extension: Slideshow = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\hijbjhjjipenfibfbleadidijdimlpmk\1.2.9_0\
CHR - Extension: Meniny = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jclppdmopeepkkepodjmjdfmghoomdhm\1.0\
CHR - Extension: Chrome MineSweeper = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ldmhhkobonimkpkfoabdmmngbbjcgilo\0.5.3\
CHR - Extension: AT_DJTiesto = C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\okmcbgkkeagngnijeiighgblfljbekip\2_0\

O1 HOSTS File: ([2011.09.26 13:56:40 | 000,000,726 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (compliance0615 Toolbar) - {31c7d459-9cc3-44f2-9dca-fc11795309b4} - C:\Program Files\IObitCom\prxtbIOb0.dll (Conduit Ltd.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVD2.dll (Conduit Ltd.)
O2 - BHO: (MyAshampoo Toolbar) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA2.dll (Conduit Ltd.)
O2 - BHO: (Hunt TB Toolbar) - {a6e4a4eb-d169-4e99-8988-250fcbafe767} - C:\Program Files\isoHunt\prxtbiso2.dll (Conduit Ltd.)
O2 - BHO: (FreeOnlineRadioPlayerRecorder Toolbar) - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (Conduit Ltd.)
O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Xilisoft Download Youtube Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (compliance0615 Toolbar) - {31C7D459-9CC3-44F2-9DCA-FC11795309B4} - C:\Program Files\IObitCom\prxtbIOb0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (Xilisoft Download Youtube Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\Xilisoft Download Youtube Toolbar\tbcore3.dll ()
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\prxtbDVD2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (MyAshampoo Toolbar) - {A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - C:\Program Files\MyAshampoo\prxtbMyA2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (Hunt TB Toolbar) - {A6E4A4EB-D169-4E99-8988-250FCBAFE767} - C:\Program Files\isoHunt\prxtbiso2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (FreeOnlineRadioPlayerRecorder Toolbar) - {F999A48B-1950-4D81-9971-79018F807B4B} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [36X Raid Configurer] C:\WINDOWS\System32\xRaidSetup.exe (Gigabyte Technology Corp.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui File not found
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKU\S-1-5-21-1202660629-507921405-725345543-1003..\Run: [ares] C:\Program Files\Ares\Ares.exe (Ares Development Group)
O4 - HKU\S-1-5-21-1202660629-507921405-725345543-1003..\Run: [ccleaner] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-1202660629-507921405-725345543-1003..\Run: [SpywareTerminatorUpdate] C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe (Crawler.com)
O4 - HKU\S-1-5-21-1202660629-507921405-725345543-1003..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogOff = 0
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O8 - Extra context menu item: Download with Xilisoft Download YouTube Video - C:\Program Files\Xilisoft\Download YouTube Video\upod_link.HTM ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Miro Juhas\Data aplikací\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm File not found
O9 - Extra 'Tools' menuitem : GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm File not found
O9 - Extra Button: Eurotran XP - {230D1201-7607-4CF6-A11F-9E4BF0A333E0} - C:\Program Files\Eurotran XP\etnxp.dll ()
O9 - Extra 'Tools' menuitem : Eurotran XP... - {2C73F784-D2DE-4422-B070-2E3332FE5744} - C:\Program Files\Eurotran XP\etnxp.dll ()
O9 - Extra 'Tools' menuitem : PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe File not found
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe File not found
O9 - Extra Button: Avanti! - {93119390-0D2E-4331-8511-A5B4F9EACA7C} - C:\Program Files\F.Developers\Avanti\avanti.exe File not found
O9 - Extra 'Tools' menuitem : Avanti! - {93119390-0D2E-4331-8511-A5B4F9EACA7C} - C:\Program Files\F.Developers\Avanti\avanti.exe File not found
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{930865B6-166F-4CDB-83EB-C89C417A2AD3}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Miro Juhas\Dokumenty\Obrázky\slnecnica-a-vcela-maj136.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Miro Juhas\Dokumenty\Obrázky\slnecnica-a-vcela-maj136.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.07.05 10:44:39 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011.09.26 15:48:31 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Miro Juhas\Plocha\OTL.exe
[2011.09.26 15:28:46 | 000,000,000 | ---D | C] -- C:\3590F75ABA9E485486C100C1A9D4FF06Z..ZZZZ.Z.ZZ..ZZ
[2011.09.26 15:28:30 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Miro Juhas\Recent
[2011.09.26 15:20:40 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011.09.26 15:09:42 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011.09.26 15:06:05 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011.09.26 15:06:05 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011.09.26 15:06:04 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011.09.26 15:06:04 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011.09.26 15:05:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011.09.26 15:05:34 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.09.26 15:05:29 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Miro Juhas\Dokumenty\Filmy
[2011.09.26 15:04:36 | 004,228,783 | R--- | C] (Swearware) -- C:\Documents and Settings\Miro Juhas\Plocha\ComboFix.exe
[2011.09.26 15:04:02 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011.09.26 14:33:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Miro Juhas\Data aplikací\ESET
[2011.09.26 14:31:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2011.09.26 14:25:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\ESET
[2011.09.26 14:14:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2011.09.26 13:40:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011.09.26 13:10:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Malwarebytes
[2011.09.26 13:10:23 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.09.26 13:10:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
[2011.09.26 13:10:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.09.26 13:10:18 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.09.26 13:10:18 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.09.26 12:16:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Realtek
[2011.09.26 12:16:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\OPTIONS
[2011.09.26 12:15:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Miro Juhas\Data aplikací\InstallShield
[2011.09.26 11:01:59 | 000,031,552 | ---- | C] (TuneUp Software) -- C:\WINDOWS\System32\TURegOpt.exe
[2011.09.26 11:01:58 | 000,029,504 | ---- | C] (TuneUp Software) -- C:\WINDOWS\System32\uxtuneup.dll
[2011.09.26 11:01:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\TuneUp Utilities 2011
[2011.09.26 11:00:43 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2011.09.26 10:21:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Spyware Terminator
[2011.09.26 10:21:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Spyware Terminator
[2011.09.26 10:21:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
[2011.09.26 10:21:01 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Terminator
[2011.09.26 10:18:15 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011.09.26 10:18:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\HijackThis
[2011.09.26 10:07:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Lavalys
[2011.09.26 10:07:55 | 000,000,000 | ---D | C] -- C:\Program Files\Lavalys
[2011.09.18 17:35:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\MioMore Desktop
[2011.09.18 17:35:02 | 000,000,000 | ---D | C] -- C:\Program Files\Mio Technology
[2011.09.18 17:33:35 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync
[2011.09.09 18:52:58 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.8.1
[2011.02.07 19:35:15 | 000,172,032 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll
[2011.02.07 19:35:15 | 000,057,344 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll
[2011.02.07 19:35:15 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll
[2011.02.07 19:35:15 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\csnpstd3.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.09.26 16:02:16 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2011.09.26 15:58:20 | 000,001,030 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-507921405-725345543-1003UA.job
[2011.09.26 15:48:28 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Miro Juhas\Plocha\OTL.exe
[2011.09.26 15:33:06 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011.09.26 15:28:16 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.09.26 15:27:29 | 000,000,920 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011.09.26 15:09:46 | 000,000,331 | RHS- | M] () -- C:\boot.ini
[2011.09.26 15:05:26 | 000,001,912 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011.09.26 15:04:34 | 004,228,783 | R--- | M] (Swearware) -- C:\Documents and Settings\Miro Juhas\Plocha\ComboFix.exe
[2011.09.26 15:03:05 | 000,000,924 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011.09.26 14:58:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-507921405-725345543-1003Core.job
[2011.09.26 14:28:33 | 000,060,800 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Plocha\TrueSight.sys
[2011.09.26 14:16:27 | 000,002,504 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011.09.26 13:51:59 | 000,000,215 | ---- | M] () -- C:\Boot.bak
[2011.09.26 13:44:06 | 000,657,920 | ---- | M] () -- C:\RogueKiller.exe
[2011.09.26 13:00:11 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011.09.26 11:29:39 | 000,187,392 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\dwm.exe
[2011.09.26 11:22:29 | 000,049,433 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Plocha\screen.JPG
[2011.09.26 10:43:05 | 000,047,994 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Plocha\cc_20110926_104259.reg
[2011.09.26 10:21:04 | 000,142,592 | ---- | M] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2011.09.26 10:18:15 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Plocha\HijackThis.lnk
[2011.09.25 14:59:36 | 000,002,296 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Plocha\Google Chrome.lnk
[2011.09.18 17:35:11 | 000,000,892 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\MioMore Desktop.lnk
[2011.09.16 20:03:28 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Plocha\Skype.lnk
[2011.09.11 16:17:25 | 000,000,203 | ---- | M] () -- C:\WINDOWS\info1
[2011.09.09 19:47:54 | 000,131,584 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.09.01 13:29:56 | 000,031,552 | ---- | M] (TuneUp Software) -- C:\WINDOWS\System32\TURegOpt.exe
[2011.09.01 13:18:56 | 000,029,504 | ---- | M] (TuneUp Software) -- C:\WINDOWS\System32\uxtuneup.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.09.26 15:19:40 | 000,000,390 | -H-- | C] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2011.09.26 15:10:24 | 000,000,424 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011.09.26 15:09:46 | 000,000,215 | ---- | C] () -- C:\Boot.bak
[2011.09.26 15:09:43 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011.09.26 15:06:05 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011.09.26 15:06:05 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011.09.26 15:06:05 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011.09.26 15:06:05 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011.09.26 15:06:05 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011.09.26 15:04:43 | 000,001,680 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Microsoft Security Essentials.lnk
[2011.09.26 14:58:56 | 000,001,912 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011.09.26 14:09:57 | 000,060,800 | ---- | C] () -- C:\Documents and Settings\Miro Juhas\Plocha\TrueSight.sys
[2011.09.26 14:09:50 | 000,657,920 | ---- | C] () -- C:\RogueKiller.exe
[2011.09.26 11:22:29 | 000,049,433 | ---- | C] () -- C:\Documents and Settings\Miro Juhas\Plocha\screen.JPG
[2011.09.26 11:01:56 | 000,001,751 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\TuneUp Utilities 2011.lnk
[2011.09.26 10:43:03 | 000,047,994 | ---- | C] () -- C:\Documents and Settings\Miro Juhas\Plocha\cc_20110926_104259.reg
[2011.09.26 10:21:04 | 000,142,592 | ---- | C] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2011.09.26 10:18:15 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\Miro Juhas\Plocha\HijackThis.lnk
[2011.09.26 10:16:45 | 044,062,208 | ---- | C] () -- C:\Documents and Settings\Miro Juhas\Plocha\eav_nt32_sky.msi
[2011.09.26 09:52:33 | 000,035,370 | ---- | C] () -- C:\WINDOWS\System32\OEMLOGO.bmp
[2011.09.26 09:52:32 | 000,000,347 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2011.09.18 17:35:02 | 000,000,892 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\MioMore Desktop.lnk
[2011.09.18 17:33:37 | 000,001,808 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Microsoft ActiveSync.lnk
[2011.09.18 17:24:07 | 005,613,823 | ---- | C] () -- C:\Documents and Settings\Miro Juhas\Plocha\1-Rumours-By Dj Cntn!-.mp3
[2011.07.17 16:59:58 | 000,187,392 | ---- | C] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\dwm.exe
[2011.07.17 16:58:32 | 000,246,272 | ---- | C] () -- C:\WINDOWS\unrar.exe
[2011.07.17 16:44:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\loader2.exe_ok
[2011.07.10 10:21:32 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2011.07.10 10:21:32 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2011.07.10 10:21:19 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\$_hpcst$.hpc
[2011.07.07 17:28:25 | 000,164,677 | ---- | C] () -- C:\WINDOWS\Zac Browser English Uninstaller.exe
[2011.03.26 11:37:19 | 000,000,354 | ---- | C] () -- C:\WINDOWS\WMDownloader.INI
[2011.03.16 19:12:37 | 000,000,101 | ---- | C] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\SRDownloader.err
[2011.02.09 15:22:09 | 000,001,152 | ---- | C] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\SRDownloader.nast
[2011.02.07 19:35:36 | 000,102,400 | ---- | C] () -- C:\WINDOWS\JAPI.dll
[2011.02.07 19:35:17 | 000,827,392 | ---- | C] () -- C:\WINDOWS\vsnpstd3.exe
[2011.02.07 19:35:16 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini
[2011.01.21 20:52:17 | 000,003,120 | ---- | C] () -- C:\WINDOWS\System32\ade3a3b7-efaa-4bb6-a44e-1be50229e465.dll
[2011.01.07 00:47:56 | 000,131,584 | ---- | C] () -- C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.01.07 00:40:06 | 000,428,724 | ---- | C] () -- C:\WINDOWS\System32\prfh0405.dat
[2011.01.07 00:40:06 | 000,077,854 | ---- | C] () -- C:\WINDOWS\System32\prfc0405.dat
[2011.01.07 00:07:37 | 000,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
[2011.01.06 11:42:53 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2011.01.06 10:24:30 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.12.14 17:43:17 | 000,000,215 | ---- | C] () -- C:\WINDOWS\registr_prospechu.ini
[2010.11.30 21:22:38 | 000,000,023 | ---- | C] () -- C:\WINDOWS\SEBRAN.INI
[2010.11.10 16:38:50 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2010.10.26 16:47:40 | 000,000,839 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2010.10.04 21:30:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2010.10.04 20:26:29 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010.07.14 19:31:35 | 000,000,108 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Microsoft.SqlServer.Compact.351.32.bc
[2010.05.25 08:45:24 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2010.05.25 08:45:24 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2010.05.25 08:45:24 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2010.05.25 08:45:24 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2010.03.01 17:21:38 | 000,140,840 | ---- | C] () -- C:\WINDOWS\hpoins15.dat
[2010.03.01 17:21:38 | 000,001,039 | ---- | C] () -- C:\WINDOWS\hpomdl15.dat
[2010.02.22 17:03:11 | 000,004,134 | ---- | C] () -- C:\WINDOWS\System32\drivers\FlyPCI.sys
[2009.11.28 09:12:53 | 000,516,096 | ---- | C] () -- C:\WINDOWS\UN32.EXE
[2009.10.29 19:59:07 | 000,028,672 | -HS- | C] () -- C:\WINDOWS\HkMgrMM.dll
[2009.09.21 20:16:19 | 000,201,216 | ---- | C] () -- C:\WINDOWS\System32\mediarcpt.dll
[2009.08.06 13:04:45 | 000,000,040 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\.zreglib
[2009.07.27 14:12:12 | 000,149,504 | ---- | C] () -- C:\WINDOWS\UNWISE.EXE
[2009.07.05 13:20:46 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2009.07.05 12:30:51 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009.07.05 12:29:52 | 001,402,984 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009.07.05 11:30:29 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2009.07.05 10:42:03 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2007.05.15 20:06:58 | 000,071,208 | ---- | C] () -- C:\WINDOWS\System32\PhysXLoader.dll
[2007.04.14 16:57:06 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007.04.14 16:57:06 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007.04.14 16:57:06 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007.04.14 16:57:04 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007.04.14 16:57:04 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007.04.14 16:57:04 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2007.04.14 16:57:04 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007.04.14 16:57:04 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2007.04.14 16:57:04 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2005.10.14 11:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 11:56:50 | 000,092,672 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 11:56:50 | 000,021,504 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2004.08.17 16:58:58 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004.08.02 15:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004.07.17 12:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2002.09.18 00:45:00 | 000,119,808 | ---- | C] () -- C:\WINDOWS\lsb_un20.exe
[2001.10.25 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001.10.25 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001.10.25 13:00:00 | 000,476,366 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2001.10.25 13:00:00 | 000,433,280 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001.10.25 13:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001.10.25 13:00:00 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2001.10.25 13:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001.10.25 13:00:00 | 000,102,838 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2001.10.25 13:00:00 | 000,067,660 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001.10.25 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001.10.25 13:00:00 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2001.10.25 13:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001.10.25 13:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.10.25 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[1763.08.08 01:08:39 | 000,004,263 | -HS- | C] () -- C:\WINDOWS\windllreg1c.sys

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 15:45
od Danstahr
========== LOP Check ==========

[2010.09.26 21:19:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ActivityMon
[2010.06.13 17:51:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
[2011.01.04 19:44:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ashampoo
[2010.11.28 15:43:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVG10
[2010.09.27 19:48:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg9
[2011.04.11 19:48:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Awem
[2011.04.26 18:13:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Big Fish Games
[2010.10.05 14:09:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2009.08.30 16:58:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DivoGames
[2009.10.09 16:57:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\eGames
[2010.12.14 16:05:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\EL
[2011.09.26 14:57:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.08.23 18:14:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Farm Frenzy
[2009.07.23 15:38:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\FireGlow
[2009.08.06 12:59:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\FlashFXP
[2009.08.30 21:11:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\GameXzone
[2011.02.23 09:50:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2011.02.10 10:01:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\iolo
[2010.01.01 13:23:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\LangSoft
[2010.10.05 14:09:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2010.09.29 15:37:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2010.12.31 17:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\mLhKi04300
[2010.11.17 15:53:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Playrix Entertainment
[2011.01.23 18:27:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ReviverSoft
[2011.07.10 10:21:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Samsung
[2010.11.19 19:25:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sandlot Games
[2011.07.07 17:30:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Souptoys
[2011.07.07 17:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Souptoys2
[2011.09.26 12:49:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
[2009.11.04 17:01:32 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\Strazca systemu
[2010.08.21 19:00:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SugarGames
[2010.10.28 07:13:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2010.10.04 17:16:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Systweak
[2011.06.28 12:55:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2011.03.31 15:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2011.07.09 08:03:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Veselé Omalovánky 1
[2011.07.09 08:01:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Veselé Omalovánky 2
[2011.07.07 16:48:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Veselé Omalovánky 6
[2011.03.24 11:12:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\VisualShape
[2009.08.15 22:59:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Winferno
[2010.07.09 16:35:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\WinZip
[2011.04.02 16:25:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Xilisoft
[2011.09.26 15:39:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Zwangi
[2011.09.26 11:00:43 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2009.10.31 15:36:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
[2010.09.27 19:25:52 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2010.09.16 10:32:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\iolo
[2011.07.18 17:03:53 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\.#
[2010.10.05 14:10:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\AVG10
[2010.08.23 17:49:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Awem
[2011.05.23 22:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\BabylonToolbar
[2010.02.21 19:28:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\bfgbar
[2010.06.23 21:44:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Bump Technologies, Inc
[2010.06.25 15:35:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\cosmo ball
[2011.03.23 18:25:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\COWON
[2010.12.03 19:16:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Crossword Forge Prefs Folder
[2011.04.06 21:55:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\DMCache
[2011.01.23 18:43:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\DVDVideoSoftIEHelpers
[2010.12.14 17:34:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\eBookPro6
[2009.10.09 16:57:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\eGames
[2009.07.15 19:27:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\EleFun Games
[2009.09.25 20:37:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\eMule
[2011.09.26 14:38:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\ESET
[2010.06.21 21:51:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\facemoods.com
[2009.10.18 21:59:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Friday's games
[2011.01.05 23:42:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\FTWeak
[2009.10.22 15:56:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\FunWebProducts
[2011.07.07 16:57:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Get from YouTube
[2010.12.14 16:30:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\GetRightToGo
[2009.10.05 21:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\GlarySoft
[2011.06.12 16:40:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\GrabPro
[2011.04.07 14:28:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\gtk-2.0
[2011.03.06 22:50:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\ICQ
[2011.04.07 13:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\IDM
[2011.07.07 16:57:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Import Audio from Video
[2010.08.13 12:34:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\InterTrust
[2009.12.13 22:01:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\IObit
[2010.09.16 16:04:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\iolo
[2010.04.15 19:07:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\JLC's Software
[2010.12.06 18:28:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\LangSoft
[2011.06.12 16:40:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy
[2009.10.14 22:19:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Opera
[2011.06.12 16:45:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Orbit
[2009.10.14 21:16:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\OtakuSoftware
[2009.12.10 16:19:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Participatory Culture Foundation
[2011.04.07 14:38:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\PCF-VLC
[2011.02.16 16:10:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\phonostar GmbH
[2010.06.25 15:35:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Pointstone
[2011.07.07 16:57:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Power Sound Editor Free
[2011.09.26 11:05:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\PriceGong
[2011.06.12 16:40:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\ProgSense
[2011.07.21 15:38:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\QuickStoresToolbar
[2009.11.18 18:20:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\r2 Studios
[2009.07.20 17:09:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\RadLight Company
[2010.02.20 08:16:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Registry Mechanic
[2011.01.23 18:18:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Reviversoft
[2009.08.28 21:23:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Sahmon Games
[2011.07.10 10:19:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Samsung
[2010.04.18 20:31:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\SBMAV Disk Cleaner Lite
[2009.09.17 20:23:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\ScummVM
[2009.09.25 15:33:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\SearchmeToolbar
[2010.09.27 19:22:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Smart PC Solutions
[2009.07.20 22:35:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\SMS Sender
[2010.12.05 20:05:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Software Informer
[2011.07.07 17:30:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Souptoys
[2011.09.26 10:21:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Spyware Terminator
[2010.10.04 17:16:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Systweak
[2010.09.05 20:40:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\TomTom
[2011.04.02 16:25:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Toolbar4
[2011.03.31 15:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\TuneUp Software
[2010.11.28 15:37:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Uniblue
[2009.07.15 19:32:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\URSE Games
[2010.09.22 21:07:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\V-Games
[2011.03.24 11:12:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\VisualShape
[2009.10.22 09:53:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\VitySoft
[2011.01.24 20:15:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Xilisoft
[2011.01.21 20:45:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\XnView
[2011.09.26 15:33:06 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011.09.26 16:02:16 | 000,000,390 | -H-- | M] () -- C:\WINDOWS\Tasks\MpIdleTask.job

========== Purity Check ==========

========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Window Washer" = C:\Program Files\Webroot\Washer\wwDisp.exe
"SpywareTerminatorUpdate" = "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe" -- [2011.09.26 10:21:05 | 003,318,784 | ---- | M] (Crawler.com)
"H/PC Connection Agent" = "C:\PROGRA~1\MICROS~2\wcescomm.exe" -- [2006.11.13 13:39:52 | 001,289,000 | ---- | M] (Microsoft Corporation)
"Google Update" = "C:\Documents and Settings\Miro Juhas\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c -- [2009.07.05 21:07:04 | 000,133,104 | ---- | M] (Google Inc.)
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2004.08.17 16:49:24 | 000,015,360 | ---- | M] (Microsoft Corporation)
"ccleaner" = "C:\Program Files\CCleaner\CCleaner.exe" /AUTO -- [2010.05.25 18:08:54 | 001,694,520 | ---- | M] (Piriform Ltd)
"ares" = "C:\Program Files\Ares\Ares.exe" -h -- [2009.02.03 15:22:18 | 001,004,544 | ---- | M] (Ares Development Group)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]
"" =

< c:\windows\*.* /U >

< %SYSTEMDRIVE%\*.exe >
[2011.09.26 13:44:06 | 000,657,920 | ---- | M] () -- C:\RogueKiller.exe

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2011.07.18 17:03:53 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\.#
[2011.04.25 20:41:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Adobe
[2009.07.11 17:56:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Ahead
[2009.07.06 16:22:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Apple Computer
[2009.09.10 10:00:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Avant Profiles
[2010.10.05 14:10:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\AVG10
[2010.08.23 17:49:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Awem
[2011.05.23 22:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\BabylonToolbar
[2010.02.21 19:28:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\bfgbar
[2010.06.23 21:44:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Bump Technologies, Inc
[2010.03.09 20:34:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\ComodoGroup
[2010.06.25 15:35:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\cosmo ball
[2011.03.23 18:25:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\COWON
[2010.12.03 19:16:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Crossword Forge Prefs Folder
[2010.06.20 13:40:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\DivX
[2011.04.06 21:55:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\DMCache
[2010.06.06 11:38:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\dvdcss
[2011.01.23 18:43:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\DVDVideoSoftIEHelpers
[2010.12.14 17:34:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\eBookPro6
[2009.10.09 16:57:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\eGames
[2009.07.15 19:27:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\EleFun Games
[2009.09.25 20:37:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\eMule
[2011.09.26 14:38:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\ESET
[2010.06.21 21:51:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\facemoods.com
[2009.10.18 21:59:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Friday's games
[2011.01.05 23:42:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\FTWeak
[2009.10.22 15:56:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\FunWebProducts
[2011.07.07 16:57:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Get from YouTube
[2010.12.14 16:30:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\GetRightToGo
[2009.10.05 21:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\GlarySoft
[2010.04.20 22:57:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Google
[2011.06.12 16:40:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\GrabPro
[2011.04.07 14:28:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\gtk-2.0
[2009.10.01 20:43:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Help
[2009.08.16 19:09:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\HP
[2009.12.10 17:49:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\HPAppData
[2011.03.06 22:50:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\ICQ
[2009.07.05 11:00:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Identities
[2011.04.07 13:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\IDM
[2011.07.07 16:57:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Import Audio from Video
[2011.09.26 12:15:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\InstallShield
[2010.08.13 12:34:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\InterTrust
[2009.12.13 22:01:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\IObit
[2010.09.16 16:04:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\iolo
[2010.04.15 19:07:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\JLC's Software
[2010.12.06 18:28:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\LangSoft
[2009.07.05 22:05:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Macromedia
[2011.09.26 13:10:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Malwarebytes
[2011.02.16 18:08:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Media Player Classic
[2011.09.26 11:29:41 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Microsoft
[2009.07.05 21:05:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla
[2011.06.12 16:40:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy
[2009.10.14 22:19:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Opera
[2011.06.12 16:45:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Orbit
[2009.10.14 21:16:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\OtakuSoftware
[2009.12.10 16:19:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Participatory Culture Foundation
[2010.09.27 19:49:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\PC Tools
[2011.04.07 14:38:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\PCF-VLC
[2011.02.16 16:10:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\phonostar GmbH
[2010.06.25 15:35:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Pointstone
[2011.07.07 16:57:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Power Sound Editor Free
[2011.09.26 11:05:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\PriceGong
[2011.06.12 16:40:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\ProgSense
[2011.07.21 15:38:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\QuickStoresToolbar
[2009.11.18 18:20:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\r2 Studios
[2009.07.20 17:09:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\RadLight Company
[2011.03.31 17:56:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Real
[2010.02.20 08:16:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Registry Mechanic
[2011.01.23 18:18:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Reviversoft
[2009.08.28 21:23:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Sahmon Games
[2011.07.10 10:19:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Samsung
[2010.04.18 20:31:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\SBMAV Disk Cleaner Lite
[2009.09.17 20:23:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\ScummVM
[2009.09.25 15:33:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\SearchmeToolbar
[2011.09.16 20:12:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Skype
[2010.09.27 19:22:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Smart PC Solutions
[2009.07.20 22:35:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\SMS Sender
[2010.12.05 20:05:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Software Informer
[2011.07.07 17:30:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Souptoys
[2011.09.26 10:21:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Spyware Terminator
[2009.10.14 22:38:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Sun
[2010.09.27 17:59:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\SUPERAntiSpyware.com
[2010.10.04 17:16:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Systweak
[2010.07.11 12:51:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\teamspeak2
[2010.09.05 20:40:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\TomTom
[2011.04.02 16:25:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Toolbar4
[2011.03.31 15:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\TuneUp Software
[2010.11.28 15:37:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Uniblue
[2009.07.15 19:32:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\URSE Games
[2010.09.22 21:07:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\V-Games
[2011.03.24 11:12:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\VisualShape
[2009.10.22 09:53:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\VitySoft
[2010.06.21 17:21:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\vlc
[2011.01.24 20:15:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\Xilisoft
[2011.01.21 20:45:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Miro Juhas\Data aplikací\XnView

< %APPDATA%\*.exe /s >
[2011.09.26 11:29:39 | 000,187,392 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\dwm.exe
[2009.11.04 17:49:36 | 000,635,664 | ---- | M] (IObit) -- C:\Documents and Settings\Miro Juhas\Data aplikací\IObit\Common\TB_Helper.exe
[2010.02.09 18:04:13 | 019,048,032 | ---- | M] (iolo technologies, LLC ) -- C:\Documents and Settings\Miro Juhas\Data aplikací\iolo\Installers\SystemMechanic.exe
[2011.07.07 17:02:00 | 003,124,384 | ---- | M] (Adobe Systems, Inc.) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
[2011.09.26 11:29:15 | 000,183,296 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Microsoft\conhost.exe
[2011.01.24 20:14:41 | 000,026,694 | R--- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Microsoft\Installer\{446E684C-A48C-4A67-89F7-824B63F96153}\_D72106D85CB38188D5EFB4.exe
[2011.06.12 16:40:48 | 000,416,160 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_23C03927E4BC4E088E65EB720619D818\LatestDLMgr.exe
[2010.12.18 00:07:06 | 000,043,440 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_23C03927E4BC4E088E65EB720619D818\SpeedstarterCZ.exe
[2010.12.17 19:48:22 | 001,720,472 | ---- | M] (Speedchecker Limited ) -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_23C03927E4BC4E088E65EB720619D818\ZrychleniPocitace.exe
[2011.06.12 16:40:55 | 001,842,096 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_23C03927E4BC4E088E65EB720619D818\ZrychleniPocitace_p2v1.exe
[2011.01.23 10:28:46 | 000,349,296 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_297F9B12CD8E487EB35CD816AFC64E30\DLMgr_3_1.6.87.exe
[2010.12.18 00:07:06 | 000,043,440 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_297F9B12CD8E487EB35CD816AFC64E30\SpeedstarterCZ.exe
[2010.12.17 19:48:22 | 001,720,472 | ---- | M] (Speedchecker Limited ) -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_297F9B12CD8E487EB35CD816AFC64E30\ZrychleniPocitace.exe
[2011.01.23 10:29:01 | 001,842,096 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_297F9B12CD8E487EB35CD816AFC64E30\ZrychleniPocitace_p2v1.exe
[2010.12.03 20:05:36 | 012,916,864 | ---- | M] (ReviverSoft LLC.) -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_7F49D7C7B8DE483093D244722EE85AC4\AFIRegistryReviverSetup.exe
[2011.01.04 19:01:45 | 013,055,464 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_7F49D7C7B8DE483093D244722EE85AC4\AFIRegistryReviver_p21v1.exe
[2011.01.04 19:01:13 | 000,349,296 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_7F49D7C7B8DE483093D244722EE85AC4\DLMgr_3_1.6.87.exe
[2010.12.03 20:50:24 | 000,059,944 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_7F49D7C7B8DE483093D244722EE85AC4\RevStarter.exe
[2011.02.13 17:33:40 | 000,356,576 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_81FD6B43C04C4DD78655B65E99FCA754\LatestDLMgr.exe
[2010.12.18 00:07:06 | 000,043,440 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_81FD6B43C04C4DD78655B65E99FCA754\SpeedstarterCZ.exe
[2010.12.17 19:48:22 | 001,720,472 | ---- | M] (Speedchecker Limited ) -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_81FD6B43C04C4DD78655B65E99FCA754\ZrychleniPocitace.exe
[2011.02.13 17:33:52 | 001,842,096 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_81FD6B43C04C4DD78655B65E99FCA754\ZrychleniPocitace_p2v1.exe
[2011.01.23 18:18:29 | 004,585,496 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_B3C3874327284D4BB41E60BC11F5D779\AFIRegRevSilent_p23v3.exe
[2011.01.23 18:18:07 | 000,349,296 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_B3C3874327284D4BB41E60BC11F5D779\DLMgr_3_1.6.87.exe
[2011.01.14 22:48:26 | 004,447,072 | ---- | M] (ReviverSoft ) -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_B3C3874327284D4BB41E60BC11F5D779\RegistryReviverSetup-afl_.exe
[2011.01.15 01:11:04 | 000,059,688 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_B3C3874327284D4BB41E60BC11F5D779\RevStarter.exe
[2011.01.06 14:46:21 | 013,069,488 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_CA3A86B1F63E426CA93FD6905CE3C6B1\AFIRegRevSilent_p22v1.exe
[2011.01.06 14:45:49 | 000,349,296 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_CA3A86B1F63E426CA93FD6905CE3C6B1\DLMgr_3_1.6.87.exe
[2010.12.30 20:45:04 | 012,930,896 | ---- | M] (ReviverSoft LLC.) -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_CA3A86B1F63E426CA93FD6905CE3C6B1\RegistryReviverSetup.exe
[2010.12.30 21:03:04 | 000,059,944 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\OpenCandy\OpenCandy_CA3A86B1F63E426CA93FD6905CE3C6B1\RevStarter.exe
[2011.02.16 16:10:31 | 000,704,248 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\QuickStoresToolbar\unins000.exe
[2010.03.03 15:58:22 | 000,045,304 | ---- | M] (Andreas Breitschopp - Softwareentwicklung und -vertrieb) -- C:\Documents and Settings\Miro Juhas\Data aplikací\QuickStoresToolbar\Update.exe
[2010.09.05 20:42:08 | 020,332,736 | ---- | M] (TomTom International B.V.) -- C:\Documents and Settings\Miro Juhas\Data aplikací\TomTom\HOME\Profiles\9gbub4a3.default\Updates\v2_7_6_2056_win.exe

< MD5 for: AGP440.SYS >
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\agp440.sys

< MD5 for: ATAPI.SYS >
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\autochk.exe
[2004.08.17 16:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\cmdcons\autochk.exe
[2004.08.17 16:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\system32\autochk.exe
[2004.08.17 16:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\system32\dllcache\autochk.exe

< MD5 for: CDROM.SYS >
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cdrom.sys
[2004.08.03 23:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2004.08.17 16:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\cryptsvc.dll
[2004.08.17 16:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\eventlog.dll
[2004.08.17 16:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004.08.17 16:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\explorer.exe
[2004.08.17 16:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\explorer.exe
[2004.08.17 16:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: HAL.DLL >
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\hal.dll
[2004.08.03 23:59:14 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\system32\hal.dll

< MD5 for: CHANGER.SYS >
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\changer.sys

< MD5 for: ISAPNP.SYS >
[2001.10.24 11:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\dllcache\isapnp.sys
[2001.10.24 11:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\drivers\isapnp.sys
[2001.10.25 13:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\isapnp.sys

< MD5 for: LSASS.EXE >
[2004.08.17 16:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2004.08.17 16:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ndis.sys
[2004.08.04 00:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys
[2004.08.04 00:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: NETLOGON.DLL >
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004.08.17 16:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004.08.17 16:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004.08.17 16:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004.08.17 16:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\scecli.dll

< MD5 for: SMSS.EXE >
[2004.08.17 16:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\dllcache\smss.exe
[2004.08.17 16:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\smss.exe
[2004.08.04 00:56:58 | 000,152,576 | ---- | M] (Microsoft Corporation) MD5=DA5CF1C368B33D75602FD6B3A7F5E0C6 -- C:\cmdcons\SYSTEM32\SMSS.EXE

< MD5 for: SVCHOST.EXE >
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\svchost.exe
[2004.08.17 16:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\dllcache\svchost.exe
[2004.08.17 16:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\svchost.exe
[2011.07.17 16:29:25 | 001,154,048 | -H-- | M] () Unable to obtain MD5 -- C:\WINDOWS\update.1\svchost.exe
[2011.07.17 16:45:34 | 000,483,328 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\update.2\svchost.exe
[2011.07.17 16:44:46 | 000,339,968 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\update.5.0\svchost.exe
[2011.07.17 16:29:25 | 001,154,048 | -H-- | M] () Unable to obtain MD5 -- C:\WINDOWS\update.tray-7-0\svchost.exe
[2011.07.17 16:29:25 | 001,154,048 | -H-- | M] () Unable to obtain MD5 -- C:\WINDOWS\update.tray-7-0-lnk\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\userinit.exe
[2004.08.17 16:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\dllcache\userinit.exe
[2004.08.17 16:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004.08.17 16:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2004.08.17 16:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\system32\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\winlogon.exe

< MD5 for: WS2_32.DLL >
[2004.08.17 16:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2004.08.17 16:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ws2_32.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009.07.05 12:28:48 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2009.07.05 12:28:48 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2009.07.05 12:28:48 | 000,495,616 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.sys /3 >
[2011.09.26 10:21:04 | 000,142,592 | ---- | M] () -- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[2011.09.26 16:05:48 | 000,041,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\znasxqie.sys

< %systemroot%\system32\*.* /3 >
[2011.09.26 14:16:27 | 000,002,504 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT
[2011.09.26 14:27:15 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
[2011.09.26 15:28:16 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< *crack* /s >
[2010.06.10 15:48:17 | 000,000,000 | ---- | M] () -- \Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\CT2405280\feed\http___crackle_com_rss_media_sxsw_featured_rss_history.xml
[2010.08.04 20:09:29 | 000,011,421 | ---- | M] () -- \Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\CT2405280\feed\http___crackle_com_rss_media_sxsw_featured_rss_structured.xml
[2011.01.21 19:35:48 | 000,000,000 | ---- | M] () -- \Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\CT2475029\feed\http___crackle_com_rss_media_sxsw_featured_rss_history.xml
[2011.01.21 19:35:48 | 000,000,000 | ---- | M] () -- \Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\CT2475029\feed\http___crackle_com_rss_media_sxsw_featured_rss_structured.xml
[2011.07.07 17:02:57 | 000,001,083 | ---- | M] () -- \Documents and Settings\Miro Juhas\Local Settings\Data aplikací\MyAshampoo\Rss\http___crackle_com_rss_media_sxsw_featured_rss.xml
[2010.04.07 14:50:51 | 000,001,247 | ---- | M] () -- \Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_safecrackerkeno_icon.jpg

< *keygen* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:FC2E567F
@Alternate Data Stream - 523 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:05EE1EEF
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z..ZZZZ.Z.ZZ..ZZ:1
@Alternate Data Stream - 1814 bytes -> C:\WINDOWS\system32\drivers\znasxqie.sys:changelist
@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2E7127D2
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:70DFA5B7
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:74CD40CD
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:4363DE71
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:264A9BB7
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D0DCD8D7
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:43E95997

< End of report >

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 15:46
od Danstahr
OTL Extras logfile created on: 26. 9. 2011 15:49:48 - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Miro Juhas\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000041B | Country: Slovensko | Language: SKY | Date Format: d. M. yyyy

2,00 Gb Total Physical Memory | 1,09 Gb Available Physical Memory | 54,64% Memory free
3,85 Gb Paging File | 2,97 Gb Available in Paging File | 77,20% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,76 Gb Total Space | 3,09 Gb Free Space | 15,64% Space Free | Partition Type: NTFS
Drive D: | 213,13 Gb Total Space | 32,54 Gb Free Space | 15,27% Space Free | Partition Type: NTFS

Computer Name: MIRO | User Name: Miro Juhas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files\Opera\Opera.exe" "%1" (Opera Software)
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"DisableThumbnailCache" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
"C:\Program Files\ICQ7.4\ICQ.exe" = C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4 -- (ICQ, LLC.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows -- (Ares Development Group)
"C:\Program Files\Java\jre6\launch4j-tmp\frd.exe" = C:\Program Files\Java\jre6\launch4j-tmp\frd.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)
"D:\blbosti\instalacky na programi\Ghost Recon Advanced Warfighter 2\graw2.exe" = D:\blbosti\instalacky na programi\Ghost Recon Advanced Warfighter 2\graw2.exe:*:Enabled:Ghost Recon Advanced Warfighter® 2 -- ()
"D:\blbosti\instalacky na programi\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe" = D:\blbosti\instalacky na programi\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe:*:Enabled:Vyhrazený server Ghost Recon Advanced Warfighter® 2 -- ()
"C:\Documents and Settings\Miro Juhas\Plocha\image96523489.exe" = c:\windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor
"C:\Program Files\aTube Catcher\yct.exe" = C:\Program Files\aTube Catcher\yct.exe:*:Enabled:aTube Catcher to download and convert videos. -- (DsNET)
"C:\Program Files\ICQ7.4\ICQ.exe" = C:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4 -- (ICQ, LLC.)
"C:\WINDOWS\system32\muzapp.exe" = C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player -- (Musiccity Co.Ltd.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{0138F525-6C8A-333F-A105-14AE030B9A54}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{04441EE4-3631-43DB-813A-9D031380C8E5}" = MarketingReg
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0FB871A9-C617-4415-BB5D-619A8D946115}" = Microsoft Antimalware Service SK-SK Language Pack
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1D45405D-B1CF-4AEC-AC09-2D8175CB98DE}" = Desktop Player
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery
"{23BE4DF2-293D-4077-82F4-1FD8C269277C}" = TuneUp Utilities Language Pack (en-US)
"{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011
"{27DC856A-0916-4988-8198-8714DDD3183D}" = AGEIA PhysX v7.05.17
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Configurer
"{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing
"{446E684C-A48C-4A67-89F7-824B63F96153}" = Stigo YouTube Downloader
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{50779A29-834E-4E36-BBEB-B7CABC67A825}" = Microsoft Security Client SK-SK Language Pack
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{546C143E-68DC-314D-97BC-1E454E3BA429}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5B4383F2-37EE-4E97-AD81-F5FF76F286DA}" = OutlookAddInNet3Setup
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37}" = ICQ7.4
"{795288DC-2652-44A5-99FD-2ECDF3C633BF}" = SweetIM for Messenger 3.3
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8E9D738A-2C30-4574-90FE-E6B4F6065D48}" = Bluesoleil3.2.2.8 Release 070421
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9FA93155-472F-4778-87A8-95244FD1535D}" = OLYMPUS Master 2
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2C9CD1B-2551-3AED-B244-6698FB929FA6}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{ACA85783-8EEA-4f0a-B2A3-A8173F30209F}" = C4200_doccd
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{BFDE4176-5DFE-4db9-AA00-8F30CB001BDA}" = c4200_Help
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C39E671D-0528-4c5e-A034-8470C5BC393A}" = C4200
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CD6A498E-0FF5-49CE-A70C-2D342E68E709}" = MioMore Desktop
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}" = Kies
"{D8B7A682-20DA-4797-8415-B1FB14D4D32B}" = PS_AIO_Software
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E28750A2-45F2-4b63-99F7-9F81A94B1E2D}" = PS_AIO_Software_min
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = USB PC Camera-168
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"{F78AC3C0-578C-49AB-BD4E-3107A6036A13}" = Tom Clancy's Ghost Recon Advanced Warfighter® 2
"{F93D2591-8201-4692-BD8D-67A0BFAC9C14}" = SweetIM Toolbar for Internet Explorer 3.9
"{FD2E3551-29BB-4FC6-B775-A3330955F7B6}" = Searchme Toolbar
"{FD7F242B-9AA0-40c3-941E-3A9821D19C09}" = PS_AIO_ProductContext
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"Ares" = Ares 2.1.1
"ATI Display Driver" = ATI Display Driver
"aTube Catcher" = aTube Catcher
"CCleaner" = CCleaner (remove only)
"Demo verze Herbáře" = Demo verze Herbáře
"Desene animate_is1" = Desene Animate v1.0
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v4.50
"FreeOnlineRadioPlayerRecorder Toolbar" = FreeOnlineRadioPlayerRecorder Toolbar
"HijackThis" = HijackThis 2.0.2
"Imikimi Plugin" = Imikimi Plugin
"InstallShield_{2EFBB82F-D0FE-460F-A12A-70D7689DC194}" = Worms Forts - V obležení
"InstallShield_{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}" = Kies
"IObitCom Toolbar" = IObitCom Toolbar
"isoHunt Toolbar" = isoHunt Toolbar
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"MyAshampoo Toolbar" = MyAshampoo Toolbar
"NeroMultiInstaller!UninstallKey" = Nero Suite
"OpenAL" = OpenAL
"Opera 11.11.2109" = Opera 11.11
"Píšeme všetkými desiatimi" = Píšeme všetkými desiatimi
"PK-PCSU_is1" = Zrychleni Pocitace
"Pony Luv" = Pony Luv (remove only)
"Power Sound Editor Free" = Power Sound Editor Free
"QuickStores-Toolbar_is1" = QuickStores-Toolbar 1.0.0
"Sandlot Connect_is1" = Sandlot Connect Version 1.2.6
"Sniper Skrytý bojovník_is1" = Sniper Skrytý bojovník
"Spyware Terminator_is1" = Spyware Terminator
"Sticker Book 4 - SHAREWARE" = Sticker Book 4 - SHAREWARE
"Super Online Tuner" = Super Online Tuner 4.5
"The KMPlayer" = The KMPlayer (remove only)
"TuneUp Utilities 2011" = TuneUp Utilities 2011
"Veselé Omalovánky 1_is1" = Veselé Omalovánky 1 - malování pro děti
"Veselé Omalovánky 2_is1" = Veselé Omalovánky 2 - malování pro děti
"Veselé Omalovánky 6_is1" = Veselé Omalovánky 6 - malování pro děti
"Výprava do Květinové země" = Výprava do Květinové země
"WIC" = Windows Imaging Component
"Windows Media Player" = Windows Media Player 11
"WM Downloader_is1" = WM Downloader 3.1.2.2.2010.04.17
"Xilisoft Download Youtube Toolbar" = Xilisoft Download Youtube Toolbar
"Xilisoft Download YouTube Video" = Xilisoft Download YouTube Video
"Zac Browser English" = Zac Browser English

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"0dc477c446281108" = Banek Clock
"4f2adc0dcee4dcac" = CZD Kalkulačka
"Eurotran XP" = Překladač Eurotran XP
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 26. 9. 2011 8:32:48 | Computer Name = MIRO | Source = crypt32 | ID = 131083
Description = Extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou
aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>
se nezdařilo. Chyba: Při ověření se systémovými hodinami nebo časovým razítkem
podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.


Error - 26. 9. 2011 8:32:48 | Computer Name = MIRO | Source = crypt32 | ID = 131083
Description = Extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou
aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>
se nezdařilo. Chyba: Při ověření se systémovými hodinami nebo časovým razítkem
podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.


Error - 26. 9. 2011 8:38:33 | Computer Name = MIRO | Source = Application Error | ID = 1000
Description = Chybující aplikace egui.exe, verze 4.2.71.2, chybující modul egui.exe,
verze 4.2.71.2, adresa chyby 0x000156b0.

Error - 26. 9. 2011 9:05:00 | Computer Name = MIRO | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 3.0.8402.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 26. 9. 2011 9:05:29 | Computer Name = MIRO | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4
3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.

Error - 26. 9. 2011 9:06:25 | Computer Name = MIRO | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070424, P2 beginsearch, P3 search, P4
3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.

Error - 26. 9. 2011 9:18:40 | Computer Name = MIRO | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 1.1.7702.0, P3 1.113.275.0, P4 1.113.275.0, P5 200015b3e9679dd8_9cca347a4659301f89105a5433539e9cad150c69,
P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

Error - 26. 9. 2011 9:23:09 | Computer Name = MIRO | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 1.1.7702.0, P3 1.113.275.0, P4 1.113.275.0, P5 backdoor_win32_cycbot.b, P6 NIL,
P7 NIL, P8 NIL, P9 NIL, P10 NIL.

Error - 26. 9. 2011 9:29:48 | Computer Name = MIRO | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 1.1.7702.0, P3 1.113.275.0, P4 1.113.275.0, P5 backdoor_win32_cycbot.b, P6 NIL,
P7 NIL, P8 NIL, P9 NIL, P10 NIL.

Error - 26. 9. 2011 9:29:49 | Computer Name = MIRO | Source = MPSampleSubmission | ID = 5000
Description = EventType avsubmit, P1 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P2 1.1.7702.0, P3 1.113.275.0, P4 1.113.275.0, P5 backdoor_win32_cycbot!cfg, P6
NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

[ System Events ]
Error - 26. 9. 2011 9:06:25 | Computer Name = MIRO | Source = Microsoft Antimalware | ID = 2001
Description = Pri pokuse programu %%860 o aktualizáciu podpisov sa vyskytla chyba.

Nová
verzia podpisu: Predchádzajúca verzia podpisu: 0.0.0.0 Zdroj aktualizácie: %%859

Etapa
aktualizácie: %%852 Zdrojová cesta: Default URL Typ podpisu: %%800 Typ aktualizácie:
%%803 Používateľ: NT AUTHORITY\SYSTEM Aktuálna verzia nástroja: Predchádzajúca verzia
nástroja: 0.0.0.0 Kód chyby: 0x80070424 Popis chyby: Zadaná služba není nainstalovaná
služba.

Error - 26. 9. 2011 9:10:30 | Computer Name = MIRO | Source = Microsoft Antimalware | ID = 2001
Description = Pri pokuse programu %%860 o aktualizáciu podpisov sa vyskytla chyba.

Nová
verzia podpisu: Predchádzajúca verzia podpisu: 0.0.0.0 Zdroj aktualizácie: %%851

Etapa
aktualizácie: %%853 Zdrojová cesta: http://go.microsoft.com/fwlink/?LinkID= ... 752CCA7094

Typ
podpisu: %%800 Typ aktualizácie: %%803 Používateľ: NT AUTHORITY\NETWORK SERVICE Aktuálna
verzia nástroja: Predchádzajúca verzia nástroja: 0.0.0.0 Kód chyby: 0x80072ee2 Popis
chyby: The operation timed out

Error - 26. 9. 2011 9:10:30 | Computer Name = MIRO | Source = Microsoft Antimalware | ID = 2001
Description = Pri pokuse programu %%860 o aktualizáciu podpisov sa vyskytla chyba.

Nová
verzia podpisu: Predchádzajúca verzia podpisu: 0.0.0.0 Zdroj aktualizácie: %%851

Etapa
aktualizácie: %%853 Zdrojová cesta: http://go.microsoft.com/fwlink/?LinkID= ... 752CCA7094

Typ
podpisu: %%801 Typ aktualizácie: %%803 Používateľ: NT AUTHORITY\NETWORK SERVICE Aktuálna
verzia nástroja: Predchádzajúca verzia nástroja: 0.0.0.0 Kód chyby: 0x80072ee2 Popis
chyby: The operation timed out

Error - 26. 9. 2011 9:10:30 | Computer Name = MIRO | Source = Microsoft Antimalware | ID = 2001
Description = Pri pokuse programu %%860 o aktualizáciu podpisov sa vyskytla chyba.

Nová
verzia podpisu: Predchádzajúca verzia podpisu: 0.0.0.0 Zdroj aktualizácie: %%851

Etapa
aktualizácie: %%853 Zdrojová cesta: http://go.microsoft.com/fwlink/?LinkID= ... 752CCA7094

Typ
podpisu: %%800 Typ aktualizácie: %%803 Používateľ: NT AUTHORITY\NETWORK SERVICE Aktuálna
verzia nástroja: Predchádzajúca verzia nástroja: 0.0.0.0 Kód chyby: 0x80072ee2 Popis
chyby: The operation timed out

Error - 26. 9. 2011 9:10:30 | Computer Name = MIRO | Source = Microsoft Antimalware | ID = 2001
Description = Pri pokuse programu %%860 o aktualizáciu podpisov sa vyskytla chyba.

Nová
verzia podpisu: Predchádzajúca verzia podpisu: 0.0.0.0 Zdroj aktualizácie: %%851

Etapa
aktualizácie: %%853 Zdrojová cesta: http://go.microsoft.com/fwlink/?LinkID= ... 752CCA7094

Typ
podpisu: %%801 Typ aktualizácie: %%803 Používateľ: NT AUTHORITY\NETWORK SERVICE Aktuálna
verzia nástroja: Predchádzajúca verzia nástroja: 0.0.0.0 Kód chyby: 0x80072ee2 Popis
chyby: The operation timed out

Error - 26. 9. 2011 9:10:30 | Computer Name = MIRO | Source = Microsoft Antimalware | ID = 2001
Description = Pri pokuse programu %%860 o aktualizáciu podpisov sa vyskytla chyba.

Nová
verzia podpisu: Predchádzajúca verzia podpisu: 0.0.0.0 Zdroj aktualizácie: %%851

Etapa
aktualizácie: %%853 Zdrojová cesta: http://go.microsoft.com/fwlink/?LinkID= ... 752CCA7094

Typ
podpisu: %%800 Typ aktualizácie: %%803 Používateľ: NT AUTHORITY\NETWORK SERVICE Aktuálna
verzia nástroja: Predchádzajúca verzia nástroja: 0.0.0.0 Kód chyby: 0x80072ee2 Popis
chyby: The operation timed out

Error - 26. 9. 2011 9:15:10 | Computer Name = MIRO | Source = Service Control Manager | ID = 7023
Description = Služba Služba HP CUE DeviceDiscovery byla ukončena s následující chybou:
%%126

Error - 26. 9. 2011 9:15:12 | Computer Name = MIRO | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: BTHidMgr

Error - 26. 9. 2011 9:27:56 | Computer Name = MIRO | Source = Service Control Manager | ID = 7023
Description = Služba Služba HP CUE DeviceDiscovery byla ukončena s následující chybou:
%%126

Error - 26. 9. 2011 9:28:13 | Computer Name = MIRO | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: BTHidMgr


< End of report >

Jen jsem si kvůli lepší čitelnosti hodil logy sem, skript napíšu za chvilku.

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 15:57
od matthew_tv
V pohodě, ja to z FTPčka tak skoro nesmažu...
Ale rychle, rychle, kamarát už čeká na PC :P
No stejně dík prozatím ;-)

//Končím v práci, zítra se tu vrátím, kouknu váš skript a napíšu, jak to dopadlo..:)

Re: Špína v PC, prosím o pomoc

Napsal: 26 zář 2011 16:27
od Danstahr
Uf, to je teda svinčík. Radši na víckrát...

:arrow: Spusťte znovu OTL, do okna dole vložte následující skript a klikněte na tlačítko Opravit. Po restartu se otevře log, ten sem prosím vložte. Také sem vložte nový log z OTL podle návodu o krok zpět.

Kód: Vybrat vše

:OTL
SRV - File not found [On_Demand | Stopped] -- -- (WMPNetworkSvc)
SRV - File not found [Auto | Stopped] -- -- (Sukoku Service)
SRV - File not found [On_Demand | Stopped] -- -- (Start BT in service)
SRV - File not found [Unknown | Stopped] -- -- (ResultDns Service)
SRV - File not found [Auto | Stopped] -- -- (hpqddsvc)
DRV - [2011.09.26 15:28:04 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2C3FAA68-C9DE-46FE-A197-9F7EE6415EEC}\MpKsla32b98c8.sys -- (MpKsla32b98c8)
DRV - [2011.09.26 15:17:54 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{2C3FAA68-C9DE-46FE-A197-9F7EE6415EEC}\MpKsld43a85fb.sys -- (MpKsld43a85fb)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/xilisoftdownloadyoutube/{D808530E-388E-417D-BCF9-99E2EC5DA240}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ostpl&s={searchTerms}&f=4
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = My Web Search
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultUrl = http://www.mywebsearch.com/jsp/cfg_redi ... searchfor={searchTerms}
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml ... tJ2QVpGw8Q
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://flv.asksearch.com/?cfg=2-113-11-qNUv
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVD2.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA2.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {ce10bf86-da68-441e-91fa-38336363e3cd} - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - No CLSID value found
IE - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\URLSearchHook: {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (Conduit Ltd.)
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "FreeOnlineRadioPlayerRecorder Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2737658&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "My Web Search"
FF - prefs.js..browser.startup.homepage: "http://search13.net?clid=486"
FF - prefs.js..extensions.enabledItems: {2832ABCD-4444-1012-2D45-132D5447C445}:1.0.0
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA82}:1.0.2
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA80}:1.0.24
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA81}:1.0.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {7645f4b1-1f19-13dd-2d6b-0200600c2a56}:1.0
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA96}:1.0.7
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9
FF - prefs.js..extensions.enabledItems: {63414328-3ab4-2c84-6c41-5a473c4b2ff7}:1.0
FF - prefs.js..extensions.enabledItems: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {1A615EA8-4C56-49EE-BE83-F9A264B79997}:1.0
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.1.0.0
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
FF - prefs.js..extensions.enabledItems: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {ce10bf86-da68-441e-91fa-38336363e3cd}:2.7.1.3
FF - prefs.js..extensions.enabledItems: quickstores@quickstores.de:1.2.0
FF - prefs.js..extensions.enabledItems: {8675f4b3-2f19-11ed-2d6b-0800600c0a16}:1.0
FF - prefs.js..extensions.enabledItems: {75656794-AB59-4712-BFBC-5D816D56F3BC}:1.1.3
FF - prefs.js..extensions.enabledItems: ffxtlbr@babylon.com:1.1.3
FF - prefs.js..extensions.enabledItems: {84b24861-62f6-364b-eba5-2e5e2061d7e6}:0.9.3
FF - prefs.js..extensions.enabledItems: {f999a48b-1950-4d81-9971-79018f807b4b}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {8675f4b3-2f19-11ed-2d6b-0800600c0a17}:1.0
FF - prefs.js..keyword.URL: "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZJxdm048YYsk&ptb=VepJ4ftGj1sytJ2QVpGw8Q&ind=2011071112&ptnrS=ZJxdm048YYsk&si=CN-z_5ra-akCFZYS3wodAG1HXw&n=77de8288&psa=&st=kwd&searchfor="
FF - prefs.js..network.proxy.type: 0
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2405280&SearchSource=3&q={searchTerms}"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://search13.net?clid=486"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.avg.com/route/?d=4cb3fe87&v=6.010.006.004&i=26&tp=ab&iy=&ychte=us&lng=sk&q="
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2224E955-00E9-4613-A844-CE69FCCAAE91}: C:\Program Files\Internet Saving Optimizer\3.8.1.4690\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}: C:\Program Files\Media Access Startup\2.0.0.1050\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\1.bin
[2011.09.26 10:53:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions
[2011.02.10 13:36:57 | 000,000,000 | ---D | M] (LongTailVideo Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{1bcec53b-aa13-4de2-814d-2d6a98e7ba79}
[2009.10.07 18:39:53 | 000,000,000 | ---D | M] (Beemp3 Search ToolBar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{2832ABCD-4444-1012-2D45-132D5447C445}
[2010.08.26 20:27:50 | 000,000,000 | ---D | M] (Softonic-Eng7 Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
[2011.06.12 10:54:59 | 000,000,000 | ---D | M] ("Get Styles") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA80}
[2010.01.23 12:42:28 | 000,000,000 | ---D | M] ("Homepage Guard") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA81}
[2010.01.23 12:42:28 | 000,000,000 | ---D | M] ("Express Tab") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA82}
[2011.06.12 10:54:59 | 000,000,000 | ---D | M] ("Usage Stat") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA96}
[2009.12.24 11:39:12 | 000,000,000 | ---D | M] (FBFan) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA99}
[2010.06.04 13:35:39 | 000,000,000 | ---D | M] (QAssistant) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
[2011.04.02 16:25:53 | 000,000,000 | ---D | M] (Xilisoft Download Youtube Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC}
[2010.03.20 08:01:47 | 000,000,000 | ---D | M] (U Flv) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{7645f4b1-1f19-13dd-2d6b-0200600c2a56}
[2011.06.05 16:50:49 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.06.04 20:56:37 | 000,000,000 | ---D | M] (mediaplayerconnectivity) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{84b24861-62f6-364b-eba5-2e5e2061d7e6}
[2011.03.17 15:12:31 | 000,000,000 | ---D | M] (KFD Flv) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a16}
[2011.06.25 11:05:26 | 000,000,000 | ---D | M] (VFD Flv) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a17}
[2011.06.05 16:50:56 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2011.06.05 16:50:57 | 000,000,000 | ---D | M] (MyAshampoo Community Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
[2011.01.23 18:31:32 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.02.16 15:21:07 | 000,000,000 | ---D | M] (Movier-media Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{ce10bf86-da68-441e-91fa-38336363e3cd}
[2011.01.11 12:02:05 | 000,000,000 | ---D | M] (Movier-media Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{ce10bf86-da68-441e-91fa-38336363e3cd}(2)
[2010.10.23 15:03:53 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2011.06.12 15:07:17 | 000,000,000 | ---D | M] (FreeOnlineRadioPlayerRecorder Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}
[2011.06.05 16:50:38 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\engine@conduit.com
[2011.05.23 21:55:14 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\ffxtlbr@babylon.com
[2011.06.05 16:50:57 | 000,000,000 | ---D | M] (QuickStores-Toolbar) -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\extensions\quickstores@quickstores.de
[2010.10.12 09:05:28 | 000,001,761 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\ask.uk.xml
[2010.05.26 15:18:50 | 000,002,333 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\askcom.xml
[2010.08.11 11:56:22 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\conduit.xml
[2011.07.09 15:42:31 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin-1.xml
[2010.09.14 18:21:31 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin-2.xml
[2010.09.27 21:30:46 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin-3.xml
[2010.10.05 14:54:53 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin-4.xml
[2011.02.20 11:21:20 | 000,000,168 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin.gif
[2011.02.20 11:21:20 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin.src
[2010.05.12 18:40:48 | 000,001,042 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\icqplugin.xml
[2011.07.17 17:05:17 | 000,009,987 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\mywebsearch.xml
[2010.09.23 14:42:42 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\search-the-web.xml
[2010.10.23 15:03:51 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\sweetim.xml
[2009.12.19 23:44:51 | 000,001,586 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\web-search.xml
[2009.07.16 19:04:05 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Miro Juhas\Data aplikací\Mozilla\Firefox\Profiles\sgyhqtm0.default\searchplugins\winamp-search.xml
[2009.10.14 22:39:26 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010.09.18 16:13:31 | 000,000,000 | ---D | M] (ResultDns) -- C:\PROGRAM FILES\MOZILLA FIREFOX 3.1 BETA 3\EXTENSIONS\{1A615EA8-4C56-49EE-BE83-F9A264B79997}
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (compliance0615 Toolbar) - {31c7d459-9cc3-44f2-9dca-fc11795309b4} - C:\Program Files\IObitCom\prxtbIOb0.dll (Conduit Ltd.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\prxtbDVD2.dll (Conduit Ltd.)
O2 - BHO: (MyAshampoo Toolbar) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files\MyAshampoo\prxtbMyA2.dll (Conduit Ltd.)
O2 - BHO: (Hunt TB Toolbar) - {a6e4a4eb-d169-4e99-8988-250fcbafe767} - C:\Program Files\isoHunt\prxtbiso2.dll (Conduit Ltd.)
O2 - BHO: (FreeOnlineRadioPlayerRecorder Toolbar) - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (Conduit Ltd.)
O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Xilisoft Download Youtube Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (compliance0615 Toolbar) - {31C7D459-9CC3-44F2-9DCA-FC11795309B4} - C:\Program Files\IObitCom\prxtbIOb0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\prxtbDVD2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (MyAshampoo Toolbar) - {A1E75A0E-4397-4BA8-BB50-E19FB66890F4} - C:\Program Files\MyAshampoo\prxtbMyA2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (Hunt TB Toolbar) - {A6E4A4EB-D169-4E99-8988-250FCBAFE767} - C:\Program Files\isoHunt\prxtbiso2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\..\Toolbar\WebBrowser: (FreeOnlineRadioPlayerRecorder Toolbar) - {F999A48B-1950-4D81-9971-79018F807B4B} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (Conduit Ltd.)
O4 - HKU\S-1-5-21-1202660629-507921405-725345543-1003..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe File not found
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1202660629-507921405-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra Button: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm File not found
O9 - Extra 'Tools' menuitem : GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm File not found
O9 - Extra Button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe File not found
O9 - Extra Button: Avanti! - {93119390-0D2E-4331-8511-A5B4F9EACA7C} - C:\Program Files\F.Developers\Avanti\avanti.exe File not found
O9 - Extra 'Tools' menuitem : Avanti! - {93119390-0D2E-4331-8511-A5B4F9EACA7C} - C:\Program Files\F.Developers\Avanti\avanti.exe File not found
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
[2011.09.09 18:52:58 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.8.1
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2011.07.17 16:58:32 | 000,246,272 | ---- | C] () -- C:\WINDOWS\unrar.exe
[2011.07.17 16:44:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\loader2.exe_ok
[2009.11.04 17:49:36 | 000,635,664 | ---- | M] (IObit) -- C:\Documents and Settings\Miro Juhas\Data aplikací\IObit\Common\TB_Helper.exe
[2011.09.26 16:05:48 | 000,041,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\znasxqie.sys
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:FC2E567F
@Alternate Data Stream - 523 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:05EE1EEF
@Alternate Data Stream - 448 bytes -> C:\3590F75ABA9E485486C100C1A9D4FF06Z..ZZZZ.Z.ZZ..ZZ:1
@Alternate Data Stream - 1814 bytes -> C:\WINDOWS\system32\drivers\znasxqie.sys:changelist
@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2E7127D2
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:70DFA5B7
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:74CD40CD
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:4363DE71
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:264A9BB7
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D0DCD8D7
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:43E95997

:Files
C:\Windows\update.*
C:\3590F75ABA9E485486C100C1A9D4FF06Z..ZZZZ.Z.ZZ..ZZ
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-507921405-725345543-1003Core.job


:Reg
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]

:Commands
[Emptytemp]
[ResetHosts]
[Clearallrestorepoints]
[EmptyFlash]

Re: Špína v PC, prosím o pomoc

Napsal: 27 zář 2011 07:01
od matthew_tv
Díks, log vkladám na FTP, jelikož má víc než povolený počet znaků.

Kód: Vybrat vše

http://somebody.tbs.sk/log.txt