Prosím o kontrolu logu
Napsal: 10 lis 2013 18:27
Dobrý den
Prosím o kontrolu logu ....v poslednom čase mi PC ide strašne pomaličky...už som odinštaloval všetko čo podľa mňa nepotrebujem a vyčistil programom CC.
Som v tomto lamka takže ma už nič ine nenapada...
Rád by som vedel aj čo všetko môžem zrušiť čo nepotrebujem a PC spomaluje.....
Ďakujem predom
log:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-11-2013
Ran by Administrator (administrator) on BRANO-PC on 10-11-2013 18:24:58
Running from C:\Documents and Settings\Administrator\My Documents\Preberanie
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Microsoft Corporation) C:\WINDOWS\system32\inetsrv\inetinfo.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(SafetyNut Inc.) C:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exe
() C:\WINDOWS\system32\CmUCReye.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(SafetyNut Inc.) C:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exe
(SafetyNut Inc.) C:\Program Files\Movies Toolbar\SafetyNut\safetynut.exe
(Samsung Electronics Co., Ltd.) D:\Kies Samsung\Kies\KiesTrayAgent.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Samsung) D:\Kies Samsung\Kies\Kies.exe
(Samsung) D:\Kies Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Microsoft Corporation) C:\Program Files\Microsoft ActiveSync\wcescomm.exe
(Microsoft Corporation) C:\PROGRA~1\MI3AA1~1\rapimgr.exe
(Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Farbar) C:\Documents and Settings\Administrator\My Documents\Preberanie\FRST(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] - nwiz.exe /install
HKLM\...\Run: [CmUCRRun] - C:\WINDOWS\system32\CmUCREye.exe [241664 2005-10-12] ()
HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\Core\smax4pnp.exe [868352 2006-12-18] (Analog Devices, Inc.)
HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [] - [x]
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-08-12] (Microsoft Corporation)
HKLM\...\Run: [JMB36X IDE Setup] - C:\WINDOWS\RaidTool\xInsIDE.exe [36864 2007-03-20] ()
HKLM\...\Run: [36X Raid Configurer] - C:\WINDOWS\system32\xRaidSetup.exe [1970176 2007-11-19] (JMicron Technology Corp.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [KiesTrayAgent] - D:\Kies Samsung\Kies\KiesTrayAgent.exe [310640 2013-03-28] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [49152 2007-03-11] (Hewlett-Packard Co.)
HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1707472 2013-11-08] (APN)
HKCU\...\Run: [KiesPreload] - D:\Kies Samsung\Kies\Kies.exe [1511792 2013-03-28] (Samsung)
HKCU\...\Run: [] - D:\Kies Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [1106288 2013-03-28] (Samsung)
HKCU\...\Run: [H/PC Connection Agent] - C:\Program Files\Microsoft ActiveSync\wcescomm.exe [1289000 2006-11-13] (Microsoft Corporation)
HKCU\...\Policies\system: [HideLegacyLogonScripts] 0
HKCU\...\Policies\system: [HideLogoffScripts] 0
HKCU\...\Policies\system: [HideStartupScripts] 0
HKCU\...\Policies\system: [RunLogonScriptSync] 1
HKCU\...\Policies\system: [RunStartupScriptSync] 0
MountPoints2: {02f5efa8-3eb6-11dd-ae83-001bfc0d2a07} - I:\LaunchU3.exe -a
MountPoints2: {3b84ad4e-28b4-11de-af4a-001bfc0d2a07} - G:\LaunchU3.exe -a
MountPoints2: {a28f5cae-e393-11df-b0c5-001bfc0d2a07} - "G:\WD SmartWare.exe" autoplay=true
HKU\Guest\...\Run: [QuickTime Task] - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
AppInit_DLLs: C:\DOCUME~1\ALLUSE~1\APPLIC~1\Wincert\WIN32C~1.DLL C:\PROGRA~1\MOVIES~1\SAFETY~1\SAFETY~2.DLL [ 2013-09-25] ()
IMEO\bitguard.exe: [Debugger] tasklist.exe
IMEO\bprotect.exe: [Debugger] tasklist.exe
IMEO\browserdefender.exe: [Debugger] tasklist.exe
IMEO\browserprotect.exe: [Debugger] tasklist.exe
HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\safetynut\x64\safetycrt.dll
HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Movies Toolbar\SafetyNut\safetycrt.dll [485384 2013-09-25] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss ... 1&tsp=4931
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5A44A67E4A6DCE01
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?st=6&barid={10 ... 1BFC0D2A07}
SearchScopes: HKLM - DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 1BFC0D2A07}
SearchScopes: HKLM - {52db1893-8a90-4192-aede-08e00b8f8473} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 1BFC0D2A07}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchT ... 1&tsp=4931
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL =
BHO: No Name - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - No File
BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {3444c3c5-6c56-4a16-a453-832b05bf6ea4} - No File
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
Toolbar: HKCU - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file://C:\Pracovné programy\AUTOCAD\AcDcToday.ocx
DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} file://C:\Pracovné programy\AUTOCAD\InstBanr.ocx
DPF: {C6637286-300D-11D4-AE0A-0010830243BD} file://C:\Pracovné programy\AUTOCAD\InstFred.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file://C:\Pracovné programy\AUTOCAD\AcPreview.ocx
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2EA6DDB2-4D8B-41BE-A285-4DB93B48B465}: [NameServer]217.118.96.203,217.118.96.226
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546
FF user.js: detected! => C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\user.js
FF SearchEngineOrder.1: Ask.com
FF Homepage: http://www.google.sk
FF Keyword.URL: hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=105&systemid=473&v=a9397-146&apn_dtid=BND473&apn_ptnrs=AG1&apn_uid=5407427443104224&o=APN10640&q=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin: @ei.VideoDownloadConverter_4z.com/Plugin - C:\Program Files\VideoDownloadConverter_4zEI\Installr\1.bin\NP4zEISB.dll No File
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File
FF SearchPlugin: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\searchplugins\Ask.xml
FF SearchPlugin: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\searchplugins\babylon.xml
FF SearchPlugin: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\searchplugins\BrowserDefender.xml
FF SearchPlugin: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\searchplugins\delta.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\zoznam-sk.xml
FF Extension: Movies Toolbar (Dist. by Somoto Ltd.) - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\Extensions\{3444c3c5-6c56-4a16-a453-832b05bf6ea4}
FF Extension: toolbar_KMPV7 - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\Extensions\toolbar_KMPV7@apn.ask.com.xpi
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
Chrome:
=======
CHR RestoreOnStartup: "sync":{"suppress_start"
CHR Extension: (SweetIM for Facebook) - C:\DOCUME~1\ADMINI~1\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0
CHR Extension: (SweetPacks Chrome Extension) - C:\DOCUME~1\ADMINI~1\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.2_0
CHR Extension: (GoPhoto.it) - C:\DOCUME~1\ADMINI~1\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk\1.5_0
CHR HKLM\...\Chrome\Extension: [jbpkiefagocgkmemidfngdkamloieekf] - C:\Program Files\TornTV.com\torn10.crx
CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx
CHR HKLM\...\Chrome\Extension: [lgnbhdnimikkoodkogjlcllngimhlapp] - C:\Program Files\FTDownloader.com\FTDownloader10.crx
CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx
CHR HKLM\...\Chrome\Extension: [pfmopbbadnfoelckkcmjjeaaegjpjjbk] - C:\Program Files\Gophoto.it\gophotoit14.crx
========================== Services (Whitelisted) =================
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-11-08] (APN LLC.)
R2 IISADMIN; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15360 2008-04-14] (Microsoft Corporation)
R2 MSFtpsvc; C:\Windows\system32\inetsrv\inetinfo.exe [15360 2008-04-14] (Microsoft Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-08-12] (Microsoft Corporation)
R2 SafetyNutManager; C:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exe [3419144 2013-09-25] (SafetyNut Inc.)
R2 SMTPSVC; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15360 2008-04-14] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\inetinfo.exe [15360 2008-04-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 ADIDTSFiltService; C:\Windows\System32\drivers\adidts.sys [139776 2006-12-08] (Analog Devices, Inc.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [271360 2007-10-18] ()
R3 CMISTOR; C:\Windows\System32\DRIVERS\cmiucr.SYS [72320 2005-10-04] (C-Media Corporation)
R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [93096 2009-07-18] (JMicron Technology Corp.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [18048 2007-10-18] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
R1 MpKslecb973dc; C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E6DEA2FA-85A8-453E-AFE8-9D2F0E8CD9BE}\MpKslecb973dc.sys [40392 2013-11-10] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 PortTalk; C:\Windows\System32\Drivers\PortTalk.sys [3567 2002-01-12] (Beyond Logic http://www.beyondlogic.org)
S3 SONYPVU1; C:\Windows\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation)
R2 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [13120 2013-08-25] ()
R3 yukonwxp; C:\Windows\System32\DRIVERS\yk51x86.sys [248832 2006-08-22] (Marvell)
S3 ALSysIO; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ALSysIO.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S4 IntelIde; No ImagePath
S3 mcdbus; system32\DRIVERS\mcdbus.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-10 17:58 - 2013-11-10 17:58 - 00001940 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175815.reg
2013-11-10 17:58 - 2013-11-10 17:58 - 00000556 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175829.reg
2013-11-10 17:57 - 2013-11-10 17:58 - 00174974 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175733.reg
2013-11-10 16:44 - 2013-11-10 16:44 - 00000000 ____D C:\FRST
2013-10-31 14:31 - 2013-11-03 11:06 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-10-31 06:50 - 2013-10-31 08:23 - 00000000 ____D C:\Documents and Settings\All Users\Documents\CrashDump
2013-10-30 17:37 - 2013-10-31 08:27 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-10-25 07:50 - 2013-10-25 07:50 - 00290784 _____ C:\Documents and Settings\Administrator\Desktop\strecha.dwg
2013-10-25 06:48 - 2013-11-10 18:23 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SafetyNut
2013-10-22 09:09 - 2013-10-22 09:09 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\searchresultstb
2013-10-17 16:24 - 2013-10-17 16:24 - 00000206 _____ C:\Documents and Settings\Administrator\My Documents\acad.err
2013-10-16 06:01 - 2013-10-16 06:02 - 01188383 _____ C:\WINDOWS\system32\USB2
2013-10-16 05:59 - 2013-10-16 06:20 - 01184357 _____ C:\WINDOWS\system32\USB
2013-10-16 02:12 - 2013-11-10 17:42 - 00000400 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2013-10-15 00:19 - 2013-11-10 15:42 - 01640360 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2013-10-13 21:31 - 2013-10-13 21:31 - 00116289 _____ C:\Documents and Settings\Administrator\My Documents\MFM%20Zadanie%20rosoft%20súpis%20a%20odpočet.xls_0.ods
2013-10-13 20:42 - 2013-10-13 20:42 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\ABBYY
2013-10-13 20:37 - 2013-11-10 17:37 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ABBYY
2013-10-13 20:37 - 2013-11-10 17:37 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\ABBYY
2013-10-13 20:35 - 2013-10-13 20:35 - 00000000 ____D C:\Program Files\MSXML 6.0
2013-10-11 01:43 - 2013-10-11 01:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$
2013-10-11 01:43 - 2013-10-11 01:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2847311$
2013-10-11 01:38 - 2013-10-11 01:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2884256$
2013-10-11 01:37 - 2013-10-11 01:37 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868038$
2013-10-11 01:36 - 2013-10-11 01:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2883150$
2013-10-11 01:36 - 2013-10-11 01:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862330$
==================== One Month Modified Files and Folders =======
2013-11-10 18:24 - 2013-03-22 14:56 - 00000000 ____D C:\Documents and Settings\Administrator\My Documents\Preberanie
2013-11-10 18:23 - 2013-10-25 06:48 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SafetyNut
2013-11-10 18:12 - 2012-12-14 19:10 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-11-10 18:12 - 2010-05-13 09:49 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-10 17:58 - 2013-11-10 17:58 - 00001940 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175815.reg
2013-11-10 17:58 - 2013-11-10 17:58 - 00000556 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175829.reg
2013-11-10 17:58 - 2013-11-10 17:57 - 00174974 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175733.reg
2013-11-10 17:56 - 2007-09-14 16:12 - 00000000 ____D C:\Documents and Settings\Administrator
2013-11-10 17:53 - 2007-09-14 16:06 - 01358751 ____N C:\WINDOWS\WindowsUpdate.log
2013-11-10 17:51 - 2008-09-03 10:23 - 00000000 ____D C:\Program Files\QuickTime
2013-11-10 17:51 - 2007-09-14 17:27 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2013-11-10 17:47 - 2013-09-20 02:55 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Rich Media Player
2013-11-10 17:44 - 2013-05-03 13:24 - 00003429 _____ C:\Documents and Settings\All Users\Application Data\hpzinstall.log
2013-11-10 17:43 - 2013-05-03 13:27 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\HP
2013-11-10 17:43 - 2007-09-14 17:27 - 00000000 ____D C:\WINDOWS\twain_32
2013-11-10 17:42 - 2013-10-16 02:12 - 00000400 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2013-11-10 17:42 - 2010-12-08 14:09 - 00000174 ____N C:\WINDOWS\wiadebug.log
2013-11-10 17:40 - 2013-05-03 13:28 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HP
2013-11-10 17:38 - 2013-09-26 09:21 - 00000000 ____D C:\Program Files\Minibar
2013-11-10 17:37 - 2013-10-13 20:37 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ABBYY
2013-11-10 17:37 - 2013-10-13 20:37 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\ABBYY
2013-11-10 17:33 - 2010-12-08 14:09 - 00000052 ____N C:\WINDOWS\wiaservc.log
2013-11-10 17:33 - 2006-02-28 13:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2013-11-10 17:32 - 2012-07-19 21:39 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2698365$
2013-11-10 17:32 - 2010-05-13 09:49 - 00000934 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-10 17:32 - 2007-10-18 10:13 - 00179105 _____ C:\WINDOWS\system32\nvapps.xml
2013-11-10 17:32 - 2007-09-14 16:12 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-11-10 17:31 - 2007-09-14 16:12 - 00032602 ____N C:\WINDOWS\SchedLgU.Txt
2013-11-10 17:31 - 2007-09-14 16:12 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2013-11-10 17:12 - 2007-09-14 17:15 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-11-10 17:11 - 2013-05-03 13:26 - 00000000 ____D C:\Program Files\HP
2013-11-10 16:44 - 2013-11-10 16:44 - 00000000 ____D C:\FRST
2013-11-10 16:31 - 2008-01-11 15:49 - 00000000 ____D C:\WINDOWS\system32\Logfiles
2013-11-10 16:26 - 2007-12-13 10:04 - 00000000 ____D C:\Program Files\ElcomSoft
2013-11-10 16:19 - 2007-09-18 10:24 - 00000000 ____D C:\AUTOSAVE
2013-11-10 15:42 - 2013-10-15 00:19 - 01640360 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2013-11-06 21:19 - 2008-01-15 12:36 - 00143872 _____ C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-05 08:05 - 2013-01-11 11:39 - 00047320 _____ C:\Documents and Settings\Administrator\My Documents\plot.log
2013-11-04 21:19 - 2008-01-25 16:32 - 00101376 ___SH C:\Documents and Settings\Administrator\My Documents\Thumbs.db
2013-11-04 21:18 - 2013-05-03 13:49 - 00000000 ____D C:\Documents and Settings\Administrator\My Documents\My Scans
2013-11-03 11:06 - 2013-10-31 14:31 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-03 09:46 - 2012-04-25 13:26 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-31 08:27 - 2013-10-30 17:37 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-10-31 08:23 - 2013-10-31 06:50 - 00000000 ____D C:\Documents and Settings\All Users\Documents\CrashDump
2013-10-31 08:19 - 2013-05-29 21:43 - 00000000 ____D C:\Documents and Settings\Administrator\My Documents\SelfMV
2013-10-27 09:33 - 2007-09-14 17:37 - 00598420 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-10-25 07:50 - 2013-10-25 07:50 - 00290784 _____ C:\Documents and Settings\Administrator\Desktop\strecha.dwg
2013-10-25 06:49 - 2013-09-26 09:20 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Wincert
2013-10-22 09:09 - 2013-10-22 09:09 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\searchresultstb
2013-10-22 09:09 - 2013-09-26 09:20 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\somotomoviestoolbar1
2013-10-17 16:24 - 2013-10-17 16:24 - 00000206 _____ C:\Documents and Settings\Administrator\My Documents\acad.err
2013-10-16 06:20 - 2013-10-16 05:59 - 01184357 _____ C:\WINDOWS\system32\USB
2013-10-16 06:02 - 2013-10-16 06:01 - 01188383 _____ C:\WINDOWS\system32\USB2
2013-10-16 02:02 - 2012-05-02 14:51 - 00001698 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
2013-10-16 02:02 - 2011-01-31 12:30 - 00001917 ____C C:\WINDOWS\epplauncher.mif
2013-10-16 02:01 - 2011-01-31 12:28 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-10-14 02:52 - 2008-09-03 14:41 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-10-13 21:31 - 2013-10-13 21:31 - 00116289 _____ C:\Documents and Settings\Administrator\My Documents\MFM%20Zadanie%20rosoft%20súpis%20a%20odpočet.xls_0.ods
2013-10-13 20:43 - 2007-09-21 11:51 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe
2013-10-13 20:42 - 2013-10-13 20:42 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\ABBYY
2013-10-13 20:35 - 2013-10-13 20:35 - 00000000 ____D C:\Program Files\MSXML 6.0
2013-10-13 20:28 - 2013-02-17 17:03 - 00002315 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
2013-10-11 06:16 - 2011-05-04 19:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-11 06:16 - 2007-09-14 17:36 - 00273376 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-10-11 01:43 - 2013-10-11 01:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$
2013-10-11 01:43 - 2013-10-11 01:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2847311$
2013-10-11 01:43 - 2013-08-07 02:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-10-11 01:39 - 2011-05-04 19:36 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
2013-10-11 01:39 - 2007-10-18 10:59 - 78106760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-10-11 01:38 - 2013-10-11 01:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2884256$
2013-10-11 01:37 - 2013-10-11 01:37 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868038$
2013-10-11 01:36 - 2013-10-11 01:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2883150$
2013-10-11 01:36 - 2013-10-11 01:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862330$
Files to move or delete:
====================
C:\Documents and Settings\Administrator\psbB91.dll
C:\Documents and Settings\Administrator\ptsA52.dll
Some content of TEMP:
====================
C:\Documents and Settings\Administrator\Local Settings\Temp\appshat-distribution.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\bi_cleaner.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\hpzmsi01.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\hpzscr01.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\MoviesToolbarSetup_Somoto.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\oi_{E1D68687-F96A-4AE7-9EDB-2E59C2DE99E4}.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\PIPInstaller_PTV_.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\UNINSTALL.EXE
C:\Documents and Settings\Administrator\Local Settings\Temp\UpdateCheckerSetup.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\_TinDel.exe
C:\Documents and Settings\NetworkService\Local Settings\Temp\mpam-e2573639.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================
Prosím o kontrolu logu ....v poslednom čase mi PC ide strašne pomaličky...už som odinštaloval všetko čo podľa mňa nepotrebujem a vyčistil programom CC.
Som v tomto lamka takže ma už nič ine nenapada...
Rád by som vedel aj čo všetko môžem zrušiť čo nepotrebujem a PC spomaluje.....
Ďakujem predom
log:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-11-2013
Ran by Administrator (administrator) on BRANO-PC on 10-11-2013 18:24:58
Running from C:\Documents and Settings\Administrator\My Documents\Preberanie
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Microsoft Corporation) C:\WINDOWS\system32\inetsrv\inetinfo.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(SafetyNut Inc.) C:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exe
() C:\WINDOWS\system32\CmUCReye.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(SafetyNut Inc.) C:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exe
(SafetyNut Inc.) C:\Program Files\Movies Toolbar\SafetyNut\safetynut.exe
(Samsung Electronics Co., Ltd.) D:\Kies Samsung\Kies\KiesTrayAgent.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Samsung) D:\Kies Samsung\Kies\Kies.exe
(Samsung) D:\Kies Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Microsoft Corporation) C:\Program Files\Microsoft ActiveSync\wcescomm.exe
(Microsoft Corporation) C:\PROGRA~1\MI3AA1~1\rapimgr.exe
(Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Farbar) C:\Documents and Settings\Administrator\My Documents\Preberanie\FRST(1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] - nwiz.exe /install
HKLM\...\Run: [CmUCRRun] - C:\WINDOWS\system32\CmUCREye.exe [241664 2005-10-12] ()
HKLM\...\Run: [SoundMAXPnP] - C:\Program Files\Analog Devices\Core\smax4pnp.exe [868352 2006-12-18] (Analog Devices, Inc.)
HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [] - [x]
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [995176 2013-08-12] (Microsoft Corporation)
HKLM\...\Run: [JMB36X IDE Setup] - C:\WINDOWS\RaidTool\xInsIDE.exe [36864 2007-03-20] ()
HKLM\...\Run: [36X Raid Configurer] - C:\WINDOWS\system32\xRaidSetup.exe [1970176 2007-11-19] (JMicron Technology Corp.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [KiesTrayAgent] - D:\Kies Samsung\Kies\KiesTrayAgent.exe [310640 2013-03-28] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [49152 2007-03-11] (Hewlett-Packard Co.)
HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1707472 2013-11-08] (APN)
HKCU\...\Run: [KiesPreload] - D:\Kies Samsung\Kies\Kies.exe [1511792 2013-03-28] (Samsung)
HKCU\...\Run: [] - D:\Kies Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [1106288 2013-03-28] (Samsung)
HKCU\...\Run: [H/PC Connection Agent] - C:\Program Files\Microsoft ActiveSync\wcescomm.exe [1289000 2006-11-13] (Microsoft Corporation)
HKCU\...\Policies\system: [HideLegacyLogonScripts] 0
HKCU\...\Policies\system: [HideLogoffScripts] 0
HKCU\...\Policies\system: [HideStartupScripts] 0
HKCU\...\Policies\system: [RunLogonScriptSync] 1
HKCU\...\Policies\system: [RunStartupScriptSync] 0
MountPoints2: {02f5efa8-3eb6-11dd-ae83-001bfc0d2a07} - I:\LaunchU3.exe -a
MountPoints2: {3b84ad4e-28b4-11de-af4a-001bfc0d2a07} - G:\LaunchU3.exe -a
MountPoints2: {a28f5cae-e393-11df-b0c5-001bfc0d2a07} - "G:\WD SmartWare.exe" autoplay=true
HKU\Guest\...\Run: [QuickTime Task] - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
AppInit_DLLs: C:\DOCUME~1\ALLUSE~1\APPLIC~1\Wincert\WIN32C~1.DLL C:\PROGRA~1\MOVIES~1\SAFETY~1\SAFETY~2.DLL [ 2013-09-25] ()
IMEO\bitguard.exe: [Debugger] tasklist.exe
IMEO\bprotect.exe: [Debugger] tasklist.exe
IMEO\browserdefender.exe: [Debugger] tasklist.exe
IMEO\browserprotect.exe: [Debugger] tasklist.exe
HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\safetynut\x64\safetycrt.dll
HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Movies Toolbar\SafetyNut\safetycrt.dll [485384 2013-09-25] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss ... 1&tsp=4931
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5A44A67E4A6DCE01
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?st=6&barid={10 ... 1BFC0D2A07}
SearchScopes: HKLM - DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 1BFC0D2A07}
SearchScopes: HKLM - {52db1893-8a90-4192-aede-08e00b8f8473} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... 1BFC0D2A07}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.delta-search.com/?q={searchT ... 1&tsp=4931
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL =
BHO: No Name - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - No File
BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {3444c3c5-6c56-4a16-a453-832b05bf6ea4} - No File
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
Toolbar: HKCU - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file://C:\Pracovné programy\AUTOCAD\AcDcToday.ocx
DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} file://C:\Pracovné programy\AUTOCAD\InstBanr.ocx
DPF: {C6637286-300D-11D4-AE0A-0010830243BD} file://C:\Pracovné programy\AUTOCAD\InstFred.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file://C:\Pracovné programy\AUTOCAD\AcPreview.ocx
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2EA6DDB2-4D8B-41BE-A285-4DB93B48B465}: [NameServer]217.118.96.203,217.118.96.226
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546
FF user.js: detected! => C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\user.js
FF SearchEngineOrder.1: Ask.com
FF Homepage: http://www.google.sk
FF Keyword.URL: hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=105&systemid=473&v=a9397-146&apn_dtid=BND473&apn_ptnrs=AG1&apn_uid=5407427443104224&o=APN10640&q=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\WINDOWS\system32\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin: @ei.VideoDownloadConverter_4z.com/Plugin - C:\Program Files\VideoDownloadConverter_4zEI\Installr\1.bin\NP4zEISB.dll No File
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll No File
FF SearchPlugin: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\searchplugins\Ask.xml
FF SearchPlugin: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\searchplugins\babylon.xml
FF SearchPlugin: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\searchplugins\BrowserDefender.xml
FF SearchPlugin: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\searchplugins\delta.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\zoznam-sk.xml
FF Extension: Movies Toolbar (Dist. by Somoto Ltd.) - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\Extensions\{3444c3c5-6c56-4a16-a453-832b05bf6ea4}
FF Extension: toolbar_KMPV7 - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\sj8d9zta.default-1361980096546\Extensions\toolbar_KMPV7@apn.ask.com.xpi
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
Chrome:
=======
CHR RestoreOnStartup: "sync":{"suppress_start"
CHR Extension: (SweetIM for Facebook) - C:\DOCUME~1\ADMINI~1\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0
CHR Extension: (SweetPacks Chrome Extension) - C:\DOCUME~1\ADMINI~1\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.3.0.2_0
CHR Extension: (GoPhoto.it) - C:\DOCUME~1\ADMINI~1\LOCALS~1\Application Data\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk\1.5_0
CHR HKLM\...\Chrome\Extension: [jbpkiefagocgkmemidfngdkamloieekf] - C:\Program Files\TornTV.com\torn10.crx
CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx
CHR HKLM\...\Chrome\Extension: [lgnbhdnimikkoodkogjlcllngimhlapp] - C:\Program Files\FTDownloader.com\FTDownloader10.crx
CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx
CHR HKLM\...\Chrome\Extension: [pfmopbbadnfoelckkcmjjeaaegjpjjbk] - C:\Program Files\Gophoto.it\gophotoit14.crx
========================== Services (Whitelisted) =================
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-11-08] (APN LLC.)
R2 IISADMIN; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15360 2008-04-14] (Microsoft Corporation)
R2 MSFtpsvc; C:\Windows\system32\inetsrv\inetinfo.exe [15360 2008-04-14] (Microsoft Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-08-12] (Microsoft Corporation)
R2 SafetyNutManager; C:\Program Files\Movies Toolbar\SafetyNut\SafetyNutManager.exe [3419144 2013-09-25] (SafetyNut Inc.)
R2 SMTPSVC; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15360 2008-04-14] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\inetinfo.exe [15360 2008-04-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 ADIDTSFiltService; C:\Windows\System32\drivers\adidts.sys [139776 2006-12-08] (Analog Devices, Inc.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [271360 2007-10-18] ()
R3 CMISTOR; C:\Windows\System32\DRIVERS\cmiucr.SYS [72320 2005-10-04] (C-Media Corporation)
R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [93096 2009-07-18] (JMicron Technology Corp.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [18048 2007-10-18] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
R1 MpKslecb973dc; C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E6DEA2FA-85A8-453E-AFE8-9D2F0E8CD9BE}\MpKslecb973dc.sys [40392 2013-11-10] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 PortTalk; C:\Windows\System32\Drivers\PortTalk.sys [3567 2002-01-12] (Beyond Logic http://www.beyondlogic.org)
S3 SONYPVU1; C:\Windows\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation)
R2 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [13120 2013-08-25] ()
R3 yukonwxp; C:\Windows\System32\DRIVERS\yk51x86.sys [248832 2006-08-22] (Marvell)
S3 ALSysIO; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ALSysIO.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S4 IntelIde; No ImagePath
S3 mcdbus; system32\DRIVERS\mcdbus.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-10 17:58 - 2013-11-10 17:58 - 00001940 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175815.reg
2013-11-10 17:58 - 2013-11-10 17:58 - 00000556 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175829.reg
2013-11-10 17:57 - 2013-11-10 17:58 - 00174974 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175733.reg
2013-11-10 16:44 - 2013-11-10 16:44 - 00000000 ____D C:\FRST
2013-10-31 14:31 - 2013-11-03 11:06 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-10-31 06:50 - 2013-10-31 08:23 - 00000000 ____D C:\Documents and Settings\All Users\Documents\CrashDump
2013-10-30 17:37 - 2013-10-31 08:27 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-10-25 07:50 - 2013-10-25 07:50 - 00290784 _____ C:\Documents and Settings\Administrator\Desktop\strecha.dwg
2013-10-25 06:48 - 2013-11-10 18:23 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SafetyNut
2013-10-22 09:09 - 2013-10-22 09:09 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\searchresultstb
2013-10-17 16:24 - 2013-10-17 16:24 - 00000206 _____ C:\Documents and Settings\Administrator\My Documents\acad.err
2013-10-16 06:01 - 2013-10-16 06:02 - 01188383 _____ C:\WINDOWS\system32\USB2
2013-10-16 05:59 - 2013-10-16 06:20 - 01184357 _____ C:\WINDOWS\system32\USB
2013-10-16 02:12 - 2013-11-10 17:42 - 00000400 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2013-10-15 00:19 - 2013-11-10 15:42 - 01640360 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2013-10-13 21:31 - 2013-10-13 21:31 - 00116289 _____ C:\Documents and Settings\Administrator\My Documents\MFM%20Zadanie%20rosoft%20súpis%20a%20odpočet.xls_0.ods
2013-10-13 20:42 - 2013-10-13 20:42 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\ABBYY
2013-10-13 20:37 - 2013-11-10 17:37 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ABBYY
2013-10-13 20:37 - 2013-11-10 17:37 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\ABBYY
2013-10-13 20:35 - 2013-10-13 20:35 - 00000000 ____D C:\Program Files\MSXML 6.0
2013-10-11 01:43 - 2013-10-11 01:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$
2013-10-11 01:43 - 2013-10-11 01:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2847311$
2013-10-11 01:38 - 2013-10-11 01:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2884256$
2013-10-11 01:37 - 2013-10-11 01:37 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868038$
2013-10-11 01:36 - 2013-10-11 01:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2883150$
2013-10-11 01:36 - 2013-10-11 01:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862330$
==================== One Month Modified Files and Folders =======
2013-11-10 18:24 - 2013-03-22 14:56 - 00000000 ____D C:\Documents and Settings\Administrator\My Documents\Preberanie
2013-11-10 18:23 - 2013-10-25 06:48 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SafetyNut
2013-11-10 18:12 - 2012-12-14 19:10 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-11-10 18:12 - 2010-05-13 09:49 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-10 17:58 - 2013-11-10 17:58 - 00001940 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175815.reg
2013-11-10 17:58 - 2013-11-10 17:58 - 00000556 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175829.reg
2013-11-10 17:58 - 2013-11-10 17:57 - 00174974 _____ C:\Documents and Settings\Administrator\My Documents\cc_20131110_175733.reg
2013-11-10 17:56 - 2007-09-14 16:12 - 00000000 ____D C:\Documents and Settings\Administrator
2013-11-10 17:53 - 2007-09-14 16:06 - 01358751 ____N C:\WINDOWS\WindowsUpdate.log
2013-11-10 17:51 - 2008-09-03 10:23 - 00000000 ____D C:\Program Files\QuickTime
2013-11-10 17:51 - 2007-09-14 17:27 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2013-11-10 17:47 - 2013-09-20 02:55 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Rich Media Player
2013-11-10 17:44 - 2013-05-03 13:24 - 00003429 _____ C:\Documents and Settings\All Users\Application Data\hpzinstall.log
2013-11-10 17:43 - 2013-05-03 13:27 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\HP
2013-11-10 17:43 - 2007-09-14 17:27 - 00000000 ____D C:\WINDOWS\twain_32
2013-11-10 17:42 - 2013-10-16 02:12 - 00000400 ____H C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job
2013-11-10 17:42 - 2010-12-08 14:09 - 00000174 ____N C:\WINDOWS\wiadebug.log
2013-11-10 17:40 - 2013-05-03 13:28 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HP
2013-11-10 17:38 - 2013-09-26 09:21 - 00000000 ____D C:\Program Files\Minibar
2013-11-10 17:37 - 2013-10-13 20:37 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\ABBYY
2013-11-10 17:37 - 2013-10-13 20:37 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\ABBYY
2013-11-10 17:33 - 2010-12-08 14:09 - 00000052 ____N C:\WINDOWS\wiaservc.log
2013-11-10 17:33 - 2006-02-28 13:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2013-11-10 17:32 - 2012-07-19 21:39 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2698365$
2013-11-10 17:32 - 2010-05-13 09:49 - 00000934 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-10 17:32 - 2007-10-18 10:13 - 00179105 _____ C:\WINDOWS\system32\nvapps.xml
2013-11-10 17:32 - 2007-09-14 16:12 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-11-10 17:31 - 2007-09-14 16:12 - 00032602 ____N C:\WINDOWS\SchedLgU.Txt
2013-11-10 17:31 - 2007-09-14 16:12 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2013-11-10 17:12 - 2007-09-14 17:15 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-11-10 17:11 - 2013-05-03 13:26 - 00000000 ____D C:\Program Files\HP
2013-11-10 16:44 - 2013-11-10 16:44 - 00000000 ____D C:\FRST
2013-11-10 16:31 - 2008-01-11 15:49 - 00000000 ____D C:\WINDOWS\system32\Logfiles
2013-11-10 16:26 - 2007-12-13 10:04 - 00000000 ____D C:\Program Files\ElcomSoft
2013-11-10 16:19 - 2007-09-18 10:24 - 00000000 ____D C:\AUTOSAVE
2013-11-10 15:42 - 2013-10-15 00:19 - 01640360 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2013-11-06 21:19 - 2008-01-15 12:36 - 00143872 _____ C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-05 08:05 - 2013-01-11 11:39 - 00047320 _____ C:\Documents and Settings\Administrator\My Documents\plot.log
2013-11-04 21:19 - 2008-01-25 16:32 - 00101376 ___SH C:\Documents and Settings\Administrator\My Documents\Thumbs.db
2013-11-04 21:18 - 2013-05-03 13:49 - 00000000 ____D C:\Documents and Settings\Administrator\My Documents\My Scans
2013-11-03 11:06 - 2013-10-31 14:31 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-03 09:46 - 2012-04-25 13:26 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-31 08:27 - 2013-10-30 17:37 - 00000000 ____D C:\Program Files\Mozilla Thunderbird
2013-10-31 08:23 - 2013-10-31 06:50 - 00000000 ____D C:\Documents and Settings\All Users\Documents\CrashDump
2013-10-31 08:19 - 2013-05-29 21:43 - 00000000 ____D C:\Documents and Settings\Administrator\My Documents\SelfMV
2013-10-27 09:33 - 2007-09-14 17:37 - 00598420 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-10-25 07:50 - 2013-10-25 07:50 - 00290784 _____ C:\Documents and Settings\Administrator\Desktop\strecha.dwg
2013-10-25 06:49 - 2013-09-26 09:20 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Wincert
2013-10-22 09:09 - 2013-10-22 09:09 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\searchresultstb
2013-10-22 09:09 - 2013-09-26 09:20 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\somotomoviestoolbar1
2013-10-17 16:24 - 2013-10-17 16:24 - 00000206 _____ C:\Documents and Settings\Administrator\My Documents\acad.err
2013-10-16 06:20 - 2013-10-16 05:59 - 01184357 _____ C:\WINDOWS\system32\USB
2013-10-16 06:02 - 2013-10-16 06:01 - 01188383 _____ C:\WINDOWS\system32\USB2
2013-10-16 02:02 - 2012-05-02 14:51 - 00001698 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
2013-10-16 02:02 - 2011-01-31 12:30 - 00001917 ____C C:\WINDOWS\epplauncher.mif
2013-10-16 02:01 - 2011-01-31 12:28 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-10-14 02:52 - 2008-09-03 14:41 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-10-13 21:31 - 2013-10-13 21:31 - 00116289 _____ C:\Documents and Settings\Administrator\My Documents\MFM%20Zadanie%20rosoft%20súpis%20a%20odpočet.xls_0.ods
2013-10-13 20:43 - 2007-09-21 11:51 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe
2013-10-13 20:42 - 2013-10-13 20:42 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\ABBYY
2013-10-13 20:35 - 2013-10-13 20:35 - 00000000 ____D C:\Program Files\MSXML 6.0
2013-10-13 20:28 - 2013-02-17 17:03 - 00002315 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
2013-10-11 06:16 - 2011-05-04 19:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-11 06:16 - 2007-09-14 17:36 - 00273376 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-10-11 01:43 - 2013-10-11 01:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862335$
2013-10-11 01:43 - 2013-10-11 01:43 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2847311$
2013-10-11 01:43 - 2013-08-07 02:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-10-11 01:39 - 2011-05-04 19:36 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
2013-10-11 01:39 - 2007-10-18 10:59 - 78106760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-10-11 01:38 - 2013-10-11 01:38 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2884256$
2013-10-11 01:37 - 2013-10-11 01:37 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868038$
2013-10-11 01:36 - 2013-10-11 01:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2883150$
2013-10-11 01:36 - 2013-10-11 01:36 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862330$
Files to move or delete:
====================
C:\Documents and Settings\Administrator\psbB91.dll
C:\Documents and Settings\Administrator\ptsA52.dll
Some content of TEMP:
====================
C:\Documents and Settings\Administrator\Local Settings\Temp\appshat-distribution.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\bi_cleaner.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\hpzmsi01.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\hpzscr01.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\MoviesToolbarSetup_Somoto.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\oi_{E1D68687-F96A-4AE7-9EDB-2E59C2DE99E4}.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\PIPInstaller_PTV_.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\UNINSTALL.EXE
C:\Documents and Settings\Administrator\Local Settings\Temp\UpdateCheckerSetup.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\_TinDel.exe
C:\Documents and Settings\NetworkService\Local Settings\Temp\mpam-e2573639.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================