"Policejní virus"
Napsal: 02 pro 2013 11:10
Dobrý den,
nedávno jsem odstraňoval "policejní virus", ale asi někde něco zůstalo neb se dnes objevil znovu. Počítač jsem projel esetem, adw, ccleaner, mwav ... Prosím o kontrolu přiloženého logu.
Ještě si dovolím podělit se o drobnou radu. V případě vyskočení známé obrazovky "policejního viru", ho lze poměrně snadno "stopnout". Stačí k tomu 2 párátka nebo třeba sirky. Těmi zafixujeme "Ctrl" a "Alt". Nyní máme obě ruce volné pro mačkání "Del" a používání myši. Pak už můžeme s trochou trpělivosti operovat v Taksmanageru a povypínat patřičné procesy
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-12-2013
Ran by Jaryn (administrator) on JARYN on 02-12-2013 11:02:13
Running from C:\Program Files\Opera\profile\temporary_downloads
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
() C:\Program Files\Samsung\USB Drivers\26_VIA_driver2\x86\VIAService.exe
(Microsoft Corporation) C:\WINDOWS\system32\cisvc.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Teruten) C:\WINDOWS\system32\FsUsbExService.Exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
(HP) C:\WINDOWS\system32\HPZipm12.exe
(Microsoft Corporation) C:\WINDOWS\system32\cidaemon.exe
(Microsoft Corporation) C:\WINDOWS\system32\cidaemon.exe
(Opera Software) C:\Program Files\Opera\opera.exe
(C. Ghisler & Co.) C:\totalcmd\TOTALCMD.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5110672 2013-09-12] (ESET)
Winlogon\Notify\AtiExtEvent: C:\Windows\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKCU\...\Policies\Explorer: [TaskbarNoNotification] 1
HKCU\...\Policies\Explorer: [HideSCAHealth] 1
HKU\Default User\...\RunOnce: [_nltide_2] - regsvr32 /s /n /i:U shell32
HKU\x\...\Run: [CTFMON.EXE] - C:\WINDOWS.0\system32\ctfmon.exe
==================== Internet (Whitelisted) ====================
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Hosts: 127.0.0.1 localhost
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
========================== Services (Whitelisted) =================
R2 CDMA Device Service; C:\Program Files\Samsung\USB Drivers\26_VIA_driver2\x86\VIAService.exe [63488 2011-08-02] ()
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1337752 2013-09-12] (ESET)
S4 IISADMIN; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15872 2008-04-14] (Microsoft Corporation)
S4 W3SVC; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2008-04-14] (Microsoft Corporation)
S4 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf"
==================== Drivers (Whitelisted) ====================
S3 61883; C:\Windows\System32\DRIVERS\61883.sys [48128 2008-04-13] (Microsoft Corporation)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [16384 2004-07-09] (Microsoft Corporation)
R1 eamon; C:\Windows\System32\DRIVERS\eamon.sys [184664 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [134248 2013-09-17] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [174400 2013-09-17] (ESET)
R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [38952 2013-09-17] (ESET)
R1 epfwtdi; C:\Windows\System32\DRIVERS\epfwtdi.sys [61600 2013-09-17] (ESET)
R3 FsUsbExDisk; C:\WINDOWS\system32\FsUsbExDisk.SYS [36608 2010-06-14] ()
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49664 2005-10-28] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2005-10-28] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2005-10-28] (HP)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2006-02-26] ()
R0 mv61xx; C:\Windows\System32\DRIVERS\mv61xx.sys [151592 2008-08-28] (Marvell Semiconductor, Inc.)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10112 2004-07-09] (Microsoft Corporation)
R3 SenFiltService; C:\Windows\System32\drivers\Senfilt.sys [1366144 2009-08-21] (Creative Technology Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2011-10-24] ()
S3 trufos; C:\Windows\System32\drivers\trufos.sys [343456 2013-11-18] (BitDefender S.R.L.)
S3 w800bus; C:\Windows\System32\DRIVERS\w800bus.sys [52384 2005-05-24] (MCCI)
S3 w800mdfl; C:\Windows\System32\DRIVERS\w800mdfl.sys [6096 2005-05-24] (MCCI)
S3 w800mdm; C:\Windows\System32\DRIVERS\w800mdm.sys [87424 2005-05-24] (MCCI)
S3 w800mgmt; C:\Windows\System32\DRIVERS\w800mgmt.sys [79216 2005-05-24] (MCCI)
S3 w800obex; C:\Windows\System32\DRIVERS\w800obex.sys [77040 2005-05-24] (MCCI)
S3 wceusbsh; C:\Windows\System32\DRIVERS\wceusbsh.sys [28672 2006-11-06] (Microsoft Corporation)
R3 yukonwxp; C:\Windows\System32\DRIVERS\yk51x86.sys [296448 2008-12-09] (Marvell)
U3 a0i9uwwj; C:\Windows\System32\Drivers\a0i9uwwj.sys [0 ] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-02 11:01 - 2013-12-02 11:01 - 00000000 ____D C:\FRST
2013-12-02 10:33 - 2013-12-02 10:46 - 00002279 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-02 10:21 - 2013-12-02 10:43 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-12-02 10:21 - 2013-12-02 10:43 - 00000051 _____ C:\WINDOWS\wiaservc.log
2013-12-02 10:21 - 2013-12-02 10:21 - 00000000 ____N C:\WINDOWS\Sti_Trace.log
2013-12-02 09:44 - 2013-12-02 09:44 - 00002576 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_094400.reg
2013-12-02 09:34 - 2013-12-02 09:35 - 06087819 _____ C:\WINDOWS\REGBK00.ZIP
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\VDLL.DLL
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\system32\runouce.exe
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\RUNDL132.EXE
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\logo_1.exe
2013-12-02 09:20 - 2013-12-02 10:17 - 00000054 _____ C:\WINDOWS\Lic.xxx
2013-12-02 09:19 - 2013-12-02 09:19 - 00632064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr80.dll
2013-12-02 09:19 - 2013-12-02 09:19 - 00554240 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp80.dll
2013-12-02 09:19 - 2013-12-02 09:19 - 00034048 _____ (MicroWorld Technologies Inc.) C:\WINDOWS\system32\eEmpty.exe
2013-12-02 09:19 - 2013-12-02 09:19 - 00000759 _____ C:\Documents and Settings\Jaryn\Plocha\MWAVSCAN.lnk
2013-12-02 09:19 - 2013-12-02 09:19 - 00000000 ____D C:\Program Files\Common Files\MicroWorld
2013-12-02 09:19 - 2013-12-02 09:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\MicroWorld
2013-12-02 09:19 - 2008-04-14 07:52 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\REGEDIT.COM
2013-12-02 09:19 - 2008-04-14 07:52 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\R.COM
2013-12-02 09:19 - 2008-04-14 07:52 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\TASKMGR.COM
2013-12-02 09:19 - 2008-04-14 07:52 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\T.COM
2013-12-02 09:13 - 2013-12-02 10:33 - 00000000 ____D C:\AdwCleaner
2013-12-02 09:09 - 2013-12-02 09:09 - 00034444 _____ C:\Documents and Settings\Jaryn\Plocha\gmer.log
2013-12-02 08:54 - 2013-12-02 08:54 - 00001046 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_085439.reg
2013-12-02 07:45 - 2013-12-02 07:45 - 00000414 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_074545.reg
2013-12-02 07:34 - 2013-12-02 07:34 - 00005630 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_S_12022013_073406.txt
2013-12-02 07:34 - 2013-12-02 07:34 - 00005470 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_D_12022013_073413.txt
2013-12-02 07:33 - 2013-12-02 07:33 - 00001463 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_SC_12022013_073300.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00001463 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_SC_12022013_073254.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000975 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_H_12022013_073201.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000856 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_PR_12022013_073234.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000811 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_DN_12022013_073238.txt
2013-12-02 07:31 - 2013-12-02 07:31 - 00009602 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_D_12022013_073130.txt
2013-12-02 07:30 - 2013-12-02 07:30 - 00006881 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_S_12022013_073057.txt
2013-11-30 09:47 - 2013-11-30 09:47 - 00001286 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131130_094705.reg
2013-11-30 09:30 - 2013-12-02 06:53 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\dXDvr333
2013-11-19 17:42 - 2013-11-19 17:42 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\MyPhoneExplorer
2013-11-19 15:10 - 2013-11-19 15:10 - 00001769 _____ C:\WINDOWS\Language_trs.ini
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Intel
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Documents and Settings\Jaryn\Data aplikací\InstallShield
2013-11-19 14:21 - 2013-11-19 14:21 - 00000000 ___RD C:\WINDOWS\AsDmiHtm
2013-11-19 13:24 - 2013-11-19 13:24 - 98989148 _____ C:\Documents and Settings\Jaryn\Dokumenty\BackupRegistry(20131119).reg
2013-11-19 13:20 - 2013-11-19 13:20 - 00001452 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131119_132014.reg
2013-11-19 13:10 - 2013-11-19 13:10 - 00000512 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131119_131033.reg
2013-11-19 11:19 - 2013-11-19 11:19 - 00089119 _____ C:\Documents and Settings\Jaryn\Plocha\cpuz
2013-11-19 11:19 - 2013-11-19 11:19 - 00089119 _____ C:\Documents and Settings\Jaryn\Dokumenty\cpuz
2013-11-19 11:18 - 2013-11-19 11:18 - 00000000 ____D C:\Program Files\CPUID
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\WINDOWS\system32\xircom
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\Program Files\xerox
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\Program Files\microsoft frontpage
2013-11-19 00:18 - 2013-11-19 00:18 - 00012612 _____ C:\Documents and Settings\Jaryn\Plocha\MWAV.LOG
2013-11-18 21:24 - 2013-11-18 21:24 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr90.dll
2013-11-18 21:24 - 2013-11-18 21:24 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp90.dll
2013-11-18 21:24 - 2013-11-18 21:24 - 00343456 _____ (BitDefender S.R.L.) C:\WINDOWS\system32\Drivers\trufos.sys
2013-11-18 21:05 - 2013-11-18 21:05 - 00000618 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131118_210459.reg
2013-11-18 19:42 - 2009-04-01 12:28 - 00093184 ____R (ATI Research Inc.) C:\WINDOWS\system32\Drivers\AtiHdmi.sys
2013-11-18 19:26 - 2013-11-19 14:21 - 00013269 _____ C:\WINDOWS\Ascd_tmp.ini
2013-11-18 19:26 - 2013-11-19 14:21 - 00000000 _____ C:\WINDOWS\AS_Debug.txt
2013-11-18 19:26 - 2006-10-11 04:33 - 00010288 _____ C:\WINDOWS\system32\Drivers\ASUSHWIO.SYS
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-11-10 17:35 - 2013-11-10 17:35 - 00005630 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131110_173533.reg
2013-11-09 16:40 - 2013-12-02 09:11 - 00029696 _____ C:\Documents and Settings\Jaryn\Local Settings\Data aplikací\MSGBOX.EXE
2013-11-09 16:16 - 2013-11-09 16:16 - 00000000 ____D C:\WINDOWS\ERUNT
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\system.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\software.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\SECURITY.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\SAM.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\default.rctemp.LOG
2013-11-09 15:56 - 2013-11-09 15:56 - 98372722 _____ C:\Documents and Settings\Jaryn\Dokumenty\BackupRegistry(20131109).reg
2013-11-09 15:31 - 2013-11-09 15:31 - 00001930 _____ C:\Documents and Settings\Jaryn\Plocha\1-Click Cleaner.lnk
2013-11-09 15:31 - 2013-11-09 15:31 - 00001927 _____ C:\Documents and Settings\Jaryn\Plocha\WinXP Manager.lnk
2013-11-09 15:31 - 2013-11-09 15:31 - 00000000 ____D C:\Program Files\Yamicsoft
2013-11-09 15:31 - 2013-11-09 15:31 - 00000000 ____D C:\Documents and Settings\Jaryn\Nabídka Start\Programy\WinXP Manager
2013-11-09 14:19 - 2013-11-09 14:19 - 00004024 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131109_141947.reg
2013-11-09 13:48 - 2013-11-09 13:48 - 00002100 _____ C:\Documents and Settings\Jaryn\.recently-used.xbel
2013-11-06 15:56 - 2013-11-06 15:56 - 00029618 _____ C:\Documents and Settings\Jaryn\Dokumenty\res_trojuh.zip
2013-11-06 15:56 - 2013-11-06 15:56 - 00000000 ____D C:\Documents and Settings\Jaryn\Dokumenty\res_trojuh
2013-11-04 12:21 - 2013-11-04 12:21 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\ImgBurn
==================== One Month Modified Files and Folders =======
2013-12-02 11:01 - 2013-12-02 11:01 - 00000000 ____D C:\FRST
2013-12-02 10:57 - 2011-01-18 22:19 - 00002266 _____ C:\WINDOWS\WINCMD.INI
2013-12-02 10:46 - 2013-12-02 10:33 - 00002279 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-02 10:45 - 2011-01-18 21:48 - 00000000 ____D C:\WINDOWS\Registration
2013-12-02 10:45 - 2001-10-25 13:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-12-02 10:43 - 2013-12-02 10:21 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-12-02 10:43 - 2013-12-02 10:21 - 00000051 _____ C:\WINDOWS\wiaservc.log
2013-12-02 10:43 - 2011-01-18 21:53 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-02 10:40 - 2011-01-18 21:54 - 00000178 ___SH C:\Documents and Settings\Jaryn\ntuser.ini
2013-12-02 10:40 - 2011-01-18 21:53 - 00032412 _____ C:\WINDOWS\SchedLgU.Txt
2013-12-02 10:35 - 2011-01-18 22:41 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2013-12-02 10:35 - 2011-01-18 22:41 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-12-02 10:34 - 2011-01-18 22:38 - 00140440 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-02 10:33 - 2013-12-02 09:13 - 00000000 ____D C:\AdwCleaner
2013-12-02 10:33 - 2011-01-18 23:18 - 00065536 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2013-12-02 10:33 - 2011-01-18 21:54 - 00000000 ____D C:\Documents and Settings\Jaryn
2013-12-02 10:33 - 2011-01-18 21:49 - 00065536 _____ C:\WINDOWS\system32\config\Internet.evt
2013-12-02 10:28 - 2011-01-18 21:54 - 00000000 ____D C:\Documents and Settings\Jaryn\Plocha
2013-12-02 10:27 - 2011-01-18 22:37 - 00000223 ___SH C:\boot.ini
2013-12-02 10:27 - 2001-10-25 13:00 - 00001165 _____ C:\WINDOWS\win.ini
2013-12-02 10:27 - 2001-10-25 13:00 - 00000227 _____ C:\WINDOWS\system.ini
2013-12-02 10:21 - 2013-12-02 10:21 - 00000000 ____N C:\WINDOWS\Sti_Trace.log
2013-12-02 10:21 - 2011-01-18 21:54 - 00000000 ___RD C:\Documents and Settings\Jaryn\Nabídka Start\Programy\Po spuštění
2013-12-02 10:17 - 2013-12-02 09:20 - 00000054 _____ C:\WINDOWS\Lic.xxx
2013-12-02 10:12 - 2011-02-04 12:36 - 00306654 ____H C:\TREEINFO.WC
2013-12-02 10:11 - 2011-01-18 21:54 - 00000000 ___HD C:\Documents and Settings\Jaryn\Local Settings\Data aplikací
2013-12-02 09:47 - 2011-01-18 22:39 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2013-12-02 09:47 - 2011-01-18 21:54 - 00000000 ___RD C:\Documents and Settings\Jaryn\Data aplikací
2013-12-02 09:44 - 2013-12-02 09:44 - 00002576 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_094400.reg
2013-12-02 09:44 - 2011-01-18 21:54 - 00000000 ___RD C:\Documents and Settings\Jaryn\Dokumenty
2013-12-02 09:35 - 2013-12-02 09:34 - 06087819 _____ C:\WINDOWS\REGBK00.ZIP
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\VDLL.DLL
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\system32\runouce.exe
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\RUNDL132.EXE
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\logo_1.exe
2013-12-02 09:19 - 2013-12-02 09:19 - 00632064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr80.dll
2013-12-02 09:19 - 2013-12-02 09:19 - 00554240 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp80.dll
2013-12-02 09:19 - 2013-12-02 09:19 - 00034048 _____ (MicroWorld Technologies Inc.) C:\WINDOWS\system32\eEmpty.exe
2013-12-02 09:19 - 2013-12-02 09:19 - 00000759 _____ C:\Documents and Settings\Jaryn\Plocha\MWAVSCAN.lnk
2013-12-02 09:19 - 2013-12-02 09:19 - 00000000 ____D C:\Program Files\Common Files\MicroWorld
2013-12-02 09:19 - 2013-12-02 09:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\MicroWorld
2013-12-02 09:18 - 2011-01-18 21:49 - 00000000 ____D C:\WINDOWS\system32\Restore
2013-12-02 09:11 - 2013-11-09 16:40 - 00029696 _____ C:\Documents and Settings\Jaryn\Local Settings\Data aplikací\MSGBOX.EXE
2013-12-02 09:11 - 2011-01-18 22:22 - 00000000 ____D C:\Program Files\Opera
2013-12-02 09:09 - 2013-12-02 09:09 - 00034444 _____ C:\Documents and Settings\Jaryn\Plocha\gmer.log
2013-12-02 08:54 - 2013-12-02 08:54 - 00001046 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_085439.reg
2013-12-02 08:49 - 2013-09-17 08:20 - 00000000 ____D C:\Documents and Settings\Jaryn\Plocha\RK_Quarantine
2013-12-02 07:46 - 2013-10-31 10:54 - 00000715 _____ C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2013-12-02 07:46 - 2013-10-31 10:54 - 00000000 ____D C:\Program Files\CCleaner
2013-12-02 07:45 - 2013-12-02 07:45 - 00000414 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_074545.reg
2013-12-02 07:34 - 2013-12-02 07:34 - 00005630 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_S_12022013_073406.txt
2013-12-02 07:34 - 2013-12-02 07:34 - 00005470 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_D_12022013_073413.txt
2013-12-02 07:33 - 2013-12-02 07:33 - 00001463 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_SC_12022013_073300.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00001463 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_SC_12022013_073254.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000975 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_H_12022013_073201.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000856 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_PR_12022013_073234.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000811 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_DN_12022013_073238.txt
2013-12-02 07:31 - 2013-12-02 07:31 - 00009602 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_D_12022013_073130.txt
2013-12-02 07:30 - 2013-12-02 07:30 - 00006881 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_S_12022013_073057.txt
2013-12-02 06:53 - 2013-11-30 09:30 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\dXDvr333
2013-11-30 17:30 - 2011-01-18 21:47 - 00000000 ____D C:\Inetpub
2013-11-30 09:47 - 2013-11-30 09:47 - 00001286 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131130_094705.reg
2013-11-30 09:30 - 2011-01-19 08:20 - 00000000 ____D C:\Program Files\Google
2013-11-30 09:30 - 2011-01-19 08:20 - 00000000 ____D C:\Documents and Settings\Jaryn\Local Settings\Data aplikací\Google
2013-11-19 17:42 - 2013-11-19 17:42 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\MyPhoneExplorer
2013-11-19 17:42 - 2011-09-05 15:38 - 00001777 _____ C:\Documents and Settings\All Users\Plocha\MyPhoneExplorer.lnk
2013-11-19 17:42 - 2011-09-05 15:38 - 00000000 ____D C:\Program Files\MyPhoneExplorer
2013-11-19 17:05 - 2011-01-18 23:18 - 00028680 ____C C:\Documents and Settings\Jaryn\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2013-11-19 15:10 - 2013-11-19 15:10 - 00001769 _____ C:\WINDOWS\Language_trs.ini
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Intel
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Documents and Settings\Jaryn\Data aplikací\InstallShield
2013-11-19 15:10 - 2011-01-18 22:03 - 00000000 ____D C:\Program Files\InstallShield Installation Information
2013-11-19 14:21 - 2013-11-19 14:21 - 00000000 ___RD C:\WINDOWS\AsDmiHtm
2013-11-19 14:21 - 2013-11-18 19:26 - 00013269 _____ C:\WINDOWS\Ascd_tmp.ini
2013-11-19 14:21 - 2013-11-18 19:26 - 00000000 _____ C:\WINDOWS\AS_Debug.txt
2013-11-19 13:24 - 2013-11-19 13:24 - 98989148 _____ C:\Documents and Settings\Jaryn\Dokumenty\BackupRegistry(20131119).reg
2013-11-19 13:20 - 2013-11-19 13:20 - 00001452 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131119_132014.reg
2013-11-19 13:10 - 2013-11-19 13:10 - 00000512 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131119_131033.reg
2013-11-19 13:08 - 2011-01-18 21:51 - 00001507 _____ C:\Documents and Settings\All Users\Nabídka Start\Windows Update.lnk
2013-11-19 11:19 - 2013-11-19 11:19 - 00089119 _____ C:\Documents and Settings\Jaryn\Plocha\cpuz
2013-11-19 11:19 - 2013-11-19 11:19 - 00089119 _____ C:\Documents and Settings\Jaryn\Dokumenty\cpuz
2013-11-19 11:18 - 2013-11-19 11:18 - 00000000 ____D C:\Program Files\CPUID
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\WINDOWS\system32\xircom
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\Program Files\xerox
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\Program Files\microsoft frontpage
2013-11-19 00:18 - 2013-11-19 00:18 - 00012612 _____ C:\Documents and Settings\Jaryn\Plocha\MWAV.LOG
2013-11-18 21:24 - 2013-11-18 21:24 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr90.dll
2013-11-18 21:24 - 2013-11-18 21:24 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp90.dll
2013-11-18 21:24 - 2013-11-18 21:24 - 00343456 _____ (BitDefender S.R.L.) C:\WINDOWS\system32\Drivers\trufos.sys
2013-11-18 21:05 - 2013-11-18 21:05 - 00000618 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131118_210459.reg
2013-11-18 19:39 - 2011-01-18 22:35 - 00000000 ____D C:\WINDOWS\system
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-11-16 05:30 - 2013-08-14 08:07 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-16 05:29 - 2011-01-19 14:21 - 80340640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-10 17:35 - 2013-11-10 17:35 - 00005630 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131110_173533.reg
2013-11-09 16:16 - 2013-11-09 16:16 - 00000000 ____D C:\WINDOWS\ERUNT
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\system.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\software.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\SECURITY.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\SAM.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\default.rctemp.LOG
2013-11-09 15:58 - 2011-01-18 22:38 - 00057344 _____ C:\WINDOWS\system32\config\SECURITY.rcbak
2013-11-09 15:58 - 2011-01-18 22:38 - 00028672 _____ C:\WINDOWS\system32\config\SAM.rcbak
2013-11-09 15:58 - 2011-01-18 22:37 - 27000832 _____ C:\WINDOWS\system32\config\software.rcbak
2013-11-09 15:58 - 2011-01-18 22:37 - 10747904 _____ C:\WINDOWS\system32\config\system.rcbak
2013-11-09 15:58 - 2011-01-18 22:37 - 00524288 _____ C:\WINDOWS\system32\config\default.rcbak
2013-11-09 15:58 - 2011-01-18 21:53 - 00000000 __SHD C:\Documents and Settings\NetworkService
2013-11-09 15:58 - 2011-01-18 21:53 - 00000000 __SHD C:\Documents and Settings\LocalService
2013-11-09 15:56 - 2013-11-09 15:56 - 98372722 _____ C:\Documents and Settings\Jaryn\Dokumenty\BackupRegistry(20131109).reg
2013-11-09 15:52 - 2011-01-18 21:54 - 00000000 ___RD C:\Documents and Settings\Jaryn\Nabídka Start\Programy
2013-11-09 15:45 - 2011-01-18 23:28 - 00000000 ____D C:\Program Files\WinRAR
2013-11-09 15:45 - 2011-01-18 22:35 - 00000000 ____D C:\WINDOWS\twain_32
2013-11-09 15:44 - 2013-10-31 11:47 - 00000000 ___RD C:\Documents and Settings\All Users.WINDOWS.0\Nabídka Start\Programy\Hry
2013-11-09 15:44 - 2011-12-20 17:13 - 00000000 ____D C:\Documents and Settings\Jaryn\Plocha\[originální]
2013-11-09 15:44 - 2011-01-18 21:54 - 00000000 ___RD C:\Documents and Settings\Jaryn\Dokumenty\Obrázky
2013-11-09 15:31 - 2013-11-09 15:31 - 00001930 _____ C:\Documents and Settings\Jaryn\Plocha\1-Click Cleaner.lnk
2013-11-09 15:31 - 2013-11-09 15:31 - 00001927 _____ C:\Documents and Settings\Jaryn\Plocha\WinXP Manager.lnk
2013-11-09 15:31 - 2013-11-09 15:31 - 00000000 ____D C:\Program Files\Yamicsoft
2013-11-09 15:31 - 2013-11-09 15:31 - 00000000 ____D C:\Documents and Settings\Jaryn\Nabídka Start\Programy\WinXP Manager
2013-11-09 14:19 - 2013-11-09 14:19 - 00004024 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131109_141947.reg
2013-11-09 13:48 - 2013-11-09 13:48 - 00002100 _____ C:\Documents and Settings\Jaryn\.recently-used.xbel
2013-11-09 13:48 - 2011-01-22 10:56 - 00000000 ____D C:\Documents and Settings\Jaryn\Data aplikací\gtk-2.0
2013-11-09 13:48 - 2011-01-22 10:54 - 00000000 ____D C:\Documents and Settings\Jaryn\.gimp-2.6
2013-11-06 15:56 - 2013-11-06 15:56 - 00029618 _____ C:\Documents and Settings\Jaryn\Dokumenty\res_trojuh.zip
2013-11-06 15:56 - 2013-11-06 15:56 - 00000000 ____D C:\Documents and Settings\Jaryn\Dokumenty\res_trojuh
2013-11-04 12:21 - 2013-11-04 12:21 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\ImgBurn
2013-11-04 12:21 - 2013-04-20 19:12 - 00001561 _____ C:\Documents and Settings\All Users\Plocha\ImgBurn.lnk
Some content of TEMP:
====================
C:\Documents and Settings\Jaryn\Local Settings\Temp\avcuf32.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\avcuf64.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\avxdisk.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdc.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdcore.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdfltlib2k.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdnimbus32.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdnimbus64.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdupdateservice.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\DEVCON.EXE
C:\Documents and Settings\Jaryn\Local Settings\Temp\eEmpty.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\encdec.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\esupdate.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\FSSync.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\Getvlist.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\ikave.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\ipc.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\kave.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\kavvlg.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\msvclnt.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\msvcp80.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\msvcr80.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\msvl64.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\msvlclnt.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\mwavdwnl.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\MWAVL.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\mwavscan.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\mwunzip.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\prLoader.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\red32.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\Reload.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\scan.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\ScanningProcess.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\setpriv.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\test2.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\trufos.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\unregx.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\UPDLL10.DLL
C:\Documents and Settings\Jaryn\Local Settings\Temp\viewtcp.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\Windows\System32\winlogon.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\Windows\System32\svchost.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\Windows\System32\services.exe
[2008-04-14 07:52] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\Windows\System32\User32.dll
[2008-04-14 07:52] - [2008-04-14 07:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\Windows\System32\userinit.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\Windows\System32\Drivers\volsnap.sys
[2008-04-14 06:42] - [2008-04-14 06:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================
nedávno jsem odstraňoval "policejní virus", ale asi někde něco zůstalo neb se dnes objevil znovu. Počítač jsem projel esetem, adw, ccleaner, mwav ... Prosím o kontrolu přiloženého logu.
Ještě si dovolím podělit se o drobnou radu. V případě vyskočení známé obrazovky "policejního viru", ho lze poměrně snadno "stopnout". Stačí k tomu 2 párátka nebo třeba sirky. Těmi zafixujeme "Ctrl" a "Alt". Nyní máme obě ruce volné pro mačkání "Del" a používání myši. Pak už můžeme s trochou trpělivosti operovat v Taksmanageru a povypínat patřičné procesy

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-12-2013
Ran by Jaryn (administrator) on JARYN on 02-12-2013 11:02:13
Running from C:\Program Files\Opera\profile\temporary_downloads
Systém Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
() C:\Program Files\Samsung\USB Drivers\26_VIA_driver2\x86\VIAService.exe
(Microsoft Corporation) C:\WINDOWS\system32\cisvc.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Teruten) C:\WINDOWS\system32\FsUsbExService.Exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
(HP) C:\WINDOWS\system32\HPZipm12.exe
(Microsoft Corporation) C:\WINDOWS\system32\cidaemon.exe
(Microsoft Corporation) C:\WINDOWS\system32\cidaemon.exe
(Opera Software) C:\Program Files\Opera\opera.exe
(C. Ghisler & Co.) C:\totalcmd\TOTALCMD.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5110672 2013-09-12] (ESET)
Winlogon\Notify\AtiExtEvent: C:\Windows\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKCU\...\Policies\Explorer: [TaskbarNoNotification] 1
HKCU\...\Policies\Explorer: [HideSCAHealth] 1
HKU\Default User\...\RunOnce: [_nltide_2] - regsvr32 /s /n /i:U shell32
HKU\x\...\Run: [CTFMON.EXE] - C:\WINDOWS.0\system32\ctfmon.exe
==================== Internet (Whitelisted) ====================
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
Hosts: 127.0.0.1 localhost
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
========================== Services (Whitelisted) =================
R2 CDMA Device Service; C:\Program Files\Samsung\USB Drivers\26_VIA_driver2\x86\VIAService.exe [63488 2011-08-02] ()
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1337752 2013-09-12] (ESET)
S4 IISADMIN; C:\WINDOWS\system32\inetsrv\inetinfo.exe [15872 2008-04-14] (Microsoft Corporation)
S4 W3SVC; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2008-04-14] (Microsoft Corporation)
S4 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf"
==================== Drivers (Whitelisted) ====================
S3 61883; C:\Windows\System32\DRIVERS\61883.sys [48128 2008-04-13] (Microsoft Corporation)
S3 CCDECODE; C:\Windows\System32\DRIVERS\CCDECODE.sys [16384 2004-07-09] (Microsoft Corporation)
R1 eamon; C:\Windows\System32\DRIVERS\eamon.sys [184664 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [134248 2013-09-17] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [174400 2013-09-17] (ESET)
R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [38952 2013-09-17] (ESET)
R1 epfwtdi; C:\Windows\System32\DRIVERS\epfwtdi.sys [61600 2013-09-17] (ESET)
R3 FsUsbExDisk; C:\WINDOWS\system32\FsUsbExDisk.SYS [36608 2010-06-14] ()
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49664 2005-10-28] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2005-10-28] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2005-10-28] (HP)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2006-02-26] ()
R0 mv61xx; C:\Windows\System32\DRIVERS\mv61xx.sys [151592 2008-08-28] (Marvell Semiconductor, Inc.)
S3 NdisIP; C:\Windows\System32\DRIVERS\NdisIP.sys [10112 2004-07-09] (Microsoft Corporation)
R3 SenFiltService; C:\Windows\System32\drivers\Senfilt.sys [1366144 2009-08-21] (Creative Technology Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2011-10-24] ()
S3 trufos; C:\Windows\System32\drivers\trufos.sys [343456 2013-11-18] (BitDefender S.R.L.)
S3 w800bus; C:\Windows\System32\DRIVERS\w800bus.sys [52384 2005-05-24] (MCCI)
S3 w800mdfl; C:\Windows\System32\DRIVERS\w800mdfl.sys [6096 2005-05-24] (MCCI)
S3 w800mdm; C:\Windows\System32\DRIVERS\w800mdm.sys [87424 2005-05-24] (MCCI)
S3 w800mgmt; C:\Windows\System32\DRIVERS\w800mgmt.sys [79216 2005-05-24] (MCCI)
S3 w800obex; C:\Windows\System32\DRIVERS\w800obex.sys [77040 2005-05-24] (MCCI)
S3 wceusbsh; C:\Windows\System32\DRIVERS\wceusbsh.sys [28672 2006-11-06] (Microsoft Corporation)
R3 yukonwxp; C:\Windows\System32\DRIVERS\yk51x86.sys [296448 2008-12-09] (Marvell)
U3 a0i9uwwj; C:\Windows\System32\Drivers\a0i9uwwj.sys [0 ] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-02 11:01 - 2013-12-02 11:01 - 00000000 ____D C:\FRST
2013-12-02 10:33 - 2013-12-02 10:46 - 00002279 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-02 10:21 - 2013-12-02 10:43 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-12-02 10:21 - 2013-12-02 10:43 - 00000051 _____ C:\WINDOWS\wiaservc.log
2013-12-02 10:21 - 2013-12-02 10:21 - 00000000 ____N C:\WINDOWS\Sti_Trace.log
2013-12-02 09:44 - 2013-12-02 09:44 - 00002576 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_094400.reg
2013-12-02 09:34 - 2013-12-02 09:35 - 06087819 _____ C:\WINDOWS\REGBK00.ZIP
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\VDLL.DLL
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\system32\runouce.exe
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\RUNDL132.EXE
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\logo_1.exe
2013-12-02 09:20 - 2013-12-02 10:17 - 00000054 _____ C:\WINDOWS\Lic.xxx
2013-12-02 09:19 - 2013-12-02 09:19 - 00632064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr80.dll
2013-12-02 09:19 - 2013-12-02 09:19 - 00554240 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp80.dll
2013-12-02 09:19 - 2013-12-02 09:19 - 00034048 _____ (MicroWorld Technologies Inc.) C:\WINDOWS\system32\eEmpty.exe
2013-12-02 09:19 - 2013-12-02 09:19 - 00000759 _____ C:\Documents and Settings\Jaryn\Plocha\MWAVSCAN.lnk
2013-12-02 09:19 - 2013-12-02 09:19 - 00000000 ____D C:\Program Files\Common Files\MicroWorld
2013-12-02 09:19 - 2013-12-02 09:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\MicroWorld
2013-12-02 09:19 - 2008-04-14 07:52 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\REGEDIT.COM
2013-12-02 09:19 - 2008-04-14 07:52 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\R.COM
2013-12-02 09:19 - 2008-04-14 07:52 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\TASKMGR.COM
2013-12-02 09:19 - 2008-04-14 07:52 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\T.COM
2013-12-02 09:13 - 2013-12-02 10:33 - 00000000 ____D C:\AdwCleaner
2013-12-02 09:09 - 2013-12-02 09:09 - 00034444 _____ C:\Documents and Settings\Jaryn\Plocha\gmer.log
2013-12-02 08:54 - 2013-12-02 08:54 - 00001046 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_085439.reg
2013-12-02 07:45 - 2013-12-02 07:45 - 00000414 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_074545.reg
2013-12-02 07:34 - 2013-12-02 07:34 - 00005630 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_S_12022013_073406.txt
2013-12-02 07:34 - 2013-12-02 07:34 - 00005470 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_D_12022013_073413.txt
2013-12-02 07:33 - 2013-12-02 07:33 - 00001463 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_SC_12022013_073300.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00001463 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_SC_12022013_073254.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000975 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_H_12022013_073201.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000856 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_PR_12022013_073234.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000811 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_DN_12022013_073238.txt
2013-12-02 07:31 - 2013-12-02 07:31 - 00009602 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_D_12022013_073130.txt
2013-12-02 07:30 - 2013-12-02 07:30 - 00006881 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_S_12022013_073057.txt
2013-11-30 09:47 - 2013-11-30 09:47 - 00001286 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131130_094705.reg
2013-11-30 09:30 - 2013-12-02 06:53 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\dXDvr333
2013-11-19 17:42 - 2013-11-19 17:42 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\MyPhoneExplorer
2013-11-19 15:10 - 2013-11-19 15:10 - 00001769 _____ C:\WINDOWS\Language_trs.ini
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Intel
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Documents and Settings\Jaryn\Data aplikací\InstallShield
2013-11-19 14:21 - 2013-11-19 14:21 - 00000000 ___RD C:\WINDOWS\AsDmiHtm
2013-11-19 13:24 - 2013-11-19 13:24 - 98989148 _____ C:\Documents and Settings\Jaryn\Dokumenty\BackupRegistry(20131119).reg
2013-11-19 13:20 - 2013-11-19 13:20 - 00001452 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131119_132014.reg
2013-11-19 13:10 - 2013-11-19 13:10 - 00000512 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131119_131033.reg
2013-11-19 11:19 - 2013-11-19 11:19 - 00089119 _____ C:\Documents and Settings\Jaryn\Plocha\cpuz
2013-11-19 11:19 - 2013-11-19 11:19 - 00089119 _____ C:\Documents and Settings\Jaryn\Dokumenty\cpuz
2013-11-19 11:18 - 2013-11-19 11:18 - 00000000 ____D C:\Program Files\CPUID
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\WINDOWS\system32\xircom
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\Program Files\xerox
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\Program Files\microsoft frontpage
2013-11-19 00:18 - 2013-11-19 00:18 - 00012612 _____ C:\Documents and Settings\Jaryn\Plocha\MWAV.LOG
2013-11-18 21:24 - 2013-11-18 21:24 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr90.dll
2013-11-18 21:24 - 2013-11-18 21:24 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp90.dll
2013-11-18 21:24 - 2013-11-18 21:24 - 00343456 _____ (BitDefender S.R.L.) C:\WINDOWS\system32\Drivers\trufos.sys
2013-11-18 21:05 - 2013-11-18 21:05 - 00000618 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131118_210459.reg
2013-11-18 19:42 - 2009-04-01 12:28 - 00093184 ____R (ATI Research Inc.) C:\WINDOWS\system32\Drivers\AtiHdmi.sys
2013-11-18 19:26 - 2013-11-19 14:21 - 00013269 _____ C:\WINDOWS\Ascd_tmp.ini
2013-11-18 19:26 - 2013-11-19 14:21 - 00000000 _____ C:\WINDOWS\AS_Debug.txt
2013-11-18 19:26 - 2006-10-11 04:33 - 00010288 _____ C:\WINDOWS\system32\Drivers\ASUSHWIO.SYS
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-11-10 17:35 - 2013-11-10 17:35 - 00005630 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131110_173533.reg
2013-11-09 16:40 - 2013-12-02 09:11 - 00029696 _____ C:\Documents and Settings\Jaryn\Local Settings\Data aplikací\MSGBOX.EXE
2013-11-09 16:16 - 2013-11-09 16:16 - 00000000 ____D C:\WINDOWS\ERUNT
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\system.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\software.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\SECURITY.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\SAM.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\default.rctemp.LOG
2013-11-09 15:56 - 2013-11-09 15:56 - 98372722 _____ C:\Documents and Settings\Jaryn\Dokumenty\BackupRegistry(20131109).reg
2013-11-09 15:31 - 2013-11-09 15:31 - 00001930 _____ C:\Documents and Settings\Jaryn\Plocha\1-Click Cleaner.lnk
2013-11-09 15:31 - 2013-11-09 15:31 - 00001927 _____ C:\Documents and Settings\Jaryn\Plocha\WinXP Manager.lnk
2013-11-09 15:31 - 2013-11-09 15:31 - 00000000 ____D C:\Program Files\Yamicsoft
2013-11-09 15:31 - 2013-11-09 15:31 - 00000000 ____D C:\Documents and Settings\Jaryn\Nabídka Start\Programy\WinXP Manager
2013-11-09 14:19 - 2013-11-09 14:19 - 00004024 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131109_141947.reg
2013-11-09 13:48 - 2013-11-09 13:48 - 00002100 _____ C:\Documents and Settings\Jaryn\.recently-used.xbel
2013-11-06 15:56 - 2013-11-06 15:56 - 00029618 _____ C:\Documents and Settings\Jaryn\Dokumenty\res_trojuh.zip
2013-11-06 15:56 - 2013-11-06 15:56 - 00000000 ____D C:\Documents and Settings\Jaryn\Dokumenty\res_trojuh
2013-11-04 12:21 - 2013-11-04 12:21 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\ImgBurn
==================== One Month Modified Files and Folders =======
2013-12-02 11:01 - 2013-12-02 11:01 - 00000000 ____D C:\FRST
2013-12-02 10:57 - 2011-01-18 22:19 - 00002266 _____ C:\WINDOWS\WINCMD.INI
2013-12-02 10:46 - 2013-12-02 10:33 - 00002279 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-02 10:45 - 2011-01-18 21:48 - 00000000 ____D C:\WINDOWS\Registration
2013-12-02 10:45 - 2001-10-25 13:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2013-12-02 10:43 - 2013-12-02 10:21 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-12-02 10:43 - 2013-12-02 10:21 - 00000051 _____ C:\WINDOWS\wiaservc.log
2013-12-02 10:43 - 2011-01-18 21:53 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-02 10:40 - 2011-01-18 21:54 - 00000178 ___SH C:\Documents and Settings\Jaryn\ntuser.ini
2013-12-02 10:40 - 2011-01-18 21:53 - 00032412 _____ C:\WINDOWS\SchedLgU.Txt
2013-12-02 10:35 - 2011-01-18 22:41 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2013-12-02 10:35 - 2011-01-18 22:41 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2013-12-02 10:34 - 2011-01-18 22:38 - 00140440 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-02 10:33 - 2013-12-02 09:13 - 00000000 ____D C:\AdwCleaner
2013-12-02 10:33 - 2011-01-18 23:18 - 00065536 _____ C:\WINDOWS\system32\config\ACEEvent.evt
2013-12-02 10:33 - 2011-01-18 21:54 - 00000000 ____D C:\Documents and Settings\Jaryn
2013-12-02 10:33 - 2011-01-18 21:49 - 00065536 _____ C:\WINDOWS\system32\config\Internet.evt
2013-12-02 10:28 - 2011-01-18 21:54 - 00000000 ____D C:\Documents and Settings\Jaryn\Plocha
2013-12-02 10:27 - 2011-01-18 22:37 - 00000223 ___SH C:\boot.ini
2013-12-02 10:27 - 2001-10-25 13:00 - 00001165 _____ C:\WINDOWS\win.ini
2013-12-02 10:27 - 2001-10-25 13:00 - 00000227 _____ C:\WINDOWS\system.ini
2013-12-02 10:21 - 2013-12-02 10:21 - 00000000 ____N C:\WINDOWS\Sti_Trace.log
2013-12-02 10:21 - 2011-01-18 21:54 - 00000000 ___RD C:\Documents and Settings\Jaryn\Nabídka Start\Programy\Po spuštění
2013-12-02 10:17 - 2013-12-02 09:20 - 00000054 _____ C:\WINDOWS\Lic.xxx
2013-12-02 10:12 - 2011-02-04 12:36 - 00306654 ____H C:\TREEINFO.WC
2013-12-02 10:11 - 2011-01-18 21:54 - 00000000 ___HD C:\Documents and Settings\Jaryn\Local Settings\Data aplikací
2013-12-02 09:47 - 2011-01-18 22:39 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2013-12-02 09:47 - 2011-01-18 21:54 - 00000000 ___RD C:\Documents and Settings\Jaryn\Data aplikací
2013-12-02 09:44 - 2013-12-02 09:44 - 00002576 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_094400.reg
2013-12-02 09:44 - 2011-01-18 21:54 - 00000000 ___RD C:\Documents and Settings\Jaryn\Dokumenty
2013-12-02 09:35 - 2013-12-02 09:34 - 06087819 _____ C:\WINDOWS\REGBK00.ZIP
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\VDLL.DLL
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\system32\runouce.exe
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\RUNDL132.EXE
2013-12-02 09:32 - 2013-12-02 09:32 - 00000000 ____D C:\WINDOWS\logo_1.exe
2013-12-02 09:19 - 2013-12-02 09:19 - 00632064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr80.dll
2013-12-02 09:19 - 2013-12-02 09:19 - 00554240 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp80.dll
2013-12-02 09:19 - 2013-12-02 09:19 - 00034048 _____ (MicroWorld Technologies Inc.) C:\WINDOWS\system32\eEmpty.exe
2013-12-02 09:19 - 2013-12-02 09:19 - 00000759 _____ C:\Documents and Settings\Jaryn\Plocha\MWAVSCAN.lnk
2013-12-02 09:19 - 2013-12-02 09:19 - 00000000 ____D C:\Program Files\Common Files\MicroWorld
2013-12-02 09:19 - 2013-12-02 09:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\MicroWorld
2013-12-02 09:18 - 2011-01-18 21:49 - 00000000 ____D C:\WINDOWS\system32\Restore
2013-12-02 09:11 - 2013-11-09 16:40 - 00029696 _____ C:\Documents and Settings\Jaryn\Local Settings\Data aplikací\MSGBOX.EXE
2013-12-02 09:11 - 2011-01-18 22:22 - 00000000 ____D C:\Program Files\Opera
2013-12-02 09:09 - 2013-12-02 09:09 - 00034444 _____ C:\Documents and Settings\Jaryn\Plocha\gmer.log
2013-12-02 08:54 - 2013-12-02 08:54 - 00001046 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_085439.reg
2013-12-02 08:49 - 2013-09-17 08:20 - 00000000 ____D C:\Documents and Settings\Jaryn\Plocha\RK_Quarantine
2013-12-02 07:46 - 2013-10-31 10:54 - 00000715 _____ C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2013-12-02 07:46 - 2013-10-31 10:54 - 00000000 ____D C:\Program Files\CCleaner
2013-12-02 07:45 - 2013-12-02 07:45 - 00000414 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131202_074545.reg
2013-12-02 07:34 - 2013-12-02 07:34 - 00005630 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_S_12022013_073406.txt
2013-12-02 07:34 - 2013-12-02 07:34 - 00005470 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_D_12022013_073413.txt
2013-12-02 07:33 - 2013-12-02 07:33 - 00001463 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_SC_12022013_073300.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00001463 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_SC_12022013_073254.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000975 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_H_12022013_073201.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000856 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_PR_12022013_073234.txt
2013-12-02 07:32 - 2013-12-02 07:32 - 00000811 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_DN_12022013_073238.txt
2013-12-02 07:31 - 2013-12-02 07:31 - 00009602 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_D_12022013_073130.txt
2013-12-02 07:30 - 2013-12-02 07:30 - 00006881 _____ C:\Documents and Settings\Jaryn\Plocha\RKreport[0]_S_12022013_073057.txt
2013-12-02 06:53 - 2013-11-30 09:30 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\dXDvr333
2013-11-30 17:30 - 2011-01-18 21:47 - 00000000 ____D C:\Inetpub
2013-11-30 09:47 - 2013-11-30 09:47 - 00001286 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131130_094705.reg
2013-11-30 09:30 - 2011-01-19 08:20 - 00000000 ____D C:\Program Files\Google
2013-11-30 09:30 - 2011-01-19 08:20 - 00000000 ____D C:\Documents and Settings\Jaryn\Local Settings\Data aplikací\Google
2013-11-19 17:42 - 2013-11-19 17:42 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\MyPhoneExplorer
2013-11-19 17:42 - 2011-09-05 15:38 - 00001777 _____ C:\Documents and Settings\All Users\Plocha\MyPhoneExplorer.lnk
2013-11-19 17:42 - 2011-09-05 15:38 - 00000000 ____D C:\Program Files\MyPhoneExplorer
2013-11-19 17:05 - 2011-01-18 23:18 - 00028680 ____C C:\Documents and Settings\Jaryn\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2013-11-19 15:10 - 2013-11-19 15:10 - 00001769 _____ C:\WINDOWS\Language_trs.ini
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Intel
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Documents and Settings\Jaryn\Data aplikací\InstallShield
2013-11-19 15:10 - 2011-01-18 22:03 - 00000000 ____D C:\Program Files\InstallShield Installation Information
2013-11-19 14:21 - 2013-11-19 14:21 - 00000000 ___RD C:\WINDOWS\AsDmiHtm
2013-11-19 14:21 - 2013-11-18 19:26 - 00013269 _____ C:\WINDOWS\Ascd_tmp.ini
2013-11-19 14:21 - 2013-11-18 19:26 - 00000000 _____ C:\WINDOWS\AS_Debug.txt
2013-11-19 13:24 - 2013-11-19 13:24 - 98989148 _____ C:\Documents and Settings\Jaryn\Dokumenty\BackupRegistry(20131119).reg
2013-11-19 13:20 - 2013-11-19 13:20 - 00001452 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131119_132014.reg
2013-11-19 13:10 - 2013-11-19 13:10 - 00000512 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131119_131033.reg
2013-11-19 13:08 - 2011-01-18 21:51 - 00001507 _____ C:\Documents and Settings\All Users\Nabídka Start\Windows Update.lnk
2013-11-19 11:19 - 2013-11-19 11:19 - 00089119 _____ C:\Documents and Settings\Jaryn\Plocha\cpuz
2013-11-19 11:19 - 2013-11-19 11:19 - 00089119 _____ C:\Documents and Settings\Jaryn\Dokumenty\cpuz
2013-11-19 11:18 - 2013-11-19 11:18 - 00000000 ____D C:\Program Files\CPUID
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\WINDOWS\system32\xircom
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\Program Files\xerox
2013-11-19 07:12 - 2013-11-19 07:12 - 00000000 ____D C:\Program Files\microsoft frontpage
2013-11-19 00:18 - 2013-11-19 00:18 - 00012612 _____ C:\Documents and Settings\Jaryn\Plocha\MWAV.LOG
2013-11-18 21:24 - 2013-11-18 21:24 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr90.dll
2013-11-18 21:24 - 2013-11-18 21:24 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp90.dll
2013-11-18 21:24 - 2013-11-18 21:24 - 00343456 _____ (BitDefender S.R.L.) C:\WINDOWS\system32\Drivers\trufos.sys
2013-11-18 21:05 - 2013-11-18 21:05 - 00000618 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131118_210459.reg
2013-11-18 19:39 - 2011-01-18 22:35 - 00000000 ____D C:\WINDOWS\system
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-11-16 05:31 - 2013-11-16 05:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-11-16 05:30 - 2013-08-14 08:07 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-16 05:29 - 2011-01-19 14:21 - 80340640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-10 17:35 - 2013-11-10 17:35 - 00005630 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131110_173533.reg
2013-11-09 16:16 - 2013-11-09 16:16 - 00000000 ____D C:\WINDOWS\ERUNT
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\system.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\software.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\SECURITY.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\SAM.rctemp.LOG
2013-11-09 15:58 - 2013-11-09 15:58 - 00000000 ____H C:\WINDOWS\system32\config\default.rctemp.LOG
2013-11-09 15:58 - 2011-01-18 22:38 - 00057344 _____ C:\WINDOWS\system32\config\SECURITY.rcbak
2013-11-09 15:58 - 2011-01-18 22:38 - 00028672 _____ C:\WINDOWS\system32\config\SAM.rcbak
2013-11-09 15:58 - 2011-01-18 22:37 - 27000832 _____ C:\WINDOWS\system32\config\software.rcbak
2013-11-09 15:58 - 2011-01-18 22:37 - 10747904 _____ C:\WINDOWS\system32\config\system.rcbak
2013-11-09 15:58 - 2011-01-18 22:37 - 00524288 _____ C:\WINDOWS\system32\config\default.rcbak
2013-11-09 15:58 - 2011-01-18 21:53 - 00000000 __SHD C:\Documents and Settings\NetworkService
2013-11-09 15:58 - 2011-01-18 21:53 - 00000000 __SHD C:\Documents and Settings\LocalService
2013-11-09 15:56 - 2013-11-09 15:56 - 98372722 _____ C:\Documents and Settings\Jaryn\Dokumenty\BackupRegistry(20131109).reg
2013-11-09 15:52 - 2011-01-18 21:54 - 00000000 ___RD C:\Documents and Settings\Jaryn\Nabídka Start\Programy
2013-11-09 15:45 - 2011-01-18 23:28 - 00000000 ____D C:\Program Files\WinRAR
2013-11-09 15:45 - 2011-01-18 22:35 - 00000000 ____D C:\WINDOWS\twain_32
2013-11-09 15:44 - 2013-10-31 11:47 - 00000000 ___RD C:\Documents and Settings\All Users.WINDOWS.0\Nabídka Start\Programy\Hry
2013-11-09 15:44 - 2011-12-20 17:13 - 00000000 ____D C:\Documents and Settings\Jaryn\Plocha\[originální]
2013-11-09 15:44 - 2011-01-18 21:54 - 00000000 ___RD C:\Documents and Settings\Jaryn\Dokumenty\Obrázky
2013-11-09 15:31 - 2013-11-09 15:31 - 00001930 _____ C:\Documents and Settings\Jaryn\Plocha\1-Click Cleaner.lnk
2013-11-09 15:31 - 2013-11-09 15:31 - 00001927 _____ C:\Documents and Settings\Jaryn\Plocha\WinXP Manager.lnk
2013-11-09 15:31 - 2013-11-09 15:31 - 00000000 ____D C:\Program Files\Yamicsoft
2013-11-09 15:31 - 2013-11-09 15:31 - 00000000 ____D C:\Documents and Settings\Jaryn\Nabídka Start\Programy\WinXP Manager
2013-11-09 14:19 - 2013-11-09 14:19 - 00004024 _____ C:\Documents and Settings\Jaryn\Dokumenty\cc_20131109_141947.reg
2013-11-09 13:48 - 2013-11-09 13:48 - 00002100 _____ C:\Documents and Settings\Jaryn\.recently-used.xbel
2013-11-09 13:48 - 2011-01-22 10:56 - 00000000 ____D C:\Documents and Settings\Jaryn\Data aplikací\gtk-2.0
2013-11-09 13:48 - 2011-01-22 10:54 - 00000000 ____D C:\Documents and Settings\Jaryn\.gimp-2.6
2013-11-06 15:56 - 2013-11-06 15:56 - 00029618 _____ C:\Documents and Settings\Jaryn\Dokumenty\res_trojuh.zip
2013-11-06 15:56 - 2013-11-06 15:56 - 00000000 ____D C:\Documents and Settings\Jaryn\Dokumenty\res_trojuh
2013-11-04 12:21 - 2013-11-04 12:21 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\ImgBurn
2013-11-04 12:21 - 2013-04-20 19:12 - 00001561 _____ C:\Documents and Settings\All Users\Plocha\ImgBurn.lnk
Some content of TEMP:
====================
C:\Documents and Settings\Jaryn\Local Settings\Temp\avcuf32.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\avcuf64.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\avxdisk.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdc.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdcore.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdfltlib2k.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdnimbus32.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdnimbus64.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\bdupdateservice.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\DEVCON.EXE
C:\Documents and Settings\Jaryn\Local Settings\Temp\eEmpty.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\encdec.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\esupdate.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\FSSync.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\Getvlist.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\ikave.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\ipc.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\kave.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\kavvlg.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\msvclnt.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\msvcp80.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\msvcr80.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\msvl64.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\msvlclnt.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\mwavdwnl.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\MWAVL.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\mwavscan.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\mwunzip.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\prLoader.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\Quarantine.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\red32.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\Reload.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\scan.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\ScanningProcess.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\setpriv.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\test2.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\trufos.dll
C:\Documents and Settings\Jaryn\Local Settings\Temp\unregx.exe
C:\Documents and Settings\Jaryn\Local Settings\Temp\UPDLL10.DLL
C:\Documents and Settings\Jaryn\Local Settings\Temp\viewtcp.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1
C:\Windows\System32\winlogon.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea
C:\Windows\System32\svchost.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93
C:\Windows\System32\services.exe
[2008-04-14 07:52] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7
C:\Windows\System32\User32.dll
[2008-04-14 07:52] - [2008-04-14 07:52] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53
C:\Windows\System32\userinit.exe
[2008-04-14 07:52] - [2008-04-14 07:52] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239
C:\Windows\System32\Drivers\volsnap.sys
[2008-04-14 06:42] - [2008-04-14 06:42] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1
==================== End Of Log ============================