Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomalý PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Pomalý PC

#16 Příspěvek od Márty84 »

:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe , ulozte na plochu a spustte.
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

radeeek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 29 črc 2007 18:43
Kontaktovat uživatele:

Re: Pomalý PC

#17 Příspěvek od radeeek »

první log Extras:

OTL Extras logfile created on: 26.8.2012 20:53:16 - Run 1

OTL by OldTimer - Version 3.2.59.1 Folder = C:\Documents and Settings\User1\Plocha

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy



511,48 Mb Total Physical Memory | 177,65 Mb Available Physical Memory | 34,73% Memory free

1,22 Gb Paging File | 0,73 Gb Available in Paging File | 59,93% Paging File free

Paging file location(s): C:\pagefile.sys 768 1536 [binary data]



%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 74,52 Gb Total Space | 6,29 Gb Free Space | 8,43% Space Free | Partition Type: NTFS



Computer Name: PC | User Name: User1 | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days



========== Extra Registry (SafeList) ==========





========== File Associations ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l



[HKEY_USERS\S-1-5-21-1409082233-602162358-725345543-1004\SOFTWARE\Classes\<extension>]

.html [@ = ChromeHTML] -- Reg Error: Key error. File not found



========== Shell Spawning ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

htmlfile [edit] -- Reg Error: Key error.

https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)

InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [JpegResamplerDir] -- "C:\Program Files\JPEG Resampler\JpegResampler.exe" "%1"

Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)

Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)

Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)



========== Security Center Settings ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]



========== System Restore Settings ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2



========== Firewall Settings ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]



[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]



[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"EnableFirewall" = 1



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DisableNotifications" = 0

"DoNotAllowExceptions" = 0



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

"5985:TCP" = 5985:TCP:*:Disabled:Vzdálená správa systému Windows



========== Authorized Applications List ==========



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"C:\Program Files\ICQ7.6\ICQ.exe" = C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6 -- (ICQ, LLC.)



[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\totalcmd\TOTALCMD.EXE" = C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows -- (C. Ghisler & Co.)

"C:\Program Files\TeamViewer\Version4\TeamViewer.exe" = C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application -- (TeamViewer GmbH)

"C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\age2_x1.exe" = C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\age2_x1.exe:*:Disabled:Age of Empires II Expansion -- (Microsoft Corporation)

"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)

"C:\Program Files\Google\Chrome\Application\chrome.exe" = C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome -- (Google Inc.)

"C:\Program Files\ICQ7.6\ICQ.exe" = C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6 -- (ICQ, LLC.)

"C:\Program Files\Winamp\winamp.exe" = C:\Program Files\Winamp\winamp.exe:*:Disabled:Winamp -- (Nullsoft, Inc.)





========== HKEY_LOCAL_MACHINE Uninstall List ==========



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser

"{083F79E4-6FE9-46FB-A6C6-4F8862742947}" = ATI HYDRAVISION

"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS

"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Multimedia Launcher

"{26A24AE4-039D-4CA4-87B4-2F83216018F0}" = Java(TM) 6 Update 18

"{26A24AE4-039D-4CA4-87B4-2F83216024F0}" = Java(TM) 6 Update 24

"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 33

"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java(TM) 7 Update 5

"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{4442AB48-DEC4-4B39-B067-1F75BF8017E7}" = Creative Centrale

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{5E65E94D-69F2-4850-9E93-6459C53A0F50}" = Microsoft .NET Framework 1.1 Czech Language Pack

"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin

"{7644E42D-B096-457F-8B5B-901238FC81AE}" = ICQ7.6

"{805A7890-3138-44E4-8DAA-480C55516989}" = MainConcept MJPEG Codec Demo

"{86604C06-DA30-425E-AECE-47304FE81C45}" = Creative Software Update

"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

"{86EC42B5-346E-4BAB-948D-58E021EA4BD1}" = ATI Catalyst Control Center

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{90120000-0010-0405-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Czech) 12

"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007

"{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007

"{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007

"{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007

"{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007

"{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007

"{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007

"{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{0B7A4B67-2A38-42B1-9857-662FAB361E08}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007

"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007

"{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{FDF9A959-241A-4662-A8DE-7DED9C22D160}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system

"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007

"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007

"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007

"{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007

"{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{A0AAD4D5-9F9C-49BB-AB64-0FD4695424E8}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007

"{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007

"{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)

"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In

"{91D77E9E-A69B-4B7A-9E8B-22861AAEBF5C}" = OpenOffice.org 2.1

"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer

"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{ABFE9B50-BA4B-4FDF-A943-EA025119DBED}" = Age of Empires III - The WarChiefs Trial

"{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master

"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2

"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2

"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = Trust webcam

"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio

"0AAD16715A341564716CE9901E2911A02B1EB808" = BalíĊek ovladaĊe systému Windows - AnyDATA Corporated (adusbser) Modem (09/21/2006 2.0.3.2)

"5C49EB77B7315FA2E925C43BA449BB322C4D9418" = BalíĊek ovladaĊe systému Windows - AnyDATA Corporation (adusbser) Ports (09/21/2006 2.0.3.2)

"7-Zip" = 7-Zip 4.65

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

"Age of Empires 2.0" = Microsoft Age of Empires II

"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion

"All ATI Software" = Softarová utilita ATI - Odinstalovat

"ATI Display Driver" = ATI Display Driver

"avast" = avast! Free Antivirus

"A-WIN-Extras 8.0.4 2615434_is1" = Mathematica Extras 8.0 (2615434)

"BSPlayerf" = BS.Player FREE

"CCleaner" = CCleaner

"Creative Centrale" = Creative Centrale

"CrystalDiskInfo_is1" = CrystalDiskInfo 5.0.0

"DAEMON Tools Toolbar" = DAEMON Tools Toolbar

"Defraggler" = Defraggler

"DesetiPrsty5" = DesetiPrsty5 5.3

"ENTERPRISE" = Microsoft Office Enterprise 2007

"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1

"Google Chrome" = Google Chrome

"HijackThis" = HijackThis 1.99.1

"ie8" = Windows Internet Explorer 8

"InCD!UninstallKey" = InCD

"InstallShield_{805A7890-3138-44E4-8DAA-480C55516989}" = MainConcept MJPEG Codec Demo

"InstallShield_{ABFE9B50-BA4B-4FDF-A943-EA025119DBED}" = Age of Empires III - The WarChiefs Trial

"InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master

"MCMJPG" = MainConcept MJPG software codec (Remove Only)

"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"Mozilla Firefox 14.0.1 (x86 cs)" = Mozilla Firefox 14.0.1 (x86 cs)

"MozillaMaintenanceService" = Mozilla Maintenance Service

"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP

"Nero - Burning Rom!UninstallKey" = Nero OEM

"NVIDIA Drivers" = NVIDIA Drivers

"Quake 3 Arena Demo" = Quake 3 Arena Demo

"QuickTime" = QuickTime

"Šifrování_is1" = Šifrování 0.4

"TeamViewer 4" = TeamViewer 4

"Totalcmd" = Total Commander (Remove or Repair)

"Winamp" = Winamp

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"Windows Media Player" = Windows Media Player 11

"Windows XP Service Pack" = Windows XP Service Pack 3

"WMFDist11" = Windows Media Format 11 runtime

"wmp11" = Windows Media Player 11

"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

"XP Codec Pack" = XP Codec Pack

"ZENMozaicEZUG" = Documentation Creative ZEN Mozaic EZ Series



========== HKEY_USERS Uninstall List ==========



[HKEY_USERS\S-1-5-21-1409082233-602162358-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Winamp Detect" = Winamp Detector Plug-in



========== Last 20 Event Log Errors ==========



[ Application Events ]

Error - 31.5.2012 16:24:28 | Computer Name = PC | Source = Application Hang | ID = 1002

Description = Zablokovaná aplikace explorer.exe, verze 6.0.2900.5512, zablokovaný

modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.



Error - 31.5.2012 16:27:41 | Computer Name = PC | Source = Application Hang | ID = 1002

Description = Zablokovaná aplikace explorer.exe, verze 6.0.2900.5512, zablokovaný

modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.



Error - 31.5.2012 16:30:21 | Computer Name = PC | Source = Application Hang | ID = 1002

Description = Zablokovaná aplikace explorer.exe, verze 6.0.2900.5512, zablokovaný

modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.



Error - 4.6.2012 8:19:47 | Computer Name = PC | Source = Application Hang | ID = 1002

Description = Zablokovaná aplikace ICQ.exe, verze 7.6.0.5620, zablokovaný modul

hungapp, verze 0.0.0.0, adresa bloku 0x00000000.



Error - 12.6.2012 10:48:37 | Computer Name = PC | Source = Application Hang | ID = 1002

Description = Zablokovaná aplikace firefox.exe, verze 12.0.0.4493, zablokovaný modul

hungapp, verze 0.0.0.0, adresa bloku 0x00000000.



Error - 13.6.2012 3:56:10 | Computer Name = PC | Source = Microsoft Office 12 | ID = 5000

Description = EventType offdiag12, P1 d6ecb0b3-4bb0-488f-a842-41c323bf158f59d2d595-b11e-4a75-8946-844f8e2cf95b,

P2 NIL, P3 NIL, P4 NIL, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.



Error - 14.6.2012 15:00:32 | Computer Name = PC | Source = Application Hang | ID = 1002

Description = Zablokovaná aplikace WINWORD.EXE, verze 12.0.6661.5000, zablokovaný

modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.



Error - 14.6.2012 15:52:18 | Computer Name = PC | Source = Application Hang | ID = 1002

Description = Zablokovaná aplikace WINWORD.EXE, verze 12.0.6661.5000, zablokovaný

modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.



Error - 27.6.2012 16:56:56 | Computer Name = PC | Source = Application Hang | ID = 1002

Description = Zablokovaná aplikace WINWORD.EXE, verze 12.0.6661.5000, zablokovaný

modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.



Error - 19.8.2012 13:01:10 | Computer Name = PC | Source = Windows Product Activation | ID = 1012

Description = Z důvodu změn hardwaru v tomto poĊítaĊi bude nutné produkt Windows

znovu aktivovat.



[ OSession Events ]

Error - 2.1.2012 4:04:24 | Computer Name = PC | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 0, Application Name: Microsoft Office Word, Application Version:

12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 54

seconds with 0 seconds of active time. This session ended with a crash.



[ System Events ]

Error - 17.8.2012 16:11:56 | Computer Name = PC | Source = Service Control Manager | ID = 7009

Description = Vypršel Ċasový limit (30000 milisekund) Ċekání na připojení služby

Služba brány aplikaĊního rozhraní.



Error - 17.8.2012 16:12:07 | Computer Name = PC | Source = Service Control Manager | ID = 7000

Description = Služba Služba brány aplikaĊního rozhraní neuspěla při spuštění v důsledku

následující chyby: %%1053



Error - 18.8.2012 11:57:40 | Computer Name = PC | Source = Service Control Manager | ID = 7034

Description = Služba Ati HotKey Poller byla neoĊekávaně ukonĊena. Tento stav nastal

již 1krát.



Error - 18.8.2012 11:57:42 | Computer Name = PC | Source = Service Control Manager | ID = 7034

Description = Služba Java Quick Starter byla neoĊekávaně ukonĊena. Tento stav nastal

již 1krát.



Error - 18.8.2012 11:58:10 | Computer Name = PC | Source = PlugPlayManager | ID = 11

Description = Zařízení Root\LEGACY_CATCHME\0000 se již v systému nenachází, přestože

nebylo nejdříve připraveno k odebrání.



Error - 19.8.2012 5:22:36 | Computer Name = PC | Source = Service Control Manager | ID = 7034

Description = Služba Ati HotKey Poller byla neoĊekávaně ukonĊena. Tento stav nastal

již 1krát.



Error - 19.8.2012 12:58:31 | Computer Name = PC | Source = PlugPlayManager | ID = 11

Description = Zařízení Root\LEGACY_PPDRV\0000 se již v systému nenachází, přestože

nebylo nejdříve připraveno k odebrání.



Error - 25.8.2012 11:41:22 | Computer Name = PC | Source = Service Control Manager | ID = 7034

Description = Služba Zařazování tisku byla neoĊekávaně ukonĊena. Tento stav nastal

již 1krát.



Error - 25.8.2012 11:41:22 | Computer Name = PC | Source = Service Control Manager | ID = 7034

Description = Služba Služba brány aplikaĊního rozhraní byla neoĊekávaně ukonĊena.

Tento stav nastal již 1krát.



Error - 25.8.2012 11:41:22 | Computer Name = PC | Source = Service Control Manager | ID = 7034

Description = Služba Ati HotKey Poller byla neoĊekávaně ukonĊena. Tento stav nastal

již 1krát.





< End of report >

radeeek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 29 črc 2007 18:43
Kontaktovat uživatele:

Re: Pomalý PC

#18 Příspěvek od radeeek »

druhý log OTL:

OTL logfile created on: 26.8.2012 20:53:16 - Run 1

OTL by OldTimer - Version 3.2.59.1 Folder = C:\Documents and Settings\User1\Plocha

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy



511,48 Mb Total Physical Memory | 177,65 Mb Available Physical Memory | 34,73% Memory free

1,22 Gb Paging File | 0,73 Gb Available in Paging File | 59,93% Paging File free

Paging file location(s): C:\pagefile.sys 768 1536 [binary data]



%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 74,52 Gb Total Space | 6,29 Gb Free Space | 8,43% Space Free | Partition Type: NTFS



Computer Name: PC | User Name: User1 | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days



========== Processes (SafeList) ==========



PRC - [2012.08.26 20:50:37 | 000,598,528 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User1\Plocha\OTL.exe

PRC - [2012.08.21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

PRC - [2012.08.14 06:31:01 | 001,229,848 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe

PRC - [2009.02.20 16:55:42 | 000,326,656 | ---- | M] () -- C:\WINDOWS\tsnpstd3.exe

PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2006.09.19 09:07:28 | 000,827,392 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

PRC - [2005.08.06 02:07:30 | 000,061,440 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe





========== Modules (No Company Name) ==========



MOD - [2012.08.26 10:46:01 | 001,803,264 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12082600\algo.dll

MOD - [2012.08.14 06:30:59 | 000,442,392 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\21.0.1180.79\ppgooglenaclpluginchrome.dll

MOD - [2012.08.14 06:30:57 | 003,997,720 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\21.0.1180.79\pdf.dll

MOD - [2012.08.14 06:29:28 | 000,144,424 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\21.0.1180.79\avutil-51.dll

MOD - [2012.08.14 06:29:27 | 000,266,792 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\21.0.1180.79\avformat-54.dll

MOD - [2012.08.14 06:29:26 | 002,480,680 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\21.0.1180.79\avcodec-54.dll

MOD - [2012.06.13 15:09:44 | 000,843,776 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_f216a820\system.drawing.dll

MOD - [2012.06.13 15:09:30 | 003,035,136 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_43669b8e\system.windows.forms.dll

MOD - [2012.06.13 15:09:00 | 000,471,040 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll

MOD - [2012.04.10 23:57:21 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_dd664ff9\mscorlib.dll

MOD - [2012.04.10 23:57:10 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_977484d8\system.xml.dll

MOD - [2012.04.10 23:56:52 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_568f5ad3\system.dll

MOD - [2009.02.20 16:55:42 | 000,326,656 | ---- | M] () -- C:\WINDOWS\tsnpstd3.exe

MOD - [2007.02.26 15:05:40 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll

MOD - [2007.02.26 15:05:40 | 000,372,736 | ---- | M] () -- c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll

MOD - [2007.02.26 15:05:39 | 000,323,584 | ---- | M] () -- c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll

MOD - [2007.02.26 15:05:05 | 000,229,376 | ---- | M] () -- c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_cs_b77a5c561934e089\mscorlib.resources.dll

MOD - [2007.02.26 15:05:05 | 000,180,224 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms.resources\1.0.5000.0_cs_b77a5c561934e089\system.windows.forms.resources.dll

MOD - [2006.09.19 09:07:28 | 000,827,392 | ---- | M] () -- C:\WINDOWS\vsnpstd3.exe

MOD - [2005.01.01 01:28:20 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll

MOD - [2005.01.01 01:28:19 | 001,269,760 | ---- | M] () -- c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll

MOD - [2005.01.01 01:28:14 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll





========== Services (SafeList) ==========



SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)

SRV - [2012.08.21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)

SRV - [2012.08.15 20:25:14 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)

SRV - [2008.05.21 13:42:56 | 000,064,000 | ---- | M] (Creative Technology Ltd) [On_Demand | Stopped] -- C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe -- (CTUPnPSv)

SRV - [2007.04.02 08:15:40 | 000,061,440 | ---- | M] (Creative Technology Ltd) [Disabled | Stopped] -- C:\Program Files\Creative\Shared Files\CTDevSrv.exe -- (CTDevice_Srv)

SRV - [2006.03.23 18:06:38 | 000,880,128 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)





========== Driver Services (SafeList) ==========



DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Protector Plus\PPEMSCAN.sys -- (PPEMSCAN)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)

DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)

DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)

DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)

DRV - File not found [Kernel | System | Stopped] -- -- (Changer)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)

DRV - File not found [Kernel | On_Demand | Unknown] -- -- (agyn26gq)

DRV - [2012.08.21 11:13:15 | 000,729,752 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)

DRV - [2012.08.21 11:13:15 | 000,355,632 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)

DRV - [2012.08.21 11:13:15 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)

DRV - [2012.08.21 11:13:14 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)

DRV - [2012.08.21 11:13:14 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)

DRV - [2012.08.21 11:13:13 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)

DRV - [2012.08.21 11:13:13 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)

DRV - [2010.02.11 14:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)

DRV - [2010.02.03 15:56:56 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)

DRV - [2009.02.17 12:09:23 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)

DRV - [2008.09.24 10:40:22 | 004,122,368 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM)

DRV - [2007.03.26 14:46:30 | 010,252,544 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snpstd3.sys -- (SNPSTD3)

DRV - [2006.10.23 03:36:38 | 000,093,440 | R--- | M] (AnyDATA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\adusbser.sys -- (adusbser)

DRV - [2006.03.23 18:15:58 | 000,102,016 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)

DRV - [2006.03.23 18:15:56 | 000,033,536 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)

DRV - [2006.03.23 18:15:56 | 000,029,440 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)

DRV - [2006.03.23 18:00:28 | 000,008,704 | ---- | M] (Nero AG) [Recognizer | System | Unknown] -- C:\WINDOWS\System32\drivers\InCDrec.sys -- (InCDrec)

DRV - [2005.08.04 05:10:18 | 001,273,344 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)

DRV - [2005.05.17 11:45:08 | 000,092,800 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvatabus.sys -- (nvatabus)

DRV - [2005.04.05 21:22:30 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)

DRV - [2005.04.05 21:22:28 | 000,033,536 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)

DRV - [2005.03.09 16:53:00 | 000,042,496 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)

DRV - [2004.03.08 13:55:50 | 000,013,567 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS -- (cdrbsdrv)

DRV - [2003.12.05 11:46:36 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)





========== Standard Registry (SafeList) ==========





========== Internet Explorer ==========



IE - HKLM\..\URLSearchHook: - No CLSID value found

IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}





IE - HKU\.DEFAULT\..\URLSearchHook: - No CLSID value found

IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-18\..\URLSearchHook: - No CLSID value found

IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0







IE - HKU\S-1-5-21-1409082233-602162358-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Bar = http://google.icq.com/search/search_frame.php

IE - HKU\S-1-5-21-1409082233-602162358-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://google.icq.com

IE - HKU\S-1-5-21-1409082233-602162358-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKU\S-1-5-21-1409082233-602162358-725345543-1004\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}

IE - HKU\S-1-5-21-1409082233-602162358-725345543-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... orm=IE8SRC

IE - HKU\S-1-5-21-1409082233-602162358-725345543-1004\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT2786678

IE - HKU\S-1-5-21-1409082233-602162358-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1409082233-602162358-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>



========== FireFox ==========



FF - prefs.js..browser.search.defaultenginename: "ICQ Search"

FF - prefs.js..browser.search.useDBForOrder: true

FF - prefs.js..browser.startup.homepage: "google.cz"

FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"

FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""

FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"

FF - prefs.js..browser.startup.homepage: ""

FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.icq.com/search/afe_result ... r=1.4.7&q="





FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()

FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@wolfram.com/Mathematica: C:\Program Files\Common Files\Wolfram Research\Browser\8.0.4.2615434\npmathplugin.dll (Wolfram Research, Inc.)

FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)



FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012.08.25 17:00:12 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.08.15 20:25:19 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.15 20:57:53 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird



[2011.05.02 22:17:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User1\Data aplikací\Mozilla\Extensions

[2012.08.08 20:02:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions

[2012.08.08 20:02:16 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}

[2012.07.20 11:53:31 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}

[2012.08.15 20:57:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2012.08.15 20:57:56 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}

File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\USER1\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\LI3QOA3B.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}

File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\USER1\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\LI3QOA3B.DEFAULT\EXTENSIONS\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}

File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\USER1\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\LI3QOA3B.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}.XPI

[2012.08.25 17:00:12 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF

[2009.02.17 12:12:57 | 000,000,000 | ---D | M] (DAEMON Tools Toolbar) -- C:\PROGRAM FILES\DAEMON TOOLS TOOLBAR\FIREFOXDTT

[2010.02.23 18:50:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION

[2012.08.15 20:25:19 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll

[2011.12.09 19:23:32 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll

[2012.06.28 20:59:47 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml

[2012.06.28 20:59:47 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml

[2012.06.28 20:59:47 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml

[2012.06.28 20:59:47 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml

[2012.06.28 20:59:47 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml



========== Chrome ==========



CHR - homepage: http://www.google.cz/

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}

CHR - homepage: http://www.google.cz/

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.79\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.79\pdf.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.79\gcswf32.dll

CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\User1\Local Settings\Data aplikac\u00ED\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll

CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll

CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll

CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL

CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll

CHR - plugin: Wolfram Mathematica (Enabled) = C:\Program Files\Common Files\Wolfram Research\Browser\8.0.4.2615434\npmathplugin.dll

CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll

CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll

CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll

CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

CHR - Extension: YouTube = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\

CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\

CHR - Extension: 1-ClickWeather for Chrome = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\fgmbighdoomjmebfbgplfmhcdbomjkoa\1.1.0.3_0\

CHR - Extension: AdBlock+ = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\chmimgmjdabgiilljdjfbonifbhiglao\1.1.9.18_0\

CHR - Extension: avast! WebRep = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_0\

CHR - Extension: SweetIM for Facebook = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of

CHR - Extension: SweetIM for Facebook = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\

CHR - Extension: Gmail = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

CHR - Extension: YouTube = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\

CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\

CHR - Extension: 1-ClickWeather for Chrome = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\fgmbighdoomjmebfbgplfmhcdbomjkoa\1.1.0.3_0\

CHR - Extension: AdBlock+ = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\chmimgmjdabgiilljdjfbonifbhiglao\1.1.9.18_0\

CHR - Extension: avast! WebRep = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_0\

CHR - Extension: SweetIM for Facebook = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of

CHR - Extension: SweetIM for Facebook = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\

CHR - Extension: Gmail = C:\Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\



O1 HOSTS File: ([2012.08.25 17:46:11 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)

O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)

O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)

O3 - HKU\S-1-5-21-1409082233-602162358-725345543-1004\..\Toolbar\ShellBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.

O3 - HKU\S-1-5-21-1409082233-602162358-725345543-1004\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.

O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)

O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe ()

O4 - HKLM..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe ()

O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Hlavní panel ATI CATALYST.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-1409082233-602162358-725345543-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-1409082233-602162358-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKU\S-1-5-21-1409082233-602162358-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-21-1409082233-602162358-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found

O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)

O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)

O15 - HKLM\..Trusted Domains: mojebanka.cz ([*] https in Trusted sites)

O15 - HKU\S-1-5-21-1409082233-602162358-725345543-1004\..Trusted Domains: mojebanka.cz ([*] https in Trusted sites)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_33)

O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)

O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)

O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_33)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_33)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.100.254

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{55DC8BD2-E179-4925-9967-56AAB8B86809}: DhcpNameServer = 192.168.100.254

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)

O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)



CREATERESTOREPOINT

Restore point Set: OTL Restore Point



NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found

NetSvcs: Ias - File not found

NetSvcs: Iprip - File not found

NetSvcs: Irmon - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found



Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)

Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)

Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)

Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)

Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)

Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)

Drivers32: vidc.ffds - C:\WINDOWS\System32\ffdshow.ax ()

Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()

Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()

Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)

Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

Drivers32: VIDC.mjpg - C:\WINDOWS\System32\mcmjpg32.dll (MainConcept)

PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin



========== Files/Folders - Created Within 30 Days ==========



[2012.08.26 20:51:04 | 000,598,528 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User1\Plocha\OTL.exe

[2012.08.25 21:07:30 | 002,639,872 | ---- | C] (David Macek) -- C:\Documents and Settings\User1\Plocha\JpegResampler.exe

[2012.08.25 21:05:38 | 000,000,000 | ---D | C] -- C:\Program Files\JR2010

[2012.08.25 21:04:04 | 000,000,000 | -HSD | C] -- C:\RECYCLER

[2012.08.25 17:51:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp

[2012.08.21 22:47:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Plocha\24MTB

[2012.08.21 21:43:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Plocha\Singltrek

[2012.08.19 18:39:41 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe

[2012.08.19 18:39:41 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe

[2012.08.19 18:39:41 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe

[2012.08.19 18:39:41 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe

[2012.08.19 18:39:28 | 000,000,000 | ---D | C] -- C:\Qoobox

[2012.08.19 18:39:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Dokumenty\Obrázky

[2012.08.19 18:39:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\User1\Dokumenty\Hudba

[2012.08.19 18:39:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\User1\Dokumenty\Filmy

[2012.08.19 18:39:22 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Dokumenty\Filmy

[2012.08.19 18:31:32 | 004,735,580 | R--- | C] (Swearware) -- C:\Documents and Settings\User1\Plocha\ComboFix.exe

[2012.08.19 11:33:38 | 000,000,000 | ---D | C] -- C:\Program Files\Defraggler

[2012.08.19 11:29:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\User1\Recent

[2012.08.19 10:55:25 | 000,000,000 | ---D | C] -- C:\Program Files\CrystalDiskInfo

[2012.08.18 18:08:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Data aplikací\Malwarebytes

[2012.08.18 18:08:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes

[2012.08.17 23:00:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Plocha\MemTest

[2012.08.17 12:43:09 | 000,000,000 | ---D | C] -- C:\Program Files\DesetiPrsty

[2012.08.15 21:55:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Local Settings\Data aplikací\Sun

[2012.08.15 21:47:22 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java

[2012.08.15 21:45:48 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle

[2012.08.15 21:45:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Data aplikací\Oracle

[2012.08.15 21:45:20 | 000,227,760 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe

[2012.08.15 21:45:11 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe

[2012.08.15 21:45:11 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe

[2012.08.15 20:57:53 | 000,772,544 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\npdeployJava1.dll

[2012.08.14 22:16:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Plocha\hijack

[2012.08.14 21:24:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Data aplikací\Fighters

[2012.08.14 21:21:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Fighters

[2012.08.07 22:20:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User1\Plocha\Slovensko 08-2012

[2011.04.27 20:17:14 | 018,734,784 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Program Files\WDM_A406.exe

[2011.04.27 20:06:31 | 001,045,320 | ---- | C] (PC Drivers HeadQuarters ) -- C:\Program Files\DriverDetective.exe

[2008.11.11 00:29:52 | 000,607,640 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files\xpiinstall.exe

[2008.10.14 13:39:17 | 002,207,280 | ---- | C] (C. Ghisler & Co.) -- C:\Program Files\tcmd704a.exe



========== Files - Modified Within 30 Days ==========



[2012.08.26 20:58:50 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin

[2012.08.26 20:50:37 | 000,598,528 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User1\Plocha\OTL.exe

[2012.08.26 20:37:20 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2012.08.26 20:37:18 | 000,000,318 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job

[2012.08.26 20:36:44 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2012.08.26 20:36:41 | 536,399,872 | -HS- | M] () -- C:\hiberfil.sys

[2012.08.25 17:46:11 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2012.08.25 17:00:15 | 000,002,553 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT

[2012.08.22 20:25:05 | 000,012,540 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak

[2012.08.21 11:13:15 | 000,729,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys

[2012.08.21 11:13:15 | 000,355,632 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys

[2012.08.21 11:13:15 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys

[2012.08.21 11:13:14 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys

[2012.08.21 11:13:14 | 000,089,624 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys

[2012.08.21 11:13:14 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys

[2012.08.21 11:13:13 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys

[2012.08.21 11:13:13 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys

[2012.08.21 11:12:33 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr

[2012.08.21 11:12:23 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe

[2012.08.20 22:17:45 | 005,212,244 | ---- | M] () -- C:\Documents and Settings\User1\Plocha\zprava_597.zip

[2012.08.19 18:32:24 | 004,735,580 | R--- | M] (Swearware) -- C:\Documents and Settings\User1\Plocha\ComboFix.exe

[2012.08.19 11:33:43 | 000,001,580 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Defraggler.lnk

[2012.08.19 11:17:02 | 000,303,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2012.08.19 10:55:29 | 000,001,643 | ---- | M] () -- C:\Documents and Settings\User1\Plocha\CrystalDiskInfo.lnk

[2012.08.15 21:44:51 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe

[2012.08.15 21:44:50 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe

[2012.08.15 09:55:54 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk

[2012.08.14 22:04:06 | 000,000,281 | RHS- | M] () -- C:\boot.ini

[2012.08.12 16:37:49 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat



========== Files Created - No Company Name ==========



[2012.08.26 20:58:50 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin

[2012.08.20 22:17:38 | 005,212,244 | ---- | C] () -- C:\Documents and Settings\User1\Plocha\zprava_597.zip

[2012.08.19 18:39:41 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe

[2012.08.19 18:39:41 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe

[2012.08.19 18:39:41 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe

[2012.08.19 18:39:41 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe

[2012.08.19 18:39:41 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe

[2012.08.19 11:33:43 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Defraggler.lnk

[2012.08.19 10:55:28 | 000,001,643 | ---- | C] () -- C:\Documents and Settings\User1\Plocha\CrystalDiskInfo.lnk

[2012.08.17 22:10:29 | 536,399,872 | -HS- | C] () -- C:\hiberfil.sys

[2012.08.12 16:37:49 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2012.05.14 19:45:41 | 000,000,087 | ---- | C] () -- C:\Documents and Settings\User1\.octave_hist

[2011.04.27 20:25:46 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe

[2011.04.27 20:24:29 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll

[2007.03.05 22:44:10 | 000,048,640 | ---- | C] () -- C:\Documents and Settings\User1\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2007.02.26 14:52:38 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\User1\Local Settings\Data aplikací\fusioncache.dat



========== LOP Check ==========



[2007.03.21 16:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3 XPack Trial

[2012.06.12 20:12:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AltrixSoft

[2010.11.16 15:38:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software

[2008.11.17 13:42:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg7

[2009.02.17 12:13:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite

[2009.05.12 17:34:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET

[2012.08.14 21:21:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Fighters

[2011.04.03 21:19:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ

[2012.07.16 13:39:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IObit

[2011.04.27 20:10:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Drivers HeadQuarters

[2009.07.30 16:30:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\{615DB4DC-B7C1-4125-9858-78EF460B76D2}

[2009.07.30 16:30:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\{C472ACE4-B620-4236-9212-2822A5A9355F}

[2007.02.26 16:55:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7

[2009.09.26 22:41:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\AVG7

[2011.05.30 21:33:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\BSplayer

[2009.07.21 17:23:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\BSplayer Pro

[2009.02.17 12:14:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\DAEMON Tools

[2012.03.09 16:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\DAEMON Tools Lite

[2012.03.09 16:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\DAEMON Tools Pro

[2009.05.12 17:36:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\ESET

[2012.08.14 21:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Fighters

[2008.12.25 19:43:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\gtk-2.0

[2012.08.25 23:51:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\ICQ

[2007.03.03 21:27:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\ICQ Toolbar

[2007.03.03 21:17:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\ICQLite

[2009.05.19 18:00:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Inkscape

[2012.07.16 16:09:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\IObit

[2012.08.25 21:05:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Jpeg Resampler

[2007.02.28 19:46:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\OLYMPUS

[2012.01.29 22:54:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\OpenCandy

[2012.08.15 21:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Oracle

[2009.06.11 16:23:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\TeamViewer

[2012.03.09 16:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\uTorrent

[2007.03.23 17:00:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\WhenU

[2012.08.26 20:37:18 | 000,000,318 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job



========== Purity Check ==========







========== Custom Scans ==========



< >



< >



< MD5 for: AGP440.SYS >

[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys

[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys

[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys

[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys

[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys



< MD5 for: ATAPI.SYS >

[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys

[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys

[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys

[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys

[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys

[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys

[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys



< MD5 for: AUTOCHK.EXE >

[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe

[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe

[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe

[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\dllcache\autochk.exe

[2006.03.02 14:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe

radeeek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 29 črc 2007 18:43
Kontaktovat uživatele:

Re: Pomalý PC

#19 Příspěvek od radeeek »

< MD5 for: CDROM.SYS >

[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys

[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys

[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\dllcache\cdrom.sys

[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys

[2006.03.02 14:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys



< MD5 for: CRYPTSVC.DLL >

[2006.03.02 14:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll

[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll

[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll

[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll



< MD5 for: EVENTLOG.DLL >

[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll

[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll

[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll

[2006.03.02 14:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll



< MD5 for: EXPLORER.EXE >

[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ERDNT\cache\explorer.exe

[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe

[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe

[2006.03.02 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe



< MD5 for: HAL.DLL >

[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll

[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll

[2008.04.13 20:31:28 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL

[2006.03.02 14:00:00 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll



< MD5 for: CHANGER.SYS >

[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys

[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys



< MD5 for: ISAPNP.SYS >

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys

[2008.10.14 16:50:53 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys

[2006.03.02 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys

[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys

[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\dllcache\isapnp.sys

[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys



< MD5 for: LSASS.EXE >

[2006.03.02 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe

[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ERDNT\cache\lsass.exe

[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe

[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe



< MD5 for: NDIS.SYS >

[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys

[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys

[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys

[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys

[2006.03.02 14:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys



< MD5 for: NETLOGON.DLL >

[2006.03.02 14:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll

[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll

[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll



< MD5 for: NVATA.SYS >

[2005.05.17 11:45:08 | 000,092,800 | R--- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F -- C:\WINDOWS\system32\drivers\nvata.sys



< MD5 for: NVATABUS.SYS >

[2005.05.17 11:45:08 | 000,092,800 | R--- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F -- C:\WINDOWS\system32\drivers\nvatabus.sys



< MD5 for: SCECLI.DLL >

[2006.03.02 14:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll

[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll

[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll

[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll



< MD5 for: SMSS.EXE >

[2006.03.02 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe

[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE

[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe

[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe



< MD5 for: SVCHOST.EXE >

[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ERDNT\cache\svchost.exe

[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe

[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe

[2006.03.02 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe



< MD5 for: TCPIP.SYS >

[2006.04.20 13:51:50 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=1DBF125862891817F374F407626967F4 -- C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys

[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys

[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys

[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys

[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys

[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys

[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\ERDNT\cache\tcpip.sys

[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys

[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys

[2006.03.02 14:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys

[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys

[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

[2006.04.20 14:18:35 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys



< MD5 for: USERINIT.EXE >

[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ERDNT\cache\userinit.exe

[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe

[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe

[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe

[2006.03.02 14:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe



< MD5 for: WINLOGON.EXE >

[2006.03.02 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe

[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ERDNT\cache\winlogon.exe

[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe

[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe



< MD5 for: WS2_32.DLL >

[2006.03.02 14:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll

[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll

[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll

[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll



< >



< %systemroot%*.* /U /s >

[3 C:\WINDOWS\AppPatch\*.tmp files -> C:\WINDOWS\AppPatch\*.tmp -> ]

[22 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]

[127 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]



< %SYSTEMDRIVE%\*.exe >



< %ALLUSERSPROFILE%\Application Data\*. >



< %ALLUSERSPROFILE%\Application Data\*.exe /s >



< %APPDATA%\*. >

[2011.03.26 20:24:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Adobe

[2010.12.10 23:34:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\AdobeUM

[2007.02.27 09:27:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Ahead

[2007.02.26 14:52:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\ATI

[2009.09.26 22:41:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\AVG7

[2011.05.30 21:33:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\BSplayer

[2009.07.21 17:23:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\BSplayer Pro

[2009.07.30 16:34:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Creative

[2007.07.06 21:37:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Cyberlink

[2009.02.17 12:14:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\DAEMON Tools

[2012.03.09 16:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\DAEMON Tools Lite

[2012.03.09 16:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\DAEMON Tools Pro

[2009.05.12 17:36:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\ESET

[2012.08.14 21:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Fighters

[2008.12.25 19:43:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\gtk-2.0

[2008.09.18 18:36:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Help

[2012.08.25 23:51:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\ICQ

[2007.03.03 21:27:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\ICQ Toolbar

[2007.03.03 21:17:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\ICQLite

[2007.02.26 14:19:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Identities

[2009.05.19 18:00:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Inkscape

[2009.10.06 17:14:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\InstallShield

[2012.07.16 16:09:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\IObit

[2012.08.25 21:05:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Jpeg Resampler

[2007.03.03 23:37:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Macromedia

[2008.09.04 16:04:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Macrovision

[2012.08.18 18:08:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Malwarebytes

[2012.03.09 17:04:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Mathematica

[2012.03.09 16:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Media Player Classic

[2012.08.18 16:07:51 | 000,000,000 | --SD | M] -- C:\Documents and Settings\User1\Data aplikací\Microsoft

[2011.05.02 22:17:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Mozilla

[2007.02.28 19:46:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\OLYMPUS

[2012.01.29 22:54:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\OpenCandy

[2012.08.06 22:46:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\OpenOffice.org2

[2012.08.15 21:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Oracle

[2010.02.12 21:27:04 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\User1\Data aplikací\SecuROM

[2012.07.18 22:33:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Skype

[2012.07.18 22:05:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\skypePM

[2008.11.11 00:32:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Sun

[2009.12.02 17:44:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\teamspeak2

[2009.06.11 16:23:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\TeamViewer

[2012.03.09 16:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\uTorrent

[2007.03.23 17:00:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\WhenU

[2012.08.12 18:04:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Winamp

[2009.03.03 18:44:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\Winamp3



< %APPDATA%\*.exe /s >

[2007.08.18 09:54:02 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\User1\Data aplikací\BSplayer\AC3 Filter\ac3config.exe

[2007.08.18 09:53:50 | 000,016,384 | ---- | M] () -- C:\Documents and Settings\User1\Data aplikací\BSplayer\AC3 Filter\dialog_patch.exe

[2008.04.13 17:26:54 | 000,036,396 | ---- | M] () -- C:\Documents and Settings\User1\Data aplikací\BSplayer\AC3 Filter\uninstall.exe

[2008.04.01 11:51:06 | 000,691,717 | ---- | M] () -- C:\Documents and Settings\User1\Data aplikací\BSplayer\FFDShow\unins000.exe

[2008.03.29 17:42:00 | 000,103,424 | ---- | M] () -- C:\Documents and Settings\User1\Data aplikací\BSplayer\Haali media splitter\dsmux.exe

[2008.03.29 17:42:02 | 000,335,872 | ---- | M] () -- C:\Documents and Settings\User1\Data aplikací\BSplayer\Haali media splitter\gdsmux.exe

[2008.03.29 17:41:54 | 000,135,168 | ---- | M] () -- C:\Documents and Settings\User1\Data aplikací\BSplayer\Haali media splitter\mkv2vfr.exe

[2008.06.10 09:11:02 | 000,041,412 | ---- | M] () -- C:\Documents and Settings\User1\Data aplikací\BSplayer\Haali media splitter\uninstall.exe

[2011.11.18 06:30:06 | 002,081,208 | ---- | M] (Speedchecker Limited ) -- C:\Documents and Settings\User1\Data aplikací\OpenCandy\64C1A26E06D846879878B6DB4EB2C359\pcspeedup_oc.exe



< %systemroot%\*. /mp /s >



< %systemroot%\system32\*.dll /lockedfiles >



< %systemroot%\Tasks\*.job /lockedfiles >



< %systemroot%\system32\drivers\*.sys /lockedfiles >

[2009.02.17 12:09:23 | 000,717,296 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys



< %systemroot%\System32\config\*.sav >

[2007.02.26 14:26:07 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav

[2007.02.26 14:26:07 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav

[2007.02.26 14:26:07 | 000,462,848 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav



< %systemroot%\system32\*.dll /lockedfiles >



< %systemroot%\system32\drivers\*.sys /3 >



< %systemroot%\system32\*.* /3 >

[2012.08.25 17:00:15 | 000,002,553 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT

[2012.08.26 20:37:20 | 000,012,598 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl



< %SYSTEMDRIVE%\*.exe >



< >



< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >

"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 05:22:17 | 000,015,360 | ---- | M] (Microsoft Corporation)



< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON



< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV

IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs



< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS

IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs



< >



< type c:\boot.ini >> test.txt /c >

[boot loader]

timeout=3

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect



< %SystemDrive%\PhysicalMBR.bin /md5 >

[2012.08.26 20:58:50 | 000,000,512 | ---- | M] () MD5=28F130DF270CF8AB87D47CA18E7A5DD2 -- C:\PhysicalMBR.bin



< >



< *crack* /s >

[2007.09.26 10:00:20 | 006,651,738 | ---- | M] () -- \Documents and Settings\User1\Plocha\Katka\Katka hudba\amnesia-2007\09 - DJ Andrew - Crackhead.mp3



< *keygen* /s >

[2010.03.25 19:54:34 | 000,000,779 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\javax\crypto\jce\key\AnubisKeyGeneratorImpl.h

[2010.03.25 19:54:34 | 000,000,791 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\javax\crypto\jce\key\BlowfishKeyGeneratorImpl.h

[2010.03.25 19:54:34 | 000,000,773 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\javax\crypto\jce\key\Cast5KeyGeneratorImpl.h

[2010.03.25 19:54:34 | 000,000,943 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\javax\crypto\jce\key\DESKeyGeneratorImpl.h

[2010.03.25 19:54:34 | 000,000,779 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\javax\crypto\jce\key\KhazadKeyGeneratorImpl.h

[2010.03.25 19:54:34 | 000,000,791 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\javax\crypto\jce\key\RijndaelKeyGeneratorImpl.h

[2010.03.25 19:54:34 | 000,001,586 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\javax\crypto\jce\key\SecretKeyGeneratorImpl.h

[2010.03.25 19:54:34 | 000,000,785 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\javax\crypto\jce\key\SerpentKeyGeneratorImpl.h

[2010.03.25 19:54:34 | 000,000,779 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\javax\crypto\jce\key\SquareKeyGeneratorImpl.h

[2010.03.25 19:54:34 | 000,000,797 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\javax\crypto\jce\key\TripleDESKeyGeneratorImpl.h

[2010.03.25 19:54:34 | 000,000,785 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\javax\crypto\jce\key\TwofishKeyGeneratorImpl.h

[2010.03.25 19:54:38 | 000,000,991 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\security\spec\RSAKeyGenParameterSpec.h

[2010.03.25 19:54:38 | 000,001,838 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\javax\crypto\KeyGenerator.h

[2010.03.25 19:54:38 | 000,001,032 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\javax\crypto\KeyGeneratorSpi.h



< *loader* /s >

[2011.09.20 08:19:45 | 000,010,145 | ---- | M] () -- \Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\conduitCommon\modules\3.6.0.10\ExternalLibraryLoader.jsm

[2011.10.02 12:57:40 | 000,010,144 | ---- | M] () -- \Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\conduitCommon\modules\3.7.0.6\ExternalLibraryLoader.jsm

[2011.11.08 07:53:58 | 000,010,144 | ---- | M] () -- \Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\conduitCommon\modules\3.8.0.8\ExternalLibraryLoader.jsm

[2011.12.13 15:57:44 | 000,010,144 | ---- | M] () -- \Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\conduitCommon\modules\3.8.1.0\ExternalLibraryLoader.jsm

[2012.01.11 12:53:08 | 000,010,144 | ---- | M] () -- \Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\conduitCommon\modules\3.9.0.3\ExternalLibraryLoader.jsm

[2012.07.16 23:06:52 | 000,010,145 | ---- | M] () -- \Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\ExternalLibraryLoader.jsm

[2010.11.19 22:26:16 | 000,001,849 | ---- | M] () -- \Documents and Settings\User1\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\fgmbighdoomjmebfbgplfmhcdbomjkoa\1.1.0.3_0\images\ajax-loader.gif

[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.dll

[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.tlb

[2011.10.04 20:45:22 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\IMAGES\XtraPreloader\loader.jpg

[2011.10.04 20:45:23 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png

[2011.10.04 20:45:21 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\MUICoreLib\xtraLoader.swf

[2011.10.04 20:45:53 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.6\Xtraz\icq\content\profile_lightboxs\preloader.html

[2010.03.25 19:54:34 | 000,000,834 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\classpath\jdwp\exception\InvalidClassLoaderException.h

[2010.03.25 19:54:34 | 000,000,726 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\classpath\jdwp\id\ClassLoaderId.h

[2010.03.25 19:54:34 | 000,001,058 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\classpath\jdwp\processor\ClassLoaderReferenceCommandSet.h

[2010.03.25 19:54:34 | 000,001,249 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\gcj\runtime\BootClassLoader.h

[2010.03.25 19:54:34 | 000,000,891 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\gcj\runtime\ExtensionClassLoader.h

[2010.03.25 19:54:34 | 000,000,718 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\gcj\runtime\HelperClassLoader.h

[2010.03.25 19:54:34 | 000,001,126 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\gcj\runtime\SharedLibLoader.h

[2010.03.25 19:54:34 | 000,000,926 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\gcj\runtime\SystemClassLoader.h

[2010.03.25 19:54:34 | 000,003,600 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\java\awt\font\opentype\truetype\GlyphLoader.h

[2010.03.25 19:54:34 | 000,000,898 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\java\io\ClassLoaderObjectInputStream.h

[2010.03.25 19:54:34 | 000,001,284 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\java\net\loader\FileURLLoader.h

[2010.03.25 19:54:34 | 000,001,674 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\java\net\loader\JarURLLoader.h

[2010.03.25 19:54:34 | 000,001,184 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\java\net\loader\RemoteURLLoader.h

[2010.03.25 19:54:34 | 000,001,796 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\java\net\loader\URLLoader.h

[2010.03.25 19:54:34 | 000,001,160 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\java\rmi\server\CombinedClassLoader.h

[2010.03.25 19:54:34 | 000,001,742 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\gnu\java\rmi\server\RMIClassLoaderImpl.h

[2010.03.25 19:54:38 | 000,004,844 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\lang\ClassLoader.h

[2010.03.25 19:54:38 | 000,002,309 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\lang\VMClassLoader.h

[2010.03.25 19:54:38 | 000,003,117 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\net\URLClassLoader.h

[2010.03.25 19:54:38 | 000,000,885 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\rmi\server\LoaderHandler.h

[2010.03.25 19:54:38 | 000,001,541 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\rmi\server\RMIClassLoader.h

[2010.03.25 19:54:38 | 000,001,002 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\rmi\server\RMIClassLoaderSpi.h

[2010.03.25 19:54:38 | 000,001,384 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\security\SecureClassLoader.h

[2010.03.25 19:54:38 | 000,001,370 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\util\ServiceLoader.h

[2010.03.25 19:54:38 | 000,000,725 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\javax\management\DefaultLoaderRepository.h

[2010.03.25 19:54:38 | 000,000,910 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\javax\management\loading\ClassLoaderRepository.h

[2006.12.01 19:32:10 | 000,023,552 | ---- | M] () -- \Program Files\OpenOffice.org 2.1\program\javaloader.uno.dll

[2006.12.02 14:23:50 | 000,005,226 | ---- | M] () -- \Program Files\OpenOffice.org 2.1\program\pythonloader.py

[2006.12.02 00:19:20 | 000,015,872 | ---- | M] () -- \Program Files\OpenOffice.org 2.1\program\pythonloader.uno.dll

[2006.12.02 15:13:08 | 000,000,145 | ---- | M] () -- \Program Files\OpenOffice.org 2.1\program\pythonloader.uno.ini

[2006.12.01 19:32:10 | 000,018,432 | ---- | M] () -- \Program Files\OpenOffice.org 2.1\program\shlibloader.uno.dll

[2006.12.02 00:02:36 | 000,003,198 | ---- | M] () -- \Program Files\OpenOffice.org 2.1\program\classes\unoloader.jar

[2006.03.02 14:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll

[2011.09.28 15:44:34 | 000,082,784 | ---- | M] () -- \WINDOWS\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll

[2008.04.14 05:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll

[2008.04.13 20:31:47 | 000,230,912 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe

[2008.04.13 20:31:48 | 000,278,528 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd

[2008.04.14 05:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll

[2008.04.14 05:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dllcache\dmloader.dll



< *minodlogin* /s >



< *tnod* /s >



< *AutoKMS* /s >



< *activator* /s >

[2010.03.25 19:54:38 | 000,000,710 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\rmi\activation\Activator.h



< *serial* /s >

[2004.08.17 15:44:16 | 000,030,301 | ---- | M] () -- \cmdcons\SERIAL.SY_

[2006.02.15 03:35:56 | 003,041,124 | ---- | M] () -- \Documents and Settings\User1\Plocha\Muzika\skarface\skankuat nec mergitur !!!!!\08 Serial Killer.mp3

[2012.03.29 06:01:00 | 000,413,696 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.1.10329.0\System.Runtime.Serialization.dll

[2012.05.13 22:56:19 | 001,186,816 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.1.10329.0\System.Runtime.Serialization.ni.dll

[2010.03.25 19:54:38 | 000,000,564 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\io\NotSerializableException.h

[2010.03.25 19:54:38 | 000,000,361 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\io\Serializable.h

[2010.03.25 19:54:38 | 000,000,715 | ---- | M] () -- \Program Files\Octave\3.2.4_gcc-4.4.0\mingw32\lib\gcc\mingw32\4.4.0\include\c++\java\io\SerializablePermission.h

[2006.12.01 22:27:22 | 000,188,993 | ---- | M] () -- \Program Files\OpenOffice.org 2.1\program\classes\serializer.jar

[2010.04.07 23:48:30 | 000,970,752 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll

[2006.03.02 14:00:00 | 000,064,640 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\serial.sys

[2007.02.26 15:05:05 | 000,011,776 | ---- | M] () -- \WINDOWS\assembly\GAC\System.Runtime.Serialization.Formatters.Soap.resources\1.0.5000.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll

[2007.02.26 15:05:38 | 000,131,072 | ---- | M] () -- \WINDOWS\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll

[2012.06.13 15:19:14 | 000,131,072 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll

[2010.06.10 18:12:53 | 000,970,752 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll

[2012.05.13 23:22:00 | 002,345,472 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\505e12638acd6fdb22e1fd2d4c6fc232\System.Runtime.Serialization.ni.dll

[2012.05.14 09:37:26 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\a644ec04e18202b60f9d828bc207972b\System.Runtime.Serialization.Formatters.Soap.ni.dll

[2004.07.15 15:31:54 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll

[2003.04.07 20:24:52 | 000,011,776 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v1.1.4322\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll

[2008.07.25 12:17:00 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll

[2010.04.07 23:48:30 | 000,970,752 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll

[2008.04.14 04:17:25 | 000,028,416 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\grserial.sys

[2008.04.14 04:21:08 | 000,064,256 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\serial.sys

[2006.03.02 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dpserial.dll

[2006.03.02 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\serialui.dll

[2006.03.02 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dllcache\dpserial.dll

[2008.04.14 04:21:08 | 000,064,256 | ---- | M] () -- \WINDOWS\system32\dllcache\serial.sys

[2006.03.02 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\dllcache\serialui.dll

[2008.04.14 04:21:08 | 000,064,256 | ---- | M] () -- \WINDOWS\system32\drivers\serial.sys



< *w7lxe* /s >



< End of report >

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Pomalý PC

#20 Příspěvek od Márty84 »

:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Znovu spustte OTL
Do spodniho okna vlozte nasledujici text (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[Purity]

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp

:otl
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\.DEFAULT\..\URLSearchHook: - No CLSID value found
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKU\S-1-5-21-1409082233-602162358-725345543-1004\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKU\S-1-5-21-1409082233-602162358-725345543-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-1409082233-602162358-725345543-1004\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.4.7&q="
[2012.08.08 20:02:16 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2012.07.20 11:53:31 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2009.02.17 12:12:57 | 000,000,000 | ---D | M] (DAEMON Tools Toolbar) -- C:\PROGRAM FILES\DAEMON TOOLS TOOLBAR\FIREFOXDTT
O3 - HKU\S-1-5-21-1409082233-602162358-725345543-1004\..\Toolbar\ShellBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKU\S-1-5-21-1409082233-602162358-725345543-1004\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Reg Error: Key error.)
[2008.11.17 13:42:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg7
[2009.05.12 17:34:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2012.07.16 13:39:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IObit
[2007.02.26 16:55:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
[2009.09.26 22:41:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\AVG7
[2009.05.12 17:36:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\ESET
[2007.03.03 21:27:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\ICQ Toolbar
[2012.07.16 16:09:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User1\Data aplikací\IObit
[3 C:\WINDOWS\AppPatch\*.tmp files -> C:\WINDOWS\AppPatch\*.tmp -> ]
[22 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[127 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

radeeek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 29 črc 2007 18:43
Kontaktovat uživatele:

Re: Pomalý PC

#21 Příspěvek od radeeek »

zde výsledek:

All processes killed

========== COMMANDS ==========



[EMPTYTEMP]



User: Administrator

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->FireFox cache emptied: 0 bytes



User: All Users



User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes



User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes



User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes



User: User1

->Temp folder emptied: 443 bytes

->Temporary Internet Files folder emptied: 4352810 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 212478918 bytes

->Google Chrome cache emptied: 243676707 bytes

->Flash cache emptied: 1190 bytes



%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 664 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes

RecycleBin emptied: 14991306 bytes



Total Files Cleaned = 454,00 mb





[EMPTYFLASH]



User: Administrator



User: All Users



User: Default User



User: LocalService



User: NetworkService



User: User1

->Flash cache emptied: 0 bytes



Total Flash Files Cleaned = 0,00 mb



========== FILES ==========

File/Folder C:\WINDOWS\system32\*.tmp.dll not found.

File/Folder C:\WINDOWS\system32\SET*.tmp not found.

File/Folder C:\WINDOWS\*.tmp not found.

========== OTL ==========

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.

Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.

Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.

Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\ not found.

Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.

HKEY_USERS\S-1-5-21-1409082233-602162358-725345543-1004\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!

Registry key HKEY_USERS\S-1-5-21-1409082233-602162358-725345543-1004\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.

Registry key HKEY_USERS\S-1-5-21-1409082233-602162358-725345543-1004\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.

Prefs.js: "ICQ Search" removed from browser.search.defaultenginename

Prefs.js: true removed from browser.search.useDBForOrder

Prefs.js: "ICQ Search" removed from sweetim.toolbar.previous.browser.search.defaultenginename

Prefs.js: "" removed from sweetim.toolbar.previous.browser.search.defaulturl

Prefs.js: "ICQ Search" removed from sweetim.toolbar.previous.browser.search.selectedEngine

Prefs.js: "" removed from browser.startup.homepage

Prefs.js: "http://search.icq.com/search/afe_result ... r=1.4.7&q=" removed from sweetim.toolbar.previous.keyword.URL

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\Plugins folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\chrome folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\Mozilla\Firefox\Profiles\li3qoa3b.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} folder moved successfully.

C:\PROGRAM FILES\DAEMON TOOLS TOOLBAR\FIREFOXDTT\components folder moved successfully.

C:\PROGRAM FILES\DAEMON TOOLS TOOLBAR\FIREFOXDTT\chrome folder moved successfully.

C:\PROGRAM FILES\DAEMON TOOLS TOOLBAR\FIREFOXDTT folder moved successfully.

Registry value HKEY_USERS\S-1-5-21-1409082233-602162358-725345543-1004\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.

Registry value HKEY_USERS\S-1-5-21-1409082233-602162358-725345543-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.

Starting removal of ActiveX control {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\ not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\ not found.

Starting removal of ActiveX control {D27CDB6E-AE6D-11CF-96B8-444553540000}

C:\WINDOWS\Downloaded Program Files\swflash.inf moved successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ not found.

C:\Documents and Settings\All Users\Data aplikací\avg7\QUEUE\TEMP folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\avg7\QUEUE\OUT folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\avg7\QUEUE\ACTIVE folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\avg7\QUEUE folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\avg7\Log folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\avg7 folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\ESET\ESET Smart Security\Stats folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\ESET\ESET Smart Security\Charon folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\ESET\ESET Smart Security\Antispam folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\ESET\ESET Smart Security folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\ESET\ESET NOD32 Antivirus\Stats folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\ESET\ESET NOD32 Antivirus folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\ESET folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\IObit\Advanced SystemCare V5 folder moved successfully.

C:\Documents and Settings\All Users\Data aplikací\IObit folder moved successfully.

C:\Documents and Settings\LocalService\Data aplikací\AVG7 folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\AVG7 folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\ESET\ESET Smart Security\Antispam folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\ESET\ESET Smart Security folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\ESET folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\ICQ Toolbar folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\IObit\Smart Defrag 2 folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\IObit\IObit Malware Fighter folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\IObit\Advanced SystemCare V5\Toolbox folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\IObit\Advanced SystemCare V5\Log folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\IObit\Advanced SystemCare V5\Boottime folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\IObit\Advanced SystemCare V5\Backup folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\IObit\Advanced SystemCare V5 folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\IObit\Advanced SystemCare folder moved successfully.

C:\Documents and Settings\User1\Data aplikací\IObit folder moved successfully.

C:\WINDOWS\AppPatch\SET2C2.tmp deleted successfully.

C:\WINDOWS\AppPatch\SET2C3.tmp deleted successfully.

C:\WINDOWS\AppPatch\SET2C4.tmp deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP112.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP12F.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP148.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP156.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP15B.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP185.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1AB.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1CA.tmp\System.dll deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1CA.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1F6.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1FD.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP20.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP230.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP24.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP273.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP27E.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2C.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2CD.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP399.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3FA.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP46A.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP90.tmp folder deleted successfully.

C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPFF.tmp folder deleted successfully.

C:\WINDOWS\Installer\MSI100.tmp deleted successfully.

C:\WINDOWS\Installer\MSI101.tmp deleted successfully.

C:\WINDOWS\Installer\MSI102.tmp deleted successfully.

C:\WINDOWS\Installer\MSI103.tmp deleted successfully.

C:\WINDOWS\Installer\MSI104.tmp deleted successfully.

C:\WINDOWS\Installer\MSI105.tmp deleted successfully.

C:\WINDOWS\Installer\MSI106.tmp deleted successfully.

C:\WINDOWS\Installer\MSI107.tmp deleted successfully.

C:\WINDOWS\Installer\MSI108.tmp deleted successfully.

C:\WINDOWS\Installer\MSI109.tmp deleted successfully.

C:\WINDOWS\Installer\MSI10A.tmp deleted successfully.

C:\WINDOWS\Installer\MSI10B.tmp deleted successfully.

C:\WINDOWS\Installer\MSI10C.tmp deleted successfully.

C:\WINDOWS\Installer\MSI10D.tmp deleted successfully.

C:\WINDOWS\Installer\MSI10E.tmp deleted successfully.

C:\WINDOWS\Installer\MSI10F.tmp deleted successfully.

C:\WINDOWS\Installer\MSI11.tmp deleted successfully.

C:\WINDOWS\Installer\MSI110.tmp deleted successfully.

C:\WINDOWS\Installer\MSI111.tmp deleted successfully.

C:\WINDOWS\Installer\MSI1118.tmp deleted successfully.

C:\WINDOWS\Installer\MSI112.tmp deleted successfully.

C:\WINDOWS\Installer\MSI12.tmp deleted successfully.

C:\WINDOWS\Installer\MSI125.tmp deleted successfully.

C:\WINDOWS\Installer\MSI13.tmp deleted successfully.

C:\WINDOWS\Installer\MSI139.tmp deleted successfully.

C:\WINDOWS\Installer\MSI14.tmp deleted successfully.

C:\WINDOWS\Installer\MSI15.tmp deleted successfully.

C:\WINDOWS\Installer\MSI16.tmp deleted successfully.

C:\WINDOWS\Installer\MSI17.tmp deleted successfully.

C:\WINDOWS\Installer\MSI18.tmp deleted successfully.

C:\WINDOWS\Installer\MSI19.tmp deleted successfully.

C:\WINDOWS\Installer\MSI1A.tmp deleted successfully.

C:\WINDOWS\Installer\MSI1B.tmp deleted successfully.

C:\WINDOWS\Installer\MSI1C.tmp deleted successfully.

C:\WINDOWS\Installer\MSI1D.tmp deleted successfully.

C:\WINDOWS\Installer\MSI1E.tmp deleted successfully.

C:\WINDOWS\Installer\MSI1F.tmp deleted successfully.

C:\WINDOWS\Installer\MSI20.tmp deleted successfully.

C:\WINDOWS\Installer\MSI21.tmp deleted successfully.

C:\WINDOWS\Installer\MSI22.tmp deleted successfully.

C:\WINDOWS\Installer\MSI23.tmp deleted successfully.

C:\WINDOWS\Installer\MSI2B.tmp deleted successfully.

C:\WINDOWS\Installer\MSI2C0.tmp deleted successfully.

C:\WINDOWS\Installer\MSI3C.tmp deleted successfully.

C:\WINDOWS\Installer\MSI3D.tmp deleted successfully.

C:\WINDOWS\Installer\MSI3E.tmp deleted successfully.

C:\WINDOWS\Installer\MSI3F.tmp deleted successfully.

C:\WINDOWS\Installer\MSI40.tmp deleted successfully.

C:\WINDOWS\Installer\MSI41.tmp deleted successfully.

C:\WINDOWS\Installer\MSI42.tmp deleted successfully.

C:\WINDOWS\Installer\MSI43.tmp deleted successfully.

C:\WINDOWS\Installer\MSI44.tmp deleted successfully.

C:\WINDOWS\Installer\MSI45.tmp deleted successfully.

C:\WINDOWS\Installer\MSI46.tmp deleted successfully.

C:\WINDOWS\Installer\MSI47.tmp deleted successfully.

C:\WINDOWS\Installer\MSI48.tmp deleted successfully.

C:\WINDOWS\Installer\MSI49.tmp deleted successfully.

C:\WINDOWS\Installer\MSI4A.tmp deleted successfully.

C:\WINDOWS\Installer\MSI4B.tmp deleted successfully.

C:\WINDOWS\Installer\MSI4C.tmp deleted successfully.

C:\WINDOWS\Installer\MSI4D.tmp deleted successfully.

C:\WINDOWS\Installer\MSI4E.tmp deleted successfully.

C:\WINDOWS\Installer\MSI4F.tmp deleted successfully.

C:\WINDOWS\Installer\MSI50.tmp deleted successfully.

C:\WINDOWS\Installer\MSI5C.tmp deleted successfully.

C:\WINDOWS\Installer\MSI60.tmp deleted successfully.

C:\WINDOWS\Installer\MSI85F.tmp deleted successfully.

C:\WINDOWS\Installer\MSI860.tmp deleted successfully.

C:\WINDOWS\Installer\MSI861.tmp deleted successfully.

C:\WINDOWS\Installer\MSI862.tmp deleted successfully.

C:\WINDOWS\Installer\MSI863.tmp deleted successfully.

C:\WINDOWS\Installer\MSI864.tmp deleted successfully.

C:\WINDOWS\Installer\MSI865.tmp deleted successfully.

C:\WINDOWS\Installer\MSI866.tmp deleted successfully.

C:\WINDOWS\Installer\MSI867.tmp deleted successfully.

C:\WINDOWS\Installer\MSI868.tmp deleted successfully.

C:\WINDOWS\Installer\MSI869.tmp deleted successfully.

C:\WINDOWS\Installer\MSI86A.tmp deleted successfully.

C:\WINDOWS\Installer\MSI86B.tmp deleted successfully.

C:\WINDOWS\Installer\MSI86C.tmp deleted successfully.

C:\WINDOWS\Installer\MSI86D.tmp deleted successfully.

C:\WINDOWS\Installer\MSI86E.tmp deleted successfully.

C:\WINDOWS\Installer\MSI86F.tmp deleted successfully.

C:\WINDOWS\Installer\MSI870.tmp deleted successfully.

C:\WINDOWS\Installer\MSI871.tmp deleted successfully.

C:\WINDOWS\Installer\MSI872.tmp deleted successfully.

C:\WINDOWS\Installer\MSI95.tmp deleted successfully.

C:\WINDOWS\Installer\MSI99.tmp deleted successfully.

C:\WINDOWS\Installer\MSI9A.tmp deleted successfully.

C:\WINDOWS\Installer\MSI9B.tmp deleted successfully.

C:\WINDOWS\Installer\MSI9C.tmp deleted successfully.

C:\WINDOWS\Installer\MSI9D.tmp deleted successfully.

C:\WINDOWS\Installer\MSI9E.tmp deleted successfully.

C:\WINDOWS\Installer\MSI9F.tmp deleted successfully.

C:\WINDOWS\Installer\MSIA0.tmp deleted successfully.

C:\WINDOWS\Installer\MSIA1.tmp deleted successfully.

C:\WINDOWS\Installer\MSIA2.tmp deleted successfully.

C:\WINDOWS\Installer\MSIA3.tmp deleted successfully.

C:\WINDOWS\Installer\MSIA4.tmp deleted successfully.

C:\WINDOWS\Installer\MSIA5.tmp deleted successfully.

C:\WINDOWS\Installer\MSIA6.tmp deleted successfully.

C:\WINDOWS\Installer\MSIA7.tmp deleted successfully.

C:\WINDOWS\Installer\MSIA8.tmp deleted successfully.

C:\WINDOWS\Installer\MSIA9.tmp deleted successfully.

C:\WINDOWS\Installer\MSIAA.tmp deleted successfully.

C:\WINDOWS\Installer\MSIAB.tmp deleted successfully.

C:\WINDOWS\Installer\MSIAC.tmp deleted successfully.

C:\WINDOWS\Installer\MSIAD.tmp deleted successfully.

C:\WINDOWS\Installer\MSIAE.tmp deleted successfully.

C:\WINDOWS\Installer\MSIAF.tmp deleted successfully.

C:\WINDOWS\Installer\MSIB0.tmp deleted successfully.

C:\WINDOWS\Installer\MSIB1.tmp deleted successfully.

C:\WINDOWS\Installer\MSIB2.tmp deleted successfully.

C:\WINDOWS\Installer\MSIB3.tmp deleted successfully.

C:\WINDOWS\Installer\MSIB4.tmp deleted successfully.

C:\WINDOWS\Installer\MSIB5.tmp deleted successfully.

C:\WINDOWS\Installer\MSIB6.tmp deleted successfully.

C:\WINDOWS\Installer\MSIB7.tmp deleted successfully.

C:\WINDOWS\Installer\MSIB8.tmp deleted successfully.

C:\WINDOWS\Installer\MSIB9.tmp deleted successfully.

C:\WINDOWS\Installer\MSIBA.tmp deleted successfully.

C:\WINDOWS\Installer\MSIBB.tmp deleted successfully.

C:\WINDOWS\Installer\MSIBC.tmp deleted successfully.

C:\WINDOWS\Installer\MSIBD.tmp deleted successfully.

C:\WINDOWS\Installer\MSIBE.tmp deleted successfully.

C:\WINDOWS\Installer\MSIC0.tmp deleted successfully.

C:\WINDOWS\Installer\MSIF0.tmp deleted successfully.



OTL by OldTimer - Version 3.2.59.1 log created on 08272012_215234



Files\Folders moved on Reboot...

C:\WINDOWS\temp\_avast_\Webshlock.txt moved successfully.



PendingFileRenameOperations files...



Registry entries deleted on Reboot...

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Pomalý PC

#22 Příspěvek od Márty84 »

:arrow: Prejmenujte ComboFix na Uninstall a spustte ho. CF by se mel odinstalovat.

:arrow:
vyosek píše::arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: Stahnete OTC http://oldtimer.geekstogo.com/OTC.exe , ulozte a spustte.
Kliknete na napis CleanUp a pote OK - Po uklidu dojde k restartu pc.



:arrow: Pak napiste, jak to vypada.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

radeeek
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 29 črc 2007 18:43
Kontaktovat uživatele:

Re: Pomalý PC

#23 Příspěvek od radeeek »

tak PC pracuje určitě lépe, než před čištěním, přesto to není 100% a myslím, že by mohl být lepší... mám strach jestli tedy neodchází spíš něco z hardware (PC je starý tak 5 let)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Pomalý PC

#24 Příspěvek od Márty84 »

Márty84 píše: :arrow: Disk vykazuje nejake chyby hledani a cteni. Muze to byt pricina problemu, ale nemusi. To tezko zjistim :)
07 _73 _60 _30 0000014F9A10 Počet chybných hledání
C3 _66 _46 __0 000003F03EA0 Počet oprav chybného čtení
Tohle jsem uz psal a nejspis je to tedy pricina problemu. Protoze havet v pc neni a procisteno taky bylo. Vic toho asi nesvedem.


Zkuste jeste provest systemovou opravu disku

:arrow: Kliknete na START a pak na Spustit
V okenku co vyskoci bude radek, do ktereho napiste

Kód: Vybrat vše

cmd
Kliknete na OK
Vyskoci na vas dalsi okno. Do nej napiste

Kód: Vybrat vše

chkdsk c: /f /r
:!: ty mezery tam jsou schvalne, taky je tam udelejte
Az to napisete, zmacknete Enter
Mela by se vam objevit moznost opravy disku, tu odsouhlaste a uvidime, jestli se neco zmeni
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pomalý PC

#25 Příspěvek od motji »

Jak to tu vypadá? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Pomalý PC

#26 Příspěvek od motji »

Dobrý den,
pro neaktivitu je toto téma uzamknuto.
Pokud ho budete chtít odemknout, kontaktujte mě na email nebo některého z mých kolegů.
Děkujeme za pochopení :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Zamčeno