Stránka 1 z 2

Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 15:55
od Ondra100
Logfile of random's system information tool 1.06 (written by random/random)
Run by Ondra at 2010-03-22 15:52:18
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 7 GB (33%) free of 20 GB
Total RAM: 1526 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:52:33, on 22.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Common Files\BinarySense\hldasvc.exe
C:\Program Files\Common Files\BinarySense\hldasvc.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\Program Files\Seznam\Postak\Postak.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\DOCUME~1\Ondra\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Ondra\Plocha\RSIT.exe
C:\Program Files\trend micro\Ondra.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &S-Rank - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SMail] "C:\Program Files\Seznam\Postak\Postak.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 5860782103
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - "C:\Program Files\Common Files\BinarySense\hlAPP.dll" (file missing)
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - SOURCENEXT - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: HDDlife HDD Access service - BinarySense, Inc. - C:\Program Files\Common Files\BinarySense\hldasvc.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

--
End of file - 8365 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B71B15CF-3093-459C-B764-AEB2486F2273} - &S-Rank - C:\Program Files\Seznam\Postak\SRank.dll [2007-05-16 269632]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-01-03 1019128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-08-24 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-08-24 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-08-24 131072]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2007-07-16 768520]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-10-25 16855552]
"ePower_DMC"=C:\Acer\Empowering Technology\ePower\ePower_DMC.exe [2006-04-04 421888]
"Boot"=C:\Acer\Empowering Technology\ePower\Boot.exe [2006-03-15 579584]
"WinFast Schedule"=C:\Program Files\WinFast\WFTVFM\WFWIZ.exe [2005-03-02 278528]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"SMail"=C:\Program Files\Seznam\Postak\Postak.exe [2008-02-21 453936]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2009-07-01 37888]
"Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2005-10-26 159744]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2006-11-23 56928]
"LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2006-12-05 54832]
"MSSE"=C:\Program Files\Microsoft Security Essentials\msseces.exe [2010-02-21 1093208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe

C:\Documents and Settings\Ondra\Nabídka Start\Programy\Po spuštění
HDDlife.lnk - C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-08-24 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Documents and Settings\Ondra\Data aplikací\Intelore\Office Password Recovery\OfficePasswordRecovery.exe"="C:\Documents and Settings\Ondra\Data aplikací\Intelore\Office Password Recovery\OfficePasswordRecovery.exe:*:Enabled:Office Password Recovery"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Formix SE\Formix.exe"="C:\Program Files\Formix SE\Formix.exe:*:Enabled:DATUM VERZE"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"

======List of files/folders created in the last 1 months======

2010-03-22 15:52:19 ----D---- C:\Program Files\trend micro
2010-03-22 15:52:18 ----D---- C:\rsit
2010-03-22 15:52:04 ----D---- C:\Program Files\TrendMicro
2010-03-19 15:51:49 ----D---- C:\Documents and Settings\Ondra\Data aplikací\Acoustica
2010-03-18 14:52:32 ----D---- C:\SAV32CLI
2010-03-18 14:51:23 ----D---- C:\SDFix
2010-03-18 14:48:58 ----SHD---- C:\RECYCLER
2010-03-18 13:55:30 ----A---- C:\ComboFix.txt
2010-03-18 13:48:18 ----D---- C:\ComboFix
2010-03-18 13:46:25 ----A---- C:\WINDOWS\system32\CF4003.exe
2010-03-12 17:44:08 ----D---- C:\Program Files\eKucharka
2010-03-11 09:34:23 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-02-25 18:18:18 ----A---- C:\Boot.bak
2010-02-25 18:18:10 ----RASHD---- C:\cmdcons
2010-02-25 18:17:29 ----A---- C:\WINDOWS\zip.exe
2010-02-25 18:17:29 ----A---- C:\WINDOWS\SWREG.exe
2010-02-25 18:17:29 ----A---- C:\WINDOWS\sed.exe
2010-02-25 18:17:29 ----A---- C:\WINDOWS\PEV.exe
2010-02-25 18:17:29 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-25 18:17:29 ----A---- C:\WINDOWS\MBR.exe
2010-02-25 18:17:29 ----A---- C:\WINDOWS\grep.exe
2010-02-25 18:17:28 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-25 18:17:28 ----A---- C:\WINDOWS\SWSC.exe
2010-02-25 18:16:15 ----D---- C:\WINDOWS\ERDNT
2010-02-25 18:16:14 ----A---- C:\WINDOWS\system32\CF30059.exe
2010-02-25 18:16:06 ----D---- C:\Qoobox
2010-02-25 17:42:25 ----D---- C:\Program Files\AVI to VCD SVCD DVD Converter
2010-02-25 17:40:19 ----D---- C:\ConverterOutput
2010-02-25 17:40:13 ----A---- C:\avi_log.txt
2010-02-25 17:40:08 ----A---- C:\WINDOWS\system32\TomsMoComp_ff.dll
2010-02-25 17:40:08 ----A---- C:\WINDOWS\system32\libmplayer.dll
2010-02-25 17:40:08 ----A---- C:\WINDOWS\system32\libmpeg2_ff.dll
2010-02-25 17:40:08 ----A---- C:\WINDOWS\system32\libavcodec.dll
2010-02-25 17:40:04 ----D---- C:\Program Files\Cucusoft
2010-02-24 09:36:24 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$

======List of files/folders modified in the last 1 months======

2010-03-22 15:52:26 ----D---- C:\WINDOWS\Prefetch
2010-03-22 15:52:19 ----RD---- C:\Program Files
2010-03-22 15:52:08 ----SHD---- C:\WINDOWS\Installer
2010-03-22 15:51:46 ----D---- C:\WINDOWS\Temp
2010-03-22 15:46:53 ----SD---- C:\WINDOWS\Tasks
2010-03-22 15:42:02 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-22 15:41:53 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-03-22 14:03:00 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-20 14:10:40 ----D---- C:\WINDOWS
2010-03-20 10:25:47 ----HD---- C:\WINDOWS\inf
2010-03-20 10:25:35 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-03-20 10:21:51 ----D---- C:\1
2010-03-19 15:51:29 ----D---- C:\Program Files\Acoustica CD Label Maker
2010-03-19 15:51:08 ----D---- C:\WINDOWS\system32
2010-03-18 14:21:47 ----D---- C:\Program Files\Zip Password Recovery Master
2010-03-18 14:03:01 ----D---- C:\Program Files\ElcomSoft
2010-03-18 13:53:39 ----A---- C:\WINDOWS\system.ini
2010-03-18 13:52:23 ----D---- C:\WINDOWS\system32\drivers
2010-03-18 13:52:23 ----D---- C:\WINDOWS\AppPatch
2010-03-18 13:52:20 ----D---- C:\Program Files\Common Files
2010-03-11 23:00:14 ----D---- C:\WINDOWS\Minidump
2010-03-11 09:34:25 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-11 09:34:24 ----D---- C:\Program Files\Movie Maker
2010-03-11 09:34:09 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-10 16:09:37 ----D---- C:\Program Files\Microsoft Security Essentials
2010-03-07 19:17:49 ----A---- C:\WINDOWS\NeroDigital.ini
2010-03-02 06:30:12 ----A---- C:\WINDOWS\system32\MRT.exe
2010-02-26 13:48:03 ----D---- C:\WINDOWS\network diagnostic
2010-02-25 18:18:19 ----RASH---- C:\boot.ini
2010-02-24 10:16:06 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2010-02-24 09:36:51 ----A---- C:\WINDOWS\imsins.BAK

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 cdrbsdrv;cdrbsdrv; C:\WINDOWS\system32\drivers\cdrbsdrv.sys [2010-01-03 38944]
R1 DritekPortIO;Dritek General Port I/O; \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys []
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2009-12-02 149040]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 wg4n;SyGate for NT, wg4n; C:\WINDOWS\SYSTEM32\Drivers\wg4n.sys [2004-10-15 14568]
R2 wg5n;SyGate for NT, wg5n; C:\WINDOWS\SYSTEM32\Drivers\wg5n.sys [2004-10-15 14568]
R2 wg6n;SyGate for NT, wg6n; C:\WINDOWS\SYSTEM32\Drivers\wg6n.sys [2004-10-15 14568]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-05-02 546976]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2007-10-19 161792]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 DCamUSBEMPIA;WinFast TV USB II Deluxe; C:\WINDOWS\system32\DRIVERS\emDevice.sys [2004-09-21 110653]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\WINDOWS\system32\DRIVERS\DKbFltr.sys [2004-12-08 16896]
R3 emAudio;USB EMP Audio Device; C:\WINDOWS\system32\drivers\emAudio.sys [2004-09-22 20608]
R3 FiltUSBEMPIA;USB Device Lower Filter; C:\WINDOWS\system32\DRIVERS\emFilter.sys [2004-09-22 79563]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-08-24 5776928]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-11-01 4620288]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 ScanUSBEMPIA;USB Still Image Capture Device; C:\WINDOWS\system32\DRIVERS\emScan.sys [2004-09-21 4857]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WFIOCTL;WFIOCTL; \??\C:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS []
S3 catchme;catchme; \??\C:\DOCUME~1\Ondra\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 w810bus;Sony Ericsson W810 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\w810bus.sys [2006-02-20 58288]
S3 w810mdfl;Sony Ericsson W810 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\w810mdfl.sys [2006-02-20 8336]
S3 w810mdm;Sony Ericsson W810 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\w810mdm.sys [2006-02-20 94064]
S3 w810mgmt;Sony Ericsson W810 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\w810mgmt.sys [2006-02-20 85408]
S3 w810obex;Sony Ericsson W810 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\w810obex.sys [2006-02-20 83344]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 vsdatant;vsdatant; C:\WINDOWS\system32\drivers\vsdatant.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 bgsvcgen;B's Recorder GOLD Library General Service; C:\WINDOWS\system32\bgsvcgen.exe [2010-01-03 139264]
R2 HDDlife HDD Access service;HDDlife HDD Access service; C:\Program Files\Common Files\BinarySense\hldasvc.exe [2008-02-15 832760]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2009-12-09 17904]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2005-08-08 167936]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2009-11-16 603904]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-11-28 800040]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-11-16 362240]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 16:18
od Caroprd111
Zdravím :)

Na logu se pracuje, prosím o strpení.

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 16:22
od Caroprd111
Obrázek Odinstalujte Spybot - Search & Destroy.


Obrázek Doporučuji odinstalovat (pokud nepoužíváte) toolbary (lišty) v Přidat nebo odebrat programy.


Obrázek Vložte sem log z C:\ComboFix.txt

Nedoporučuji používat ComboFix z vlastní iniciativy, může dojít k poškození systému!

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 16:32
od Ondra100
ComboFix 10-03-17.07 - Ondra 18.03.2010 13:49:12.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1526.937 [GMT 1:00]
Spuštěný z: c:\documents and settings\Ondra\Plocha\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-02-18 do 2010-03-18 )))))))))))))))))))))))))))))))
.

2010-03-18 12:46 . 2010-03-18 12:46 390144 ----a-w- c:\windows\system32\CF4003.exe
2010-03-12 16:44 . 2010-03-12 16:48 -------- d-----w- c:\program files\eKucharka
2010-03-11 08:29 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-02-25 17:16 . 2010-02-25 17:16 390144 ----a-w- c:\windows\system32\CF30059.exe
2010-02-25 16:42 . 2010-02-25 16:42 -------- d-----w- c:\program files\AVI to VCD SVCD DVD Converter
2010-02-25 16:40 . 2010-02-25 16:40 -------- d-----w- C:\ConverterOutput
2010-02-25 16:40 . 2004-10-12 13:42 262144 ----a-w- c:\windows\system32\TomsMoComp_ff.dll
2010-02-25 16:40 . 2004-10-12 13:40 2255360 ----a-w- c:\windows\system32\libavcodec.dll
2010-02-25 16:40 . 2004-10-05 15:16 395776 ----a-w- c:\windows\system32\libmplayer.dll
2010-02-25 16:40 . 2004-10-04 00:50 112640 ----a-w- c:\windows\system32\libmpeg2_ff.dll
2010-02-25 16:40 . 2010-02-25 16:40 -------- d-----w- c:\program files\Cucusoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-10 15:09 . 2010-02-15 16:30 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-02-24 09:16 . 2010-02-15 16:32 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-18 02:55 . 2010-02-10 17:08 -------- d-----w- c:\program files\ICQ7.0
2010-02-10 17:09 . 2010-02-10 17:09 -------- d-----w- c:\program files\ICQ6Toolbar
2010-02-10 17:08 . 2009-10-18 09:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-08 14:20 . 2009-10-18 12:57 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-02-07 10:48 . 2010-02-07 10:48 -------- d-----w- c:\program files\Zip Password Recovery Master
2010-02-07 10:45 . 2010-02-07 10:45 -------- d-----w- c:\program files\Visual Zip Password Recovery Processor
2010-02-07 10:34 . 2009-12-27 14:04 -------- d-----w- c:\program files\Passware
2010-02-01 17:44 . 2010-02-01 17:43 -------- d-----w- c:\program files\CyberLink
2010-01-20 14:49 . 2010-01-20 14:49 -------- d-----w- c:\program files\OpenOffice.org 3
2010-01-17 17:46 . 2010-01-17 17:46 -------- d-----w- c:\program files\YouTube Downloader
2010-01-03 19:37 . 2010-01-03 19:38 59240 ----a-w- c:\windows\system32\GenSvcInst.exe
2010-01-03 19:37 . 2010-01-03 19:38 38944 ----a-w- c:\windows\system32\drivers\CDRBSDRV.SYS
2010-01-03 19:37 . 2010-01-03 19:38 139264 ----a-w- c:\windows\system32\bgsvcgen.exe
2009-12-31 16:50 . 2006-03-02 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:08 . 2006-03-02 12:00 916480 ------w- c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-02-25_17.26.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-02 05:23 . 2010-03-02 05:23 16384 c:\windows\Temp\Perflib_Perfdata_fc.dat
+ 2010-03-18 12:36 . 2010-03-18 12:36 16384 c:\windows\Temp\Perflib_Perfdata_79c.dat
+ 2010-03-11 08:32 . 2010-03-11 08:32 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2010-01-19 08:36 . 2010-01-19 08:36 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2009-06-18 17:48 . 2009-12-02 14:23 149040 c:\windows\system32\drivers\MpFilter.sys
+ 2010-03-10 15:09 . 2010-03-10 15:09 272384 c:\windows\Installer\15f04a.msi
+ 2010-03-10 15:08 . 2010-03-10 15:08 254976 c:\windows\Installer\15f027.msi
+ 2010-02-21 00:00 . 2010-02-21 00:00 8480768 c:\windows\Installer\694b8.msp
+ 2009-10-18 10:54 . 2010-03-02 05:30 31648712 c:\windows\system32\MRT.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-08-24 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-08-24 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-08-24 131072]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2007-07-16 768520]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-25 16855552]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-04-04 421888]
"Boot"="c:\acer\Empowering Technology\ePower\Boot.exe" [2006-03-15 579584]
"WinFast Schedule"="c:\program files\WinFast\WFTVFM\WFWIZ.exe" [2005-03-02 278528]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SMail"="c:\program files\Seznam\Postak\Postak.exe" [2008-02-21 453936]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Ondra\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HDDlife.lnk - c:\program files\BinarySense\HDDlife 3\HDDlifePro.exe [2008-2-15 2278648]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-5-15 384512]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Acer Empowering Technology.lnk - c:\acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2009-10-18 45056]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Ondra\\Data aplikací\\Intelore\\Office Password Recovery\\OfficePasswordRecovery.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Formix SE\\Formix.exe"=
"c:\\Program Files\\ICQ7.0\\ICQ.exe"=
"c:\\Program Files\\ICQ7.0\\aolload.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [10.2.2010 18:09 246520]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFTVFM\WFIOCTL.sys [18.10.2009 13:13 9446]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-03-18 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 15:28]

2010-03-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 17:02]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: {{88EB38EF-4D2C-436D-ABD3-56B232674062} - c:\program files\ICQ7.0\ICQ.exe
Handler: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - c:\program files\Common Files\BinarySense\hlAPP.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-18 13:53
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1659004503-1284227242-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0F4A205D-B4D5-B782-51E9-E0FCEA2263D5}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"palhefaepcfeijngclaopicbpcojjffc"=hex:6b,61,68,63,68,67,6c,61,6b,66,6b,6f,70,
6d,61,6b,65,69,64,66,6e,6c,00,00
"oafigehbkhfgibooihhomekalologl"=hex:6b,61,68,63,68,67,6c,61,6b,66,6b,6f,70,6d,
61,6b,65,69,64,66,6e,6c,00,00
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(2524)
c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll
c:\program files\Common Files\Ahead\Lib\MFC71U.DLL
c:\program files\Common Files\Ahead\Lib\BCGCBPRO860un71.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-03-18 13:55:29
ComboFix-quarantined-files.txt 2010-03-18 12:55
ComboFix2.txt 2010-02-25 17:28

Před spuštěním: 6 799 675 392
Po spuštění: 6 880 182 272

- - End Of File - - 9DF549CBF98FE61B95F947AAD1A51B41

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 16:47
od Caroprd111
Obrázek Stahněte OTL http://oldtimer.geekstogo.com/OTL.exe
  • Spusťte program, poté klikněte na Run Scan
  • Po dokončení, sem vložte logy OTL.Txt a Extras.txt

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 16:59
od Ondra100
OTL logfile created on: 22.3.2010 16:55:03 - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Ondra\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 60,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 84,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 6,44 Gb Free Space | 32,98% Space Free | Partition Type: NTFS
Drive D: | 54,99 Gb Total Space | 15,76 Gb Free Space | 28,66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OND-F0A308A7C77
Current User Name: Ondra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.03.22 16:54:39 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
PRC - [2010.03.18 18:05:29 | 000,212,992 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Documents and Settings\Ondra\Local Settings\temp\RtkBtMnt.exe
PRC - [2010.02.21 05:03:12 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010.01.03 20:37:30 | 000,139,264 | ---- | M] (SOURCENEXT) -- C:\WINDOWS\system32\bgsvcgen.exe
PRC - [2010.01.03 17:07:48 | 000,246,520 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2009.12.09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009.11.16 21:51:29 | 000,603,904 | ---- | M] (TuneUp Software) -- C:\WINDOWS\system32\TUProgSt.exe
PRC - [2009.09.24 06:50:10 | 003,520,256 | ---- | M] (Ghisler Software GmbH) -- C:\totalcmd\TOTALCMD.EXE
PRC - [2009.07.01 17:37:06 | 000,037,888 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
PRC - [2009.05.18 10:50:18 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009.05.18 10:50:18 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008.02.21 21:22:50 | 000,453,936 | ---- | M] (Seznam.cz a.s.) -- C:\Program Files\Seznam\Postak\Postak.exe
PRC - [2008.02.15 13:17:00 | 000,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe
PRC - [2008.02.15 13:16:18 | 002,278,648 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
PRC - [2007.06.27 17:04:00 | 001,213,736 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007.06.27 17:03:40 | 000,152,872 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2006.04.04 17:08:44 | 000,421,888 | ---- | M] () -- C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
PRC - [2006.03.27 10:37:58 | 000,045,056 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
PRC - [2005.03.02 12:21:58 | 000,278,528 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files\WinFast\WFTVFM\WFWIZ.exe


========== Modules (SafeList) ==========

MOD - [2010.03.22 16:54:39 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
MOD - [2008.04.14 04:21:45 | 001,028,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc42.dll
MOD - [2006.03.02 13:00:00 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc42loc.dll
MOD - [2005.10.11 12:18:54 | 000,028,672 | ---- | M] () -- C:\Acer\Empowering Technology\ePower\SysHook.dll


========== Win32 Services (SafeList) ==========

SRV - [2010.01.03 20:37:30 | 000,139,264 | ---- | M] (SOURCENEXT) [Auto | Running] -- C:\WINDOWS\System32\bgsvcgen.exe -- (bgsvcgen)
SRV - [2010.01.03 17:07:48 | 000,246,520 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.12.09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2009.11.16 21:51:29 | 000,603,904 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)
SRV - [2009.11.16 21:51:22 | 000,362,240 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\WINDOWS\system32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2008.11.12 16:44:18 | 000,027,904 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2008.07.29 18:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008.02.15 13:17:00 | 000,832,760 | ---- | M] (BinarySense, Inc.) [Auto | Running] -- C:\Program Files\Common Files\BinarySense\hldasvc.exe -- (HDDlife HDD Access service)


========== Driver Services (SafeList) ==========

DRV - [2010.01.03 20:37:30 | 000,038,944 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)
DRV - [2009.12.02 15:23:40 | 000,149,040 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2008.04.13 19:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) Ovladač zvukové karty USB (WDM)
DRV - [2008.04.13 17:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007.11.01 13:38:56 | 004,620,288 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.10.19 10:29:22 | 000,161,792 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2007.08.24 10:22:56 | 005,776,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2007.05.02 10:00:58 | 000,546,976 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2006.11.02 21:27:36 | 000,020,112 | ---- | M] (Dritek System Inc.) [Kernel | System | Running] -- C:\Program Files\Launch Manager\DPortIO.sys -- (DritekPortIO)
DRV - [2006.02.20 17:59:36 | 000,083,344 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810obex.sys -- (w810obex)
DRV - [2006.02.20 17:59:34 | 000,085,408 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mgmt.sys -- (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM)
DRV - [2006.02.20 17:59:33 | 000,094,064 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mdm.sys -- (w810mdm)
DRV - [2006.02.20 17:59:31 | 000,008,336 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mdfl.sys -- (w810mdfl)
DRV - [2006.02.20 17:59:27 | 000,058,288 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810bus.sys -- (w810bus) Sony Ericsson W810 Driver driver (WDM)
DRV - [2005.01.06 15:55:38 | 000,009,446 | ---- | M] (Leadtek Research Inc.) [Kernel | On_Demand | Running] -- C:\Program Files\WinFast\WFTVFM\WFIOCTL.sys -- (WFIOCTL)
DRV - [2004.12.08 14:10:00 | 000,016,896 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKbFltr.SYS -- (DKbFltr)
DRV - [2004.10.15 17:32:44 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg6n.sys -- (wg6n)
DRV - [2004.10.15 17:32:42 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg5n.sys -- (wg5n)
DRV - [2004.10.15 17:32:40 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg4n.sys -- (wg4n)
DRV - [2004.09.22 17:41:00 | 000,020,608 | ---- | M] (Empia Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emAudio.sys -- (emAudio)
DRV - [2004.09.22 09:42:00 | 000,079,563 | ---- | M] (eMPIA Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emFilter.sys -- (FiltUSBEMPIA)
DRV - [2004.09.21 14:52:00 | 000,110,653 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emDevice.sys -- (DCamUSBEMPIA)
DRV - [2004.09.21 14:52:00 | 000,004,857 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emScan.sys -- (ScanUSBEMPIA)
DRV - [2003.09.19 16:45:48 | 000,021,248 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2009.10.18 12:40:50 | 000,344,066 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 11796 more lines...
O3 - HKLM\..\Toolbar: (&S-Rank) - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll (Seznam.cz a.s.)
O3 - HKCU\..\Toolbar\WebBrowser: (&S-Rank) - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll (Seznam.cz a.s.)
O4 - HKLM..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe ()
O4 - HKLM..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe ()
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [SMail] C:\Program Files\Seznam\Postak\Postak.exe (Seznam.cz a.s.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe (Leadtek Research Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer Empowering Technology.lnk = C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe (Acer Inc.)
O4 - Startup: C:\Documents and Settings\Ondra\Nabídka Start\Programy\Po spuštění\HDDlife.lnk = C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe (BinarySense, Inc.)
O4 - Startup: C:\Documents and Settings\Ondra\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 5860782103 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.2
O18 - Protocol\Handler\hddlife {BD758015-47D9-477A-8873-4B688A2BC0E2} - C:\Program Files\Common Files\BinarySense\hlAPP.dll (BinarySense, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Ondra\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ondra\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.10.18 10:51:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010.03.22 16:54:26 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
[2010.03.22 15:52:19 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.03.22 15:52:18 | 000,000,000 | ---D | C] -- C:\rsit
[2010.03.22 15:52:04 | 000,000,000 | ---D | C] -- C:\Program Files\TrendMicro
[2010.03.19 15:51:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Dokumenty\Acoustica
[2010.03.19 15:51:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Data aplikací\Acoustica
[2010.03.18 18:08:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Plocha\Nepoužívané odkazy plochy
[2010.03.18 14:52:32 | 000,000,000 | ---D | C] -- C:\SAV32CLI
[2010.03.18 14:51:23 | 000,000,000 | ---D | C] -- C:\SDFix
[2010.03.18 14:48:58 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.03.18 13:48:18 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010.03.18 13:46:25 | 000,390,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF4003.exe
[2010.03.12 17:44:08 | 000,000,000 | ---D | C] -- C:\Program Files\eKucharka
[2010.03.11 09:29:14 | 003,558,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\moviemk.exe
[2010.02.25 18:18:10 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.02.25 18:17:29 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.02.25 18:17:29 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.02.25 18:17:28 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.02.25 18:17:28 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.02.25 18:16:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.02.25 18:16:14 | 000,390,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30059.exe
[2010.02.25 18:16:06 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.02.25 17:42:25 | 000,000,000 | ---D | C] -- C:\Program Files\AVI to VCD SVCD DVD Converter
[2010.02.25 17:40:19 | 000,000,000 | ---D | C] -- C:\ConverterOutput
[2010.02.25 17:40:04 | 000,000,000 | ---D | C] -- C:\Program Files\Cucusoft
[2010.02.22 10:00:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Dokumenty\ICQ
[2010.02.15 17:33:59 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2009.10.18 12:46:26 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\Interop.Shell32.dll
[2009.10.18 11:38:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.10.18 10:53:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2009.10.18 10:50:53 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.03.22 16:54:39 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
[2010.03.22 16:34:23 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.03.22 16:30:20 | 000,000,841 | ---- | M] () -- C:\Documents and Settings\Ondra\Nabídka Start\Programy\Po spuštění\HDDlife.lnk
[2010.03.22 16:30:02 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2010.03.22 16:29:07 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.03.22 16:29:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.03.22 16:29:03 | 1600,139,264 | -HS- | M] () -- C:\hiberfil.sys
[2010.03.22 16:28:22 | 006,815,744 | -H-- | M] () -- C:\Documents and Settings\Ondra\NTUSER.DAT
[2010.03.22 16:28:01 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Ondra\ntuser.ini
[2010.03.22 15:58:44 | 000,002,435 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\HiJackThis.lnk
[2010.03.22 15:51:34 | 001,401,344 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\HijackThis.msi
[2010.03.22 15:47:03 | 000,781,909 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\RSIT.exe
[2010.03.19 15:53:10 | 000,000,729 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Register Acoustica CD Label Maker.lnk
[2010.03.19 15:53:10 | 000,000,703 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Acoustica CD Label Maker.lnk
[2010.03.19 15:30:10 | 000,012,041 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Levoš.odt
[2010.03.18 13:53:39 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.03.18 13:46:56 | 003,894,152 | R--- | M] () -- C:\Documents and Settings\Ondra\Plocha\ComboFix.exe
[2010.03.18 13:46:10 | 000,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF4003.exe
[2010.03.15 20:21:04 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.03.12 18:02:38 | 000,261,632 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2010.03.12 17:48:16 | 000,000,640 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\eKuchařka.lnk
[2010.03.10 16:08:30 | 000,000,820 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Microsoft Security Essentials.lnk
[2010.03.07 19:17:49 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.03.02 19:03:59 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\Ondra\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.02.25 18:18:19 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.02.25 18:16:04 | 000,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30059.exe
[2010.02.25 17:42:29 | 000,000,755 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\AVI to VCD SVCD DVD Converter.lnk
[2010.02.25 17:40:09 | 000,000,805 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Cucusoft AVI to VCD DVD MPEG Creator Pro.lnk
[2010.02.24 10:16:06 | 000,181,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2010.02.24 09:36:51 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.02.22 21:01:08 | 000,000,375 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010.02.21 15:48:21 | 000,000,918 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\NET Radio Rekorder.lnk
[2010.02.21 15:48:21 | 000,000,113 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\REDSYSTEM.url
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.03.22 15:52:05 | 000,002,435 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\HiJackThis.lnk
[2010.03.22 15:51:31 | 001,401,344 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\HijackThis.msi
[2010.03.22 15:47:00 | 000,781,909 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\RSIT.exe
[2010.03.19 15:53:10 | 000,000,729 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Register Acoustica CD Label Maker.lnk
[2010.03.19 15:53:10 | 000,000,703 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Acoustica CD Label Maker.lnk
[2010.03.19 15:53:09 | 000,299,552 | ---- | C] () -- C:\WINDOWS\wmsysprx.prx
[2010.03.19 15:30:09 | 000,012,041 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Levoš.odt
[2010.03.18 13:46:48 | 003,894,152 | R--- | C] () -- C:\Documents and Settings\Ondra\Plocha\ComboFix.exe
[2010.03.12 17:44:12 | 000,000,640 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\eKuchařka.lnk
[2010.03.10 16:14:33 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.02.25 18:18:18 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.02.25 18:18:16 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.02.25 18:17:29 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.02.25 18:17:29 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.02.25 18:17:29 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.02.25 18:17:29 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.02.25 18:17:29 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.02.25 17:42:29 | 000,000,755 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\AVI to VCD SVCD DVD Converter.lnk
[2010.02.25 17:40:09 | 000,000,805 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Cucusoft AVI to VCD DVD MPEG Creator Pro.lnk
[2010.02.25 17:40:08 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2010.02.25 17:40:08 | 001,761,280 | ---- | C] () -- C:\WINDOWS\System32\ffdshow.ax
[2010.02.25 17:40:08 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2010.02.25 17:40:08 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010.02.25 17:40:08 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2010.02.25 17:40:07 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\ac3filter.ax
[2010.02.21 15:48:21 | 000,000,918 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\NET Radio Rekorder.lnk
[2010.02.21 15:48:21 | 000,000,113 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\REDSYSTEM.url
[2010.01.25 18:18:35 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\Ondra\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.12.27 14:31:32 | 000,001,014 | ---- | C] () -- C:\WINDOWS\ARCHPR.INI
[2009.12.27 14:20:07 | 000,000,183 | ---- | C] () -- C:\WINDOWS\aimpr.ini
[2009.11.12 16:48:38 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2009.11.10 18:13:37 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009.10.18 13:57:46 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009.10.18 13:57:45 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2009.10.18 13:57:44 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009.10.18 13:57:44 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009.10.18 13:57:43 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009.10.18 13:57:42 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009.10.18 13:57:42 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009.10.18 12:46:26 | 000,331,776 | ---- | C] () -- C:\WINDOWS\System32\ScrollBarLib.dll
[2009.10.18 10:58:46 | 001,174,000 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2009.10.18 10:58:46 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4864.dll
[2009.10.18 10:58:46 | 000,104,636 | ---- | C] () -- C:\WINDOWS\System32\igmedcompkrn.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:73F8B3C1
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2BE9FEFC
< End of report >

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 17:01
od Ondra100
OTL Extras logfile created on: 22.3.2010 16:55:03 - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Ondra\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 60,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 84,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 6,44 Gb Free Space | 32,98% Space Free | Partition Type: NTFS
Drive D: | 54,99 Gb Total Space | 15,76 Gb Free Space | 28,66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OND-F0A308A7C77
Current User Name: Ondra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\PROGRA~1\MICROS~2\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\PROGRA~1\MICROS~2\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\ICQ7.0\ICQ.exe" = C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7 -- (ICQ, Inc.)
"C:\Program Files\ICQ7.0\aolload.exe" = C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\Ondra\Data aplikací\Intelore\Office Password Recovery\OfficePasswordRecovery.exe" = C:\Documents and Settings\Ondra\Data aplikací\Intelore\Office Password Recovery\OfficePasswordRecovery.exe:*:Enabled:Office Password Recovery -- File not found
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Program Files\Formix SE\Formix.exe" = C:\Program Files\Formix SE\Formix.exe:*:Enabled:DATUM VERZE -- ()
"C:\Program Files\ICQ7.0\ICQ.exe" = C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7 -- (ICQ, Inc.)
"C:\Program Files\ICQ7.0\aolload.exe" = C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.5.3
"{23E797E9-F852-4AEA-93F0-772ED2B9D9F9}" = OpenOffice.org 3.1
"{305B9844-B05F-4AB6-AC50-48EEA1C30D4C}" = Passware Kit Standard Demo 9.5
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{43922202-9C8F-466B-8038-16AC60AAEED2}" = Multimedia Driver
"{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 pro Windows
"{546C143E-68DC-314D-97BC-1E454E3BA429}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY
"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{88EB38EF-4D2C-436D-ABD3-56B232674062}" = ICQ7
"{8B4E2214-DD65-40EC-AA27-E457AE1C405B}" = TMPGEnc Authoring Works 4 Trial Version
"{8D2C1E44-7685-4D05-8342-B0DC6422FA47}" = Ulead Straight-to-Disc SDK
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{95120000-00AF-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (Czech)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A9DBEBC-C800-4776-A970-D76D6AA405B1}" = PHOTOfunSTUDIO -viewer-
"{A2C9CD1B-2551-3AED-B244-6698FB929FA6}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
"{AC76BA86-7AD7-1029-7B44-A92000000001}" = Adobe Reader 9.2 - Czech
"{BD49141C-188C-4B75-9F46-C2C42F2D1029}" = Nero 7 Essentials
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3A13A35-63AC-427a-92E6-960C1D01FABB}" = Poradce pro upgrade na systém Windows 7
"{C5ADA65A-7828-4D85-B071-ECC52B51F794}" = Sony Ericsson PC Suite 1.20.173
"{C882DE6B-1482-42D6-A7C2-A9F946EDBAF6}" = WinFast PVR
"{CA9A3609-3ECC-4574-8824-A8161A71A603}" = Canon MP150
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DC67641A-05C4-4FED-A462-1EB1DC6CF2F5}" = ArcSoft Software Suite
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{E590FD1C-E8C6-4D2E-8CA9-77B403F7EE01}" = Microsoft Antimalware
"{E81D9FF6-B45F-4DD4-9673-86B08AF6F705}" = HDDlife Pro 3.1
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F70D5D8C-C1AF-40B3-9E47-3BB5F19EEA3A}" = Atheros for Acer Driver 5.3.0.45_Foxconn Installation Program
"123 Password Recovery" = 123 Password Recovery
"Acoustica CD/DVD Label Maker" = Acoustica CD/DVD Label Maker
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Asterisk Password Recovery_is1" = Asterisk Password Recovery 1.0
"Atomic ICQ Password Recovery_is1" = Atomic ICQ Password Recovery 1.10
"AVI to VCD SVCD DVD Converter_is1" = AVI to VCD SVCD DVD Converter 5.8
"Cucusoft MPEG/MOV/RM/DivX/AVI to DVD/VCD/SVCD Creator Pro_is1" = Cucusoft MPEG/MOV/RM/DivX/AVI to DVD/VCD/SVCD Creator Pro 7.07
"DVD Shrink_is1" = DVD Shrink 3.2
"eKuchařka_is1" = eKuchařka 2.3
"ffdshow_is1" = ffdshow [rev 3255] [2010-02-08]
"Formix SE_is1" = Formix SE - formuláře kanceláře
"Harry's Filters 3" = Harry's Filters 3
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"ICQ Password" = ICQ Password
"ICQToolbar" = ICQ Toolbar
"ie8" = Windows Internet Explorer 8
"jApploaderSE" = Softick jApploaderSE 1.00 (remove only)
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.1.6 (Full)
"LManager" = Launch Manager
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NET Rádio Rekordér" = NET Rádio Rekordér 3.6.9
"Paltalk Password Recovery_is1" = Paltalk Password Recovery 1.0
"SMail" = Seznam Pošťák
"SpotIM_is1" = SpotIM 1.8
"Totalcmd" = Total Commander (Remove or Repair)
"Visual Zip Password Recovery Processor" = Visual Zip Password Recovery Processor
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"Zip Password Recovery Master" = Zip Password Recovery Master
"Zoner Photo Studio 9_is1" = Zoner Photo Studio 9

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Intelore - Office Password Recovery" = Office Password Recovery v2.0 (remove only)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 25.2.2010 13:09:35 | Computer Name = OND-F0A308A7C77 | Source = Application Error | ID = 1000
Description = Chybující aplikace wmplayer.exe, verze 11.0.5721.5145, chybující modul
unknown, verze 0.0.0.0, adresa chyby 0x00000000.

Error - 25.2.2010 13:09:44 | Computer Name = OND-F0A308A7C77 | Source = Application Error | ID = 1000
Description = Chybující aplikace wmplayer.exe, verze 11.0.5721.5145, chybující modul
unknown, verze 0.0.0.0, adresa chyby 0x00000000.

Error - 25.2.2010 13:09:58 | Computer Name = OND-F0A308A7C77 | Source = Application Error | ID = 1000
Description = Chybující aplikace wmplayer.exe, verze 11.0.5721.5145, chybující modul
unknown, verze 0.0.0.0, adresa chyby 0x00000000.

Error - 25.2.2010 13:10:04 | Computer Name = OND-F0A308A7C77 | Source = Application Error | ID = 1000
Description = Chybující aplikace wmplayer.exe, verze 11.0.5721.5145, chybující modul
unknown, verze 0.0.0.0, adresa chyby 0x00000000.

Error - 25.2.2010 13:14:22 | Computer Name = OND-F0A308A7C77 | Source = Application Error | ID = 1000
Description = Chybující aplikace wmplayer.exe, verze 11.0.5721.5145, chybující modul
unknown, verze 0.0.0.0, adresa chyby 0x00000000.

Error - 25.2.2010 13:30:21 | Computer Name = OND-F0A308A7C77 | Source = Application Error | ID = 1000
Description = Chybující aplikace wmplayer.exe, verze 11.0.5721.5145, chybující modul
unknown, verze 0.0.0.0, adresa chyby 0x00000000.

Error - 25.2.2010 13:30:26 | Computer Name = OND-F0A308A7C77 | Source = Application Error | ID = 1001
Description = Chybný blok 341647977

Error - 25.2.2010 13:30:46 | Computer Name = OND-F0A308A7C77 | Source = Application Error | ID = 1000
Description = Chybující aplikace wmplayer.exe, verze 11.0.5721.5145, chybující modul
unknown, verze 0.0.0.0, adresa chyby 0x00000000.

Error - 10.3.2010 11:08:25 | Computer Name = OND-F0A308A7C77 | Source = MSSecurityEssentials | ID = 5000
Description =

[ System Events ]
Error - 9.3.2010 9:34:37 | Computer Name = OND-F0A308A7C77 | Source = BROWSER | ID = 8032
Description = Službě Browser se při přenosu \Device\NetBT_Tcpip_{14B94934-EEC6-4ED3-B394-4735E2D59BAA}
příliš často nezdařilo načíst záložní seznam. Záložní prohledávač bude ukončen.

Error - 9.3.2010 13:33:08 | Computer Name = OND-F0A308A7C77 | Source = BROWSER | ID = 8032
Description = Službě Browser se při přenosu \Device\NetBT_Tcpip_{14B94934-EEC6-4ED3-B394-4735E2D59BAA}
příliš často nezdařilo načíst záložní seznam. Záložní prohledávač bude ukončen.

Error - 11.3.2010 4:30:43 | Computer Name = OND-F0A308A7C77 | Source = BROWSER | ID = 8032
Description = Službě Browser se při přenosu \Device\NetBT_Tcpip_{14B94934-EEC6-4ED3-B394-4735E2D59BAA}
příliš často nezdařilo načíst záložní seznam. Záložní prohledávač bude ukončen.

Error - 11.3.2010 18:02:28 | Computer Name = OND-F0A308A7C77 | Source = System Error | ID = 1003
Description = Kód chyby 1000000a, parametr1 0000000c, parametr2 00000002, parametr3
00000000, parametr4 80505476.

Error - 20.3.2010 5:18:39 | Computer Name = OND-F0A308A7C77 | Source = Cdrom | ID = 262155
Description = Ovladač zjistil chybu řadiče na \Device\CdRom0.

Error - 20.3.2010 5:18:44 | Computer Name = OND-F0A308A7C77 | Source = Cdrom | ID = 262155
Description = Ovladač zjistil chybu řadiče na \Device\CdRom0.

Error - 20.3.2010 5:18:45 | Computer Name = OND-F0A308A7C77 | Source = Cdrom | ID = 262155
Description = Ovladač zjistil chybu řadiče na \Device\CdRom0.

Error - 20.3.2010 5:18:47 | Computer Name = OND-F0A308A7C77 | Source = Cdrom | ID = 262155
Description = Ovladač zjistil chybu řadiče na \Device\CdRom0.

Error - 20.3.2010 5:18:48 | Computer Name = OND-F0A308A7C77 | Source = Cdrom | ID = 262155
Description = Ovladač zjistil chybu řadiče na \Device\CdRom0.

Error - 20.3.2010 5:29:59 | Computer Name = OND-F0A308A7C77 | Source = Cdrom | ID = 262155
Description = Ovladač zjistil chybu řadiče na \Device\CdRom0.


< End of report >

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 17:15
od Caroprd111
Obrázek Spusťte OTL a do spodního okna vložte následující skript.

Kód: Vybrat vše

:OTL
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:73F8B3C1
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2BE9FEFC

:COMMANDS
[RESETHOSTS]
[Reboot]
Poté klikněte na Run fix, PC se restartuje, log vložte sem.

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 17:23
od Ondra100
Error: Unable to interpret <@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:73F8B3C1> in the current context!
Error: Unable to interpret <@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2BE9FEFC> in the current context!

OTL by OldTimer - Version 3.1.37.3 log created on 03222010_172329

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 17:27
od Caroprd111
Zopakujte celý postup ještě jednou.

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 17:34
od Ondra100
fix nul jsem to nekolikrát a pořád stejné. Error.

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 17:37
od Caroprd111
Kopírujete všechno z bílého rámečku :???:

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 17:49
od Ondra100
OTL logfile created on: 22.3.2010 17:45:33 - Run 2
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Ondra\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 63,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 6,44 Gb Free Space | 32,99% Space Free | Partition Type: NTFS
Drive D: | 54,99 Gb Total Space | 15,76 Gb Free Space | 28,66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OND-F0A308A7C77
Current User Name: Ondra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.03.22 16:54:39 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
PRC - [2010.03.18 18:05:29 | 000,212,992 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Documents and Settings\Ondra\Local Settings\temp\RtkBtMnt.exe
PRC - [2010.02.21 05:03:12 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010.01.03 20:37:30 | 000,139,264 | ---- | M] (SOURCENEXT) -- C:\WINDOWS\system32\bgsvcgen.exe
PRC - [2010.01.03 17:07:48 | 000,246,520 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2009.12.09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009.12.09 18:02:36 | 000,202,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
PRC - [2009.11.16 21:51:29 | 000,603,904 | ---- | M] (TuneUp Software) -- C:\WINDOWS\system32\TUProgSt.exe
PRC - [2009.07.01 17:37:06 | 000,037,888 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
PRC - [2009.05.18 10:50:18 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009.05.18 10:50:18 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008.02.21 21:22:50 | 000,453,936 | ---- | M] (Seznam.cz a.s.) -- C:\Program Files\Seznam\Postak\Postak.exe
PRC - [2008.02.15 13:17:00 | 000,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe
PRC - [2008.02.15 13:16:18 | 002,278,648 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
PRC - [2007.06.27 17:04:00 | 001,213,736 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007.06.27 17:03:40 | 000,152,872 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2006.04.04 17:08:44 | 000,421,888 | ---- | M] () -- C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
PRC - [2006.03.27 10:37:58 | 000,045,056 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
PRC - [2005.03.02 12:21:58 | 000,278,528 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files\WinFast\WFTVFM\WFWIZ.exe


========== Modules (SafeList) ==========

MOD - [2010.03.22 16:54:39 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
MOD - [2008.04.14 04:21:45 | 001,028,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc42.dll
MOD - [2006.03.02 13:00:00 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc42loc.dll
MOD - [2005.10.11 12:18:54 | 000,028,672 | ---- | M] () -- C:\Acer\Empowering Technology\ePower\SysHook.dll


========== Win32 Services (SafeList) ==========

SRV - [2010.01.03 20:37:30 | 000,139,264 | ---- | M] (SOURCENEXT) [Auto | Running] -- C:\WINDOWS\System32\bgsvcgen.exe -- (bgsvcgen)
SRV - [2010.01.03 17:07:48 | 000,246,520 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.12.09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2009.11.16 21:51:29 | 000,603,904 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)
SRV - [2009.11.16 21:51:22 | 000,362,240 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\WINDOWS\system32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2008.11.12 16:44:18 | 000,027,904 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2008.07.29 18:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008.02.15 13:17:00 | 000,832,760 | ---- | M] (BinarySense, Inc.) [Auto | Running] -- C:\Program Files\Common Files\BinarySense\hldasvc.exe -- (HDDlife HDD Access service)


========== Driver Services (SafeList) ==========

DRV - [2010.01.03 20:37:30 | 000,038,944 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)
DRV - [2009.12.02 15:23:40 | 000,149,040 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2008.04.13 19:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) Ovladač zvukové karty USB (WDM)
DRV - [2008.04.13 17:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007.11.01 13:38:56 | 004,620,288 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.10.19 10:29:22 | 000,161,792 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2007.08.24 10:22:56 | 005,776,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2007.05.02 10:00:58 | 000,546,976 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2006.11.02 21:27:36 | 000,020,112 | ---- | M] (Dritek System Inc.) [Kernel | System | Running] -- C:\Program Files\Launch Manager\DPortIO.sys -- (DritekPortIO)
DRV - [2006.02.20 17:59:36 | 000,083,344 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810obex.sys -- (w810obex)
DRV - [2006.02.20 17:59:34 | 000,085,408 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mgmt.sys -- (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM)
DRV - [2006.02.20 17:59:33 | 000,094,064 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mdm.sys -- (w810mdm)
DRV - [2006.02.20 17:59:31 | 000,008,336 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mdfl.sys -- (w810mdfl)
DRV - [2006.02.20 17:59:27 | 000,058,288 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810bus.sys -- (w810bus) Sony Ericsson W810 Driver driver (WDM)
DRV - [2005.01.06 15:55:38 | 000,009,446 | ---- | M] (Leadtek Research Inc.) [Kernel | On_Demand | Running] -- C:\Program Files\WinFast\WFTVFM\WFIOCTL.sys -- (WFIOCTL)
DRV - [2004.12.08 14:10:00 | 000,016,896 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKbFltr.SYS -- (DKbFltr)
DRV - [2004.10.15 17:32:44 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg6n.sys -- (wg6n)
DRV - [2004.10.15 17:32:42 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg5n.sys -- (wg5n)
DRV - [2004.10.15 17:32:40 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg4n.sys -- (wg4n)
DRV - [2004.09.22 17:41:00 | 000,020,608 | ---- | M] (Empia Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emAudio.sys -- (emAudio)
DRV - [2004.09.22 09:42:00 | 000,079,563 | ---- | M] (eMPIA Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emFilter.sys -- (FiltUSBEMPIA)
DRV - [2004.09.21 14:52:00 | 000,110,653 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emDevice.sys -- (DCamUSBEMPIA)
DRV - [2004.09.21 14:52:00 | 000,004,857 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emScan.sys -- (ScanUSBEMPIA)
DRV - [2003.09.19 16:45:48 | 000,021,248 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2010.03.22 17:42:08 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O3 - HKLM\..\Toolbar: (&S-Rank) - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll (Seznam.cz a.s.)
O3 - HKCU\..\Toolbar\WebBrowser: (&S-Rank) - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll (Seznam.cz a.s.)
O4 - HKLM..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe ()
O4 - HKLM..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe ()
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [SMail] C:\Program Files\Seznam\Postak\Postak.exe (Seznam.cz a.s.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe (Leadtek Research Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer Empowering Technology.lnk = C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe (Acer Inc.)
O4 - Startup: C:\Documents and Settings\Ondra\Nabídka Start\Programy\Po spuštění\HDDlife.lnk = C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe (BinarySense, Inc.)
O4 - Startup: C:\Documents and Settings\Ondra\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 5860782103 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.2
O18 - Protocol\Handler\hddlife {BD758015-47D9-477A-8873-4B688A2BC0E2} - C:\Program Files\Common Files\BinarySense\hlAPP.dll (BinarySense, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Ondra\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ondra\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.10.18 10:51:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010.03.22 17:17:11 | 000,000,000 | ---D | C] -- C:\_OTL
[2010.03.22 16:54:26 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
[2010.03.22 15:52:19 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.03.22 15:52:18 | 000,000,000 | ---D | C] -- C:\rsit
[2010.03.22 15:52:04 | 000,000,000 | ---D | C] -- C:\Program Files\TrendMicro
[2010.03.19 15:51:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Dokumenty\Acoustica
[2010.03.19 15:51:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Data aplikací\Acoustica
[2010.03.18 18:08:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Plocha\Nepoužívané odkazy plochy
[2010.03.18 14:52:32 | 000,000,000 | ---D | C] -- C:\SAV32CLI
[2010.03.18 14:51:23 | 000,000,000 | ---D | C] -- C:\SDFix
[2010.03.18 14:48:58 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.03.18 13:48:18 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010.03.18 13:46:25 | 000,390,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF4003.exe
[2010.03.12 17:44:08 | 000,000,000 | ---D | C] -- C:\Program Files\eKucharka
[2010.03.11 09:29:14 | 003,558,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\moviemk.exe
[2010.02.25 18:18:10 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.02.25 18:17:29 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.02.25 18:17:29 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.02.25 18:17:28 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.02.25 18:17:28 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.02.25 18:16:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.02.25 18:16:14 | 000,390,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30059.exe
[2010.02.25 18:16:06 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.02.25 17:42:25 | 000,000,000 | ---D | C] -- C:\Program Files\AVI to VCD SVCD DVD Converter
[2010.02.25 17:40:19 | 000,000,000 | ---D | C] -- C:\ConverterOutput
[2010.02.25 17:40:04 | 000,000,000 | ---D | C] -- C:\Program Files\Cucusoft
[2010.02.22 10:00:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Dokumenty\ICQ
[2010.02.15 17:33:59 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2009.10.18 12:46:26 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\Interop.Shell32.dll
[2009.10.18 11:38:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.10.18 10:53:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2009.10.18 10:50:53 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.03.22 17:48:27 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.03.22 17:44:20 | 000,000,841 | ---- | M] () -- C:\Documents and Settings\Ondra\Nabídka Start\Programy\Po spuštění\HDDlife.lnk
[2010.03.22 17:44:02 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2010.03.22 17:43:11 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.03.22 17:43:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.03.22 17:43:07 | 1600,139,264 | -HS- | M] () -- C:\hiberfil.sys
[2010.03.22 17:42:27 | 006,815,744 | -H-- | M] () -- C:\Documents and Settings\Ondra\NTUSER.DAT
[2010.03.22 17:42:21 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Ondra\ntuser.ini
[2010.03.22 17:42:08 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2010.03.22 16:54:39 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
[2010.03.22 15:58:44 | 000,002,435 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\HiJackThis.lnk
[2010.03.22 15:51:34 | 001,401,344 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\HijackThis.msi
[2010.03.22 15:47:03 | 000,781,909 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\RSIT.exe
[2010.03.19 15:53:10 | 000,000,729 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Register Acoustica CD Label Maker.lnk
[2010.03.19 15:53:10 | 000,000,703 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Acoustica CD Label Maker.lnk
[2010.03.19 15:30:10 | 000,012,041 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Levoš.odt
[2010.03.18 13:53:39 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.03.18 13:46:56 | 003,894,152 | R--- | M] () -- C:\Documents and Settings\Ondra\Plocha\ComboFix.exe
[2010.03.18 13:46:10 | 000,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF4003.exe
[2010.03.15 20:21:04 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.03.12 18:02:38 | 000,261,632 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2010.03.12 17:48:16 | 000,000,640 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\eKuchařka.lnk
[2010.03.10 16:08:30 | 000,000,820 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Microsoft Security Essentials.lnk
[2010.03.07 19:17:49 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.03.02 19:03:59 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\Ondra\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.02.25 18:18:19 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.02.25 18:16:04 | 000,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30059.exe
[2010.02.25 17:42:29 | 000,000,755 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\AVI to VCD SVCD DVD Converter.lnk
[2010.02.25 17:40:09 | 000,000,805 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Cucusoft AVI to VCD DVD MPEG Creator Pro.lnk
[2010.02.24 10:16:06 | 000,181,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2010.02.24 09:36:51 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.02.22 21:01:08 | 000,000,375 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010.02.21 15:48:21 | 000,000,918 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\NET Radio Rekorder.lnk
[2010.02.21 15:48:21 | 000,000,113 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\REDSYSTEM.url
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.03.22 15:52:05 | 000,002,435 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\HiJackThis.lnk
[2010.03.22 15:51:31 | 001,401,344 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\HijackThis.msi
[2010.03.22 15:47:00 | 000,781,909 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\RSIT.exe
[2010.03.19 15:53:10 | 000,000,729 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Register Acoustica CD Label Maker.lnk
[2010.03.19 15:53:10 | 000,000,703 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Acoustica CD Label Maker.lnk
[2010.03.19 15:53:09 | 000,299,552 | ---- | C] () -- C:\WINDOWS\wmsysprx.prx
[2010.03.19 15:30:09 | 000,012,041 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Levoš.odt
[2010.03.18 13:46:48 | 003,894,152 | R--- | C] () -- C:\Documents and Settings\Ondra\Plocha\ComboFix.exe
[2010.03.12 17:44:12 | 000,000,640 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\eKuchařka.lnk
[2010.03.10 16:14:33 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.02.25 18:18:18 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.02.25 18:18:16 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.02.25 18:17:29 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.02.25 18:17:29 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.02.25 18:17:29 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.02.25 18:17:29 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.02.25 18:17:29 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.02.25 17:42:29 | 000,000,755 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\AVI to VCD SVCD DVD Converter.lnk
[2010.02.25 17:40:09 | 000,000,805 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Cucusoft AVI to VCD DVD MPEG Creator Pro.lnk
[2010.02.25 17:40:08 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2010.02.25 17:40:08 | 001,761,280 | ---- | C] () -- C:\WINDOWS\System32\ffdshow.ax
[2010.02.25 17:40:08 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2010.02.25 17:40:08 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010.02.25 17:40:08 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2010.02.25 17:40:07 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\ac3filter.ax
[2010.02.21 15:48:21 | 000,000,918 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\NET Radio Rekorder.lnk
[2010.02.21 15:48:21 | 000,000,113 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\REDSYSTEM.url
[2010.01.25 18:18:35 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\Ondra\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.12.27 14:31:32 | 000,001,014 | ---- | C] () -- C:\WINDOWS\ARCHPR.INI
[2009.12.27 14:20:07 | 000,000,183 | ---- | C] () -- C:\WINDOWS\aimpr.ini
[2009.11.12 16:48:38 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2009.11.10 18:13:37 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009.10.18 13:57:46 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009.10.18 13:57:45 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2009.10.18 13:57:44 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009.10.18 13:57:44 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009.10.18 13:57:43 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009.10.18 13:57:42 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009.10.18 13:57:42 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009.10.18 12:46:26 | 000,331,776 | ---- | C] () -- C:\WINDOWS\System32\ScrollBarLib.dll
[2009.10.18 10:58:46 | 001,174,000 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2009.10.18 10:58:46 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4864.dll
[2009.10.18 10:58:46 | 000,104,636 | ---- | C] () -- C:\WINDOWS\System32\igmedcompkrn.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2BE9FEFC
< End of report >

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 22 bře 2010 18:41
od Caroprd111
Obrázek V nouzovém režimu spusťte OTL a do spodního okna vložte následující skript.

Kód: Vybrat vše

:OTL
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:73F8B3C1
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2BE9FEFC

:COMMANDS
[RESETHOSTS]
[Reboot]
Poté klikněte na Run fix, PC se restartuje, log vložte sem.

Re: Pomalé pc a nemužu zadat rozlišení monitoru

Napsal: 23 bře 2010 13:54
od Ondra100
OTL logfile created on: 23.3.2010 13:50:05 - Run 3
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Ondra\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 62,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 86,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 6,44 Gb Free Space | 32,95% Space Free | Partition Type: NTFS
Drive D: | 54,99 Gb Total Space | 15,76 Gb Free Space | 28,66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OND-F0A308A7C77
Current User Name: Ondra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.03.22 16:54:39 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
PRC - [2010.03.18 18:05:29 | 000,212,992 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Documents and Settings\Ondra\Local Settings\temp\RtkBtMnt.exe
PRC - [2010.02.21 05:03:12 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010.01.03 20:37:30 | 000,139,264 | ---- | M] (SOURCENEXT) -- C:\WINDOWS\system32\bgsvcgen.exe
PRC - [2010.01.03 17:07:48 | 000,246,520 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2009.12.09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009.12.09 18:02:36 | 000,202,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
PRC - [2009.11.16 21:51:29 | 000,603,904 | ---- | M] (TuneUp Software) -- C:\WINDOWS\system32\TUProgSt.exe
PRC - [2009.07.01 17:37:06 | 000,037,888 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
PRC - [2009.05.18 10:50:18 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009.05.18 10:50:18 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008.02.21 21:22:50 | 000,453,936 | ---- | M] (Seznam.cz a.s.) -- C:\Program Files\Seznam\Postak\Postak.exe
PRC - [2008.02.15 13:17:00 | 000,832,760 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\Common Files\BinarySense\hldasvc.exe
PRC - [2008.02.15 13:16:18 | 002,278,648 | ---- | M] (BinarySense, Inc.) -- C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
PRC - [2007.06.27 17:04:00 | 001,213,736 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007.06.27 17:03:40 | 000,152,872 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2006.04.04 17:08:44 | 000,421,888 | ---- | M] () -- C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
PRC - [2006.03.27 10:37:58 | 000,045,056 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
PRC - [2005.03.02 12:21:58 | 000,278,528 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files\WinFast\WFTVFM\WFWIZ.exe


========== Modules (SafeList) ==========

MOD - [2010.03.22 16:54:39 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
MOD - [2008.04.14 04:21:45 | 001,028,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc42.dll
MOD - [2006.03.02 13:00:00 | 000,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc42loc.dll
MOD - [2005.10.11 12:18:54 | 000,028,672 | ---- | M] () -- C:\Acer\Empowering Technology\ePower\SysHook.dll


========== Win32 Services (SafeList) ==========

SRV - [2010.01.03 20:37:30 | 000,139,264 | ---- | M] (SOURCENEXT) [Auto | Running] -- C:\WINDOWS\System32\bgsvcgen.exe -- (bgsvcgen)
SRV - [2010.01.03 17:07:48 | 000,246,520 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.12.09 18:02:38 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2009.11.16 21:51:29 | 000,603,904 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)
SRV - [2009.11.16 21:51:22 | 000,362,240 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\WINDOWS\system32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2008.11.12 16:44:18 | 000,027,904 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2008.07.29 18:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008.02.15 13:17:00 | 000,832,760 | ---- | M] (BinarySense, Inc.) [Auto | Running] -- C:\Program Files\Common Files\BinarySense\hldasvc.exe -- (HDDlife HDD Access service)


========== Driver Services (SafeList) ==========

DRV - [2010.01.03 20:37:30 | 000,038,944 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)
DRV - [2009.12.02 15:23:40 | 000,149,040 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2008.04.13 19:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) Ovladač zvukové karty USB (WDM)
DRV - [2008.04.13 17:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007.11.01 13:38:56 | 004,620,288 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.10.19 10:29:22 | 000,161,792 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2007.08.24 10:22:56 | 005,776,928 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2007.05.02 10:00:58 | 000,546,976 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2006.11.02 21:27:36 | 000,020,112 | ---- | M] (Dritek System Inc.) [Kernel | System | Running] -- C:\Program Files\Launch Manager\DPortIO.sys -- (DritekPortIO)
DRV - [2006.02.20 17:59:36 | 000,083,344 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810obex.sys -- (w810obex)
DRV - [2006.02.20 17:59:34 | 000,085,408 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mgmt.sys -- (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM)
DRV - [2006.02.20 17:59:33 | 000,094,064 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mdm.sys -- (w810mdm)
DRV - [2006.02.20 17:59:31 | 000,008,336 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mdfl.sys -- (w810mdfl)
DRV - [2006.02.20 17:59:27 | 000,058,288 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810bus.sys -- (w810bus) Sony Ericsson W810 Driver driver (WDM)
DRV - [2005.01.06 15:55:38 | 000,009,446 | ---- | M] (Leadtek Research Inc.) [Kernel | On_Demand | Running] -- C:\Program Files\WinFast\WFTVFM\WFIOCTL.sys -- (WFIOCTL)
DRV - [2004.12.08 14:10:00 | 000,016,896 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKbFltr.SYS -- (DKbFltr)
DRV - [2004.10.15 17:32:44 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg6n.sys -- (wg6n)
DRV - [2004.10.15 17:32:42 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg5n.sys -- (wg5n)
DRV - [2004.10.15 17:32:40 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg4n.sys -- (wg4n)
DRV - [2004.09.22 17:41:00 | 000,020,608 | ---- | M] (Empia Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emAudio.sys -- (emAudio)
DRV - [2004.09.22 09:42:00 | 000,079,563 | ---- | M] (eMPIA Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emFilter.sys -- (FiltUSBEMPIA)
DRV - [2004.09.21 14:52:00 | 000,110,653 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emDevice.sys -- (DCamUSBEMPIA)
DRV - [2004.09.21 14:52:00 | 000,004,857 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emScan.sys -- (ScanUSBEMPIA)
DRV - [2003.09.19 16:45:48 | 000,021,248 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2010.03.23 09:35:53 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O3 - HKLM\..\Toolbar: (&S-Rank) - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll (Seznam.cz a.s.)
O3 - HKCU\..\Toolbar\WebBrowser: (&S-Rank) - {B71B15CF-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Postak\SRank.dll (Seznam.cz a.s.)
O4 - HKLM..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe ()
O4 - HKLM..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe ()
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [SMail] C:\Program Files\Seznam\Postak\Postak.exe (Seznam.cz a.s.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe (Leadtek Research Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer Empowering Technology.lnk = C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe (Acer Inc.)
O4 - Startup: C:\Documents and Settings\Ondra\Nabídka Start\Programy\Po spuštění\HDDlife.lnk = C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe (BinarySense, Inc.)
O4 - Startup: C:\Documents and Settings\Ondra\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 5860782103 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.2
O18 - Protocol\Handler\hddlife {BD758015-47D9-477A-8873-4B688A2BC0E2} - C:\Program Files\Common Files\BinarySense\hlAPP.dll (BinarySense, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Ondra\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ondra\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.10.18 10:51:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010.03.22 17:17:11 | 000,000,000 | ---D | C] -- C:\_OTL
[2010.03.22 16:54:26 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
[2010.03.22 15:52:19 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.03.22 15:52:18 | 000,000,000 | ---D | C] -- C:\rsit
[2010.03.22 15:52:04 | 000,000,000 | ---D | C] -- C:\Program Files\TrendMicro
[2010.03.19 15:51:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Dokumenty\Acoustica
[2010.03.19 15:51:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Data aplikací\Acoustica
[2010.03.18 18:08:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Plocha\Nepoužívané odkazy plochy
[2010.03.18 14:52:32 | 000,000,000 | ---D | C] -- C:\SAV32CLI
[2010.03.18 14:51:23 | 000,000,000 | ---D | C] -- C:\SDFix
[2010.03.18 14:48:58 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.03.18 13:48:18 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010.03.18 13:46:25 | 000,390,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF4003.exe
[2010.03.12 17:44:08 | 000,000,000 | ---D | C] -- C:\Program Files\eKucharka
[2010.03.11 09:29:14 | 003,558,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\moviemk.exe
[2010.02.25 18:18:10 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.02.25 18:17:29 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.02.25 18:17:29 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.02.25 18:17:28 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.02.25 18:17:28 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.02.25 18:16:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.02.25 18:16:14 | 000,390,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30059.exe
[2010.02.25 18:16:06 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.02.25 17:42:25 | 000,000,000 | ---D | C] -- C:\Program Files\AVI to VCD SVCD DVD Converter
[2010.02.25 17:40:19 | 000,000,000 | ---D | C] -- C:\ConverterOutput
[2010.02.25 17:40:04 | 000,000,000 | ---D | C] -- C:\Program Files\Cucusoft
[2010.02.22 10:00:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ondra\Dokumenty\ICQ
[2010.02.15 17:33:59 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2009.10.18 12:46:26 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\Interop.Shell32.dll
[2009.10.18 11:38:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.10.18 10:53:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2009.10.18 10:50:53 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.03.23 13:49:10 | 000,000,841 | ---- | M] () -- C:\Documents and Settings\Ondra\Nabídka Start\Programy\Po spuštění\HDDlife.lnk
[2010.03.23 13:48:52 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2010.03.23 13:47:57 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.03.23 13:47:54 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.03.23 13:47:53 | 1600,139,264 | -HS- | M] () -- C:\hiberfil.sys
[2010.03.23 09:36:18 | 006,815,744 | -H-- | M] () -- C:\Documents and Settings\Ondra\NTUSER.DAT
[2010.03.23 09:36:10 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Ondra\ntuser.ini
[2010.03.23 09:35:53 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2010.03.23 09:03:11 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.03.22 16:54:39 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ondra\Plocha\OTL.exe
[2010.03.22 15:58:44 | 000,002,435 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\HiJackThis.lnk
[2010.03.22 15:51:34 | 001,401,344 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\HijackThis.msi
[2010.03.22 15:47:03 | 000,781,909 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\RSIT.exe
[2010.03.19 15:53:10 | 000,000,729 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Register Acoustica CD Label Maker.lnk
[2010.03.19 15:53:10 | 000,000,703 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Acoustica CD Label Maker.lnk
[2010.03.19 15:30:10 | 000,012,041 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Levoš.odt
[2010.03.18 13:53:39 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.03.18 13:46:56 | 003,894,152 | R--- | M] () -- C:\Documents and Settings\Ondra\Plocha\ComboFix.exe
[2010.03.18 13:46:10 | 000,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF4003.exe
[2010.03.15 20:21:04 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.03.12 18:02:38 | 000,261,632 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2010.03.12 17:48:16 | 000,000,640 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\eKuchařka.lnk
[2010.03.10 16:08:30 | 000,000,820 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Microsoft Security Essentials.lnk
[2010.03.07 19:17:49 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.03.02 19:03:59 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\Ondra\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.02.25 18:18:19 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.02.25 18:16:04 | 000,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF30059.exe
[2010.02.25 17:42:29 | 000,000,755 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\AVI to VCD SVCD DVD Converter.lnk
[2010.02.25 17:40:09 | 000,000,805 | ---- | M] () -- C:\Documents and Settings\Ondra\Plocha\Cucusoft AVI to VCD DVD MPEG Creator Pro.lnk
[2010.02.24 10:16:06 | 000,181,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2010.02.24 09:36:51 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.02.22 21:01:08 | 000,000,375 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010.02.21 15:48:21 | 000,000,918 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\NET Radio Rekorder.lnk
[2010.02.21 15:48:21 | 000,000,113 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\REDSYSTEM.url
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.03.22 15:52:05 | 000,002,435 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\HiJackThis.lnk
[2010.03.22 15:51:31 | 001,401,344 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\HijackThis.msi
[2010.03.22 15:47:00 | 000,781,909 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\RSIT.exe
[2010.03.19 15:53:10 | 000,000,729 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Register Acoustica CD Label Maker.lnk
[2010.03.19 15:53:10 | 000,000,703 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Acoustica CD Label Maker.lnk
[2010.03.19 15:53:09 | 000,299,552 | ---- | C] () -- C:\WINDOWS\wmsysprx.prx
[2010.03.19 15:30:09 | 000,012,041 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Levoš.odt
[2010.03.18 13:46:48 | 003,894,152 | R--- | C] () -- C:\Documents and Settings\Ondra\Plocha\ComboFix.exe
[2010.03.12 17:44:12 | 000,000,640 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\eKuchařka.lnk
[2010.03.10 16:14:33 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.02.25 18:18:18 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.02.25 18:18:16 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.02.25 18:17:29 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.02.25 18:17:29 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.02.25 18:17:29 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.02.25 18:17:29 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.02.25 18:17:29 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.02.25 17:42:29 | 000,000,755 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\AVI to VCD SVCD DVD Converter.lnk
[2010.02.25 17:40:09 | 000,000,805 | ---- | C] () -- C:\Documents and Settings\Ondra\Plocha\Cucusoft AVI to VCD DVD MPEG Creator Pro.lnk
[2010.02.25 17:40:08 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2010.02.25 17:40:08 | 001,761,280 | ---- | C] () -- C:\WINDOWS\System32\ffdshow.ax
[2010.02.25 17:40:08 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2010.02.25 17:40:08 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010.02.25 17:40:08 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2010.02.25 17:40:07 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\ac3filter.ax
[2010.02.21 15:48:21 | 000,000,918 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\NET Radio Rekorder.lnk
[2010.02.21 15:48:21 | 000,000,113 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\REDSYSTEM.url
[2010.01.25 18:18:35 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\Ondra\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.12.27 14:31:32 | 000,001,014 | ---- | C] () -- C:\WINDOWS\ARCHPR.INI
[2009.12.27 14:20:07 | 000,000,183 | ---- | C] () -- C:\WINDOWS\aimpr.ini
[2009.11.12 16:48:38 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2009.11.10 18:13:37 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009.10.18 13:57:46 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009.10.18 13:57:45 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2009.10.18 13:57:44 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009.10.18 13:57:44 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009.10.18 13:57:43 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009.10.18 13:57:42 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009.10.18 13:57:42 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009.10.18 12:46:26 | 000,331,776 | ---- | C] () -- C:\WINDOWS\System32\ScrollBarLib.dll
[2009.10.18 10:58:46 | 001,174,000 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2009.10.18 10:58:46 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4864.dll
[2009.10.18 10:58:46 | 000,104,636 | ---- | C] () -- C:\WINDOWS\System32\igmedcompkrn.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2BE9FEFC
< End of report >