Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosba o pomoc - 100% CPU, zpomalený počítač

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
mon.men
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 26 zář 2012 20:56

Prosba o pomoc - 100% CPU, zpomalený počítač

#1 Příspěvek od mon.men »

Dobrý večer,
během dneška se mi začal sekat počítač, strašně dlouho trvá jakékoliv načítání, po spuštění firefoxu se využití CPU posune na 100%, hudba se v přehrávači seká, počítač je celkově pomalý. Prosím o radu a předem děkuji za pomoc.
Zde je log z RSIT:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Mončičák at 2012-09-26 21:18:30
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 16 GB (33%) free of 50 GB
Total RAM: 2047 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:21:14, on 26.9.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\CooL Wallpaper Changer\coolwpc.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Documents and Settings\Mončičák\Plocha\RSIT.exe
C:\Program Files\trend micro\Mončičák.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search13.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=14672
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search13.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: YTD Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
R3 - URLSearchHook: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll
O2 - BHO: uTorrentControl2 - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: YTD Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll
O3 - Toolbar: YTD Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files\YTD Toolbar\IE\6.2\ytdToolbarIE.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
O4 - HKCU\..\Run: [CooLWPC3] C:\Program Files\CooL Wallpaper Changer\coolwpc.exe /boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Mončičák\Data aplikací\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm (file missing)
O9 - Extra 'Tools' menuitem: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm (file missing)
O9 - Extra button: &Virtuální klávesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: &Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe
O23 - Service: Google Update Service (gupdate1cabd3b195a07f2) (gupdate1cabd3b195a07f2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe

--
End of file - 11198 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Automatic troubleshooting.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\dymngkir.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.google.cz/"
prefs.js - "extensions.enabledItems" - "{20a82645-c095-46ed-80e3-08825760534b}:0.0.0, jqs@sun.com:1.0, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3, linkfilter@kaspersky.ru:9.0.0.463, {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, noia2_option@kk.noia:3.76, {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}:6.0.19, {6236BA26-C117-4007-928C-DE0716C7FA96}:1.0.4, {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16, {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76"
prefs.js - "keyword.URL" - "http://www.google.cz/#hl=cs&source=hp&q= "

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.278 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32]
"Description"=
"Path"=C:\WINDOWS\system32\npdeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
linkfilter@kaspersky.ru
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
yahoo.xml

C:\Documents and Settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\dymngkir.default\extensions\
{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
{ACAA314B-EEBA-48e4-AD47-84E31C44796C}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-03-26 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2010-03-06 798771]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll [2009-07-03 68112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{687578b9-7132-4a7a-80e4-30ee31099e03}]
uTorrentControl2 Toolbar - C:\Program Files\uTorrentControl2\prxtbuTor.dll [2011-05-09 176936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-05-10 329504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10 3834016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-05-10 59168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll [2009-08-05 264720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2012-05-10 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3FEE66E-E034-436a-86E4-9690573BEE8A}]
YTD Toolbar - C:\Program Files\YTD Toolbar\IE\6.2\ytdToolbarIE.dll [2012-07-26 1213832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
Yontoo - C:\Program Files\Yontoo\YontooIEClient.dll [2012-08-11 194928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2010-03-06 798771]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{687578b9-7132-4a7a-80e4-30ee31099e03} - uTorrentControl2 Toolbar - C:\Program Files\uTorrentControl2\prxtbuTor.dll [2011-05-09 176936]
{F3FEE66E-E034-436a-86E4-9690573BEE8A} - YTD Toolbar - C:\Program Files\YTD Toolbar\IE\6.2\ytdToolbarIE.dll [2012-07-26 1213832]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe [2010-08-20 311680]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-01-11 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-01-11 13666408]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2010-11-02 19580520]
""= []
"SearchSettings"=C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe [2012-07-26 1095560]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CooLWPC3"=C:\Program Files\CooL Wallpaper Changer\coolwpc.exe [2003-04-06 1008128]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2009-07-03 219664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-09-28 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-09-28 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"C:\Documents and Settings\Mončičák\Local Settings\Temp\Rar$EX00.859\utorrent.exe"="C:\Documents and Settings\Mončičák\Local Settings\Temp\Rar$EX00.859\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"G:\EasySetupAssistant\wr741n\EasySetupAssistant.exe"="G:\EasySetupAssistant\wr741n\EasySetupAssistant.exe:*:Enabled:TP-LINK Easy Setup Assistant"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll

======List of files/folders created in the last 1 month======

2012-11-09 15:45:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2712808$
2012-11-09 15:44:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2731847$
2012-11-09 15:39:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2705219$
2012-09-26 21:18:31 ----D---- C:\Program Files\trend micro
2012-09-26 21:18:30 ----D---- C:\rsit
2012-09-25 16:07:15 ----D---- C:\Program Files\Yontoo
2012-09-25 16:07:06 ----D---- C:\Documents and Settings\All Users\Data aplikací\Tarma Installer
2012-09-25 16:06:22 ----D---- C:\Program Files\1ClickDownload
2012-09-23 21:54:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2736233$

======List of files/folders modified in the last 1 month======

2012-09-26 21:18:31 ----RD---- C:\Program Files
2012-09-26 21:18:04 ----D---- C:\WINDOWS\Prefetch
2012-09-26 21:10:26 ----D---- C:\WINDOWS\Temp
2012-09-26 18:44:22 ----D---- C:\WINDOWS\system32\CatRoot2
2012-09-26 18:36:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Kaspersky Lab
2012-09-26 13:28:10 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-09-26 11:20:23 ----D---- C:\Program Files\TuneUp Utilities 2010
2012-09-26 11:20:18 ----SHD---- C:\WINDOWS\Installer
2012-09-26 11:20:17 ----SHD---- C:\Config.Msi
2012-09-26 11:02:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2012-09-26 11:01:17 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-09-26 10:44:49 ----D---- C:\WINDOWS
2012-09-26 09:32:15 ----D---- C:\WINDOWS\system32
2012-09-26 09:32:13 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-09-26 09:10:47 ----D---- C:\Documents and Settings\Mončičák\Data aplikací\uTorrent
2012-09-26 08:50:57 ----D---- C:\WINDOWS\Debug
2012-09-25 13:43:00 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-09-25 08:42:00 ----D---- C:\Program Files\Mozilla Firefox
2012-09-24 20:42:13 ----D---- C:\Documents and Settings\Mončičák\Data aplikací\Skype
2012-09-23 23:10:56 ----SD---- C:\WINDOWS\Tasks
2012-09-23 22:28:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2012-09-23 22:26:55 ----HD---- C:\WINDOWS\inf
2012-09-23 22:26:43 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-09-23 22:26:41 ----D---- C:\Program Files\Internet Explorer
2012-09-23 22:25:43 ----HD---- C:\WINDOWS\$hf_mig$
2012-09-23 21:50:26 ----A---- C:\WINDOWS\system32\MRT.exe
2012-09-23 21:50:02 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2012-09-23 21:49:55 ----RD---- C:\Program Files\Skype
2012-09-11 16:47:28 ----D---- C:\WINDOWS\system32\CatRoot
2012-08-28 17:17:31 ----A---- C:\WINDOWS\system32\wininet.dll
2012-08-28 17:17:30 ----A---- C:\WINDOWS\system32\urlmon.dll
2012-08-28 17:17:29 ----A---- C:\WINDOWS\system32\url.dll
2012-08-28 17:17:29 ----A---- C:\WINDOWS\system32\occache.dll
2012-08-28 17:17:29 ----A---- C:\WINDOWS\system32\mstime.dll
2012-08-28 17:17:28 ----A---- C:\WINDOWS\system32\mshtmled.dll
2012-08-28 17:17:28 ----A---- C:\WINDOWS\system32\mshtml.dll
2012-08-28 17:17:22 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2012-08-28 17:17:21 ----A---- C:\WINDOWS\system32\msfeeds.dll
2012-08-28 17:17:21 ----A---- C:\WINDOWS\system32\licmgr10.dll
2012-08-28 17:17:21 ----A---- C:\WINDOWS\system32\jsproxy.dll
2012-08-28 17:17:19 ----A---- C:\WINDOWS\system32\iertutil.dll
2012-08-28 17:17:17 ----A---- C:\WINDOWS\system32\iepeers.dll
2012-08-28 17:17:17 ----A---- C:\WINDOWS\system32\ieframe.dll
2012-08-28 17:17:09 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2012-08-28 14:07:56 ----A---- C:\WINDOWS\system32\ie4uinit.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 kl1;Kl1; C:\WINDOWS\system32\drivers\kl1.sys [2009-06-15 128016]
R0 klbg;Kaspersky Lab Boot Guard Driver; C:\WINDOWS\system32\drivers\klbg.sys [2008-12-15 33808]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-06-07 717296]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-09-28 77568]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-07-05 218688]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2010-03-06 296976]
R2 acedrv11;acedrv11; \??\C:\WINDOWS\system32\drivers\acedrv11.sys []
R2 rspndr;Odpovídající zařízení zjišťování topologie linkové vrstvy; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2009-09-28 62848]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-11-02 6188648]
R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:\WINDOWS\system32\DRIVERS\klim5.sys [2009-05-13 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2009-05-16 19472]
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys [2009-02-24 116736]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-01-12 10276768]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-08-07 98944]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 DumpDrv;Crash Dump Driver; C:\WINDOWS\system32\drivers\DumpDrv.sys [2009-09-28 9472]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 Asushwio;Asushwio; \??\G:\Bin\Asushwio.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 PAC207;VideoCAM GF112; C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-04-08 162176]
S3 Revoflt;Revoflt; C:\WINDOWS\system32\DRIVERS\revoflt.sys [2009-12-30 27064]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-22 32384]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2009-09-28 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-09-28 82944]
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2009-09-28 133632]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2012-07-26 794560]
R2 AVP;Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe [2010-08-20 311680]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2012-05-10 153376]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-01-11 154216]
R2 STI Simulator;STI Simulator; C:\WINDOWS\System32\PAStiSvc.exe [2005-01-14 53248]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2009-11-17 1021256]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2009-09-28 14848]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2009-09-28 14848]
S2 gupdate1cabd3b195a07f2;Google Update Service (gupdate1cabd3b195a07f2); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-06 133104]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-06 133104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-25 114144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-03-06 435016]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2009-09-28 913920]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Doporucuji odinstalovat (pokud nepouzivate) toolbary (listy prohlizecu) v Přidat nebo odebrat programy

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
    
    netsvcs
    drivers32
    savembr:0
    
    /md5start
    atapi.sys
    autochk.exe
    cdrom.sys
    explorer.exe
    hal.dll
    scecli.dll
    services.exe
    svchost.exe
    tcpip.sys
    userinit.exe
    winlogon.exe
    /md5stop
    
    %systemroot%*.* /U /s
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    %SYSTEMDRIVE%\*.exe
    
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    
    %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
    %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
    %PROGRAMFILES%\Opera\opera.exe /md5
    %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5
    
    %SystemDrive%\PhysicalMBR.bin /md5 
    
    *crack* /s
    *keygen* /s
    *loader* /s
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
  • Pokud budou logy dlouhe (forum bude kricet o prekroceni maximalniho poctu znaku), tak je rozdelte do vice prispevku
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

mon.men
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 26 zář 2012 20:56

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#3 Příspěvek od mon.men »

Zatím to vypadá, že už první rada pomohla, odinstalovala jsem jakýsi program yontoo, který jsme v životě neviděla a CPU se výrazně snížilo. Pokud by potíže přetrvávaly, zksuím radu druhou a poté bych opět napsala.
Děkuji moc za radu

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#4 Příspěvek od vyosek »

OTL udelejte prosim i ted, jelikoz ten yontoo se hodne zazira do systemu a OTL nam jej odhali kde pripadne zustal, plus je tam spousta dalsich veci co nam brzdi PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

mon.men
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 26 zář 2012 20:56

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#5 Příspěvek od mon.men »

Tak jsem to provedla, ale napsalo mi to že to nemůže soubor OTL najít a otevřel se prázdný poznámkový blok (respektive dva prázdé poznámkové bloky).

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#6 Příspěvek od vyosek »

Zkuste jej udelat v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

mon.men
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 26 zář 2012 20:56

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#7 Příspěvek od mon.men »

Dobrý den, tak se mi to povedlo tady je extras:
OTL Extras logfile created on: 27.9.2012 14:15:58 - Run 1
OTL by OldTimer - Version 3.2.68.0 Folder = C:\Documents and Settings\Mončičák\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,42 Gb Available Physical Memory | 70,83% Memory free
3,85 Gb Paging File | 3,34 Gb Available in Paging File | 86,74% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48,83 Gb Total Space | 15,84 Gb Free Space | 32,43% Space Free | Partition Type: NTFS
Drive D: | 48,83 Gb Total Space | 14,56 Gb Free Space | 29,81% Space Free | Partition Type: NTFS
Drive E: | 184,06 Gb Total Space | 70,83 Gb Free Space | 38,48% Space Free | Partition Type: NTFS
Drive F: | 184,06 Gb Total Space | 6,82 Gb Free Space | 3,71% Space Free | Partition Type: NTFS
Drive H: | 29,87 Gb Total Space | 23,71 Gb Free Space | 79,39% Space Free | Partition Type: FAT32
Drive J: | 5,12 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: INTEL-A1EBF0423 | User Name: Mončičák | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_USERS\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\ICQ7.0\ICQ.exe" = C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.0\aolload.exe" = C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\ICQ7.0\ICQ.exe" = C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.0\aolload.exe" = C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
"C:\Documents and Settings\Mončičák\Local Settings\Temp\Rar$EX00.859\utorrent.exe" = C:\Documents and Settings\Mončičák\Local Settings\Temp\Rar$EX00.859\utorrent.exe:*:Enabled:µTorrent
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"G:\EasySetupAssistant\wr741n\EasySetupAssistant.exe" = G:\EasySetupAssistant\wr741n\EasySetupAssistant.exe:*:Enabled:TP-LINK Easy Setup Assistant
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP190_series" = Canon MP190 series MP Drivers
"{18A5DFF2-8A95-49F3-873F-743CB5549F3D}" = Canon ScanGear Starter
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java(TM) 6 Update 32
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims™ 2 Mazlíčci
"{49FC50FC-F965-40D9-89B4-CBFF80941033}" = Windows Movie Maker 2.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{546C143E-68DC-314D-97BC-1E454E3BA429}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY
"{5C648FDB-0138-4619-B66E-230EF53E8E2C}" = The Sims™ 2 Pro Teenagery Kolekce
"{5DE71D48-01EB-4BF2-A643-50FE6C9B6AC9}" = OpenOffice.org 3.2
"{5E65E94D-69F2-4850-9E93-6459C53A0F50}" = Microsoft .NET Framework 1.1 Czech Language Pack
"{6522C636-B04C-4333-9BEB-9E0C0B6350D6}" = The Sims™ 2 Koupelny a kuchyně Interiérový design Kolekce
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.7
"{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0}" = The Sims 2 Pro rodinnou zábavu - Kolekce
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = The Sims 2
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Ve světě podnikání
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = The Sims™ 2 Volný čas
"{88EB38EF-4D2C-436D-ABD3-56B232674062}" = ICQ7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University
"{90120000-0010-0405-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Czech) 12
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{0B7A4B67-2A38-42B1-9857-662FAB361E08}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{FDF9A959-241A-4662-A8DE-7DED9C22D160}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{A0AAD4D5-9F9C-49BB-AB64-0FD4695424E8}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{3FD35521-B8F1-4CE0-85E0-DC6CA1E01012}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{943B6738-4801-4982-90EC-0442EF7AEB16}" = Kaspersky Anti-Virus 2010
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}" = The Sims™ 2 Pro luxusní život - Kolekce
"{9F6208C3-8DED-4D72-812A-BA5B50EAF00A}" = San Fermín
"{A2C9CD1B-2551-3AED-B244-6698FB929FA6}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1029-7B44-A95000000001}" = Adobe Reader 9.5.1 - Czech
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 Service Pack 1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D335AC77-6F59-46D6-9082-F74A9F7E0FC3}" = Canon MP Drivers 7.0
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = jetAudio Basic VX
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Sims™ 2 Roční období
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = The Sims™ 2 Pojďme slavit! Kolekce
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = The Sims™ 2 Šťastnou cestu
"{FE3997D3-6B56-4AC4-A99C-9DDFC45359BF}" = TuneUp Utilities Language Pack (en-US)
"1ClickDownload" = 1ClickDownloader
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Alenka 2 - Kouzelná země" = Alenka 2 - Kouzelná země
"Anki" = Anki
"Ashampoo Burning Studio 2010_is1" = Ashampoo Burning Studio 2010
"Audacity_is1" = Audacity 1.2.6
"Brave Dwarves 2 Deluxe_is1" = Brave Dwarves 2 Deluxe 1.4
"CanonMyPrinter" = Canon Utilities My Printer
"CCleaner" = CCleaner
"Clownfish" = Clownfish for Skype
"CooLWPC3" = CooL Wallpaper Changer (odinstalovat)
"DAEMON Tools Lite" = DAEMON Tools Lite
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Free YouTube Download_is1" = Free YouTube Download 1.2
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.5.722
"Google Chrome" = Google Chrome
"InstallWIX_{943B6738-4801-4982-90EC-0442EF7AEB16}" = Kaspersky Anti-Virus 2010
"jetAudio 7.0.x Czech Language Pack" = jetAudio 7.0.x Czech Language Pack
"Kubik SMS DreamCom_is1" = Kubik SMS DreamCom 5.89
"Kukuxumusu ANTfermin Screensaver" = Kukuxumusu ANTfermin Screensaver
"Kukuxumusu Dinner Screensaver" = Kukuxumusu Dinner Screensaver
"Kukuxumusu Kaput Screensaver" = Kukuxumusu Kaput Screensaver
"Kukuxumusu Kosmos Screensaver" = Kukuxumusu Kosmos Screensaver
"Luxor 5th Passage 1.00" = Luxor 5th Passage 1.00
"Luxor: Amun Rising" = Luxor: Amun Rising
"Magic ISO Maker v5.4 (build 0239)" = Magic ISO Maker v5.4 (build 0239)
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft Silverlight" = Microsoft Silverlight
"Mozilla Firefox 15.0.1 (x86 cs)" = Mozilla Firefox 15.0.1 (x86 cs)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"Pohádkový příběh" = Pohádkový příběh
"ProtectDisc Driver 11" = ProtectDisc Driver, Version 11
"PrtScr_is1" = PrtScr 1.5
"Rome Puzzle_is1" = Rome Puzzle
"Totalcmd" = Total Commander (Remove or Repair)
"TuneUp Utilities" = TuneUp Utilities
"Turtle Odyssey 3-in-1" = Turtle Odyssey 3-in-1
"uTorrent" = µTorrent
"WinRAR archiver" = WinRAR
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Quest for Glory II" = Quest for Glory II

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 26.9.2012 5:20:18 | Computer Name = INTEL-A1EBF0423 | Source = MsiInstaller | ID = 1024
Description = Aktualizaci TuneUp Utilities 9.0.4300.7 produktu TuneUp Utilities
Language Pack (en-US) nebylo možné nainstalovat. Kód chyby: 1603. Instalační služba
systému Windows může vytvořit soubor protokolu s informacemi, které usnadní řešení
potíží při instalaci softwaru. Další informace naleznete na webu na adrese http://go.microsoft.com/fwlink/?LinkId=23127

Error - 26.9.2012 5:20:18 | Computer Name = INTEL-A1EBF0423 | Source = MsiInstaller | ID = 1024
Description = Aktualizaci TuneUp Utilities 9.0.4400.16 produktu TuneUp Utilities
Language Pack (en-US) nebylo možné nainstalovat. Kód chyby: 1603. Instalační služba
systému Windows může vytvořit soubor protokolu s informacemi, které usnadní řešení
potíží při instalaci softwaru. Další informace naleznete na webu na adrese http://go.microsoft.com/fwlink/?LinkId=23127

Error - 26.9.2012 5:20:18 | Computer Name = INTEL-A1EBF0423 | Source = MsiInstaller | ID = 1024
Description = Aktualizaci TuneUp Utilities 9.0.4500.27 produktu TuneUp Utilities
Language Pack (en-US) nebylo možné nainstalovat. Kód chyby: 1603. Instalační služba
systému Windows může vytvořit soubor protokolu s informacemi, které usnadní řešení
potíží při instalaci softwaru. Další informace naleznete na webu na adrese http://go.microsoft.com/fwlink/?LinkId=23127

Error - 26.9.2012 5:20:18 | Computer Name = INTEL-A1EBF0423 | Source = MsiInstaller | ID = 1024
Description = Aktualizaci TuneUp Utilities 9.0.4600.3 produktu TuneUp Utilities
Language Pack (en-US) nebylo možné nainstalovat. Kód chyby: 1603. Instalační služba
systému Windows může vytvořit soubor protokolu s informacemi, které usnadní řešení
potíží při instalaci softwaru. Další informace naleznete na webu na adrese http://go.microsoft.com/fwlink/?LinkId=23127

Error - 26.9.2012 5:20:18 | Computer Name = INTEL-A1EBF0423 | Source = MsiInstaller | ID = 1024
Description = Aktualizaci TuneUp Utilities 9.0.4700.23 produktu TuneUp Utilities
Language Pack (en-US) nebylo možné nainstalovat. Kód chyby: 1603. Instalační služba
systému Windows může vytvořit soubor protokolu s informacemi, které usnadní řešení
potíží při instalaci softwaru. Další informace naleznete na webu na adrese http://go.microsoft.com/fwlink/?LinkId=23127

Error - 26.9.2012 5:20:18 | Computer Name = INTEL-A1EBF0423 | Source = MsiInstaller | ID = 1024
Description = Aktualizaci TuneUp Utilities 9.0.6000.8 produktu TuneUp Utilities
Language Pack (en-US) nebylo možné nainstalovat. Kód chyby: 1603. Instalační služba
systému Windows může vytvořit soubor protokolu s informacemi, které usnadní řešení
potíží při instalaci softwaru. Další informace naleznete na webu na adrese http://go.microsoft.com/fwlink/?LinkId=23127

Error - 26.9.2012 5:20:18 | Computer Name = INTEL-A1EBF0423 | Source = MsiInstaller | ID = 1024
Description = Aktualizaci TuneUp Utilities 9.0.6010.7 produktu TuneUp Utilities
Language Pack (en-US) nebylo možné nainstalovat. Kód chyby: 1603. Instalační služba
systému Windows může vytvořit soubor protokolu s informacemi, které usnadní řešení
potíží při instalaci softwaru. Další informace naleznete na webu na adrese http://go.microsoft.com/fwlink/?LinkId=23127

Error - 26.9.2012 5:20:18 | Computer Name = INTEL-A1EBF0423 | Source = MsiInstaller | ID = 1024
Description = Aktualizaci TuneUp Utilities 9.0.6020.6 produktu TuneUp Utilities
Language Pack (en-US) nebylo možné nainstalovat. Kód chyby: 1603. Instalační služba
systému Windows může vytvořit soubor protokolu s informacemi, které usnadní řešení
potíží při instalaci softwaru. Další informace naleznete na webu na adrese http://go.microsoft.com/fwlink/?LinkId=23127

Error - 26.9.2012 5:20:18 | Computer Name = INTEL-A1EBF0423 | Source = MsiInstaller | ID = 1021
Description = Aktualizaci C:\Program Files\TuneUp Utilities 2010\UpdateWizard\package_9.0.2020.1_to_9.0.3000.136.msp
produktu TuneUp Utilities Language Pack (en-US) nebylo možné odebrat. Kód chyby:
1647. Instalační služba systému Windows může vytvořit soubor protokolu s informacemi,
které usnadní řešení potíží při instalaci softwaru. Další informace naleznete na
webu na adrese http://go.microsoft.com/fwlink/?LinkId=23127

Error - 26.9.2012 12:35:39 | Computer Name = INTEL-A1EBF0423 | Source = WmiAdapter | ID = 4099
Description = Otevření služby se nezdařil

[ OSession Events ]
Error - 11.1.2012 12:01:35 | Computer Name = INTEL-A1EBF0423 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6654.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 1024
seconds with 780 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 26.9.2012 12:35:38 | Computer Name = INTEL-A1EBF0423 | Source = Service Control Manager | ID = 7011
Description = Vypršel časový limit (30000 milisekund) čekání na odezvu transakce
služby nvsvc.

Error - 26.9.2012 12:35:38 | Computer Name = INTEL-A1EBF0423 | Source = Service Control Manager | ID = 7009
Description = Vypršel časový limit (30000 milisekund) čekání na připojení služby
Adaptér výkonu služby WMI.

Error - 26.9.2012 12:35:39 | Computer Name = INTEL-A1EBF0423 | Source = Service Control Manager | ID = 7000
Description = Služba Adaptér výkonu služby WMI neuspěla při spuštění v důsledku
následující chyby: %%1053

Error - 26.9.2012 12:35:59 | Computer Name = INTEL-A1EBF0423 | Source = Service Control Manager | ID = 7011
Description = Vypršel časový limit (30000 milisekund) čekání na odezvu transakce
služby TuneUp.UtilitiesSvc.

Error - 26.9.2012 13:40:09 | Computer Name = INTEL-A1EBF0423 | Source = atapi | ID = 262153
Description = Zařízení \Device\Ide\IdePort2 neodpovídá v periodě časového limitu.

Error - 26.9.2012 14:15:52 | Computer Name = INTEL-A1EBF0423 | Source = atapi | ID = 262153
Description = Zařízení \Device\Ide\IdePort2 neodpovídá v periodě časového limitu.

Error - 26.9.2012 14:27:04 | Computer Name = INTEL-A1EBF0423 | Source = atapi | ID = 262153
Description = Zařízení \Device\Ide\IdePort2 neodpovídá v periodě časového limitu.

Error - 26.9.2012 16:47:31 | Computer Name = INTEL-A1EBF0423 | Source = atapi | ID = 262153
Description = Zařízení \Device\Ide\IdePort2 neodpovídá v periodě časového limitu.

Error - 26.9.2012 16:55:42 | Computer Name = INTEL-A1EBF0423 | Source = atapi | ID = 262153
Description = Zařízení \Device\Ide\IdePort2 neodpovídá v periodě časového limitu.

Error - 27.9.2012 8:42:32 | Computer Name = INTEL-A1EBF0423 | Source = atapi | ID = 262153
Description = Zařízení \Device\Ide\IdePort2 neodpovídá v periodě časového limitu.


< End of report >

mon.men
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 26 zář 2012 20:56

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#8 Příspěvek od mon.men »

A tady OTL. Do neděle tu nebudu, poté se bduu počítači opět věnovat.
Předem děkuji za kontrolu.

OTL logfile created on: 27.9.2012 14:15:58 - Run 1
OTL by OldTimer - Version 3.2.68.0 Folder = C:\Documents and Settings\Mončičák\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,42 Gb Available Physical Memory | 70,83% Memory free
3,85 Gb Paging File | 3,34 Gb Available in Paging File | 86,74% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48,83 Gb Total Space | 15,84 Gb Free Space | 32,43% Space Free | Partition Type: NTFS
Drive D: | 48,83 Gb Total Space | 14,56 Gb Free Space | 29,81% Space Free | Partition Type: NTFS
Drive E: | 184,06 Gb Total Space | 70,83 Gb Free Space | 38,48% Space Free | Partition Type: NTFS
Drive F: | 184,06 Gb Total Space | 6,82 Gb Free Space | 3,71% Space Free | Partition Type: NTFS
Drive H: | 29,87 Gb Total Space | 23,71 Gb Free Space | 79,39% Space Free | Partition Type: FAT32
Drive J: | 5,12 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: INTEL-A1EBF0423 | User Name: Mončičák | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2012.09.26 22:12:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mončičák\Plocha\OTL.exe
PRC - [2012.09.25 08:41:26 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.11.08 16:13:42 | 003,490,304 | ---- | M] (JetAudio, Inc.) -- C:\Program Files\JetAudio\JetAudio.exe
PRC - [2009.11.17 11:17:38 | 000,486,216 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
PRC - [2009.11.17 11:15:36 | 001,021,256 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
PRC - [2009.09.28 15:33:17 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005.07.15 23:48:33 | 000,479,232 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Gmail Notifier\gnotify.exe
PRC - [2005.01.14 10:32:38 | 000,053,248 | ---- | M] () -- C:\WINDOWS\system32\PAStiSvc.exe
PRC - [2003.04.06 11:42:04 | 001,008,128 | ---- | M] (Pavel Chmelař) -- C:\Program Files\CooL Wallpaper Changer\coolwpc.exe


========== Modules (No Company Name) ==========

MOD - [2012.09.26 11:01:16 | 009,813,424 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll
MOD - [2012.09.25 08:41:20 | 002,244,064 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2010.03.06 15:08:35 | 000,798,771 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
MOD - [2009.11.09 19:38:46 | 000,319,488 | ---- | M] () -- C:\Program Files\WinRAR\rarlng.dll
MOD - [2008.05.15 18:13:28 | 000,279,040 | ---- | M] () -- C:\Program Files\JetAudio\jdl_exif.dll
MOD - [2006.10.17 20:13:40 | 000,057,410 | ---- | M] () -- C:\Program Files\JetAudio\JetCfg.dll
MOD - [2005.10.07 16:05:32 | 000,125,440 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2005.01.14 10:32:38 | 000,053,248 | ---- | M] () -- C:\WINDOWS\system32\PAStiSvc.exe


========== Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2012.09.25 08:41:22 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2010.08.20 19:11:44 | 000,311,680 | ---- | M] (Kaspersky Lab) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe -- (AVP)
SRV - [2010.03.06 15:12:45 | 000,435,016 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2009.11.17 11:15:36 | 001,021,256 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2009.11.17 11:12:10 | 000,030,024 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2005.01.14 10:32:38 | 000,053,248 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PAStiSvc.exe -- (STI Simulator)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- G:\Bin\Asushwio.sys -- (Asushwio)
DRV - [2011.07.05 19:23:39 | 000,218,688 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2010.11.02 20:36:26 | 006,188,648 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2010.06.07 22:05:39 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2010.03.06 12:22:20 | 000,296,976 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2010.02.03 15:56:56 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009.12.30 11:20:56 | 000,027,064 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009.11.18 08:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009.11.18 08:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009.10.14 08:24:44 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2009.09.28 15:38:48 | 000,009,472 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\dumpdrv.sys -- (DumpDrv)
DRV - [2009.06.15 15:01:00 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\kl1.sys -- (kl1)
DRV - [2009.05.16 21:59:44 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009.05.13 18:46:52 | 000,031,760 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2009.02.24 18:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2009.01.19 20:31:56 | 000,277,544 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\acedrv11.sys -- (acedrv11)
DRV - [2008.12.15 21:41:32 | 000,033,808 | ---- | M] (Kaspersky Lab) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\klbg.sys -- (klbg)
DRV - [2007.08.07 17:40:38 | 000,098,944 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2005.04.08 11:46:18 | 000,162,176 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pfc027.sys -- (PAC207)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search13.net/
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search13.net/
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search13.net/
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search13.net/
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=14672
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.cz/
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = cs
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 54 E6 5D D0 F0 DE CA 01 [binary data]
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search13.net/
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search13.net/
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes,DefaultScope = {2862F8CC-4A20-4902-A1ED-D9994190CE96}
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... orm=IE8SRC
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{2862F8CC-4A20-4902-A1ED-D9994190CE96}: "URL" = http://www.google.cz/search?q={searchTe ... {startPage}
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{A83E3183-417B-4F7D-9A84-B3690A240E01}: "URL" = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... =CT3072253
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{CB6CCA24-840C-4964-B9F1-3B63D75B693F}: "URL" = http://websearch.ask.com/redirect?clien ... 678E4EF19C
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\search13: "URL" = http://search13.net/search.php?q={searchTerms}
IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://www.google.cz/#hl=cs&source=hp&q= "
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=937811"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.cz/"
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.4
FF - prefs.js..extensions.enabledAddons: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledAddons: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:1.1
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.463
FF - prefs.js..extensions.enabledItems: noia2_option@kk.noia:3.76
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA96}:1.0.4
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76
FF - prefs.js..keyword.URL: "http://www.google.cz/#hl=cs&source=hp&q= "


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.25 08:41:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.05.10 16:49:56 | 000,000,000 | ---D | M]

[2010.03.06 13:06:20 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mončičák\Data aplikací\Mozilla\Extensions
[2012.09.26 22:20:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\0\extensions
[2012.09.26 22:22:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\dymngkir.default\extensions
[2011.09.29 15:51:45 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Documents and Settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\dymngkir.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.08.05 18:29:37 | 000,741,958 | ---- | M] () (No name found) -- C:\Documents and Settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\dymngkir.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012.09.25 22:28:19 | 000,270,876 | ---- | M] () (No name found) -- C:\Documents and Settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\dymngkir.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012.06.22 07:18:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.01.28 11:41:38 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010.03.06 13:19:34 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MONčIčáK\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\DYMNGKIR.DEFAULT\EXTENSIONS\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MONčIčáK\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\DYMNGKIR.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}.XPI
[2012.05.10 16:49:01 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010.03.06 12:13:20 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012.09.25 08:41:29 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.06.22 05:55:30 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2012.06.22 05:55:30 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2012.06.22 05:55:30 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2012.06.22 05:55:30 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2012.06.22 05:55:30 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U32 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\WINDOWS\system32\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Savings-Slider = C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.1_0\
CHR - Extension: uTorrentControl2 = C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\
CHR - Extension: Gmail = C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2001.10.25 14:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (WebTransBHO Class) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (WebTranslator) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O3 - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004..\Run: [CooLWPC3] C:\Program Files\CooL Wallpaper Changer\coolwpc.exe (Pavel Chmelař)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Mončičák\Data aplikací\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm File not found
O9 - Extra 'Tools' menuitem : StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm File not found
O9 - Extra Button: &Virtuální klávesnice - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O9 - Extra Button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O9 - Extra 'Tools' menuitem : Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
O9 - Extra Button: &Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_32)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE1F0B6D-9E15-40B5-81BE-80547FA52463}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (C:\Documents and Settings\All Users\Data aplikací\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe) - C:\Documents and Settings\All Users\Data aplikací\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mončičák\Data aplikací\CooLWPC Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.03.06 12:11:36 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2011.02.17 00:30:09 | 000,048,912 | R--- | M] (Electronic Arts) - J:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2010.11.23 02:09:03 | 000,000,052 | R--- | M] () - J:\Autorun.inf -- [ CDFS ]
O33 - MountPoints2\{bc61d874-b188-11e0-9aa6-001fc60b631c}\Shell - "" = AutoRun
O33 - MountPoints2\{bc61d874-b188-11e0-9aa6-001fc60b631c}\Shell\AutoRun\command - "" = J:\NokiaPCIA_Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2012.09.27 14:12:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mončičák\Plocha\Kamelot
[2012.09.26 22:12:40 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mončičák\Plocha\OTL.exe
[2012.09.26 21:18:31 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.09.26 21:18:30 | 000,000,000 | ---D | C] -- C:\rsit
[2012.09.26 19:51:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mončičák\Plocha\Nox Arcana
[2012.09.26 10:33:00 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Mončičák\Recent
[2012.09.26 10:22:29 | 051,622,242 | ---- | C] (ACE DESIGN Software ) -- C:\Documents and Settings\Mončičák\Plocha\ACEMCP603PRO.exe
[2012.09.25 16:07:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Tarma Installer
[2012.09.25 16:06:22 | 000,000,000 | ---D | C] -- C:\Program Files\1ClickDownload
[2011.12.04 21:09:04 | 002,138,112 | ---- | C] (Sierra) -- C:\Program Files\Pharaoh.exe
[2011.12.04 21:08:57 | 000,301,568 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Program Files\L3CODECP.ACM
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2012.11.09 15:58:58 | 000,226,408 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.09.27 14:19:16 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.09.27 14:05:00 | 000,000,492 | ---- | M] () -- C:\WINDOWS\tasks\Automatic troubleshooting.job
[2012.09.27 14:03:21 | 000,271,490 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2012.09.27 14:02:46 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.09.27 14:02:17 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012.09.27 14:02:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.09.27 09:25:27 | 005,760,590 | ---- | M] () -- C:\Documents and Settings\Mončičák\Data aplikací\CooLWPC Wallpaper.bmp
[2012.09.26 22:45:01 | 000,000,940 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012.09.26 22:12:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mončičák\Plocha\OTL.exe
[2012.09.26 22:03:57 | 000,045,677 | ---- | M] () -- C:\Documents and Settings\Mončičák\Plocha\Správce úloh systému Windows.jpg
[2012.09.26 21:12:51 | 000,781,383 | ---- | M] () -- C:\Documents and Settings\Mončičák\Plocha\RSIT.exe
[2012.09.26 19:50:22 | 077,531,890 | ---- | M] () -- C:\Documents and Settings\Mončičák\Plocha\Plants-vs.-Zombies.apk
[2012.09.26 11:01:17 | 000,696,240 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012.09.26 11:01:16 | 000,073,136 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012.09.26 10:23:07 | 051,622,242 | ---- | M] (ACE DESIGN Software ) -- C:\Documents and Settings\Mončičák\Plocha\ACEMCP603PRO.exe
[2012.09.26 10:20:37 | 002,404,768 | ---- | M] () -- C:\Documents and Settings\Mončičák\Plocha\Winamp_drevo.zip
[2012.09.26 09:32:16 | 000,441,750 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.09.26 09:32:16 | 000,438,322 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2012.09.26 09:32:16 | 000,083,042 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2012.09.26 09:32:16 | 000,071,686 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.09.25 22:49:58 | 000,324,415 | ---- | M] () -- C:\Documents and Settings\Mončičák\Plocha\rotacismy_a_sigmatismy_001.jpg
[2012.09.25 21:10:32 | 001,030,246 | ---- | M] () -- C:\Documents and Settings\Mončičák\Plocha\comparing older and younger siblings teching strategies.pdf
[2012.09.25 20:48:42 | 799,051,776 | ---- | M] () -- C:\Documents and Settings\Mončičák\Plocha\Pan-Nikdo-2009_kinotip.cz.avi
[2012.09.25 18:22:03 | 000,711,685 | ---- | M] () -- C:\Documents and Settings\Mončičák\Plocha\aschreie.pdf
[2012.09.25 17:33:23 | 000,001,694 | ---- | M] () -- C:\Documents and Settings\Mončičák\Plocha\vpn-muni.cz.pbk
[2012.09.23 23:01:09 | 000,041,984 | ---- | M] () -- C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012.09.27 14:19:16 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.09.26 22:03:57 | 000,045,677 | ---- | C] () -- C:\Documents and Settings\Mončičák\Plocha\Správce úloh systému Windows.jpg
[2012.09.26 21:12:50 | 000,781,383 | ---- | C] () -- C:\Documents and Settings\Mončičák\Plocha\RSIT.exe
[2012.09.26 19:46:00 | 077,531,890 | ---- | C] () -- C:\Documents and Settings\Mončičák\Plocha\Plants-vs.-Zombies.apk
[2012.09.26 10:20:28 | 002,404,768 | ---- | C] () -- C:\Documents and Settings\Mončičák\Plocha\Winamp_drevo.zip
[2012.09.25 22:49:58 | 000,324,415 | ---- | C] () -- C:\Documents and Settings\Mončičák\Plocha\rotacismy_a_sigmatismy_001.jpg
[2012.09.25 21:10:32 | 001,030,246 | ---- | C] () -- C:\Documents and Settings\Mončičák\Plocha\comparing older and younger siblings teching strategies.pdf
[2012.09.25 19:54:09 | 799,051,776 | ---- | C] () -- C:\Documents and Settings\Mončičák\Plocha\Pan-Nikdo-2009_kinotip.cz.avi
[2012.09.25 18:22:03 | 000,711,685 | ---- | C] () -- C:\Documents and Settings\Mončičák\Plocha\aschreie.pdf
[2012.09.25 17:33:01 | 000,001,694 | ---- | C] () -- C:\Documents and Settings\Mončičák\Plocha\vpn-muni.cz.pbk
[2012.06.03 18:13:47 | 005,760,590 | ---- | C] () -- C:\Documents and Settings\Mončičák\Data aplikací\CooLWPC Wallpaper.bmp
[2012.03.04 22:59:22 | 000,000,083 | ---- | C] () -- C:\WINDOWS\wwp.INI
[2012.02.15 14:29:42 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011.12.04 21:09:10 | 000,220,712 | ---- | C] () -- C:\Program Files\Uninst.isu
[2011.12.04 21:09:10 | 000,208,202 | ---- | C] () -- C:\Program Files\Trainer.exe
[2011.12.04 21:09:05 | 007,212,420 | ---- | C] () -- C:\Program Files\sound.pak
[2011.12.04 21:09:05 | 001,910,880 | ---- | C] () -- C:\Program Files\Pharaoh2.emp
[2011.12.04 21:09:05 | 000,590,127 | ---- | C] () -- C:\Program Files\Pharaoh_MM.eng
[2011.12.04 21:09:05 | 000,269,804 | ---- | C] () -- C:\Program Files\Pharaoh_Text.eng
[2011.12.04 21:09:05 | 000,095,744 | ---- | C] () -- C:\Program Files\SMACKW32.DLL
[2011.12.04 21:09:05 | 000,040,960 | ---- | C] () -- C:\Program Files\setupreg.exe
[2011.12.04 21:09:05 | 000,000,564 | ---- | C] () -- C:\Program Files\Pharaoh.inf
[2011.12.04 21:09:05 | 000,000,432 | ---- | C] () -- C:\Program Files\Sierra.inf
[2011.12.04 21:09:05 | 000,000,280 | ---- | C] () -- C:\Program Files\setup.bat
[2011.12.04 21:09:05 | 000,000,084 | ---- | C] () -- C:\Program Files\Pharaohmap.inf
[2011.12.04 21:09:05 | 000,000,039 | ---- | C] () -- C:\Program Files\Pharaoh.ini
[2011.12.04 21:09:04 | 000,331,776 | ---- | C] () -- C:\Program Files\mss32.dll
[2011.12.04 21:09:04 | 000,314,556 | ---- | C] () -- C:\Program Files\MissionEditorGuide.pdf
[2011.12.04 21:09:04 | 000,280,576 | ---- | C] () -- C:\Program Files\mss16.dll
[2011.12.04 21:09:04 | 000,126,976 | ---- | C] () -- C:\Program Files\MP3DEC.ASI
[2011.12.04 21:09:04 | 000,052,224 | ---- | C] () -- C:\Program Files\MSSEAX.M3D
[2011.12.04 21:09:04 | 000,049,664 | ---- | C] () -- C:\Program Files\MSSDS3DS.M3D
[2011.12.04 21:09:04 | 000,049,664 | ---- | C] () -- C:\Program Files\MSSDS3DH.M3D
[2011.12.04 21:09:04 | 000,049,152 | ---- | C] () -- C:\Program Files\MSSRSX.M3D
[2011.12.04 21:09:04 | 000,049,152 | ---- | C] () -- C:\Program Files\MSSA3D.M3D
[2011.12.04 21:09:04 | 000,032,768 | ---- | C] () -- C:\Program Files\MP3UNPAK.EXE
[2011.12.04 21:09:04 | 000,004,640 | ---- | C] () -- C:\Program Files\mssb16.tsk
[2011.12.04 21:09:04 | 000,003,819 | ---- | C] () -- C:\Program Files\MYTH.NFO
[2011.12.04 21:08:57 | 017,187,872 | ---- | C] () -- C:\Program Files\mission1.pak
[2011.12.04 21:08:57 | 000,000,067 | ---- | C] () -- C:\Program Files\Language.inf
[2011.12.04 21:08:56 | 000,204,861 | ---- | C] () -- C:\Program Files\customuninstall.dll
[2011.12.04 21:08:56 | 000,176,128 | ---- | C] () -- C:\Program Files\BINKW32.DLL
[2011.12.04 21:08:56 | 000,000,412 | ---- | C] () -- C:\Program Files\FILE_ID.DIZ
[2011.02.20 01:03:08 | 000,000,030 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2011.01.25 23:22:11 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD_Start.INI
[2010.12.26 22:52:28 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010.03.06 16:01:06 | 000,041,984 | ---- | C] () -- C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.03.06 12:13:51 | 000,064,200 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat

========== ZeroAccess Check ==========

[2010.03.06 12:07:07 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 08:51:56 | 001,499,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.09.28 15:33:18 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 08:52:06 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012.06.01 00:21:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\2DBoy
[2010.03.10 12:56:06 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2010.11.08 23:20:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\cerasus.media
[2012.06.13 13:39:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2012.06.12 21:58:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
[2010.03.06 15:08:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\LangSoft
[2010.12.27 13:53:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MumboJumbo
[2012.05.31 23:59:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2012.09.26 22:20:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Tarma Installer
[2012.03.04 22:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.03.06 15:12:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2010.10.23 16:16:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ubisoft
[2010.03.06 15:12:12 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2010.03.06 16:00:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\TuneUp Software
[2011.06.28 10:23:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\.anki
[2011.05.30 15:37:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\.matplotlib
[2011.07.05 22:06:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\.minecraft
[2012.05.31 21:19:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Audacity
[2012.06.19 14:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Awem
[2011.12.19 15:51:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Canon
[2010.11.08 23:20:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\cerasus.media
[2010.03.06 15:58:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\COWON
[2010.06.07 22:09:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\DAEMON Tools
[2012.07.13 20:17:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\DAEMON Tools Lite
[2012.06.13 11:51:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\DAEMON Tools Pro
[2011.09.29 15:58:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\DVDVideoSoft
[2011.09.29 15:51:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\DVDVideoSoftIEHelpers
[2010.03.08 13:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Expert SoftWorks
[2010.05.08 19:04:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\funkitron
[2012.07.06 23:36:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\ICQ
[2012.05.14 14:07:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\iSpring Solutions
[2012.02.02 11:19:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Jetdogs Studios
[2010.03.06 15:08:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\LangSoft
[2010.08.31 23:45:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Meridian93
[2010.12.27 13:53:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\MumboJumbo
[2010.04.15 23:08:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\OpenOffice.org
[2010.12.02 16:30:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\ProtectDisc
[2012.04.08 19:45:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Rovio
[2010.04.25 21:53:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\SecondLife
[2010.04.15 23:01:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Software602
[2010.03.06 15:12:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\TuneUp Software
[2012.09.26 09:10:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\uTorrent
[2010.03.06 16:38:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\V-Games
[2010.03.06 12:20:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Windows Desktop Search
[2012.08.05 18:22:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\wtxpcom

========== Purity Check ==========



========== Custom Scans ==========

< >
[2010.03.06 12:09:11 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2010.03.06 12:18:37 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2010.03.06 15:12:53 | 000,000,492 | ---- | C] () -- C:\WINDOWS\Tasks\Automatic troubleshooting.job
[2010.03.06 16:53:22 | 000,000,936 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2010.03.06 16:53:22 | 000,000,940 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2011.12.29 12:18:28 | 000,000,284 | ---- | C] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

< >

< >

< MD5 for: ATAPI.SYS >
[2009.09.28 15:48:24 | 017,815,748 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\dllcache\autochk.exe

< MD5 for: CDROM.SYS >
[2009.09.28 15:48:24 | 017,815,748 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.05.02 11:49:40 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\system32\dllcache\cdrom.sys
[2009.09.28 15:33:04 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2009.09.28 15:33:17 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=8AB626E4E4B289646E11311E66FB0B88 -- C:\WINDOWS\explorer.exe
[2009.09.28 15:33:17 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=8AB626E4E4B289646E11311E66FB0B88 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: HAL.DLL >
[2009.09.28 15:48:24 | 017,815,748 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2009.09.28 15:33:24 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=429B2A7E9569C19BFE58F71FC02DE220 -- C:\WINDOWS\system32\hal.dll

< MD5 for: SCECLI.DLL >
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2009.09.28 15:35:24 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\system32\dllcache\services.exe
[2009.09.28 15:35:24 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\system32\services.exe

< MD5 for: SVCHOST.EXE >
[2009.09.28 15:35:47 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=67E38B4A549833E02D4D1617B5DBC318 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2009.09.28 15:35:47 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=67E38B4A549833E02D4D1617B5DBC318 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2009.09.28 15:35:53 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=367DE8E5F638C091F49273144274F629 -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2009.09.28 15:35:53 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=367DE8E5F638C091F49273144274F629 -- C:\WINDOWS\system32\drivers\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009.09.28 15:36:09 | 000,509,440 | ---- | M] (Microsoft Corporation) MD5=4212BABCC4408B052193DABAD9A691AB -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2009.09.28 15:36:09 | 000,509,440 | ---- | M] (Microsoft Corporation) MD5=4212BABCC4408B052193DABAD9A691AB -- C:\WINDOWS\system32\winlogon.exe

< >

< %systemroot%*.* /U /s >
[24 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[1 C:\WINDOWS\system32\config\systemprofile\*.tmp files -> C:\WINDOWS\system32\config\systemprofile\*.tmp -> ]
[2 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\*.tmp files -> C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\*.tmp -> ]
[120 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >
[1996.09.16 04:00:00 | 000,202,240 | RH-- | M] (DreamWorks Interactive) -- C:\SETUP95.EXE

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2011.06.28 10:23:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\.anki
[2011.05.30 15:37:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\.matplotlib
[2011.07.05 22:06:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\.minecraft
[2010.12.05 19:25:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Adobe
[2012.01.01 19:41:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Apple Computer
[2012.05.31 21:19:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Audacity
[2012.06.19 14:33:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Awem
[2011.12.19 15:51:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Canon
[2010.11.08 23:20:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\cerasus.media
[2010.03.06 15:58:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\COWON
[2010.03.06 16:04:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\CyberLink
[2010.06.07 22:09:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\DAEMON Tools
[2012.07.13 20:17:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\DAEMON Tools Lite
[2012.06.13 11:51:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\DAEMON Tools Pro
[2011.09.29 15:58:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\DVDVideoSoft
[2011.09.29 15:51:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\DVDVideoSoftIEHelpers
[2010.03.08 13:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Expert SoftWorks
[2010.05.08 19:04:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\funkitron
[2010.03.06 16:43:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Google
[2010.08.30 15:39:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Hamachi
[2012.07.06 23:36:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\ICQ
[2010.03.06 12:20:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Identities
[2010.10.23 16:16:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\InstallShield
[2012.05.14 14:07:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\iSpring Solutions
[2012.02.02 11:19:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Jetdogs Studios
[2010.03.06 15:08:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\LangSoft
[2010.03.06 13:20:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Macromedia
[2010.08.31 23:45:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Meridian93
[2012.06.12 21:39:01 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Microsoft
[2010.03.06 13:06:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Mozilla
[2010.12.27 13:53:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\MumboJumbo
[2010.04.15 23:08:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\OpenOffice.org
[2010.12.02 16:30:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\ProtectDisc
[2010.04.23 14:00:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Real
[2012.04.08 19:45:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Rovio
[2010.04.25 21:53:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\SecondLife
[2012.09.24 20:42:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Skype
[2011.08.11 16:06:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\skypePM
[2010.04.15 23:01:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Software602
[2010.03.06 12:14:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Sun
[2010.03.06 15:12:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\TuneUp Software
[2012.09.26 09:10:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\uTorrent
[2010.03.06 16:38:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\V-Games
[2010.03.06 12:20:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\Windows Desktop Search
[2012.08.05 18:22:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mončičák\Data aplikací\wtxpcom

< %APPDATA%\*.exe /s >
[2011.03.28 11:01:10 | 002,833,568 | ---- | M] (Adobe Systems, Inc.) -- C:\Documents and Settings\Mončičák\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
[2012.06.12 21:39:01 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Mončičák\Data aplikací\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2010.04.25 21:53:35 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Mončičák\Data aplikací\SecondLife\logs\SecondLife.exec_marker

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job >
[2012.07.20 20:40:03 | 000,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2012.09.27 14:51:15 | 000,000,492 | ---- | M] () -- C:\WINDOWS\Tasks\Automatic troubleshooting.job
[2012.09.27 14:02:17 | 000,000,936 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2012.09.27 14:45:46 | 000,000,940 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009.06.15 15:01:00 | 000,128,016 | ---- | M] (Kaspersky Lab) Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\kl1.sys
[2009.05.16 21:59:44 | 000,019,472 | ---- | M] (Kaspersky Lab) Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\klmouflt.sys
[2010.06.07 22:05:39 | 000,717,296 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2010.03.06 12:57:40 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2010.03.06 12:57:40 | 001,101,824 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2010.03.06 12:57:40 | 000,487,424 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2012.09.26 11:01:17 | 000,696,240 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\system32\FlashPlayerApp.exe
[2012.09.26 11:01:16 | 000,073,136 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
[2012.11.09 15:58:58 | 000,226,408 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2012.09.27 14:03:21 | 000,271,490 | ---- | M] () -- C:\WINDOWS\system32\NvApps.xml
[2012.09.26 09:32:16 | 000,083,042 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2012.09.26 09:32:16 | 000,071,686 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2012.09.26 09:32:16 | 000,438,322 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2012.09.26 09:32:16 | 000,441,750 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2012.09.26 09:32:13 | 001,048,846 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2012.09.27 14:02:46 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >
[1996.09.16 04:00:00 | 000,202,240 | RH-- | M] (DreamWorks Interactive) -- C:\SETUP95.EXE

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CooLWPC3" = C:\Program Files\CooL Wallpaper Changer\coolwpc.exe /boot -- [2003.04.06 11:42:04 | 001,008,128 | ---- | M] (Pavel Chmelař)
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 08:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)

< >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2012.09.25 08:41:26 | 000,917,984 | ---- | M] (Mozilla Corporation) MD5=9C376F42BDE37F18D0A39AF7415D9BE6 -- C:\Program Files\Mozilla Firefox\firefox.exe

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2009.09.28 15:33:55 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\Program Files\Internet Explorer\IEXPLORE.EXE

< %PROGRAMFILES%\Opera\opera.exe /md5 >

< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2012.09.25 11:43:01 | 001,239,064 | ---- | M] (Google Inc.) MD5=6194CC4A71F51CF3E815252BB43AAC28 -- C:\Program Files\Google\Chrome\Application\chrome.exe

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.09.27 14:19:16 | 000,000,512 | ---- | M] () MD5=521E96BC9B86B94D1500AB75FCD7D7BF -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2010.12.27 13:52:26 | 000,357,986 | ---- | M] () -- \Program Files\Bejeweled 3\cached\sounds\firework_crackle.wav

< *keygen* /s >

< *loader* /s >
[2010.08.20 19:11:40 | 000,170,584 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\prloader.dll
[2012.05.15 09:59:24 | 000,072,638 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.gif
[2012.05.15 09:59:24 | 000,003,032 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.png
[2012.07.20 22:48:47 | 000,000,001 | ---- | M] () -- \Documents and Settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\dymngkir.default\{F0B1CEAC-7C0D-407c-B25E-623D7CBECCCB}\youtubedownloader.lock
[2012.09.26 12:00:11 | 000,000,381 | ---- | M] () -- \Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.1_0\loader_1036.js
[2012.07.01 23:39:05 | 000,000,673 | ---- | M] () -- \Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\ajax-loader.gif
[2012.09.26 11:00:14 | 000,003,784 | ---- | M] () -- \Documents and Settings\Mončičák\Local Settings\Temporary Internet Files\Content.IE5\4PQYUWR5\bundleloader[1].js
[2012.09.26 11:00:30 | 000,000,723 | ---- | M] () -- \Documents and Settings\Mončičák\Local Settings\Temporary Internet Files\Content.IE5\4PQYUWR5\downloaderror[1].js
[2012.09.26 11:00:30 | 000,001,174 | ---- | M] () -- \Documents and Settings\Mončičák\Local Settings\Temporary Internet Files\Content.IE5\YVWUZ8S2\downloader[1].js
[2010.11.25 22:19:12 | 000,008,192 | ---- | M] () -- \Program Files\Anki\_win32sysloader.pyd
[2002.10.31 10:31:44 | 000,032,768 | ---- | M] () -- \Program Files\Ballance cz portable 1.13\Plugins\VirtoolsLoaderR.dll
[2011.07.22 15:12:04 | 002,795,648 | ---- | M] () -- \Program Files\Common Files\DVDVideoSoft\Dll\DVSVideoDownloader.dll
[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.dll
[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.tlb
[2007.08.26 00:23:02 | 000,073,728 | ---- | M] () -- \Program Files\DVDVideoSoft\Free YouTube Download\HttpVideoDownloader.dll
[2011.07.22 15:28:10 | 000,042,144 | ---- | M] () -- \Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\DVDVideoSoft.DVSVideoDownloader.dll
[2008.01.03 15:46:51 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.0\imApp\theme\IMAGES\XtraPreloader\loader.jpg
[2008.01.03 15:46:51 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.0\imApp\theme\IMAGES\XtraPreloader\loader.swf
[2009.12.20 09:55:30 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.0\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png
[2008.01.03 15:46:51 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.0\imApp\theme\MUICoreLib\xtraLoader.swf
[2010.04.18 17:22:35 | 000,002,886 | ---- | M] () -- \Program Files\ICQ7.0\Xtraz\icq\content\babylon_feed\preloader01_b.swf
[2011.04.13 19:30:21 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.0\Xtraz\icq\content\icq_profile\preloader.html
[2011.02.28 19:42:28 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.0\Xtraz\icq\content\profile_forms\preloader.html
[2011.02.28 19:42:35 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.0\Xtraz\icq\content\profile_lightboxs\preloader.html
[2012.06.21 23:09:03 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.0\Xtraz\icq\content\rps\preloader02.swf
[2012.06.21 21:43:32 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.0\Xtraz\icq\content\slide-a-lama\preloader02.swf
[2010.08.27 22:28:37 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.0\Xtraz\icq\content\warsheep\preloader02.swf
[2010.08.27 22:32:31 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.0\Xtraz\icq\content\zoopaloola\preloader02.swf
[2010.03.06 18:58:16 | 000,552,798 | ---- | M] () -- \Program Files\ICQ7.0\Xtraz\icq\theme\game_center\loaderBkg.png
[2010.08.20 19:11:44 | 000,170,584 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\prloader.dll
[2009.07.03 16:34:22 | 000,000,673 | ---- | M] () -- \Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\Skin\images\wtb\loader.gif
[2010.02.17 05:44:10 | 000,006,308 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.py
[2010.04.15 23:07:37 | 000,021,504 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.dll
[2010.02.17 12:37:14 | 000,000,171 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.ini
[2010.04.15 23:07:41 | 000,029,696 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\bin\javaloader.uno.dll
[2010.02.18 02:06:56 | 000,003,872 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\java\unoloader.jar
[2009.09.25 15:00:00 | 000,001,849 | ---- | M] () -- \Program Files\TuneUp Utilities 2010\data\TuneUpUtilities.gadget\images\loader.gif
[2005.06.07 13:25:46 | 000,044,032 | ---- | M] () -- \Program Files\WinRAR\RarExtLoader.exe
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dllcache\dmloader.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2DAD076E
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:EDD903C5

< End of report >

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#9 Příspěvek od vyosek »

:arrow: Spustte znovu OTL
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :otl
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
    DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
    DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
    DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
    DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
    DRV - File not found [Kernel | On_Demand | Stopped] -- G:\Bin\Asushwio.sys -- (Asushwio)
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search13.net/
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search13.net/
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search13.net/
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search13.net/
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=14672
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.cz/
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = cs
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 54 E6 5D D0 F0 DE CA 01 [binary data]
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search13.net/
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search13.net/
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes,DefaultScope = {2862F8CC-4A20-4902-A1ED-D9994190CE96}
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{2862F8CC-4A20-4902-A1ED-D9994190CE96}: "URL" = http://www.google.cz/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{A83E3183-417B-4F7D-9A84-B3690A240E01}: "URL" = http://search.yahoo.com/search?fr=chr-g ... =937811&p={searchTerms}
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3072253
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\{CB6CCA24-840C-4964-B9F1-3B63D75B693F}: "URL" = http://websearch.ask.com/redirect?clien ... src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=T8&apn_dtid=YYYYYYYYCZ&apn_uid=614864fe-26a0-4ca3-9071-47d67c5be272&apn_sauid=1249EE29-2DAE-4E5E-86E8-E1678E4EF19C
    IE - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\SearchScopes\search13: "URL" = http://search13.net/search.php?q={searchTerms}
    FF - prefs.js..browser.search.defaultengine: "Ask.com"
    FF - prefs.js..browser.search.defaultenginename: "Yahoo"
    FF - prefs.js..browser.search.defaulturl: "http://www.google.cz/#hl=cs&source=hp&q= "
    FF - prefs.js..browser.search.order.1: "Ask.com"
    FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=937811"
    FF - prefs.js..browser.search.selectedEngine: "Yahoo"
    FF - prefs.js..browser.search.useDBForOrder: true
    FF - prefs.js..keyword.URL: "http://www.google.cz/#hl=cs&source=hp&q= "
    [2011.09.29 15:51:45 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Documents and Settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\dymngkir.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MONčIčáK\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\DYMNGKIR.DEFAULT\EXTENSIONS\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MONčIčáK\DATA APLIKACí\MOZILLA\FIREFOX\PROFILES\DYMNGKIR.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}.XPI
    CHR - Extension: uTorrentControl2 = C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\
    O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
    O3 - HKLM\..\Toolbar: (WebTranslator) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll ()
    O3 - HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
    O33 - MountPoints2\{bc61d874-b188-11e0-9aa6-001fc60b631c}\Shell - "" = AutoRun
    [2010.03.06 15:12:12 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
    [2010.03.06 12:09:11 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
    [2010.03.06 12:18:37 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
    [2010.03.06 15:12:53 | 000,000,492 | ---- | C] () -- C:\WINDOWS\Tasks\Automatic troubleshooting.job
    [2010.03.06 16:53:22 | 000,000,936 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    [2010.03.06 16:53:22 | 000,000,940 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    [2011.12.29 12:18:28 | 000,000,284 | ---- | C] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
    [24 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
    [2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
    [1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
    [1 C:\WINDOWS\system32\config\systemprofile\*.tmp files -> C:\WINDOWS\system32\config\systemprofile\*.tmp -> ]
    [2 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\*.tmp files -> C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\*.tmp -> ]
    @Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2DAD076E
    @Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:EDD903C5
    
    :services
    Application Updater
    gupdate1cabd3b195a07f2
    gupdatem
    
    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=-
    ""=-
    "SearchSettings"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"=-
    
    :files
    C:\Program Files\Common Files\Spigot
    C:\Program Files\YTD Toolbar
    C:\Program Files\DAEMON Tools Toolbar
    C:\Program Files\uTorrentControl2
    C:\Program Files\Application Updater
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [EMPTYJAVA]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

mon.men
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 26 zář 2012 20:56

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#10 Příspěvek od mon.men »

Dobrý den,
tady je log zobrazený po restartu:

All processes killed
========== OTL ==========
Service WDICA stopped successfully!
Service WDICA deleted successfully!
Service PDRFRAME stopped successfully!
Service PDRFRAME deleted successfully!
Service PDRELI stopped successfully!
Service PDRELI deleted successfully!
Service PDFRAME stopped successfully!
Service PDFRAME deleted successfully!
Service PDCOMP stopped successfully!
Service PDCOMP deleted successfully!
Service PCIDump stopped successfully!
Service PCIDump deleted successfully!
Service lbrtfdc stopped successfully!
Service lbrtfdc deleted successfully!
Service i2omgmt stopped successfully!
Service i2omgmt deleted successfully!
Service Changer stopped successfully!
Service Changer deleted successfully!
Service Asushwio stopped successfully!
Service Asushwio deleted successfully!
File G:\Bin\Asushwio.sys not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache| /E : value set successfully!
HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs| /E : value set successfully!
HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomizeSearch| /E : value set successfully!
HKU\S-1-5-21-1390067357-1708537768-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKEY_USERS\S-1-5-21-1390067357-1708537768-1177238915-1004\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1390067357-1708537768-1177238915-1004\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-1390067357-1708537768-1177238915-1004\Software\Microsoft\Internet Explorer\SearchScopes\{2862F8CC-4A20-4902-A1ED-D9994190CE96}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2862F8CC-4A20-4902-A1ED-D9994190CE96}\ not found.
Registry key HKEY_USERS\S-1-5-21-1390067357-1708537768-1177238915-1004\Software\Microsoft\Internet Explorer\SearchScopes\{A83E3183-417B-4F7D-9A84-B3690A240E01}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A83E3183-417B-4F7D-9A84-B3690A240E01}\ not found.
Registry key HKEY_USERS\S-1-5-21-1390067357-1708537768-1177238915-1004\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9}\ not found.
Registry key HKEY_USERS\S-1-5-21-1390067357-1708537768-1177238915-1004\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_USERS\S-1-5-21-1390067357-1708537768-1177238915-1004\Software\Microsoft\Internet Explorer\SearchScopes\{CB6CCA24-840C-4964-B9F1-3B63D75B693F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CB6CCA24-840C-4964-B9F1-3B63D75B693F}\ not found.
Registry key HKEY_USERS\S-1-5-21-1390067357-1708537768-1177238915-1004\Software\Microsoft\Internet Explorer\SearchScopes\{searchTerms}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{searchTerms}\ not found.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Yahoo" removed from browser.search.defaultenginename
Prefs.js: "http://www.google.cz/#hl=cs&source=hp&q= " removed from browser.search.defaulturl
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "chr-greentree_ff&ilc=12&type=937811" removed from browser.search.param.yahoo-fr
Prefs.js: "Yahoo" removed from browser.search.selectedEngine
Prefs.js: true removed from browser.search.useDBForOrder
Prefs.js: "http://www.google.cz/#hl=cs&source=hp&q= " removed from keyword.URL
C:\Documents and Settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\dymngkir.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}\chrome folder moved successfully.
C:\Documents and Settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\dymngkir.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\plugins folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Options folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\rssItem folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\popup folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\icons\useful_components folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\icons\urlGadget folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\icons folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\base64\searchBox folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\base64\rssItem folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\base64\ifarme folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\base64\icons folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\base64\dyamincMenu folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media\base64 folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Media folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\utils\interface folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\utils folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\usage folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\translation folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\toolbarsManager folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\toolbarInfo folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\settings folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\serviceMap folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\login folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\jsonData folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\feed folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\cookieMonster folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\ContextMenuService folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\aliasReplace folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\alerts folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services\404 folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\services folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\popup\view folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\popup\controller folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\popup folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\model folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\lib folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\xmlMenu\view folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\xmlMenu\model folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\xmlMenu\controller folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\xmlMenu folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\urlGadget\view folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\urlGadget\model folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\urlGadget\controller folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\urlGadget folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\multiRssItem\view folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\multiRssItem\model folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\multiRssItem\controller folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\multiRssItem folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\menuPanel\view folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\menuPanel\model folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\menuPanel\controller folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\menuPanel folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\gadgets\view folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\gadgets\model folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\gadgets folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\factories\view folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\factories\model folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\factories folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\dynamicMenu\view folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\dynamicMenu\model folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\dynamicMenu\controller folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\dynamicMenu\consts folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\dynamicMenu folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\contextMenu\view folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\contextMenu\model folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\contextMenu\controller folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\contextMenu folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\container folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\components\view\InjectScript folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\components\view folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\components\model folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\components\controller folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\components folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items\about folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\items folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\css folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\controller folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\compatibility folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\API\Toolbar folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\API\Component\view folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\API\Component\model folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\API\Component\controller folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\API\Component folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js\API folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\js folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\Css folder moved successfully.
C:\Documents and Settings\Mončičák\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0 folder moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ deleted successfully.
C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{BFC32E1D-EE75-4A48-BC60-104E11EE2431} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFC32E1D-EE75-4A48-BC60-104E11EE2431}\ deleted successfully.
C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll moved successfully.
Registry value HKEY_USERS\S-1-5-21-1390067357-1708537768-1177238915-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
File C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bc61d874-b188-11e0-9aa6-001fc60b631c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bc61d874-b188-11e0-9aa6-001fc60b631c}\ not found.
C:\Documents and Settings\All Users\Data aplikací\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} folder moved successfully.
C:\WINDOWS\Tasks\desktop.ini moved successfully.
C:\WINDOWS\Tasks\SA.DAT moved successfully.
C:\WINDOWS\Tasks\Automatic troubleshooting.job moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\WINDOWS\Tasks\AppleSoftwareUpdate.job moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1125.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP119F.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP12C4.tmp\mscorlib.dll deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP12C4.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP13F.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP19F.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1C60.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2000.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP214B.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2153.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2169.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP27D.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2AA.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2E89.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2EB2.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP386E.tmp\mscorlib.dll deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP386E.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP62D.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP85F.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP943.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9AA.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPC17.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPCA2.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPCEE.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE0B.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPE95.tmp folder deleted successfully.
C:\WINDOWS\Installer\MSI10C.tmp deleted successfully.
C:\WINDOWS\Installer\MSI118.tmp deleted successfully.
C:\WINDOWS\system32\CONFIG.TMP deleted successfully.
C:\WINDOWS\system32\config\systemprofile\nsv1085.tmp\NSISArray.dll deleted successfully.
C:\WINDOWS\system32\config\systemprofile\nsv1085.tmp folder deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\5D.tmp deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\CR_15DD0.tmp\SETUP_PATCH.PACKED.7Z deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\CR_15DD0.tmp folder deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:2DAD076E deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:EDD903C5 deleted successfully.
========== SERVICES/DRIVERS ==========
Error: No service named Application Updater was found to stop!
Service\Driver key Application Updater not found.
Service gupdate1cabd3b195a07f2 stopped successfully!
Service gupdate1cabd3b195a07f2 deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\{0228e555-4f9c-4e35-a3ec-b109a192b4c2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ctfmon.exe deleted successfully.
========== FILES ==========
File\Folder C:\Program Files\Common Files\Spigot not found.
File\Folder C:\Program Files\YTD Toolbar not found.
C:\Program Files\DAEMON Tools Toolbar\Resources folder moved successfully.
C:\Program Files\DAEMON Tools Toolbar folder moved successfully.
File\Folder C:\Program Files\uTorrentControl2 not found.
File\Folder C:\Program Files\Application Updater not found.
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temporary Internet Files folder emptied: 33170 bytes

User: Monèièák

User: Mončičák
->Temp folder emptied: 58621251 bytes
->Temporary Internet Files folder emptied: 3170492 bytes
->Java cache emptied: 170726 bytes
->FireFox cache emptied: 58696989 bytes
->Google Chrome cache emptied: 7146666 bytes
->Flash cache emptied: 2837839 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 851906 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5243843 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 414955550 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 548864 bytes

Total Files Cleaned = 527,00 mb


[EMPTYFLASH]

User: All Users

User: Default User

User: LocalService

User: Monèièák

User: Mončičák
->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


[EMPTYJAVA]

User: All Users

User: Default User

User: LocalService

User: Monèièák

User: Mončičák
->Java cache emptied: 0 bytes

User: NetworkService

Total Java Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.68.0 log created on 09302012_134725

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#11 Příspěvek od vyosek »

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Napiste co PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

mon.men
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 26 zář 2012 20:56

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#12 Příspěvek od mon.men »

Vše jsem udělala, ale pořád mi firefox.exe a avp.exe užírají notnou část z CPU (většinou na 100%) a pokud do toho ještě pustím hudbu, (ať v počítači a nebo na youtube) vše se seká. Do toho se mi ještě v přibližně stejnou dobu jako začal být pomalý počítač rozdělily všechny videa, která pustím na youtube apod. na dvě části a uprostřed je zelená čára. Chci se zeptat co s tím?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#13 Příspěvek od vyosek »

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

mon.men
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 26 zář 2012 20:56

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#14 Příspěvek od mon.men »

ComboFix 12-09-30.01 - Mončičák 30.09.2012 22:53:22.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1381 [GMT 2:00]
Spuštěný z: c:\documents and settings\Mončičák\Plocha\ComboFix.exe
AV: Kaspersky Anti-Virus *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Data aplikací\AudioDecoderFilterGraph.txt
c:\program files\Save
c:\program files\Save\highscore.jas
c:\program files\Save\Janos.dat
c:\program files\Save\Janos\autosave.sav
c:\program files\Save\Janos\My Egyptian City.sav
c:\program files\Save\Neshi.dat
c:\program files\Save\Neshi\autosave.sav
c:\program files\Save\Neshi\autosave_history.sav
c:\program files\Save\Neshi\autosave_replay.sav
c:\program files\Save\Neshi\Kleo 1.sav
c:\program files\Save\Neshi\My Egyptian City.sav
c:\program files\Save\Neshi\My Egyptian City10.sav
c:\program files\Save\Neshi\My Egyptian City11.sav
c:\program files\Save\Neshi\My Egyptian City12.sav
c:\program files\Save\Neshi\My Egyptian City13.sav
c:\program files\Save\Neshi\My Egyptian City14.sav
c:\program files\Save\Neshi\My Egyptian City15.sav
c:\program files\Save\Neshi\My Egyptian City15b.sav
c:\program files\Save\Neshi\My Egyptian City16.sav
c:\program files\Save\Neshi\My Egyptian City17.sav
c:\program files\Save\Neshi\My Egyptian City18.sav
c:\program files\Save\Neshi\My Egyptian City18b.sav
c:\program files\Save\Neshi\My Egyptian City19.sav
c:\program files\Save\Neshi\My Egyptian City2.sav
c:\program files\Save\Neshi\My Egyptian City20char.sav
c:\program files\Save\Neshi\My Egyptian City21.sav
c:\program files\Save\Neshi\My Egyptian City22.sav
c:\program files\Save\Neshi\My Egyptian City3.sav
c:\program files\Save\Neshi\My Egyptian City4.sav
c:\program files\Save\Neshi\My Egyptian City5.sav
c:\program files\Save\Neshi\My Egyptian City6.sav
c:\program files\Save\Neshi\My Egyptian City7.sav
c:\program files\Save\Neshi\My Egyptian City8.sav
c:\program files\Save\Neshi\My Egyptian City9.sav
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-28 do 2012-09-30 )))))))))))))))))))))))))))))))
.
.
2012-09-30 20:47 . 2012-09-30 20:47 -------- d-----w- c:\windows\system32\LogFiles
2012-09-30 11:47 . 2012-09-30 11:47 -------- d-----w- C:\_OTL
2012-09-27 12:19 . 2012-09-27 12:19 512 ----a-w- C:\PhysicalMBR.bin
2012-09-26 19:18 . 2012-09-26 19:21 -------- d-----w- c:\program files\trend micro
2012-09-26 19:18 . 2012-09-26 19:21 -------- d-----w- C:\rsit
2012-09-25 14:07 . 2012-09-26 20:20 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Tarma Installer
2012-09-25 14:06 . 2012-09-25 14:06 -------- d-----w- c:\program files\1ClickDownload
2012-09-25 06:41 . 2012-09-25 06:41 73696 ----a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-26 09:01 . 2012-04-04 16:37 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-26 09:01 . 2011-05-23 07:01 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-28 15:17 . 2009-09-28 13:36 920064 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:17 . 2009-09-28 13:34 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:17 . 2009-09-28 13:33 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2009-09-28 13:33 385024 ----a-w- c:\windows\system32\html.iec
2012-07-06 13:58 . 2009-09-28 13:33 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 13:59 . 2010-03-06 10:04 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 18:21 . 2009-09-28 13:36 1875072 ----a-w- c:\windows\system32\win32k.sys
2000-08-12 14:15 . 2011-12-04 19:09 280 ----a-w- c:\program files\setup.bat
2000-07-13 00:31 . 2011-12-04 19:09 208202 ----a-w- c:\program files\Trainer.exe
2000-07-12 20:35 . 2011-12-04 19:09 2138112 ----a-w- c:\program files\Pharaoh.exe
2000-07-12 20:08 . 2011-12-04 19:09 40960 ----a-w- c:\program files\setupreg.exe
2000-06-19 15:00 . 2011-12-04 19:08 204861 ----a-w- c:\program files\customuninstall.dll
2000-03-31 20:47 . 2011-12-04 19:08 301568 ----a-w- c:\program files\L3CODECP.ACM
1999-10-20 19:53 . 2011-12-04 19:09 95744 ----a-w- c:\program files\SMACKW32.DLL
1999-10-20 19:53 . 2011-12-04 19:09 52224 ----a-w- c:\program files\MSSEAX.M3D
1999-10-20 19:53 . 2011-12-04 19:09 49664 ----a-w- c:\program files\MSSDS3DS.M3D
1999-10-20 19:53 . 2011-12-04 19:09 49664 ----a-w- c:\program files\MSSDS3DH.M3D
1999-10-20 19:53 . 2011-12-04 19:09 49152 ----a-w- c:\program files\MSSRSX.M3D
1999-10-20 19:53 . 2011-12-04 19:09 49152 ----a-w- c:\program files\MSSA3D.M3D
1999-10-20 19:53 . 2011-12-04 19:09 4640 ----a-w- c:\program files\mssb16.tsk
1999-10-20 19:53 . 2011-12-04 19:09 331776 ----a-w- c:\program files\mss32.dll
1999-10-20 19:53 . 2011-12-04 19:09 280576 ----a-w- c:\program files\mss16.dll
1999-10-20 19:53 . 2011-12-04 19:09 126976 ----a-w- c:\program files\MP3DEC.ASI
1999-10-20 19:52 . 2011-12-04 19:08 176128 ----a-w- c:\program files\BINKW32.DLL
1999-10-19 10:34 . 2011-12-04 19:09 32768 ----a-w- c:\program files\MP3UNPAK.EXE
2012-09-25 06:41 . 2012-02-15 17:59 266720 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-09-28 . 66E217E5E009815E06BA4F632794B731 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CooLWPC3"="c:\program files\CooL Wallpaper Changer\coolwpc.exe" [2003-04-06 1008128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-01-11 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-11 13666408]
"RTHDCPL"="RTHDCPL.EXE" [2010-11-02 19580520]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2010-08-20 311680]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Data aplikací\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
"Clownfish"="c:\program files\Clownfish\Clownfish.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"CanonMyPrinter"=c:\program files\Canon\MyPrinter\BJMyPrt.exe /logon
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ7.0\\ICQ.exe"=
"c:\\Program Files\\ICQ7.0\\aolload.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [15.12.2008 21:41 33808]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [7.6.2010 22:05 717296]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [5.7.2011 19:23 218688]
R2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [19.1.2009 20:31 277544]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13.5.2009 18:46 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16.5.2009 21:59 19472]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [28.9.2009 15:38 9472]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13.7.2012 13:28 160944]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [14.11.2010 19:08 1691480]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [3.5.2012 13:57 114144]
S3 PAC207;VideoCAM GF112;c:\windows\system32\drivers\pfc027.sys [8.4.2005 11:46 162176]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [18.4.2010 18:32 27064]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
.
------- Doplňkový sken -------
.
uStart Page =
uDefault_Search_URL =
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant =
uCustomizeSearch =
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\documents and settings\Mončičák\Data aplikací\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} -
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Mončičák\Data aplikací\Mozilla\Firefox\Profiles\dymngkir.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - user.js: network.http.max-persistent-connections-per-server - 4
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-09-30 23:13
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2064)
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\PAStiSvc.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Celkový čas: 2012-09-30 23:21:16 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-09-30 21:21
.
Před spuštěním: Volných bajtů: 17 735 446 528
Po spuštění: Volných bajtů: 17 615 376 384
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /TUTag=CMV0H8 /Kernel=TUKernel.exe
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional (TuneUp Backup)" /noexecute=optin /fastdetect /TUTag=CMV0H8-BAK
.
- - End Of File - - E44E2906E3777FE95C08E8682C4A9B83

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosba o pomoc - 100% CPU, zpomalený počítač

#15 Příspěvek od vyosek »

Nastala nejaka zmena?
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno