Stránka 1 z 1

Nod hlási trojský kun /kryptik ....

Napsal: 25 led 2010 16:21
od onkel1
Tak zasa som sa pustil do boja z háveďou a potrebujem vašu pomoc .....

Pridávam log z hijakthisu

Kód: Vybrat vše

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:25:34, on 25.1.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\GoldenSoft\ChannelRg.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\qttask.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\netmon\netmon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\DOCUME~1\Tono\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Eset\nod32.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Eset\nod32.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\DOCUME~1\Tono\LOCALS~1\Temp\mexe.com
C:\DOCUME~1\Tono\LOCALS~1\temp\download.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) -  - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\ACE Mega CoDecS Pack\SystemS\RealMedia\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [netmon.exe] C:\Program Files\netmon\netmon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Tono\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [cdoosoft] C:\DOCUME~1\Tono\LOCALS~1\Temp\herss.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0C71BDAA-5B30-4E12-A317-D225FEB9A068} (AxVideoView Control) - http://fitsportse.dyndns.org/AxViewer/AxVideoView.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: ChannelRg - Unknown owner - C:\Program Files\Common Files\GoldenSoft\ChannelRg.exe
O23 - Service: Google Update Service (gupdate1c987ac865fb074) (gupdate1c987ac865fb074) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 9732 bytes

Re: Nod hlási trojský kun /kryptik ....

Napsal: 25 led 2010 16:55
od pitimir
Ahoj, hodim ti sem navody a na logy sa pozriem o taku hodinku-dve...medzitym idem behat :)

1) Stiahni OTL. Uloz na plochu a spust dvojklikom subor "OTL.exe". Otvori sa okno programu, v nom zaskrtni "Scan All Users", "Lop" aj "Purity Check" a "File Scan" zmen na 7 dni miesto 30. Do policka pod nazvom "Custom Scans/Fixes" skopiruj:

Kód: Vybrat vše

netsvcs
%SYSTEMDRIVE%\*.exe
%SYSTEMDRIVE%\eventlog.dll /s /md5
%SYSTEMDRIVE%\scecli.dll /s /md5
%SYSTEMDRIVE%\netlogon.dll /s /md5
%SYSTEMDRIVE%\cngaudit.dll /s /md5
%SYSTEMDRIVE%\sceclt.dll /s /md5
%SYSTEMDRIVE%\ntelogon.dll /s /md5
%SYSTEMDRIVE%\logevent.dll /s /md5
%SYSTEMDRIVE%\iaStor.sys /s /md5
%SYSTEMDRIVE%\nvstor.sys /s /md5
%SYSTEMDRIVE%\atapi.sys /s /md5
%SYSTEMDRIVE%\IdeChnDr.sys /s /md5
%SYSTEMDRIVE%\viasraid.sys /s /md5
%SYSTEMDRIVE%\AGP440.sys /s /md5
%SYSTEMDRIVE%\vaxscsi.sys /s /md5
%SYSTEMDRIVE%\nvatabus.sys /s /md5
%SYSTEMDRIVE%\viamraid.sys /s /md5
%SYSTEMDRIVE%\nvata.sys /s /md5
%SYSTEMROOT%\*. /mp /s
CREATERESTOREPOINT
%SYSTEMROOT%\system32\*.dll /lockedfiles
%SYSTEMROOT%\Tasks\*.job /lockedfiles
Potom klikni na "Run Scan". Zacne scan pocitaca, po jeho ukonceni sa otvoria dva reporty - obsah oboch potrebujem vidiet.


2) Stiahni GMER, rozbal ho na plochu a spust. Program automaticky zacne scan (po jeho skonceni vloz log c. 1) - pokial pri scanovani nieco najde (=vyskoci nejake upozornenie), klik na "NO" a nastavis program podla obrazku:
Obrázek
Klik na "Scan". Po scane klik na "Save" a log c. 2 vloz sem.

Ak nic nenajde (=nevyskoci nic), zaskrtaj vpravo vsetko a spusti scan. Po jeho ukonceni klik na "Copy" a vloz log c. 2.

Re: Nod hlási trojský kun /kryptik ....

Napsal: 25 led 2010 17:33
od onkel1
OTL.txt

Kód: Vybrat vše

OTL logfile created on: 25.1.2010 17:24:59 - Run 1
OTL by OldTimer - Version 3.1.26.0     Folder = C:\Documents and Settings\Tono\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 57,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 100,22 Gb Total Space | 43,75 Gb Free Space | 43,65% Space Free | Partition Type: NTFS
Drive D: | 197,87 Gb Total Space | 54,45 Gb Free Space | 27,52% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: PC
Current User Name: Tono
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 7 Days
Output = Standard
 
[color=#E56717]========== Processes (SafeList) ==========[/color]
 
PRC - [2010.01.25 17:22:50 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tono\Desktop\OTL.exe
PRC - [2010.01.24 21:25:04 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009.12.10 15:05:48 | 00,401,728 | ---- | M] (Nokia) -- C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
PRC - [2009.12.08 11:27:10 | 01,503,232 | ---- | M] (Nokia) -- C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
PRC - [2009.11.20 19:01:18 | 00,832,296 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2009.10.30 12:57:08 | 00,369,200 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2009.10.29 21:49:26 | 00,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\WINDOWS\system32\qttask.exe
PRC - [2009.10.27 09:26:36 | 00,657,408 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2009.10.27 09:15:44 | 00,132,608 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2009.10.27 09:15:02 | 00,120,832 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2009.10.27 09:13:44 | 00,090,112 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
PRC - [2009.10.21 10:24:00 | 00,272,384 | ---- | M] () -- C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe
PRC - [2009.10.09 13:11:12 | 25,623,336 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe
PRC - [2009.10.09 13:11:12 | 00,078,008 | R--- | M] (Skype Technologies) -- C:\Program Files\Skype\Plugin Manager\skypePM.exe
PRC - [2009.06.15 05:37:26 | 00,208,896 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Documents and Settings\Tono\Local Settings\temp\RtkBtMnt.exe
PRC - [2009.03.28 07:18:14 | 00,570,880 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2008.09.26 07:38:38 | 00,917,504 | ---- | M] (Eset ) -- C:\Program Files\Eset\nod32kui.exe
PRC - [2008.09.26 07:38:38 | 00,495,616 | ---- | M] (Eset ) -- C:\Program Files\Eset\nod32krn.exe
PRC - [2008.06.10 04:27:04 | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
PRC - [2008.06.02 21:58:06 | 01,015,808 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2008.06.02 21:24:00 | 00,858,632 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LManager.exe
PRC - [2008.05.30 16:28:32 | 00,536,576 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe
PRC - [2008.04.14 04:42:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.07.20 14:21:34 | 00,557,056 | ---- | M] (Lavasoft AB) -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
PRC - [2007.07.17 10:13:56 | 00,049,152 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
PRC - [2007.07.17 10:13:34 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
PRC - [2007.05.28 09:32:36 | 16,132,608 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.exe
PRC - [2007.04.01 08:02:38 | 00,568,176 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2007.04.01 08:02:36 | 00,273,256 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
PRC - [2006.10.24 20:09:24 | 05,279,232 | ---- | M] () -- C:\Program Files\netmon\netmon.exe
PRC - [2003.11.28 14:11:16 | 00,086,016 | ---- | M] () -- C:\Program Files\Common Files\GoldenSoft\ChannelRg.exe
 
 
[color=#E56717]========== Modules (SafeList) ==========[/color]
 
MOD - [2010.01.25 17:22:50 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tono\Desktop\OTL.exe
MOD - [2007.04.01 15:00:48 | 00,086,016 | ---- | M] (Broadcom Corporation.) -- C:\WINDOWS\system32\BtMmHook.dll
MOD - [2007.04.01 07:57:16 | 00,053,248 | ---- | M] () -- C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll
 
 
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
 
SRV - [2010.01.24 21:25:04 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2009.10.27 09:26:36 | 00,657,408 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009.10.19 13:43:48 | 00,072,704 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2009.08.06 07:54:46 | 00,183,112 | ---- | M] () [On_Demand | Stopped] -- C:\WINDOWS\system32\PnkBstrB.exe -- (PnkBstrB)
SRV - [2009.03.28 07:18:14 | 00,570,880 | ---- | M] (Crawler.com) [Auto | Running] -- C:\Program Files\Spyware Terminator\sp_rsser.exe -- (sp_rssrv)
SRV - [2009.02.05 17:12:19 | 00,133,104 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c987ac865fb074) Google Update Service (gupdate1c987ac865fb074)
SRV - [2008.09.26 07:38:38 | 00,495,616 | ---- | M] (Eset ) [Auto | Running] -- C:\Program Files\Eset\nod32krn.exe -- (NOD32krn)
SRV - [2008.05.30 16:28:32 | 00,536,576 | ---- | M] (ATI Technologies Inc.) [Auto | Running] -- C:\WINDOWS\system32\ati2evxx.exe -- (Ati HotKey Poller)
SRV - [2008.04.14 04:41:56 | 00,028,160 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\irmon.dll -- (Irmon)
SRV - [2007.07.20 14:21:34 | 00,557,056 | ---- | M] (Lavasoft AB) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe -- (aawservice)
SRV - [2007.04.01 08:02:36 | 00,273,256 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe -- (btwdins)
SRV - [2006.10.30 03:34:02 | 00,122,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2006.10.26 18:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2006.10.26 13:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2005.11.14 01:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2003.11.28 14:11:16 | 00,086,016 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\GoldenSoft\ChannelRg.exe -- (ChannelRg)
 
 
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
 
DRV - [2009.12.28 12:55:24 | 00,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009.11.02 15:07:50 | 00,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009.10.06 11:56:34 | 00,136,704 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2009.10.06 11:56:32 | 00,008,320 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2009.10.06 11:52:50 | 00,007,936 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2009.10.06 11:52:34 | 00,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009.10.06 11:52:34 | 00,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2009.10.06 11:52:34 | 00,007,936 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009.08.06 07:54:53 | 00,138,184 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PnkBstrK.sys -- (PnkBstrK)
DRV - [2009.07.24 23:21:14 | 00,004,608 | ---- | M] (RealVNC Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vncmirror.sys -- (vncmirror)
DRV - [2009.04.28 21:20:06 | 00,044,944 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)
DRV - [2008.09.26 07:38:38 | 00,502,208 | ---- | M] (Eset ) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\amon.sys -- (AMON)
DRV - [2008.08.26 09:26:12 | 00,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.08.24 12:55:50 | 00,030,464 | ---- | M] (CamTrax Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CamSpaceJoy.sys -- (CamSpaceJoy)
DRV - [2008.08.24 12:55:48 | 00,014,848 | ---- | M] (CamTrax Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CamSpaceBus.sys -- (CamSpaceBus)
DRV - [2008.06.02 21:58:04 | 00,215,904 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2008.06.02 21:23:58 | 00,017,408 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKbFltr.SYS -- (DKbFltr)
DRV - [2008.05.30 16:28:34 | 02,880,512 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2008.05.29 12:33:10 | 00,027,672 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Entech.sys -- (ENTECH)
DRV - [2008.04.13 23:24:38 | 00,028,672 | ---- | M] (National Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nscirda.sys -- (NSCIRDA)
DRV - [2008.04.13 23:23:10 | 00,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008.04.13 23:15:38 | 00,026,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser.sys -- (usbser)
DRV - [2008.04.13 21:09:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
DRV - [2008.04.13 21:06:06 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007.05.30 13:04:56 | 04,424,192 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.05.01 20:52:00 | 00,290,816 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2007.04.29 23:37:20 | 02,206,976 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Intel(R)
DRV - [2007.03.31 06:02:42 | 00,876,384 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2007.03.31 06:02:40 | 00,055,352 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2007.03.23 03:50:42 | 00,067,960 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2007.03.23 03:50:24 | 00,149,123 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2007.03.23 03:50:08 | 00,037,424 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2007.03.23 03:49:54 | 00,539,072 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2007.02.16 14:46:00 | 00,160,256 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2006.12.22 04:56:44 | 00,988,800 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2006.12.22 04:56:00 | 00,209,664 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2006.12.22 04:55:56 | 00,730,112 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2006.06.19 07:26:58 | 00,012,672 | R--- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdmxsdk.sys -- (mdmxsdk)
DRV - [2006.06.09 02:38:24 | 00,006,909 | R--- | M] (Conexant Systems, Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\UIUSYS.SYS -- (UIUSys)
DRV - [2001.08.23 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
 
 
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== Internet Explorer ==========[/color]
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
 
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1757981266-2049760794-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/
IE - HKU\S-1-5-21-1757981266-2049760794-725345543-1003\..\URLSearchHook:  - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1757981266-2049760794-725345543-1003\S-1-5-21-1757981266-2049760794-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1757981266-2049760794-725345543-1003\S-1-5-21-1757981266-2049760794-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
[color=#E56717]========== FireFox ==========[/color]
 
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.bearshare.com/"
FF - prefs.js..extensions.enabledItems: {5556F97E-11A5-46b0-9082-32AD74AAA920}:0.4.1.8
FF - prefs.js..extensions.enabledItems: change@c-est-simple.com:0.0.0.11
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.2.16
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5
FF - prefs.js..extensions.enabledItems: {5546F97E-11A5-46b0-9082-32AD74AAA920}:0.5.5.5
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: bkmrksync@nokia.com:1.0.0.723
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2009.01.24 21:50:43 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.12.05 09:40:20 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010.01.12 16:47:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.01.19 16:17:26 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.01.19 16:17:26 | 00,000,000 | ---D | M]
 
[2008.09.26 08:15:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Mozilla\Extensions
[2010.01.24 17:56:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Mozilla\Firefox\Profiles\zj12bra3.default\extensions
[2009.04.09 20:57:56 | 00,000,000 | ---D | M] (InFormEnter) -- C:\Documents and Settings\Tono\Application Data\Mozilla\Firefox\Profiles\zj12bra3.default\extensions\{5546F97E-11A5-46b0-9082-32AD74AAA920}
[2009.07.13 07:26:26 | 00,000,000 | ---D | M] (AutoFormer) -- C:\Documents and Settings\Tono\Application Data\Mozilla\Firefox\Profiles\zj12bra3.default\extensions\{5556F97E-11A5-46b0-9082-32AD74AAA920}
[2009.11.09 18:40:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Mozilla\Firefox\Profiles\zj12bra3.default\extensions\change@c-est-simple.com
[2008.09.27 19:08:04 | 00,002,921 | ---- | M] () -- C:\Documents and Settings\Tono\Application Data\Mozilla\Firefox\Profiles\zj12bra3.default\searchplugins\daemon-search.xml
[2009.08.03 15:33:05 | 00,001,595 | ---- | M] () -- C:\Documents and Settings\Tono\Application Data\Mozilla\Firefox\Profiles\zj12bra3.default\searchplugins\ebay.xml
[2010.01.06 16:10:27 | 00,000,687 | ---- | M] () -- C:\Documents and Settings\Tono\Application Data\Mozilla\Firefox\Profiles\zj12bra3.default\searchplugins\icq-search.xml
[2010.01.23 22:32:45 | 00,000,950 | ---- | M] () -- C:\Documents and Settings\Tono\Application Data\Mozilla\Firefox\Profiles\zj12bra3.default\searchplugins\icqplugin-1.xml
[2010.01.24 13:56:37 | 00,000,950 | ---- | M] () -- C:\Documents and Settings\Tono\Application Data\Mozilla\Firefox\Profiles\zj12bra3.default\searchplugins\icqplugin-2.xml
[2010.01.12 21:21:39 | 00,000,950 | ---- | M] () -- C:\Documents and Settings\Tono\Application Data\Mozilla\Firefox\Profiles\zj12bra3.default\searchplugins\icqplugin.xml
[2010.01.24 21:25:20 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.11.22 13:34:53 | 00,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2003.01.13 16:08:06 | 00,499,712 | ---- | M] (Morgan Multimedia) -- C:\Program Files\Mozilla Firefox\plugins\npjp2.dll
[2009.06.25 13:53:06 | 00,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2009.06.25 13:53:06 | 00,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2009.06.25 13:53:06 | 00,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2009.06.25 13:53:06 | 00,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2009.06.25 13:53:06 | 00,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml
 
O1 HOSTS File: ([2009.06.23 18:04:22 | 00,000,063 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: 127.0.0.1       activate.adobe.com
O2 - BHO: (Podpora odkazu pro Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - No CLSID value found.
O3 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [netmon.exe] C:\Program Files\netmon\netmon.exe ()
O4 - HKLM..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe (Eset )
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\ACE Mega CoDecS Pack\SystemS\RealMedia\Update_OB\realsched.exe File not found
O4 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003..\Run: []  File not found
O4 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003..\Run: [cdoosoft] C:\DOCUME~1\Tono\LOCALS~1\Temp\herss.exe File not found
O4 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003..\Run: [Google Update] C:\Documents and Settings\Tono\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe (Nokia)
O4 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1757981266-2049760794-725345543-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 -  File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 -  File not found
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0C71BDAA-5B30-4E12-A317-D225FEB9A068} http://fitsportse.dyndns.org/AxViewer/AxVideoView.cab (AxVideoView Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (C:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe) - C:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Tono\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tono\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O29 - HKLM SecurityProviders - (digiwet.dll) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.01.25 17:13:59 | 00,000,053 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.01.25 17:13:59 | 00,000,053 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{88ebcc45-0624-11de-a675-001f3b218787}\Shell\AutoRun\command - "" = G:\c2e.exe -- File not found
O33 - MountPoints2\{88ebcc45-0624-11de-a675-001f3b218787}\Shell\open\Command - "" = G:\c2e.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
 
NetSvcs: 6to4 -  File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008.09.25 14:34:46 | 00,000,000 | ---D | M]
NetSvcs: Iprip -  File not found
NetSvcs: Irmon - C:\WINDOWS\system32\irmon.dll (Microsoft Corporation)
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55172488459452416)
 
[color=#E56717]========== Files/Folders - Created Within 7 Days ==========[/color]
 
[2010.01.25 17:22:41 | 00,547,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Tono\Desktop\OTL.exe
[2010.01.25 16:31:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\VDLL.DLL
[2010.01.25 16:31:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\RUNDL132.EXE
[2010.01.25 16:31:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\logo_1.exe
[2010.01.25 16:03:09 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Tono\Recent
[2010.01.24 22:05:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\Local Settings\Application Data\ModelMakerTools
[2010.01.24 22:05:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\Application Data\ModelMakerTools
[2010.01.24 21:40:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\.netbeans
[2010.01.24 21:40:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\.netbeans-registration
[2010.01.24 21:37:54 | 00,000,000 | ---D | C] -- C:\Sun
[2010.01.24 21:26:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010.01.24 21:25:17 | 00,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.01.24 21:25:17 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.01.24 21:25:17 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.01.24 21:16:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\.nbi
[2010.01.24 17:43:01 | 00,000,000 | ---D | C] -- C:\Program Files\AnalogX
[2010.01.24 17:42:51 | 00,346,320 | ---- | C] (AnalogX, LLC) -- C:\Documents and Settings\Tono\Desktop\capturei.exe
[2010.01.24 09:38:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\My Documents\Ovi
[2010.01.21 16:02:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\Desktop\utj_vh_
[2010.01.21 14:31:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\Desktop\rapget141
[2010.01.21 14:23:10 | 00,000,000 | ---D | C] -- C:\Program Files\USD_WarXtreme
[2010.01.21 14:14:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\Desktop\janosik
[2010.01.21 14:12:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\Local Settings\Application Data\Deployment
[2010.01.21 14:12:00 | 00,020,480 | ---- | C] (RapidShare AG) -- C:\Documents and Settings\Tono\Desktop\RSMInit.exe
[2010.01.20 18:11:30 | 00,000,000 | ---D | C] -- C:\Program Files\Autodesk
[2010.01.20 16:49:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\Desktop\43957-ESP-SenicaEIAkompletpdf
[2010.01.19 19:17:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Tono\Desktop\OST Ulovit miliardáře
[2009.05.27 15:57:07 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009.03.12 11:39:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2009.02.11 16:06:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009.02.10 06:24:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008.09.25 14:05:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008.09.25 12:57:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008.09.25 12:53:33 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
[color=#E56717]========== Files - Modified Within 7 Days ==========[/color]
 
[2010.01.25 17:25:31 | 00,284,915 | ---- | M] () -- C:\Documents and Settings\Tono\Desktop\gmer.zip
[2010.01.25 17:22:50 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Tono\Desktop\OTL.exe
[2010.01.25 17:15:57 | 00,000,996 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.01.25 17:15:50 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.01.25 17:15:45 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.01.25 17:15:43 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.01.25 17:14:23 | 13,369,344 | -H-- | M] () -- C:\Documents and Settings\Tono\NTUSER.DAT
[2010.01.25 17:14:23 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\Tono\ntuser.ini
[2010.01.25 17:14:14 | 00,000,218 | ---- | M] () -- C:\Documents and Settings\Tono\My Documents\pinfect.zip
[2010.01.25 17:13:59 | 00,000,053 | RHS- | M] () -- C:\autorun.inf
[2010.01.25 16:53:01 | 00,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-2049760794-725345543-1003UA.job
[2010.01.25 16:44:01 | 00,001,000 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.01.25 16:30:41 | 00,000,054 | ---- | M] () -- C:\WINDOWS\Lic.xxx
[2010.01.24 21:39:46 | 00,000,116 | ---- | M] () -- C:\Documents and Settings\Tono\.asadminpass
[2010.01.24 21:39:34 | 00,000,781 | ---- | M] () -- C:\Documents and Settings\Tono\.asadmintruststore
[2010.01.24 21:25:03 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.01.24 21:25:03 | 00,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.01.24 21:25:03 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010.01.24 21:25:02 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2010.01.24 21:25:02 | 00,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.01.24 20:29:12 | 00,097,280 | RHS- | M] () -- C:\c2e.exe
[2010.01.24 19:53:24 | 00,011,165 | ---- | M] () -- C:\Documents and Settings\Tono\Desktop\Nový objekt - Pracovný hárok programu Microsoft Office Excel.xlsx
[2010.01.24 17:42:54 | 00,346,320 | ---- | M] (AnalogX, LLC) -- C:\Documents and Settings\Tono\Desktop\capturei.exe
[2010.01.24 10:08:45 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.01.24 09:48:21 | 00,222,720 | ---- | M] () -- C:\Documents and Settings\Tono\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.01.23 20:53:01 | 00,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-2049760794-725345543-1003Core.job
[2010.01.21 14:12:00 | 00,020,480 | ---- | M] (RapidShare AG) -- C:\Documents and Settings\Tono\Desktop\RSMInit.exe
[2010.01.19 20:07:50 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Tono\Desktop\~$vý objekt - Dokument programu Microsoft Office Word.doc
[2010.01.19 20:06:17 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\Tono\Desktop\~$vý objekt - Dokument programu Microsoft Office Word.docx
[2010.01.19 18:44:50 | 01,371,712 | ---- | M] () -- C:\Documents and Settings\Tono\Desktop\img227.jpg
[2010.01.19 18:44:40 | 01,414,132 | ---- | M] () -- C:\Documents and Settings\Tono\Desktop\img229.jpg
[2010.01.19 18:44:18 | 00,777,365 | ---- | M] () -- C:\Documents and Settings\Tono\Desktop\img228.jpg
[2010.01.19 18:44:10 | 00,964,803 | ---- | M] () -- C:\Documents and Settings\Tono\Desktop\img226.jpg
[2010.01.19 18:34:00 | 00,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
[color=#E56717]========== Files Created - No Company Name ==========[/color]
 
[2010.01.25 17:25:31 | 00,284,915 | ---- | C] () -- C:\Documents and Settings\Tono\Desktop\gmer.zip
[2010.01.25 17:13:59 | 00,097,280 | RHS- | C] () -- C:\c2e.exe
[2010.01.24 21:39:46 | 00,000,116 | ---- | C] () -- C:\Documents and Settings\Tono\.asadminpass
[2010.01.24 21:39:34 | 00,000,781 | ---- | C] () -- C:\Documents and Settings\Tono\.asadmintruststore
[2010.01.24 20:28:58 | 00,000,053 | RHS- | C] () -- C:\autorun.inf
[2010.01.24 18:35:33 | 00,011,165 | ---- | C] () -- C:\Documents and Settings\Tono\Desktop\Nový objekt - Pracovný hárok programu Microsoft Office Excel.xlsx
[2010.01.19 20:07:50 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Tono\Desktop\~$vý objekt - Dokument programu Microsoft Office Word.doc
[2010.01.19 20:06:17 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\Tono\Desktop\~$vý objekt - Dokument programu Microsoft Office Word.docx
[2010.01.19 18:43:53 | 01,414,132 | ---- | C] () -- C:\Documents and Settings\Tono\Desktop\img229.jpg
[2010.01.19 18:43:50 | 00,777,365 | ---- | C] () -- C:\Documents and Settings\Tono\Desktop\img228.jpg
[2010.01.19 18:43:48 | 01,371,712 | ---- | C] () -- C:\Documents and Settings\Tono\Desktop\img227.jpg
[2010.01.19 18:43:45 | 00,964,803 | ---- | C] () -- C:\Documents and Settings\Tono\Desktop\img226.jpg
[2009.10.29 21:43:37 | 00,000,761 | ---- | C] () -- C:\WINDOWS\m3jp2k.ini
[2009.10.29 21:43:37 | 00,000,702 | ---- | C] () -- C:\WINDOWS\mmtvmj.ini
[2009.10.29 21:43:34 | 00,000,714 | ---- | C] () -- C:\WINDOWS\m3jpeg.ini
[2009.10.29 21:43:26 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2009.10.29 21:43:23 | 00,152,064 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009.10.29 21:43:17 | 00,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009.10.21 17:05:46 | 00,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2009.10.20 06:13:34 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\DiskID32.dll
[2009.08.06 07:54:53 | 00,138,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009.06.19 19:06:22 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2009.06.19 19:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009.06.19 19:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009.06.19 19:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009.06.19 19:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009.06.19 19:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009.06.19 19:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2009.06.19 19:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009.06.19 19:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2009.06.19 19:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2009.06.19 06:14:50 | 00,000,029 | ---- | C] () -- C:\WINDOWS\softy.ini
[2009.06.09 06:14:17 | 00,035,328 | ---- | C] () -- C:\WINDOWS\System32\cygz.dll
[2009.06.09 06:14:17 | 00,035,328 | ---- | C] () -- C:\WINDOWS\cygz.dll
[2009.05.19 06:07:15 | 00,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Application Data\D6F6BC4DE8.sys
[2009.05.19 06:07:14 | 00,002,828 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2009.04.25 15:58:59 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Tono\Application Data\AVSDVDPlayer.m3u
[2009.04.25 15:56:32 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009.03.28 07:18:14 | 00,141,312 | ---- | C] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2009.03.25 07:00:39 | 00,013,312 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2009.02.06 19:04:40 | 00,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2009.02.04 17:54:11 | 00,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfmonnt.dll
[2009.01.26 18:00:09 | 00,000,043 | ---- | C] () -- C:\WINDOWS\prdelka.INI
[2009.01.17 08:22:19 | 00,688,128 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2009.01.17 08:22:19 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2009.01.06 17:22:52 | 00,278,528 | ---- | C] () -- C:\WINDOWS\System32\qsysd.dll
[2008.12.23 11:24:25 | 00,357,776 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2008.12.11 20:43:36 | 00,000,127 | ---- | C] () -- C:\Documents and Settings\Tono\Local Settings\Application Data\fusioncache.dat
[2008.12.11 18:40:04 | 00,215,144 | R--- | C] () -- C:\WINDOWS\pw32a.dll
[2008.12.10 18:50:06 | 00,000,144 | ---- | C] () -- C:\WINDOWS\Readiris.ini
[2008.12.10 18:38:34 | 00,167,936 | ---- | C] () -- C:\WINDOWS\System32\hpsfs.dll
[2008.11.23 11:13:02 | 00,000,243 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.09.27 19:31:51 | 00,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008.09.27 19:06:09 | 00,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008.09.26 16:09:06 | 00,222,720 | ---- | C] () -- C:\Documents and Settings\Tono\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.09.26 08:20:01 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.09.26 07:52:22 | 00,002,695 | ---- | C] () -- C:\WINDOWS\wdict32.INI
[2008.09.26 07:52:19 | 00,003,728 | ---- | C] () -- C:\WINDOWS\wtran32.INI
[2008.09.26 07:27:38 | 00,000,384 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008.09.25 14:07:04 | 00,002,589 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2007.12.14 12:51:58 | 00,163,840 | ---- | C] () -- C:\WINDOWS\System32\hppatusg01.dll
[2007.04.01 08:00:28 | 02,842,624 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2007.04.01 07:41:52 | 00,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2005.02.17 11:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005.02.17 11:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2002.12.05 17:51:00 | 00,059,392 | R--- | C] () -- C:\WINDOWS\streamhlp.dll
[2002.03.17 01:00:00 | 00,007,420 | ---- | C] () -- C:\WINDOWS\UA000106.DLL
[2001.11.14 12:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[2001.01.12 10:52:26 | 00,044,032 | ---- | C] () -- C:\WINDOWS\System32\vbpng1.dll
[2001.01.12 10:49:38 | 00,021,504 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[1996.04.03 20:33:26 | 00,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
 
[color=#E56717]========== LOP Check ==========[/color]
 
[2008.09.25 13:35:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broadcom
[2009.11.02 15:07:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2008.10.12 08:27:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
[2009.11.22 13:34:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2009.12.05 09:37:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2009.02.15 21:46:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lightbox
[2009.03.28 08:19:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MicroWorld
[2008.12.10 19:03:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009.02.23 20:04:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009.12.05 09:58:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2010.01.12 16:43:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OviInstallerCache
[2009.09.28 15:49:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PassMark
[2009.03.29 13:39:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009.05.02 16:05:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2009.09.28 17:18:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009.03.13 17:38:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2009.05.18 19:48:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009.03.13 17:38:12 | 00,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009.08.26 17:36:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\BitSpirit
[2009.07.18 19:52:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\BSplayer PRO
[2009.08.24 16:48:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Crayon Physics Deluxe
[2009.04.04 13:29:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\DAEMON Tools
[2009.12.28 12:36:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\DAEMON Tools Lite
[2009.04.04 13:29:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\DAEMON Tools Pro
[2009.09.22 16:07:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Desktopicon
[2009.03.29 21:01:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Ethereal
[2009.09.15 11:09:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\FileZilla
[2008.10.16 19:11:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\FlashFXP
[2009.06.05 06:13:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\fltk.org
[2009.01.23 18:35:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\foobar2000
[2008.10.12 08:27:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\GlobalSCAPE
[2009.08.06 06:37:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Leadertech
[2010.01.24 22:05:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\ModelMakerTools
[2009.02.23 20:04:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\NCH Swift Sound
[2009.12.05 09:59:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Nokia
[2009.12.05 09:58:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Nokia Ovi Suite
[2008.10.10 15:32:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Opera
[2010.01.06 19:03:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\PC Suite
[2009.12.14 16:31:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Spyware Terminator
[2009.03.05 07:19:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\Thinstall
[2009.03.13 17:38:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\TuneUp Software
[2009.11.15 15:21:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\VitySoft
[2009.04.30 18:55:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Tono\Application Data\XnView
 
[color=#E56717]========== Purity Check ==========[/color]
 
 
 
[color=#E56717]========== Custom Scans ==========[/color]
 
 
[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]
[2010.01.24 20:29:12 | 00,097,280 | RHS- | M] () -- C:\c2e.exe
 
[color=#A23BEC]< %SYSTEMDRIVE%\eventlog.dll /s /md5 >[/color]
[2004.08.03 23:56:44 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008.04.14 04:41:54 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 04:41:54 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
 
[color=#A23BEC]< %SYSTEMDRIVE%\scecli.dll /s /md5 >[/color]
[2004.08.03 23:56:46 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 04:42:06 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:42:06 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
 
[color=#A23BEC]< %SYSTEMDRIVE%\netlogon.dll /s /md5 >[/color]
[2004.08.03 23:56:46 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 04:42:02 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 04:42:02 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
 
[color=#A23BEC]< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\sceclt.dll /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\logevent.dll /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\iaStor.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\nvstor.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\atapi.sys /s /md5 >[/color]
[2004.08.03 21:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008.04.13 23:10:32 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 23:10:32 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 21:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys
[2004.08.03 21:59:44 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
 
[color=#A23BEC]< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\viasraid.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\AGP440.sys /s /md5 >[/color]
[2008.04.13 23:06:40 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 23:06:40 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
 
[color=#A23BEC]< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\viamraid.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMDRIVE%\nvata.sys /s /md5 >[/color]
 
[color=#A23BEC]< %SYSTEMROOT%\*. /mp /s >[/color]
 
[color=#A23BEC]< %SYSTEMROOT%\system32\*.dll /lockedfiles >[/color]
[2008.05.30 16:28:34 | 00,372,736 | R--- | M] (Advanced Micro Devices, Inc.)[b] Unable to obtain MD5[/b] -- C:\WINDOWS\system32\ATIDEMGX.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
 
[color=#A23BEC]< %SYSTEMROOT%\Tasks\*.job /lockedfiles >[/color]
 
[color=#E56717]========== Alternate Data Streams ==========[/color]
 
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:FB10A1D50BC54FFE
@Alternate Data Stream - 184 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
@Alternate Data Stream - 179 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0295CBF7
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B7177954
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:302A9871
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0E08FC17
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >


Re: Nod hlási trojský kun /kryptik ....

Napsal: 25 led 2010 17:34
od onkel1
exstras.txt

Kód: Vybrat vše

OTL Extras logfile created on: 25.1.2010 17:24:59 - Run 1
OTL by OldTimer - Version 3.1.26.0     Folder = C:\Documents and Settings\Tono\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy
 
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 57,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 80,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 100,22 Gb Total Space | 43,75 Gb Free Space | 43,65% Space Free | Partition Type: NTFS
Drive D: | 197,87 Gb Total Space | 54,45 Gb Free Space | 27,52% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: PC
Current User Name: Tono
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 7 Days
Output = Standard
 
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== File Associations ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-1757981266-2049760794-725345543-1003\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- Reg Error: Key error. File not found
 
[color=#E56717]========== Shell Spawning ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- Reg Error: Key error.
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[color=#E56717]========== Security Center Settings ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[color=#E56717]========== Authorized Applications List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.)
"C:\Documents and Settings\Tono\Desktop\Miranda_IM_Bagr_pack_v1.3.1\Miranda IM Bagr pack\miranda32.exe" = C:\Documents and Settings\Tono\Desktop\Miranda_IM_Bagr_pack_v1.3.1\Miranda IM Bagr pack\miranda32.exe:*:Enabled:Miranda IM -- ( )
"C:\Program Files\Valve\hl.exe" = C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher -- (Valve)
"C:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe" = C:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe:*:Enabled:Java(TM) Platform SE binary -- File not found
"C:\WINDOWS\system32\java.exe" = C:\WINDOWS\system32\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\GlobalSCAPE\CuteFTP 8 Professional\ftpte.exe" = C:\Program Files\GlobalSCAPE\CuteFTP 8 Professional\ftpte.exe:*:Enabled:FTP Transfer Engine -- (GlobalSCAPE, Inc.)
"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe" = C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe:*:Enabled:ENABLE -- (Advanced Micro Devices Inc.)
"C:\Program Files\Eset\nod32kui.exe" = C:\Program Files\Eset\nod32kui.exe:*:Enabled:ENABLE -- (Eset )
"C:\WINDOWS\RTHDCPL.exe" = C:\WINDOWS\RTHDCPL.exe:*:Enabled:ENABLE -- (Realtek Semiconductor Corp.)
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe:*:Enabled:ENABLE -- (Synaptics, Inc.)
"C:\Program Files\Java\jre6\bin\jusched.exe" = C:\Program Files\Java\jre6\bin\jusched.exe:*:Enabled:ENABLE -- File not found
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" = C:\Program Files\Common Files\Real\Update_OB\realsched.exe:*:Enabled:ENABLE -- (RealNetworks, Inc.)
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe" = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe:*:Enabled:ENABLE -- (Broadcom Corporation.)
"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" = C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe:*:Enabled:ENABLE -- (ATI Technologies Inc.)
"C:\WINDOWS\system32\wscntfy.exe" = C:\WINDOWS\system32\wscntfy.exe:*:Enabled:ENABLE -- (Microsoft Corporation)
"C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe" = C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe:*:Enabled:ENABLE -- (Lavasoft AB)
"C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe" = C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe:*:Enabled:ENABLE -- (Broadcom Corporation.)
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" = C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:ENABLE -- (Malwarebytes Corporation)
"C:\WINDOWS\system32\sndvol32.exe" = C:\WINDOWS\system32\sndvol32.exe:*:Enabled:ENABLE -- (Microsoft Corporation)
"C:\Program Files\Windows Media Player\wmplayer.exe" = C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:ENABLE -- (Microsoft Corporation)
"C:\Program Files\TuneUp Utilities 2009\OneClickStarter.exe" = C:\Program Files\TuneUp Utilities 2009\OneClickStarter.exe:*:Enabled:ENABLE -- File not found
"C:\WINDOWS\system32\netsh.exe" = C:\WINDOWS\system32\netsh.exe:*:Enabled:ENABLE -- (Microsoft Corporation)
"C:\Documents and Settings\Tono\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" = C:\Documents and Settings\Tono\Local Settings\Application Data\Google\Update\GoogleUpdate.exe:*:Enabled:ENABLE -- (Google Inc.)
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:ENABLE -- (Opera Software)
"C:\Program Files\Launch Manager\LManager.exe" = C:\Program Files\Launch Manager\LManager.exe:*:Enabled:ENABLE -- (Dritek System Inc.)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk -- File not found
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager -- (Skype Technologies)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
 
 
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}" = Java DB 10.5.3.0
"{01C08A7D-4CCD-41F8-B020-4B4BB8C08C68}" = Catalyst Control Center - Branding
"{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update
"{03EC1FFD-2F3C-AB30-FC8F-8A464EA3AB54}" = CCC Help Norwegian
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"{1204162A-1E08-4BB4-8F9C-D963D6375834}" = Scan To
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1A49527E-76D9-1A0E-1242-D1C449E2F246}" = Catalyst Control Center Localization French
"{1EB867A9-2CAC-9F2B-70AA-225B89329957}" = Catalyst Control Center Localization Swedish
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 18
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0160180}" = Java(TM) SE Development Kit 6 Update 18
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3C22A328-753B-709F-B575-8E7F26EF5769}" = CCC Help Portuguese
"{3DACACEC-5F90-4CEF-AB6B-77E0AF71BF5C}" = hppusgM1120
"{426E1B57-707D-E5D9-82BB-D375728C0101}" = Catalyst Control Center Localization Dutch
"{46369E80-6A3D-55A6-D54A-489ADE5258A2}" = Catalyst Control Center Localization Portuguese
"{476275FA-A3F8-3BD2-1042-2BD29F13CC2E}" = Skins
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4CE6B3C4-D8E2-4A5D-BEF5-5B69AF843B0C}" = PC Connectivity Solution
"{51EAB826-C5A4-2578-44AE-61CB8F6AF06C}" = CCC Help Korean
"{521E1CA4-C40B-E2E0-9C88-94B89CFE1FF9}" = Catalyst Control Center Localization German
"{54213804-C8B0-FF91-FEE4-AE177D55EF56}" = CCC Help Finnish
"{54C87F30-9A03-A151-E25D-643C6A19BE4D}" = Catalyst Control Center Localization Norwegian
"{564B16F4-6B5B-47B0-9AB6-FF2E943947F7}" = Nokia Ovi Suite Software Updater
"{567B13FA-9FA9-050E-5CD7-6C07F3A28DF7}" = CCC Help Turkish
"{5C51F530-415D-6DC1-AF78-4839F93B84C3}" = CCC Help English
"{5DB65884-C963-4454-AABA-4CA3089281FA}" = NVIDIA PhysX
"{5F212730-512E-C674-11B5-C4AEECAE1366}" = Catalyst Control Center Localization Thai
"{5F339FE5-9930-1B33-6090-EFFFD1749F3C}" = ccc-core-static
"{64682560-7401-4C2D-4B68-622001EBDB38}" = CCC Help French
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{666E9A48-A877-A912-6E7F-565C4E36A4BB}" = CCC Help Chinese Traditional
"{672F8700-B561-252F-6585-333FEE398EE3}" = CCC Help Swedish
"{68280718-3175-6C86-75E5-EA4706D0F545}" = Catalyst Control Center Localization Chinese Traditional
"{690BE098-6D0D-493D-B079-BD7E8F81A141}" = Opera 10.10
"{6A0DC722-5AE2-7878-04E3-12FD42242815}" = CCC Help German
"{6A41F0A6-445C-A426-3B9B-0F3138C36EC6}" = Catalyst Control Center Graphics Light
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F3AA35-BC41-119C-B74E-FFF0072973FE}" = CCC Help Spanish
"{765A0DD0-B60B-F6A0-6A8D-54054A4E6487}" = Catalyst Control Center Localization Czech
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{79170233-E0A5-5A4A-28D9-C6A0CF774F13}" = Catalyst Control Center Localization Danish
"{79435D1E-148B-8C58-8F3E-6E96D9284149}" = Catalyst Control Center Localization Chinese Standard
"{7B0B88BC-FF93-DA03-F84E-D23477157E5C}" = Catalyst Control Center Core Implementation
"{7C2B745A-E7F1-41F1-B9BB-3DDB8D52E4CE}" = Readiris Pro 11
"{7CBFA1C0-9F76-FF29-3EFC-9F7655E8FF56}" = CCC Help Thai
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{80361553-17D6-84D1-31E2-D8ABF0C66959}" = ccc-utility
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{88410D8F-8529-492B-B556-2394A29B811B}" = Broadcom Driver v4.170.25.19_Foxconn Installation Program
"{8D100E0C-1A5A-43AD-93EF-76F94AE61C30}" = OviMPlatform
"{8E87FED9-68EA-8A40-CB37-1F532F4D6D72}" = Catalyst Control Center Graphics Full New
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90110405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-041B-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders  (Slovak) 12
"{90120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{90120000-0016-041B-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Slovak) 2007
"{90120000-0018-041B-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Slovak) 2007
"{90120000-001A-041B-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Slovak) 2007
"{90120000-001B-041B-0000-0000000FF1CE}" = Microsoft Office Word MUI (Slovak) 2007
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040E-0000-0000000FF1CE}" = Microsoft Office Proof (Hungarian) 2007
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-002C-041B-0000-0000000FF1CE}" = Microsoft Office Proofing (Slovak) 2007
"{90120000-006E-041B-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Slovak) 2007
"{91F34319-08DE-457a-99C0-0BCDFAC145B9}" = CuteFTP 8 Professional
"{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}" = Nokia PC Suite
"{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v3
"{97521F0B-9072-0C9C-C765-961B07DEA729}" = Catalyst Control Center Localization Japanese
"{9A6C83A6-C190-EBA9-8E38-D480A994DA92}" = Catalyst Control Center Localization Italian
"{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}" = Counter-Strike 1.6
"{9B6C43B6-8B1B-34DA-1E05-B5BC51B2B804}" = Catalyst Control Center Localization Spanish
"{9C62C977-0111-F5FC-EBCA-4D917BADF751}" = CCC Help Dutch
"{A34C7BA8-938B-55FD-2600-57BECFB55D6A}" = CCC Help Greek
"{A6139E1F-1392-1442-8152-87BA59B2F64D}" = ccc-core-preinstall
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1029-7B44-A81200000003}" = Adobe Reader 8 - Czech
"{AEF1E88C-A98D-890F-CFDC-FD6FD3B8E829}" = CCC Help Italian
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B46FFFB4-FE24-3338-D53F-3C899AFD5A23}" = CCC Help Polish
"{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}" = Nokia Ovi Suite
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{B98B1629-E1F6-5DD5-8D1E-C8C3F6F80C89}" = Catalyst Control Center Graphics Full Existing
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB1DE0B0-3AEB-4890-A4F0-3388D51BC331}" = MrvlUsgTracking
"{BE1826A9-7EEE-492A-B3BC-DEF3DFAE37EE}" = TIPCI
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{BFBBA4F4-03C8-4126-B81D-4A2542DA1E11}" = AuthenTec Fingerprint Sensor Minimum Install
"{C084BC61-E537-11DE-8616-005056806466}" = Google Zem
"{C165A1B2-08D0-52C3-D5DB-665C8F251570}" = Catalyst Control Center Localization Turkish
"{C50EF365-2898-489A-B6C7-30DAA466E9A2}" = Nokia Connectivity Cable Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB88A5FF-59EE-6BF7-A5B5-2C7B63872745}" = Catalyst Control Center Localization Korean
"{CC6C4177-6365-1500-9279-480C79B0E592}" = CCC Help Czech
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D26BCF43-7100-E5F9-27FD-EA03670F1AE8}" = CCC Help Danish
"{D3B3B9B2-FE73-44CB-8C0A-F737D92F991B}" = Broadcom Gigabit Integrated Controller
"{DBC3FDEC-D5F4-439C-9A18-EF454A74E3DE}_is1" = NOD32 FiX v1.5
"{DC34C68C-A16F-56A7-AEFA-5DB8DAA6E9E3}" = CCC Help Russian
"{DD530FBD-D52A-8044-15B6-2E62E65AE83E}" = Catalyst Control Center Localization Polish
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = AusLogics Disk Defrag
"{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuide(R) Viewer ActiveX Control Release 6.5
"{E42BF37A-510C-D596-081D-307CA952D888}" = Catalyst Control Center Localization Hungarian
"{E58BE852-C68B-D02E-A6CF-BB8B4614AD42}" = Catalyst Control Center Localization Greek
"{E5A48BBD-7D1B-A49A-27D7-D02BE34940D6}" = CCC Help Hungarian
"{E697374A-6555-990E-821F-09AF8388CEAA}" = CCC Help Japanese
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{ECB8E83D-CE7B-C7E5-7F36-7677EAAB5F39}" = Catalyst Control Center Localization Russian
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1C3541D-5B93-4131-B440-692FBA3DD250}" = Ovi Desktop Sync Engine
"{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}" = Command and ConquerTM Generals Zero Hour
"{F58C48CB-A079-3BEC-5CB3-1E81F36AC79D}" = Catalyst Control Center Localization Finnish
"{F70D5D8C-C1AF-40B3-9E47-3BB5F19EEA3A}" = Atheros for Acer Driver 5.3.0.45_Foxconn Installation Program
"{F915CF43-C7E7-9886-48F4-640F124A0AAB}" = CCC Help Chinese Standard
"{FFFF6D5C-E2F1-4B40-BC89-8923312E89EB}}_is1" = ACE Mega CoDecS Pack
"05B59228C7E1C21DFBE89260F879BD95880548D8" = Windows Driver Package - Nokia Modem  (10/05/2009 4.2)
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd  (08/22/2008 7.0.0.0)
"6A630DCEC5EEC912115F2FF59D8C2C769798D930" = Windows Driver Package - Nokia Modem  (10/12/2007 3.6)
"819D45A9F73817F5B6D7C71A33ADAB88C5DA1765" = Windows Driver Package - Nokia Modem  (08/03/2007 6.84.0.2)
"8CDCFB95BB84DD9C0F88F22266A0CA86035E55BA" = Windows Driver Package - Nokia Modem  (06/01/2009 7.01.0.4)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"All ATI Software" = ATI - Software Uninstall Utility
"AnalogX Capture" = AnalogX Capture
"ATI Display Driver" = ATI Display Driver
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118" = HDAUDIO Soft Data Fax Modem with SmartCP
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DVD Shrink_is1" = DVD Shrink 3.2
"EasyCapture_is1" = EasyCapture 1.0.0.0
"EAX Unified" = EAX Unified
"Hamachi" = Hamachi 1.0.2.5
"High Quality Photo Resizer_is1" = High Quality Photo Resizer 1.60
"HijackThis" = HijackThis 2.0.2
"HP LaserJet M1120 MFP" = HP LaserJet M1120 MFP Series
"InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"InstallShield_{BE1826A9-7EEE-492A-B3BC-DEF3DFAE37EE}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}" = Command and ConquerTM Generals Zero Hour
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Mozilla Firefox (3.0.17)" = Mozilla Firefox (3.0.17)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NetMon&Stat_is1" = NetMon&Stat 1.10
"NOD32" = Antivirový systém NOD32
"Nokia Ovi Suite" = Nokia Ovi Suite
"Nokia PC Suite" = Nokia PC Suite
"PSPad editor_is1" = PSPad editor
"RealPlayer 6.0" = RealPlayer
"Scorpions WinCheater 2.07 (pouze program)_is1" = Scorpions WinCheater
"Spyware Terminator_is1" = Spyware Terminator
"STANDARD" = Microsoft Office Standard 2007
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"The KMPlayer" = The KMPlayer (remove only)
"Totalcmd" = Total Commander (Remove or Repair)
"VertrigoServ" = VertrigoServ (remove only)
"Visual LightBox" = Visual LightBox
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"yBook_is1" = yBook
 
[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]
 
[HKEY_USERS\S-1-5-21-1757981266-2049760794-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"ShockWave V0.95" = ShockWave V0.95
 
[color=#E56717]========== Last 10 Event Log Errors ==========[/color]
 
[ Application Events ]
Error - 22.1.2010 11:04:20 | Computer Name = PC | Source = crypt32 | ID = 131080
Description = Pri automatickej aktualizácii zlyhalo načítanie poradového čísla zoznamu
 základných certifikátov nezávislých vydavateľov z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
 s chybou: Operácia sa vrátila, pretože uplynul časový limit.  
 
Error - 22.1.2010 11:04:35 | Computer Name = PC | Source = crypt32 | ID = 131077
Description = Pri automatickej aktualizácii zlyhalo načítanie základného certifikátu
 nezávislého vydavateľa z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/801D62D07B449D5C5C035C98EA61FA443C2A58FE.crt>
 s chybou: Operácia sa vrátila, pretože uplynul časový limit.  
 
Error - 22.1.2010 11:04:35 | Computer Name = PC | Source = crypt32 | ID = 131080
Description = Pri automatickej aktualizácii zlyhalo načítanie poradového čísla zoznamu
 základných certifikátov nezávislých vydavateľov z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
 s chybou: Zadaný server nemôže vykonať požadovanú operáciu.  
 
Error - 22.1.2010 12:04:56 | Computer Name = PC | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikácia psani.exe, verzia 1.0.3.0, zablokovaný modul
 hungapp, verzia 0.0.0.0, adresa zablokovania 0x00000000.
 
Error - 22.1.2010 12:04:57 | Computer Name = PC | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikácia psani.exe, verzia 1.0.3.0, zablokovaný modul
 hungapp, verzia 0.0.0.0, adresa zablokovania 0x00000000.
 
Error - 24.1.2010 8:59:35 | Computer Name = PC | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikácia firefox.exe, verzia 1.9.0.3642, zablokovaný 
modul hungapp, verzia 0.0.0.0, adresa zablokovania 0x00000000.
 
Error - 24.1.2010 8:59:36 | Computer Name = PC | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikácia firefox.exe, verzia 1.9.0.3642, zablokovaný 
modul hungapp, verzia 0.0.0.0, adresa zablokovania 0x00000000.
 
Error - 24.1.2010 13:22:40 | Computer Name = PC | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikácia ImageReady.exe, verzia 9.0.0.196, zablokovaný
 modul hungapp, verzia 0.0.0.0, adresa zablokovania 0x00000000.
 
Error - 24.1.2010 13:22:52 | Computer Name = PC | Source = Application Hang | ID = 1001
Description = Chybný blok 182926794.
 
Error - 24.1.2010 16:26:53 | Computer Name = PC | Source = MsiInstaller | ID = 11311
Description = Product: Java Auto Updater -- Error 1311.Source file not found(cabinet):
 C:\Documents and Settings\Tono\Application Data\Sun\Java\AU\au.cab.  Verify that
 the file exists and that you can access it.
 
[ System Events ]
Error - 25.1.2010 9:54:26 | Computer Name = PC | Source = Dhcp | ID = 1000
Description = Počítač prišiel o prenájom adresy IP 5.221.125.60 na  sieťovej karte
 so sieťovou adresou 7A7905DD7D3C.
 
Error - 25.1.2010 9:54:31 | Computer Name = PC | Source = W32Time | ID = 39452689
Description = Poskytovateľ času NtpClient: Pri vyhľadávaní ručne nakonfigurovaného
partnera
 zoznam.sk,0x1 serverom DNS sa vyskytla chyba. NtpClient sa pokúsi o vyhľadávanie
 servera DNS znova o 15  min.  Vyskytla sa chyba: Došlo k pokusu o operáciu so soketom
 v čase nedosiahnuteľnosti hostiteľa. (0x80072751)
 
Error - 25.1.2010 9:54:31 | Computer Name = PC | Source = W32Time | ID = 39452701
Description = Poskytovateľ času NtpClient je nakonfigurovaný tak, aby získaval čas
 z jedného alebo viacerých  časových zdrojov, žiadny zo zdrojov však nie je momentálne
 prístupný.  Počas 14 minút nebude uskutočnený žiadny pokus o skontaktovanie zdroja.
NtpClient
 nemá žiadny zdroj presného času. 
 
Error - 25.1.2010 11:14:14 | Computer Name = PC | Source = Dhcp | ID = 1000
Description = Počítač prišiel o prenájom adresy IP 5.221.125.60 na  sieťovej karte
 so sieťovou adresou 7A7905DD7D3C.
 
Error - 25.1.2010 11:14:20 | Computer Name = PC | Source = W32Time | ID = 39452689
Description = Poskytovateľ času NtpClient: Pri vyhľadávaní ručne nakonfigurovaného
partnera
 zoznam.sk,0x1 serverom DNS sa vyskytla chyba. NtpClient sa pokúsi o vyhľadávanie
 servera DNS znova o 15  min.  Vyskytla sa chyba: Došlo k pokusu o operáciu so soketom
 v čase nedosiahnuteľnosti hostiteľa. (0x80072751)
 
Error - 25.1.2010 11:14:20 | Computer Name = PC | Source = W32Time | ID = 39452701
Description = Poskytovateľ času NtpClient je nakonfigurovaný tak, aby získaval čas
 z jedného alebo viacerých  časových zdrojov, žiadny zo zdrojov však nie je momentálne
 prístupný.  Počas 14 minút nebude uskutočnený žiadny pokus o skontaktovanie zdroja.
NtpClient
 nemá žiadny zdroj presného času. 
 
Error - 25.1.2010 11:15:59 | Computer Name = PC | Source = W32Time | ID = 39452689
Description = Poskytovateľ času NtpClient: Pri vyhľadávaní ručne nakonfigurovaného
partnera
 zoznam.sk,0x1 serverom DNS sa vyskytla chyba. NtpClient sa pokúsi o vyhľadávanie
 servera DNS znova o 15  min.  Vyskytla sa chyba: Došlo k pokusu o operáciu so soketom
 v čase nedosiahnuteľnosti hostiteľa. (0x80072751)
 
Error - 25.1.2010 11:15:59 | Computer Name = PC | Source = W32Time | ID = 39452701
Description = Poskytovateľ času NtpClient je nakonfigurovaný tak, aby získaval čas
 z jedného alebo viacerých  časových zdrojov, žiadny zo zdrojov však nie je momentálne
 prístupný.  Počas 14 minút nebude uskutočnený žiadny pokus o skontaktovanie zdroja.
NtpClient
 nemá žiadny zdroj presného času. 
 
Error - 25.1.2010 12:16:09 | Computer Name = PC | Source = sr | ID = 1
Description = Pri spracovaní súboru „“ vo zväzku „HarddiskVolume1“ filtrom služby
 Obnovovanie systému sa vyskytla neočakávaná chyba „0xC0000001“. Služba prestala
 sledovať zväzok.
 
Error - 25.1.2010 12:16:10 | Computer Name = PC | Source = Service Control Manager | ID = 7000
Description = Spustenie služby adfs zlyhalo kvôli nasledujúcej chybe:   %%2
 
[ TuneUp Events ]
Error - 28.3.2009 7:02:14 | Computer Name = PC | Source = TuneUp Program Statistics | ID = 131840
Description = 
 
Error - 29.3.2009 3:09:21 | Computer Name = PC | Source = TuneUp Program Statistics | ID = 131840
Description = 
 
Error - 29.3.2009 10:49:36 | Computer Name = PC | Source = TuneUp Program Statistics | ID = 131840
Description = 
 
Error - 29.3.2009 11:17:44 | Computer Name = PC | Source = TuneUp Program Statistics | ID = 131840
Description = 
 
Error - 6.4.2009 8:27:59 | Computer Name = PC | Source = TuneUp Program Statistics | ID = 131840
Description = 
 
Error - 6.4.2009 10:39:11 | Computer Name = PC | Source = TuneUp Program Statistics | ID = 131840
Description = 
 
Error - 10.4.2009 1:20:29 | Computer Name = PC | Source = TuneUp Program Statistics | ID = 131840
Description = 
 
Error - 1.5.2009 9:01:47 | Computer Name = PC | Source = TuneUp Program Statistics | ID = 131840
Description = 
 
Error - 15.5.2009 16:22:46 | Computer Name = PC | Source = TuneUp Program Statistics | ID = 131840
Description = 
 
Error - 5.8.2009 11:36:20 | Computer Name = PC | Source = TuneUp Program Statistics | ID = 131840
Description = 
 
 
< End of report >


Re: Nod hlási trojský kun /kryptik ....

Napsal: 25 led 2010 19:09
od pitimir
OK, este GMER a poprosim ta o edit tvojich postov a vybratie logov z kodu - zle sa to potom studuje. Vdaka ;)