Stránka 1 z 8

Prosím o kontrolu logu

Napsal: 13 říj 2013 12:10
od Claire*
Měla jsem velký problém s viry a nejsem si jistá, jestli je teď pc kompletně čistý. Díky předem.

Logfile of random's system information tool 1.09 (written by random/random)
Run by Admin at 2013-10-13 12:39:22
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 156 GB (66%) free of 238 GB
Total RAM: 894 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:39:44, on 13.10.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\PANDORA.TV\PanService\KMPService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Admin\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Admin.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON SX230 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE /FU "C:\DOCUME~1\Admin\LOCALS~1\Temp\E_S52.tmp" /EF "HKCU"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files\PANDORA.TV\PanService\KMPService.exe

--
End of file - 6436 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ahs68hmw.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/?clid=1"
prefs.js - "keyword.URL" - "http://search.seznam.cz/?sourceid=undefined&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.117 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.40.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ahs68hmw.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ahs68hmw.default\searchplugins\
firmycz.xml
mapycz.xml
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-13 462248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-30 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-13 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-30 266240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2013-07-17 347192]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-06-28 344064]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-11-15 77824]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"EEventManager"=C:\Program Files\Epson Software\Event Manager\EEventManager.exe [2010-10-12 979328]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2013-08-16 152392]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"EPSON SX230 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE [2011-01-21 212480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-06-28 46080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe"="C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe:*:Enabled:KMPProcess"
"C:\Program Files\Epson Software\Event Manager\EEventManager.exe"="C:\Program Files\Epson Software\Event Manager\EEventManager.exe:*:Enabled:EEventManager Application"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv

======List of files/folders created in the last 1 month======

2013-10-13 12:39:24 ----D---- C:\Program Files\trend micro
2013-10-13 12:39:22 ----D---- C:\rsit
2013-10-13 12:16:53 ----D---- C:\Program Files\Microsoft Works
2013-10-13 12:16:37 ----D---- C:\Program Files\Microsoft Visual Studio
2013-10-13 12:16:37 ----D---- C:\Program Files\Common Files\DESIGNER
2013-10-13 12:14:24 ----D---- C:\WINDOWS\SHELLNEW
2013-10-13 12:13:56 ----D---- C:\Program Files\Microsoft Office
2013-10-13 12:13:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2013-10-13 12:13:21 ----RHD---- C:\MSOCache
2013-10-13 12:05:46 ----D---- C:\Documents and Settings\Admin\Data aplikací\PhotoFiltre Studio X
2013-10-13 12:04:21 ----D---- C:\Program Files\Common Files\EPSON
2013-10-13 12:04:06 ----A---- C:\WINDOWS\system32\E_DCINST.DLL
2013-10-13 12:04:03 ----A---- C:\WINDOWS\system32\E_FD4BHKE.DLL
2013-10-13 12:04:02 ----A---- C:\WINDOWS\system32\E_FLBHKE.DLL
2013-10-13 12:03:55 ----D---- C:\WINDOWS\LastGood
2013-10-13 12:01:16 ----D---- C:\Documents and Settings\Admin\Data aplikací\Epson
2013-10-13 11:39:22 ----D---- C:\Program Files\PhotoFiltre Studio X
2013-10-13 11:38:04 ----D---- C:\Program Files\Youtube Downloader HD
2013-10-13 11:38:04 ----D---- C:\Documents and Settings\Admin\Data aplikací\OpenCandy
2013-10-13 11:20:22 ----D---- C:\Program Files\PANDORA.TV
2013-10-13 11:17:26 ----D---- C:\Program Files\The KMPlayer
2013-10-13 11:08:33 ----D---- C:\Documents and Settings\Admin\Data aplikací\Apple Computer
2013-10-13 11:08:09 ----A---- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2013-10-13 11:06:10 ----D---- C:\Program Files\iPod
2013-10-13 11:05:54 ----D---- C:\Program Files\iTunes
2013-10-13 11:05:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2013-10-13 11:05:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-10-13 11:03:16 ----D---- C:\Program Files\Apple Software Update
2013-10-13 11:01:58 ----D---- C:\Program Files\Bonjour
2013-10-13 11:01:01 ----D---- C:\Program Files\Common Files\Apple
2013-10-13 11:01:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2013-10-13 10:38:03 ----A---- C:\WINDOWS\system32\drivers\usbprint.sys
2013-10-13 10:37:52 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2013-10-13 10:29:59 ----D---- C:\Program Files\Common Files\ABBYY
2013-10-13 10:29:59 ----D---- C:\Program Files\ABBYY FineReader 9.0 Sprint
2013-10-13 10:29:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\ABBYY
2013-10-13 10:28:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\UDL
2013-10-13 10:27:10 ----D---- C:\Documents and Settings\Admin\Data aplikací\InstallShield
2013-10-13 10:26:01 ----D---- C:\Program Files\Epson Software
2013-10-13 10:24:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\EPSON
2013-10-13 10:24:40 ----A---- C:\WINDOWS\system32\eswiaud.dll
2013-10-13 10:24:40 ----A---- C:\WINDOWS\system32\esdevapp.exe
2013-10-13 10:24:40 ----A---- C:\WINDOWS\system32\escdev.dll
2013-10-13 10:24:32 ----D---- C:\Program Files\epson
2013-10-13 08:55:50 ----D---- C:\Documents and Settings\Admin\Data aplikací\Malwarebytes
2013-10-13 08:55:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2013-10-13 08:55:43 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2013-10-13 08:55:43 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2013-10-13 00:25:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2013-10-13 00:25:55 ----D---- C:\Program Files\Common Files\Java
2013-10-13 00:25:41 ----A---- C:\WINDOWS\system32\npDeployJava1.dll
2013-10-13 00:25:41 ----A---- C:\WINDOWS\system32\javaws.exe
2013-10-13 00:25:41 ----A---- C:\WINDOWS\system32\deployJava1.dll
2013-10-13 00:25:36 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-10-13 00:25:36 ----A---- C:\WINDOWS\system32\javaw.exe
2013-10-13 00:25:36 ----A---- C:\WINDOWS\system32\java.exe
2013-10-13 00:25:18 ----D---- C:\Program Files\Java
2013-10-13 00:25:07 ----D---- C:\Documents and Settings\Admin\Data aplikací\Sun
2013-10-13 00:22:24 ----D---- C:\Program Files\Common Files\Adobe
2013-10-13 00:22:24 ----D---- C:\Program Files\Adobe
2013-10-13 00:21:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2013-10-13 00:18:04 ----D---- C:\Documents and Settings\Admin\Data aplikací\WinRAR
2013-10-13 00:18:02 ----D---- C:\Program Files\WinRAR
2013-10-13 00:03:28 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2013-10-13 00:03:27 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2013-10-13 00:03:25 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2013-10-13 00:03:23 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2013-10-13 00:03:22 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2013-10-13 00:03:20 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2013-10-13 00:03:19 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2013-10-13 00:03:17 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2013-10-13 00:03:07 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2013-10-13 00:03:07 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2013-10-12 22:22:20 ----D---- C:\Documents and Settings\Admin\Data aplikací\vlc
2013-10-12 22:21:57 ----D---- C:\Program Files\VideoLAN
2013-10-12 22:16:55 ----D---- C:\totalcmd
2013-10-12 22:16:55 ----D---- C:\Documents and Settings\Admin\Data aplikací\GHISLER
2013-10-12 21:34:28 ----A---- C:\WINDOWS\system32\ksuser.dll
2013-10-12 21:34:28 ----A---- C:\WINDOWS\system32\drivers\mstee.sys
2013-10-12 21:34:28 ----A---- C:\WINDOWS\system32\drivers\mspqm.sys
2013-10-12 21:34:28 ----A---- C:\WINDOWS\system32\drivers\mspclock.sys
2013-10-12 21:34:28 ----A---- C:\WINDOWS\system32\drivers\mskssrv.sys
2013-10-12 21:34:20 ----A---- C:\WINDOWS\system32\dxdllreg.exe
2013-10-12 21:29:07 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2013-10-12 21:28:40 ----RA---- C:\WINDOWS\system32\atiiiexx.dll
2013-10-12 21:28:35 ----RA---- C:\WINDOWS\system32\atiicdxx.dat
2013-10-12 21:23:45 ----D---- C:\Program Files\ATI Technologies
2013-10-12 21:23:44 ----A---- C:\WINDOWS\ATICIM.INI
2013-10-12 21:11:56 ----D---- C:\Documents and Settings\Admin\Data aplikací\Avira
2013-10-12 21:02:03 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2013-10-12 21:01:43 ----A---- C:\WINDOWS\system32\drivers\avkmgr.sys
2013-10-12 21:01:42 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2013-10-12 21:01:41 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2013-10-12 21:01:31 ----D---- C:\Program Files\Avira
2013-10-12 21:01:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2013-10-12 20:52:53 ----SHD---- C:\RECYCLER
2013-10-12 20:52:04 ----A---- C:\WINDOWS\system32\h323log.txt
2013-10-12 20:50:42 ----D---- C:\WINDOWS\system32\ReinstallBackups
2013-10-12 20:49:59 ----A---- C:\WINDOWS\system32\drivers\Rtlnic51.sys
2013-10-12 20:49:58 ----D---- C:\WINDOWS\OPTIONS
2013-10-12 20:48:05 ----D---- C:\Program Files\Realtek Sound Manager
2013-10-12 20:48:04 ----N---- C:\WINDOWS\avrack.ini
2013-10-12 20:48:04 ----D---- C:\Program Files\AvRack
2013-10-12 20:48:02 ----N---- C:\WINDOWS\system32\RtlCPAPI.dll
2013-10-12 20:48:02 ----N---- C:\WINDOWS\system32\ChCfg.exe
2013-10-12 20:48:02 ----N---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2013-10-12 20:48:02 ----N---- C:\WINDOWS\soundman.exe
2013-10-12 20:48:01 ----N---- C:\WINDOWS\system32\RTLCPL.exe
2013-10-12 20:48:01 ----N---- C:\WINDOWS\alcupd.exe
2013-10-12 20:48:01 ----N---- C:\WINDOWS\alcrmv.exe
2013-10-12 20:38:48 ----D---- C:\Program Files\DIFX
2013-10-12 20:37:50 ----DC---- C:\WINDOWS\system32\DRVSTORE
2013-10-12 20:37:29 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2013-10-12 20:37:10 ----A---- C:\WINDOWS\system32\hidserv.dll
2013-10-12 20:36:21 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2013-10-12 20:35:55 ----A---- C:\WINDOWS\system32\drivers\RTL8139.sys
2013-10-12 20:35:42 ----A---- C:\WINDOWS\system32\usbui.dll
2013-10-12 20:34:23 ----SHD---- C:\WINDOWS\Installer
2013-10-12 20:34:23 ----D---- C:\Program Files\Common Files\ODBC
2013-10-12 20:34:23 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-10-12 20:34:23 ----A---- C:\WINDOWS\ODBCINST.INI
2013-10-12 20:34:19 ----D---- C:\Program Files\Common Files\SpeechEngines
2013-10-12 20:34:18 ----RD---- C:\Program Files
2013-10-12 20:34:18 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-10-12 20:34:18 ----D---- C:\Program Files\Common Files
2013-10-12 20:34:16 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2013-10-12 20:34:16 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2013-10-12 20:34:16 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdur.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdru.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2013-10-12 20:34:11 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2013-10-12 20:34:11 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2013-10-12 20:34:11 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2013-10-12 20:34:11 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2013-10-12 20:34:11 ----RA---- C:\WINDOWS\system32\kbdest.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdycl.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdsl1.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdsl.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdro.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdpl1.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdpl.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdhu1.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdhu.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdcr.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\KBDAL.DLL
2013-10-12 20:34:08 ----A---- C:\WINDOWS\system32\irclass.dll
2013-10-12 20:34:08 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2013-10-12 20:34:07 ----A---- C:\WINDOWS\system32\spxcoins.dll
2013-10-12 20:34:07 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2013-10-12 20:34:07 ----A---- C:\WINDOWS\system32\dgsetup.dll
2013-10-12 20:34:06 ----A---- C:\WINDOWS\TASKMAN.EXE
2013-10-12 20:34:05 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2013-10-12 20:34:05 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2013-10-12 20:34:05 ----A---- C:\WINDOWS\system32\batt.dll
2013-10-12 20:34:05 ----A---- C:\WINDOWS\NOTEPAD.EXE
2013-10-12 20:34:04 ----A---- C:\WINDOWS\system32\storprop.dll
2013-10-12 20:33:58 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2013-10-12 20:33:54 ----RA---- C:\WINDOWS\SET8.tmp
2013-10-12 20:33:52 ----RA---- C:\WINDOWS\SET4.tmp
2013-10-12 20:33:50 ----RA---- C:\WINDOWS\SET3.tmp
2013-10-12 20:33:47 ----HD---- C:\Program Files\InstallShield Installation Information
2013-10-12 20:33:45 ----D---- C:\WINDOWS\system32\CatRoot2
2013-10-12 20:33:45 ----D---- C:\WINDOWS\system32\CatRoot
2013-10-12 20:33:39 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2013-10-12 20:33:19 ----A---- C:\WINDOWS\setuplog.txt
2013-10-12 20:33:16 ----SHD---- C:\System Volume Information
2013-10-12 20:33:16 ----D---- C:\Documents and Settings
2013-10-12 20:33:16 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2013-10-12 20:32:06 ----SH---- C:\boot.ini
2013-10-12 20:32:06 ----D---- C:\Program Files\Common Files\InstallShield
2013-10-12 20:31:53 ----D---- C:\ATI
2013-10-12 20:24:51 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-10-12 20:24:51 ----RSD---- C:\WINDOWS\Fonts
2013-10-12 20:24:51 ----RD---- C:\WINDOWS\Web
2013-10-12 20:24:51 ----HD---- C:\WINDOWS\inf
2013-10-12 20:24:51 ----D---- C:\WINDOWS\WinSxS
2013-10-12 20:24:51 ----D---- C:\WINDOWS\twain_32
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Temp
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\wins
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\wbem
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\usmt
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\spool
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\ShellExt
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\Setup
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\ras
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\oobe
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\npp
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\mui
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\inetsrv
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\IME
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\icsxml
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\ias
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\export
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\drivers\etc
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\drivers\disdn
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\drivers
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\dhcp
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\cs-cz
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\cs
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\config
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\3com_dmi
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\3076
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\2052
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1054
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1042
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1041
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1037
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1033
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1031
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1029
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1028
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1025
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system
2013-10-12 20:24:51 ----D---- C:\WINDOWS\security
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Resources
2013-10-12 20:24:51 ----D---- C:\WINDOWS\repair
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Provisioning
2013-10-12 20:24:51 ----D---- C:\WINDOWS\pchealth
2013-10-12 20:24:51 ----D---- C:\WINDOWS\PeerNet
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Network Diagnostic
2013-10-12 20:24:51 ----D---- C:\WINDOWS\mui
2013-10-12 20:24:51 ----D---- C:\WINDOWS\msapps
2013-10-12 20:24:51 ----D---- C:\WINDOWS\msagent
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Media
2013-10-12 20:24:51 ----D---- C:\WINDOWS\L2Schemas
2013-10-12 20:24:51 ----D---- C:\WINDOWS\java
2013-10-12 20:24:51 ----D---- C:\WINDOWS\ime
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Help
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Driver Cache
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Debug
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Cursors
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Connection Wizard
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Config
2013-10-12 20:24:51 ----D---- C:\WINDOWS\AppPatch
2013-10-12 20:24:51 ----D---- C:\WINDOWS\addins
2013-10-12 20:24:51 ----D---- C:\WINDOWS
2013-10-12 20:24:51 ----ASH---- C:\pagefile.sys
2013-10-12 20:18:54 ----D---- C:\Documents and Settings\Admin\Data aplikací\Macromedia
2013-10-12 20:18:53 ----D---- C:\Documents and Settings\Admin\Data aplikací\Adobe
2013-10-12 20:14:23 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2013-10-12 20:08:35 ----D---- C:\Documents and Settings\Admin\Data aplikací\Mozilla
2013-10-12 20:07:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\Mozilla
2013-10-12 20:07:55 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-10-12 20:07:51 ----D---- C:\Program Files\Mozilla Firefox
2013-10-12 20:04:31 ----A---- C:\WINDOWS\system32\d3d9caps.dat
2013-10-12 19:48:37 ----D---- C:\Program Files\Google
2013-10-12 19:19:02 ----D---- C:\temp
2013-10-12 19:13:27 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2013-10-12 19:12:52 ----D---- C:\Documents and Settings\Admin\Data aplikací\Identities
2013-10-12 19:12:51 ----HD---- C:\Program Files\Uninstall Information
2013-10-12 19:12:47 ----ASH---- C:\Documents and Settings\Admin\Data aplikací\desktop.ini
2013-10-12 19:12:46 ----SD---- C:\Documents and Settings\Admin\Data aplikací\Microsoft
2013-10-12 19:12:35 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2013-10-12 19:12:33 ----A---- C:\WINDOWS\system32\wpa.bak
2013-10-12 19:11:46 ----D---- C:\WINDOWS\SoftwareDistribution
2013-10-12 19:11:38 ----D---- C:\WINDOWS\Prefetch
2013-10-12 19:11:37 ----SD---- C:\WINDOWS\system32\Microsoft
2013-10-12 19:11:37 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-10-12 19:07:13 ----AS---- C:\WINDOWS\bootstat.dat
2013-10-12 19:05:22 ----D---- C:\WINDOWS\system32\xircom
2013-10-12 19:05:22 ----D---- C:\Program Files\xerox
2013-10-12 19:05:22 ----D---- C:\Program Files\microsoft frontpage
2013-10-12 19:05:14 ----RASH---- C:\MSDOS.SYS
2013-10-12 19:05:14 ----RASH---- C:\IO.SYS
2013-10-12 19:05:14 ----A---- C:\WINDOWS\control.ini
2013-10-12 19:05:14 ----A---- C:\CONFIG.SYS
2013-10-12 19:05:14 ----A---- C:\AUTOEXEC.BAT
2013-10-12 19:05:00 ----A---- C:\WINDOWS\OEWABLog.txt
2013-10-12 19:04:57 ----A---- C:\WINDOWS\system32\mapi32.dll
2013-10-12 19:04:13 ----SD---- C:\WINDOWS\Downloaded Program Files
2013-10-12 19:04:13 ----RD---- C:\WINDOWS\Offline Web Pages
2013-10-12 19:04:05 ----HD---- C:\Program Files\WindowsUpdate
2013-10-12 19:04:01 ----D---- C:\Program Files\Online Services
2013-10-12 19:03:46 ----D---- C:\WINDOWS\system32\DirectX
2013-10-12 19:03:40 ----A---- C:\WINDOWS\system32\atrace.dll
2013-10-12 19:03:37 ----A---- C:\WINDOWS\system32\desktop.ini
2013-10-12 19:03:37 ----A---- C:\WINDOWS\desktop.ini
2013-10-12 19:03:31 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2013-10-12 19:03:30 ----D---- C:\Program Files\Common Files\Services
2013-10-12 19:03:30 ----A---- C:\WINDOWS\system32\acctres.dll
2013-10-12 19:03:28 ----SD---- C:\WINDOWS\Tasks
2013-10-12 19:03:28 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2013-10-12 19:03:27 ----D---- C:\Program Files\Common Files\MSSoap
2013-10-12 19:03:23 ----D---- C:\WINDOWS\srchasst
2013-10-12 19:03:22 ----D---- C:\WINDOWS\system32\Macromed
2013-10-12 19:03:19 ----A---- C:\WINDOWS\system32\wuweb.dll
2013-10-12 19:03:19 ----A---- C:\WINDOWS\system32\wucltui.dll
2013-10-12 19:03:19 ----A---- C:\WINDOWS\system32\wuauserv.dll
2013-10-12 19:03:19 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\wups.dll
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\wuaueng.dll
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\wuauclt.exe
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2013-10-12 19:03:17 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2013-10-12 19:03:17 ----A---- C:\WINDOWS\system32\qmgr.dll
2013-10-12 19:03:17 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2013-10-12 19:03:12 ----D---- C:\Program Files\Movie Maker
2013-10-12 19:02:56 ----A---- C:\WINDOWS\system32\safrslv.dll
2013-10-12 19:02:56 ----A---- C:\WINDOWS\system32\safrdm.dll
2013-10-12 19:02:56 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2013-10-12 19:02:56 ----A---- C:\WINDOWS\system32\racpldlg.dll
2013-10-12 19:02:52 ----A---- C:\WINDOWS\system32\fltMc.exe
2013-10-12 19:02:52 ----A---- C:\WINDOWS\system32\fltlib.dll
2013-10-12 19:02:52 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2013-10-12 19:02:51 ----D---- C:\WINDOWS\system32\Restore
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\srsvc.dll
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\srrstr.dll
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\srclient.dll
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\ils.dll
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2013-10-12 19:02:50 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2013-10-12 19:02:50 ----A---- C:\WINDOWS\system32\msconf.dll
2013-10-12 19:02:50 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2013-10-12 19:02:50 ----A---- C:\WINDOWS\system32\mnmdd.dll
2013-10-12 19:02:48 ----D---- C:\Program Files\NetMeeting
2013-10-12 19:02:48 ----A---- C:\WINDOWS\system32\msoert2.dll
2013-10-12 19:02:47 ----A---- C:\WINDOWS\system32\msoeacct.dll
2013-10-12 19:02:46 ----A---- C:\WINDOWS\system32\inetres.dll
2013-10-12 19:02:46 ----A---- C:\WINDOWS\system32\inetcomm.dll
2013-10-12 19:02:44 ----D---- C:\Program Files\Outlook Express
2013-10-12 19:02:44 ----A---- C:\WINDOWS\system32\schedsvc.dll
2013-10-12 19:02:44 ----A---- C:\WINDOWS\system32\mstinit.exe
2013-10-12 19:02:44 ----A---- C:\WINDOWS\system32\mstask.dll
2013-10-12 19:02:43 ----A---- C:\WINDOWS\system32\isign32.dll
2013-10-12 19:02:43 ----A---- C:\WINDOWS\system32\inetcfg.dll
2013-10-12 19:02:43 ----A---- C:\WINDOWS\system32\icwphbk.dll
2013-10-12 19:02:43 ----A---- C:\WINDOWS\system32\icwdial.dll
2013-10-12 19:02:38 ----D---- C:\Program Files\Common Files\System
2013-10-12 19:02:35 ----D---- C:\Program Files\Internet Explorer
2013-10-12 19:02:33 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2013-10-12 19:02:25 ----D---- C:\Program Files\ComPlus Applications
2013-10-12 19:02:23 ----A---- C:\WINDOWS\vbaddin.ini
2013-10-12 19:02:23 ----A---- C:\WINDOWS\vb.ini
2013-10-12 19:02:19 ----D---- C:\WINDOWS\Registration
2013-10-12 19:01:54 ----D---- C:\Program Files\Windows Media Player
2013-10-12 19:01:49 ----D---- C:\Program Files\Messenger
2013-10-12 19:01:45 ----D---- C:\Program Files\MSN Gaming Zone
2013-10-12 19:01:45 ----A---- C:\WINDOWS\system32\write.exe
2013-10-12 19:01:38 ----A---- C:\WINDOWS\system32\sndvol32.exe
2013-10-12 19:01:38 ----A---- C:\WINDOWS\system32\hticons.dll
2013-10-12 19:01:37 ----A---- C:\WINDOWS\system32\winchat.exe
2013-10-12 19:01:37 ----A---- C:\WINDOWS\system32\avwav.dll
2013-10-12 19:01:37 ----A---- C:\WINDOWS\system32\avtapi.dll
2013-10-12 19:01:37 ----A---- C:\WINDOWS\system32\avmeter.dll
2013-10-12 19:01:32 ----A---- C:\WINDOWS\system32\charmap.exe
2013-10-12 19:01:32 ----A---- C:\WINDOWS\system32\getuname.dll
2013-10-12 19:01:31 ----A---- C:\WINDOWS\system32\winmine.exe
2013-10-12 19:01:31 ----A---- C:\WINDOWS\system32\sol.exe
2013-10-12 19:01:31 ----A---- C:\WINDOWS\system32\mshearts.exe
2013-10-12 19:01:31 ----A---- C:\WINDOWS\system32\freecell.exe
2013-10-12 19:01:31 ----A---- C:\WINDOWS\system32\calc.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\tslabels.ini
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\tskill.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\tscon.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\shadow.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\rwinsta.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\reset.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\regini.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\qwinsta.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\qappsrv.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\msg.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\logoff.exe
2013-10-12 19:01:29 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2013-10-12 19:01:29 ----A---- C:\WINDOWS\system32\cdmodem.dll
2013-10-12 19:01:25 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2013-10-12 19:01:24 ----A---- C:\WINDOWS\system32\sndrec32.exe
2013-10-12 19:01:24 ----A---- C:\WINDOWS\system32\mplay32.exe
2013-10-12 19:01:24 ----A---- C:\WINDOWS\system32\hypertrm.dll
2013-10-12 19:01:24 ----A---- C:\WINDOWS\system32\accwiz.exe
2013-10-12 19:01:23 ----D---- C:\Program Files\Windows NT
2013-10-12 19:01:23 ----A---- C:\WINDOWS\system32\mspaint.exe
2013-10-12 19:01:23 ----A---- C:\WINDOWS\system32\clipbrd.exe
2013-10-12 19:01:22 ----A---- C:\WINDOWS\system32\spider.exe
2013-10-12 19:01:22 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2013-10-12 19:01:22 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2013-10-12 19:01:22 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2013-10-12 19:01:21 ----A---- C:\WINDOWS\system32\tsgqec.dll
2013-10-12 19:01:21 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2013-10-12 19:01:21 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2013-10-12 19:01:21 ----A---- C:\WINDOWS\system32\aaclient.dll
2013-10-12 19:01:20 ----A---- C:\WINDOWS\system32\remotepg.dll
2013-10-12 19:01:20 ----A---- C:\WINDOWS\system32\rdshost.exe
2013-10-12 19:01:20 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2013-10-12 19:01:20 ----A---- C:\WINDOWS\system32\mstscax.dll
2013-10-12 19:01:20 ----A---- C:\WINDOWS\system32\mstsc.exe
2013-10-12 19:01:19 ----D---- C:\WINDOWS\system32\MsDtc
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\termsrv.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\sessmgr.exe
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\rdpclip.exe
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\rdchost.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\qprocess.exe
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\icaapi.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\xolehlp.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\mtxoci.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\msdtctm.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\msdtclog.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\msdtc.exe
2013-10-12 19:01:17 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2013-10-12 19:01:17 ----A---- C:\WINDOWS\system32\mtxex.dll
2013-10-12 19:01:17 ----A---- C:\WINDOWS\system32\mtxdm.dll
2013-10-12 19:01:17 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2013-10-12 19:01:16 ----D---- C:\WINDOWS\system32\Com
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\stclient.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\comrepl.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\comaddin.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\colbact.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\clbcatex.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\catsrvut.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\catsrvps.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\catsrv.dll
2013-10-12 19:01:15 ----A---- C:\WINDOWS\system32\comuid.dll
2013-10-12 19:01:15 ----A---- C:\WINDOWS\system32\comsvcs.dll
2013-10-12 19:01:15 ----A---- C:\WINDOWS\system32\comsnap.dll
2013-10-12 19:01:15 ----A---- C:\WINDOWS\system32\clbcatq.dll
2013-10-12 19:01:09 ----A---- C:\WINDOWS\system32\servdeps.dll
2013-10-12 19:01:09 ----A---- C:\WINDOWS\system32\mmfutil.dll
2013-10-12 19:01:09 ----A---- C:\WINDOWS\system32\licwmi.dll
2013-10-12 19:01:09 ----A---- C:\WINDOWS\system32\cmprops.dll
2013-10-12 19:01:05 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2013-10-12 19:01:05 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys

======List of files/folders modified in the last 1 month======

2013-10-13 12:14:30 ----A---- C:\WINDOWS\win.ini
2013-10-12 20:34:17 ----A---- C:\WINDOWS\system.ini
2013-10-12 19:04:50 ----ASH---- C:\WINDOWS\fonts\desktop.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2013-07-29 136672]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2013-03-06 37352]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2012-08-27 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2013-08-22 88840]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-11-17 2297664]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-06-28 1241088]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 RTL8023;Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver; C:\WINDOWS\system32\DRIVERS\Rtlnic51.sys [2003-12-31 69504]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt []
S3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-14 20992]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2013-07-17 108088]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2013-07-17 84024]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-12-21 57008]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-06-28 376832]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-10-13 182696]
R2 PanService;PandoraService; C:\Program Files\PANDORA.TV\PanService\KMPService.exe [2013-07-08 1922600]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-08-16 553288]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-06-28 516096]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-12 257416]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-09-11 118680]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 AntiVirWebService;Avira Web Protection; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-08-09 815160]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-12 116648]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-12 116648]

-----------------EOF-----------------

Re: Prosím o kontrolu logu

Napsal: 13 říj 2013 13:26
od Márty84
Zdravim :)

:???: S jakymi viry? A jak jste to resila? Jsou ted s pc nejake problemy?

:arrow: Udelejte !!!kompletni!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 15:03
od Claire*
Přesně s jakými viry bohužel netuším, počítač byl poslán k opraváři→ komplet promazání, opětovné nainstalování Win. Zatím bez problémů.

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.10.13.01

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 6.0.2900.5512
Admin :: ADMIN-130349736 [administrátor]

14.10.2013 15:16:17
MBAM-log-2013-10-14 (16-02-57).txt

Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 235765
Uplynulý čas: 45 minut, 53 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 1
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Nebyla provedena žádná instrukce.

Nalezené složky: 2
C:\Documents and Settings\Admin\Data aplikací\OpenCandy (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\Admin\Data aplikací\OpenCandy\607F19A265B34322B0FCD79227F2A7B7 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.

Nalezené soubory: 5
C:\Documents and Settings\Admin\Local Settings\Temp\PIPInstaller_PTV_.exe (PUP.Optional.BundledToolBar.A) -> Nebyla provedena žádná instrukce.
C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4TQ7OH6J\Offercast2802_PTV_[1].exe (PUP.Optional.BundledToolBar.A) -> Nebyla provedena žádná instrukce.
C:\RECYCLER\S-1-5-21-1417001333-2146877963-1801674531-1004\Dc57\cracked amtlib.dll\32-bit\amtlib.dll (PUP.RiskwareTool.CK) -> Nebyla provedena žádná instrukce.
C:\RECYCLER\S-1-5-21-1417001333-2146877963-1801674531-1004\Dc57\cracked amtlib.dll\64-bit\amtlib.dll (PUP.RiskwareTool.CK) -> Nebyla provedena žádná instrukce.
C:\System Volume Information\_restore{0E8B450F-322B-4380-AF53-B6D93FBE360F}\RP12\A0000456.exe (PUP.Optional.OpenCandy.A) -> Nebyla provedena žádná instrukce.

(konec)

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 18:37
od Márty84
Aha, takze s pc problem neni, ale chcete to radeji poradne proverit a mam tedy patrat i hloubeji, chapu to spravne? :)


:arrow: Nalezy MBAM nechte odstranit, pak MBAM odinstalujte.

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Spustte ho.
Kliknete na Scan a program zacne pracovat.
Az skonci, vyplivne na vas log (pokud ne, najdete ho zde C:\AdwCleaner\AdwCleaner[R?].txt ), ten mi sem zkopirujte.

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 18:53
od Claire*
Přesně, už mám s viry hodně špatných zkušeností, tak alespoň na chvíli bych od nich ráda měla pokoj :D
Jen menší dotaz, proč se měl MBAM odinstalovat?

# AdwCleaner v3.007 - Report created 14/10/2013 at 19:50:24
# Updated 09/10/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Admin - ADMIN-130349736
# Running from : C:\Documents and Settings\Admin\Plocha\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

***** [ Browsers ] *****

-\\ Internet Explorer v6.0.2900.5512


-\\ Mozilla Firefox v24.0 (cs)

[ File : C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ahs68hmw.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [937 octets] - [14/10/2013 19:50:24]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [996 octets] ##########

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 18:57
od Márty84
Dobre, tak to projedem poradne :)

Claire* píše:Jen menší dotaz, proč se měl MBAM odinstalovat?
Protoze mate v pc Aviru. Dva antiviry v jednom pc byt nemuzou, tloukli by se.



:arrow: Znovu ukoncete vsechny programy a spustte AdwCleaner.
Tentokrat kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne dalsi log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zase zkopirujte.

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 19:04
od Claire*
Tadá :lol:

# AdwCleaner v3.007 - Report created 14/10/2013 at 20:01:13
# Updated 09/10/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Admin - ADMIN-130349736
# Running from : C:\Documents and Settings\Admin\Plocha\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

***** [ Browsers ] *****

-\\ Internet Explorer v6.0.2900.5512


-\\ Mozilla Firefox v24.0 (cs)

[ File : C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ahs68hmw.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [1075 octets] - [14/10/2013 19:50:24]
AdwCleaner[R1].txt - [1136 octets] - [14/10/2013 20:00:23]
AdwCleaner[S0].txt - [1064 octets] - [14/10/2013 20:01:13]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1124 octets] ##########

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 19:06
od Márty84
:)

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe , ulozte ho na plochu a spustte.
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Zprava a objevi se log. Ten mi sem vlozte

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 19:12
od Claire*
RogueKiller V8.7.2 [Oct 3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v : Normální režim
Uživatel : Admin [Práva správce]
Mód : Kontrola -- Datum : 10/14/2013 20:11:28
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 2 ¤¤¤
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
[EXT RUN][ROGUE ST] HKLM\ON_E:\[...]\Run : 8360 (C:\pbepbhhg.exe) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
[Address] SSDT[25] : NtClose @ 0x805B1C3A -> HOOKED (Unknown @ 0xF7AE406C)
[Address] SSDT[41] : NtCreateKey @ 0x8061A286 -> HOOKED (Unknown @ 0xF7AE4026)
[Address] SSDT[50] : NtCreateSection @ 0x805A06EC -> HOOKED (Unknown @ 0xF7AE4076)
[Address] SSDT[53] : NtCreateThread @ 0x805C7208 -> HOOKED (Unknown @ 0xF7AE401C)
[Address] SSDT[63] : NtDeleteKey @ 0x8061A716 -> HOOKED (Unknown @ 0xF7AE402B)
[Address] SSDT[65] : NtDeleteValueKey @ 0x8061A8E6 -> HOOKED (Unknown @ 0xF7AE4035)
[Address] SSDT[68] : NtDuplicateObject @ 0x805B384E -> HOOKED (Unknown @ 0xF7AE4067)
[Address] SSDT[98] : NtLoadKey @ 0x8061C482 -> HOOKED (Unknown @ 0xF7AE403A)
[Address] SSDT[122] : NtOpenProcess @ 0x805C1296 -> HOOKED (Unknown @ 0xF7AE4008)
[Address] SSDT[128] : NtOpenThread @ 0x805C1522 -> HOOKED (Unknown @ 0xF7AE400D)
[Address] SSDT[177] : NtQueryValueKey @ 0x806184BE -> HOOKED (Unknown @ 0xF7AE408F)
[Address] SSDT[193] : NtReplaceKey @ 0x8061C332 -> HOOKED (Unknown @ 0xF7AE4044)
[Address] SSDT[200] : NtRequestWaitReplyPort @ 0x8059808E -> HOOKED (Unknown @ 0xF7AE4080)
[Address] SSDT[204] : NtRestoreKey @ 0x8061BC3E -> HOOKED (Unknown @ 0xF7AE403F)
[Address] SSDT[213] : NtSetContextThread @ 0x805C792A -> HOOKED (Unknown @ 0xF7AE407B)
[Address] SSDT[237] : NtSetSecurityObject @ 0x805B5FC0 -> HOOKED (Unknown @ 0xF7AE4085)
[Address] SSDT[247] : NtSetValueKey @ 0x8061880C -> HOOKED (Unknown @ 0xF7AE4030)
[Address] SSDT[255] : NtSystemDebugControl @ 0x8060E1DA -> HOOKED (Unknown @ 0xF7AE408A)
[Address] SSDT[257] : NtTerminateProcess @ 0x805C8C2A -> HOOKED (Unknown @ 0xF7AE4017)
[Address] Shadow SSDT[549] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0xF7AE409E)
[Address] Shadow SSDT[552] : NtUserSetWinEventHook -> HOOKED (Unknown @ 0xF7AE40A3)

¤¤¤ Externí včelstvo: ¤¤¤
-> E:\windows\system32\config\SYSTEM | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\SOFTWARE | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\SECURITY | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\SAM | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\DEFAULT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\Default User\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\All Users\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]
-> E:\Documents and Settings\NetworkService\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\LocalService\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\Šárka\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - WDC WD2500AAKX-001CA0 +++++
--- User ---
[MBR] 7fb2926d047c4900e5fd74949e74c507
[BSP] d1179404c374f89d18b4716e81fae5d4 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 238464 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) (Standardní diskové jednotky) - HDT722516DLAT80 +++++
--- User ---
[MBR] c099a000fb5ce058f226ad2d9a9bccfc
[BSP] 527c6e6740066ccf85d9bf86f5ffa4f1 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 63 | Size: 154021 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_10142013_201128.txt >>

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 19:15
od Márty84
:arrow: Znovu spustte RogueKiller (pokud jste ho jeste nezavrel/a, rovnou kliknete na napis Smazat)
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Smazat.
Pak kliknete na napis Zprava a objevi se log. Ten mi sem vlozte.
Pak kliknete na napis Oprava Host a Zprava.
Objevi se dalsi log. I ten mi sem vlozte.

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 19:19
od Claire*
RogueKiller V8.7.2 [Oct 3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v : Normální režim
Uživatel : Admin [Práva správce]
Mód : Odebrat -- Datum : 10/14/2013 20:17:28
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 0 ¤¤¤

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
[Address] SSDT[25] : NtClose @ 0x805B1C3A -> HOOKED (Unknown @ 0xF7AE406C)
[Address] SSDT[41] : NtCreateKey @ 0x8061A286 -> HOOKED (Unknown @ 0xF7AE4026)
[Address] SSDT[50] : NtCreateSection @ 0x805A06EC -> HOOKED (Unknown @ 0xF7AE4076)
[Address] SSDT[53] : NtCreateThread @ 0x805C7208 -> HOOKED (Unknown @ 0xF7AE401C)
[Address] SSDT[63] : NtDeleteKey @ 0x8061A716 -> HOOKED (Unknown @ 0xF7AE402B)
[Address] SSDT[65] : NtDeleteValueKey @ 0x8061A8E6 -> HOOKED (Unknown @ 0xF7AE4035)
[Address] SSDT[68] : NtDuplicateObject @ 0x805B384E -> HOOKED (Unknown @ 0xF7AE4067)
[Address] SSDT[98] : NtLoadKey @ 0x8061C482 -> HOOKED (Unknown @ 0xF7AE403A)
[Address] SSDT[122] : NtOpenProcess @ 0x805C1296 -> HOOKED (Unknown @ 0xF7AE4008)
[Address] SSDT[128] : NtOpenThread @ 0x805C1522 -> HOOKED (Unknown @ 0xF7AE400D)
[Address] SSDT[177] : NtQueryValueKey @ 0x806184BE -> HOOKED (Unknown @ 0xF7AE408F)
[Address] SSDT[193] : NtReplaceKey @ 0x8061C332 -> HOOKED (Unknown @ 0xF7AE4044)
[Address] SSDT[200] : NtRequestWaitReplyPort @ 0x8059808E -> HOOKED (Unknown @ 0xF7AE4080)
[Address] SSDT[204] : NtRestoreKey @ 0x8061BC3E -> HOOKED (Unknown @ 0xF7AE403F)
[Address] SSDT[213] : NtSetContextThread @ 0x805C792A -> HOOKED (Unknown @ 0xF7AE407B)
[Address] SSDT[237] : NtSetSecurityObject @ 0x805B5FC0 -> HOOKED (Unknown @ 0xF7AE4085)
[Address] SSDT[247] : NtSetValueKey @ 0x8061880C -> HOOKED (Unknown @ 0xF7AE4030)
[Address] SSDT[255] : NtSystemDebugControl @ 0x8060E1DA -> HOOKED (Unknown @ 0xF7AE408A)
[Address] SSDT[257] : NtTerminateProcess @ 0x805C8C2A -> HOOKED (Unknown @ 0xF7AE4017)
[Address] Shadow SSDT[549] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0xF7AE409E)
[Address] Shadow SSDT[552] : NtUserSetWinEventHook -> HOOKED (Unknown @ 0xF7AE40A3)

¤¤¤ Externí včelstvo: ¤¤¤
-> E:\windows\system32\config\SYSTEM | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\SOFTWARE | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\SECURITY | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\SAM | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\DEFAULT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\Default User\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\All Users\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]
-> E:\Documents and Settings\NetworkService\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\LocalService\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\Šárka\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - WDC WD2500AAKX-001CA0 +++++
--- User ---
[MBR] 7fb2926d047c4900e5fd74949e74c507
[BSP] d1179404c374f89d18b4716e81fae5d4 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 238464 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) (Standardní diskové jednotky) - HDT722516DLAT80 +++++
--- User ---
[MBR] c099a000fb5ce058f226ad2d9a9bccfc
[BSP] 527c6e6740066ccf85d9bf86f5ffa4f1 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 63 | Size: 154021 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_10142013_201728.txt >>
RKreport[0]_D_10142013_201619.txt;RKreport[0]_S_10142013_201128.txt;RKreport[0]_S_10142013_201718.txt


RogueKiller V8.7.2 [Oct 3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v : Normální režim
Uživatel : Admin [Práva správce]
Mód : Oprava HOSTS -- Datum : 10/14/2013 20:17:48
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 0 ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤
-> E:\windows\system32\config\SYSTEM | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\SOFTWARE | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\SECURITY | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\SAM | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\windows\system32\config\DEFAULT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\Default User\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\All Users\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]
-> E:\Documents and Settings\NetworkService\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\LocalService\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> E:\Documents and Settings\Šárka\NTUSER.DAT | DRVINFO [Drv - E:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ Resetovaný HOSTS: ¤¤¤


Dokončeno : << RKreport[0]_H_10142013_201748.txt >>
RKreport[0]_D_10142013_201619.txt;RKreport[0]_D_10142013_201728.txt;RKreport[0]_S_10142013_201128.txt
RKreport[0]_S_10142013_201718.txt



:arrow: soubor HOST byl pak zakázán Avirou

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 19:21
od Márty84
Avira mozna remcala, ale RK stejne provedl co mel :D



:!: Pokud nemate, zazalohujte si radeji dulezita data (fotky, dokumenty, atd.) :!:

:!: Nepouzivejte ComboFix bez predchozi domluvy! Je to poruseni pravidel fora a ztratite tim narok na pomoc!

:arrow: Stahnete ComboFix http://download.bleepingcomputer.com/sUBs/ComboFix.exe a ulozte ho na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Spustte ComboFix.
Odsouhlaste licencni podminky a nechte program pracovat. Jestli vam nabidne instalaci Konzoly pro zotaveni, souhlaste.
Po dobu skenu nic nespoustejte, nikam neklikejte.
Po dokonceni skenovani (muze dojit i k restartu pc) by se mel vytvorit log, ktery bude umisteny zde C:\ComboFix.txt
Jeho obsah sem zkopirujte

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 19:25
od Claire*
Tak na tohle počkám, až bude víc času a konečně si seženu exterňák :D
Ale prohnala jsem disk Avirou a znovu se jí něco nelíbilo, mám složky/soubory co našla, smazat z karantény?

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 19:28
od Márty84
:???: Muzete mi sem zkopirovat, pripadne opsat, ci vyfotit, co se Avire nelibilo?

:arrow: Kdyz si tedy zatim na CF netroufate, dejte mi sem novy log z RSIT

a k tomu

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe , ulozte na plochu a spustte.
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).

Re: Prosím o kontrolu logu

Napsal: 14 říj 2013 19:35
od Claire*
Bylo by to na dlouho a tolik času nemám, tak jsem to zatim zvládla tak do 41%, ale i tak něco našla (všechno má stejný název, je jich přes 100).
Obrázek

plus
Logfile of random's system information tool 1.09 (written by random/random)
Run by Admin at 2013-10-14 20:36:36
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 158 GB (66%) free of 238 GB
Total RAM: 894 MB (39% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:36:43, on 14.10.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE
C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Admin\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\Admin.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON SX230 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE /FU "C:\DOCUME~1\Admin\LOCALS~1\Temp\E_S52.tmp" /EF "HKCU"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 6969 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ahs68hmw.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/?clid=1"
prefs.js - "keyword.URL" - "http://search.seznam.cz/?sourceid=undefined&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.117 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.40.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ahs68hmw.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ahs68hmw.default\searchplugins\
firmycz.xml
mapycz.xml
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-13 462248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-30 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-13 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-03-30 266240]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2013-07-17 347192]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-06-28 344064]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-11-15 77824]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"EEventManager"=C:\Program Files\Epson Software\Event Manager\EEventManager.exe [2010-10-12 979328]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2013-08-16 152392]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"EPSON SX230 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHKE.EXE [2011-01-21 212480]
"AdobeBridge"= []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-06-28 46080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Epson Software\Event Manager\EEventManager.exe"="C:\Program Files\Epson Software\Event Manager\EEventManager.exe:*:Enabled:EEventManager Application"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe"="C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe:*:Enabled:KMPProcess"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv

======List of files/folders created in the last 1 month======

2013-10-14 19:50:21 ----D---- C:\AdwCleaner
2013-10-14 17:57:57 ----D---- C:\WINDOWS\system32\NtmsData
2013-10-14 15:15:56 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2013-10-13 21:01:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\regid.1986-12.com.adobe
2013-10-13 20:49:46 ----AH---- C:\WINDOWS\system32\mlfcache.dat
2013-10-13 13:54:40 ----A---- C:\WINDOWS\EEventManager.INI
2013-10-13 12:39:24 ----D---- C:\Program Files\trend micro
2013-10-13 12:39:22 ----D---- C:\rsit
2013-10-13 12:16:53 ----D---- C:\Program Files\Microsoft Works
2013-10-13 12:16:37 ----D---- C:\Program Files\Microsoft Visual Studio
2013-10-13 12:16:37 ----D---- C:\Program Files\Common Files\DESIGNER
2013-10-13 12:14:24 ----D---- C:\WINDOWS\SHELLNEW
2013-10-13 12:13:56 ----D---- C:\Program Files\Microsoft Office
2013-10-13 12:13:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2013-10-13 12:13:21 ----RHD---- C:\MSOCache
2013-10-13 12:05:46 ----D---- C:\Documents and Settings\Admin\Data aplikací\PhotoFiltre Studio X
2013-10-13 12:04:21 ----D---- C:\Program Files\Common Files\EPSON
2013-10-13 12:04:06 ----A---- C:\WINDOWS\system32\E_DCINST.DLL
2013-10-13 12:04:03 ----A---- C:\WINDOWS\system32\E_FD4BHKE.DLL
2013-10-13 12:04:02 ----A---- C:\WINDOWS\system32\E_FLBHKE.DLL
2013-10-13 12:01:16 ----D---- C:\Documents and Settings\Admin\Data aplikací\Epson
2013-10-13 11:39:22 ----D---- C:\Program Files\PhotoFiltre Studio X
2013-10-13 11:38:04 ----D---- C:\Program Files\Youtube Downloader HD
2013-10-13 11:17:26 ----D---- C:\Program Files\The KMPlayer
2013-10-13 11:08:33 ----D---- C:\Documents and Settings\Admin\Data aplikací\Apple Computer
2013-10-13 11:08:09 ----A---- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2013-10-13 11:06:10 ----D---- C:\Program Files\iPod
2013-10-13 11:05:54 ----D---- C:\Program Files\iTunes
2013-10-13 11:05:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2013-10-13 11:05:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-10-13 11:03:16 ----D---- C:\Program Files\Apple Software Update
2013-10-13 11:01:58 ----D---- C:\Program Files\Bonjour
2013-10-13 11:01:01 ----D---- C:\Program Files\Common Files\Apple
2013-10-13 11:01:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2013-10-13 10:38:03 ----A---- C:\WINDOWS\system32\drivers\usbprint.sys
2013-10-13 10:37:52 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2013-10-13 10:29:59 ----D---- C:\Program Files\Common Files\ABBYY
2013-10-13 10:29:59 ----D---- C:\Program Files\ABBYY FineReader 9.0 Sprint
2013-10-13 10:29:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\ABBYY
2013-10-13 10:28:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\UDL
2013-10-13 10:27:10 ----D---- C:\Documents and Settings\Admin\Data aplikací\InstallShield
2013-10-13 10:26:01 ----D---- C:\Program Files\Epson Software
2013-10-13 10:24:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\EPSON
2013-10-13 10:24:40 ----A---- C:\WINDOWS\system32\eswiaud.dll
2013-10-13 10:24:40 ----A---- C:\WINDOWS\system32\esdevapp.exe
2013-10-13 10:24:40 ----A---- C:\WINDOWS\system32\escdev.dll
2013-10-13 10:24:32 ----D---- C:\Program Files\epson
2013-10-13 08:55:50 ----D---- C:\Documents and Settings\Admin\Data aplikací\Malwarebytes
2013-10-13 08:55:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2013-10-13 00:25:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2013-10-13 00:25:55 ----D---- C:\Program Files\Common Files\Java
2013-10-13 00:25:41 ----A---- C:\WINDOWS\system32\npDeployJava1.dll
2013-10-13 00:25:41 ----A---- C:\WINDOWS\system32\javaws.exe
2013-10-13 00:25:41 ----A---- C:\WINDOWS\system32\deployJava1.dll
2013-10-13 00:25:36 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-10-13 00:25:36 ----A---- C:\WINDOWS\system32\javaw.exe
2013-10-13 00:25:36 ----A---- C:\WINDOWS\system32\java.exe
2013-10-13 00:25:18 ----D---- C:\Program Files\Java
2013-10-13 00:25:07 ----D---- C:\Documents and Settings\Admin\Data aplikací\Sun
2013-10-13 00:22:24 ----D---- C:\Program Files\Common Files\Adobe
2013-10-13 00:22:24 ----D---- C:\Program Files\Adobe
2013-10-13 00:21:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2013-10-13 00:18:04 ----D---- C:\Documents and Settings\Admin\Data aplikací\WinRAR
2013-10-13 00:18:02 ----D---- C:\Program Files\WinRAR
2013-10-13 00:03:28 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2013-10-13 00:03:27 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2013-10-13 00:03:25 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2013-10-13 00:03:23 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2013-10-13 00:03:22 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2013-10-13 00:03:20 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2013-10-13 00:03:19 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2013-10-13 00:03:17 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2013-10-13 00:03:07 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2013-10-13 00:03:07 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2013-10-12 22:22:20 ----D---- C:\Documents and Settings\Admin\Data aplikací\vlc
2013-10-12 22:21:57 ----D---- C:\Program Files\VideoLAN
2013-10-12 22:16:55 ----D---- C:\totalcmd
2013-10-12 22:16:55 ----D---- C:\Documents and Settings\Admin\Data aplikací\GHISLER
2013-10-12 21:34:28 ----A---- C:\WINDOWS\system32\ksuser.dll
2013-10-12 21:34:28 ----A---- C:\WINDOWS\system32\drivers\mstee.sys
2013-10-12 21:34:28 ----A---- C:\WINDOWS\system32\drivers\mspqm.sys
2013-10-12 21:34:28 ----A---- C:\WINDOWS\system32\drivers\mspclock.sys
2013-10-12 21:34:28 ----A---- C:\WINDOWS\system32\drivers\mskssrv.sys
2013-10-12 21:34:20 ----A---- C:\WINDOWS\system32\dxdllreg.exe
2013-10-12 21:29:07 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2013-10-12 21:28:40 ----RA---- C:\WINDOWS\system32\atiiiexx.dll
2013-10-12 21:28:35 ----RA---- C:\WINDOWS\system32\atiicdxx.dat
2013-10-12 21:23:45 ----D---- C:\Program Files\ATI Technologies
2013-10-12 21:23:44 ----A---- C:\WINDOWS\ATICIM.INI
2013-10-12 21:11:56 ----D---- C:\Documents and Settings\Admin\Data aplikací\Avira
2013-10-12 21:02:03 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2013-10-12 21:01:43 ----A---- C:\WINDOWS\system32\drivers\avkmgr.sys
2013-10-12 21:01:42 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2013-10-12 21:01:41 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2013-10-12 21:01:31 ----D---- C:\Program Files\Avira
2013-10-12 21:01:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2013-10-12 20:52:53 ----SHD---- C:\RECYCLER
2013-10-12 20:52:04 ----A---- C:\WINDOWS\system32\h323log.txt
2013-10-12 20:50:42 ----D---- C:\WINDOWS\system32\ReinstallBackups
2013-10-12 20:49:59 ----A---- C:\WINDOWS\system32\drivers\Rtlnic51.sys
2013-10-12 20:49:58 ----D---- C:\WINDOWS\OPTIONS
2013-10-12 20:48:05 ----D---- C:\Program Files\Realtek Sound Manager
2013-10-12 20:48:04 ----N---- C:\WINDOWS\avrack.ini
2013-10-12 20:48:04 ----D---- C:\Program Files\AvRack
2013-10-12 20:48:02 ----N---- C:\WINDOWS\system32\RtlCPAPI.dll
2013-10-12 20:48:02 ----N---- C:\WINDOWS\system32\ChCfg.exe
2013-10-12 20:48:02 ----N---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2013-10-12 20:48:02 ----N---- C:\WINDOWS\soundman.exe
2013-10-12 20:48:01 ----N---- C:\WINDOWS\system32\RTLCPL.exe
2013-10-12 20:48:01 ----N---- C:\WINDOWS\alcupd.exe
2013-10-12 20:48:01 ----N---- C:\WINDOWS\alcrmv.exe
2013-10-12 20:38:48 ----D---- C:\Program Files\DIFX
2013-10-12 20:37:50 ----DC---- C:\WINDOWS\system32\DRVSTORE
2013-10-12 20:37:29 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2013-10-12 20:37:10 ----A---- C:\WINDOWS\system32\hidserv.dll
2013-10-12 20:36:21 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2013-10-12 20:35:55 ----A---- C:\WINDOWS\system32\drivers\RTL8139.sys
2013-10-12 20:35:42 ----A---- C:\WINDOWS\system32\usbui.dll
2013-10-12 20:34:23 ----SHD---- C:\WINDOWS\Installer
2013-10-12 20:34:23 ----D---- C:\Program Files\Common Files\ODBC
2013-10-12 20:34:23 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-10-12 20:34:23 ----A---- C:\WINDOWS\ODBCINST.INI
2013-10-12 20:34:19 ----D---- C:\Program Files\Common Files\SpeechEngines
2013-10-12 20:34:18 ----RD---- C:\Program Files
2013-10-12 20:34:18 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-10-12 20:34:18 ----D---- C:\Program Files\Common Files
2013-10-12 20:34:16 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2013-10-12 20:34:16 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2013-10-12 20:34:16 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdur.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdru.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2013-10-12 20:34:14 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2013-10-12 20:34:13 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2013-10-12 20:34:11 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2013-10-12 20:34:11 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2013-10-12 20:34:11 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2013-10-12 20:34:11 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2013-10-12 20:34:11 ----RA---- C:\WINDOWS\system32\kbdest.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdycl.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdsl1.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdsl.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdro.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdpl1.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdpl.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdhu1.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdhu.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\kbdcr.dll
2013-10-12 20:34:09 ----A---- C:\WINDOWS\system32\KBDAL.DLL
2013-10-12 20:34:08 ----A---- C:\WINDOWS\system32\irclass.dll
2013-10-12 20:34:08 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2013-10-12 20:34:07 ----A---- C:\WINDOWS\system32\spxcoins.dll
2013-10-12 20:34:07 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2013-10-12 20:34:07 ----A---- C:\WINDOWS\system32\dgsetup.dll
2013-10-12 20:34:06 ----A---- C:\WINDOWS\TASKMAN.EXE
2013-10-12 20:34:05 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2013-10-12 20:34:05 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2013-10-12 20:34:05 ----A---- C:\WINDOWS\system32\batt.dll
2013-10-12 20:34:05 ----A---- C:\WINDOWS\NOTEPAD.EXE
2013-10-12 20:34:04 ----A---- C:\WINDOWS\system32\storprop.dll
2013-10-12 20:33:58 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2013-10-12 20:33:54 ----RA---- C:\WINDOWS\SET8.tmp
2013-10-12 20:33:52 ----RA---- C:\WINDOWS\SET4.tmp
2013-10-12 20:33:50 ----RA---- C:\WINDOWS\SET3.tmp
2013-10-12 20:33:47 ----HD---- C:\Program Files\InstallShield Installation Information
2013-10-12 20:33:45 ----D---- C:\WINDOWS\system32\CatRoot2
2013-10-12 20:33:45 ----D---- C:\WINDOWS\system32\CatRoot
2013-10-12 20:33:39 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2013-10-12 20:33:19 ----A---- C:\WINDOWS\setuplog.txt
2013-10-12 20:33:16 ----SHD---- C:\System Volume Information
2013-10-12 20:33:16 ----D---- C:\Documents and Settings
2013-10-12 20:33:16 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2013-10-12 20:32:06 ----SH---- C:\boot.ini
2013-10-12 20:32:06 ----D---- C:\Program Files\Common Files\InstallShield
2013-10-12 20:31:53 ----D---- C:\ATI
2013-10-12 20:24:51 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-10-12 20:24:51 ----RSD---- C:\WINDOWS\Fonts
2013-10-12 20:24:51 ----RD---- C:\WINDOWS\Web
2013-10-12 20:24:51 ----HD---- C:\WINDOWS\inf
2013-10-12 20:24:51 ----D---- C:\WINDOWS\WinSxS
2013-10-12 20:24:51 ----D---- C:\WINDOWS\twain_32
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Temp
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\wins
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\wbem
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\usmt
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\spool
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\ShellExt
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\Setup
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\ras
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\oobe
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\npp
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\mui
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\inetsrv
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\IME
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\icsxml
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\ias
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\export
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\drivers\etc
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\drivers\disdn
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\drivers
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\dhcp
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\cs-cz
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\cs
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\config
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\3com_dmi
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\3076
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\2052
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1054
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1042
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1041
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1037
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1033
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1031
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1029
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1028
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32\1025
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system32
2013-10-12 20:24:51 ----D---- C:\WINDOWS\system
2013-10-12 20:24:51 ----D---- C:\WINDOWS\security
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Resources
2013-10-12 20:24:51 ----D---- C:\WINDOWS\repair
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Provisioning
2013-10-12 20:24:51 ----D---- C:\WINDOWS\pchealth
2013-10-12 20:24:51 ----D---- C:\WINDOWS\PeerNet
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Network Diagnostic
2013-10-12 20:24:51 ----D---- C:\WINDOWS\mui
2013-10-12 20:24:51 ----D---- C:\WINDOWS\msapps
2013-10-12 20:24:51 ----D---- C:\WINDOWS\msagent
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Media
2013-10-12 20:24:51 ----D---- C:\WINDOWS\L2Schemas
2013-10-12 20:24:51 ----D---- C:\WINDOWS\java
2013-10-12 20:24:51 ----D---- C:\WINDOWS\ime
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Help
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Driver Cache
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Debug
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Cursors
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Connection Wizard
2013-10-12 20:24:51 ----D---- C:\WINDOWS\Config
2013-10-12 20:24:51 ----D---- C:\WINDOWS\AppPatch
2013-10-12 20:24:51 ----D---- C:\WINDOWS\addins
2013-10-12 20:24:51 ----D---- C:\WINDOWS
2013-10-12 20:24:51 ----ASH---- C:\pagefile.sys
2013-10-12 20:18:54 ----D---- C:\Documents and Settings\Admin\Data aplikací\Macromedia
2013-10-12 20:18:53 ----D---- C:\Documents and Settings\Admin\Data aplikací\Adobe
2013-10-12 20:14:23 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2013-10-12 20:08:35 ----D---- C:\Documents and Settings\Admin\Data aplikací\Mozilla
2013-10-12 20:07:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\Mozilla
2013-10-12 20:07:55 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-10-12 20:07:51 ----D---- C:\Program Files\Mozilla Firefox
2013-10-12 20:04:31 ----A---- C:\WINDOWS\system32\d3d9caps.dat
2013-10-12 19:48:37 ----D---- C:\Program Files\Google
2013-10-12 19:19:02 ----D---- C:\temp
2013-10-12 19:13:27 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2013-10-12 19:12:52 ----D---- C:\Documents and Settings\Admin\Data aplikací\Identities
2013-10-12 19:12:51 ----HD---- C:\Program Files\Uninstall Information
2013-10-12 19:12:47 ----ASH---- C:\Documents and Settings\Admin\Data aplikací\desktop.ini
2013-10-12 19:12:46 ----SD---- C:\Documents and Settings\Admin\Data aplikací\Microsoft
2013-10-12 19:12:35 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2013-10-12 19:12:33 ----A---- C:\WINDOWS\system32\wpa.bak
2013-10-12 19:11:46 ----D---- C:\WINDOWS\SoftwareDistribution
2013-10-12 19:11:38 ----D---- C:\WINDOWS\Prefetch
2013-10-12 19:11:37 ----SD---- C:\WINDOWS\system32\Microsoft
2013-10-12 19:11:37 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-10-12 19:07:13 ----AS---- C:\WINDOWS\bootstat.dat
2013-10-12 19:05:22 ----D---- C:\WINDOWS\system32\xircom
2013-10-12 19:05:22 ----D---- C:\Program Files\xerox
2013-10-12 19:05:22 ----D---- C:\Program Files\microsoft frontpage
2013-10-12 19:05:14 ----RASH---- C:\MSDOS.SYS
2013-10-12 19:05:14 ----RASH---- C:\IO.SYS
2013-10-12 19:05:14 ----A---- C:\WINDOWS\control.ini
2013-10-12 19:05:14 ----A---- C:\CONFIG.SYS
2013-10-12 19:05:14 ----A---- C:\AUTOEXEC.BAT
2013-10-12 19:05:00 ----A---- C:\WINDOWS\OEWABLog.txt
2013-10-12 19:04:57 ----A---- C:\WINDOWS\system32\mapi32.dll
2013-10-12 19:04:13 ----SD---- C:\WINDOWS\Downloaded Program Files
2013-10-12 19:04:13 ----RD---- C:\WINDOWS\Offline Web Pages
2013-10-12 19:04:05 ----HD---- C:\Program Files\WindowsUpdate
2013-10-12 19:04:01 ----D---- C:\Program Files\Online Services
2013-10-12 19:03:46 ----D---- C:\WINDOWS\system32\DirectX
2013-10-12 19:03:40 ----A---- C:\WINDOWS\system32\atrace.dll
2013-10-12 19:03:37 ----A---- C:\WINDOWS\system32\desktop.ini
2013-10-12 19:03:37 ----A---- C:\WINDOWS\desktop.ini
2013-10-12 19:03:31 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2013-10-12 19:03:30 ----D---- C:\Program Files\Common Files\Services
2013-10-12 19:03:30 ----A---- C:\WINDOWS\system32\acctres.dll
2013-10-12 19:03:28 ----SD---- C:\WINDOWS\Tasks
2013-10-12 19:03:28 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2013-10-12 19:03:27 ----D---- C:\Program Files\Common Files\MSSoap
2013-10-12 19:03:23 ----D---- C:\WINDOWS\srchasst
2013-10-12 19:03:22 ----D---- C:\WINDOWS\system32\Macromed
2013-10-12 19:03:19 ----A---- C:\WINDOWS\system32\wuweb.dll
2013-10-12 19:03:19 ----A---- C:\WINDOWS\system32\wucltui.dll
2013-10-12 19:03:19 ----A---- C:\WINDOWS\system32\wuauserv.dll
2013-10-12 19:03:19 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\wups.dll
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\wuaueng.dll
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\wuauclt.exe
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\wuapi.dll
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2013-10-12 19:03:18 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2013-10-12 19:03:17 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2013-10-12 19:03:17 ----A---- C:\WINDOWS\system32\qmgr.dll
2013-10-12 19:03:17 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2013-10-12 19:03:12 ----D---- C:\Program Files\Movie Maker
2013-10-12 19:02:56 ----A---- C:\WINDOWS\system32\safrslv.dll
2013-10-12 19:02:56 ----A---- C:\WINDOWS\system32\safrdm.dll
2013-10-12 19:02:56 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2013-10-12 19:02:56 ----A---- C:\WINDOWS\system32\racpldlg.dll
2013-10-12 19:02:52 ----A---- C:\WINDOWS\system32\fltMc.exe
2013-10-12 19:02:52 ----A---- C:\WINDOWS\system32\fltlib.dll
2013-10-12 19:02:52 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2013-10-12 19:02:51 ----D---- C:\WINDOWS\system32\Restore
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\srsvc.dll
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\srrstr.dll
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\srclient.dll
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\ils.dll
2013-10-12 19:02:51 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2013-10-12 19:02:50 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2013-10-12 19:02:50 ----A---- C:\WINDOWS\system32\msconf.dll
2013-10-12 19:02:50 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2013-10-12 19:02:50 ----A---- C:\WINDOWS\system32\mnmdd.dll
2013-10-12 19:02:48 ----D---- C:\Program Files\NetMeeting
2013-10-12 19:02:48 ----A---- C:\WINDOWS\system32\msoert2.dll
2013-10-12 19:02:47 ----A---- C:\WINDOWS\system32\msoeacct.dll
2013-10-12 19:02:46 ----A---- C:\WINDOWS\system32\inetres.dll
2013-10-12 19:02:46 ----A---- C:\WINDOWS\system32\inetcomm.dll
2013-10-12 19:02:44 ----D---- C:\Program Files\Outlook Express
2013-10-12 19:02:44 ----A---- C:\WINDOWS\system32\schedsvc.dll
2013-10-12 19:02:44 ----A---- C:\WINDOWS\system32\mstinit.exe
2013-10-12 19:02:44 ----A---- C:\WINDOWS\system32\mstask.dll
2013-10-12 19:02:43 ----A---- C:\WINDOWS\system32\isign32.dll
2013-10-12 19:02:43 ----A---- C:\WINDOWS\system32\inetcfg.dll
2013-10-12 19:02:43 ----A---- C:\WINDOWS\system32\icwphbk.dll
2013-10-12 19:02:43 ----A---- C:\WINDOWS\system32\icwdial.dll
2013-10-12 19:02:38 ----D---- C:\Program Files\Common Files\System
2013-10-12 19:02:35 ----D---- C:\Program Files\Internet Explorer
2013-10-12 19:02:33 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2013-10-12 19:02:25 ----D---- C:\Program Files\ComPlus Applications
2013-10-12 19:02:23 ----A---- C:\WINDOWS\vbaddin.ini
2013-10-12 19:02:23 ----A---- C:\WINDOWS\vb.ini
2013-10-12 19:02:19 ----D---- C:\WINDOWS\Registration
2013-10-12 19:01:54 ----D---- C:\Program Files\Windows Media Player
2013-10-12 19:01:49 ----D---- C:\Program Files\Messenger
2013-10-12 19:01:45 ----D---- C:\Program Files\MSN Gaming Zone
2013-10-12 19:01:45 ----A---- C:\WINDOWS\system32\write.exe
2013-10-12 19:01:38 ----A---- C:\WINDOWS\system32\sndvol32.exe
2013-10-12 19:01:38 ----A---- C:\WINDOWS\system32\hticons.dll
2013-10-12 19:01:37 ----A---- C:\WINDOWS\system32\winchat.exe
2013-10-12 19:01:37 ----A---- C:\WINDOWS\system32\avwav.dll
2013-10-12 19:01:37 ----A---- C:\WINDOWS\system32\avtapi.dll
2013-10-12 19:01:37 ----A---- C:\WINDOWS\system32\avmeter.dll
2013-10-12 19:01:32 ----A---- C:\WINDOWS\system32\charmap.exe
2013-10-12 19:01:32 ----A---- C:\WINDOWS\system32\getuname.dll
2013-10-12 19:01:31 ----A---- C:\WINDOWS\system32\winmine.exe
2013-10-12 19:01:31 ----A---- C:\WINDOWS\system32\sol.exe
2013-10-12 19:01:31 ----A---- C:\WINDOWS\system32\mshearts.exe
2013-10-12 19:01:31 ----A---- C:\WINDOWS\system32\freecell.exe
2013-10-12 19:01:31 ----A---- C:\WINDOWS\system32\calc.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\tslabels.ini
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\tskill.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\tscon.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\shadow.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\rwinsta.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\reset.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\regini.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\qwinsta.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\qappsrv.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\msg.exe
2013-10-12 19:01:30 ----A---- C:\WINDOWS\system32\logoff.exe
2013-10-12 19:01:29 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2013-10-12 19:01:29 ----A---- C:\WINDOWS\system32\cdmodem.dll
2013-10-12 19:01:25 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2013-10-12 19:01:24 ----A---- C:\WINDOWS\system32\sndrec32.exe
2013-10-12 19:01:24 ----A---- C:\WINDOWS\system32\mplay32.exe
2013-10-12 19:01:24 ----A---- C:\WINDOWS\system32\hypertrm.dll
2013-10-12 19:01:24 ----A---- C:\WINDOWS\system32\accwiz.exe
2013-10-12 19:01:23 ----D---- C:\Program Files\Windows NT
2013-10-12 19:01:23 ----A---- C:\WINDOWS\system32\mspaint.exe
2013-10-12 19:01:23 ----A---- C:\WINDOWS\system32\clipbrd.exe
2013-10-12 19:01:22 ----A---- C:\WINDOWS\system32\spider.exe
2013-10-12 19:01:22 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2013-10-12 19:01:22 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2013-10-12 19:01:22 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2013-10-12 19:01:21 ----A---- C:\WINDOWS\system32\tsgqec.dll
2013-10-12 19:01:21 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2013-10-12 19:01:21 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2013-10-12 19:01:21 ----A---- C:\WINDOWS\system32\aaclient.dll
2013-10-12 19:01:20 ----A---- C:\WINDOWS\system32\remotepg.dll
2013-10-12 19:01:20 ----A---- C:\WINDOWS\system32\rdshost.exe
2013-10-12 19:01:20 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2013-10-12 19:01:20 ----A---- C:\WINDOWS\system32\mstscax.dll
2013-10-12 19:01:20 ----A---- C:\WINDOWS\system32\mstsc.exe
2013-10-12 19:01:19 ----D---- C:\WINDOWS\system32\MsDtc
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\termsrv.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\sessmgr.exe
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\rdpclip.exe
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\rdchost.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\qprocess.exe
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\icaapi.dll
2013-10-12 19:01:19 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\xolehlp.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\mtxoci.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\msdtctm.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\msdtclog.dll
2013-10-12 19:01:18 ----A---- C:\WINDOWS\system32\msdtc.exe
2013-10-12 19:01:17 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2013-10-12 19:01:17 ----A---- C:\WINDOWS\system32\mtxex.dll
2013-10-12 19:01:17 ----A---- C:\WINDOWS\system32\mtxdm.dll
2013-10-12 19:01:17 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2013-10-12 19:01:16 ----D---- C:\WINDOWS\system32\Com
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\stclient.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\comrepl.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\comaddin.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\colbact.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\clbcatex.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\catsrvut.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\catsrvps.dll
2013-10-12 19:01:16 ----A---- C:\WINDOWS\system32\catsrv.dll
2013-10-12 19:01:15 ----A---- C:\WINDOWS\system32\comuid.dll
2013-10-12 19:01:15 ----A---- C:\WINDOWS\system32\comsvcs.dll
2013-10-12 19:01:15 ----A---- C:\WINDOWS\system32\comsnap.dll
2013-10-12 19:01:15 ----A---- C:\WINDOWS\system32\clbcatq.dll
2013-10-12 19:01:09 ----A---- C:\WINDOWS\system32\servdeps.dll
2013-10-12 19:01:09 ----A---- C:\WINDOWS\system32\mmfutil.dll
2013-10-12 19:01:09 ----A---- C:\WINDOWS\system32\licwmi.dll
2013-10-12 19:01:09 ----A---- C:\WINDOWS\system32\cmprops.dll
2013-10-12 19:01:05 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2013-10-12 19:01:05 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys

======List of files/folders modified in the last 1 month======

2013-10-13 12:14:30 ----A---- C:\WINDOWS\win.ini
2013-10-12 20:34:17 ----A---- C:\WINDOWS\system.ini
2013-10-12 19:04:50 ----ASH---- C:\WINDOWS\fonts\desktop.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2013-07-29 136672]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2013-03-06 37352]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2012-08-27 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2013-08-22 88840]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-11-17 2297664]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-06-28 1241088]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 RTL8023;Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver; C:\WINDOWS\system32\DRIVERS\Rtlnic51.sys [2003-12-31 69504]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt []
S3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-14 20992]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2013-07-17 108088]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2013-07-17 84024]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-12-21 57008]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-06-28 376832]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-10-13 182696]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-08-16 553288]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-06-28 516096]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-12 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-12 257416]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-12 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-09-11 118680]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S4 AntiVirWebService;Avira Web Protection; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2013-08-09 815160]

-----------------EOF-----------------