Stránka 1 z 2

prosím o kontrolu logu pomalé PC

Napsal: 12 úno 2012 10:10
od Oji
Logfile of random's system information tool 1.09 (written by random/random)
Run by Admin at 2012-02-12 10:06:39
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 92 GB (78%) free of 117 GB
Total RAM: 511 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:07:44, on 12.2.2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Seznam.cz\postak.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
F:\moje data\programy\antivir\RSIT.exe
C:\Program Files\trend micro\Admin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.9\pdfforgeToolbarIE.dll
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\3046\toolbaru.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.9\pdfforgeToolbarIE.dll
O2 - BHO: Lištička - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\listicka.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\3046\toolbaru.dll
O3 - Toolbar: (no name) - {4AD56E6F-7074-41EE-8A40-583C2C76EFCD} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Nástroje Lištičky - {1EA00BE1-6E54-4E2A-8099-680300BF23E1} - C:\Program Files\Seznam.cz\toolbar\toolbar.dll
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.9\pdfforgeToolbarIE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Antivirus Pro 2010] "C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe" /hide
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Seznam Postak] "C:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to AMV Converter... - C:\kfph\AMVConverter\grab.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\kfph\MediaManager\grab.html
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{10F3810B-5628-48A9-8BB7-D361247C4DB4}: NameServer = 192.168.150.237,194.228.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E71ECD8-B3D0-4D43-87B5-5CF22ECA1B34}: NameServer = 192.168.150.237,194.228.2.1
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 9406 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1123561945-725345543-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1123561945-725345543-1003UA.job
C:\WINDOWS\tasks\Norton Security Scan.job
C:\WINDOWS\tasks\RMSchedule.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{35BE11B1-063F-4046-8D29-C9D1A85202FD}.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\628oys85.default

prefs.js - "browser.startup.homepage" - "http://home.juicyaccess.com"
prefs.js - "extensions.enabledItems" - "{872A1C39-DF0B-4c8b-AD84-12BA24A3B781}:4.1.4.0, {0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}:1.5.0.850, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {2224E955-00E9-4613-A844-CE69FCCAAE91}:3.4.0.4340, pdfforge@mybrowserbar.com:4.9, wtxpcom@mybrowserbar.com:4.9, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10"
prefs.js - "keyword.URL" - "http://search.yahoo.com/search?fr=green ... =971163&p="

"{872A1C39-DF0B-4c8b-AD84-12BA24A3B781}"=C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar
"{2224E955-00E9-4613-A844-CE69FCCAAE91}"=C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF
"{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}"=C:\Program Files\Media Access Startup\1.5.0.850\FF
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe Flash Player 9.0
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1]
"Description"=Yahoo! activeX Plug-in Bridge
"Path"=C:\Program Files\Yahoo!\Common\npyaxmpb.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
aboutRights.js
aboutRobots.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
txEXSLTRegExFunctions.js
WebContentConverter.js

C:\Program Files\Mozilla Firefox\plugins\
flashplayer.xpt
npnul32.dll
nppdf32.dll
NPSWF32.dll
NPSWF32_FlashUtil.exe

C:\Program Files\Mozilla Firefox\searchplugins\
FFToolbar.xml
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
yahoo.xml

C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\628oys85.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}
{635abd67-4fe9-1b23-4f01-e679fa7484c1}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-21 263280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll [2010-09-18 842296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\4.9\pdfforgeToolbarIE.dll [2011-12-13 1071456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Lištička - C:\Program Files\Seznam.cz\listicka.dll [2010-10-07 1961240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQ Toolbar - C:\PROGRA~1\ICQTOO~1\3046\toolbaru.dll [2006-12-25 701952]
{4AD56E6F-7074-41EE-8A40-583C2C76EFCD}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-21 263280]
{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - Nástroje Lištičky - C:\Program Files\Seznam.cz\toolbar\toolbar.dll [2010-10-07 187672]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\4.9\pdfforgeToolbarIE.dll [2011-12-13 1071456]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-10-24 90112]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2005-11-08 128920]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2008-05-09 1817600]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-10-22 7700480]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-10-22 86016]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-02-25 77824]
"Antivirus Pro 2010"=C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe /hide []
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]
""= []
"SearchSettings"=C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe [2011-12-13 922976]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"Google Update"=C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-07-27 133104]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-07-21 39408]
"Seznam Postak"=C:\Program Files\Seznam.cz\postak.exe [2010-10-07 488728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe /s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-09-16 1961984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2006-02-25 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2004-12-20 33792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Admin^Nabídka Start^Programy^Po spuštění^hamachi.lnk]
C:\PROGRA~1\Hamachi\hamachi.exe []

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 267304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=
scecli
scecli
scecli

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Rva50.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Rva50.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceClassicControlPanel"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=255
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe"="C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:*:Enabled:Pro Evolution Soccer 2008"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:explorer"
"C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe"="C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:*:Enabled:Football Manager 2008"
"C:\Documents and Settings\Admin\Plocha\Skype.exe"="C:\Documents and Settings\Admin\Plocha\Skype.exe:*:Enabled:Skype"
"C:\Program Files\BitLord\BitLord.exe"="C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP62"=vp6vfw.dll
"msacm.vorbis"=vorbis.acm
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"midi3"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-02-12 10:06:45 ----D---- C:\Program Files\trend micro
2012-02-12 10:06:39 ----D---- C:\rsit
2012-02-12 10:03:04 ----D---- C:\Program Files\Yahoo!
2012-02-12 10:00:35 ----D---- C:\Program Files\CCleaner
2012-02-12 09:48:16 ----A---- C:\WINDOWS\system32\wpa.bak
2012-02-11 12:23:33 ----D---- C:\WINDOWSL
2012-02-11 12:23:33 ----ASH---- C:\pagefile.sys
2012-02-11 12:03:01 ----ASH---- C:\hiberfil.sys
2012-02-11 11:54:44 ----A---- C:\AUTOEXEC.BAT
2012-01-19 17:57:00 ----A---- C:\WINDOWS\ALIK.INI

======List of files/folders modified in the last 1 month======

2012-02-12 10:07:17 ----D---- C:\WINDOWS\system32\CatRoot2
2012-02-12 10:07:17 ----D---- C:\WINDOWS\system32\CatRoot_bak
2012-02-12 10:07:17 ----D---- C:\WINDOWS\system32\CatRoot
2012-02-12 10:07:06 ----HD---- C:\WINDOWS\inf
2012-02-12 10:06:45 ----RD---- C:\Program Files
2012-02-12 10:05:07 ----D---- C:\WINDOWS\TEMP
2012-02-12 09:58:29 ----D---- C:\WINDOWS\Prefetch
2012-02-12 09:53:30 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2012-02-12 09:48:50 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-02-12 09:48:30 ----AC---- C:\WINDOWS\setuplog.txt
2012-02-12 09:48:16 ----D---- C:\WINDOWS\system32
2012-02-12 09:12:17 ----D---- C:\Program Files\Mozilla Firefox
2012-02-11 12:03:30 ----SHD---- C:\Config.Msi
2012-02-11 12:03:03 ----D---- C:\Documents and Settings
2012-02-11 12:00:28 ----SHD---- C:\System Volume Information
2012-02-11 11:51:30 ----D---- C:\Program Files\Windows Media Player
2012-02-11 11:51:27 ----D---- C:\Program Files\Movie Maker
2012-02-11 11:51:08 ----D---- C:\Program Files\NetMeeting
2012-02-11 11:51:06 ----D---- C:\Program Files\Outlook Express
2012-02-11 11:51:06 ----D---- C:\Program Files\Common Files\System
2012-02-11 11:50:59 ----D---- C:\Program Files\Internet Explorer
2012-02-11 11:49:15 ----D---- C:\Program Files\Messenger
2012-02-11 11:48:56 ----D---- C:\Program Files\Windows NT
2012-02-11 11:45:35 ----SH---- C:\boot.ini
2012-02-11 10:34:19 ----AC---- C:\WINDOWS\wincmd.ini
2012-02-01 18:30:50 ----D---- C:\Documents and Settings\Admin\Data aplikací\Spyware Terminator
2012-01-20 16:42:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2012-01-19 17:57:35 ----D---- C:\WINDOWS
2012-01-19 17:56:39 ----D---- C:\WINDOWS\system

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\system32\DRIVERS\PxHelp20.sys [2004-12-20 20016]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2005-12-11 664064]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2004-08-04 44672]
R0 viamraid;viamraid; C:\WINDOWS\system32\DRIVERS\viamraid.sys [2004-07-06 60672]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-09-07 28880]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2004-08-17 41216]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-09-07 100176]
R2 MaVctrl;MaVctrl; C:\WINDOWS\system32\DRIVERS\MaVc2K.sys [2004-08-23 11089]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2002-09-23 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2002-09-23 55936]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-09-07 23376]
R3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2006-05-21 223128]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-10-22 3994624]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\viaudios.sys [2004-03-17 117248]
S2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2004-08-03 88448]
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-10-26 3786944]
S3 cmpci;C-Media PCI Audio Driver (WDM); C:\WINDOWS\system32\drivers\cmaudio.sys [2002-11-18 377358]
S3 cwrwdm;Ovladač SoundFusion(tm) WDM; C:\WINDOWS\system32\DRIVERS\cwrwdm.sys [2004-08-03 48640]
S3 Edspport;EDSP Port Driver; C:\WINDOWS\system32\DRIVERS\es56hpi.sys [2001-10-24 594238]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-01-17 25280]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\WINDOWS\system32\DRIVERS\k750bus.sys [2005-07-07 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\k750mdfl.sys [2005-07-07 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\WINDOWS\system32\DRIVERS\k750mdm.sys [2005-07-07 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\WINDOWS\system32\DRIVERS\k750mgmt.sys [2005-07-07 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\WINDOWS\system32\DRIVERS\k750obex.sys [2005-07-07 79488]
S3 MaRdPnp;MaRdPnp; C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys [2004-09-13 49611]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2006-10-13 163584]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2011-12-14 748440]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-10-22 159810]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2010-08-05 583640]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-04-22 66872]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2008-05-09 606720]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S2 NWCWorkstation;Klient systému NetWare; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-07-21 182768]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: prosím o kontrolu logu pomalé PC

Napsal: 12 úno 2012 10:56
od Márty84
Zdravim :)

Neco tam vidim.

Nejdrive udelejte uplnou kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem jeho log. Predem nic nemazte, miva obcas falesny poplach

Re: prosím o kontrolu logu pomalé PC

Napsal: 12 úno 2012 16:08
od Oji
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.60.1.1000
www.malwarebytes.org

Verze databáze: v2012.02.12.02

Windows XP Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.18702
Admin :: INTELP4 [administrátor]

Ochrana: Povolena

12.2.2012 11:17:56
mbam-log-2012-02-12 (16-07-07).txt

Typ: Úplná kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 319384
Uplynulý čas: 2 hodin, 45 minut, 13 sekund

Nalezené procesy v paměti: 1
C:\Program Files\Application Updater\ApplicationUpdater.exe (PUP.Dealio.TB) -> 1908 -> Žádná instrukce nebyla provedena.

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 93
HKLM\SYSTEM\CurrentControlSet\Services\Application Updater (PUP.Dealio.TB) -> Žádná instrukce nebyla provedena.
HKCR\AppID\{57ABA38E-6535-48F3-99FD-EFDC62137C78} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{25B8D58C-B0CB-46b0-BA64-05B3804E4E86} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\ExplorerBar.FunExplorer.1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\ExplorerBar.FunExplorer (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{2E8E2100-98CB-4AAC-9480-63A281ACAFF5} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\TypeLib\{D335D84D-61D8-4B5F-9C4E-067DC8B27ED5} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\Interface\{42C23154-00FA-4A93-9DE9-3EB523CFFFF6} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\AIMActiveXDLL.AIMHelper.1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\AIMActiveXDLL.AIMHelper (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{3FB17508-0BF4-4FDE-845A-323A1052957C} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\TypeLib\{0514C9B0-E4C6-4D6B-A3A6-B38BC280B115} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\Interface\{3FB17508-0BF4-4FDE-845A-323A1052957C} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{51B67A88-02D0-43CB-8D12-5CA3E2D4CF49} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\OEActiveXDLL.DesktopButtonHandler.1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\OEActiveXDLL.DesktopButtonHandler (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{CDBFB47B-58A8-4111-BF95-06178DCE326D} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\ExplorerBar.FunRedirector.1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\ExplorerBar.FunRedirector (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{D44CC2FB-77B8-48A5-A5DC-F961F2D258FB} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\OEActiveXDLL.DesktopOEAddin1.1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\OEActiveXDLL.DesktopOEAddin1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\Installer\Features\E5A579D1621164F44A32148791436AE3 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\Installer\Products\E5A579D1621164F44A32148791436AE3 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E5A579D1621164F44A32148791436AE3 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\Installer\UpgradeCodes\B0F0EB6EC578EC54F90B6FCD03D7DD95 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\B0F0EB6EC578EC54F90B6FCD03D7DD95 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4AD56E6F-7074-41EE-8A40-583C2C76EFCD} (Rogue.PCSuperCharger) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02705FD89352CE24BAB275AC5589E38C (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\06B0D94320DD05A4E9DB282F94C0DA38 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1109202CDBA16CA419000CAF22DC3CF9 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18013DBED0B359542A12FAFBE579CB03 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19C4600189189494F8DA9315E398EA48 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1CEF2348A925D32489049BC015A2FBDA (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E259CE5965475E4AB3A1200C49CCF35 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22F45360DE7C90B439A645289CF9B2DD (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2452F2CD3177189479B39659A8AE88FC (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2677411F68E73A14B94EA51766AC0760 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2CC4FA804BFD0A041B857D16AFECDB18 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\354306B5FC152ED4995417B24A4297C3 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4978F13E5121802419CEA3AD9EE8451E (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5134055961694D94AB0F6D6B58B60CCA (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F0155814F886004495DA93F7B7F6C7F (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F15B616E5327C148A68625CB0B90C98 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B1D2633A813EA645A5B4B57D73EDEAC (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C07FC781ABBBEB41A95822938168847 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\746D1DF045C9E4C49B480D77D5D41737 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7BD319C63E0F4FE4B8DA3232A14C4AAD (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8A5F96A30E6BB874693CB43A636903FD (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8C6FF01E712E0B04B8ABA6074B0F4656 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8DB5173D5B5D0F04FB5132B9383DCBE3 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\90CF330D92424144186ED821BC6FD291 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\913971928D8605C40879DB575B7A7C4B (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\92430752A00FA6748B9782E647D1D2A8 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98A12ED2F6EF15746866D10403464F8A (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\991B13F7BF5972E40AC7059929ECFBA0 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9DC359691A7A8AF49A18461E15B4AF0A (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A3F615493AE24294E9E2A8091C557D40 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5BD0354B4CC2E34786929405276F8B2 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B7E05F91EC77F73439FAB74946182C65 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAA4E39C82B6FF54DA2FF843BD7F68D2 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB5F2C7ED86329349BF6C4C455476CEF (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD9619B7EEF775948A4EE131B16FCCD8 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C33ADBFA7B15A9947A8BC54299B85DA5 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C762A014430216B44A4D962CE9BDFF7B (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C7A9B7138E9A75B439EC09153CEACC40 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2C0C17A2E0BC2849B0D2A0EDF5743B2 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2F71258B0760D94F92CC1BC754B71BF (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F28578EE4F61E5E4AA992AE68C1BEDD3 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F4808D2FD10CCEF49BC57B6C533CD553 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F572404D07A14014093FB02B74BCBA69 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA280F294852EBB4C800E7986EA0AF04 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FD46FF488EFB9CB42AD7D5C8B3BC7C8C (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDFB031C7DF8E634DBE3D73820D80ADC (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCR\AppID\AIMActiveXDLL.DLL (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCU\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\DoubleD (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Internet Saving Optimizer (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Media Access Startup (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Office\Outlook\Addins\OEActiveXDLL.DesktopOEAddin1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\DoubleD (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Internet Saving Optimizer (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Media Access Startup (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Purchased Products (Rogue.Multiple) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\JuicyAccess Toolbar (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{16B6279B-9FF5-41fb-8BF9-404324F5DD1F}}_is1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1FB52AB3-5987-45a2-85E0-F3EC30DDDC29}}_is1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C5096216-7703-409E-B85A-8A6EE7395128}}_is1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.

Nalezené hodnoty v registru: 17
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAM FILES\APPLICATION UPDATER\APPLICATIONUPDATER.EXE (PUP.Dealio.TB) -> Data: 1 -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Data: ©ěVŤH˘K…b—ą«xŇ -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{4AD56E6F-7074-41EE-8A40-583C2C76EFCD} (Rogue.PCSuperCharger) -> Data: onŐJtpîAŠ@X<,vďÍ -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{4AD56E6F-7074-41EE-8A40-583C2C76EFCD} (Rogue.PCSuperCharger) -> Data: -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4AD56E6F-7074-41EE-8A40-583C2C76EFCD} (Rogue.PCSuperCharger) -> Data: -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Data: -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{4AD56E6F-7074-41EE-8A40-583C2C76EFCD} (Rogue.PCSuperCharger) -> Data: -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions\{872A1C39-DF0B-4c8b-AD84-12BA24A3B781} (Adware.DoubleD) -> Data: -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions|{872A1C39-DF0B-4c8b-AD84-12BA24A3B781} (Adware.DoubleD) -> Data: C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions\{2224E955-00E9-4613-A844-CE69FCCAAE91} (Adware.DoubleD) -> Data: -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions|{2224E955-00E9-4613-A844-CE69FCCAAE91} (Adware.DoubleD) -> Data: C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions\{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC} (Adware.DoubleD) -> Data: -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions|{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC} (Adware.DoubleD) -> Data: C:\Program Files\Media Access Startup\1.5.0.850\FF -> Žádná instrukce nebyla provedena.
HKCU\Control Panel\don't load|scui.cpl (Hijack.SecurityCenter) -> Data: No -> Žádná instrukce nebyla provedena.
HKCU\Control Panel\don't load|wscui.cpl (Hijack.SecurityCenter) -> Data: No -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|DefaultScope (Adware.DoubleD) -> Data: {5617ECA9-488D-4BA2-8562-9710B9AB78D2} -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Data: 1 -> Žádná instrukce nebyla provedena.

Nalezené datové položky v registru: 6
HKCU\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Žádná instrukce nebyla provedena.

Nalezené složky: 97
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\15D3A7BB (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\15D3A7BB\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\24618E3F (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\24618E3F\611F5CA (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\29A73ACD (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\29A73ACD\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\2A3DCDAF (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\2A3DCDAF\611F5CA (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\36F1A852 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\36F1A852\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\3FA86A06 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\3FA86A06\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\4DAC9037 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\4DAC9037\611F5CA (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\4F73E13A (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\4F73E13A\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\50EF6DF6 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\50EF6DF6\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\51B9750F (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\51B9750F\611F5CA (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\6216A4BD (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\6216A4BD\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\62404B3E (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\62404B3E\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\628759C1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\628759C1\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\69E6D3E5 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\69E6D3E5\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\879169BE (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\879169BE\611F5CA (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\9B242A8C (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\9B242A8C\611F5CA (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\A26F7F7 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\A26F7F7\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\A53562F1 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\A53562F1\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\B3AC8875 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\B3AC8875\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\B75FA91E (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\B75FA91E\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\BED3DEFB (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\BED3DEFB\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\C3C6C2CD (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\C3C6C2CD\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\C41B8701 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\C41B8701\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\C90EEF64 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\C90EEF64\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\CC8FDF08 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\CC8FDF08\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\CE8732D (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\CE8732D\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\D5797E3B (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\D5797E3B\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\EB91CE86 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\EB91CE86\3E688669 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\F0A80E14 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\F0A80E14\5702F56C (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mIDEFunc.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mIDEWriteReg.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mMSI.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Application Data\SalesMon (Rogue.Multiple) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Application Data\SalesMon\Data (Rogue.Multiple) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Cache (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\chrome (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\chrome\locale (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\chrome\locale\en-US (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\components (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\searchplugins (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Skins (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\Data (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF\chrome (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF\chrome\content (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF\components (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\Data (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\FF (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\FF\chrome (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\FF\chrome\content (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\FF\components (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\System Search Dispatcher (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\System Search Dispatcher\1.3.0.840 (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\System Search Dispatcher\1.3.0.840\Data (Adware.DoubleD) -> Žádná instrukce nebyla provedena.

Nalezené soubory: 193
C:\Program Files\Application Updater\ApplicationUpdater.exe (PUP.Dealio.TB) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\HPIEAddOn.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\AIMActiveXDLL.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\NPIEAddOn.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\OEActiveXDLL.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\System Search Dispatcher\1.3.0.840\ssd.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\SSD.exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\mydll.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\productinfo.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\riched20smiley.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\stbaol.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\stbapp.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\stbdl.exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\stbie.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\stbmsn.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\stbol.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\stbolex.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\stbyahoo8.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\program files\doubled\juicyaccess toolbar\4.1.4.20920\stbyahoo9.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
C:\RECYCLER\S-1-5-21-515967899-1123561945-725345543-1003\Dc1580.exe (RiskWare.Tool.CK) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1155181.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1155182.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1155183.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\System Volume Information\_restore{B0507CBE-98B4-4B19-BF63-1FFE4D751063}\RP898\A1157462.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158010.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158011.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158013.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158014.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158015.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158017.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158022.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158023.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158024.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158026.exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158027.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158028.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158029.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158031.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158033.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158039.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158040.exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158045.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158038.exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158326.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158315.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158317.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158318.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158319.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158320.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158321.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158324.exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158325.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158327.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158328.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158329.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\system volume information\_restore{b0507cbe-98b4-4b19-bf63-1ffe4d751063}\rp898\a1158330.dll (Adware.DoubleD.Gen) -> Žádná instrukce nebyla provedena.
c:\windows\system32\00xstrmp.exe (Trojan.Downloader) -> Žádná instrukce nebyla provedena.
c:\windows\system32\wisdstr.exe (Rogue.Installer) -> Žádná instrukce nebyla provedena.
C:\4.tmp (Trojan.Agent) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\Admin\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\instance.dat (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\mia.lib (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\Setup.dat (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\Setup.msi (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\Setup.par (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\Setup.res (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\{1D975A5E-1126-4F46-A423-41781934A63E} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\{5EA804FD-5E7A-4405-A638-CAFBD22489D9} (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\24618E3F\611F5CA\Microsoft.VC80.MFC.manifest (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\2A3DCDAF\611F5CA\SkinCrafterDll.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\4DAC9037\611F5CA\gdiplus.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\62404B3E\3E688669\FFToolbar.xml (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\879169BE\611F5CA\mfc80.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\F0A80E14\5702F56C\home.juicyaccess.com.url (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\mFileBagEXE.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\AdwareSetup.exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\cfcpxlog.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\FFToolbar.xpi (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\HJSetup.exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\libiconv2.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\libintl3.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\MsiZap.Exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\msvcp60.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\ProductInfo.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\sqlite3.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\tbcore.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mFileBagIDE.dll\bag\tre4.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mIDEFunc.dll\mEXEFunc.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mIDEWriteReg.dll\mEXEWriteReg.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Documents and Settings\All Users\Data aplikací\{5EA804FD-5E7A-4405-A638-CAFBD22489D9}\OFFLINE\mMSI.dll\mMSIExec.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\gdiplus.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\mfc80.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Microsoft.VC80.MFC.manifest (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\SkinCrafterDll.dll (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Cache\01c9eb2893468d1fba80553d2b75bd30.gif (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Cache\867b44b1158783875052f103c3a2f11a.gif (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Cache\bc83ac54dd36e7479704363c8fbd7e43.gif (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Cache\c14631dd1d688aa0ae8e9c9dd396c653.gif (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Cache\default1.dat (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Cache\loading.dat (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Cache\loading.gif (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\Module_DailyVideo.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\Module_Game.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\Module_Logo.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\Module_Option.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\Module_Search.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\Module_Smiley_Config.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\Module_Smiley_TellAFriend.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\Module_Wallpaper.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\Module_Web.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\pixel.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\ProductInfo.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\profile.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\SearchEngineList.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\tbcore.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\ToolbarLayout.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\UpdateCentre.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\UpdateCentreBk.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\URLDynamic.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Data\URLStatic.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\chrome.manifest (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\install.rdf (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\chrome\JuicyAccessToolbar.jar (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\chrome\locale\en-US\global.dtd (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\components\DDAutoComplete.js (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\components\ISmileyCore.xpt (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\components\TBFFHelper.js (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\components\TBFFHelper.xpt (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\FFToolbar\searchplugins\juicyaccesssearchplugins.xml (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\About.mg (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\Component_ComboBox.mg (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\Module_DailyVideo.mg (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\Module_Game.mg (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\Module_Logo.mg (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\Module_Option.mg (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\Module_Search.mg (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\Module_Smiley.mg (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\Module_Wallpaper.mg (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\Module_Web.mg (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnDefault.png (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnDisplay.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnDisplay.png (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnDisplay18.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnDisplay20.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnGlitters.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnGlitters.png (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnGlitters18.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnGlitters20.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnOption.png (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnSmiley.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnSmiley.png (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnSmiley18.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnSmiley20.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnTellFd.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnTellFd.png (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnTellFd18.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnTellFd20.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnWink.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnWink.png (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnWink18.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Icons\TBBtnWink20.bmp (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Skins\myskin1.skf (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Skins\myskin2.skf (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Skins\myskin3.skf (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Skins\myskin4.skf (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Skins\TellafriendSkin.skf (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Skins\TellafriendSkin_s.skf (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\DoubleD\JuicyAccess Toolbar\4.1.4.20920\Skins\ToastSkin.skf (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\unins000.dat (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\unins000.exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\Data\config.md (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF\chrome.manifest (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF\install.rdf (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF\chrome\NPAddOn.jar (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF\chrome\content\NPAddOn.js (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF\chrome\content\NPAddOn.xul (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF\components\NPFFAddOn.xpt (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF\components\NPFFHelperComponent.js (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\unins000.dat (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\unins000.exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\Data\config.md (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\FF\chrome.manifest (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\FF\install.rdf (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\FF\chrome\HPAddOn.jar (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\FF\chrome\content\HPAddOn.js (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\FF\chrome\content\HPAddOn.xul (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\FF\components\HPFFAddOn.xpt (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\Media Access Startup\1.5.0.850\FF\components\HPFFHelperComponent.js (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\System Search Dispatcher\1.3.0.840\unins000.dat (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\System Search Dispatcher\1.3.0.840\unins000.exe (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\System Search Dispatcher\1.3.0.840\Data\eacore.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\System Search Dispatcher\1.3.0.840\Data\URLDynamic.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.
C:\Program Files\System Search Dispatcher\1.3.0.840\Data\URLStatic.mx (Adware.DoubleD) -> Žádná instrukce nebyla provedena.

(konec)

Re: prosím o kontrolu logu pomalé PC

Napsal: 12 úno 2012 17:05
od Márty84
V MBAM vse smazte a dejte mi sem novy log z RSIT

Re: prosím o kontrolu logu pomalé PC

Napsal: 12 úno 2012 17:37
od Oji
Logfile of random's system information tool 1.09 (written by random/random)
Run by Admin at 2012-02-12 17:28:47
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 93 GB (80%) free of 117 GB
Total RAM: 511 MB (17% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:30:03, on 12.2.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Seznam.cz\postak.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
F:\moje data\programy\antivir\RSIT.exe
C:\Program Files\trend micro\Admin.exe
C:\WINDOWS\SoftwareDistribution\Download\29355a8b161af6a381801eeacdf9aae8\update\update.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.9\pdfforgeToolbarIE.dll
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\3046\toolbaru.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.9\pdfforgeToolbarIE.dll
O2 - BHO: Lištička - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\listicka.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\3046\toolbaru.dll
O3 - Toolbar: Nástroje Lištičky - {1EA00BE1-6E54-4E2A-8099-680300BF23E1} - C:\Program Files\Seznam.cz\toolbar\toolbar.dll
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.9\pdfforgeToolbarIE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Seznam Postak] "C:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to AMV Converter... - C:\kfph\AMVConverter\grab.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\kfph\MediaManager\grab.html
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{10F3810B-5628-48A9-8BB7-D361247C4DB4}: NameServer = 192.168.150.237,194.228.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E71ECD8-B3D0-4D43-87B5-5CF22ECA1B34}: NameServer = 192.168.150.237,194.228.2.1
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 9218 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1123561945-725345543-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1123561945-725345543-1003UA.job
C:\WINDOWS\tasks\Norton Security Scan.job
C:\WINDOWS\tasks\RMSchedule.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{35BE11B1-063F-4046-8D29-C9D1A85202FD}.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\628oys85.default

prefs.js - "browser.startup.homepage" - "http://home.juicyaccess.com"
prefs.js - "extensions.enabledItems" - "{872A1C39-DF0B-4c8b-AD84-12BA24A3B781}:4.1.4.0, {0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}:1.5.0.850, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {2224E955-00E9-4613-A844-CE69FCCAAE91}:3.4.0.4340, pdfforge@mybrowserbar.com:4.9, wtxpcom@mybrowserbar.com:4.9, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10"
prefs.js - "keyword.URL" - "http://search.yahoo.com/search?fr=green ... =971163&p="

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe Flash Player 9.0
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1]
"Description"=Yahoo! activeX Plug-in Bridge
"Path"=C:\Program Files\Yahoo!\Common\npyaxmpb.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
aboutRights.js
aboutRobots.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
txEXSLTRegExFunctions.js
WebContentConverter.js

C:\Program Files\Mozilla Firefox\plugins\
flashplayer.xpt
npnul32.dll
nppdf32.dll
NPSWF32.dll
NPSWF32_FlashUtil.exe

C:\Program Files\Mozilla Firefox\searchplugins\
FFToolbar.xml
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
yahoo.xml

C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\628oys85.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}
{635abd67-4fe9-1b23-4f01-e679fa7484c1}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\4.9\pdfforgeToolbarIE.dll [2011-12-13 1071456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Lištička - C:\Program Files\Seznam.cz\listicka.dll [2010-10-07 1961240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQ Toolbar - C:\PROGRA~1\ICQTOO~1\3046\toolbaru.dll [2006-12-25 701952]
{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - Nástroje Lištičky - C:\Program Files\Seznam.cz\toolbar\toolbar.dll [2010-10-07 187672]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\4.9\pdfforgeToolbarIE.dll [2011-12-13 1071456]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-10-24 90112]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2005-11-08 128920]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2008-05-09 1817600]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-10-22 7700480]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-10-22 86016]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-02-25 77824]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2010-09-07 2838912]
""= []
"SearchSettings"=C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe [2011-12-13 922976]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2012-01-13 460872]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-07-27 133104]
"Seznam Postak"=C:\Program Files\Seznam.cz\postak.exe [2010-10-07 488728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe /s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-09-16 1961984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2006-02-25 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2004-12-20 33792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Admin^Nabídka Start^Programy^Po spuštění^hamachi.lnk]
C:\PROGRA~1\Hamachi\hamachi.exe []

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 267304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
scecli
scecli

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Rva50.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Rva50.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=255
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe"="C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:*:Enabled:Pro Evolution Soccer 2008"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:explorer"
"C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe"="C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:*:Enabled:Football Manager 2008"
"C:\Documents and Settings\Admin\Plocha\Skype.exe"="C:\Documents and Settings\Admin\Plocha\Skype.exe:*:Enabled:Skype"
"C:\Program Files\BitLord\BitLord.exe"="C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP62"=vp6vfw.dll
"msacm.vorbis"=vorbis.acm
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"midi3"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-02-12 17:28:37 ----D---- C:\WINDOWS\LastGood
2012-02-12 17:26:10 ----A---- C:\WINDOWS\OEWABLog.txt
2012-02-12 17:23:31 ----D---- C:\WINDOWS\Prefetch
2012-02-12 12:43:29 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2012-02-12 12:42:24 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2012-02-12 12:41:35 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2012-02-12 12:37:53 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2012-02-12 12:37:29 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2012-02-12 12:37:13 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2012-02-12 12:36:56 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2012-02-12 12:36:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2012-02-12 12:36:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2012-02-12 12:35:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2012-02-12 12:35:40 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2012-02-12 12:35:22 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2012-02-12 12:34:57 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2012-02-12 12:34:41 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2012-02-12 12:34:24 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2012-02-12 12:33:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2012-02-12 12:33:38 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2012-02-12 12:33:22 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2012-02-12 12:33:06 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2012-02-12 12:32:48 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2012-02-12 12:32:26 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2012-02-12 12:32:08 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2012-02-12 12:31:51 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2012-02-12 12:31:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2012-02-12 12:31:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2012-02-12 12:30:38 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2012-02-12 12:30:16 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2012-02-12 12:29:51 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2012-02-12 12:29:22 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2012-02-12 12:29:04 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2012-02-12 12:28:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2012-02-12 12:28:31 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2012-02-12 12:28:13 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2012-02-12 12:27:54 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2012-02-12 12:27:39 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2012-02-12 12:27:21 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2012-02-12 12:27:01 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2012-02-12 12:26:35 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2012-02-12 12:25:13 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2012-02-12 12:24:46 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2012-02-12 12:24:27 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2012-02-12 12:23:30 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$
2012-02-12 12:22:07 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2012-02-12 12:21:51 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2012-02-12 12:21:31 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2012-02-12 12:21:06 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2012-02-12 12:20:49 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2012-02-12 12:20:29 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2012-02-12 12:20:07 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2012-02-12 12:19:50 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2012-02-12 12:19:30 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2012-02-12 12:19:15 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2012-02-12 12:18:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2012-02-12 12:18:16 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2012-02-12 12:17:37 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2012-02-12 12:16:40 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2012-02-12 12:14:18 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2012-02-12 12:13:44 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2012-02-12 12:13:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2012-02-12 12:13:08 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2012-02-12 12:12:56 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_1$
2012-02-12 12:12:45 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2012-02-12 12:12:34 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2012-02-12 12:12:13 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2012-02-12 12:12:02 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2012-02-12 12:11:48 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2012-02-12 12:11:35 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2012-02-12 12:11:15 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2012-02-12 12:11:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2012-02-12 12:10:39 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2012-02-12 12:10:24 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2012-02-12 12:10:06 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2012-02-12 12:09:46 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2012-02-12 12:09:26 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2012-02-12 12:09:10 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2012-02-12 12:08:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2012-02-12 12:08:19 ----D---- C:\WINDOWS\LastGood.Tmp
2012-02-12 12:02:44 ----A---- C:\WINDOWS\setuplog.txt
2012-02-12 11:18:14 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2012-02-12 11:14:58 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2012-02-12 11:14:56 ----D---- C:\Documents and Settings\Admin\Data aplikací\Malwarebytes
2012-02-12 11:12:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2012-02-12 11:11:59 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2012-02-12 11:11:57 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-02-12 10:06:45 ----D---- C:\Program Files\trend micro
2012-02-12 10:06:39 ----D---- C:\rsit
2012-02-12 10:03:04 ----D---- C:\Program Files\Yahoo!
2012-02-12 10:00:35 ----D---- C:\Program Files\CCleaner
2012-02-12 09:48:16 ----A---- C:\WINDOWS\system32\wpa.bak
2012-02-11 12:23:33 ----D---- C:\WINDOWSL
2012-02-11 12:23:33 ----ASH---- C:\pagefile.sys
2012-02-11 12:03:01 ----ASH---- C:\hiberfil.sys
2012-02-11 11:54:44 ----A---- C:\AUTOEXEC.BAT
2012-01-19 17:57:00 ----A---- C:\WINDOWS\ALIK.INI

======List of files/folders modified in the last 1 month======

2012-02-12 17:30:08 ----HD---- C:\WINDOWS\inf
2012-02-12 17:30:00 ----HD---- C:\WINDOWS\$hf_mig$
2012-02-12 17:29:57 ----D---- C:\WINDOWS
2012-02-12 17:27:20 ----D---- C:\WINDOWS\system32
2012-02-12 17:27:13 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-02-12 17:27:09 ----AC---- C:\WINDOWS\wincmd.ini
2012-02-12 17:26:51 ----D---- C:\WINDOWS\TEMP
2012-02-12 17:25:22 ----D---- C:\WINDOWS\Debug
2012-02-12 17:24:26 ----D---- C:\WINDOWS\system32\CatRoot2
2012-02-12 17:22:24 ----D---- C:\WINDOWS\system32\Setup
2012-02-12 17:22:24 ----D---- C:\WINDOWS\AppPatch
2012-02-12 17:22:23 ----D---- C:\WINDOWS\system32\wbem
2012-02-12 17:22:22 ----RSD---- C:\WINDOWS\Fonts
2012-02-12 17:22:13 ----D---- C:\WINDOWS\system32\drivers
2012-02-12 17:21:22 ----D---- C:\WINDOWS\security
2012-02-12 17:21:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-02-12 17:19:35 ----D---- C:\WINDOWS\WinSxS
2012-02-12 17:18:42 ----RD---- C:\Program Files
2012-02-12 12:44:20 ----D---- C:\WINDOWS\system32\CatRoot
2012-02-12 12:43:32 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-02-12 12:36:24 ----D---- C:\Program Files\Outlook Express
2012-02-12 12:34:27 ----D---- C:\Program Files\Movie Maker
2012-02-12 12:09:49 ----D---- C:\Program Files\Messenger
2012-02-12 11:56:59 ----D---- C:\WINDOWS\ehome
2012-02-12 11:56:52 ----D---- C:\WINDOWS\system32\inetsrv
2012-02-12 11:56:51 ----D---- C:\WINDOWS\network diagnostic
2012-02-12 11:56:51 ----D---- C:\WINDOWS\ime
2012-02-12 11:56:50 ----D---- C:\WINDOWS\Help
2012-02-12 11:55:52 ----D---- C:\WINDOWS\system32\cs-cz
2012-02-12 11:55:50 ----D---- C:\WINDOWS\system32\usmt
2012-02-12 11:55:45 ----D---- C:\WINDOWS\l2schemas
2012-02-12 11:55:40 ----D---- C:\WINDOWS\system32\cs
2012-02-12 11:55:39 ----D---- C:\WINDOWS\system32\bits
2012-02-12 11:55:39 ----D---- C:\WINDOWS\PeerNet
2012-02-12 11:47:55 ----D---- C:\WINDOWS\ServicePackFiles
2012-02-12 11:47:29 ----D---- C:\WINDOWS\system32\Restore
2012-02-12 11:47:29 ----D---- C:\WINDOWS\system32\npp
2012-02-12 11:47:22 ----D---- C:\WINDOWS\msagent
2012-02-12 11:47:10 ----D---- C:\WINDOWS\srchasst
2012-02-12 11:46:59 ----D---- C:\WINDOWS\system32\Com
2012-02-12 11:44:18 ----D---- C:\Program Files\Mozilla Firefox
2012-02-12 11:43:42 ----D---- C:\WINDOWS\system32\oobe
2012-02-12 11:43:36 ----D---- C:\WINDOWS\system
2012-02-12 11:31:35 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-02-12 11:01:45 ----D---- C:\Documents and Settings\Admin\Data aplikací\Spyware Terminator
2012-02-12 10:28:42 ----D---- C:\Program Files\Google
2012-02-12 10:28:29 ----SHD---- C:\WINDOWS\Installer
2012-02-12 10:26:01 ----D---- C:\Program Files\Internet Explorer
2012-02-12 10:23:10 ----HDC---- C:\WINDOWS\ie8
2012-02-12 10:09:04 ----SH---- C:\boot.ini
2012-02-12 10:09:04 ----A---- C:\WINDOWS\win.ini
2012-02-12 10:09:04 ----A---- C:\WINDOWS\system.ini
2012-02-12 09:53:30 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2012-02-11 12:03:30 ----SHD---- C:\Config.Msi
2012-02-11 12:03:03 ----D---- C:\Documents and Settings
2012-02-11 12:00:28 ----SHD---- C:\System Volume Information
2012-02-11 11:51:30 ----D---- C:\Program Files\Windows Media Player
2012-02-11 11:51:08 ----D---- C:\Program Files\NetMeeting
2012-02-11 11:51:06 ----D---- C:\Program Files\Common Files\System
2012-02-11 11:48:56 ----D---- C:\Program Files\Windows NT
2012-01-20 16:42:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\system32\DRIVERS\PxHelp20.sys [2004-12-20 20016]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2005-12-11 664064]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-13 44672]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-09-07 28880]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-09-07 100176]
R2 MaVctrl;MaVctrl; C:\WINDOWS\system32\DRIVERS\MaVc2K.sys [2004-08-23 11089]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2002-09-23 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2002-09-23 55936]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-09-07 23376]
R3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2006-05-21 223128]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-10-22 3994624]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\viaudios.sys [2004-03-17 117248]
S0 viamraid;viamraid; C:\WINDOWS\system32\DRIVERS\viamraid.sys [2004-07-06 60672]
S2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-10-26 3786944]
S3 cmpci;C-Media PCI Audio Driver (WDM); C:\WINDOWS\system32\drivers\cmaudio.sys [2002-11-18 377358]
S3 cwrwdm;Ovladač SoundFusion(tm) WDM; C:\WINDOWS\system32\DRIVERS\cwrwdm.sys [2004-08-03 48640]
S3 Edspport;EDSP Port Driver; C:\WINDOWS\system32\DRIVERS\es56hpi.sys [2001-10-24 594238]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-01-17 25280]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:\WINDOWS\system32\DRIVERS\k750bus.sys [2005-07-07 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\k750mdfl.sys [2005-07-07 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:\WINDOWS\system32\DRIVERS\k750mdm.sys [2005-07-07 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:\WINDOWS\system32\DRIVERS\k750mgmt.sys [2005-07-07 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:\WINDOWS\system32\DRIVERS\k750obex.sys [2005-07-07 79488]
S3 MaRdPnp;MaRdPnp; C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys [2004-09-13 49611]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-13 163584]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-10-22 159810]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2010-08-05 583640]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-04-22 66872]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2008-05-09 606720]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
S2 NWCWorkstation;Klient systému NetWare; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: prosím o kontrolu logu pomalé PC

Napsal: 12 úno 2012 18:38
od Márty84
:arrow: Jen pro jistotu, najdete v pc tento soubor C:\WINDOWS\SoftwareDistribution\Download\29355a8b161af6a381801eeacdf9aae8\update\update.exe a otestujte ho na virustotal, pripadne jotti, podle tohoto navodu http://forum.viry.cz/viewtopic.php?t=5846



:arrow: Stahnete OTM http://oldtimer.geekstogo.com/OTM.exe , ulozte nejlepe na plochu a spustte
Do leveho okna zkopirujte tento skript

Kód: Vybrat vše

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1123561945-725345543-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1123561945-725345543-1003UA.job
C:\WINDOWS\tasks\Norton Security Scan.job
C:\WINDOWS\tasks\RMSchedule.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{35BE11B1-063F-4046-8D29-C9D1A85202FD}.job
C:\Program Files\AntivirusPro_2010
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk

:reg
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
"{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-
"{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=-
"QuickTime Task"=-
""=-
"Malwarebytes' Anti-Malware"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

:commands
[ClearAllRestorePoints]
[RESETHOSTS]
[Purity]
[EMPTYTEMP]
[EMPTYFLASH]
Kliknete na MoveIt a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu sem dejte log, ktery bude zde C:\_OTM\MovedFiles\

Re: prosím o kontrolu logu pomalé PC

Napsal: 12 úno 2012 19:08
od Oji
C:\WINDOWS\SoftwareDistribution\Download\29355a8b161af6a381801eeacdf9aae8\update\update.exe
Tohle nemohu najít měl jsem tam ale flesku ale ta už je ted zformátovaná

Re: prosím o kontrolu logu pomalé PC

Napsal: 12 úno 2012 19:13
od Márty84
OK, pokracujte s OTM

Re: prosím o kontrolu logu pomalé PC

Napsal: 12 úno 2012 20:15
od Oji
All processes killed
========== FILES ==========
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004469_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004470_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004471_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004472_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004479_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004480_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004481_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004482_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004483_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004484_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004485_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004486_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004487_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004488_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004489_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004490_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004491_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004492_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004493_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004495_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004498_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004503_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004504_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004505_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004506_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004507_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004508_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004509_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004511_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004512_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004513_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004514_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004515_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004516_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004517_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004518_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004519_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004520_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004521_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004522_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004525_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004526_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004527_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004529_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004530_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004531_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004533_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004536_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004537_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004541_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004542_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004544_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004547_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004549_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004550_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004551_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004552_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004555_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004556_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004557_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004558_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004559_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004564_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004710_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004711_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004712_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004713_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004720_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004721_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004722_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\_004724_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004725_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004728_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004729_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004731_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004732_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004733_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004735_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004738_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004739_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004743_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004744_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004746_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004749_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004751_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004752_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004753_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004754_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004757_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004758_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004759_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004760_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004761_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004766_.tmp.dll
LoadLibrary failed for C:\WINDOWS\system32\_004768_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\drivers\_004447_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\drivers\_004458_.tmp.dll
DllUnregisterServer procedure not found in C:\WINDOWS\system32\drivers\_004688_.tmp.dll
C:\WINDOWS\system32\_004469_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004470_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004471_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004472_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004479_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004480_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004481_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004482_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004483_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004484_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004485_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004486_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004487_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004488_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004489_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004490_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004491_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004492_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004493_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004495_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004498_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004499_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004503_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004504_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004505_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004506_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004507_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004508_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004509_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004511_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004512_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004513_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004514_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004515_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004516_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004517_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004518_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004519_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004520_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004521_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004522_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004525_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004526_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004527_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004529_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004530_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004531_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004533_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004536_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004537_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004541_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004542_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004544_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004547_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004549_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004550_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004551_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004552_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004555_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004556_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004557_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004558_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004559_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004564_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004710_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004711_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004712_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004713_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004720_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004721_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004722_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004724_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004725_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004728_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004729_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004731_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004732_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004733_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004735_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004738_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004739_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004743_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004744_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004746_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004749_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004751_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004752_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004753_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004754_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004757_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004758_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004759_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004760_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004761_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004766_.tmp.dll moved successfully.
C:\WINDOWS\system32\_004768_.tmp.dll moved successfully.
C:\WINDOWS\system32\drivers\_004447_.tmp.dll moved successfully.
C:\WINDOWS\system32\drivers\_004458_.tmp.dll moved successfully.
C:\WINDOWS\system32\drivers\_004688_.tmp.dll moved successfully.
C:\WINDOWS\system32\SET1300.tmp moved successfully.
C:\WINDOWS\system32\SET1303.tmp moved successfully.
C:\WINDOWS\system32\SET1308.tmp moved successfully.
C:\WINDOWS\system32\SET1316.tmp moved successfully.
C:\WINDOWS\system32\SET1455.tmp moved successfully.
C:\WINDOWS\system32\SET1458.tmp moved successfully.
C:\WINDOWS\system32\SET145D.tmp moved successfully.
C:\WINDOWS\system32\SET146B.tmp moved successfully.
C:\WINDOWS\system32\SET15D9.tmp moved successfully.
C:\WINDOWS\system32\SET15DC.tmp moved successfully.
C:\WINDOWS\system32\SET15E1.tmp moved successfully.
C:\WINDOWS\system32\SET15EF.tmp moved successfully.
C:\WINDOWS\system32\SET2D6.tmp moved successfully.
C:\WINDOWS\system32\SET313.tmp moved successfully.
C:\WINDOWS\system32\SET314.tmp moved successfully.
C:\WINDOWS\system32\SET316.tmp moved successfully.
C:\WINDOWS\system32\SET318.tmp moved successfully.
C:\WINDOWS\system32\SET31A.tmp moved successfully.
C:\WINDOWS\system32\SET321.tmp moved successfully.
C:\WINDOWS\system32\SET322.tmp moved successfully.
C:\WINDOWS\system32\SET325.tmp moved successfully.
C:\WINDOWS\system32\SET32A.tmp moved successfully.
C:\WINDOWS\system32\SET32B.tmp moved successfully.
C:\WINDOWS\system32\SET32C.tmp moved successfully.
C:\WINDOWS\system32\SET32E.tmp moved successfully.
C:\WINDOWS\system32\SET32F.tmp moved successfully.
C:\WINDOWS\system32\SET330.tmp moved successfully.
C:\WINDOWS\system32\SET331.tmp moved successfully.
C:\WINDOWS\system32\SET332.tmp moved successfully.
C:\WINDOWS\system32\SET334.tmp moved successfully.
C:\WINDOWS\system32\SET335.tmp moved successfully.
C:\WINDOWS\system32\SET336.tmp moved successfully.
C:\WINDOWS\system32\SET337.tmp moved successfully.
C:\WINDOWS\system32\SET341.tmp moved successfully.
C:\WINDOWS\system32\SET342.tmp moved successfully.
C:\WINDOWS\system32\SET343.tmp moved successfully.
C:\WINDOWS\system32\SET344.tmp moved successfully.
C:\WINDOWS\system32\SET347.tmp moved successfully.
C:\WINDOWS\system32\SET349.tmp moved successfully.
C:\WINDOWS\system32\SET34A.tmp moved successfully.
C:\WINDOWS\system32\SET351.tmp moved successfully.
C:\WINDOWS\system32\SET354.tmp moved successfully.
C:\WINDOWS\system32\SET355.tmp moved successfully.
C:\WINDOWS\system32\SET357.tmp moved successfully.
C:\WINDOWS\system32\SET358.tmp moved successfully.
C:\WINDOWS\system32\SET359.tmp moved successfully.
C:\WINDOWS\system32\SET35E.tmp moved successfully.
C:\WINDOWS\system32\SET35F.tmp moved successfully.
C:\WINDOWS\system32\SET360.tmp moved successfully.
C:\WINDOWS\system32\SET361.tmp moved successfully.
C:\WINDOWS\system32\SET362.tmp moved successfully.
C:\WINDOWS\system32\SET368.tmp moved successfully.
C:\WINDOWS\system32\SET36D.tmp moved successfully.
C:\WINDOWS\system32\SET36E.tmp moved successfully.
C:\WINDOWS\system32\SET372.tmp moved successfully.
C:\WINDOWS\system32\SET375.tmp moved successfully.
C:\WINDOWS\system32\SET376.tmp moved successfully.
C:\WINDOWS\system32\SET37D.tmp moved successfully.
C:\WINDOWS\system32\SET37E.tmp moved successfully.
C:\WINDOWS\system32\SET380.tmp moved successfully.
C:\WINDOWS\system32\SET384.tmp moved successfully.
C:\WINDOWS\system32\SET38D.tmp moved successfully.
C:\WINDOWS\system32\SET38E.tmp moved successfully.
C:\WINDOWS\system32\SET391.tmp moved successfully.
C:\WINDOWS\system32\SET393.tmp moved successfully.
C:\WINDOWS\system32\SET394.tmp moved successfully.
C:\WINDOWS\system32\SET395.tmp moved successfully.
C:\WINDOWS\system32\SET396.tmp moved successfully.
C:\WINDOWS\system32\SET397.tmp moved successfully.
C:\WINDOWS\system32\SET3A7.tmp moved successfully.
C:\WINDOWS\system32\SET3AC.tmp moved successfully.
C:\WINDOWS\system32\SET3AE.tmp moved successfully.
C:\WINDOWS\system32\SET3B0.tmp moved successfully.
C:\WINDOWS\system32\SET3B1.tmp moved successfully.
C:\WINDOWS\system32\SET3B2.tmp moved successfully.
C:\WINDOWS\system32\SET3B3.tmp moved successfully.
C:\WINDOWS\system32\SET3B5.tmp moved successfully.
C:\WINDOWS\system32\SET3B6.tmp moved successfully.
C:\WINDOWS\system32\SET3BA.tmp moved successfully.
C:\WINDOWS\system32\SET3BB.tmp moved successfully.
C:\WINDOWS\system32\SET3BC.tmp moved successfully.
C:\WINDOWS\system32\SET3BD.tmp moved successfully.
C:\WINDOWS\system32\SET3BE.tmp moved successfully.
C:\WINDOWS\system32\SET3BF.tmp moved successfully.
C:\WINDOWS\system32\SET3C0.tmp moved successfully.
C:\WINDOWS\system32\SET3C2.tmp moved successfully.
C:\WINDOWS\system32\SET3C4.tmp moved successfully.
C:\WINDOWS\system32\SET3C6.tmp moved successfully.
C:\WINDOWS\system32\SET3C7.tmp moved successfully.
C:\WINDOWS\system32\SET3C8.tmp moved successfully.
C:\WINDOWS\system32\SET3C9.tmp moved successfully.
C:\WINDOWS\system32\SET3CF.tmp moved successfully.
C:\WINDOWS\system32\SET3D0.tmp moved successfully.
C:\WINDOWS\system32\SET3D2.tmp moved successfully.
C:\WINDOWS\system32\SET3D3.tmp moved successfully.
C:\WINDOWS\system32\SET3D6.tmp moved successfully.
C:\WINDOWS\system32\SET3D7.tmp moved successfully.
C:\WINDOWS\system32\SET3D8.tmp moved successfully.
C:\WINDOWS\system32\SET3D9.tmp moved successfully.
C:\WINDOWS\system32\SET3DA.tmp moved successfully.
C:\WINDOWS\system32\SET3DB.tmp moved successfully.
C:\WINDOWS\system32\SET3E0.tmp moved successfully.
C:\WINDOWS\system32\SET3E1.tmp moved successfully.
C:\WINDOWS\system32\SET3E2.tmp moved successfully.
C:\WINDOWS\system32\SET3E3.tmp moved successfully.
C:\WINDOWS\system32\SET3E4.tmp moved successfully.
C:\WINDOWS\system32\SET3E6.tmp moved successfully.
C:\WINDOWS\system32\SET3E7.tmp moved successfully.
C:\WINDOWS\system32\SET3E8.tmp moved successfully.
C:\WINDOWS\system32\SET3E9.tmp moved successfully.
C:\WINDOWS\system32\SET3EA.tmp moved successfully.
C:\WINDOWS\system32\SET3EC.tmp moved successfully.
C:\WINDOWS\system32\SET3ED.tmp moved successfully.
C:\WINDOWS\system32\SET3EE.tmp moved successfully.
C:\WINDOWS\system32\SET3EF.tmp moved successfully.
C:\WINDOWS\system32\SET3F0.tmp moved successfully.
C:\WINDOWS\system32\SET3F1.tmp moved successfully.
C:\WINDOWS\system32\SET3F2.tmp moved successfully.
C:\WINDOWS\system32\SET3F3.tmp moved successfully.
C:\WINDOWS\system32\SET3F4.tmp moved successfully.
C:\WINDOWS\system32\SET3FE.tmp moved successfully.
C:\WINDOWS\system32\SET3FF.tmp moved successfully.
C:\WINDOWS\system32\SET400.tmp moved successfully.
C:\WINDOWS\system32\SET401.tmp moved successfully.
C:\WINDOWS\system32\SET402.tmp moved successfully.
C:\WINDOWS\system32\SET403.tmp moved successfully.
C:\WINDOWS\system32\SET404.tmp moved successfully.
C:\WINDOWS\system32\SET405.tmp moved successfully.
C:\WINDOWS\system32\SET406.tmp moved successfully.
C:\WINDOWS\system32\SET409.tmp moved successfully.
C:\WINDOWS\system32\SET40A.tmp moved successfully.
C:\WINDOWS\system32\SET40B.tmp moved successfully.
C:\WINDOWS\system32\SET40D.tmp moved successfully.
C:\WINDOWS\system32\SET40E.tmp moved successfully.
C:\WINDOWS\system32\SET40F.tmp moved successfully.
C:\WINDOWS\system32\SET413.tmp moved successfully.
C:\WINDOWS\system32\SET416.tmp moved successfully.
C:\WINDOWS\system32\SET419.tmp moved successfully.
C:\WINDOWS\system32\SET41A.tmp moved successfully.
C:\WINDOWS\system32\SET41C.tmp moved successfully.
C:\WINDOWS\system32\SET41D.tmp moved successfully.
C:\WINDOWS\system32\SET41E.tmp moved successfully.
C:\WINDOWS\system32\SET41F.tmp moved successfully.
C:\WINDOWS\system32\SET420.tmp moved successfully.
C:\WINDOWS\system32\SET424.tmp moved successfully.
C:\WINDOWS\system32\SET425.tmp moved successfully.
C:\WINDOWS\system32\SET427.tmp moved successfully.
C:\WINDOWS\system32\SET428.tmp moved successfully.
C:\WINDOWS\system32\SET429.tmp moved successfully.
C:\WINDOWS\system32\SET42A.tmp moved successfully.
C:\WINDOWS\system32\SET42B.tmp moved successfully.
C:\WINDOWS\system32\SET42C.tmp moved successfully.
C:\WINDOWS\system32\SET42D.tmp moved successfully.
C:\WINDOWS\system32\SET42E.tmp moved successfully.
C:\WINDOWS\system32\SET42F.tmp moved successfully.
C:\WINDOWS\system32\SET430.tmp moved successfully.
C:\WINDOWS\system32\SET431.tmp moved successfully.
C:\WINDOWS\system32\SET432.tmp moved successfully.
C:\WINDOWS\system32\SET433.tmp moved successfully.
C:\WINDOWS\system32\SET434.tmp moved successfully.
C:\WINDOWS\system32\SET435.tmp moved successfully.
C:\WINDOWS\system32\SET436.tmp moved successfully.
C:\WINDOWS\system32\SET437.tmp moved successfully.
C:\WINDOWS\system32\SET43A.tmp moved successfully.
C:\WINDOWS\system32\SET43E.tmp moved successfully.
C:\WINDOWS\system32\SET43F.tmp moved successfully.
C:\WINDOWS\system32\SET440.tmp moved successfully.
C:\WINDOWS\system32\SET441.tmp moved successfully.
C:\WINDOWS\system32\SET446.tmp moved successfully.
C:\WINDOWS\system32\SET447.tmp moved successfully.
C:\WINDOWS\system32\SET448.tmp moved successfully.
C:\WINDOWS\system32\SET449.tmp moved successfully.
C:\WINDOWS\system32\SET44A.tmp moved successfully.
C:\WINDOWS\system32\SET44B.tmp moved successfully.
C:\WINDOWS\system32\SET44D.tmp moved successfully.
C:\WINDOWS\system32\SET44F.tmp moved successfully.
C:\WINDOWS\system32\SET450.tmp moved successfully.
C:\WINDOWS\system32\SET452.tmp moved successfully.
C:\WINDOWS\system32\SET453.tmp moved successfully.
C:\WINDOWS\system32\SET454.tmp moved successfully.
C:\WINDOWS\system32\SET457.tmp moved successfully.
C:\WINDOWS\system32\SET458.tmp moved successfully.
C:\WINDOWS\system32\SET459.tmp moved successfully.
C:\WINDOWS\system32\SET45A.tmp moved successfully.
C:\WINDOWS\system32\SET45B.tmp moved successfully.
C:\WINDOWS\system32\SET462.tmp moved successfully.
C:\WINDOWS\system32\SET463.tmp moved successfully.
C:\WINDOWS\system32\SET464.tmp moved successfully.
C:\WINDOWS\system32\SET466.tmp moved successfully.
C:\WINDOWS\system32\SET467.tmp moved successfully.
C:\WINDOWS\system32\SET46A.tmp moved successfully.
C:\WINDOWS\system32\SET46C.tmp moved successfully.
C:\WINDOWS\system32\SET46D.tmp moved successfully.
C:\WINDOWS\system32\SET46E.tmp moved successfully.
C:\WINDOWS\system32\SET470.tmp moved successfully.
C:\WINDOWS\system32\SET471.tmp moved successfully.
C:\WINDOWS\system32\SET479.tmp moved successfully.
C:\WINDOWS\system32\SET47A.tmp moved successfully.
C:\WINDOWS\system32\SET47B.tmp moved successfully.
C:\WINDOWS\system32\SET47C.tmp moved successfully.
C:\WINDOWS\system32\SET47D.tmp moved successfully.
C:\WINDOWS\system32\SET47E.tmp moved successfully.
C:\WINDOWS\system32\SET481.tmp moved successfully.
C:\WINDOWS\system32\SET483.tmp moved successfully.
C:\WINDOWS\system32\SET484.tmp moved successfully.
C:\WINDOWS\system32\SET485.tmp moved successfully.
C:\WINDOWS\system32\SET486.tmp moved successfully.
C:\WINDOWS\system32\SET487.tmp moved successfully.
C:\WINDOWS\system32\SET488.tmp moved successfully.
C:\WINDOWS\system32\SET489.tmp moved successfully.
C:\WINDOWS\system32\SET48A.tmp moved successfully.
C:\WINDOWS\system32\SET48B.tmp moved successfully.
C:\WINDOWS\system32\SET48C.tmp moved successfully.
C:\WINDOWS\system32\SET48D.tmp moved successfully.
C:\WINDOWS\system32\SET48E.tmp moved successfully.
C:\WINDOWS\system32\SET48F.tmp moved successfully.
C:\WINDOWS\system32\SET490.tmp moved successfully.
C:\WINDOWS\system32\SET491.tmp moved successfully.
C:\WINDOWS\system32\SET492.tmp moved successfully.
C:\WINDOWS\system32\SET495.tmp moved successfully.
C:\WINDOWS\system32\SET49F.tmp moved successfully.
C:\WINDOWS\system32\SET4A1.tmp moved successfully.
C:\WINDOWS\system32\SET4A2.tmp moved successfully.
C:\WINDOWS\system32\SET4A3.tmp moved successfully.
C:\WINDOWS\system32\SET4A7.tmp moved successfully.
C:\WINDOWS\system32\SET4A8.tmp moved successfully.
C:\WINDOWS\system32\SET4AC.tmp moved successfully.
C:\WINDOWS\system32\SET4AE.tmp moved successfully.
C:\WINDOWS\system32\SET4AF.tmp moved successfully.
C:\WINDOWS\system32\SET4B0.tmp moved successfully.
C:\WINDOWS\system32\SET4B2.tmp moved successfully.
C:\WINDOWS\system32\SET4B4.tmp moved successfully.
C:\WINDOWS\system32\SET4B5.tmp moved successfully.
C:\WINDOWS\system32\SET4B6.tmp moved successfully.
C:\WINDOWS\system32\SET4B7.tmp moved successfully.
C:\WINDOWS\system32\SET4B8.tmp moved successfully.
C:\WINDOWS\system32\SET4BA.tmp moved successfully.
C:\WINDOWS\system32\SET4BB.tmp moved successfully.
C:\WINDOWS\system32\SET4BF.tmp moved successfully.
C:\WINDOWS\system32\SET4C0.tmp moved successfully.
C:\WINDOWS\system32\SET4C1.tmp moved successfully.
C:\WINDOWS\system32\SET4C4.tmp moved successfully.
C:\WINDOWS\system32\SET4C5.tmp moved successfully.
C:\WINDOWS\system32\SET4C6.tmp moved successfully.
C:\WINDOWS\system32\SET4C7.tmp moved successfully.
C:\WINDOWS\system32\SET4C8.tmp moved successfully.
C:\WINDOWS\system32\SET4C9.tmp moved successfully.
C:\WINDOWS\system32\SET4CA.tmp moved successfully.
C:\WINDOWS\system32\SET4D0.tmp moved successfully.
C:\WINDOWS\system32\SET4D1.tmp moved successfully.
C:\WINDOWS\system32\SET4D2.tmp moved successfully.
C:\WINDOWS\system32\SET4D3.tmp moved successfully.
C:\WINDOWS\system32\SET4D8.tmp moved successfully.
C:\WINDOWS\system32\SET4DA.tmp moved successfully.
C:\WINDOWS\system32\SET4DC.tmp moved successfully.
C:\WINDOWS\system32\SET4DD.tmp moved successfully.
C:\WINDOWS\system32\SET4E1.tmp moved successfully.
C:\WINDOWS\system32\SET4E3.tmp moved successfully.
C:\WINDOWS\system32\SET4E5.tmp moved successfully.
C:\WINDOWS\system32\SET4E6.tmp moved successfully.
C:\WINDOWS\system32\SET4E7.tmp moved successfully.
C:\WINDOWS\system32\SET4E8.tmp moved successfully.
C:\WINDOWS\system32\SET4E9.tmp moved successfully.
C:\WINDOWS\system32\SET4EB.tmp moved successfully.
C:\WINDOWS\system32\SET4F0.tmp moved successfully.
C:\WINDOWS\system32\SET4F1.tmp moved successfully.
C:\WINDOWS\system32\SET4F6.tmp moved successfully.
C:\WINDOWS\system32\SET4FA.tmp moved successfully.
C:\WINDOWS\system32\SET4FC.tmp moved successfully.
C:\WINDOWS\system32\SET4FE.tmp moved successfully.
C:\WINDOWS\system32\SET501.tmp moved successfully.
C:\WINDOWS\system32\SET503.tmp moved successfully.
C:\WINDOWS\system32\SET505.tmp moved successfully.
C:\WINDOWS\system32\SET506.tmp moved successfully.
C:\WINDOWS\system32\SET507.tmp moved successfully.
C:\WINDOWS\system32\SET508.tmp moved successfully.
C:\WINDOWS\system32\SET50A.tmp moved successfully.
C:\WINDOWS\system32\SET50B.tmp moved successfully.
C:\WINDOWS\system32\SET513.tmp moved successfully.
C:\WINDOWS\system32\SET514.tmp moved successfully.
C:\WINDOWS\system32\SET515.tmp moved successfully.
C:\WINDOWS\system32\SET517.tmp moved successfully.
C:\WINDOWS\system32\SET518.tmp moved successfully.
C:\WINDOWS\system32\SET519.tmp moved successfully.
C:\WINDOWS\system32\SET51B.tmp moved successfully.
C:\WINDOWS\system32\SET51C.tmp moved successfully.
C:\WINDOWS\system32\SET51D.tmp moved successfully.
C:\WINDOWS\system32\SET51F.tmp moved successfully.
C:\WINDOWS\system32\SET520.tmp moved successfully.
C:\WINDOWS\system32\SET521.tmp moved successfully.
C:\WINDOWS\system32\SET522.tmp moved successfully.
C:\WINDOWS\system32\SET526.tmp moved successfully.
C:\WINDOWS\system32\SET528.tmp moved successfully.
C:\WINDOWS\system32\SET529.tmp moved successfully.
C:\WINDOWS\system32\SET52A.tmp moved successfully.
C:\WINDOWS\system32\SET52D.tmp moved successfully.
C:\WINDOWS\system32\SET52E.tmp moved successfully.
C:\WINDOWS\system32\SET52F.tmp moved successfully.
C:\WINDOWS\system32\SET532.tmp moved successfully.
C:\WINDOWS\system32\SET533.tmp moved successfully.
C:\WINDOWS\system32\SET538.tmp moved successfully.
C:\WINDOWS\system32\SET539.tmp moved successfully.
C:\WINDOWS\system32\SET53A.tmp moved successfully.
C:\WINDOWS\system32\SET53B.tmp moved successfully.
C:\WINDOWS\system32\SET53C.tmp moved successfully.
C:\WINDOWS\system32\SET53E.tmp moved successfully.
C:\WINDOWS\system32\SET53F.tmp moved successfully.
C:\WINDOWS\system32\SET540.tmp moved successfully.
C:\WINDOWS\system32\SET541.tmp moved successfully.
C:\WINDOWS\system32\SET542.tmp moved successfully.
C:\WINDOWS\system32\SET543.tmp moved successfully.
C:\WINDOWS\system32\SET544.tmp moved successfully.
C:\WINDOWS\system32\SET545.tmp moved successfully.
C:\WINDOWS\system32\SET546.tmp moved successfully.
C:\WINDOWS\system32\SET547.tmp moved successfully.
C:\WINDOWS\system32\SET548.tmp moved successfully.
C:\WINDOWS\system32\SET549.tmp moved successfully.
C:\WINDOWS\system32\SET54A.tmp moved successfully.
C:\WINDOWS\system32\SET54B.tmp moved successfully.
C:\WINDOWS\system32\SET54C.tmp moved successfully.
C:\WINDOWS\system32\SET54D.tmp moved successfully.
C:\WINDOWS\system32\SET54E.tmp moved successfully.
C:\WINDOWS\system32\SET54F.tmp moved successfully.
C:\WINDOWS\system32\SET550.tmp moved successfully.
C:\WINDOWS\system32\SET552.tmp moved successfully.
C:\WINDOWS\system32\SET553.tmp moved successfully.
C:\WINDOWS\system32\SET554.tmp moved successfully.
C:\WINDOWS\system32\SET555.tmp moved successfully.
C:\WINDOWS\system32\SET556.tmp moved successfully.
C:\WINDOWS\system32\SET557.tmp moved successfully.
C:\WINDOWS\system32\SET558.tmp moved successfully.
C:\WINDOWS\system32\SET559.tmp moved successfully.
C:\WINDOWS\system32\SET55A.tmp moved successfully.
C:\WINDOWS\system32\SET55B.tmp moved successfully.
C:\WINDOWS\system32\SET55C.tmp moved successfully.
C:\WINDOWS\system32\SET55D.tmp moved successfully.
C:\WINDOWS\system32\SET55E.tmp moved successfully.
C:\WINDOWS\system32\SET560.tmp moved successfully.
C:\WINDOWS\system32\SET565.tmp moved successfully.
C:\WINDOWS\system32\SET566.tmp moved successfully.
C:\WINDOWS\system32\SET567.tmp moved successfully.
C:\WINDOWS\system32\SET56C.tmp moved successfully.
C:\WINDOWS\system32\SET56D.tmp moved successfully.
C:\WINDOWS\system32\SET56E.tmp moved successfully.
C:\WINDOWS\system32\SET56F.tmp moved successfully.
C:\WINDOWS\system32\SET570.tmp moved successfully.
C:\WINDOWS\system32\SET571.tmp moved successfully.
C:\WINDOWS\system32\SET572.tmp moved successfully.
C:\WINDOWS\system32\SET573.tmp moved successfully.
C:\WINDOWS\system32\SET574.tmp moved successfully.
C:\WINDOWS\system32\SET575.tmp moved successfully.
C:\WINDOWS\system32\SET576.tmp moved successfully.
C:\WINDOWS\system32\SET577.tmp moved successfully.
C:\WINDOWS\system32\SET578.tmp moved successfully.
C:\WINDOWS\system32\SET579.tmp moved successfully.
C:\WINDOWS\system32\SET57C.tmp moved successfully.
C:\WINDOWS\system32\SET57D.tmp moved successfully.
C:\WINDOWS\system32\SET57E.tmp moved successfully.
C:\WINDOWS\system32\SET580.tmp moved successfully.
C:\WINDOWS\system32\SET581.tmp moved successfully.
C:\WINDOWS\system32\SET582.tmp moved successfully.
C:\WINDOWS\system32\SET583.tmp moved successfully.
C:\WINDOWS\system32\SET584.tmp moved successfully.
C:\WINDOWS\system32\SET588.tmp moved successfully.
C:\WINDOWS\system32\SET58B.tmp moved successfully.
C:\WINDOWS\system32\SET58C.tmp moved successfully.
C:\WINDOWS\system32\SET58F.tmp moved successfully.
C:\WINDOWS\system32\SET590.tmp moved successfully.
C:\WINDOWS\system32\SET591.tmp moved successfully.
C:\WINDOWS\system32\SET593.tmp moved successfully.
C:\WINDOWS\system32\SET594.tmp moved successfully.
C:\WINDOWS\system32\SET595.tmp moved successfully.
C:\WINDOWS\system32\SET596.tmp moved successfully.
C:\WINDOWS\system32\SET597.tmp moved successfully.
C:\WINDOWS\system32\SET598.tmp moved successfully.
C:\WINDOWS\system32\SET599.tmp moved successfully.
C:\WINDOWS\system32\SET59A.tmp moved successfully.
C:\WINDOWS\system32\SET59B.tmp moved successfully.
C:\WINDOWS\system32\SET59C.tmp moved successfully.
C:\WINDOWS\system32\SET59D.tmp moved successfully.
C:\WINDOWS\system32\SET59E.tmp moved successfully.
C:\WINDOWS\system32\SET59F.tmp moved successfully.
C:\WINDOWS\system32\SET5A4.tmp moved successfully.
C:\WINDOWS\system32\SET5A5.tmp moved successfully.
C:\WINDOWS\system32\SET5A6.tmp moved successfully.
C:\WINDOWS\system32\SET5A7.tmp moved successfully.
C:\WINDOWS\system32\SET5A8.tmp moved successfully.
C:\WINDOWS\system32\SET5A9.tmp moved successfully.
C:\WINDOWS\system32\SET5AA.tmp moved successfully.
C:\WINDOWS\system32\SET5AB.tmp moved successfully.
C:\WINDOWS\system32\SET5AC.tmp moved successfully.
C:\WINDOWS\system32\SET5AD.tmp moved successfully.
C:\WINDOWS\system32\SET5AE.tmp moved successfully.
C:\WINDOWS\system32\SET5AF.tmp moved successfully.
C:\WINDOWS\system32\SET5B0.tmp moved successfully.
C:\WINDOWS\system32\SET5B1.tmp moved successfully.
C:\WINDOWS\system32\SET5B2.tmp moved successfully.
C:\WINDOWS\system32\SET5B3.tmp moved successfully.
C:\WINDOWS\system32\SET5B4.tmp moved successfully.
C:\WINDOWS\system32\SET5B5.tmp moved successfully.
C:\WINDOWS\system32\SET5B6.tmp moved successfully.
C:\WINDOWS\system32\SET5B7.tmp moved successfully.
C:\WINDOWS\system32\SET5B8.tmp moved successfully.
C:\WINDOWS\system32\SET5BD.tmp moved successfully.
C:\WINDOWS\system32\SET5BE.tmp moved successfully.
C:\WINDOWS\system32\SET5BF.tmp moved successfully.
C:\WINDOWS\system32\SET5C1.tmp moved successfully.
C:\WINDOWS\system32\SET5C2.tmp moved successfully.
C:\WINDOWS\system32\SET5C3.tmp moved successfully.
C:\WINDOWS\system32\SET5C4.tmp moved successfully.
C:\WINDOWS\system32\SET5C5.tmp moved successfully.
C:\WINDOWS\system32\SET5C6.tmp moved successfully.
C:\WINDOWS\system32\SET5C7.tmp moved successfully.
C:\WINDOWS\system32\SET5C8.tmp moved successfully.
C:\WINDOWS\system32\SET5CA.tmp moved successfully.
C:\WINDOWS\system32\SET5CC.tmp moved successfully.
C:\WINDOWS\system32\SET5CD.tmp moved successfully.
C:\WINDOWS\system32\SET5CE.tmp moved successfully.
C:\WINDOWS\system32\SET5CF.tmp moved successfully.
C:\WINDOWS\system32\SET5D1.tmp moved successfully.
C:\WINDOWS\system32\SET5D3.tmp moved successfully.
C:\WINDOWS\system32\SET5D4.tmp moved successfully.
C:\WINDOWS\system32\SET5D5.tmp moved successfully.
C:\WINDOWS\system32\SET5D6.tmp moved successfully.
C:\WINDOWS\system32\SET5D7.tmp moved successfully.
C:\WINDOWS\system32\SET5D9.tmp moved successfully.
C:\WINDOWS\system32\SET5DC.tmp moved successfully.
C:\WINDOWS\system32\SET5DD.tmp moved successfully.
C:\WINDOWS\system32\SET5DF.tmp moved successfully.
C:\WINDOWS\system32\SET5E0.tmp moved successfully.
C:\WINDOWS\system32\SET5E1.tmp moved successfully.
C:\WINDOWS\system32\SET5E3.tmp moved successfully.
C:\WINDOWS\system32\SET5E4.tmp moved successfully.
C:\WINDOWS\system32\SET5E5.tmp moved successfully.
C:\WINDOWS\system32\SET5E6.tmp moved successfully.
C:\WINDOWS\system32\SET5E7.tmp moved successfully.
C:\WINDOWS\system32\SET5E9.tmp moved successfully.
C:\WINDOWS\system32\SET5EA.tmp moved successfully.
C:\WINDOWS\system32\SET5EB.tmp moved successfully.
C:\WINDOWS\system32\SET5EC.tmp moved successfully.
C:\WINDOWS\system32\SET5ED.tmp moved successfully.
C:\WINDOWS\system32\SET5EE.tmp moved successfully.
C:\WINDOWS\system32\SET5F0.tmp moved successfully.
C:\WINDOWS\system32\SET5F1.tmp moved successfully.
C:\WINDOWS\system32\SET5F3.tmp moved successfully.
C:\WINDOWS\system32\SET5F5.tmp moved successfully.
C:\WINDOWS\system32\SET5F7.tmp moved successfully.
C:\WINDOWS\system32\SET5F8.tmp moved successfully.
C:\WINDOWS\system32\SET5FA.tmp moved successfully.
C:\WINDOWS\system32\SET5FB.tmp moved successfully.
C:\WINDOWS\system32\SET5FC.tmp moved successfully.
C:\WINDOWS\system32\SET5FD.tmp moved successfully.
C:\WINDOWS\system32\SET5FE.tmp moved successfully.
C:\WINDOWS\system32\SET5FF.tmp moved successfully.
C:\WINDOWS\system32\SET600.tmp moved successfully.
C:\WINDOWS\system32\SET601.tmp moved successfully.
C:\WINDOWS\system32\SET602.tmp moved successfully.
C:\WINDOWS\system32\SET604.tmp moved successfully.
C:\WINDOWS\system32\SET608.tmp moved successfully.
C:\WINDOWS\system32\SET609.tmp moved successfully.
C:\WINDOWS\system32\SET612.tmp moved successfully.
C:\WINDOWS\system32\SET613.tmp moved successfully.
C:\WINDOWS\system32\SET614.tmp moved successfully.
C:\WINDOWS\system32\SET617.tmp moved successfully.
C:\WINDOWS\system32\SET618.tmp moved successfully.
C:\WINDOWS\system32\SET619.tmp moved successfully.
C:\WINDOWS\system32\SET61A.tmp moved successfully.
C:\WINDOWS\system32\SET61C.tmp moved successfully.
C:\WINDOWS\system32\SET61D.tmp moved successfully.
C:\WINDOWS\system32\SET61E.tmp moved successfully.
C:\WINDOWS\system32\SET61F.tmp moved successfully.
C:\WINDOWS\system32\SET620.tmp moved successfully.
C:\WINDOWS\system32\SET621.tmp moved successfully.
C:\WINDOWS\system32\SET624.tmp moved successfully.
C:\WINDOWS\system32\SET62B.tmp moved successfully.
C:\WINDOWS\system32\SET62D.tmp moved successfully.
C:\WINDOWS\system32\SET634.tmp moved successfully.
C:\WINDOWS\system32\SET635.tmp moved successfully.
C:\WINDOWS\system32\SET636.tmp moved successfully.
C:\WINDOWS\system32\SET63B.tmp moved successfully.
C:\WINDOWS\system32\SET63C.tmp moved successfully.
C:\WINDOWS\system32\SET63E.tmp moved successfully.
C:\WINDOWS\system32\SET640.tmp moved successfully.
C:\WINDOWS\system32\SET641.tmp moved successfully.
C:\WINDOWS\system32\SET642.tmp moved successfully.
C:\WINDOWS\system32\SET643.tmp moved successfully.
C:\WINDOWS\system32\SET645.tmp moved successfully.
C:\WINDOWS\system32\SET646.tmp moved successfully.
C:\WINDOWS\system32\SET64A.tmp moved successfully.
C:\WINDOWS\system32\SET64B.tmp moved successfully.
C:\WINDOWS\system32\SET64C.tmp moved successfully.
C:\WINDOWS\system32\SET64E.tmp moved successfully.
C:\WINDOWS\system32\SET650.tmp moved successfully.
C:\WINDOWS\system32\SET651.tmp moved successfully.
C:\WINDOWS\system32\SET652.tmp moved successfully.
C:\WINDOWS\system32\SET653.tmp moved successfully.
C:\WINDOWS\system32\SET654.tmp moved successfully.
C:\WINDOWS\system32\SET659.tmp moved successfully.
C:\WINDOWS\system32\SET65B.tmp moved successfully.
C:\WINDOWS\system32\SET65C.tmp moved successfully.
C:\WINDOWS\system32\SET65D.tmp moved successfully.
C:\WINDOWS\system32\SET65E.tmp moved successfully.
C:\WINDOWS\system32\SET65F.tmp moved successfully.
C:\WINDOWS\system32\SET666.tmp moved successfully.
C:\WINDOWS\system32\SET667.tmp moved successfully.
C:\WINDOWS\system32\SET66D.tmp moved successfully.
C:\WINDOWS\system32\SET66E.tmp moved successfully.
C:\WINDOWS\system32\SET66F.tmp moved successfully.
C:\WINDOWS\system32\SET670.tmp moved successfully.
C:\WINDOWS\system32\SET672.tmp moved successfully.
C:\WINDOWS\system32\SET674.tmp moved successfully.
C:\WINDOWS\system32\SET678.tmp moved successfully.
C:\WINDOWS\system32\SET679.tmp moved successfully.
C:\WINDOWS\system32\SET67A.tmp moved successfully.
C:\WINDOWS\system32\SET67C.tmp moved successfully.
C:\WINDOWS\system32\SET67D.tmp moved successfully.
C:\WINDOWS\system32\SET683.tmp moved successfully.
C:\WINDOWS\system32\SET687.tmp moved successfully.
C:\WINDOWS\system32\SET68A.tmp moved successfully.
C:\WINDOWS\system32\SET68C.tmp moved successfully.
C:\WINDOWS\system32\SET68F.tmp moved successfully.
C:\WINDOWS\system32\SET690.tmp moved successfully.
C:\WINDOWS\system32\SET691.tmp moved successfully.
C:\WINDOWS\system32\SET695.tmp moved successfully.
C:\WINDOWS\system32\SET697.tmp moved successfully.
C:\WINDOWS\system32\SET698.tmp moved successfully.
C:\WINDOWS\system32\SET699.tmp moved successfully.
C:\WINDOWS\system32\SET69B.tmp moved successfully.
C:\WINDOWS\system32\SET69C.tmp moved successfully.
C:\WINDOWS\system32\SET6A2.tmp moved successfully.
C:\WINDOWS\system32\SET6A3.tmp moved successfully.
C:\WINDOWS\system32\SET6A5.tmp moved successfully.
C:\WINDOWS\system32\SET6A6.tmp moved successfully.
C:\WINDOWS\system32\SET6A7.tmp moved successfully.
C:\WINDOWS\system32\SET6AA.tmp moved successfully.
C:\WINDOWS\system32\SET6AC.tmp moved successfully.
C:\WINDOWS\system32\SET6AF.tmp moved successfully.
C:\WINDOWS\system32\SET6B0.tmp moved successfully.
C:\WINDOWS\system32\SET6B2.tmp moved successfully.
C:\WINDOWS\system32\SET6B6.tmp moved successfully.
C:\WINDOWS\system32\SET6C3.tmp moved successfully.
C:\WINDOWS\system32\SET6C4.tmp moved successfully.
C:\WINDOWS\system32\SET6C5.tmp moved successfully.
C:\WINDOWS\system32\SET6C6.tmp moved successfully.
C:\WINDOWS\system32\SET6CB.tmp moved successfully.
C:\WINDOWS\system32\SET6CE.tmp moved successfully.
C:\WINDOWS\system32\SET6CF.tmp moved successfully.
C:\WINDOWS\system32\SET6D2.tmp moved successfully.
C:\WINDOWS\system32\SET6D3.tmp moved successfully.
C:\WINDOWS\system32\SET6D4.tmp moved successfully.
C:\WINDOWS\system32\SET6D5.tmp moved successfully.
C:\WINDOWS\system32\SET6D6.tmp moved successfully.
C:\WINDOWS\system32\SET6D8.tmp moved successfully.
C:\WINDOWS\system32\SET6D9.tmp moved successfully.
C:\WINDOWS\system32\SET6DA.tmp moved successfully.
C:\WINDOWS\system32\SET6DC.tmp moved successfully.
C:\WINDOWS\system32\SET6DD.tmp moved successfully.
C:\WINDOWS\system32\SET6DE.tmp moved successfully.
C:\WINDOWS\system32\SET6E1.tmp moved successfully.
C:\WINDOWS\system32\SET6E4.tmp moved successfully.
C:\WINDOWS\system32\SET6E7.tmp moved successfully.
C:\WINDOWS\system32\SET6E8.tmp moved successfully.
C:\WINDOWS\system32\SET6EB.tmp moved successfully.
C:\WINDOWS\system32\SET6EC.tmp moved successfully.
C:\WINDOWS\system32\SET6ED.tmp moved successfully.
C:\WINDOWS\system32\SET6EE.tmp moved successfully.
C:\WINDOWS\system32\SET6F0.tmp moved successfully.
C:\WINDOWS\system32\SET6F2.tmp moved successfully.
C:\WINDOWS\system32\SET6F5.tmp moved successfully.
C:\WINDOWS\system32\SET6F6.tmp moved successfully.
C:\WINDOWS\system32\SET6F7.tmp moved successfully.
C:\WINDOWS\system32\SET6F9.tmp moved successfully.
C:\WINDOWS\system32\SET6FA.tmp moved successfully.
C:\WINDOWS\system32\SET6FB.tmp moved successfully.
C:\WINDOWS\system32\SET6FC.tmp moved successfully.
C:\WINDOWS\system32\SET6FD.tmp moved successfully.
C:\WINDOWS\system32\SET6FE.tmp moved successfully.
C:\WINDOWS\system32\SET6FF.tmp moved successfully.
C:\WINDOWS\system32\SET702.tmp moved successfully.
C:\WINDOWS\system32\SET703.tmp moved successfully.
C:\WINDOWS\system32\SET704.tmp moved successfully.
C:\WINDOWS\system32\SET705.tmp moved successfully.
C:\WINDOWS\system32\SET707.tmp moved successfully.
C:\WINDOWS\system32\SET708.tmp moved successfully.
C:\WINDOWS\system32\SET709.tmp moved successfully.
C:\WINDOWS\system32\SET70A.tmp moved successfully.
C:\WINDOWS\system32\SET70C.tmp moved successfully.
C:\WINDOWS\system32\SET70E.tmp moved successfully.
C:\WINDOWS\system32\SET70F.tmp moved successfully.
C:\WINDOWS\system32\SET711.tmp moved successfully.
C:\WINDOWS\system32\SET712.tmp moved successfully.
C:\WINDOWS\system32\SET714.tmp moved successfully.
C:\WINDOWS\system32\SET717.tmp moved successfully.
C:\WINDOWS\system32\SET718.tmp moved successfully.
C:\WINDOWS\system32\SET71A.tmp moved successfully.
C:\WINDOWS\system32\SET71B.tmp moved successfully.
C:\WINDOWS\system32\SET720.tmp moved successfully.
C:\WINDOWS\system32\SET721.tmp moved successfully.
C:\WINDOWS\system32\SET725.tmp moved successfully.
C:\WINDOWS\system32\SET726.tmp moved successfully.
C:\WINDOWS\system32\SET728.tmp moved successfully.
C:\WINDOWS\system32\SET72B.tmp moved successfully.
C:\WINDOWS\system32\SET72C.tmp moved successfully.
C:\WINDOWS\system32\SET72D.tmp moved successfully.
C:\WINDOWS\system32\SET72F.tmp moved successfully.
C:\WINDOWS\system32\SET730.tmp moved successfully.
C:\WINDOWS\system32\SET731.tmp moved successfully.
C:\WINDOWS\system32\SET733.tmp moved successfully.
C:\WINDOWS\system32\SET734.tmp moved successfully.
C:\WINDOWS\system32\SET735.tmp moved successfully.
C:\WINDOWS\system32\SET737.tmp moved successfully.
C:\WINDOWS\system32\SET738.tmp moved successfully.
C:\WINDOWS\system32\SET739.tmp moved successfully.
C:\WINDOWS\system32\SET73A.tmp moved successfully.
C:\WINDOWS\system32\SET73E.tmp moved successfully.
C:\WINDOWS\system32\SET73F.tmp moved successfully.
C:\WINDOWS\system32\SET742.tmp moved successfully.
C:\WINDOWS\system32\SET744.tmp moved successfully.
C:\WINDOWS\system32\SET746.tmp moved successfully.
C:\WINDOWS\system32\SET747.tmp moved successfully.
C:\WINDOWS\system32\SET749.tmp moved successfully.
C:\WINDOWS\system32\SET74A.tmp moved successfully.
C:\WINDOWS\system32\SET74B.tmp moved successfully.
C:\WINDOWS\system32\SET74C.tmp moved successfully.
C:\WINDOWS\system32\SET74D.tmp moved successfully.
C:\WINDOWS\system32\SET74E.tmp moved successfully.
C:\WINDOWS\system32\SET751.tmp moved successfully.
C:\WINDOWS\system32\SET754.tmp moved successfully.
C:\WINDOWS\system32\SET755.tmp moved successfully.
C:\WINDOWS\system32\SET756.tmp moved successfully.
C:\WINDOWS\system32\SET758.tmp moved successfully.
C:\WINDOWS\system32\SET759.tmp moved successfully.
C:\WINDOWS\system32\SET75A.tmp moved successfully.
C:\WINDOWS\system32\SET75B.tmp moved successfully.
C:\WINDOWS\system32\SET75C.tmp moved successfully.
C:\WINDOWS\system32\SET75E.tmp moved successfully.
C:\WINDOWS\system32\SET760.tmp moved successfully.
C:\WINDOWS\system32\SET762.tmp moved successfully.
C:\WINDOWS\system32\SET763.tmp moved successfully.
C:\WINDOWS\system32\SET764.tmp moved successfully.
C:\WINDOWS\system32\SET768.tmp moved successfully.
C:\WINDOWS\system32\SET772.tmp moved successfully.
C:\WINDOWS\system32\SET774.tmp moved successfully.
C:\WINDOWS\system32\SET775.tmp moved successfully.
C:\WINDOWS\system32\SET776.tmp moved successfully.
C:\WINDOWS\system32\SET778.tmp moved successfully.
C:\WINDOWS\system32\SET77A.tmp moved successfully.
C:\WINDOWS\system32\SET77D.tmp moved successfully.
C:\WINDOWS\system32\SET780.tmp moved successfully.
C:\WINDOWS\system32\SET782.tmp moved successfully.
C:\WINDOWS\system32\SET783.tmp moved successfully.
C:\WINDOWS\system32\SET784.tmp moved successfully.
C:\WINDOWS\system32\SET78A.tmp moved successfully.
C:\WINDOWS\system32\SET795.tmp moved successfully.
C:\WINDOWS\system32\SET798.tmp moved successfully.
C:\WINDOWS\system32\SET799.tmp moved successfully.
C:\WINDOWS\system32\SET79A.tmp moved successfully.
C:\WINDOWS\system32\SET79D.tmp moved successfully.
C:\WINDOWS\system32\SET7A5.tmp moved successfully.
C:\WINDOWS\system32\SET7AC.tmp moved successfully.
C:\WINDOWS\system32\SET7AE.tmp moved successfully.
C:\WINDOWS\system32\SET7B5.tmp moved successfully.
C:\WINDOWS\system32\SET7B7.tmp moved successfully.
C:\WINDOWS\system32\SET7BC.tmp moved successfully.
C:\WINDOWS\system32\SET7CB.tmp moved successfully.
C:\WINDOWS\system32\SET7CF.tmp moved successfully.
C:\WINDOWS\system32\SET7D1.tmp moved successfully.
C:\WINDOWS\system32\SET7D3.tmp moved successfully.
C:\WINDOWS\system32\SET7DA.tmp moved successfully.
C:\WINDOWS\system32\SET7DF.tmp moved successfully.
C:\WINDOWS\system32\SET7E0.tmp moved successfully.
C:\WINDOWS\system32\SET7F5.tmp moved successfully.
C:\WINDOWS\system32\SET7FB.tmp moved successfully.
C:\WINDOWS\system32\SET7FD.tmp moved successfully.
C:\WINDOWS\system32\SET7FE.tmp moved successfully.
C:\WINDOWS\system32\SET804.tmp moved successfully.
C:\WINDOWS\system32\SET808.tmp moved successfully.
C:\WINDOWS\system32\SET816.tmp moved successfully.
C:\WINDOWS\system32\SET819.tmp moved successfully.
C:\WINDOWS\system32\SET81A.tmp moved successfully.
C:\WINDOWS\system32\SET81B.tmp moved successfully.
C:\WINDOWS\system32\SET81D.tmp moved successfully.
C:\WINDOWS\system32\SET81E.tmp moved successfully.
C:\WINDOWS\system32\SET829.tmp moved successfully.
C:\WINDOWS\system32\SET834.tmp moved successfully.
C:\WINDOWS\system32\SET846.tmp moved successfully.
C:\WINDOWS\system32\SET847.tmp moved successfully.
C:\WINDOWS\system32\SET84C.tmp moved successfully.
C:\WINDOWS\system32\SET868.tmp moved successfully.
C:\WINDOWS\system32\SET869.tmp moved successfully.
C:\WINDOWS\system32\SET86C.tmp moved successfully.
C:\WINDOWS\system32\SET871.tmp moved successfully.
C:\WINDOWS\system32\SET873.tmp moved successfully.
C:\WINDOWS\system32\SET87A.tmp moved successfully.
C:\WINDOWS\system32\SET87B.tmp moved successfully.
C:\WINDOWS\system32\SET87C.tmp moved successfully.
C:\WINDOWS\system32\SET87E.tmp moved successfully.
C:\WINDOWS\system32\SET87F.tmp moved successfully.
C:\WINDOWS\system32\SET880.tmp moved successfully.
C:\WINDOWS\system32\SET883.tmp moved successfully.
C:\WINDOWS\system32\SET885.tmp moved successfully.
C:\WINDOWS\system32\SET886.tmp moved successfully.
C:\WINDOWS\system32\SET888.tmp moved successfully.
C:\WINDOWS\system32\SET88B.tmp moved successfully.
C:\WINDOWS\system32\SET88D.tmp moved successfully.
C:\WINDOWS\system32\SET892.tmp moved successfully.
C:\WINDOWS\system32\SET893.tmp moved successfully.
C:\WINDOWS\system32\SET89B.tmp moved successfully.
C:\WINDOWS\system32\SET8A2.tmp moved successfully.
C:\WINDOWS\system32\SET8A7.tmp moved successfully.
C:\WINDOWS\system32\SET8AA.tmp moved successfully.
C:\WINDOWS\system32\SET8AD.tmp moved successfully.
C:\WINDOWS\system32\SET8AF.tmp moved successfully.
C:\WINDOWS\system32\SET8B3.tmp moved successfully.
C:\WINDOWS\system32\SET8B5.tmp moved successfully.
C:\WINDOWS\system32\SET8B6.tmp moved successfully.
C:\WINDOWS\system32\SET8B7.tmp moved successfully.
C:\WINDOWS\system32\SET8BA.tmp moved successfully.
C:\WINDOWS\system32\SET8BB.tmp moved successfully.
C:\WINDOWS\system32\SET8BF.tmp moved successfully.
C:\WINDOWS\system32\SET8C0.tmp moved successfully.
C:\WINDOWS\system32\SET8C3.tmp moved successfully.
C:\WINDOWS\system32\SET8C5.tmp moved successfully.
C:\WINDOWS\system32\SET8C7.tmp moved successfully.
C:\WINDOWS\system32\SET8CA.tmp moved successfully.
C:\WINDOWS\system32\SET8CC.tmp moved successfully.
C:\WINDOWS\system32\SET8CD.tmp moved successfully.
C:\WINDOWS\system32\SET8CF.tmp moved successfully.
C:\WINDOWS\system32\SET8D1.tmp moved successfully.
C:\WINDOWS\system32\SET8D3.tmp moved successfully.
C:\WINDOWS\system32\SET8D6.tmp moved successfully.
C:\WINDOWS\system32\SET8D7.tmp moved successfully.
C:\WINDOWS\system32\SET8D9.tmp moved successfully.
C:\WINDOWS\system32\SETA50.tmp moved successfully.
C:\WINDOWS\system32\SETA56.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET13CC.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET13CD.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET1522.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET16A5.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET63F.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET640.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET641.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET642.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET643.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET644.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET645.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET646.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET647.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET648.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET649.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET64A.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET64B.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET793.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET794.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET795.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET796.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET797.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET798.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET799.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET79A.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET79B.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET79C.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET79D.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET79E.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET79F.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET7A0.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET8F4.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET917.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET918.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET919.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET91A.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET91B.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET91C.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET91D.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET91E.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET91F.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET920.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET921.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET922.tmp moved successfully.
C:\WINDOWS\system32\Setup\SET923.tmp moved successfully.
C:\WINDOWS\system32\Setup\SETA73.tmp moved successfully.
C:\WINDOWS\system32\spool\drivers\w32x86\3\SET1409.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET64C.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET64D.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET64F.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET650.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET651.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET65E.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET661.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET663.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET665.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET66A.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET66D.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET66E.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET66F.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET671.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET672.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET674.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7A0.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7A1.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7A3.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7A4.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7A5.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7B2.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7B5.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7B7.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7B9.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7BE.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7C1.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7C2.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7C3.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7C5.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7C6.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET7C8.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET924.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET925.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET927.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET928.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET929.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET936.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET937.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET939.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET93B.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET93D.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET942.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET945.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET946.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET947.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET949.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET94A.tmp moved successfully.
C:\WINDOWS\system32\wbem\SET94C.tmp moved successfully.
C:\WINDOWS\002853_.tmp moved successfully.
C:\WINDOWS\002862_.tmp moved successfully.
C:\WINDOWS\003011_.tmp moved successfully.
C:\WINDOWS\003059_.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET32.tmp moved successfully.
C:\WINDOWS\SET35.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET41.tmp moved successfully.
C:\WINDOWS\SET622.tmp moved successfully.
C:\WINDOWS\SET776.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\SET8F9.tmp moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1123561945-725345543-1003Core.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1123561945-725345543-1003UA.job moved successfully.
C:\WINDOWS\tasks\Norton Security Scan.job moved successfully.
C:\WINDOWS\tasks\RMSchedule.job moved successfully.
C:\WINDOWS\tasks\User_Feed_Synchronization-{35BE11B1-063F-4046-8D29-C9D1A85202FD}.job moved successfully.
File/Folder C:\Program Files\AntivirusPro_2010 not found.
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk moved successfully.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\\{B922D405-6D13-4A2B-AE89-08A030DA4402} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{B922D405-6D13-4A2B-AE89-08A030DA4402} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HP Software Update deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Malwarebytes' Anti-Malware deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent\ deleted successfully.
========== COMMANDS ==========

Restore points cleared and new OTM Restore Point set!
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 1859826 bytes
->Temporary Internet Files folder emptied: 5276161 bytes
->FireFox cache emptied: 28838663 bytes
->Google Chrome cache emptied: 6802642 bytes
->Flash cache emptied: 343 bytes

User: All Users

User: All Users.WINDOWSL

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User.WINDOWSL
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Home
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2532296 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 546863 bytes
Windows Temp folder emptied: 224730 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 100028912 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 3831047127 bytes

Total Files Cleaned = 3 793,00 mb


[EMPTYFLASH]

User: Admin
->Flash cache emptied: 0 bytes

User: All Users

User: All Users.WINDOWSL

User: Default User

User: Default User.WINDOWSL

User: Home

User: LocalService

User: LocalService.NT AUTHORITY

User: NetworkService

User: NetworkService.NT AUTHORITY

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.19.0 log created on 02122012_200803

Files moved on Reboot...
File C:\Documents and Settings\Admin\Local Settings\Temp\Temporary Internet Files\Content.IE5\WTYRCTAT\531&ga_hid=1666587100&ga_fc=0&u_tz=60&u_his=75&u_java=1&u_h=768&u_w=1024&u_ah=768&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&biw=-12245933&bih=-12245933&ifk=1645031247&fu=0&ifi=1&dtd=47 not found!
File C:\Documents and Settings\Admin\Local Settings\Temp\Temporary Internet Files\Content.IE5\ETW1K9I3\pay;sec0=racing;sec1=burninrubber2;sec2=pay;!category=racing;!category=pop;!category=float;!category=expand;gen=games;pos=atf;tag=adj;mtype=standard;sz=728x90;tile=1;dcopt=[2] not found!
File C:\Documents and Settings\Admin\Local Settings\Temp\Temporary Internet Files\Content.IE5\ASSS6OPZ\531&ga_hid=1068974753&ga_fc=0&u_tz=60&u_his=75&u_java=1&u_h=768&u_w=1024&u_ah=768&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&biw=-12245933&bih=-12245933&ifk=2447529802&fu=0&ifi=1&dtd=47 not found!
File C:\Documents and Settings\Admin\Local Settings\Temp\Temporary Internet Files\Content.IE5\ASSS6OPZ\pay;sec0=racing;sec1=burninrubber2;sec2=pay;!category=racing;!category=pop;!category=float;!category=expand;gen=games;pos=atf;tag=adj;mtype=standard;sz=300x250;tile=3;u=!ca[2] not found!
File C:\Documents and Settings\Admin\Local Settings\Temp\Temporary Internet Files\Content.IE5\ASSS6OPZ\pay;sec0=racing;sec1=burninrubber2;sec2=pay;!category=racing;!category=pop;!category=float;!category=expand;gen=games;pos=btf;tag=adj;mtype=standard;sz=180x60;tile=1;dcopt=[1] not found!
File C:\Documents and Settings\Admin\Local Settings\Temp\Temporary Internet Files\Content.IE5\6MBF30YP\regionalcontent;sz=300x250;kl=N;klg=cs;kt=K;kga=-1;kr=F;kw=medicopter+117+intro;kgg=-1;kcr=cz;dc_dedup=1;kmyd=ad_creative_1;tile=1;dcopt=ist;ord=3891000234655927[2] not found!

Registry entries deleted on Reboot...

Re: prosím o kontrolu logu pomalé PC

Napsal: 13 úno 2012 09:23
od Márty84
OTM odvedlo dobrou praci :)

Jak je na tom zatim pocitac? Zrychlil trochu?

Provedte jeste sken s OTL

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe , ulozte na plochu a spustte
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*loader* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte.

Re: prosím o kontrolu logu pomalé PC

Napsal: 13 úno 2012 14:34
od Oji
Dobrá udělám to a je to mnohem lepší..super díky...

Re: prosím o kontrolu logu pomalé PC

Napsal: 13 úno 2012 15:26
od Oji
OTL logfile created on: 13.2.2012 14:50:56 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Admin\Plocha\dokumenty\Dokumenty\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

511,48 Mb Total Physical Memory | 247,45 Mb Available Physical Memory | 48,38% Memory free
1,97 Gb Paging File | 1,61 Gb Available in Paging File | 81,77% Paging File free
Paging file location(s): C:\pagefile.sys 1536 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 114,49 Gb Total Space | 95,24 Gb Free Space | 83,18% Space Free | Partition Type: NTFS

Computer Name: INTELP4 | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012.02.13 14:48:02 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Admin\Plocha\dokumenty\Dokumenty\Downloads\OTL.exe
PRC - [2012.01.20 06:35:36 | 001,047,024 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
PRC - [2012.01.13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011.12.13 17:42:08 | 000,922,976 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
PRC - [2011.11.28 19:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011.11.28 19:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010.10.07 14:55:06 | 000,488,728 | ---- | M] () -- C:\Program Files\Seznam.cz\postak.exe
PRC - [2010.08.05 07:46:02 | 000,583,640 | ---- | M] (PC Tools) -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
PRC - [2008.05.09 11:53:03 | 000,606,720 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2008.05.09 11:53:02 | 001,817,600 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
PRC - [2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005.11.08 23:00:38 | 000,128,920 | ---- | M] (DT Soft Ltd.) -- C:\Program Files\DAEMON Tools\daemon.exe
PRC - [2005.10.24 14:45:00 | 000,090,112 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe


========== Modules (No Company Name) ==========

MOD - [2012.02.13 11:17:44 | 001,691,648 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12021300\algo.dll
MOD - [2012.01.20 06:35:35 | 000,411,120 | ---- | M] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\Application\16.0.912.77\ppgooglenaclpluginchrome.dll
MOD - [2012.01.20 06:35:34 | 003,767,792 | ---- | M] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\Application\16.0.912.77\pdf.dll
MOD - [2012.01.20 06:34:10 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\Application\16.0.912.77\avutil-51.dll
MOD - [2012.01.20 06:34:09 | 000,222,208 | ---- | M] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\Application\16.0.912.77\avformat-53.dll
MOD - [2012.01.20 06:34:07 | 001,746,432 | ---- | M] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\Application\16.0.912.77\avcodec-53.dll
MOD - [2012.01.20 03:14:40 | 008,593,056 | ---- | M] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\Application\16.0.912.77\gcswf32.dll
MOD - [2010.10.07 14:55:06 | 000,488,728 | ---- | M] () -- C:\Program Files\Seznam.cz\postak.exe
MOD - [2010.10.07 14:54:58 | 000,849,176 | ---- | M] () -- C:\Program Files\Seznam.cz\email.3.dll
MOD - [2010.10.07 14:54:40 | 001,164,568 | ---- | M] () -- C:\Program Files\Seznam.cz\core.3.dll
MOD - [2006.10.22 11:22:00 | 000,212,992 | ---- | M] () -- C:\WINDOWS\system32\nvapi.dll
MOD - [2005.10.20 09:36:08 | 000,077,824 | R--- | M] () -- C:\Program Files\HP\Digital Imaging\bin\crm\xmltok.dll
MOD - [2005.10.20 09:36:08 | 000,065,536 | R--- | M] () -- C:\Program Files\HP\Digital Imaging\bin\crm\xmlparse.dll
MOD - [2005.07.27 10:17:00 | 000,007,168 | ---- | M] () -- C:\Program Files\DAEMON Tools\Plugins\Images\bw5mount.dll
MOD - [2001.10.28 16:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2012.01.13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.11.28 19:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010.08.05 07:46:02 | 000,583,640 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2008.05.09 11:53:03 | 000,606,720 | ---- | M] (Crawler.com) [Auto | Running] -- C:\Program Files\Spyware Terminator\sp_rsser.exe -- (sp_rssrv)


========== Driver Services (SafeList) ==========

DRV - [2012.02.12 11:16:13 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011.12.10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011.11.28 18:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011.11.28 18:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011.11.28 18:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011.11.28 18:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011.11.28 18:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011.11.28 18:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011.11.28 18:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2008.05.09 11:53:03 | 000,141,312 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys -- (sp_rsdrv2)
DRV - [2008.04.13 19:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008.04.13 19:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008.01.17 16:19:39 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2006.05.21 12:24:56 | 000,223,128 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\dtscsi.sys -- (dtscsi)
DRV - [2005.12.11 10:28:41 | 000,664,064 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2005.10.26 16:08:00 | 003,786,944 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005.07.07 15:26:04 | 000,055,216 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750bus.sys -- (k750bus) Sony Ericsson 750 driver (WDM)
DRV - [2005.07.07 15:26:00 | 000,006,576 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750mdfl.sys -- (k750mdfl)
DRV - [2005.07.07 15:25:58 | 000,089,872 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750mdm.sys -- (k750mdm)
DRV - [2005.07.07 15:25:52 | 000,081,728 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750mgmt.sys -- (k750mgmt)
DRV - [2005.07.07 15:25:50 | 000,079,488 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750obex.sys -- (k750obex)
DRV - [2004.09.13 04:11:30 | 000,049,611 | R--- | M] (Mobile Action Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MaRdP2K.sys -- (MaRdPnp)
DRV - [2004.08.23 08:40:04 | 000,011,089 | R--- | M] (Mobile Action Technology Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\MaVc2K.sys -- (MaVctrl)
DRV - [2004.08.03 21:32:26 | 000,048,640 | ---- | M] (Crystal Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cwrwdm.sys -- (cwrwdm) Ovladač SoundFusion(tm)
DRV - [2004.03.17 14:22:58 | 000,117,248 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viaudios.sys -- (VIAudio) Vinyl AC'97 Audio Controller (WDM)
DRV - [2002.11.18 15:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [2002.09.23 13:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2002.09.23 13:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2001.10.24 11:53:04 | 000,594,238 | ---- | M] (ESS Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\es56hpi.sys -- (Edspport)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-515967899-1123561945-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-515967899-1123561945-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-515967899-1123561945-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKU\S-1-5-21-515967899-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163&ilc=12"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://home.juicyaccess.com"
FF - prefs.js..extensions.enabledItems: {872A1C39-DF0B-4c8b-AD84-12BA24A3B781}:4.1.4.0
FF - prefs.js..extensions.enabledItems: {0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}:1.5.0.850
FF - prefs.js..extensions.enabledItems: {2224E955-00E9-4613-A844-CE69FCCAAE91}:3.4.0.4340
FF - prefs.js..extensions.enabledItems: pdfforge@mybrowserbar.com:4.9
FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:4.9
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=green ... =971163&p="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009.08.06 21:55:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.05.10 08:26:19 | 000,000,000 | ---D | M]

[2009.08.06 21:55:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Extensions
[2012.02.12 10:08:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\628oys85.default\extensions
[2010.06.19 14:44:09 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\628oys85.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.02.12 10:08:26 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\628oys85.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012.01.06 13:51:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\ADMIN\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\628OYS85.DEFAULT\EXTENSIONS\{20A82645-C095-46ED-80E3-08825760534B}
[2012.01.06 13:52:15 | 000,000,000 | ---D | M] (Widgi Toolbar Platform) -- C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM
File not found (No name found) -- C:\PROGRAM FILES\DOUBLED\JUICYACCESS TOOLBAR\4.1.4.20920\FFTOOLBAR
File not found (No name found) -- C:\PROGRAM FILES\INTERNET SAVING OPTIMIZER\3.4.0.4340\FF
File not found (No name found) -- C:\PROGRAM FILES\MEDIA ACCESS STARTUP\1.5.0.850\FF
[2012.01.06 13:52:15 | 000,000,000 | ---D | M] (pdfforge Toolbar) -- C:\PROGRAM FILES\PDFFORGE TOOLBAR\FF
[2008.03.24 19:21:00 | 002,889,088 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPSWF32.dll
[2009.06.23 06:35:04 | 000,001,619 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\FFToolbar.xml
[2009.08.06 21:55:02 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2009.08.06 21:55:02 | 000,001,687 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2009.08.06 21:55:02 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2009.08.06 21:55:02 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2009.08.06 21:55:02 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Admin\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Admin\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Admin\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Admin\Local Settings\Data aplikac\u00ED\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2012.02.12 20:10:02 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Lištička) - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\listicka.dll ()
O3 - HKLM\..\Toolbar: (Nástroje Lištičky) - {1EA00BE1-6E54-4E2A-8099-680300BF23E1} - C:\Program Files\Seznam.cz\toolbar\toolbar.dll ()
O3 - HKU\S-1-5-21-515967899-1123561945-725345543-1003\..\Toolbar\WebBrowser: (Nástroje Lištičky) - {34AB3C4C-DA1A-4067-96F4-31452C7CFE65} - C:\Program Files\Seznam.cz\listicka.dll ()
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKU\S-1-5-21-515967899-1123561945-725345543-1003..\Run: [Seznam Postak] C:\Program Files\Seznam.cz\postak.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-515967899-1123561945-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-515967899-1123561945-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-515967899-1123561945-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKU\S-1-5-21-515967899-1123561945-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKU\S-1-5-21-515967899-1123561945-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKU\S-1-5-21-515967899-1123561945-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKU\S-1-5-21-515967899-1123561945-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O8 - Extra context menu item: Add to AMV Converter... - C:\kfph\AMVConverter\grab.html File not found
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\kfph\MediaManager\grab.html File not found
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html File not found
O9 - Extra Button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra 'Tools' menuitem : Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra Button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra 'Tools' menuitem : Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{10F3810B-5628-48A9-8BB7-D361247C4DB4}: NameServer = 192.168.150.237,194.228.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E71ECD8-B3D0-4D43-87B5-5CF22ECA1B34}: NameServer = 192.168.150.237,194.228.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012.02.11 11:54:44 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (EA.com/On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (EA.com/On2.com)
Drivers32: vidc.VP62 - C:\WINDOWS\System32\vp6vfw.dll (EA.com/On2.com)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2012.02.12 21:19:50 | 000,435,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012.02.12 20:03:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2012.02.12 18:59:32 | 000,000,000 | ---D | C] -- C:\_OTM
[2012.02.12 18:57:40 | 000,523,264 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Admin\Plocha\OTM.exe
[2012.02.12 18:46:46 | 000,953,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40u.dll
[2012.02.12 18:45:28 | 000,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comctl32.dll
[2012.02.12 18:43:43 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndproxy.sys
[2012.02.12 17:33:38 | 000,139,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdpwd.sys
[2012.02.12 17:33:28 | 000,105,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mup.sys
[2012.02.12 17:31:40 | 000,010,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndistapi.sys
[2012.02.12 17:27:59 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2012.02.12 17:23:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2012.02.12 11:18:14 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2012.02.12 11:14:58 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012.02.12 11:14:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Data aplikací\Malwarebytes
[2012.02.12 11:12:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
[2012.02.12 11:12:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2012.02.12 11:11:59 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.02.12 11:11:57 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.02.12 10:42:17 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Admin\Recent
[2012.02.12 10:34:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Plocha\zaloha kolařík
[2012.02.12 10:06:45 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.02.12 10:06:39 | 000,000,000 | ---D | C] -- C:\rsit
[2012.02.12 10:03:04 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2012.02.12 10:00:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Nabídka Start\Programy\CCleaner
[2012.02.12 10:00:35 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.02.12 09:48:11 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pidgen.dll.wga
[2012.02.12 09:48:10 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpcdll.dll.wga
[2012.02.11 12:23:33 | 000,000,000 | ---D | C] -- C:\WINDOWSL
[2012.01.19 17:57:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Alík - Než půjdu do školy
[2012.01.19 17:56:39 | 000,177,824 | ---- | C] (Sheridan Software Systems, Inc.) -- C:\WINDOWS\System\THREED16.OCX
[2012.01.19 17:55:42 | 000,935,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VB40016.DLL
[2012.01.19 17:55:42 | 000,536,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OC25.DLL
[2012.01.19 17:55:42 | 000,304,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLE2.DLL
[2012.01.19 17:55:42 | 000,177,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TYPELIB.DLL
[2012.01.19 17:55:42 | 000,164,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLE2DISP.DLL
[2012.01.19 17:55:42 | 000,152,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLE2NLS.DLL
[2012.01.19 17:55:42 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\COMPOBJ.DLL
[2012.01.19 17:55:42 | 000,057,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLE2CONV.DLL
[2012.01.19 17:55:42 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLE2PROX.DLL
[2012.01.19 17:55:42 | 000,035,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VAEN21.OLB
[2012.01.19 17:55:42 | 000,026,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\CTL3DV2.DLL
[2012.01.19 17:55:42 | 000,012,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SCP.DLL
[2012.01.19 17:55:42 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\STKIT416.DLL
[18 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012.02.13 14:53:18 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.02.13 14:40:45 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.02.13 14:36:54 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012.02.13 14:34:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.02.12 21:19:50 | 000,002,553 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012.02.12 21:09:04 | 000,118,152 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.02.12 21:04:53 | 000,437,980 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2012.02.12 21:04:53 | 000,130,252 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.02.12 21:04:53 | 000,082,794 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2012.02.12 21:04:53 | 000,071,482 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.02.12 20:55:07 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012.02.12 20:01:36 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2012.02.12 19:10:13 | 000,000,855 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2012.02.12 18:57:45 | 000,523,264 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Admin\Plocha\OTM.exe
[2012.02.12 17:21:25 | 000,096,384 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd6989.sys
[2012.02.12 11:17:39 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2012.02.12 11:16:13 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012.02.12 11:12:10 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes Anti-Malware.lnk
[2012.02.12 10:09:04 | 000,000,321 | -HS- | M] () -- C:\boot.ini
[2012.02.12 10:00:36 | 000,001,548 | ---- | M] () -- C:\Documents and Settings\Admin\Plocha\CCleaner.lnk
[2012.02.12 09:48:15 | 000,013,588 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak
[2012.02.11 12:03:01 | 536,399,872 | -HS- | M] () -- C:\hiberfil.sys
[2012.02.11 11:54:44 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2012.01.26 18:40:09 | 000,002,257 | ---- | M] () -- C:\Documents and Settings\Admin\Plocha\Google Chrome.lnk
[2012.01.19 18:11:55 | 000,000,266 | ---- | M] () -- C:\Documents and Settings\Admin\Plocha\Zástupce - START.EXE.lnk
[2012.01.19 17:57:00 | 000,000,038 | ---- | M] () -- C:\WINDOWS\ALIK.INI

========== Files Created - No Company Name ==========

[2012.02.13 14:53:18 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.02.12 17:28:51 | 000,781,383 | ---- | C] () -- C:\Documents and Settings\Admin\Plocha\RSIT.exe
[2012.02.12 11:32:12 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2012.02.12 11:12:10 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes Anti-Malware.lnk
[2012.02.12 10:00:36 | 000,001,548 | ---- | C] () -- C:\Documents and Settings\Admin\Plocha\CCleaner.lnk
[2012.02.12 09:48:16 | 000,013,588 | ---- | C] () -- C:\WINDOWS\System32\wpa.bak
[2012.02.11 12:03:01 | 536,399,872 | -HS- | C] () -- C:\hiberfil.sys
[2012.02.11 11:54:44 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2012.01.19 18:11:55 | 000,000,266 | ---- | C] () -- C:\Documents and Settings\Admin\Plocha\Zástupce - START.EXE.lnk
[2012.01.19 17:57:00 | 000,000,038 | ---- | C] () -- C:\WINDOWS\ALIK.INI
[2012.01.19 17:55:42 | 000,157,696 | ---- | C] () -- C:\WINDOWS\System\STORAGE.DLL
[2012.01.19 17:55:42 | 000,028,113 | ---- | C] () -- C:\WINDOWS\System\OLE2.REG
[2012.01.19 17:55:42 | 000,014,933 | ---- | C] () -- C:\WINDOWS\System\VSHARE.386
[2011.03.04 17:22:30 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2010.10.28 12:50:23 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.10.20 10:32:04 | 000,037,336 | ---- | C] () -- C:\WINDOWS\System32\CleanMFT32.exe
[2009.09.09 16:05:24 | 000,017,902 | ---- | C] () -- C:\Documents and Settings\Admin\Data aplikací\ewofeni.lib
[2009.09.09 16:05:24 | 000,014,853 | ---- | C] () -- C:\WINDOWS\ijasuvi.sys
[2009.09.09 16:05:24 | 000,014,733 | ---- | C] () -- C:\Program Files\Common Files\xipodi.com
[2009.09.09 16:05:24 | 000,013,425 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\latulo.dl
[2009.09.09 16:05:24 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\huvurozi.bin
[2009.09.09 16:05:24 | 000,011,213 | ---- | C] () -- C:\Program Files\Common Files\neko.dl
[2009.09.09 16:05:23 | 000,019,884 | ---- | C] () -- C:\WINDOWS\System32\yfumawone.bin
[2009.09.09 16:05:23 | 000,019,235 | ---- | C] () -- C:\WINDOWS\ifezotumih.dat
[2009.09.09 16:05:23 | 000,018,688 | ---- | C] () -- C:\Program Files\Common Files\cojotilyk.bin
[2009.09.09 16:05:23 | 000,017,035 | ---- | C] () -- C:\WINDOWS\System32\kobofytov.com
[2009.09.09 16:05:23 | 000,015,525 | ---- | C] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\ycexut.dl
[2009.09.09 16:05:23 | 000,015,491 | ---- | C] () -- C:\Program Files\Common Files\ehoz.inf
[2009.09.09 16:05:23 | 000,012,054 | ---- | C] () -- C:\Documents and Settings\Admin\Data aplikací\oxeceza.scr
[2009.04.28 15:00:29 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\PUTTY.RND
[2008.11.19 18:16:39 | 000,000,003 | ---- | C] () -- C:\WINDOWS\sbacknt.bin
[2008.09.01 18:04:36 | 000,001,160 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2008.08.25 15:17:48 | 000,134,919 | ---- | C] () -- C:\WINDOWS\HPHins12.dat
[2008.08.25 15:17:48 | 000,014,916 | ---- | C] () -- C:\WINDOWS\hphmdl12.dat
[2008.08.25 15:17:33 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2008.08.10 11:07:52 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\UnAudioNT.dll
[2008.08.10 10:46:47 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2008.08.10 10:46:46 | 000,152,064 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008.08.10 10:46:45 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008.06.04 07:45:42 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008.06.04 07:08:46 | 000,000,060 | ---- | C] () -- C:\WINDOWS\game.ini
[2008.05.23 08:53:17 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2008.05.23 08:53:17 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2008.05.23 08:53:17 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2008.05.23 08:53:17 | 000,049,152 | ---- | C] () -- C:\WINDOWS\VFind.exe
[2008.05.09 11:53:03 | 000,141,312 | ---- | C] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008.04.05 14:55:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008.03.21 16:27:13 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2008.03.21 16:27:13 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2008.03.21 16:27:13 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2008.03.07 19:50:25 | 000,000,238 | ---- | C] () -- C:\WINDOWS\mafosav.INI
[2008.01.27 14:36:57 | 000,000,060 | ---- | C] () -- C:\WINDOWS\CoolYouTubeDownloader.ini
[2008.01.17 17:34:25 | 000,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.01.17 17:33:02 | 000,107,832 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2008.01.17 17:32:40 | 000,066,872 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2008.01.11 22:32:33 | 000,441,548 | ---- | C] () -- C:\Documents and Settings\Admin\Data aplikací\NMM-MetaData.db
[2007.12.29 20:49:55 | 000,000,007 | ---- | C] () -- C:\WINDOWS\System32\ngxt.bin
[2007.08.01 18:15:09 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2007.07.13 19:12:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EngineExe.INI
[2007.07.13 19:05:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\AlbumExe.INI
[2007.07.13 19:02:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\FileMgrExe.INI
[2007.07.13 19:01:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VideoExe.INI
[2007.07.13 19:00:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MelodyExe.INI
[2007.07.13 14:18:04 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\fusioncache.dat
[2007.07.05 19:52:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PanelExe.INI
[2007.02.23 18:51:00 | 000,000,290 | ---- | C] () -- C:\WINDOWS\level.ini
[2007.01.21 12:41:55 | 000,003,734 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006.12.25 11:25:00 | 000,000,072 | ---- | C] () -- C:\WINDOWS\MediaManager.INI
[2006.10.22 11:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.10.22 11:22:00 | 001,622,016 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2006.10.22 11:22:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.10.22 11:22:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2006.10.22 11:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.10.22 11:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.10.22 11:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.10.22 11:22:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2006.10.22 11:22:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2006.10.22 11:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.22 11:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006.03.06 10:41:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\AMV_DecDLL.dll
[2005.12.26 20:13:15 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\pxhpinst.exe
[2005.12.26 20:13:06 | 000,000,192 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2005.12.26 18:25:31 | 000,000,855 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2005.12.20 16:04:41 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2005.12.17 16:04:49 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2005.12.11 10:29:47 | 000,223,128 | ---- | C] () -- C:\WINDOWS\System32\drivers\dtscsi.sys
[2005.12.11 10:28:41 | 000,096,384 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd6989.sys
[2005.12.03 23:46:48 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2005.12.03 23:46:17 | 000,157,184 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2004.12.19 16:27:00 | 000,151,552 | ---- | C] () -- C:\Documents and Settings\Admin\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004.12.19 16:20:40 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004.12.18 18:29:47 | 000,000,101 | ---- | C] () -- C:\WINDOWS\CMMIXER.INI
[2004.12.18 18:27:02 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2004.12.18 17:32:48 | 000,039,104 | ---- | C] () -- C:\WINDOWS\cmijack.dat
[2004.12.18 17:32:47 | 000,022,178 | ---- | C] () -- C:\WINDOWS\cmaudio.dat
[2004.12.18 15:58:42 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004.12.18 15:57:37 | 000,118,152 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004.12.18 15:11:06 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004.12.18 15:05:22 | 000,022,916 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004.09.16 13:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004.09.16 13:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\ADFUUD.SYS
[2004.08.17 15:58:58 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004.08.02 14:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2003.09.30 11:47:47 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2003.09.30 11:47:47 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2003.09.30 11:47:47 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2003.09.30 11:47:46 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2003.09.30 11:47:46 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2002.09.23 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2002.09.23 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2002.09.23 13:00:00 | 000,437,980 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2002.09.23 13:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2002.09.23 13:00:00 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2002.09.23 13:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2002.09.23 13:00:00 | 000,130,252 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2002.09.23 13:00:00 | 000,082,794 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2002.09.23 13:00:00 | 000,071,482 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2002.09.23 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2002.09.23 13:00:00 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2002.09.23 13:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2002.09.23 13:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2002.09.23 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[1996.04.03 20:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2008.01.27 14:37:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\CoolFlvMan
[2008.04.27 14:48:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\CoolYouTubeDownloader
[2008.06.04 07:11:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\COWON
[2008.03.01 14:42:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Datalayer
[2011.02.12 10:14:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ICQ
[2009.07.31 12:39:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ICQ Toolbar
[2008.08.25 16:06:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Image Zone Express
[2008.04.12 10:42:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\LangSoft
[2008.09.01 18:02:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Mikrotik
[2008.01.11 22:19:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Nokia
[2008.01.25 21:03:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Nokia Multimedia Player
[2008.03.01 13:05:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Nokia N73
[2008.01.11 22:12:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\PC Suite
[2011.03.04 17:26:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\pdfforge
[2007.02.17 13:11:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Samsung
[2012.01.06 13:52:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Search Settings
[2008.02.24 14:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Sports Interactive
[2012.02.13 14:41:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Spyware Terminator
[2008.11.19 18:15:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\vghd
[2010.10.01 21:10:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2008.06.04 07:18:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Downloaded Installations
[2008.04.12 10:41:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\LangSoft
[2008.01.11 22:13:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2012.01.20 16:42:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
[2012.02.12 09:53:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP

========== Purity Check ==========



========== Custom Scans ==========


< >

< >


< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2009.01.30 11:36:28 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:AGP440.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\sp3.cab:AGP440.sys
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWSL\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\agp440.sys
[2008.04.13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\agp440.sys
[2008.04.13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2009.01.30 11:36:28 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:atapi.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\sp3.cab:atapi.sys
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWSL\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 13:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWSL\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\autochk.exe
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\autochk.exe
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2008.04.14 13:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWSL\system32\autochk.exe
[2008.04.14 13:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWSL\system32\dllcache\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe

< MD5 for: CDROM.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2009.01.30 11:36:28 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:cdrom.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\sp3.cab:cdrom.sys
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWSL\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2008.04.14 13:00:00 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWSL\system32\drivers\cdrom.sys
[2004.08.03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 04:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 04:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\cryptsvc.dll
[2008.04.14 04:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cryptsvc.dll
[2008.04.14 04:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 13:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWSL\system32\cryptsvc.dll
[2008.04.14 13:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWSL\system32\dllcache\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2008.04.14 04:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 04:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\eventlog.dll
[2008.04.14 04:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\eventlog.dll
[2008.04.14 04:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2008.04.14 13:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWSL\system32\dllcache\eventlog.dll
[2008.04.14 13:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWSL\system32\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\explorer.exe
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\explorer.exe
[2008.04.14 13:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWSL\explorer.exe
[2008.04.14 13:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWSL\system32\dllcache\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007.06.13 14:11:59 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=9B32416BD5988C97B6397CE0B02CAF97 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007.06.13 14:23:39 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=ED7B460B142A32097B8A8F6ECC941815 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: HAL.DLL >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2009.01.30 11:36:28 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:hal.dll
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\sp3.cab:hal.dll
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWSL\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.13 19:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.13 19:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\hal.dll
[2008.04.13 19:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\hal.dll
[2008.04.13 19:31:28 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL
[2008.04.14 13:00:00 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWSL\system32\hal.dll
[2004.08.03 22:59:10 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll

< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2009.01.30 11:36:28 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:Changer.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\sp3.cab:Changer.sys
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWSL\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.13 19:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[2008.04.13 19:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\changer.sys
[2008.04.13 19:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\changer.sys

< MD5 for: ISAPNP.SYS >
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2009.01.30 11:36:28 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\sp3.cab:isapnp.sys
[2009.09.10 15:49:29 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\sp3.cab:isapnp.sys
[2008.04.14 13:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWSL\Driver Cache\i386\sp3.cab:isapnp.sys
[2001.10.24 11:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2002.09.23 13:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\i386\isapnp.sys
[2008.04.14 03:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 03:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\isapnp.sys
[2008.04.14 03:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\isapnp.sys
[2008.04.14 03:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 13:00:00 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWSL\system32\drivers\isapnp.sys

< MD5 for: LSASS.EXE >
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 04:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 04:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\lsass.exe
[2008.04.14 04:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\lsass.exe
[2008.04.14 04:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
[2008.04.14 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWSL\system32\dllcache\lsass.exe
[2008.04.14 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWSL\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\ndis.sys
[2008.04.13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ndis.sys
[2008.04.13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2008.04.14 13:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWSL\system32\dllcache\ndis.sys
[2008.04.14 13:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWSL\system32\drivers\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

< MD5 for: NETLOGON.DLL >
[2009.02.06 19:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 19:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 04:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 04:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\netlogon.dll
[2008.04.14 04:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\netlogon.dll
[2008.04.14 04:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
[2008.04.14 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWSL\system32\dllcache\netlogon.dll
[2008.04.14 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWSL\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
[2008.04.14 13:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWSL\system32\dllcache\scecli.dll
[2008.04.14 13:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWSL\system32\scecli.dll

< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2008.04.14 04:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 04:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\smss.exe
[2008.04.14 04:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\smss.exe
[2008.04.14 04:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
[2008.04.14 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWSL\system32\dllcache\smss.exe
[2008.04.14 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWSL\system32\smss.exe

< MD5 for: SVCHOST.EXE >
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\svchost.exe
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\svchost.exe
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2008.04.14 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWSL\system32\dllcache\svchost.exe
[2008.04.14 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWSL\system32\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.06.20 11:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2005.05.25 20:07:12 | 000,359,936 | ---- | M] (Microsoft Corporation) MD5=63FDFEA54EB53DE2D863EE454937CE1E -- C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[2007.10.30 17:53:32 | 000,360,832 | ---- | M] (Microsoft Corporation) MD5=64798ECFA43D78C7178375FCDD16D8C8 -- C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys

Re: prosím o kontrolu logu pomalé PC

Napsal: 13 úno 2012 15:26
od Oji
[2008.06.20 11:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2005.05.25 20:04:02 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=88763A98A4C26C409741B4AA162720C9 -- C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
[2007.10.30 18:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\tcpip.sys
[2008.04.14 13:00:00 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWSL\system32\dllcache\tcpip.sys
[2008.04.14 13:00:00 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWSL\system32\drivers\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\SoftwareDistribution\Download\fe608cd8d2b8f77abaee7a69a696bcf7\sp3qfe\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\userinit.exe
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\userinit.exe
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2008.04.14 13:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWSL\system32\dllcache\userinit.exe
[2008.04.14 13:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWSL\system32\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

< MD5 for: VIAMRAID.SYS >
[2004.07.06 22:45:00 | 000,060,672 | ---- | M] (VIA Technologies inc,.ltd) MD5=44056E9FEE477F512EE58BCFEE949621 -- C:\WINDOWS\system32\drivers\viamraid.sys

< MD5 for: WINLOGON.EXE >
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012.01.13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.04.14 04:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\winlogon.exe
[2008.04.14 04:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\winlogon.exe
[2008.04.14 04:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
[2008.04.14 13:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWSL\system32\dllcache\winlogon.exe
[2008.04.14 13:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWSL\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 04:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 04:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\ws2_32.dll
[2008.04.14 04:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ws2_32.dll
[2008.04.14 04:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
[2008.04.14 13:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWSL\system32\dllcache\ws2_32.dll
[2008.04.14 13:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWSL\system32\ws2_32.dll

< >

< %systemroot%*.* /U /s >
[23 C:\WINDOWS\$NtServicePackUninstall$\*.tmp files -> C:\WINDOWS\$NtServicePackUninstall$\*.tmp -> ]
[23 C:\WINDOWS\AppPatch\*.tmp files -> C:\WINDOWS\AppPatch\*.tmp -> ]
[18 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[18 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
[9 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[3 C:\WINDOWS\pchealth\helpctr\binaries\*.tmp files -> C:\WINDOWS\pchealth\helpctr\binaries\*.tmp -> ]
[27 C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\*.tmp files -> C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >
[2008.02.15 16:04:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CleverSpeeder

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2011.03.27 10:40:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Adobe
[2008.08.10 10:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\AdobeUM
[2008.02.07 20:34:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Ahead
[2008.01.27 14:37:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\CoolFlvMan
[2008.04.27 14:48:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\CoolYouTubeDownloader
[2008.06.04 07:11:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\COWON
[2004.12.18 19:39:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\CyberLink
[2008.03.01 14:42:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Datalayer
[2008.05.24 11:09:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Hamachi
[2005.12.11 12:05:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Help
[2008.08.28 13:36:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\HP
[2011.02.12 10:14:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ICQ
[2009.07.31 12:39:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\ICQ Toolbar
[2004.12.18 15:15:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Identities
[2008.08.25 16:06:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Image Zone Express
[2007.12.12 15:27:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\InstallShield
[2008.04.12 10:42:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\LangSoft
[2005.12.24 12:05:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Macromedia
[2012.02.12 11:14:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Malwarebytes
[2009.09.16 15:19:25 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Admin\Data aplikací\Microsoft
[2008.09.01 18:02:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Mikrotik
[2009.08.06 21:55:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Mozilla
[2008.01.11 22:19:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Nokia
[2008.01.25 21:03:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Nokia Multimedia Player
[2008.03.01 13:05:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Nokia N73
[2008.01.11 22:12:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\PC Suite
[2011.03.04 17:26:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\pdfforge
[2007.02.17 13:11:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Samsung
[2012.01.06 13:52:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Search Settings
[2007.11.03 16:34:29 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Admin\Data aplikací\SecuROM
[2010.10.28 13:51:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Skype
[2010.10.28 12:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\skypePM
[2008.02.24 14:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Sports Interactive
[2012.02.13 14:41:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\Spyware Terminator
[2008.11.19 18:15:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\vghd
[2008.01.27 14:24:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\vlc
[2008.03.08 21:15:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Data aplikací\WinRAR

< %APPDATA%\*.exe /s >
[2006.12.30 14:28:33 | 000,001,518 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_16496df1.exe
[2006.12.30 14:28:33 | 000,002,550 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_18be6784.exe
[2006.12.30 14:28:33 | 000,000,766 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_294823.exe
[2006.12.30 14:28:33 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_2cd672ae.exe
[2006.12.30 14:28:33 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_4ae13d6c.exe
[2006.12.30 14:28:33 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_69525f90.exe< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2006.05.21 12:24:56 | 000,223,128 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\dtscsi.sys
[2005.12.11 10:28:41 | 000,664,064 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
[2012.02.12 17:21:25 | 000,096,384 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd6989.sys

< %systemroot%\System32\config\*.sav >
[2005.12.04 01:38:34 | 000,262,144 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2005.12.04 00:21:14 | 000,262,144 | ---- | M] () -- C:\WINDOWS\System32\config\security.sav
[2005.12.04 01:38:34 | 013,369,344 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2005.12.04 01:38:34 | 003,145,728 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >
[2012.02.12 11:16:13 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2012.02.12 17:21:25 | 000,096,384 | ---- | M] () -- C:\WINDOWS\system32\drivers\sptd6989.sys

< %systemroot%\system32\*.* /3 >
[2012.02.12 21:19:50 | 000,002,553 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT
[2012.02.12 21:09:04 | 000,118,152 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2012.02.13 14:36:54 | 000,088,566 | ---- | M] () -- C:\WINDOWS\system32\nvapps.xml
[2012.02.12 21:04:53 | 000,082,794 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2012.02.12 21:04:53 | 000,071,482 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2012.02.12 21:04:53 | 000,437,980 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2012.02.12 21:04:53 | 000,130,252 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2012.02.12 21:04:53 | 000,692,482 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2012.02.12 17:24:12 | 000,000,090 | ---- | M] () -- C:\WINDOWS\system32\spupdwxp.log
[2012.02.12 20:22:16 | 000,601,444 | ---- | M] () -- C:\WINDOWS\system32\TZLog.log
[2012.02.12 09:48:15 | 000,013,588 | ---- | M] () -- C:\WINDOWS\system32\wpa.bak
[2012.02.13 14:40:45 | 000,013,646 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 04:22:17 | 000,015,360 | ---- | M] (Microsoft Corporation)
"Seznam Postak" = "C:\Program Files\Seznam.cz\postak.exe" -s -- [2010.10.07 14:55:06 | 000,488,728 | ---- | M] ()

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< >

< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=3
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWSL="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.02.13 14:53:18 | 000,000,512 | ---- | M] () MD5=B3CC8BB81D3C20CC2450BD8A3B018DC2 -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2008.04.08 07:39:32 | 000,004,121 | ---- | M] () -- \Program Files\Alex Kočičák\data\design4\decor\lava_crack1.jpg
[2008.04.08 07:39:32 | 000,006,331 | ---- | M] () -- \Program Files\Alex Kočičák\data\design4\decor\lava_crack2.jpg
[2008.04.08 07:35:56 | 000,019,525 | ---- | M] () -- \Program Files\Alex Kočičák\data\design4\decor\_lava_crack1.tga
[2008.04.08 07:36:14 | 000,022,544 | ---- | M] () -- \Program Files\Alex Kočičák\data\design4\decor\_lava_crack2.tga
[2008.04.04 08:36:14 | 000,005,952 | ---- | M] () -- \Program Files\Alex Kočičák\data\objects\crack\crack.JPG
[2008.04.04 08:36:58 | 000,027,692 | ---- | M] () -- \Program Files\Alex Kočičák\data\objects\crack\_crack.tga
[2008.04.08 09:09:22 | 000,004,125 | ---- | M] () -- \Program Files\Alex Kočičák\data\tutorial\tu_cracks.jpg
[2008.04.08 09:08:14 | 000,015,420 | ---- | M] () -- \Program Files\Alex Kočičák\data\tutorial\_tu_cracks.tga

< *keygen* /s >

< *loader* /s >
[2008.05.19 15:40:03 | 000,000,031 | ---- | M] () -- \Documents and Settings\Admin\Data aplikací\CoolYouTubeDownloader\CoolYouTubeDownloader.ini
[2010.02.28 15:32:07 | 000,000,055 | ---- | M] () -- \Documents and Settings\Admin\Data aplikací\Macromedia\Shockwave Player\Prefs\4KCQAVEK\grooveloader.txt
[2007.12.19 14:08:13 | 000,005,795 | ---- | M] () -- \Program Files\ICQ6\services\icqApp\ver1\theme\IMAGES\XtraPreloader\loader.jpg
[2008.08.27 14:53:11 | 000,004,089 | ---- | M] () -- \Program Files\ICQ6\services\icqApp\ver1\theme\IMAGES\XtraPreloader\loader.swf
[2007.12.19 14:08:14 | 000,005,520 | ---- | M] () -- \Program Files\ICQ6\services\icqApp\ver1\theme\MUICoreLib\xtraLoader.swf
[2008.04.12 10:43:25 | 000,002,886 | ---- | M] () -- \Program Files\ICQ6\services\icqXtraz\ver1\content\babylon_feed\preloader01_b.swf
[2009.07.19 17:56:05 | 000,003,479 | ---- | M] () -- \Program Files\ICQ6\services\icqXtraz\ver1\content\coreg\preloader04.swf
[2008.04.12 10:05:29 | 000,003,830 | ---- | M] () -- \Program Files\ICQ6\services\icqXtraz\ver1\content\pool\preloader02.swf
[2007.03.29 13:17:09 | 000,003,830 | ---- | M] () -- \Program Files\ICQ6\services\icqXtraz\ver1\content\rps\preloader02.swf
[2007.03.29 13:17:09 | 000,003,830 | ---- | M] () -- \Program Files\ICQ6\services\icqXtraz\ver1\content\slide-a-lama\preloader02.swf
[2008.05.05 16:10:07 | 000,003,830 | ---- | M] () -- \Program Files\ICQ6\services\icqXtraz\ver1\content\warsheep\preloader02.swf
[2008.03.16 14:20:10 | 000,003,830 | ---- | M] () -- \Program Files\ICQ6\services\icqXtraz\ver1\content\xicq_admirerx\preloader02.swf
[2008.03.12 12:36:57 | 000,003,830 | ---- | M] () -- \Program Files\ICQ6\services\icqXtraz\ver1\content\zoopaloola\preloader02.swf
[2008.03.11 19:30:32 | 000,552,798 | ---- | M] () -- \Program Files\ICQ6\services\icqXtraz\ver1\theme\game_center\loaderBkg.png
[2005.08.10 18:01:12 | 000,044,934 | ---- | M] () -- \Program Files\Macromedia\Flash 8\en\Configuration\Components\User Interface\Loader.swc
[2005.06.20 14:45:24 | 000,000,544 | ---- | M] () -- \Program Files\Macromedia\Flash 8\en\First Run\Classes\FP7\MovieClipLoader.as
[2005.06.20 14:45:26 | 000,000,544 | ---- | M] () -- \Program Files\Macromedia\Flash 8\en\First Run\Classes\FP8\MovieClipLoader.as
[2005.07.13 11:06:52 | 000,010,454 | ---- | M] () -- \Program Files\Macromedia\Flash 8\en\First Run\Classes\mx\controls\Loader.as
[2008.11.19 18:15:26 | 000,152,936 | ---- | M] () -- \Program Files\vghd\VirtuaGirl_Downloader.exe
[2006.12.23 17:37:56 | 000,044,032 | ---- | M] () -- \Program Files\WinRAR\RarExtLoader.exe
[2008.02.23 14:38:13 | 000,000,060 | ---- | M] () -- \WINDOWS\CoolYouTubeDownloader.ini
[2004.08.17 15:49:06 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll
[23 \WINDOWS\$NtServicePackUninstall$\*.tmp files -> \WINDOWS\$NtServicePackUninstall$\*.tmp -> ]
[2008.04.14 04:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll
[2008.04.13 19:31:47 | 000,230,912 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe
[2008.04.13 19:31:48 | 000,278,528 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd
[2008.04.14 04:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\dmloader.dll
[2008.04.13 19:31:47 | 000,230,912 | ---- | M] () -- \WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\osloader.exe
[2008.04.13 19:31:48 | 000,278,528 | ---- | M] () -- \WINDOWS\SoftwareDistribution\Download\1dab8d41b73a912c39f7d3fd77a4df39\osloader.ntd
[2008.04.14 04:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\dmloader.dll
[2008.04.13 19:31:47 | 000,230,912 | ---- | M] () -- \WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\osloader.exe
[2008.04.13 19:31:48 | 000,278,528 | ---- | M] () -- \WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\osloader.ntd
[2008.04.14 04:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[2011.10.05 11:12:42 | 000,012,532 | ---- | M] () -- \WINDOWS\system32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2011.10.05 11:19:08 | 000,009,622 | ---- | M] () -- \WINDOWS\system32\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr
[2008.04.14 13:00:00 | 000,035,840 | ---- | M] () -- \WINDOWSL\system32\dmloader.dll
[1 \WINDOWSL\system32\*.tmp files -> \WINDOWSL\system32\*.tmp -> ]
[2008.04.14 13:00:00 | 000,035,840 | ---- | M] () -- \WINDOWSL\system32\dllcache\dmloader.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1

< End of report >

Re: prosím o kontrolu logu pomalé PC

Napsal: 13 úno 2012 15:27
od Oji
OTL Extras logfile created on: 13.2.2012 14:50:56 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Admin\Plocha\dokumenty\Dokumenty\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

511,48 Mb Total Physical Memory | 247,45 Mb Available Physical Memory | 48,38% Memory free
1,97 Gb Paging File | 1,61 Gb Available in Paging File | 81,77% Paging File free
Paging file location(s): C:\pagefile.sys 1536 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 114,49 Gb Total Space | 95,24 Gb Free Space | 83,18% Space Free | Partition Type: NTFS

Computer Name: INTELP4 | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-515967899-1123561945-725345543-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe" = C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:*:Enabled:Pro Evolution Soccer 2008
"C:\Program Files\ICQ6\ICQ.exe" = C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, Inc.)
"C:\WINDOWS\Explorer.EXE" = C:\WINDOWS\Explorer.EXE:*:Enabled:explorer -- (Microsoft Corporation)
"C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe" = C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:*:Enabled:Football Manager 2008
"C:\Documents and Settings\Admin\Plocha\Skype.exe" = C:\Documents and Settings\Admin\Plocha\Skype.exe:*:Enabled:Skype
"C:\Program Files\BitLord\BitLord.exe" = C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{1D975A5E-1126-4F46-A423-41781934A63E}" = JuicyAccess Toolbar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20749F76-4228-43AD-8AB5-E7B20D8040C4}" = hph_readme
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26ED1160-22B1-4b19-8C21-42A1BACAAF75}" = pdfforge Toolbar v4.9
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36DC3E2F-CD8C-4953-9E8F-9A1916D10AA1}" = hph_software
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{48B82226-75E3-4E90-92CC-D30F79EA6380}" = Norton Security Scan
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}" = MP3 Player Utilities 4.05
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{90280405-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional s aplikací FrontPage
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1029-7B44-A70500000002}" = Adobe Reader 7.0.5 - Czech
"{ACCCEE83-B49B-4964-8A4F-378B8FBC9F75}" = hph_ProductContext
"{B19F9155-9337-4807-B5EF-ED471DDB2CCE}" = hph_software_req
"{BE365801-FB4B-49D7-87D2-9477EE371F1C}" = D1300_Help
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C13F11D1-00BA-44DF-B626-35E1C03F85E5}" = D1300
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2A3C9D5-0B56-4656-8277-7EDC65D62B6E}" = HP Photosmart and Deskjet 7.0 Software (csy)
"{D67B1C57-0E05-4F8C-9011-1C8BAE293782}" = Samsung PC Studio
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"{FFFF6D5C-E2F1-4B40-BC89-8923312E89EB}}_is1" = ACE Mega CoDecS Pack
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Alex Kočičák" = Alex Kočičák
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner (remove only)
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.1.6
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verze 1.60.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NVIDIA Drivers" = NVIDIA Drivers
"PCI Audio Driver" = PCI Audio Driver
"QuickTime" = QuickTime
"Registry Mechanic_is1" = Registry Mechanic 10.0
"Spyware Terminator_is1" = Spyware Terminator
"szn-software-postak" = Seznam Pošťák (Všichni uživatelé tohoto počítače.)
"Totalcmd" = Total Commander (Remove or Repair)
"vghd" = VirtuaGirl HD
"VIA Audio Driver Setup Program" = VIA Audio Driver Setup Program
"Výprava do Květinové země" = Výprava do Květinové země
"WIC" = Windows Imaging Component
"Winamp" = Winamp (remove only)
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
"YInstHelper" = Yahoo! Install Manager

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-515967899-1123561945-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 7.3.2008 14:25:03 | Computer Name = INTELP4 | Source = avast! | ID = 33554522
Description =

Error - 7.3.2008 14:25:03 | Computer Name = INTELP4 | Source = avast! | ID = 33554522
Description =

Error - 7.3.2008 14:28:37 | Computer Name = INTELP4 | Source = avast! | ID = 33554522
Description =

Error - 10.3.2008 12:58:32 | Computer Name = INTELP4 | Source = avast! | ID = 33554522
Description =

Error - 10.3.2008 12:58:43 | Computer Name = INTELP4 | Source = avast! | ID = 33554522
Description =

Error - 10.3.2008 12:58:43 | Computer Name = INTELP4 | Source = avast! | ID = 33554522
Description =

Error - 9.5.2008 6:52:47 | Computer Name = INTELP4 | Source = avast! | ID = 33554522
Description =

Error - 23.11.2008 11:44:28 | Computer Name = INTELP4 | Source = avast! | ID = 33554522
Description =

Error - 4.2.2009 6:48:17 | Computer Name = INTELP4 | Source = avast! | ID = 33554522
Description =

Error - 17.2.2009 8:28:28 | Computer Name = INTELP4 | Source = avast! | ID = 33554522
Description =

[ Application Events ]
Error - 8.12.2011 11:22:02 | Computer Name = INTELP4 | Source = Application Error | ID = 1000
Description = Chybující aplikace iexplore.exe, verze 8.0.6001.18702, chybující modul
mshtml.dll, verze 8.0.6001.18928, adresa chyby 0x00067838.

Error - 17.12.2011 11:02:28 | Computer Name = INTELP4 | Source = Application Error | ID = 1000
Description = Chybující aplikace iexplore.exe, verze 8.0.6001.18702, chybující modul
mshtml.dll, verze 8.0.6001.18928, adresa chyby 0x00067838.

Error - 27.12.2011 4:59:49 | Computer Name = INTELP4 | Source = Application Error | ID = 1000
Description = Chybující aplikace iexplore.exe, verze 8.0.6001.18702, chybující modul
mshtml.dll, verze 8.0.6001.18928, adresa chyby 0x00067838.

Error - 19.1.2012 12:58:51 | Computer Name = INTELP4 | Source = Application Error | ID = 1000
Description = Chybující aplikace , verze 0.0.0.0, chybující modul ntdll.dll, verze
5.1.2600.3520, adresa chyby 0x000119b3.

Error - 19.1.2012 13:01:24 | Computer Name = INTELP4 | Source = Application Error | ID = 1004
Description = Chybující aplikace winlogon.exe, verze 0.0.0.0, chybující modul ntdll.dll,
verze 5.1.2600.3520, adresa chyby 0x000119b3.

Error - 12.2.2012 4:14:51 | Computer Name = INTELP4 | Source = Application Error | ID = 1000
Description = Chybující aplikace iexplore.exe, verze 6.0.2900.5512, chybující modul
urlmon.dll, verze 8.0.6001.18923, adresa chyby 0x0002df76.

Error - 12.2.2012 4:19:17 | Computer Name = INTELP4 | Source = Application Error | ID = 1000
Description = Chybující aplikace iexplore.exe, verze 6.0.2900.5512, chybující modul
urlmon.dll, verze 8.0.6001.18923, adresa chyby 0x0002df76.

Error - 12.2.2012 4:20:53 | Computer Name = INTELP4 | Source = Application Error | ID = 1000
Description = Chybující aplikace iexplore.exe, verze 6.0.2900.5512, chybující modul
urlmon.dll, verze 8.0.6001.18923, adresa chyby 0x0002df76.

Error - 12.2.2012 4:32:42 | Computer Name = INTELP4 | Source = Application Error | ID = 1000
Description = Chybující aplikace iexplore.exe, verze 6.0.2900.5512, chybující modul
urlmon.dll, verze 8.0.6001.18923, adresa chyby 0x0002df76.

Error - 12.2.2012 4:48:13 | Computer Name = INTELP4 | Source = Windows Product Activation | ID = 1010
Description = Licence systému Windows byla obnovena z důvodu chyby systému. Pravděpodobně
bude nutné produkt Windows znovu aktivovat.

[ System Events ]
Error - 12.2.2012 15:05:47 | Computer Name = INTELP4 | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 12.2.2012 15:10:30 | Computer Name = INTELP4 | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 12.2.2012 15:12:20 | Computer Name = INTELP4 | Source = Service Control Manager | ID = 7000
Description = Služba Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS
neuspěla při spuštění v důsledku následující chyby: %%87

Error - 12.2.2012 15:12:20 | Computer Name = INTELP4 | Source = Service Control Manager | ID = 7023
Description = Služba Klient systému NetWare byla ukončena s následující chybou:
%%2

Error - 12.2.2012 16:10:22 | Computer Name = INTELP4 | Source = Service Control Manager | ID = 7000
Description = Služba Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS
neuspěla při spuštění v důsledku následující chyby: %%87

Error - 12.2.2012 16:10:22 | Computer Name = INTELP4 | Source = Service Control Manager | ID = 7023
Description = Služba Klient systému NetWare byla ukončena s následující chybou:
%%2

Error - 13.2.2012 9:39:53 | Computer Name = INTELP4 | Source = Service Control Manager | ID = 7000
Description = Služba Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS
neuspěla při spuštění v důsledku následující chyby: %%87

Error - 13.2.2012 9:39:53 | Computer Name = INTELP4 | Source = Service Control Manager | ID = 7022
Description = Služba avast! Antivirus přestala během spouštění reagovat.

Error - 13.2.2012 9:39:53 | Computer Name = INTELP4 | Source = Service Control Manager | ID = 7023
Description = Služba Klient systému NetWare byla ukončena s následující chybou:
%%2

Error - 13.2.2012 9:40:33 | Computer Name = INTELP4 | Source = Service Control Manager | ID = 7011
Description = Vypršel časový limit (30000 milisekund) čekání na odezvu transakce
služby NVSvc.


< End of report >

Re: prosím o kontrolu logu pomalé PC

Napsal: 13 úno 2012 20:03
od Márty84
Znovu spustte OTL
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

:otl
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163&ilc=12"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://home.juicyaccess.com"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=971163&p="
FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
[2012.02.12 10:08:26 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\628oys85.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
File not found (No name found) -- C:\PROGRAM FILES\DOUBLED\JUICYACCESS TOOLBAR\4.1.4.20920\FFTOOLBAR
File not found (No name found) -- C:\PROGRAM FILES\INTERNET SAVING OPTIMIZER\3.4.0.4340\FF
File not found (No name found) -- C:\PROGRAM FILES\MEDIA ACCESS STARTUP\1.5.0.850\FF
O4 - HKLM..\Run: [DAEMON Tools] C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
[18 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
[23 C:\WINDOWS\$NtServicePackUninstall$\*.tmp files -> C:\WINDOWS\$NtServicePackUninstall$\*.tmp -> ]
[23 C:\WINDOWS\AppPatch\*.tmp files -> C:\WINDOWS\AppPatch\*.tmp -> ]
[18 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[18 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
[9 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[3 C:\WINDOWS\pchealth\helpctr\binaries\*.tmp files -> C:\WINDOWS\pchealth\helpctr\binaries\*.tmp -> ]
[27 C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\*.tmp files -> C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\*.tmp -> ]
[2006.12.30 14:28:33 | 000,001,518 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_16496df1.exe
[2006.12.30 14:28:33 | 000,002,550 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_18be6784.exe
[2006.12.30 14:28:33 | 000,000,766 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_294823.exe
[2006.12.30 14:28:33 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_2cd672ae.exe
[2006.12.30 14:28:33 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_4ae13d6c.exe
[2006.12.30 14:28:33 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Admin\Data aplikací\Microsoft\Installer\{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}\_69525f90.exe
[2012.02.12 21:04:53 | 000,082,794 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2012.02.12 21:04:53 | 000,071,482 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2012.02.12 21:04:53 | 000,437,980 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2012.02.12 21:04:53 | 000,130,252 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2012.02.12 20:22:16 | 000,601,444 | ---- | M] () -- C:\WINDOWS\system32\TZLog.log
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp

:commands
[EMPTYTEMP]
[Purity]
[EMPTYFLASH]
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.