dotaz na HijackThis

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43294
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: dotaz na HijackThis

Příspěvekod jaro3 » 20 led 2012 22:35

Potřeboval bych ještě vložit začátek logu z OTL..
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43294
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: dotaz na HijackThis

Příspěvekod jaro3 » 20 led 2012 23:10

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[2012.01.20 11:49:39 | 000,491,684 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.01.20 11:49:39 | 000,488,784 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2012.01.20 11:49:39 | 000,105,202 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2012.01.20 11:49:39 | 000,090,810 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2004.09.14 21:56:24 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004.09.14 21:56:23 | 000,491,684 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004.09.14 21:56:23 | 000,488,784 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2004.09.14 21:56:23 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2004.09.14 21:56:22 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2004.09.14 21:56:22 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004.09.14 21:56:21 | 000,105,202 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2004.09.14 21:56:21 | 000,090,810 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
@Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 179 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0295CBF7
@Alternate Data Stream - 162 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:FB1B13D8
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:890CC2F3
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:9FB286BF
@Alternate Data Stream - 12 bytes -> C:\Documents and Settings\R\Dokumenty:{1AA87861-906F-43B3-9815-7429EA2967F9}
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
c:\windows\Tasks\*.job
C:\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
C:\Documents and Settings\R\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Documents and Settings\All Users\Data aplikací\8164EED642.sys
C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
C:\WINDOWS\System32\d3d9caps.dat
C:\WINDOWS\mgxoschk.ini
C:\WINDOWS\System32\mlfcache.dat
C:\Documents and Settings\R\Data aplikací\ezpinst.exe
C:\Documents and Settings\R\Data aplikací\inst.exe
C:\Documents and Settings\R\Data aplikací\Search Settings
C:\Documents and Settings\R\Data aplikací\Spyware Terminator(2)
C:\WINDOWS\System32\imon1.dat
C:\WINDOWS\System32\drivers\sfi.dat

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" =-

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Aktualizuj javu:
Java SE Runtime Environment 7

Klikni na Accept License Agreement
Vyber si OS (Windows nebo Windows x64, Offline Installation)
jre-7-windows-i586-p.exe nebo
jre-7-windows-x64.exe
Stáhni ( download) a nainstaluj.
Ostatní javy odeber v přidat/odebrat programy.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
C:\WINDOWS\EmailComposerFree.INI
C:\WINDOWS\System32\SSCProt.dll

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

medicey44
nováček
Příspěvky: 30
Registrován: leden 12
Pohlaví: Muž
Stav:
Offline

Re: dotaz na HijackThis

Příspěvekod medicey44 » 20 led 2012 23:43

Dobrý večer pořád ještě otravuji jinak také mi to stahlo nějaký nový trojan při testování ,T-cleanerem.rar a jmenuje se Trojan:Win32/Orsam!rts a byl odebrán antivirem, microsoftsecurity Essentials.




OTL logfile created on: 20.1.2012 19:45:56 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\R\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1014.11 Mb Total Physical Memory | 502.07 Mb Available Physical Memory | 49.51% Memory free
2.39 Gb Paging File | 1.99 Gb Available in Paging File | 83.45% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 18.69 Gb Free Space | 33.43% Space Free | Partition Type: NTFS

Computer Name: DELL | User Name: R | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\R\Plocha\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
PRC - C:\Program Files\Nero\Tools\InCD\NBHRegInCDSrv.exe (Nero AG)
PRC - C:\Program Files\Nero\Tools\InCD\InCDSrv.exe (Nero AG)
PRC - C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe (Autodata Limited)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Acronis)
PRC - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe ()
PRC - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe ()
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\IObit\Advanced SystemCare 5\ASCv5ExtMenu.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\madexcept_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\madbasic_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 5\maddisAsm_.bpl ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Free Download Manager\fdmbtsupp.dll ()
MOD - C:\Program Files\Free Download Manager\iefdm2.dll ()
MOD - C:\Program Files\PSPad editor\PSPadShell.dll ()
MOD - C:\Program Files\Free Download Manager\FUM\fumcore.dll ()
MOD - C:\Program Files\WinRAR\rarlng.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe ()
MOD - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll ()
MOD - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe ()
MOD - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll ()
MOD - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\Plugins\iZoom\fx.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\Libeay32.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\IntStngs.dll ()
MOD - C:\WINDOWS\system32\LMablmpm.dll ()
MOD - C:\WINDOWS\system32\vorbis.dll ()
MOD - C:\WINDOWS\system32\ogg.dll ()


========== Win32 Services (SafeList) ==========

SRV - (SQLAgent$SONY_MEDIAMGR) -- File not found
SRV - (sdCoreService) -- File not found
SRV - (sdAuxService) -- File not found
SRV - (PEVSystemStart) -- File not found
SRV - (NOD32krn) -- File not found
SRV - (MSSQL$SONY_MEDIAMGR) -- File not found
SRV - (MatSvc) -- File not found
SRV - (IObitBarService) -- File not found
SRV - (cmdAgent) -- File not found
SRV - (CLPSLS) -- File not found
SRV - (Browser Defender Update Service) -- File not found
SRV - (AdvancedSystemCareService5) -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (WLANKEEPER) Intel(R) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel(R) Corporation)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) -- C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (PredatorACE) -- C:\Program Files\Predator2\PredatorACE.exe (Montpellier-Informatique)
SRV - (GeniusMouseService) -- C:\Genius\ioCentre\GMouseService.exe ()
SRV - (NMSAccessU) -- C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (NMSAccess) -- C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (NeroRegInCDSrv) -- C:\Program Files\Nero\Tools\InCD\NBHRegInCDSrv.exe (Nero AG)
SRV - (InCDSrv) -- C:\Program Files\Nero\Tools\InCD\InCDSrv.exe (Nero AG)
SRV - (Autodata Limited License Service) -- C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe (Autodata Limited)
SRV - (AcrSch2Svc) -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Acronis)
SRV - (PSI_SVC_2) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (CardBusService) -- C:\Program Files\Common Files\AVerMedia\Service\CardBusService.exe ()
SRV - (lmab_device) -- C:\WINDOWS\System32\LMabcoms.exe ()


========== Driver Services (SafeList) ==========

DRV - (MpKsl57216544) -- File not found
DRV - (AMON) -- C:\WINDOWS\system32\drivers\amon.sys (Eset )
DRV - (clwvd) -- C:\WINDOWS\system32\drivers\clwvd.sys (CyberLink Corporation)
DRV - (LMIRfsClientNP) -- C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (cmdGuard) -- C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) -- C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (NETwLx32) Ovladač adaptéru řady Intel(R) -- C:\WINDOWS\system32\drivers\NETwLx32.sys (Intel Corporation)
DRV - (LMIRfsDriver) -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (DrvAgent32) -- C:\WINDOWS\system32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (PCTCore) -- C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (gMouUsb) -- C:\WINDOWS\system32\drivers\gMouUsb.sys ()
DRV - (gHidPnp) -- C:\WINDOWS\system32\drivers\gHidPnp.sys ()
DRV - (InCDFs) -- C:\WINDOWS\system32\drivers\InCDFs.sys (Nero AG)
DRV - (InCDRec) -- C:\WINDOWS\system32\drivers\InCDRec.sys (Nero AG)
DRV - (InCDPass) -- C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (gMouPS2) -- C:\WINDOWS\system32\drivers\gMouPS2.sys ( Mouse Upfilter Driver )
DRV - (StarOpen) -- C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (NETw5x32) Intel(R) -- C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (npf) -- C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (MPE) -- C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (AVerBDA3x) -- C:\WINDOWS\system32\drivers\AVerBDA3x.sys (AVerMedia TECHNOLOGIES, Inc.)
DRV - (USBCCID) -- C:\WINDOWS\system32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w39n51) Intel(R) -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (SNPSTD3) USB PC Camera (SNPSTD3) -- C:\WINDOWS\system32\drivers\snpstd3.sys ()
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (MarvinBus) -- C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (PCLEPCI) -- C:\WINDOWS\system32\drivers\Pclepci.sys (Pinnacle Systems GmbH)
DRV - (NSNDIS5) -- C:\WINDOWS\system32\nsndis5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (OMCI) -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60341
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - No CLSID value found
IE - HKCU\..\URLSearchHook: {7757CBCC-0975-4b79-A519-90B142CA3A23} - No CLSID value found
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "MyAshampoo Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.49
FF - prefs.js..extensions.enabledItems: cs@dictionaries.addons.mozilla.org:1.0.2
FF - prefs.js..extensions.enabledItems: {ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}:2.7
FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.3.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.2.1
FF - prefs.js..extensions.enabledItems: {7f57cf46-4467-4c2d-adfa-0cba7c507e54}:0.19.7
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.1
FF - prefs.js..extensions.enabledItems: support@predictad.com:1.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@IObitBar.com/Plugin: C:\Program Files\IObitBar\toolbar\1.bin\NPi0Stub.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.0: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.3088: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.709: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.709: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.11.3006: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.709: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@stickypassword.com/Sticky Password: C:\Program Files\Sticky Password\npspAutofill.dll File not found
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\R\Data aplikací\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\R\Data aplikací\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\R\Local Settings\Data aplikací\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\R\Local Settings\Data aplikací\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009.06.24 16:01:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}: C:\Program Files\Crawler\Toolbar\firefox\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.03.13 17:25:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\i0ffxtbr@IObitBar.com: C:\Program Files\IObitBar\toolbar\1.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2011.01.20 19:14:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.01.13 13:02:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.01.16 13:52:40 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{54affe52-8223-453b-be1e-2fe2e250045c}: C:\Documents and Settings\R\Data aplikací\Lamantine\Sticky Password\spAutofill

[2011.08.06 12:46:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Extensions
[2009.03.09 16:07:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2011.08.06 12:46:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Extensions\MediaCoderPrefs
[2012.01.18 13:00:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions
[2010.05.19 09:34:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.01.28 15:14:59 | 000,000,000 | ---D | M] (PhotoPos Toolbar) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{5D0EC45B-D2E4-4DD0-A5B2-69DDEFE852A8}
[2011.12.20 18:46:47 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}(2)
[2011.11.25 12:28:29 | 000,000,000 | ---D | M] (iMacros for Firefox) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2012.01.08 16:24:40 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012.01.18 12:22:23 | 000,000,000 | ---D | M] (kikin plugin) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{AA994882-F391-4d2e-806F-8908DA4814ED}
[2010.11.20 15:02:17 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011.12.24 11:22:47 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011.10.21 10:24:32 | 000,000,000 | ---D | M] (Seznam lištiÄŤka) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[2011.12.13 17:50:52 | 000,000,000 | ---D | M] (Centrum.cz nastavenĂ) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2011.03.23 10:37:42 | 000,000,000 | ---D | M] (FoxLingo) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2009.12.11 15:44:26 | 000,000,000 | ---D | M] (FoxLingo) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}(2)
[2011.12.13 17:50:52 | 000,000,000 | ---D | M] (Centrum domĂ©novĂ˝ pomocnĂ­k) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\centrumpomocnik@centrum.cz
[2010.09.18 11:19:36 | 000,000,000 | ---D | M] (ÄŚeskĂ© slovnĂ­ky pro kontrolu pravopisu) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\cs@dictionaries.addons.mozilla.org
[2011.03.22 09:51:25 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\extensions\engine@conduit.com
[2009.08.09 14:50:07 | 000,000,687 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\ask.xml
[2009.05.30 17:46:02 | 000,002,235 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\askcom.xml
[2011.07.31 14:51:34 | 000,000,923 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\conduit.xml
[2012.01.13 10:25:55 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-1.xml
[2010.10.21 14:28:02 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-10.xml
[2010.10.28 19:01:31 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-11.xml
[2010.10.29 08:59:14 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-12.xml
[2011.11.08 14:31:49 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-13.xml
[2010.03.23 14:17:16 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-2.xml
[2010.04.02 13:35:05 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-3.xml
[2010.06.23 16:23:08 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-4.xml
[2010.06.27 13:57:34 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-5.xml
[2010.07.22 14:46:41 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-6.xml
[2010.07.24 09:48:44 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-7.xml
[2010.09.09 17:03:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-8.xml
[2010.09.16 16:54:52 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin-9.xml
[2010.01.22 22:24:51 | 000,000,955 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\icqplugin.xml
[2011.08.05 16:46:56 | 000,000,280 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\kikin-search.xml
[2009.08.03 11:40:37 | 000,002,264 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\seznam.xml
[2011.05.27 19:37:47 | 000,001,542 | ---- | M] () -- C:\Documents and Settings\R\Data aplikací\Mozilla\Firefox\Profiles\t86whsu2.default\searchplugins\web-search-powered-by-google.xml
[2012.01.13 13:02:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010.01.08 18:55:06 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.12.07 13:58:27 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012.01.13 13:02:18 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011.04.29 08:28:12 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}(2)
[2011.12.09 14:23:33 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}(3)
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\R\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\T86WHSU2.DEFAULT\EXTENSIONS\{7F57CF46-4467-4C2D-ADFA-0CBA7C507E54}.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\R\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\T86WHSU2.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\R\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\T86WHSU2.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\R\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\T86WHSU2.DEFAULT\EXTENSIONS\{EA614400-E918-4741-9A97-7A972FF7C30B}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\R\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\T86WHSU2.DEFAULT\EXTENSIONS\{EF62E1CE-D2A4-4CDD-B7EC-92B120366B66}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\R\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\T86WHSU2.DEFAULT\EXTENSIONS\CS@DICTIONARIES.ADDONS.MOZILLA.ORG
[2011.01.20 19:14:22 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011.12.21 08:39:32 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007.04.10 16:21:08 | 000,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007.03.22 19:23:30 | 000,017,248 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2012.01.03 14:10:44 | 000,182,672 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2007.12.21 03:00:00 | 000,144,720 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2009.01.23 13:09:04 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009.01.23 13:09:04 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009.01.23 13:09:04 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009.01.23 13:09:04 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009.01.23 13:09:04 | 000,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2007.12.21 03:00:00 | 000,081,920 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2007.03.10 00:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
[2007.07.26 13:05:16 | 000,001,329 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\crawlersrch.xml
[2010.10.18 13:14:12 | 000,002,037 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrchtweak.xml
[2011.12.21 06:38:17 | 000,002,364 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2011.12.21 07:21:58 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2011.12.21 07:21:58 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2011.12.21 07:21:58 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011.12.21 07:21:58 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.12.21 07:21:58 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2011.12.16 17:17:07 | 000,439,153 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 15105 more lines...
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (kikin Plugin) - {E601996F-E400-41CA-804B-CD6373A7EEE2} - C:\Program Files\kikin\ie_kikin.dll (kikin)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {5D0EC45B-D2E4-4DD0-A5B2-69DDEFE852A8} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {EFA17369-CDC0-4927-9AFC-BAAD1F96B2AE} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (&Adresa) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O3 - HKCU\..\Toolbar\WebBrowser: (&Adresa) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O3 - HKCU\..\Toolbar\WebBrowser: (&Odkazy) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [reset] C:\WINDOWS\reset.reg ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
O4 - HKCU..\Run: [UberIcon] C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe ()
O4 - Startup: C:\Documents and Settings\R\Nabídka Start\Programy\Po spuštění\RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe ()
O4 - Startup: C:\Documents and Settings\R\Nabídka Start\Programy\Po spuštění\UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: Crawler Search - tbr:iemenu File not found
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\R\Data aplikací\DVDVideoSoftIEHelpers\youtubedownload.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\R\Data aplikací\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Stáhnout Free Download Managerem - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Stáhnout video Free Download Managerem - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Stáhnout vše Free Download Managerem - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Stáhnout vybrané Free Download Managerem - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Translate this web page with Babylon - Reg Error: Value error. File not found
O8 - Extra context menu item: Translate with Babylon - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : My kikin - {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - C:\Program Files\kikin\ie_kikin.dll (kikin)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\wshbth.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tbr - No CLSID value found
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)

medicey44
nováček
Příspěvky: 30
Registrován: leden 12
Pohlaví: Muž
Stav:
Offline

Re: dotaz na HijackThis

Příspěvekod medicey44 » 20 led 2012 23:45

Další část,nevím zda to bude stačit,a děkuji,Rudolf.



O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) -C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) -C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") -C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - (%SystemRoot%\System32\dimsntfy.dll) - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - (WgaLogon.dll) - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Proces mezipaměti kategorií součástí - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\R\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\R\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) -C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) -C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) -C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) -C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) -C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) -C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) -C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) -C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) -C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{4e82b88f-f6c4-11de-94f6-0015c545b3f7}\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012.01.20 19:41:35 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\R\Plocha\OTL.exe
[2012.01.20 16:51:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Google Překladač hrozba viru_soubory
[2012.01.20 16:43:35 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\R\Recent
[2012.01.20 11:45:14 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2012.01.19 21:33:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Informace k upgrade STEREO 20 pro rok 2012 _ Aktuality _ Ježek software s.r.o. - Ekonomické systémy STEREO a DUEL_soubory
[2012.01.19 20:58:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Energie u Pramene Modifikovaný elektret ME_soubory
[2012.01.19 20:56:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Energie u Pramene První generátor VE v ČSR_soubory
[2012.01.19 20:53:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Energie u Pramene Získávání energie z „Nulového bodu“_soubory
[2012.01.19 16:03:02 | 004,628,200 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\R\Dokumenty\WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[2012.01.19 09:50:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\PicPick - ke stažení zdarma - Stahuj_cz_soubory
[2012.01.19 09:33:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Kde upravit automaticky spouštěné programy - JNP_cz_soubory
[2012.01.19 00:13:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Návod k použití ComboFixu_soubory
[2012.01.18 23:23:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\ŠkodlivýSoftware.cz - Návody - ComboFix_soubory
[2012.01.18 20:24:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Chytrý telefon s 3D displejem a fotoaparátem zlevnil na 6000 korun – Novinky_cz_soubory
[2012.01.17 16:24:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Jak připravit kvásek a základní těsta na chleba - Chléb a pečivo - www.iReceptar_cz_soubory
[2012.01.17 16:23:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Žitný kváskový chléb – recept pro pekárny - Naturlife_cz_soubory
[2012.01.17 16:22:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Jak děláme domácí chléb z kvásku a něco navíc o chlebu_soubory
[2012.01.17 15:36:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Domácí pekárna - Top recepty_cz_soubory
[2012.01.17 15:35:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Chléb pšenično-žitný z pivního kvásku - Top Recepty_cz_soubory
[2012.01.17 15:32:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Kvásek k pečení domácího chleba recept - Vareni_cz_soubory
[2012.01.17 15:30:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Kmínový chleba s kváskem2_soubory
[2012.01.17 15:29:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Kmínový chleba s kváskem_soubory
[2012.01.17 15:27:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Domácí chléb z kvásku, prima-recepty_cz_soubory
[2012.01.17 12:43:35 | 000,000,000 | ---D | C] -- C:\Program Files\PC Inspector File Recovery
[2012.01.17 12:43:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\PC Inspector File Recovery
[2012.01.17 12:40:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Vyhodili jste staré VHS Velká chyba _ Diit_soubory
[2012.01.17 09:51:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Průvodce Obnova souborů i preventivní zálohování - JNP_cz_soubory
[2012.01.16 23:07:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Uživatelský panel • Zobrazit zprávy_soubory
[2012.01.16 20:26:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Kondiciogram a biorytmy - roční přehled kondice_soubory
[2012.01.16 20:25:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Kondiciogram a biorytmy - kondiční kalendář_soubory
[2012.01.16 20:25:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Kondiciogram a biorytmy - biorytmické cykly_soubory
[2012.01.16 20:22:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Kondiciogram a biorytmy_soubory
[2012.01.16 20:21:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Věštírna online - Numerologie, datum narození, jména_soubory
[2012.01.16 19:50:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\0098. recept na kvásek z žitné mouky od Marietty - recept pro domácí pekárnu_soubory
[2012.01.16 18:32:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Plocha\Sigilie
[2012.01.16 17:19:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Jednoduché účetnictví a daňová evidence _ Účto - Tichý & spol 2_soubory
[2012.01.16 17:04:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Jednoduché účetnictví a daňová evidence _ Účto - Tichý & spol_soubory
[2012.01.16 15:57:00 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.01.16 14:37:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\VIRY.CZ • Zobrazit téma - Hijackthis skrateny navod_soubory
[2012.01.16 14:21:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\VIRY.CZ • Zobrazit téma - Návod Acronis True Image Home a Seagate DiscWizard_soubory
[2012.01.16 14:11:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Hijackthis_cz_soubory
[2012.01.16 11:57:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Application Data
[2012.01.16 11:19:57 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\R\Plocha\HiJackThis.exe
[2012.01.16 09:30:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\HijackThis Detailní prověrka počítače - JNP_cz_soubory
[2012.01.15 17:41:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Recepty pro domácí pekárny_soubory
[2012.01.15 17:39:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Recepty na domácí chleba z domácí pekárny _ ETA a_s_soubory
[2012.01.15 15:53:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\DeepBurner
[2012.01.15 15:40:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Data aplikací\DeepBurner
[2012.01.15 13:46:49 | 000,000,000 | ---D | C] -- C:\Program Files\Astonsoft
[2012.01.15 13:42:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\CCN - Visit our main website, www.carboncentralnetwork_com_soubory
[2012.01.14 21:14:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\jak vydělat peníze - Seznam_soubory
[2012.01.14 21:14:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\jak vydělat peníze 2_soubory
[2012.01.14 21:12:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Obchodní podmínky_soubory
[2012.01.14 16:51:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\ELPIDA - Pomáháme seniorům stát se samozřejmou, sebevědomou a respektovanou součástí společnosti_soubory
[2012.01.14 16:37:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\CEPELIK22_soubory
[2012.01.14 16:33:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Instalace a přeinstalace systému Windows 7_soubory
[2012.01.14 14:53:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Průvodce instalací Windows 2_soubory
[2012.01.14 14:32:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Nejlepší programy pro práci s diskovými oddíly - Živě_cz_soubory
[2012.01.14 14:30:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Naklonujte si harddisk. Zachráníte data i operační systém - iDNES_cz_soubory
[2012.01.14 13:07:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Using DiscWizard _ MaxBlast to back up non-Seagate... - Seagate Community Forums_soubory
[2012.01.14 11:00:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\5 profi tipů pro pokročilé čištění Windows - JNP_cz_soubory
[2012.01.13 14:55:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Information_soubory
[2012.01.13 12:39:49 | 000,400,864 | ---- | C] (Acronis) -- C:\WINDOWS\System32\drivers\timntr.sys
[2012.01.13 12:39:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Seagate
[2012.01.13 12:08:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Nadšenec si sám postavil hobití dům, vyšel ho na sto tisíc korun – Novinky_cz_soubory
[2012.01.13 11:40:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Podrobnosti k souboru ke stažení Windows Installer 4.5 Redistributable - Čeština_soubory
[2012.01.13 10:54:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Cestami rudého zla _ virtually_cz_soubory
[2012.01.13 00:16:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Pravěká dieta_soubory
[2012.01.12 18:38:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2012.01.12 18:30:00 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger
[2012.01.12 18:29:57 | 000,221,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\seo.dll
[2012.01.12 18:29:57 | 000,189,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpadm.dll
[2012.01.12 18:29:57 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\smtpapi.dll
[2012.01.12 18:29:57 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpapi.dll
[2012.01.12 18:29:57 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rwnh.dll
[2012.01.12 18:29:57 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rwnh.dll
[2012.01.12 11:56:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Microsoft Fix it Center Beta download - Slunečnice.cz - programy ke stažení zdarma_soubory
[2012.01.12 11:24:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Zakázání uživatelského rozhraní pro konfiguraci nástroje Obnovení systému (Tento článek může obsahovat odkazy na anglický obsah (dosud nepřeložený)_)_soubory
[2012.01.12 10:31:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Popis konzoly pro zotavení systému Windows XP pro pokročilé uživatele_soubory
[2012.01.11 23:51:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Super Ovladac
[2012.01.11 23:51:00 | 000,000,000 | ---D | C] -- C:\Program Files\Driver-Soft
[2012.01.11 23:08:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Mé přijaté soubory
[2012.01.11 23:08:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\FLEXnet
[2012.01.11 23:05:51 | 006,609,920 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\drivers\NETwLx32.sys
[2012.01.11 23:05:51 | 002,756,608 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\NETwLr32.dll
[2012.01.11 23:05:51 | 000,675,840 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\NETwLc32.dll
[2012.01.11 23:04:47 | 000,000,000 | ---D | C] -- C:\Intel
[2012.01.11 22:05:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\ioCentre
[2012.01.11 22:05:30 | 000,017,408 | ---- | C] ( Mouse Upfilter Driver ) -- C:\WINDOWS\System32\drivers\gMouPS2.sys
[2012.01.11 22:03:54 | 000,000,000 | ---D | C] -- C:\Genius
[2012.01.11 22:03:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Data aplikací\InstallShield
[2012.01.11 21:47:29 | 000,405,504 | ---- | C] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
[2012.01.11 21:47:28 | 001,601,536 | ---- | C] (SigmaTel, Inc.) -- C:\WINDOWS\System32\stlang.dll
[2012.01.11 21:47:27 | 004,952,064 | ---- | C] (SigmaTel, Inc.) -- C:\WINDOWS\System32\stacgui.cpl
[2012.01.11 21:44:47 | 000,270,336 | ---- | C] (SigmaTel, Inc.) -- C:\WINDOWS\System32\stacapi.dll
[2012.01.11 21:32:59 | 000,146,944 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\st325602.dll
[2012.01.11 21:07:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\super ovladač klíč - Hledat Googlem_soubory
[2012.01.11 20:53:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\SuperOvladac
[2012.01.11 20:05:21 | 000,021,336 | ---- | C] (IObit) -- C:\WINDOWS\System32\RegistryDefragBootTime.exe
[2012.01.11 19:10:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\IObit
[2012.01.11 19:09:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Advanced SystemCare 5
[2012.01.11 18:48:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Dell Latitude D620 1.8GHz Core 2 Duo 1GB 80GB CD-RW_DVD-ROM Laptop Notebook _ eParts and More_soubory
[2012.01.11 12:28:54 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ieencode.dll
[2012.01.11 12:28:54 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieencode.dll
[2012.01.11 12:28:53 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hscupd.exe
[2012.01.11 12:06:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Tipy a triky ve Windows_soubory
[2012.01.11 11:27:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\OpenWith.org V čem jen ten soubor otevřít - JNP_cz_soubory
[2012.01.11 11:25:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Aktualizace Windows XP Service Pack 3 « Optimalista - osobní rozvoj_soubory
[2012.01.11 11:02:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\VIRY.CZ • Zobrazit téma - 'XP anti-virus 2011' - nefungují automatické aktualizace_soubory
[2012.01.11 10:53:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Windows proces rstrui.exe _ rstrui_soubory
[2012.01.11 00:41:03 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2012.01.11 00:31:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Formulář pro vaši reakci není k dispozici_soubory
[2012.01.11 00:25:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Technická podpora Microsoft online_soubory
[2012.01.11 00:23:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Chybová zpráva Obnovení systému nelze vytvořit bod obnovení_soubory
[2012.01.11 00:16:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Jak nastavit bod obnovení systému v systému Windows XP_soubory
[2012.01.11 00:14:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Jak pomocí nástroje Obnovení systému pomocí služby WMI v systému Windows XP_soubory
[2012.01.10 23:13:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Jak udělat bod obnovení systému _ Odpovědi_cz_soubory
[2012.01.10 22:38:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Windows Vista - Zálohování Complete PC Backup 2. část_soubory
[2012.01.10 22:32:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\kde naleznu soubor _volume information_ - JNP_cz_soubory
[2012.01.10 22:29:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\volume information - Hledat Googlem_soubory
[2012.01.10 22:29:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\System volume information - Živě_cz_soubory
[2012.01.10 21:14:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\VIRY.CZ • Zobrazit téma - System Volume Information_soubory
[2012.01.10 21:11:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Jak se dostat ke složce System Volume Information_soubory
[2012.01.10 21:05:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Jak smazat „System Volume Information“ - Radek Hulán - oficiální web - MyEgo_cz_soubory
[2012.01.10 20:58:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Tip týdne Jak na zapomenuté heslo Windows - JNP_cz_soubory
[2012.01.10 18:13:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Plocha\MARKET agent
[2012.01.10 17:02:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Aukro.cz _ Krby Vytápění - nákup a prodej, skvělé ceny - aukce i prodej KupTeď!_soubory
[2012.01.10 16:57:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\ATMOS - 24. Odtahový ventilátor UCJ4C82 - DC75SE_soubory
[2012.01.10 14:56:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Plocha\Novinky
[2012.01.10 13:29:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Jak se přihlásit na účet administrator [vyřešeno] _ MojeWindows.cz - Windows XP _ Windows Vista _ Windows 7_soubory
[2012.01.10 11:58:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Poradna Garance odpovědi do 24 hodin! - JNP_cz_soubory
[2012.01.10 11:51:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Přihlášení k webům společnosti Mladá fronta a_s_soubory
[2012.01.09 23:49:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Wix - Create Your Website Today_soubory
[2012.01.09 23:29:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Google Překladač šablony_soubory
[2012.01.09 17:33:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Local Settings\Data aplikací\PCHealth
[2012.01.09 17:14:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Vymahači mají nové finty. Znásobují lidem dluhy - www.lidovky_cz_soubory
[2012.01.09 16:26:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Karel Gott věští budoucnost lidstva Celý svět čekají strašné věci. Řeknu vám jaké - Super_cz_soubory
[2012.01.09 15:32:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Návod na použití mužů. Znáte ho - ProŽeny.cz ...nejsi v tom sama_soubory
[2012.01.09 11:30:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DiskAnalyzer
[2012.01.09 11:04:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Extensions for Windows - The Unofficial Windows Upgrade_soubory
[2012.01.09 11:02:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Free Disk Analyzer proč nemáte volné místo _ ExtraWindows_soubory
[2012.01.09 10:42:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Nejstahovanější programy roku 2011 - Magazín Stahuj_cz_soubory
[2012.01.09 10:27:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\R\Dokumenty\Tisíce řidičů dostávají výzvy k zaplacení ručení na auta, která nevlastní – Novinky_cz_soubory
[2012.01.08 21:43:23 | 000,116,224 | ---- | C] (Xerox) -- C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2012.01.08 21:43:20 | 000,023,040 | ---- | C] (Xerox Corporation) -- C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2012.01.08 21:43:11 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xrxflnch.exe
[2012.01.08 21:43:04 | 000,099,865 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\xlog.exe
[2012.01.08 21:42:56 | 000,016,970 | ---- | C] (US Robotics MCD (Megahertz)) -- C:\WINDOWS\System32\dllcache\xem336n5.sys
[2012.01.08 21:42:54 | 000,019,455 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wvchntxx.sys
[2012.01.08 21:42:48 | 000,012,063 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wsiintxx.sys
[2012.01.08 21:42:20 | 000,008,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiacpi.sys
[2012.01.08 21:42:16 | 000,154,624 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\wlluc48.sys
[2012.01.08 21:42:13 | 000,034,890 | ---- | C] (Raytheon Corp.) -- C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2012.01.08 21:41:56 | 000,771,581 | ---- | C] (Rockwell) -- C:\WINDOWS\System32\dllcache\winacisa.sys
[2012.01.08 21:41:50 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiamsmud.dll
[2012.01.08 21:41:46 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiafbdrv.dll
[2012.01.08 21:41:34 | 000,701,386 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\wdhaalba.sys
[2012.01.08 21:41:33 | 000,023,615 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wch7xxnt.sys
[2012.01.08 21:41:32 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wceusbsh.sys
[2012.01.08 21:41:28 | 000,035,871 | ---- | C] (Winbond Electronics Corp.) -- C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2012.01.08 21:41:24 | 000,033,599 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv04nt.sys
[2012.01.08 21:41:23 | 000,019,551 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv02nt.sys
[2012.01.08 21:41:22 | 000,029,311 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv01nt.sys
[2012.01.08 21:41:19 | 000,011,775 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv05nt.sys
[2012.01.08 21:41:18 | 000,012,127 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv02nt.sys
[2012.01.08 21:41:17 | 000,012,415 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv01nt.sys
[2012.01.08 21:41:13 | 000,016,925 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w940nd.sys
[2012.01.08 21:41:09 | 000,019,016 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w926nd.sys
[2012.01.08 21:41:05 | 000,019,528 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w840nd.sys
[2012.01.08 21:40:55 | 000,064,605 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vvoice.sys
[2012.01.08 21:40:50 | 000,397,502 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vpctcom.sys
[2012.01.08 21:40:45 | 000,604,253 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\vmodem.sys
[2012.01.08 21:40:42 | 000,249,402 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\vinwm.sys
[2012.01.08 21:40:38 | 000,024,576 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\dllcache\viairda.sys
[2012.01.08 21:40:36 | 000,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\viaide.sys
[2012.01.08 21:40:28 | 000,687,999 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usrwdxjs.sys
[2012.01.08 21:40:24 | 000,765,884 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usrti.sys
[2012.01.08 21:40:20 | 000,113,762 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usrpda.sys
[2012.01.08 21:40:16 | 000,007,556 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usroslba.sys
[2012.01.08 21:40:12 | 000,224,802 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usr1807a.sys
[2012.01.08 21:40:08 | 000,794,399 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806v.sys
[2012.01.08 21:40:05 | 000,793,598 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806.sys
[2012.01.08 21:40:01 | 000,794,654 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1801.sys
[2012.01.08 21:39:58 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbser.sys
[2012.01.08 21:39:57 | 000,017,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbohci.sys
[2012.01.08 21:39:55 | 000,032,384 | ---- | C] (KLSI USA, Inc.) -- C:\WINDOWS\System32\dllcache\usb101et.sys
[2012.01.08 21:39:48 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxud32.dll
[2012.01.08 21:39:44 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu40.dll
[2012.01.08 21:39:41 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu22.dll
[2012.01.08 21:39:37 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu12.dll
[2012.01.08 21:39:34 | 000,050,688 | ---- | C] (UMAX DATA SYSTEMS INC.) -- C:\WINDOWS\System32\dllcache\umaxscan.dll
[2012.01.08 21:39:30 | 000,022,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxpcls.sys
[2012.01.08 21:39:27 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxp60.dll
[2012.01.08 21:39:23 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxcam.dll
[2012.01.08 21:39:20 | 000,212,480 | ---- | C] (UMAX DATA SYSTEMS INC.) -- C:\WINDOWS\System32\dllcache\um54scan.dll
[2012.01.08 21:39:16 | 000,216,576 | ---- | C] (UMAX DATA SYSTEMS INC.) -- C:\WINDOWS\System32\dllcache\um34scan.dll
[2012.01.08 21:39:13 | 000,036,736 | ---- | C] (Promise Technology, Inc.) -- C:\WINDOWS\System32\dllcache\ultra.sys
[2012.01.08 21:39:08 | 000,011,520 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\twotrack.sys
[2012.01.08 21:38:56 | 000,166,784 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxpm.sys
[2012.01.08 21:38:52 | 000,525,568 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxp.dll
[2012.01.08 21:38:49 | 000,159,232 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkbm.sys
[2012.01.08 21:38:45 | 000,440,576 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkb.dll
[2012.01.08 21:38:42 | 000,222,336 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3dm.sys
[2012.01.08 21:38:38 | 000,315,520 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3d.dll
[2012.01.08 21:38:34 | 000,034,375 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\tpro4.sys
[2012.01.08 21:38:31 | 000,043,008 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\tp4res.dll
[2012.01.08 21:38:30 | 000,082,944 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\tp4mon.exe
[2012.01.08 21:38:26 | 000,031,744 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\tp4.dll
[2012.01.08 21:38:19 | 000,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\toside.sys
[2012.01.08 21:38:16 | 000,230,912 | ---- | C] (Toshiba Corporation) -- C:\WINDOWS\System32\dllcache\tosdvd03.sys
[2012.01.08 21:38:12 | 000,241,664 | ---- | C] (Toshiba Corporation) -- C:\WINDOWS\System32\dllcache\tosdvd02.sys
[2012.01.08 21:38:09 | 000,028,232 | ---- | C] (TOSHIBA Corporation) -- C:\WINDOWS\System32\dllcache\tos4mo.sys
[2012.01.08 21:38:03 | 000,123,995 | ---- | C] (Tiger Jet Network) -- C:\WINDOWS\System32\dllcache\tjisdn.sys
[2012.01.08 21:37:55 | 000,138,528 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2012.01.08 21:37:52 | 000,081,408 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiul50.dll
[2012.01.08 21:37:50 | 000,149,376 | ---- | C] (M-Systems) -- C:\WINDOWS\System32\dllcache\tffsport.sys
[2012.01.08 21:37:45 | 000,017,129 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2012.01.08 21:37:42 | 000,037,961 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdk100b.sys
[2012.01.08 21:37:32 | 000,030,464 | ---- | C] (Toshiba Corporation) -- C:\WINDOWS\System32\dllcache\tbatm155.sys
[2012.01.08 21:37:25 | 000,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tandqic.sys
[2012.01.08 21:37:22 | 000,036,640 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2012.01.08 21:37:18 | 000,172,768 | ---- | C] (Number Nine Visual Technology) -- C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2012.01.08 21:37:09 | 000,032,640 | ---- | C] (LSI Logic) -- C:\WINDOWS\System32\dllcache\symc8xx.sys
[2012.01.08 21:37:06 | 000,016,256 | ---- | C] (Symbios Logic Inc.) -- C:\WINDOWS\System32\dllcache\symc810.sys
[2012.01.08 21:37:03 | 000,030,688 | ---- | C] (LSI Logic) -- C:\WINDOWS\System32\dllcache\sym_u3.sys
[2012.01.08 21:37:00 | 000,028,384 | ---- | C] (LSI Logic) -- C:\WINDOWS\System32\dllcache\sym_hi.sys
[2012.01.08 21:36:56 | 000,094,293 | ---- | C] (Perle Systems Ltd. ) -- C:\WINDOWS\System32\dllcache\sxports.dll
[2012.01.08 21:36:53 | 000,103,936 | ---- | C] (Perle Systems Ltd. ) -- C:\WINDOWS\System32\dllcache\sx.sys
[2012.01.08 21:36:49 | 000,003,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swusbflt.sys
[2012.01.08 21:36:46 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swpidflt.dll
[2012.01.08 21:36:43 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swpdflt2.dll
[2012.01.08 21:36:40 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sw_wheel.dll
[2012.01.08 21:36:37 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sw_effct.dll
[2012.01.08 21:36:31 | 000,155,648 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnprop.dll
[2012.01.08 21:36:28 | 000,053,248 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlncoin.dll
[2012.01.08 21:36:24 | 000,285,792 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnata.sys
[2012.01.08 21:36:20 | 000,017,024 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\stcusb.sys
[2012.01.08 21:36:14 | 000,048,736 | ---- | C] (3Com) -- C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2012.01.08 21:36:10 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srusd.dll
[2012.01.08 21:36:02 | 000,024,660 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\spxupchk.dll
[2012.01.08 21:35:56 | 000,061,824 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\speed.sys
[2012.01.08 21:35:53 | 000,106,584 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\spdports.dll
[2012.01.08 21:35:49 | 000,019,072 | ---- | C] (Adaptec, Inc.) -- C:\WINDOWS\System32\dllcache\sparrow.sys
[2012.01.08 21:35:45 | 000,007,552 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypvu1.sys
[2012.01.08 21:35:42 | 000,037,040 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypi.sys
[2012.01.08 21:35:39 | 000,114,688 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypi.dll
[2012.01.08 21:35:36 | 000,020,752 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonync.sys
[2012.01.08 21:35:33 | 000,009,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sonymc.sys
[2012.01.08 21:35:32 | 000,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sonyait.sys
[2012.01.08 21:35:28 | 000,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snyaitmc.sys
[2012.01.08 21:35:13 | 000,058,368 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smiminib.sys
[2012.01.08 21:35:08 | 000,147,200 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smidispb.dll
[2012.01.08 21:35:05 | 000,025,034 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2012.01.08 21:35:02 | 000,035,913 | ---- | C] (SMC) -- C:\WINDOWS\System32\dllcache\smcirda.sys
[2012.01.08 21:34:59 | 000,024,576 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smc8000n.sys
[2012.01.08 21:34:55 | 000,006,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbhc.sys
[2012.01.08 21:34:54 | 000,006,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbclass.sys
[2012.01.08 21:34:53 | 000,016,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbbatt.sys
[2012.01.08 21:34:50 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb3w.dll
[2012.01.08 21:34:47 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb0w.dll
[2012.01.08 21:34:43 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sma0w.dll
[2012.01.08 21:34:39 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm91w.dll
[2012.01.08 21:34:27 | 000,063,547 | ---- | C] (Symbol Technologies) -- C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2012.01.08 21:34:23 | 000,091,294 | ---- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) -- C:\WINDOWS\System32\dllcache\skfpwin.sys
[2012.01.08 21:34:20 | 000,095,018 | ---- | C] (SysKonnect GmbH.) -- C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2012.01.08 21:34:17 | 000,157,696 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisv256.dll
[2012.01.08 21:34:14 | 000,050,432 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisv.sys
[2012.01.08 21:34:13 | 000,032,768 | ---- | C] (SiS Corporation) -- C:\WINDOWS\System32\dllcache\sisnic.sys
[2012.01.08 21:34:10 | 000,238,592 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrv.dll
[2012.01.08 21:34:07 | 000,104,064 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrp.sys
[2012.01.08 21:34:04 | 000,150,144 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis6306v.dll
[2012.01.08 21:34:01 | 000,068,608 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis6306p.sys
[2012.01.08 21:33:57 | 000,252,032 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis300iv.dll
[2012.01.08 21:33:54 | 000,101,760 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis300ip.sys
[2012.01.08 21:33:35 | 000,161,728 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2012.01.08 21:33:32 | 000,018,400 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmld.sys
[2012.01.08 21:33:29 | 000,098,080 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2012.01.08 21:33:26 | 000,386,560 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiul50.dll
[2012.01.08 21:33:23 | 000,036,480 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\sfmanm.sys
[2012.01.08 21:33:17 | 000,006,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\serscan.sys
[2012.01.08 21:33:14 | 000,017,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sermouse.sys
[2012.01.08 21:33:09 | 000,006,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\seaddsmc.sys
[2012.01.08 21:33:07 | 000,011,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scsiscan.sys
[2012.01.08 21:33:04 | 000,011,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scsiprnt.sys
[2012.01.08 21:32:56 | 000,017,280 | ---- | C] (SCM Microsystems) -- C:\WINDOWS\System32\dllcache\scr111.sys
[2012.01.08 21:32:52 | 000,016,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scmstcs.sys
[2012.01.08 21:32:48 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2012.01.08 21:32:45 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2012.01.08 21:32:43 | 000,043,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sbp2port.sys
[2012.01.08 21:32:40 | 000,495,616 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\sblfx.dll
[2012.01.08 21:32:35 | 000,075,392 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3savmxm.sys
[2012.01.08 21:32:32 | 000,245,632 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3savmx.dll
[2012.01.08 21:32:29 | 000,077,824 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2012.01.08 21:32:26 | 000,198,400 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4.dll
[2012.01.08 21:32:23 | 000,061,504 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2012.01.08 21:32:20 | 000,179,264 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2012.01.08 21:32:17 | 000,210,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2012.01.08 21:32:14 | 000,062,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2012.01.08 21:32:11 | 000,041,216 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2012.01.08 21:32:08 | 000,182,272 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2012.01.08 21:32:05 | 000,166,720 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3m.sys
[2012.01.08 21:32:02 | 000,065,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\s3legacy.sys
[2012.01.08 21:31:58 | 000,082,432 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia450.dll
[2012.01.08 21:31:55 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia430.dll
[2012.01.08 21:31:51 | 000,029,696 | ---- | C] (RICOH Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw450ext.dll
[2012.01.08 21:31:50 | 000,028,160 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw430ext.dll
[2012.01.08 21:31:47 | 000,020,992 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8139.sys
[2012.01.08 21:31:44 | 000,019,017 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8029.sys
[2012.01.08 21:31:41 | 000,030,720 | ---- | C] (Conexant Systems Inc.) -- C:\WINDOWS\System32\dllcache\rthwcls.sys
[2012.01.08 21:31:36 | 000,009,728 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2012.01.08 21:31:32 | 000,003,840 | ---- | C] (Conexant Systems Inc.) -- C:\WINDOWS\System32\dllcache\rpfun.sys
[2012.01.08 21:31:29 | 000,079,104 | ---- | C] (Comtrol Corporation) -- C:\WINDOWS\System32\dllcache\rocket.sys
[2012.01.08 21:31:25 | 000,037,563 | ---- | C] (RadioLAN) -- C:\WINDOWS\System32\dllcache\rlnet5.sys
[2012.01.08 21:31:21 | 000,086,097 | ---- | C] (Xircom) -- C:\WINDOWS\Syst

medicey44
nováček
Příspěvky: 30
Registrován: leden 12
Pohlaví: Muž
Stav:
Offline

Re: dotaz na HijackThis

Příspěvekod medicey44 » 20 led 2012 23:48

Ještě zdravím jakou Jawu to mám stahnout,mám XP Home 32,a žádný odkaz podobný na moje xp jsem na tom vašem odkazu nenašel snad jenom na 7 a na 64,děkuji a promiňte mi vím toho docela málo,co se k čemu hodí,Rudolf

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43294
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: dotaz na HijackThis

Příspěvekod jaro3 » 21 led 2012 08:45

Rudolfe:

Dobrý večer pořád ještě otravuji jinak také mi to stahlo nějaký nový trojan při testování ,T-cleanerem.rar a jmenuje se Trojan:Win32/Orsam!rts a byl odebrán antivirem, microsoftsecurity Essentials.

Přeci zde píšu:
a použij i T-Cleaner
http://leteckaposta.cz/323994438
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš

pozn. před stažením T-Cleaneru a po dobu čištění deaktivuj antivir a antispyware ,následně T-Cleaner smaž a zapni si znovu antivir a antispyware.

T_Cleaner není žádná nákaza , ale některé viry ho jako nákazu stále mylně identifikují...

Ještě zdravím jakou Jawu to mám stahnout,mám XP Home 32,a žádný odkaz podobný na moje xp jsem na tom vašem odkazu nenašel snad jenom na 7 a na 64,děkuji a promiňte mi vím toho docela málo,co se k čemu hodí,Rudolf---
Stáhni si tuto:
jre-7-windows-i586.exe

Toto otestuj na Virustotal
C:\WINDOWS\EmailComposerFree.INI
C:\WINDOWS\System32\SSCProt.dll


Ten script udělej tento:

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
SRV - (SQLAgent$SONY_MEDIAMGR) -- File not found
SRV - (sdCoreService) -- File not found
SRV - (sdAuxService) -- File not found
SRV - (PEVSystemStart) -- File not found
SRV - (NOD32krn) -- File not found
SRV - (MSSQL$SONY_MEDIAMGR) -- File not found
SRV - (MatSvc) -- File not found
SRV - (IObitBarService) -- File not found
SRV - (cmdAgent) -- File not found
SRV - (CLPSLS) -- File not found
SRV - (Browser Defender Update Service) -- File not found
DRV - (MpKsl57216544) -- File not found
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - No CLSID value found
IE - HKCU\..\URLSearchHook: {7757CBCC-0975-4b79-A519-90B142CA3A23} - No CLSID value found
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "MyAshampoo Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.49
FF - prefs.js..extensions.enabledItems: {ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}:2.7
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.2.1
FF - prefs.js..extensions.enabledItems: {7f57cf46-4467-4c2d-adfa-0cba7c507e54}:0.19.7
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q="
FF - HKCU\Software\MozillaPlugins\@stickypassword.com/Sticky Password: C:\Program Files\Sticky Password\npspAutofill.dll File not found
O33 - MountPoints2\{4e82b88f-f6c4-11de-94f6-0015c545b3f7}\Shell - "" = AutoRun
[2012.01.20 11:49:39 | 000,491,684 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.01.20 11:49:39 | 000,488,784 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2012.01.20 11:49:39 | 000,105,202 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2012.01.20 11:49:39 | 000,090,810 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2004.09.14 21:56:24 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004.09.14 21:56:23 | 000,491,684 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004.09.14 21:56:23 | 000,488,784 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2004.09.14 21:56:23 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2004.09.14 21:56:22 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2004.09.14 21:56:22 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004.09.14 21:56:21 | 000,105,202 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2004.09.14 21:56:21 | 000,090,810 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
@Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 179 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0295CBF7
@Alternate Data Stream - 162 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:FB1B13D8
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:890CC2F3
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:9FB286BF
@Alternate Data Stream - 12 bytes -> C:\Documents and Settings\R\Dokumenty:{1AA87861-906F-43B3-9815-7429EA2967F9}
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
c:\windows\Tasks\*.job
C:\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
C:\Documents and Settings\R\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Documents and Settings\All Users\Data aplikací\8164EED642.sys
C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
C:\WINDOWS\System32\d3d9caps.dat
C:\WINDOWS\mgxoschk.ini
C:\WINDOWS\System32\mlfcache.dat
C:\Documents and Settings\R\Data aplikací\ezpinst.exe
C:\Documents and Settings\R\Data aplikací\inst.exe
C:\Documents and Settings\R\Data aplikací\Search Settings
C:\Documents and Settings\R\Data aplikací\Spyware Terminator(2)
C:\WINDOWS\System32\imon1.dat
C:\WINDOWS\System32\drivers\sfi.dat

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" =-

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

medicey44
nováček
Příspěvky: 30
Registrován: leden 12
Pohlaví: Muž
Stav:
Offline

Re: dotaz na HijackThis

Příspěvekod medicey44 » 21 led 2012 20:45

Dobrý večer,opět se přihlašuji s nějakými podivnostmi jo jinak zdravím,dal jsem to navržené do ,,OTL ,,vše šlo v pohodě až na ten restart ten tam stojí už asi 3hodiny a na monitoru je napsáno vypínání jinak se nic neděje ,žádný.log tam ty úkony které jste mi napsal dneska v8 hodin ráno jsem udělal,jo a ten,,Virustotal ,, také neukázal žádný výsledek,prozatím děkuji a co s tím stojícím NTB mám udělat abych něco nepokazil,Rudolf

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43294
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: dotaz na HijackThis

Příspěvekod jaro3 » 22 led 2012 09:06

Normálně zkus restartovat PC...

Pokud nebude log , podívej se do C:\_OTL\

Jinak to normálně celé proved znovu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

medicey44
nováček
Příspěvky: 30
Registrován: leden 12
Pohlaví: Muž
Stav:
Offline

Re: dotaz na HijackThis

Příspěvekod medicey44 » 22 led 2012 10:58

Dobré ráno a pěkný den,pozdě v noci jsem to musel vypnout tvrdě vypínačem na NTB pak jsem kliknul na ,,OTL ,,znova u udělalo to tento ,, log,, který přikládám a děkuji Rudolf.



All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Error: No service named SQLAgent$SONY_MEDIAMGR was found to stop!
Service\Driver key SQLAgent$SONY_MEDIAMGR not found.
File File not found not found.
Error: No service named sdCoreService was found to stop!
Service\Driver key sdCoreService not found.
File File not found not found.
Error: No service named sdAuxService was found to stop!
Service\Driver key sdAuxService not found.
File File not found not found.
Error: No service named PEVSystemStart was found to stop!
Service\Driver key PEVSystemStart not found.
File File not found not found.
Error: No service named NOD32krn was found to stop!
Service\Driver key NOD32krn not found.
File File not found not found.
Error: No service named MSSQL$SONY_MEDIAMGR was found to stop!
Service\Driver key MSSQL$SONY_MEDIAMGR not found.
File File not found not found.
Error: No service named MatSvc was found to stop!
Service\Driver key MatSvc not found.
File File not found not found.
Error: No service named IObitBarService was found to stop!
Service\Driver key IObitBarService not found.
File File not found not found.
Error: No service named cmdAgent was found to stop!
Service\Driver key cmdAgent not found.
File File not found not found.
Error: No service named CLPSLS was found to stop!
Service\Driver key CLPSLS not found.
File File not found not found.
Error: No service named Browser Defender Update Service was found to stop!
Service\Driver key Browser Defender Update Service not found.
File File not found not found.
Error: No service named MpKsl57216544 was found to stop!
Service\Driver key MpKsl57216544 not found.
File File not found not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{7757CBCC-0975-4b79-A519-90B142CA3A23} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7757CBCC-0975-4b79-A519-90B142CA3A23}\ not found.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "MyAshampoo Customized Web Search" removed from browser.search.defaultthis.engineName
Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl
Prefs.js: "Search the web (Babylon)" removed from browser.search.order.1
Prefs.js: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3 removed from extensions.enabledItems
Prefs.js: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.49 removed from extensions.enabledItems
Prefs.js: {ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}:2.7 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17 removed from extensions.enabledItems
Prefs.js: {20a82645-c095-46ed-80e3-08825760534b}:1.2.1 removed from extensions.enabledItems
Prefs.js: {7f57cf46-4467-4c2d-adfa-0cba7c507e54}:0.19.7 removed from extensions.enabledItems
Prefs.js: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.1 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 removed from extensions.enabledItems
Prefs.js: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15 removed from extensions.enabledItems
Prefs.js: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q=" removed from keyword.URL
Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@stickypassword.com/Sticky Password\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4e82b88f-f6c4-11de-94f6-0015c545b3f7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4e82b88f-f6c4-11de-94f6-0015c545b3f7}\ not found.
File C:\WINDOWS\System32\perfh009.dat not found.
File C:\WINDOWS\System32\perfh005.dat not found.
File C:\WINDOWS\System32\perfc005.dat not found.
File C:\WINDOWS\System32\perfc009.dat not found.
File C:\WINDOWS\System32\perfi009.dat not found.
File C:\WINDOWS\System32\perfh009.dat not found.
File C:\WINDOWS\System32\perfh005.dat not found.
File C:\WINDOWS\System32\perfi005.dat not found.
File C:\WINDOWS\System32\perfd005.dat not found.
File C:\WINDOWS\System32\perfd009.dat not found.
File C:\WINDOWS\System32\perfc005.dat not found.
File C:\WINDOWS\System32\perfc009.dat not found.
Unable to delete ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2 .
Unable to delete ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:0295CBF7 .
Unable to delete ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:FB1B13D8 .
Unable to delete ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:890CC2F3 .
Unable to delete ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:9FB286BF .
Unable to delete ADS C:\Documents and Settings\R\Dokumenty:{1AA87861-906F-43B3-9815-7429EA2967F9} .
Unable to delete ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8 .
File/Folder C:\WINDOWS\*.tmp not found.
File/Folder C:\WINDOWS\System32\*.tmp not found.
C:\WINDOWS\System32\Security.dll moved successfully.
File rity] not found.
File ptytemp] not found.
File art explorer] not found.
File boot] not found.

OTL by OldTimer - Version 3.2.31.0 log created on 01212012_172653

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43294
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: dotaz na HijackThis

Příspěvekod jaro3 » 22 led 2012 19:24

Jsou nějaké problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 110 hostů