
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Preventinka - pomalý počítač
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Preventinka - pomalý počítač
Dobrý den,
jsem úplný začátečník a prosím o kontrolu logu. Počítač je moc pomalý.Mockrát děkuji.
Logfile of random's system information tool 1.06 (written by random/random)
Run by Hanka at 2010-02-18 22:13:08
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (15%) free of 20 GB
Total RAM: 1023 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:13:21, on 18.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\istis2\xfigsys2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\msa.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Hanka\Plocha\RSIT.exe
C:\Program Files\trend micro\Hanka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101731&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
F2 - REG:system.ini: Shell=Explorer.exe rundll32.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.2.dll
O3 - Toolbar: &S-Rank - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [istis2] C:\istis2\xfigsys2.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA698] command.com /c del "C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9846] cmd.exe /c del "C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [SpybotDeletingB7145] command.com /c del "C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5557] cmd.exe /c del "C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp"
O4 - HKCU\..\RunOnce: [UniblueRegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Kniha klipů HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Chytrý výběr - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://icq.oberon-media.com/online/onli ... uncher.cab
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://games.icq.com/online/online2/mah ... uncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://arcade.icq.com/online/online2/be ... der_v6.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate1ca911d4d7cf296) (gupdate1ca911d4d7cf296) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 8495 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\core.2.dll [2010-01-18 1098392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B71B15CF-3093-459C-B764-AEB2486F2273} - &S-Rank - C:\Program Files\Seznam\Postak\SRank.dll [2007-05-16 269632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-09-27 16844800]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-04-19 7700480]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-04-19 86016]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"PAC7302_Monitor"=C:\WINDOWS\PixArt\PAC7302\Monitor.exe [2007-08-09 319488]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-02-11 2756488]
"istis2"=C:\istis2\xfigsys2.exe [2007-02-26 1095680]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA698"=command.com /c del C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp []
"SpybotDeletingC9846"=cmd.exe /c del C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-24 203928]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB7145"=command.com /c del C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp []
"SpybotDeletingD5557"=cmd.exe /c del C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp []
"UniblueRegistryBooster"=C:\Program Files\Uniblue\RegistryBooster\launcher.exe [2010-02-15 60208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hanka^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
C:\PROGRA~1\Xfire\Xfire.exe [2006-02-15 3631752]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"DisallowRun"=1
"NoClose"=0
"NoLogOff"=0
"NoSecurityTab"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======File associations======
.ini - open - "C:\Program Files\GetDiz\GetDiz.exe" "%1"
.txt - open - "C:\Program Files\GetDiz\GetDiz.exe" "%1"
======List of files/folders created in the last 1 months======
2010-02-18 22:13:09 ----D---- C:\Program Files\trend micro
2010-02-18 22:13:08 ----D---- C:\rsit
2010-02-18 21:23:13 ----A---- C:\WINDOWS\msa.exe
2010-02-18 21:23:03 ----A---- C:\WINDOWS\system32\sshnas21.dll
2010-02-18 21:17:05 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Uniblue
2010-02-18 21:17:00 ----D---- C:\Program Files\Uniblue
2010-02-18 19:58:32 ----A---- C:\WINDOWS\wininit.ini
2010-02-17 21:59:00 ----D---- C:\Program Files\XTS Manager
2010-02-17 21:58:10 ----D---- C:\Program Files\Windows RT
2010-02-16 20:20:05 ----D---- C:\Program Files\YouTube Downloader
2010-02-15 03:00:33 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-02-13 05:18:07 ----D---- C:\WINDOWS\system32\XPSViewer
2010-02-13 05:18:04 ----D---- C:\Program Files\MSBuild
2010-02-13 05:18:03 ----D---- C:\WINDOWS\system32\en-US
2010-02-13 05:17:57 ----D---- C:\Program Files\Reference Assemblies
2010-02-13 05:17:32 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-02-13 05:17:31 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-02-13 05:17:31 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-02-11 07:15:24 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Opera
2010-02-11 07:15:15 ----D---- C:\Program Files\Opera
2010-02-11 03:03:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-11 03:03:03 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-11 03:01:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-11 03:01:02 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-11 03:00:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-11 03:00:47 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-11 03:00:35 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-11 03:00:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-09 09:34:24 ----D---- C:\Program Files\Everstrike Software
2010-02-09 09:34:24 ----D---- C:\Program Files\Common Files\Everstrike Software
2010-02-08 23:09:09 ----RSD---- C:\WINDOWS\assembly
2010-02-08 23:08:45 ----D---- C:\WINDOWS\Microsoft.NET
2010-02-03 14:43:19 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-02-03 14:43:16 ----D---- C:\Program Files\Alwil Software
2010-02-03 14:43:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-01-25 10:59:17 ----D---- C:\Program Files\Common Files\Skype
2010-01-25 10:59:14 ----RD---- C:\Program Files\Skype
======List of files/folders modified in the last 1 months======
2010-02-18 22:13:09 ----RD---- C:\Program Files
2010-02-18 22:09:01 ----SD---- C:\WINDOWS\Tasks
2010-02-18 21:55:23 ----D---- C:\Program Files\Mozilla Firefox
2010-02-18 21:27:10 ----D---- C:\WINDOWS\Temp
2010-02-18 21:23:13 ----D---- C:\WINDOWS
2010-02-18 21:23:03 ----D---- C:\WINDOWS\system32
2010-02-18 19:41:18 ----SHD---- C:\WINDOWS\Installer
2010-02-18 19:41:17 ----HD---- C:\Config.Msi
2010-02-18 19:36:12 ----D---- C:\Program Files\TweakNow RegCleaner
2010-02-18 19:31:29 ----D---- C:\WINDOWS\Prefetch
2010-02-18 19:28:14 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-02-18 19:21:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-02-18 19:05:45 ----D---- C:\WINDOWS\Debug
2010-02-18 18:30:01 ----D---- C:\istis2
2010-02-18 15:58:34 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-18 10:08:52 ----D---- C:\Documents and Settings\Hanka\Data aplikací\vlc
2010-02-18 04:01:12 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Skype
2010-02-18 01:25:13 ----D---- C:\Documents and Settings\Hanka\Data aplikací\skypePM
2010-02-16 20:37:17 ----HD---- C:\WINDOWS\inf
2010-02-16 19:58:00 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-02-15 03:03:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-15 03:02:52 ----D---- C:\WINDOWS\WinSxS
2010-02-15 03:01:02 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-15 03:00:47 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-13 18:22:45 ----A---- C:\WINDOWS\NeroDigital.ini
2010-02-13 05:18:02 ----RSD---- C:\WINDOWS\Fonts
2010-02-13 05:17:44 ----D---- C:\WINDOWS\system32\spool
2010-02-13 05:16:21 ----D---- C:\WINDOWS\system32\mui
2010-02-13 05:16:21 ----D---- C:\Program Files\Internet Explorer
2010-02-11 22:30:59 ----D---- C:\Documents and Settings\Hanka\Data aplikací\ICQ
2010-02-11 03:03:07 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-11 03:03:04 ----D---- C:\WINDOWS\system32\drivers
2010-02-09 09:34:24 ----D---- C:\Program Files\Common Files
2010-02-08 23:11:08 ----SD---- C:\Documents and Settings\Hanka\Data aplikací\Microsoft
2010-02-08 23:08:54 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-02-08 23:08:45 ----D---- C:\WINDOWS\pchealth
2010-02-05 00:32:57 ----D---- C:\Program Files\ESET
2010-02-03 22:27:24 ----D---- C:\WINDOWS\network diagnostic
2010-02-03 19:26:59 ----D---- C:\Program Files\Seznam.cz
2010-02-01 20:26:20 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-02-11 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-02-11 162512]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-02-11 46672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-02-11 19024]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-02-11 100432]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-02-11 23376]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-10-02 4613120]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-04-19 3988384]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-13 163584]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2008-06-16 9856]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-10-23 103296]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 aiuvip22;aiuvip22; C:\WINDOWS\system32\drivers\aiuvip22.sys []
S3 apiw6lyq;apiw6lyq; C:\WINDOWS\system32\drivers\apiw6lyq.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\Hanka\LOCALS~1\Temp\AXI87F.tmp []
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 RTCore32;RTCore32; \??\C:\install\rm\RTCore32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73344]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-04-19 159810]
R2 NWCWorkstation;Klient systému NetWare; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
S2 gupdate1ca911d4d7cf296;Služba Google Update (gupdate1ca911d4d7cf296); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-09 133104]
S2 SSHNAS;SSHNAS; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
jsem úplný začátečník a prosím o kontrolu logu. Počítač je moc pomalý.Mockrát děkuji.
Logfile of random's system information tool 1.06 (written by random/random)
Run by Hanka at 2010-02-18 22:13:08
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (15%) free of 20 GB
Total RAM: 1023 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:13:21, on 18.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\istis2\xfigsys2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\msa.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Hanka\Plocha\RSIT.exe
C:\Program Files\trend micro\Hanka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101731&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
F2 - REG:system.ini: Shell=Explorer.exe rundll32.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.2.dll
O3 - Toolbar: &S-Rank - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [istis2] C:\istis2\xfigsys2.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA698] command.com /c del "C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9846] cmd.exe /c del "C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [SpybotDeletingB7145] command.com /c del "C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5557] cmd.exe /c del "C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp"
O4 - HKCU\..\RunOnce: [UniblueRegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Kniha klipů HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Chytrý výběr - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://icq.oberon-media.com/online/onli ... uncher.cab
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://games.icq.com/online/online2/mah ... uncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://arcade.icq.com/online/online2/be ... der_v6.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate1ca911d4d7cf296) (gupdate1ca911d4d7cf296) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 8495 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\core.2.dll [2010-01-18 1098392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B71B15CF-3093-459C-B764-AEB2486F2273} - &S-Rank - C:\Program Files\Seznam\Postak\SRank.dll [2007-05-16 269632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-09-27 16844800]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-04-19 7700480]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-04-19 86016]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"PAC7302_Monitor"=C:\WINDOWS\PixArt\PAC7302\Monitor.exe [2007-08-09 319488]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-02-11 2756488]
"istis2"=C:\istis2\xfigsys2.exe [2007-02-26 1095680]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA698"=command.com /c del C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp []
"SpybotDeletingC9846"=cmd.exe /c del C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-24 203928]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB7145"=command.com /c del C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp []
"SpybotDeletingD5557"=cmd.exe /c del C:\Documents and Settings\Hanka\Local Settings\Temp\6A.tmp []
"UniblueRegistryBooster"=C:\Program Files\Uniblue\RegistryBooster\launcher.exe [2010-02-15 60208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hanka^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
C:\PROGRA~1\Xfire\Xfire.exe [2006-02-15 3631752]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"DisallowRun"=1
"NoClose"=0
"NoLogOff"=0
"NoSecurityTab"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======File associations======
.ini - open - "C:\Program Files\GetDiz\GetDiz.exe" "%1"
.txt - open - "C:\Program Files\GetDiz\GetDiz.exe" "%1"
======List of files/folders created in the last 1 months======
2010-02-18 22:13:09 ----D---- C:\Program Files\trend micro
2010-02-18 22:13:08 ----D---- C:\rsit
2010-02-18 21:23:13 ----A---- C:\WINDOWS\msa.exe
2010-02-18 21:23:03 ----A---- C:\WINDOWS\system32\sshnas21.dll
2010-02-18 21:17:05 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Uniblue
2010-02-18 21:17:00 ----D---- C:\Program Files\Uniblue
2010-02-18 19:58:32 ----A---- C:\WINDOWS\wininit.ini
2010-02-17 21:59:00 ----D---- C:\Program Files\XTS Manager
2010-02-17 21:58:10 ----D---- C:\Program Files\Windows RT
2010-02-16 20:20:05 ----D---- C:\Program Files\YouTube Downloader
2010-02-15 03:00:33 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-02-13 05:18:07 ----D---- C:\WINDOWS\system32\XPSViewer
2010-02-13 05:18:04 ----D---- C:\Program Files\MSBuild
2010-02-13 05:18:03 ----D---- C:\WINDOWS\system32\en-US
2010-02-13 05:17:57 ----D---- C:\Program Files\Reference Assemblies
2010-02-13 05:17:32 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-02-13 05:17:31 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-02-13 05:17:31 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-02-11 07:15:24 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Opera
2010-02-11 07:15:15 ----D---- C:\Program Files\Opera
2010-02-11 03:03:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-11 03:03:03 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-11 03:01:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-11 03:01:02 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-11 03:00:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-11 03:00:47 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-11 03:00:35 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-11 03:00:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-09 09:34:24 ----D---- C:\Program Files\Everstrike Software
2010-02-09 09:34:24 ----D---- C:\Program Files\Common Files\Everstrike Software
2010-02-08 23:09:09 ----RSD---- C:\WINDOWS\assembly
2010-02-08 23:08:45 ----D---- C:\WINDOWS\Microsoft.NET
2010-02-03 14:43:19 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-02-03 14:43:16 ----D---- C:\Program Files\Alwil Software
2010-02-03 14:43:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-01-25 10:59:17 ----D---- C:\Program Files\Common Files\Skype
2010-01-25 10:59:14 ----RD---- C:\Program Files\Skype
======List of files/folders modified in the last 1 months======
2010-02-18 22:13:09 ----RD---- C:\Program Files
2010-02-18 22:09:01 ----SD---- C:\WINDOWS\Tasks
2010-02-18 21:55:23 ----D---- C:\Program Files\Mozilla Firefox
2010-02-18 21:27:10 ----D---- C:\WINDOWS\Temp
2010-02-18 21:23:13 ----D---- C:\WINDOWS
2010-02-18 21:23:03 ----D---- C:\WINDOWS\system32
2010-02-18 19:41:18 ----SHD---- C:\WINDOWS\Installer
2010-02-18 19:41:17 ----HD---- C:\Config.Msi
2010-02-18 19:36:12 ----D---- C:\Program Files\TweakNow RegCleaner
2010-02-18 19:31:29 ----D---- C:\WINDOWS\Prefetch
2010-02-18 19:28:14 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-02-18 19:21:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-02-18 19:05:45 ----D---- C:\WINDOWS\Debug
2010-02-18 18:30:01 ----D---- C:\istis2
2010-02-18 15:58:34 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-18 10:08:52 ----D---- C:\Documents and Settings\Hanka\Data aplikací\vlc
2010-02-18 04:01:12 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Skype
2010-02-18 01:25:13 ----D---- C:\Documents and Settings\Hanka\Data aplikací\skypePM
2010-02-16 20:37:17 ----HD---- C:\WINDOWS\inf
2010-02-16 19:58:00 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-02-15 03:03:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-15 03:02:52 ----D---- C:\WINDOWS\WinSxS
2010-02-15 03:01:02 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-15 03:00:47 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-13 18:22:45 ----A---- C:\WINDOWS\NeroDigital.ini
2010-02-13 05:18:02 ----RSD---- C:\WINDOWS\Fonts
2010-02-13 05:17:44 ----D---- C:\WINDOWS\system32\spool
2010-02-13 05:16:21 ----D---- C:\WINDOWS\system32\mui
2010-02-13 05:16:21 ----D---- C:\Program Files\Internet Explorer
2010-02-11 22:30:59 ----D---- C:\Documents and Settings\Hanka\Data aplikací\ICQ
2010-02-11 03:03:07 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-11 03:03:04 ----D---- C:\WINDOWS\system32\drivers
2010-02-09 09:34:24 ----D---- C:\Program Files\Common Files
2010-02-08 23:11:08 ----SD---- C:\Documents and Settings\Hanka\Data aplikací\Microsoft
2010-02-08 23:08:54 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-02-08 23:08:45 ----D---- C:\WINDOWS\pchealth
2010-02-05 00:32:57 ----D---- C:\Program Files\ESET
2010-02-03 22:27:24 ----D---- C:\WINDOWS\network diagnostic
2010-02-03 19:26:59 ----D---- C:\Program Files\Seznam.cz
2010-02-01 20:26:20 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-02-11 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-02-11 162512]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-02-11 46672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-02-11 19024]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-02-11 100432]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-02-11 23376]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-10-02 4613120]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-04-19 3988384]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-13 163584]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2008-06-16 9856]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-10-23 103296]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 aiuvip22;aiuvip22; C:\WINDOWS\system32\drivers\aiuvip22.sys []
S3 apiw6lyq;apiw6lyq; C:\WINDOWS\system32\drivers\apiw6lyq.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\Hanka\LOCALS~1\Temp\AXI87F.tmp []
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 RTCore32;RTCore32; \??\C:\install\rm\RTCore32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73344]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-04-19 159810]
R2 NWCWorkstation;Klient systému NetWare; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
S2 gupdate1ca911d4d7cf296;Služba Google Update (gupdate1ca911d4d7cf296); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-09 133104]
S2 SSHNAS;SSHNAS; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
- Unlimited_Killer
- Přítel fóra
- Příspěvky: 1969
- Registrován: 24 srp 2009 16:18
Re: Preventinka - pomalý počítač
Dobrý večer, máme to tam ale pěknou havěť.
1) ComboFix

1) ComboFix
- Stáhněte a uložte na Plochu ComboFix.
- Ještě před spuštěním vypněte rezidentní štít antiviru, či antispywaru.
- Spusťte ho s administrátorským oprávněním.
- Po spuštění se Vám zobrazí licenční podmínky, klikněte na 'Ano'.
- Budete také dotázáni na instalaci konzole pro zotavení, taktéž klikněte na 'Ano'.
- Celý sken bude trvat tak 5-10 minut, v závislosti na tom, kolika soubory se bude CF prodírat.
- Váš PC bude pravděpodobně restartován, tak se toho nelekněte.
- Než úplně skončí sken, nic nedělejte, hlavně neklikejte do spuštěného okna s ComboFixem.
- Po skončení skenu (či následném restartu) na Vás 'vypadne' log, který vkopírujete ve formě textu sem.
- Pokud žádný log 'nevypadne', naleznete jej v umístění C:\ComboFix.txt
inactive
Re: Preventinka - pomalý počítač
Moc děkuji za pomoc ....
ComboFix 10-02-18.05 - Hanka 18.02.2010 22:36:01.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.745 [GMT 1:00]
Spuštěný z: c:\documents and settings\Hanka\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\msa.exe
c:\windows\msb.exe
c:\windows\system32\AutoRun.inf
c:\windows\system32\sshnas21.dll
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
-------\Service_SSHNAS
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-18 do 2010-02-18 )))))))))))))))))))))))))))))))
.
2010-02-18 21:13 . 2010-02-18 21:13 -------- d-----w- c:\program files\trend micro
2010-02-18 21:13 . 2010-02-18 21:13 -------- d-----w- C:\rsit
2010-02-18 20:17 . 2010-02-18 20:17 -------- d-----w- c:\program files\Uniblue
2010-02-17 20:59 . 2010-02-17 20:59 -------- d-----w- c:\program files\XTS Manager
2010-02-17 20:58 . 2010-02-18 20:05 -------- d-----w- c:\program files\Windows RT
2010-02-16 19:20 . 2010-02-16 19:20 -------- d-----w- c:\program files\YouTube Downloader
2010-02-13 04:18 . 2010-02-13 04:18 -------- d-----w- c:\windows\system32\XPSViewer
2010-02-13 04:18 . 2010-02-13 04:18 -------- d-----w- c:\program files\MSBuild
2010-02-13 04:17 . 2010-02-13 04:17 -------- d-----w- c:\program files\Reference Assemblies
2010-02-13 04:17 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-02-13 04:17 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-02-13 04:17 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-02-13 04:17 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-02-13 04:17 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-02-13 04:17 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-02-13 04:17 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-02-13 04:17 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-02-13 04:17 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-02-11 06:15 . 2010-02-11 06:15 -------- d-----w- c:\program files\Opera
2010-02-09 08:34 . 2010-02-14 09:46 -------- d-----w- c:\program files\Everstrike Software
2010-02-09 08:34 . 2010-02-09 08:34 -------- d-----w- c:\program files\Common Files\Everstrike Software
2010-02-08 22:26 . 2010-02-09 08:31 -------- d-----r- c:\documents and settings\Hanka\My Private Folder
2010-02-03 13:43 . 2010-02-11 18:38 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-02-03 13:43 . 2010-02-11 18:42 162512 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-02-03 13:43 . 2010-02-11 18:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-02-03 13:43 . 2010-02-11 18:39 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-02-03 13:43 . 2010-02-11 18:38 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-02-03 13:43 . 2010-02-11 18:38 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-02-03 13:43 . 2010-02-11 18:38 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-02-03 13:43 . 2010-02-11 18:53 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-03 13:43 . 2010-02-11 18:53 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-02-03 13:43 . 2010-02-03 13:43 -------- d-----w- c:\program files\Alwil Software
2010-01-25 09:59 . 2010-01-25 09:59 -------- d-----w- c:\program files\Common Files\Skype
2010-01-25 09:59 . 2010-01-25 09:59 -------- d-----r- c:\program files\Skype
2010-01-24 04:34 . 2010-01-24 04:35 -------- d-----w- c:\documents and settings\All Users\ALL
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-18 18:36 . 2009-09-06 01:46 -------- d-----w- c:\program files\TweakNow RegCleaner
2010-02-18 18:28 . 2009-11-07 19:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-15 02:03 . 2001-10-25 14:00 78052 ----a-w- c:\windows\system32\perfc005.dat
2010-02-15 02:03 . 2001-10-25 14:00 429024 ----a-w- c:\windows\system32\perfh005.dat
2010-02-04 23:32 . 2008-06-16 20:49 -------- d-----w- c:\program files\ESET
2010-02-03 18:26 . 2009-09-24 14:42 -------- d-----w- c:\program files\Seznam.cz
2010-01-18 06:34 . 2008-06-17 01:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-11 05:29 . 2010-01-11 05:29 -------- d-----w- c:\program files\Windows Media Connect 2
2010-01-11 00:58 . 2010-01-11 00:58 -------- d-----w- c:\program files\DsNET Corp
2010-01-09 11:20 . 2010-01-09 11:17 -------- d-----w- c:\program files\Google
2010-01-09 11:17 . 2010-01-09 11:17 -------- d-----w- c:\program files\DivX
2010-01-09 11:17 . 2010-01-09 11:17 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-01-04 19:42 . 2009-10-14 10:56 -------- d-----w- c:\program files\Garena
2009-12-31 16:50 . 2004-08-03 21:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-29 21:31 . 2009-08-24 15:48 -------- d-----w- c:\program files\ICQ6.5
2009-12-21 19:08 . 2004-08-17 13:49 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-17 07:42 . 2008-06-17 01:33 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2004-08-17 13:49 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-06 12:19 . 2008-06-17 01:36 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-06 12:19 . 2008-06-17 01:36 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-04 18:22 . 2004-08-03 21:15 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:14 . 2004-08-17 13:49 1294336 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:14 . 2004-08-17 15:49 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:09 . 2001-10-25 14:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:09 . 2001-10-24 12:25 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:09 . 2004-08-17 15:49 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:09 . 2004-08-17 13:49 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:09 . 2004-08-17 13:49 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-21 16:03 . 2004-08-17 13:49 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"UniblueRegistryBooster"="c:\program files\Uniblue\RegistryBooster\launcher.exe" [2010-02-15 60208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-27 16844800]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"nwiz"="nwiz.exe" [2007-04-19 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-19 86016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2007-08-09 319488]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
"istis2"="c:\istis2\xfigsys2.exe" [2007-02-26 1095680]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSecurityTab"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Hanka^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
path=c:\documents and settings\Hanka\Nabídka Start\Programy\Po spuštění\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12.9.2009 21:12 721904]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3.2.2010 14:43 162512]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3.2.2010 14:43 19024]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate1ca911d4d7cf296;Služba Google Update (gupdate1ca911d4d7cf296);c:\program files\Google\Update\GoogleUpdate.exe [9.1.2010 12:17 133104]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp --> c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp [?]
S3 RTCore32;RTCore32;c:\install\rm\RTCore32.sys [14.10.2009 13:38 4608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
2010-02-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-02-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-09 11:17]
2010-02-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-09 11:17]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.ask.com/?o=101731&l=dis
DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - hxxp://games.icq.com/online/online2/mahjong_escape_ancient_china/SpinTopGamesLauncher.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://arcade.icq.com/online/online2/bejeweled2/popcaploader_v6.cab
FF - ProfilePath - c:\documents and settings\Hanka\Data aplikací\Mozilla\Firefox\Profiles\iorlbrve.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101728&gct=&gc=1&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
URLSearchHooks-{C94E154B-1459-4A47-966B-4B843BEFC7DB} - c:\program files\AskSearch\bin\DefaultSearch.dll
AddRemove-{1A8C0F9C-B7C3-4FCC-8FBA-72A710A8F4D0}_is1 - l:\psp\GAME\etc\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-18 22:40
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spyo.sys >>UNKNOWN [0x86F88938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf760df28
\Driver\ACPI -> ACPI.sys @ 0xf7387cb8
\Driver\atapi -> atapi.sys @ 0xf731cb40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7212bb0
PacketIndicateHandler -> NDIS.sys @ 0xf721fa21
SendHandler -> NDIS.sys @ 0xf71fd87b
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(1896)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Uniblue\RegistryBooster\registrybooster.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Celkový čas: 2010-02-18 22:43:43 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-18 21:43
Před spuštěním: 3 060 113 408
Po spuštění: 2 992 599 040
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 8730491BDCAD8C4B25C381FAF504C62B
ComboFix 10-02-18.05 - Hanka 18.02.2010 22:36:01.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.745 [GMT 1:00]
Spuštěný z: c:\documents and settings\Hanka\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\msa.exe
c:\windows\msb.exe
c:\windows\system32\AutoRun.inf
c:\windows\system32\sshnas21.dll
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
-------\Service_SSHNAS
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-18 do 2010-02-18 )))))))))))))))))))))))))))))))
.
2010-02-18 21:13 . 2010-02-18 21:13 -------- d-----w- c:\program files\trend micro
2010-02-18 21:13 . 2010-02-18 21:13 -------- d-----w- C:\rsit
2010-02-18 20:17 . 2010-02-18 20:17 -------- d-----w- c:\program files\Uniblue
2010-02-17 20:59 . 2010-02-17 20:59 -------- d-----w- c:\program files\XTS Manager
2010-02-17 20:58 . 2010-02-18 20:05 -------- d-----w- c:\program files\Windows RT
2010-02-16 19:20 . 2010-02-16 19:20 -------- d-----w- c:\program files\YouTube Downloader
2010-02-13 04:18 . 2010-02-13 04:18 -------- d-----w- c:\windows\system32\XPSViewer
2010-02-13 04:18 . 2010-02-13 04:18 -------- d-----w- c:\program files\MSBuild
2010-02-13 04:17 . 2010-02-13 04:17 -------- d-----w- c:\program files\Reference Assemblies
2010-02-13 04:17 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-02-13 04:17 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-02-13 04:17 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-02-13 04:17 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-02-13 04:17 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-02-13 04:17 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-02-13 04:17 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-02-13 04:17 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-02-13 04:17 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-02-11 06:15 . 2010-02-11 06:15 -------- d-----w- c:\program files\Opera
2010-02-09 08:34 . 2010-02-14 09:46 -------- d-----w- c:\program files\Everstrike Software
2010-02-09 08:34 . 2010-02-09 08:34 -------- d-----w- c:\program files\Common Files\Everstrike Software
2010-02-08 22:26 . 2010-02-09 08:31 -------- d-----r- c:\documents and settings\Hanka\My Private Folder
2010-02-03 13:43 . 2010-02-11 18:38 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-02-03 13:43 . 2010-02-11 18:42 162512 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-02-03 13:43 . 2010-02-11 18:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-02-03 13:43 . 2010-02-11 18:39 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-02-03 13:43 . 2010-02-11 18:38 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-02-03 13:43 . 2010-02-11 18:38 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-02-03 13:43 . 2010-02-11 18:38 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-02-03 13:43 . 2010-02-11 18:53 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-03 13:43 . 2010-02-11 18:53 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-02-03 13:43 . 2010-02-03 13:43 -------- d-----w- c:\program files\Alwil Software
2010-01-25 09:59 . 2010-01-25 09:59 -------- d-----w- c:\program files\Common Files\Skype
2010-01-25 09:59 . 2010-01-25 09:59 -------- d-----r- c:\program files\Skype
2010-01-24 04:34 . 2010-01-24 04:35 -------- d-----w- c:\documents and settings\All Users\ALL
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-18 18:36 . 2009-09-06 01:46 -------- d-----w- c:\program files\TweakNow RegCleaner
2010-02-18 18:28 . 2009-11-07 19:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-15 02:03 . 2001-10-25 14:00 78052 ----a-w- c:\windows\system32\perfc005.dat
2010-02-15 02:03 . 2001-10-25 14:00 429024 ----a-w- c:\windows\system32\perfh005.dat
2010-02-04 23:32 . 2008-06-16 20:49 -------- d-----w- c:\program files\ESET
2010-02-03 18:26 . 2009-09-24 14:42 -------- d-----w- c:\program files\Seznam.cz
2010-01-18 06:34 . 2008-06-17 01:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-11 05:29 . 2010-01-11 05:29 -------- d-----w- c:\program files\Windows Media Connect 2
2010-01-11 00:58 . 2010-01-11 00:58 -------- d-----w- c:\program files\DsNET Corp
2010-01-09 11:20 . 2010-01-09 11:17 -------- d-----w- c:\program files\Google
2010-01-09 11:17 . 2010-01-09 11:17 -------- d-----w- c:\program files\DivX
2010-01-09 11:17 . 2010-01-09 11:17 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-01-04 19:42 . 2009-10-14 10:56 -------- d-----w- c:\program files\Garena
2009-12-31 16:50 . 2004-08-03 21:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-29 21:31 . 2009-08-24 15:48 -------- d-----w- c:\program files\ICQ6.5
2009-12-21 19:08 . 2004-08-17 13:49 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-17 07:42 . 2008-06-17 01:33 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2004-08-17 13:49 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-06 12:19 . 2008-06-17 01:36 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-06 12:19 . 2008-06-17 01:36 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-04 18:22 . 2004-08-03 21:15 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:14 . 2004-08-17 13:49 1294336 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:14 . 2004-08-17 15:49 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:09 . 2001-10-25 14:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:09 . 2001-10-24 12:25 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:09 . 2004-08-17 15:49 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:09 . 2004-08-17 13:49 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:09 . 2004-08-17 13:49 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-21 16:03 . 2004-08-17 13:49 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"UniblueRegistryBooster"="c:\program files\Uniblue\RegistryBooster\launcher.exe" [2010-02-15 60208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-27 16844800]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"nwiz"="nwiz.exe" [2007-04-19 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-19 86016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2007-08-09 319488]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
"istis2"="c:\istis2\xfigsys2.exe" [2007-02-26 1095680]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSecurityTab"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Hanka^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
path=c:\documents and settings\Hanka\Nabídka Start\Programy\Po spuštění\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12.9.2009 21:12 721904]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3.2.2010 14:43 162512]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3.2.2010 14:43 19024]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate1ca911d4d7cf296;Služba Google Update (gupdate1ca911d4d7cf296);c:\program files\Google\Update\GoogleUpdate.exe [9.1.2010 12:17 133104]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp --> c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp [?]
S3 RTCore32;RTCore32;c:\install\rm\RTCore32.sys [14.10.2009 13:38 4608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
2010-02-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-02-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-09 11:17]
2010-02-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-09 11:17]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.ask.com/?o=101731&l=dis
DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - hxxp://games.icq.com/online/online2/mahjong_escape_ancient_china/SpinTopGamesLauncher.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://arcade.icq.com/online/online2/bejeweled2/popcaploader_v6.cab
FF - ProfilePath - c:\documents and settings\Hanka\Data aplikací\Mozilla\Firefox\Profiles\iorlbrve.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101728&gct=&gc=1&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
URLSearchHooks-{C94E154B-1459-4A47-966B-4B843BEFC7DB} - c:\program files\AskSearch\bin\DefaultSearch.dll
AddRemove-{1A8C0F9C-B7C3-4FCC-8FBA-72A710A8F4D0}_is1 - l:\psp\GAME\etc\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-18 22:40
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spyo.sys >>UNKNOWN [0x86F88938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf760df28
\Driver\ACPI -> ACPI.sys @ 0xf7387cb8
\Driver\atapi -> atapi.sys @ 0xf731cb40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7212bb0
PacketIndicateHandler -> NDIS.sys @ 0xf721fa21
SendHandler -> NDIS.sys @ 0xf71fd87b
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(1896)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Uniblue\RegistryBooster\registrybooster.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Celkový čas: 2010-02-18 22:43:43 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-18 21:43
Před spuštěním: 3 060 113 408
Po spuštění: 2 992 599 040
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 8730491BDCAD8C4B25C381FAF504C62B
- Unlimited_Killer
- Přítel fóra
- Příspěvky: 1969
- Registrován: 24 srp 2009 16:18
Re: Preventinka - pomalý počítač
Pokračujeme.
1) Skript do ComboFix-u

1) Skript do ComboFix-u
- Otevřete si Poznámkový blok [Start → Spustit → notepad → Enter].
- Do něj vkopírujte následující text:
Kód: Vybrat vše
KillAll:: Registry:: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{C94E154B-1459-4A47-966B-4B843BEFC7DB}"=- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "Shell"="explorer.exe" [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HP Software Update"=- "QuickTime Task"=- "Adobe Reader Speed Launcher"=- "istis2"=- File:: C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job C:\WINDOWS\tasks\AppleSoftwareUpdate.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk Collect:: c:\istis2\xfigsys2.exe Folder:: C:\Program Files\AskSearch C:\PROGRA~1\ICQTOO~1 c:\istis2 Extra:: DDS:: uStart Page = hxxp://www.ask.com/?o=101731&l=dis DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - hxxp://games.icq.com/online/online2/mah ... uncher.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://arcade.icq.com/online/online2/be ... der_v6.cab FireFox:: FF - ProfilePath - c:\documents and settings\Hanka\Data aplikací\Mozilla\Firefox\Profiles\iorlbrve.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q= FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q= Reboot::
- Uložte tento soubor na Plochu pod jménem CFScript (koncovka .txt).
- Přetáhněte tento soubor nad ComboFix a pusťte ho.
- I tento soubor, i ComboFix musí být na Ploše!
- ComboFix se spustí a vykoná příkazy ze skriptu.
- Počítač bude pravděpodobně restartován.
- Po restartu na Vás vyskočí okno s logem, který mi vkopírujete sem ve formě textu.
inactive
Re: Preventinka - pomalý počítač
ComboFix 10-02-18.05 - Hanka 18.02.2010 23:28:39.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.752 [GMT 1:00]
Spuštěný z: c:\documents and settings\Hanka\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Hanka\Plocha\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk"
"c:\windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job"
"c:\windows\tasks\Ad-Aware Update (Daily 1).job"
"c:\windows\tasks\Ad-Aware Update (Daily 2).job"
"c:\windows\tasks\Ad-Aware Update (Daily 3).job"
"c:\windows\tasks\Ad-Aware Update (Daily 4).job"
"c:\windows\tasks\AppleSoftwareUpdate.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
file zipped: c:\istis2\xfigsys2.exe
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
c:\istis2
c:\istis2\itisys.gyy
c:\istis2\xfigsys2.exe
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\0.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\0small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\1.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\10.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\100.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\100small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\101.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\101small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\102.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\102small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\103.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\103small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\104.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\104small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\105.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\105small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\106.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\106small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\107.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\107small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\108.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\108small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\109.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\109small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\10small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\11.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\110.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\110small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\111.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\111small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\112.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\112small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\113.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\113small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\114.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\114small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\115.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\115small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\116.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\116small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\117.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\117small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\118.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\118small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\119.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\119small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\11small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\12.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\120.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\120small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\121.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\121small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\122.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\122small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\123.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\123small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\124.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\124small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\125.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\125small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\126.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\126small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\127.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\127small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\128.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\128small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\129.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\129small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\12small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\13.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\130.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\130small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\131.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\131small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\132.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\132small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\133.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\133small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\134.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\134small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\135.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\135small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\136.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\136small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\137.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\137small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\138.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\138small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\139.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\139small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\13small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\14.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\140.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\140small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\141.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\141small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\142.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\142small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\143.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\143small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\144.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\144small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\145.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\145small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\146.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\146small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\147.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\147small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\148.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\148small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\149.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\149small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\14small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\15.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\150.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\150small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\151.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\151small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\152.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\152small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\153.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\153small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\154.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\154small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\155.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\155small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\156.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\156small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\157.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\157small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\158.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\158small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\159.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\159small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\15small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\16.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\160.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\160small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\161.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\161small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\162.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\162small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\163.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\163small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\164.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\164small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\165.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\165small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\166.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\166small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\167.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\167small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\168.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\168small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\169.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\169small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\16small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\17.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\170.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\170small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\171.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\171small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\172.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\172small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\173.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\173small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\174.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\174small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\175.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\175small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\176.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\176small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\177.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\177small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\178.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\178small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\179.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\179small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\17small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\18.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\180.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\180small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\181.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\181small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\182.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\182small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\183.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\183small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\184.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\184small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\185.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\185small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\186.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\186small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\187.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\187small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\188.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\188small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\189.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\189small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\18small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\19.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\190.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\190small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\191.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\191small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\192.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\192small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\193.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\193small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\194.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\194small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\195.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\195small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\196.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\196small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\197.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\197small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\198.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\198small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\199.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\199small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\19small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\1small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\2.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\20.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\200.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\200small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\201.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\201small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\202.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\202small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\203.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\203small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\204.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\204small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\205.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\205small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\206.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\206small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\207.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\207small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\208.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\208small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\209.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\209small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\20small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\21.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\210.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\210small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\211.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\211small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\212.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\212small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\213.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\213small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\214.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\214small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\215.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\215small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\216.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\216small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\217.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\217small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\218.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\218small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\219.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\219small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\21small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\22.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\220.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\220small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\221.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\221small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\222.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\222small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\223.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\223small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\224.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\224small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\225.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\225small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\226.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\226small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\227.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\227small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\228.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\228small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\229.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\229small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\22small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\23.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\230.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\230small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\231.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\231small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\232.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\232small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\233.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\233small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\234.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\234small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\235.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\235small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\236.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\236small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\237.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\237small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\238.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\238small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\239.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\239small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\23small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\24.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\240.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\240small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\241.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\241small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\242.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\242small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\243.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\243small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\244.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\244small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\245.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\245small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\246.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\246small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\247.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\247small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\248.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\248small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\249.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\249small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\24small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\25.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\250.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\250small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\251.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\251small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\252.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\252small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\253.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\253small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\254.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\254small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\255.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\255small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\256.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\256small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\257.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\257small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\258.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\258small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\259.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\259small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\25small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\26.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\260.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\260small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\261.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\261small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\262.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\262small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\263.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\263small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\264.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\264small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\265.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\265small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\266.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\266small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\267.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\267small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\268.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\268small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\269.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\269small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\26small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\27.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\270.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\270small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\271.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\271small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\272.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\272small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\273.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\273small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\274.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\274small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\275.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\275small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\276.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\276small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\277.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\277small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\278.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\278small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\279.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\279small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\27small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\28.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\280.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\280small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\281.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\281small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\282.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\282small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\283.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\283small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\284.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\284small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\285.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\285small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\286.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\286small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\287.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\287small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\288.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\288small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\289.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\289small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\28small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\29.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\290.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\290small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\291.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\291small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\292.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\292small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\293.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\293small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\294.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\294small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\295.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\295small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\296.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\296small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\297.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\297small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\298.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\298small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\299.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\299small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\29small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\2small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\3.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\30.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\300.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\300small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\301.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\301small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\302.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\302small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\303.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\303small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\304.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\304small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\305.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\305small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\306.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\306small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\307.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\307small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\308.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\308small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\309.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\309small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\30small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\31.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\310.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\310small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\311.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\311small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\312.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\312small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\313.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\313small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\314.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\314small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\315.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\315small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\316.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\316small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\317.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\317small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\318.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\318small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\319.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\319small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\31small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\32.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\320.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\320small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\321.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\321small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\322.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\322small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\323.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\323small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\324.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\324small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\325.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\325small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\326.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\326small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\327.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\327small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\328.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\328small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\329.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\329small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\32small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\33.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\330.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\330small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\331.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\331small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\332.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\332small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\333.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\333small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\334.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\334small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\335.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\335small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\336.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\336small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\337.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\337small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\338.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\338small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\339.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\339small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\33small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\34.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\340.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\340small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\341.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\341small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\342.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\342small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\343.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\343small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\344.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\344small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\345.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\345small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\346.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\346small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\347.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\347small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\348.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\348small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\349.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\349small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\34small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\35.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\350.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\350small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\351.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\351small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\352.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\352small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\353.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\353small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\354.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\354small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\355.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\355small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\356.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\356small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\357.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\357small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\358.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\358small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\359.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\359small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\35small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\36.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\360.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\360small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\361.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\361small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\362.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\362small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\363.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\363small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\364.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\364small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\365.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\365small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\366.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\366small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\367.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\367small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\368.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\368small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\369.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\369small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\36small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\37.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\370.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\370small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\371.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\371small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\372.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\372small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\373.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\373small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\374.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\374small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\375.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\375small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\376.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\376small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\377.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\377small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\378.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\378small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\379.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\379small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\37small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\38.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\380.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\380small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\381.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\381small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\382.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\382small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\383.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\383small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\384.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\384small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\385.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\385small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\386.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\386small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\387.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\387small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\388.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\388small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\389.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\389small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\38small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\39.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\390.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\390small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\391.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\391small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\392.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\392small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\393.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\393small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\394.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\394small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\395.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\395small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\396.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\396small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\397.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\397small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\398.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\398small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\399.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\399small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\39small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\3small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\4.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\40.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\400.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\400small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\401.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\401small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\402.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\402small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\403.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\403small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\404.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\404small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\405.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\405small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\406.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\406small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\407.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\407small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\408.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\408small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\409.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\409small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\40small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\41.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\410.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\410small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\411.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\411small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\412.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\412small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\413.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\413small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\414.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\414small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\415.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\415small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\416.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\416small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\417.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\417small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\418.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\418small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\419.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\419small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\41small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\42.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\420.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\420small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\421.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\421small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\422.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\422small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\423.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\423small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\424.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\424small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\425.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\425small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\426.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\426small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\427.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\427small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\428.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\428small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\429.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\429small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\42small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\43.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\430.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\430small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\431.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\431small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\432.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\432small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\433.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\433small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\434.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\434small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\435.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\435small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\436.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\436small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\437.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\437small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\438.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\438small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\439.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\439small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\43small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\44.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\440.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\440small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\441.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\441small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\442.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\442small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\443.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\443small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\444.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\444small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\445.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\445small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\446.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\446small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\447.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\447small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\448.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\448small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\449.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\449small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\44small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\45.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\450.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\450small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\451.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\451small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\452.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\452small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\453.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\453small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\45small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\46.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\46small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\47.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\47small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\48.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\48small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\49.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\49small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\4small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\5.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\50.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\50small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\51.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\51small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\52.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\52small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\53.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\53small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\54.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\54small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\55.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\55small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\56.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\56small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\57.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\57small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\58.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\58small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\59.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\59small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\5small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\6.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\60.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\60small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\61.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\61small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\62.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\62small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\63.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\63small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\64.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\64small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\65.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\65small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\66.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\66small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\67.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\67small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\68.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\68small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\69.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\69small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\6small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\7.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\70.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\70small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\71.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\71small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\72.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\72small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\73.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\73small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\74.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\74small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\75.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\75small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\76.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\76small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\77.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\77small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\78.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\78small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\79.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\79small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\7small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\8.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\80.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\80small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\81.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\81small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\82.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\82small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\83.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\83small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\84.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\84small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\85.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\85small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\86.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\86small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\87.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\87small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\88.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\88small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\89.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\89small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\8small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\9.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\90.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\90small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\91.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\91small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\92.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\92small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\93.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\93small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\94.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\94small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\95.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\95small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\96.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\96small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\97.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\97small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\98.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\98small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\99.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\99small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\9small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\flags.dat
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\w1.dat
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\z1.dat
c:\istis2\xfigsyslg\Computer1\dates.dat
c:\istis2\xfigsyslg\Flag.dat
c:\progra~1\ICQTOO~1
c:\progra~1\ICQTOO~1\about.html
c:\progra~1\ICQTOO~1\basis.xml
c:\progra~1\ICQTOO~1\Dlg_Res.xml
c:\progra~1\ICQTOO~1\download.html
c:\progra~1\ICQTOO~1\Games.xml
c:\progra~1\ICQTOO~1\games_button.xml
c:\progra~1\ICQTOO~1\icons.bmp
c:\progra~1\ICQTOO~1\loading.html
c:\progra~1\ICQTOO~1\logo_small.gif
c:\progra~1\ICQTOO~1\tb_buttons.xml
c:\progra~1\ICQTOO~1\tb_games.xml
c:\progra~1\ICQTOO~1\tb_options.xml
c:\progra~1\ICQTOO~1\toolbaru.crc
c:\progra~1\ICQTOO~1\toolbaru.dll
c:\progra~1\ICQTOO~1\version.txt
c:\program files\AskSearch
c:\windows\tasks\AppleSoftwareUpdate.job
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.752 [GMT 1:00]
Spuštěný z: c:\documents and settings\Hanka\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Hanka\Plocha\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk"
"c:\windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job"
"c:\windows\tasks\Ad-Aware Update (Daily 1).job"
"c:\windows\tasks\Ad-Aware Update (Daily 2).job"
"c:\windows\tasks\Ad-Aware Update (Daily 3).job"
"c:\windows\tasks\Ad-Aware Update (Daily 4).job"
"c:\windows\tasks\AppleSoftwareUpdate.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
file zipped: c:\istis2\xfigsys2.exe
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk
c:\istis2
c:\istis2\itisys.gyy
c:\istis2\xfigsys2.exe
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\0.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\0small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\1.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\10.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\100.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\100small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\101.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\101small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\102.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\102small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\103.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\103small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\104.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\104small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\105.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\105small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\106.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\106small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\107.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\107small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\108.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\108small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\109.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\109small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\10small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\11.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\110.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\110small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\111.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\111small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\112.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\112small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\113.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\113small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\114.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\114small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\115.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\115small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\116.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\116small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\117.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\117small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\118.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\118small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\119.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\119small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\11small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\12.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\120.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\120small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\121.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\121small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\122.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\122small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\123.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\123small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\124.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\124small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\125.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\125small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\126.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\126small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\127.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\127small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\128.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\128small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\129.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\129small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\12small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\13.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\130.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\130small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\131.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\131small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\132.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\132small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\133.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\133small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\134.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\134small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\135.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\135small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\136.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\136small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\137.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\137small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\138.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\138small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\139.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\139small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\13small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\14.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\140.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\140small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\141.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\141small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\142.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\142small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\143.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\143small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\144.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\144small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\145.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\145small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\146.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\146small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\147.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\147small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\148.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\148small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\149.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\149small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\14small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\15.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\150.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\150small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\151.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\151small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\152.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\152small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\153.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\153small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\154.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\154small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\155.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\155small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\156.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\156small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\157.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\157small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\158.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\158small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\159.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\159small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\15small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\16.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\160.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\160small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\161.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\161small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\162.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\162small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\163.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\163small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\164.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\164small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\165.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\165small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\166.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\166small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\167.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\167small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\168.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\168small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\169.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\169small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\16small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\17.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\170.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\170small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\171.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\171small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\172.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\172small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\173.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\173small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\174.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\174small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\175.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\175small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\176.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\176small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\177.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\177small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\178.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\178small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\179.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\179small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\17small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\18.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\180.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\180small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\181.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\181small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\182.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\182small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\183.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\183small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\184.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\184small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\185.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\185small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\186.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\186small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\187.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\187small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\188.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\188small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\189.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\189small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\18small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\19.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\190.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\190small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\191.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\191small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\192.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\192small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\193.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\193small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\194.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\194small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\195.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\195small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\196.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\196small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\197.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\197small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\198.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\198small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\199.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\199small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\19small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\1small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\2.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\20.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\200.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\200small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\201.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\201small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\202.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\202small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\203.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\203small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\204.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\204small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\205.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\205small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\206.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\206small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\207.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\207small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\208.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\208small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\209.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\209small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\20small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\21.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\210.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\210small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\211.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\211small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\212.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\212small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\213.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\213small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\214.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\214small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\215.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\215small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\216.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\216small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\217.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\217small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\218.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\218small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\219.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\219small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\21small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\22.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\220.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\220small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\221.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\221small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\222.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\222small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\223.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\223small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\224.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\224small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\225.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\225small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\226.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\226small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\227.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\227small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\228.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\228small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\229.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\229small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\22small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\23.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\230.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\230small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\231.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\231small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\232.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\232small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\233.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\233small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\234.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\234small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\235.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\235small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\236.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\236small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\237.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\237small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\238.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\238small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\239.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\239small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\23small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\24.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\240.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\240small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\241.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\241small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\242.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\242small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\243.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\243small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\244.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\244small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\245.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\245small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\246.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\246small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\247.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\247small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\248.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\248small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\249.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\249small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\24small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\25.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\250.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\250small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\251.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\251small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\252.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\252small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\253.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\253small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\254.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\254small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\255.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\255small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\256.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\256small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\257.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\257small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\258.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\258small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\259.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\259small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\25small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\26.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\260.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\260small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\261.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\261small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\262.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\262small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\263.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\263small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\264.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\264small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\265.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\265small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\266.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\266small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\267.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\267small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\268.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\268small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\269.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\269small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\26small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\27.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\270.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\270small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\271.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\271small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\272.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\272small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\273.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\273small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\274.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\274small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\275.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\275small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\276.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\276small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\277.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\277small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\278.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\278small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\279.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\279small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\27small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\28.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\280.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\280small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\281.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\281small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\282.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\282small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\283.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\283small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\284.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\284small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\285.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\285small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\286.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\286small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\287.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\287small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\288.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\288small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\289.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\289small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\28small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\29.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\290.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\290small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\291.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\291small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\292.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\292small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\293.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\293small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\294.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\294small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\295.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\295small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\296.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\296small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\297.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\297small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\298.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\298small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\299.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\299small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\29small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\2small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\3.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\30.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\300.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\300small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\301.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\301small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\302.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\302small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\303.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\303small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\304.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\304small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\305.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\305small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\306.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\306small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\307.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\307small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\308.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\308small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\309.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\309small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\30small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\31.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\310.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\310small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\311.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\311small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\312.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\312small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\313.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\313small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\314.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\314small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\315.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\315small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\316.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\316small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\317.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\317small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\318.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\318small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\319.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\319small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\31small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\32.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\320.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\320small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\321.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\321small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\322.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\322small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\323.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\323small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\324.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\324small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\325.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\325small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\326.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\326small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\327.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\327small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\328.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\328small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\329.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\329small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\32small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\33.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\330.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\330small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\331.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\331small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\332.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\332small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\333.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\333small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\334.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\334small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\335.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\335small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\336.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\336small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\337.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\337small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\338.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\338small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\339.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\339small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\33small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\34.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\340.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\340small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\341.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\341small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\342.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\342small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\343.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\343small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\344.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\344small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\345.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\345small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\346.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\346small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\347.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\347small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\348.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\348small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\349.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\349small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\34small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\35.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\350.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\350small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\351.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\351small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\352.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\352small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\353.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\353small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\354.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\354small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\355.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\355small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\356.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\356small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\357.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\357small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\358.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\358small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\359.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\359small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\35small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\36.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\360.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\360small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\361.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\361small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\362.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\362small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\363.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\363small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\364.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\364small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\365.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\365small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\366.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\366small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\367.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\367small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\368.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\368small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\369.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\369small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\36small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\37.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\370.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\370small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\371.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\371small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\372.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\372small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\373.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\373small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\374.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\374small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\375.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\375small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\376.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\376small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\377.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\377small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\378.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\378small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\379.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\379small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\37small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\38.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\380.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\380small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\381.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\381small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\382.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\382small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\383.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\383small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\384.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\384small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\385.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\385small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\386.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\386small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\387.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\387small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\388.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\388small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\389.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\389small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\38small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\39.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\390.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\390small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\391.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\391small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\392.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\392small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\393.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\393small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\394.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\394small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\395.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\395small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\396.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\396small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\397.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\397small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\398.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\398small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\399.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\399small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\39small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\3small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\4.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\40.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\400.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\400small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\401.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\401small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\402.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\402small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\403.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\403small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\404.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\404small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\405.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\405small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\406.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\406small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\407.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\407small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\408.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\408small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\409.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\409small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\40small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\41.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\410.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\410small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\411.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\411small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\412.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\412small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\413.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\413small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\414.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\414small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\415.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\415small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\416.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\416small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\417.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\417small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\418.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\418small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\419.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\419small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\41small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\42.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\420.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\420small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\421.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\421small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\422.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\422small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\423.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\423small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\424.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\424small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\425.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\425small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\426.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\426small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\427.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\427small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\428.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\428small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\429.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\429small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\42small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\43.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\430.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\430small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\431.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\431small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\432.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\432small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\433.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\433small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\434.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\434small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\435.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\435small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\436.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\436small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\437.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\437small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\438.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\438small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\439.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\439small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\43small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\44.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\440.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\440small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\441.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\441small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\442.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\442small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\443.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\443small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\444.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\444small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\445.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\445small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\446.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\446small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\447.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\447small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\448.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\448small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\449.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\449small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\44small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\45.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\450.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\450small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\451.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\451small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\452.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\452small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\453.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\453small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\45small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\46.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\46small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\47.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\47small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\48.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\48small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\49.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\49small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\4small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\5.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\50.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\50small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\51.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\51small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\52.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\52small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\53.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\53small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\54.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\54small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\55.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\55small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\56.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\56small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\57.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\57small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\58.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\58small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\59.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\59small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\5small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\6.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\60.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\60small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\61.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\61small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\62.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\62small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\63.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\63small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\64.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\64small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\65.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\65small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\66.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\66small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\67.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\67small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\68.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\68small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\69.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\69small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\6small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\7.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\70.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\70small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\71.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\71small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\72.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\72small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\73.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\73small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\74.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\74small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\75.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\75small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\76.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\76small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\77.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\77small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\78.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\78small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\79.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\79small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\7small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\8.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\80.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\80small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\81.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\81small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\82.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\82small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\83.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\83small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\84.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\84small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\85.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\85small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\86.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\86small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\87.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\87small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\88.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\88small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\89.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\89small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\8small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\9.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\90.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\90small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\91.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\91small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\92.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\92small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\93.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\93small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\94.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\94small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\95.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\95small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\96.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\96small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\97.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\97small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\98.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\98small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\99.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\99small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\9small.jpg
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\ss\flags.dat
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\w1.dat
c:\istis2\xfigsyslg\Computer1\18022010 #Hanka\z1.dat
c:\istis2\xfigsyslg\Computer1\dates.dat
c:\istis2\xfigsyslg\Flag.dat
c:\progra~1\ICQTOO~1
c:\progra~1\ICQTOO~1\about.html
c:\progra~1\ICQTOO~1\basis.xml
c:\progra~1\ICQTOO~1\Dlg_Res.xml
c:\progra~1\ICQTOO~1\download.html
c:\progra~1\ICQTOO~1\Games.xml
c:\progra~1\ICQTOO~1\games_button.xml
c:\progra~1\ICQTOO~1\icons.bmp
c:\progra~1\ICQTOO~1\loading.html
c:\progra~1\ICQTOO~1\logo_small.gif
c:\progra~1\ICQTOO~1\tb_buttons.xml
c:\progra~1\ICQTOO~1\tb_games.xml
c:\progra~1\ICQTOO~1\tb_options.xml
c:\progra~1\ICQTOO~1\toolbaru.crc
c:\progra~1\ICQTOO~1\toolbaru.dll
c:\progra~1\ICQTOO~1\version.txt
c:\program files\AskSearch
c:\windows\tasks\AppleSoftwareUpdate.job
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
Re: Preventinka - pomalý počítač
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-18 do 2010-02-18 )))))))))))))))))))))))))))))))
.
2010-02-18 21:13 . 2010-02-18 21:13 -------- d-----w- c:\program files\trend micro
2010-02-18 21:13 . 2010-02-18 21:13 -------- d-----w- C:\rsit
2010-02-18 20:17 . 2010-02-18 20:17 -------- d-----w- c:\program files\Uniblue
2010-02-17 20:59 . 2010-02-17 20:59 -------- d-----w- c:\program files\XTS Manager
2010-02-17 20:58 . 2010-02-18 20:05 -------- d-----w- c:\program files\Windows RT
2010-02-16 19:20 . 2010-02-16 19:20 -------- d-----w- c:\program files\YouTube Downloader
2010-02-13 04:18 . 2010-02-13 04:18 -------- d-----w- c:\windows\system32\XPSViewer
2010-02-13 04:18 . 2010-02-13 04:18 -------- d-----w- c:\program files\MSBuild
2010-02-13 04:17 . 2010-02-13 04:17 -------- d-----w- c:\program files\Reference Assemblies
2010-02-13 04:17 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-02-13 04:17 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-02-13 04:17 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-02-13 04:17 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-02-13 04:17 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-02-13 04:17 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-02-13 04:17 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-02-13 04:17 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-02-13 04:17 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-02-11 06:15 . 2010-02-11 06:15 -------- d-----w- c:\program files\Opera
2010-02-09 08:34 . 2010-02-14 09:46 -------- d-----w- c:\program files\Everstrike Software
2010-02-09 08:34 . 2010-02-09 08:34 -------- d-----w- c:\program files\Common Files\Everstrike Software
2010-02-08 22:26 . 2010-02-09 08:31 -------- d-----r- c:\documents and settings\Hanka\My Private Folder
2010-02-03 13:43 . 2010-02-11 18:38 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-02-03 13:43 . 2010-02-11 18:42 162512 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-02-03 13:43 . 2010-02-11 18:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-02-03 13:43 . 2010-02-11 18:39 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-02-03 13:43 . 2010-02-11 18:38 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-02-03 13:43 . 2010-02-11 18:38 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-02-03 13:43 . 2010-02-11 18:38 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-02-03 13:43 . 2010-02-11 18:53 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-03 13:43 . 2010-02-11 18:53 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-02-03 13:43 . 2010-02-03 13:43 -------- d-----w- c:\program files\Alwil Software
2010-01-25 09:59 . 2010-01-25 09:59 -------- d-----w- c:\program files\Common Files\Skype
2010-01-25 09:59 . 2010-01-25 09:59 -------- d-----r- c:\program files\Skype
2010-01-24 04:34 . 2010-01-24 04:35 -------- d-----w- c:\documents and settings\All Users\ALL
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-18 18:36 . 2009-09-06 01:46 -------- d-----w- c:\program files\TweakNow RegCleaner
2010-02-18 18:28 . 2009-11-07 19:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-15 02:03 . 2001-10-25 14:00 78052 ----a-w- c:\windows\system32\perfc005.dat
2010-02-15 02:03 . 2001-10-25 14:00 429024 ----a-w- c:\windows\system32\perfh005.dat
2010-02-04 23:32 . 2008-06-16 20:49 -------- d-----w- c:\program files\ESET
2010-02-03 18:26 . 2009-09-24 14:42 -------- d-----w- c:\program files\Seznam.cz
2010-01-18 06:34 . 2008-06-17 01:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-11 05:29 . 2010-01-11 05:29 -------- d-----w- c:\program files\Windows Media Connect 2
2010-01-11 00:58 . 2010-01-11 00:58 -------- d-----w- c:\program files\DsNET Corp
2010-01-09 11:20 . 2010-01-09 11:17 -------- d-----w- c:\program files\Google
2010-01-09 11:17 . 2010-01-09 11:17 -------- d-----w- c:\program files\DivX
2010-01-09 11:17 . 2010-01-09 11:17 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-01-04 19:42 . 2009-10-14 10:56 -------- d-----w- c:\program files\Garena
2009-12-31 16:50 . 2004-08-03 21:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-29 21:31 . 2009-08-24 15:48 -------- d-----w- c:\program files\ICQ6.5
2009-12-21 19:08 . 2004-08-17 13:49 916480 ------w- c:\windows\system32\wininet.dll
2009-12-17 07:42 . 2008-06-17 01:33 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2004-08-17 13:49 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-06 12:19 . 2008-06-17 01:36 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-06 12:19 . 2008-06-17 01:36 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-04 18:22 . 2004-08-03 21:15 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:14 . 2004-08-17 13:49 1294336 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:14 . 2004-08-17 15:49 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:09 . 2001-10-25 14:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:09 . 2001-10-24 12:25 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:09 . 2004-08-17 15:49 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:09 . 2004-08-17 13:49 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:09 . 2004-08-17 13:49 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-21 16:03 . 2004-08-17 13:49 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-27 16844800]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"nwiz"="nwiz.exe" [2007-04-19 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-19 86016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2007-08-09 319488]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSecurityTab"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Hanka^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
path=c:\documents and settings\Hanka\Nabídka Start\Programy\Po spuštění\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12.9.2009 21:12 721904]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3.2.2010 14:43 162512]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3.2.2010 14:43 19024]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate1ca911d4d7cf296;Služba Google Update (gupdate1ca911d4d7cf296);c:\program files\Google\Update\GoogleUpdate.exe [9.1.2010 12:17 133104]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp --> c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp [?]
S3 RTCore32;RTCore32;c:\install\rm\RTCore32.sys [14.10.2009 13:38 4608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Doplňkový sken -------
.
FF - ProfilePath - c:\documents and settings\Hanka\Data aplikací\Mozilla\Firefox\Profiles\iorlbrve.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-18 23:37
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spkz.sys >>UNKNOWN [0x86F88938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75e0f28
\Driver\ACPI -> ACPI.sys @ 0xf735acb8
\Driver\atapi -> atapi.sys @ 0xf72efb40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf71e5bb0
PacketIndicateHandler -> NDIS.sys @ 0xf71f2a21
SendHandler -> NDIS.sys @ 0xf71d087b
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(2624)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Celkový čas: 2010-02-18 23:40:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-18 22:39
ComboFix2.txt 2010-02-18 21:43
Před spuštěním: 3 018 838 016
Po spuštění: 2 975 330 304
- - End Of File - - E3D5456FA781F7FC9E488D3D0C1B2851
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-18 do 2010-02-18 )))))))))))))))))))))))))))))))
.
2010-02-18 21:13 . 2010-02-18 21:13 -------- d-----w- c:\program files\trend micro
2010-02-18 21:13 . 2010-02-18 21:13 -------- d-----w- C:\rsit
2010-02-18 20:17 . 2010-02-18 20:17 -------- d-----w- c:\program files\Uniblue
2010-02-17 20:59 . 2010-02-17 20:59 -------- d-----w- c:\program files\XTS Manager
2010-02-17 20:58 . 2010-02-18 20:05 -------- d-----w- c:\program files\Windows RT
2010-02-16 19:20 . 2010-02-16 19:20 -------- d-----w- c:\program files\YouTube Downloader
2010-02-13 04:18 . 2010-02-13 04:18 -------- d-----w- c:\windows\system32\XPSViewer
2010-02-13 04:18 . 2010-02-13 04:18 -------- d-----w- c:\program files\MSBuild
2010-02-13 04:17 . 2010-02-13 04:17 -------- d-----w- c:\program files\Reference Assemblies
2010-02-13 04:17 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-02-13 04:17 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-02-13 04:17 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-02-13 04:17 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-02-13 04:17 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-02-13 04:17 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-02-13 04:17 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-02-13 04:17 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-02-13 04:17 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-02-11 06:15 . 2010-02-11 06:15 -------- d-----w- c:\program files\Opera
2010-02-09 08:34 . 2010-02-14 09:46 -------- d-----w- c:\program files\Everstrike Software
2010-02-09 08:34 . 2010-02-09 08:34 -------- d-----w- c:\program files\Common Files\Everstrike Software
2010-02-08 22:26 . 2010-02-09 08:31 -------- d-----r- c:\documents and settings\Hanka\My Private Folder
2010-02-03 13:43 . 2010-02-11 18:38 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-02-03 13:43 . 2010-02-11 18:42 162512 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-02-03 13:43 . 2010-02-11 18:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-02-03 13:43 . 2010-02-11 18:39 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-02-03 13:43 . 2010-02-11 18:38 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-02-03 13:43 . 2010-02-11 18:38 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-02-03 13:43 . 2010-02-11 18:38 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-02-03 13:43 . 2010-02-11 18:53 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-03 13:43 . 2010-02-11 18:53 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-02-03 13:43 . 2010-02-03 13:43 -------- d-----w- c:\program files\Alwil Software
2010-01-25 09:59 . 2010-01-25 09:59 -------- d-----w- c:\program files\Common Files\Skype
2010-01-25 09:59 . 2010-01-25 09:59 -------- d-----r- c:\program files\Skype
2010-01-24 04:34 . 2010-01-24 04:35 -------- d-----w- c:\documents and settings\All Users\ALL
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-18 18:36 . 2009-09-06 01:46 -------- d-----w- c:\program files\TweakNow RegCleaner
2010-02-18 18:28 . 2009-11-07 19:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-15 02:03 . 2001-10-25 14:00 78052 ----a-w- c:\windows\system32\perfc005.dat
2010-02-15 02:03 . 2001-10-25 14:00 429024 ----a-w- c:\windows\system32\perfh005.dat
2010-02-04 23:32 . 2008-06-16 20:49 -------- d-----w- c:\program files\ESET
2010-02-03 18:26 . 2009-09-24 14:42 -------- d-----w- c:\program files\Seznam.cz
2010-01-18 06:34 . 2008-06-17 01:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-11 05:29 . 2010-01-11 05:29 -------- d-----w- c:\program files\Windows Media Connect 2
2010-01-11 00:58 . 2010-01-11 00:58 -------- d-----w- c:\program files\DsNET Corp
2010-01-09 11:20 . 2010-01-09 11:17 -------- d-----w- c:\program files\Google
2010-01-09 11:17 . 2010-01-09 11:17 -------- d-----w- c:\program files\DivX
2010-01-09 11:17 . 2010-01-09 11:17 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-01-04 19:42 . 2009-10-14 10:56 -------- d-----w- c:\program files\Garena
2009-12-31 16:50 . 2004-08-03 21:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-29 21:31 . 2009-08-24 15:48 -------- d-----w- c:\program files\ICQ6.5
2009-12-21 19:08 . 2004-08-17 13:49 916480 ------w- c:\windows\system32\wininet.dll
2009-12-17 07:42 . 2008-06-17 01:33 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2004-08-17 13:49 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-06 12:19 . 2008-06-17 01:36 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-06 12:19 . 2008-06-17 01:36 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-04 18:22 . 2004-08-03 21:15 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:14 . 2004-08-17 13:49 1294336 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:14 . 2004-08-17 15:49 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:09 . 2001-10-25 14:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:09 . 2001-10-24 12:25 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:09 . 2004-08-17 15:49 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:09 . 2004-08-17 13:49 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:09 . 2004-08-17 13:49 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-21 16:03 . 2004-08-17 13:49 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-27 16844800]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"nwiz"="nwiz.exe" [2007-04-19 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-19 86016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2007-08-09 319488]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSecurityTab"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Hanka^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
path=c:\documents and settings\Hanka\Nabídka Start\Programy\Po spuštění\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12.9.2009 21:12 721904]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3.2.2010 14:43 162512]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3.2.2010 14:43 19024]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate1ca911d4d7cf296;Služba Google Update (gupdate1ca911d4d7cf296);c:\program files\Google\Update\GoogleUpdate.exe [9.1.2010 12:17 133104]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp --> c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp [?]
S3 RTCore32;RTCore32;c:\install\rm\RTCore32.sys [14.10.2009 13:38 4608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Doplňkový sken -------
.
FF - ProfilePath - c:\documents and settings\Hanka\Data aplikací\Mozilla\Firefox\Profiles\iorlbrve.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-18 23:37
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spkz.sys >>UNKNOWN [0x86F88938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75e0f28
\Driver\ACPI -> ACPI.sys @ 0xf735acb8
\Driver\atapi -> atapi.sys @ 0xf72efb40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf71e5bb0
PacketIndicateHandler -> NDIS.sys @ 0xf71f2a21
SendHandler -> NDIS.sys @ 0xf71d087b
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\Hanka\LOCALS~1\Temp\AXI87F.tmp"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(2624)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Celkový čas: 2010-02-18 23:40:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-18 22:39
ComboFix2.txt 2010-02-18 21:43
Před spuštěním: 3 018 838 016
Po spuštění: 2 975 330 304
- - End Of File - - E3D5456FA781F7FC9E488D3D0C1B2851
- Unlimited_Killer
- Přítel fóra
- Příspěvky: 1969
- Registrován: 24 srp 2009 16:18
Re: Preventinka - pomalý počítač
Super. 
1) Odinstalace virtuálních mechanik

1) Odinstalace virtuálních mechanik
- Odinstalujte všechny virtuální mechaniky - například Alcohol, DeamonTools atd.
- Přejděte na tento odkaz.
- Zde si stáhněte verzi SPTD dle Vašeho operačního systému (XP/Vista/W7 - 32/64bit).
- Stažený soubor dvojklikem spusťte.
- Klikněte na prostřední tlačítko 'Uninstall'.
- Restartujte PC.
- Stáhněte MBR.exe na Plochu.
- Proklikejte se na Start → Spustit [Win+R] a zadejte či vkopírujte následující text:
Kód: Vybrat vše
"%userprofile%\plocha\mbr" -t
- Nyní stiskněte 'Enter'.
- Na Ploše by se měl vytvořit soubor MBR.log, jehož obsah mi sem vkopírujete ve formě textu.
- Stáhněte GMER, rozbalte ho na Plochu a dvojklikem ho spusťte.
- Několik sekund bude skenovat.
- Až sken dokončí, klikněte na 'Save' - to vygeneruje první log, který mi vložíte ve formě textu sem.
- Poté vytvořte druhý log, přičemž se budete řídit tímto návodem - tento log mi sem taktéž vložíte.
inactive
Re: Preventinka - pomalý počítač
tealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
Re: Preventinka - pomalý počítač
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-02-19 22:04:03
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Hanka\LOCALS~1\Temp\pxtdipow.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF3FF04FE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF3FF0322]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF3FF045C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
Rootkit quick scan 2010-02-19 22:04:03
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Hanka\LOCALS~1\Temp\pxtdipow.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF3FF04FE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF3FF0322]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF3FF045C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
- Unlimited_Killer
- Přítel fóra
- Příspěvky: 1969
- Registrován: 24 srp 2009 16:18
Re: Preventinka - pomalý počítač
během gmeru jsem musela dvakrát restartovat, protože se najednou vše spadl byla jen prázdná plocha bez všech ikonek, jen obrázek pozadí a moc děkuji za spolupráci:)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-20 00:12:34
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Hanka\LOCALS~1\Temp\pxtdipow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF3A0EC5A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF3A0EB16]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xF3A0F0CA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF3A0EFF4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF3A0E6EC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF3A0EBF0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF3A0E62C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF3A0E690]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF3A0ED10]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xF3A0F198]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF3A0ECD0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF3A0EE50]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF3A1B4FE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF3A1B322]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF3A1B45C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
PAGE ntkrnlpa.exe!ZwLoadDriver 8058413A 7 Bytes JMP F3A1B460 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 805AB3AC 7 Bytes JMP F3A1B326 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC520 5 Bytes JMP F3A174BA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject 805C2FA4 5 Bytes JMP F3A18972 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1144 7 Bytes JMP F3A1B502 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF68BC360, 0x24CB9D, 0xE8000020]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[740] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[740] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Fastfat \FatCdrom aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC9 0x7F 0x8E 0x91 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x7A 0x27 0x2C 0xF5 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAB 0xF1 0xC7 0xB9 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x6F 0xA1 0xCD 0x7C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xA4 0x20 0x49 0x95 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x7A 0x27 0x2C 0xF5 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xDC 0xD1 0x3F 0xB0 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x33 0x4E 0x6E 0x83 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x97 0x89 0x02 0x2A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0xF0 0x0B 0xA9 0xFC ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0xC1 0x6F 0xB6 0x7A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC9 0x7F 0x8E 0x91 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x7A 0x27 0x2C 0xF5 ...
---- EOF - GMER 1.0.15 ----
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-20 00:12:34
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Hanka\LOCALS~1\Temp\pxtdipow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF3A0EC5A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF3A0EB16]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xF3A0F0CA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF3A0EFF4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF3A0E6EC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF3A0EBF0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF3A0E62C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF3A0E690]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF3A0ED10]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xF3A0F198]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF3A0ECD0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF3A0EE50]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF3A1B4FE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF3A1B322]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF3A1B45C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
PAGE ntkrnlpa.exe!ZwLoadDriver 8058413A 7 Bytes JMP F3A1B460 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 805AB3AC 7 Bytes JMP F3A1B326 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC520 5 Bytes JMP F3A174BA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject 805C2FA4 5 Bytes JMP F3A18972 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1144 7 Bytes JMP F3A1B502 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF68BC360, 0x24CB9D, 0xE8000020]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[740] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[740] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Fastfat \FatCdrom aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC9 0x7F 0x8E 0x91 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x7A 0x27 0x2C 0xF5 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAB 0xF1 0xC7 0xB9 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x6F 0xA1 0xCD 0x7C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xA4 0x20 0x49 0x95 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x7A 0x27 0x2C 0xF5 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xDC 0xD1 0x3F 0xB0 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x33 0x4E 0x6E 0x83 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x97 0x89 0x02 0x2A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0xF0 0x0B 0xA9 0xFC ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0xC1 0x6F 0xB6 0x7A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC9 0x7F 0x8E 0x91 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x7A 0x27 0x2C 0xF5 ...
---- EOF - GMER 1.0.15 ----
- Unlimited_Killer
- Přítel fóra
- Příspěvky: 1969
- Registrován: 24 srp 2009 16:18
Re: Preventinka - pomalý počítač
Logfile of random's system information tool 1.06 (written by random/random)
Run by Hanka at 2010-02-20 00:25:24
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (13%) free of 20 GB
Total RAM: 1023 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:25:27, on 20.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Hanka\Plocha\RSIT.exe
C:\Program Files\trend micro\Hanka.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.2.dll
O3 - Toolbar: &S-Rank - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Kniha klipů HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Chytrý výběr - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://icq.oberon-media.com/online/onli ... uncher.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate1ca911d4d7cf296) (gupdate1ca911d4d7cf296) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 6072 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\core.2.dll [2010-01-18 1098392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B71B15CF-3093-459C-B764-AEB2486F2273} - &S-Rank - C:\Program Files\Seznam\Postak\SRank.dll [2007-05-16 269632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-09-27 16844800]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-04-19 7700480]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-04-19 86016]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
"PAC7302_Monitor"=C:\WINDOWS\PixArt\PAC7302\Monitor.exe [2007-08-09 319488]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-02-11 2756488]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hanka^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
C:\PROGRA~1\Xfire\Xfire.exe [2006-02-15 3631752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoLogOff"=0
"NoSecurityTab"=1
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======File associations======
.ini - open - "C:\Program Files\GetDiz\GetDiz.exe" "%1"
.txt - open - "C:\Program Files\GetDiz\GetDiz.exe" "%1"
======List of files/folders created in the last 1 months======
2010-02-19 15:50:47 ----SHD---- C:\RECYCLER
2010-02-18 23:40:01 ----A---- C:\ComboFix.txt
2010-02-18 23:22:15 ----D---- C:\ComboFix
2010-02-18 22:35:24 ----A---- C:\Boot.bak
2010-02-18 22:35:20 ----RASHD---- C:\cmdcons
2010-02-18 22:31:20 ----A---- C:\WINDOWS\zip.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\SWSC.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\SWREG.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\sed.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\PEV.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\MBR.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\grep.exe
2010-02-18 22:31:08 ----D---- C:\WINDOWS\ERDNT
2010-02-18 22:28:56 ----D---- C:\Qoobox
2010-02-18 22:13:09 ----D---- C:\Program Files\trend micro
2010-02-18 22:13:08 ----D---- C:\rsit
2010-02-18 21:17:05 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Uniblue
2010-02-18 21:17:00 ----D---- C:\Program Files\Uniblue
2010-02-18 19:58:32 ----A---- C:\WINDOWS\wininit.ini
2010-02-17 21:59:00 ----D---- C:\Program Files\XTS Manager
2010-02-17 21:58:10 ----D---- C:\Program Files\Windows RT
2010-02-16 20:20:05 ----D---- C:\Program Files\YouTube Downloader
2010-02-15 03:00:33 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-02-13 05:18:07 ----D---- C:\WINDOWS\system32\XPSViewer
2010-02-13 05:18:04 ----D---- C:\Program Files\MSBuild
2010-02-13 05:18:03 ----D---- C:\WINDOWS\system32\en-US
2010-02-13 05:17:57 ----D---- C:\Program Files\Reference Assemblies
2010-02-13 05:17:32 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-02-13 05:17:31 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-02-13 05:17:31 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-02-11 07:15:24 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Opera
2010-02-11 07:15:15 ----D---- C:\Program Files\Opera
2010-02-11 03:03:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-11 03:03:03 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-11 03:01:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-11 03:01:02 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-11 03:00:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-11 03:00:47 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-11 03:00:35 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-11 03:00:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-09 09:34:24 ----D---- C:\Program Files\Everstrike Software
2010-02-09 09:34:24 ----D---- C:\Program Files\Common Files\Everstrike Software
2010-02-08 23:09:09 ----RSD---- C:\WINDOWS\assembly
2010-02-08 23:08:45 ----D---- C:\WINDOWS\Microsoft.NET
2010-02-03 14:43:19 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-02-03 14:43:16 ----D---- C:\Program Files\Alwil Software
2010-02-03 14:43:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-01-25 10:59:17 ----D---- C:\Program Files\Common Files\Skype
2010-01-25 10:59:14 ----RD---- C:\Program Files\Skype
======List of files/folders modified in the last 1 months======
2010-02-20 00:21:24 ----D---- C:\WINDOWS\Prefetch
2010-02-20 00:19:57 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-20 00:16:36 ----D---- C:\Program Files\Mozilla Firefox
2010-02-20 00:16:01 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Skype
2010-02-20 00:15:59 ----D---- C:\WINDOWS\Temp
2010-02-20 00:15:49 ----D---- C:\Documents and Settings\Hanka\Data aplikací\skypePM
2010-02-19 22:57:20 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-19 21:55:46 ----D---- C:\WINDOWS\system32\drivers
2010-02-19 21:54:42 ----RD---- C:\Program Files
2010-02-19 21:51:59 ----D---- C:\WINDOWS
2010-02-18 23:37:23 ----A---- C:\WINDOWS\system.ini
2010-02-18 23:34:12 ----SD---- C:\WINDOWS\Tasks
2010-02-18 23:30:37 ----D---- C:\WINDOWS\system32
2010-02-18 23:30:37 ----D---- C:\WINDOWS\AppPatch
2010-02-18 23:30:33 ----D---- C:\Program Files\Common Files
2010-02-18 22:38:51 ----D---- C:\WINDOWS\system32\config
2010-02-18 22:38:22 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-02-18 22:35:24 ----RASH---- C:\boot.ini
2010-02-18 22:31:19 ----SHD---- C:\System Volume Information
2010-02-18 22:31:19 ----D---- C:\WINDOWS\system32\Restore
2010-02-18 19:41:18 ----SHD---- C:\WINDOWS\Installer
2010-02-18 19:41:17 ----D---- C:\Config.Msi
2010-02-18 19:36:12 ----D---- C:\Program Files\TweakNow RegCleaner
2010-02-18 19:28:14 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-02-18 19:21:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-02-18 19:05:45 ----D---- C:\WINDOWS\Debug
2010-02-18 10:08:52 ----D---- C:\Documents and Settings\Hanka\Data aplikací\vlc
2010-02-16 20:37:17 ----HD---- C:\WINDOWS\inf
2010-02-15 03:03:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-15 03:02:52 ----D---- C:\WINDOWS\WinSxS
2010-02-15 03:01:02 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-15 03:00:47 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-13 18:22:45 ----A---- C:\WINDOWS\NeroDigital.ini
2010-02-13 05:18:02 ----RSD---- C:\WINDOWS\Fonts
2010-02-13 05:17:44 ----D---- C:\WINDOWS\system32\spool
2010-02-13 05:16:21 ----D---- C:\WINDOWS\system32\mui
2010-02-13 05:16:21 ----D---- C:\Program Files\Internet Explorer
2010-02-11 22:30:59 ----D---- C:\Documents and Settings\Hanka\Data aplikací\ICQ
2010-02-11 03:03:07 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-08 23:11:08 ----SD---- C:\Documents and Settings\Hanka\Data aplikací\Microsoft
2010-02-08 23:08:54 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-02-08 23:08:45 ----D---- C:\WINDOWS\pchealth
2010-02-05 00:32:57 ----D---- C:\Program Files\ESET
2010-02-03 22:27:24 ----D---- C:\WINDOWS\network diagnostic
2010-02-03 19:26:59 ----D---- C:\Program Files\Seznam.cz
2010-02-01 20:26:20 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-02-11 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-02-11 162512]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-02-11 46672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-02-11 19024]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-02-11 100432]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-02-11 23376]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-10-02 4613120]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-04-19 3988384]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-13 163584]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-10-23 103296]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\Hanka\LOCALS~1\Temp\AXI87F.tmp []
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2008-06-16 9856]
S3 RTCore32;RTCore32; \??\C:\install\rm\RTCore32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-04-19 159810]
R2 NWCWorkstation;Klient systému NetWare; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
S2 gupdate1ca911d4d7cf296;Služba Google Update (gupdate1ca911d4d7cf296); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-09 133104]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Run by Hanka at 2010-02-20 00:25:24
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (13%) free of 20 GB
Total RAM: 1023 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:25:27, on 20.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Hanka\Plocha\RSIT.exe
C:\Program Files\trend micro\Hanka.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.2.dll
O3 - Toolbar: &S-Rank - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Kniha klipů HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Chytrý výběr - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://icq.oberon-media.com/online/onli ... uncher.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate1ca911d4d7cf296) (gupdate1ca911d4d7cf296) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 6072 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\core.2.dll [2010-01-18 1098392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B71B15CF-3093-459C-B764-AEB2486F2273} - &S-Rank - C:\Program Files\Seznam\Postak\SRank.dll [2007-05-16 269632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-09-27 16844800]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-04-19 7700480]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-04-19 86016]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
"PAC7302_Monitor"=C:\WINDOWS\PixArt\PAC7302\Monitor.exe [2007-08-09 319488]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-02-11 2756488]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hanka^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
C:\PROGRA~1\Xfire\Xfire.exe [2006-02-15 3631752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoLogOff"=0
"NoSecurityTab"=1
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======File associations======
.ini - open - "C:\Program Files\GetDiz\GetDiz.exe" "%1"
.txt - open - "C:\Program Files\GetDiz\GetDiz.exe" "%1"
======List of files/folders created in the last 1 months======
2010-02-19 15:50:47 ----SHD---- C:\RECYCLER
2010-02-18 23:40:01 ----A---- C:\ComboFix.txt
2010-02-18 23:22:15 ----D---- C:\ComboFix
2010-02-18 22:35:24 ----A---- C:\Boot.bak
2010-02-18 22:35:20 ----RASHD---- C:\cmdcons
2010-02-18 22:31:20 ----A---- C:\WINDOWS\zip.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\SWSC.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\SWREG.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\sed.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\PEV.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\MBR.exe
2010-02-18 22:31:20 ----A---- C:\WINDOWS\grep.exe
2010-02-18 22:31:08 ----D---- C:\WINDOWS\ERDNT
2010-02-18 22:28:56 ----D---- C:\Qoobox
2010-02-18 22:13:09 ----D---- C:\Program Files\trend micro
2010-02-18 22:13:08 ----D---- C:\rsit
2010-02-18 21:17:05 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Uniblue
2010-02-18 21:17:00 ----D---- C:\Program Files\Uniblue
2010-02-18 19:58:32 ----A---- C:\WINDOWS\wininit.ini
2010-02-17 21:59:00 ----D---- C:\Program Files\XTS Manager
2010-02-17 21:58:10 ----D---- C:\Program Files\Windows RT
2010-02-16 20:20:05 ----D---- C:\Program Files\YouTube Downloader
2010-02-15 03:00:33 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-02-13 05:18:07 ----D---- C:\WINDOWS\system32\XPSViewer
2010-02-13 05:18:04 ----D---- C:\Program Files\MSBuild
2010-02-13 05:18:03 ----D---- C:\WINDOWS\system32\en-US
2010-02-13 05:17:57 ----D---- C:\Program Files\Reference Assemblies
2010-02-13 05:17:32 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-02-13 05:17:31 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-02-13 05:17:31 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-02-11 07:15:24 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Opera
2010-02-11 07:15:15 ----D---- C:\Program Files\Opera
2010-02-11 03:03:08 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-11 03:03:03 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-11 03:01:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-11 03:01:02 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-11 03:00:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-11 03:00:47 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-11 03:00:35 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-11 03:00:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-09 09:34:24 ----D---- C:\Program Files\Everstrike Software
2010-02-09 09:34:24 ----D---- C:\Program Files\Common Files\Everstrike Software
2010-02-08 23:09:09 ----RSD---- C:\WINDOWS\assembly
2010-02-08 23:08:45 ----D---- C:\WINDOWS\Microsoft.NET
2010-02-03 14:43:19 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-02-03 14:43:16 ----D---- C:\Program Files\Alwil Software
2010-02-03 14:43:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-01-25 10:59:17 ----D---- C:\Program Files\Common Files\Skype
2010-01-25 10:59:14 ----RD---- C:\Program Files\Skype
======List of files/folders modified in the last 1 months======
2010-02-20 00:21:24 ----D---- C:\WINDOWS\Prefetch
2010-02-20 00:19:57 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-20 00:16:36 ----D---- C:\Program Files\Mozilla Firefox
2010-02-20 00:16:01 ----D---- C:\Documents and Settings\Hanka\Data aplikací\Skype
2010-02-20 00:15:59 ----D---- C:\WINDOWS\Temp
2010-02-20 00:15:49 ----D---- C:\Documents and Settings\Hanka\Data aplikací\skypePM
2010-02-19 22:57:20 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-19 21:55:46 ----D---- C:\WINDOWS\system32\drivers
2010-02-19 21:54:42 ----RD---- C:\Program Files
2010-02-19 21:51:59 ----D---- C:\WINDOWS
2010-02-18 23:37:23 ----A---- C:\WINDOWS\system.ini
2010-02-18 23:34:12 ----SD---- C:\WINDOWS\Tasks
2010-02-18 23:30:37 ----D---- C:\WINDOWS\system32
2010-02-18 23:30:37 ----D---- C:\WINDOWS\AppPatch
2010-02-18 23:30:33 ----D---- C:\Program Files\Common Files
2010-02-18 22:38:51 ----D---- C:\WINDOWS\system32\config
2010-02-18 22:38:22 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-02-18 22:35:24 ----RASH---- C:\boot.ini
2010-02-18 22:31:19 ----SHD---- C:\System Volume Information
2010-02-18 22:31:19 ----D---- C:\WINDOWS\system32\Restore
2010-02-18 19:41:18 ----SHD---- C:\WINDOWS\Installer
2010-02-18 19:41:17 ----D---- C:\Config.Msi
2010-02-18 19:36:12 ----D---- C:\Program Files\TweakNow RegCleaner
2010-02-18 19:28:14 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-02-18 19:21:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-02-18 19:05:45 ----D---- C:\WINDOWS\Debug
2010-02-18 10:08:52 ----D---- C:\Documents and Settings\Hanka\Data aplikací\vlc
2010-02-16 20:37:17 ----HD---- C:\WINDOWS\inf
2010-02-15 03:03:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-15 03:02:52 ----D---- C:\WINDOWS\WinSxS
2010-02-15 03:01:02 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-15 03:00:47 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-13 18:22:45 ----A---- C:\WINDOWS\NeroDigital.ini
2010-02-13 05:18:02 ----RSD---- C:\WINDOWS\Fonts
2010-02-13 05:17:44 ----D---- C:\WINDOWS\system32\spool
2010-02-13 05:16:21 ----D---- C:\WINDOWS\system32\mui
2010-02-13 05:16:21 ----D---- C:\Program Files\Internet Explorer
2010-02-11 22:30:59 ----D---- C:\Documents and Settings\Hanka\Data aplikací\ICQ
2010-02-11 03:03:07 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-08 23:11:08 ----SD---- C:\Documents and Settings\Hanka\Data aplikací\Microsoft
2010-02-08 23:08:54 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-02-08 23:08:45 ----D---- C:\WINDOWS\pchealth
2010-02-05 00:32:57 ----D---- C:\Program Files\ESET
2010-02-03 22:27:24 ----D---- C:\WINDOWS\network diagnostic
2010-02-03 19:26:59 ----D---- C:\Program Files\Seznam.cz
2010-02-01 20:26:20 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-02-11 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-02-11 162512]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-02-11 46672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-02-11 19024]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-02-11 100432]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-02-11 23376]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-10-02 4613120]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-04-19 3988384]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-13 163584]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-10-23 103296]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\Hanka\LOCALS~1\Temp\AXI87F.tmp []
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2008-06-16 9856]
S3 RTCore32;RTCore32; \??\C:\install\rm\RTCore32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-04-19 159810]
R2 NWCWorkstation;Klient systému NetWare; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
S2 gupdate1ca911d4d7cf296;Služba Google Update (gupdate1ca911d4d7cf296); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-09 133104]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
- Unlimited_Killer
- Přítel fóra
- Příspěvky: 1969
- Registrován: 24 srp 2009 16:18
Re: Preventinka - pomalý počítač
0K.
1) Zazipujte/Zararujte složku C:\Qoobox - uploadněte ji na server http://www.leteckaposta.cz
1) Zazipujte/Zararujte složku C:\Qoobox - uploadněte ji na server http://www.leteckaposta.cz
- Odkaz na soubor mi pošlete Soukromou zprávou.
- Proklikejte se přes Start do Spustit [klávesová zkratka je Win+R].
- Do textového pole napište:
Kód: Vybrat vše
ComboFix /Uninstall
- Stiskněte Enter.
- Spustí se odinstalace ComboFixu, která smaže všechny jeho součásti.
- Stáhněte OTC a dvojklikem ho spusťte.
- Vyskočí okénko, kde kliknete na 'CleanUp!'.
- Potvrdíte kliknutím na 'Yes'.
- Poté se ještě zeptá, zda chcete restartovat PC - to proveďte opět kliknutím na 'Yes'.
inactive