Tak hotovo !
V programu LSPfix už xfire_lsp_10650.dll byl v pravém okně takže tam jsem nic neměnil.
Přikládám log z HJT a SDFix
------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:12:32, on 4.10.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Universal Shield 4.1\US30Service.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\WINDOWS\Logi_MwX.Exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\steam\steam.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\SmartDisk\FlashPath\sdstat.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Opera\Opera.exe
C:\Documents and Settings\Jarda\Plocha\Kryštof\Viry\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\TRANSLAT\WEBIE.DLL
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\TRANSLAT\WEBIE.DLL
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [anvshell] anvshell.exe
O4 - HKLM\..\Run: [LiveNote] livenote.exe
O4 - HKLM\..\Run: [Omnipage] "C:\Program Files\ScanSoft\OmniPageSE\opware32.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [systemidle] stemIdle.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [System32 Spool ] winint.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [MSN Messanger] msnmsng.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [systemidle] stemIdle.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [System32 Spool ] winint.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [MSN Messanger] msnmsng.exe (User 'Default user')
O4 - Startup: desktop(2)(2).ini
O4 - Startup: desktop(2).ini
O4 - Startup: desktop(3).ini
O4 - Global Startup: desktop(2)(2).ini
O4 - Global Startup: desktop(2).ini
O4 - Global Startup: desktop(3).ini
O4 - Global Startup: FlashPath Monitor.lnk = C:\Program Files\SmartDisk\FlashPath\sdstat.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Search - ?p=ZNfox000
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\TRANSLAT\WEBIE.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O15 - Trusted Zone: *.iframedollars.biz
O15 - Trusted Zone: *.iframedollars.biz (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: CW App KB R9 -
https://www.mojebanka.cz/jars/cwapp.cab
O16 - DPF: IB App KB R9 -
https://www.mojebanka.cz/jars/ibapp.cab
O16 - DPF: KB KTpro Pack -
https://www.mojebanka.cz/jars/kt_pro_v1101.cab
O16 - DPF: KB SH Pack -
https://www.mojebanka.cz/jars/sh_pack.cab
O16 - DPF: KTPro SP KB R9 -
https://www.mojebanka.cz/jars/ktpsp.cab
O16 - DPF: MIB Pack -
https://www.mojebanka.cz/jars/mib_pack_v1400.cab
O16 - DPF: SH App KB R9 -
https://www.mojebanka.cz/jars/shapp.cab
O16 - DPF: {0E8C12E2-5329-7ED2-1881-13296992E442} -
http://213.159.117.150/1/rdgCZ10.exe
O16 - DPF: {1230CB21-C88D-11CF-0000-000000000000} -
http://www.browserupdate.co.uk/cabs/cus ... iq0107.cab
O16 - DPF: {17403C87-B807-522F-03B1-5C8718D0ADAD} -
http://213.159.117.150/1/rdgCZ10.exe
O16 - DPF: {2E5583D0-9080-1F05-9A45-58A279C2660F} -
http://213.159.117.150/1/rdgCZ10.exe
O16 - DPF: {3DC6F52B-DB47-2503-66B4-41670D26AC9D} -
http://213.159.117.150/1/rdgCZ10.exe
O16 - DPF: {4583D395-934D-455E-3CD2-30C144F294DB} -
http://213.159.117.150/1/rdgCZ10.exe
O16 - DPF: {4BC54967-CD56-4191-9DD7-086CA61F2691} -
http://advnt01.com/dialer/czeck1_ver3.CAB
O16 - DPF: {50E43D86-A74D-11D0-98CE-004005249458} (AnimatedGif Control) -
https://www.mojebanka.cz/jars/confwiz/MVSGif.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {75E305ED-D351-5BCE-EB5D-2B0E59DE0817} -
http://213.159.117.150/1/rdgCZ10.exe
O16 - DPF: {76C20F22-42B6-5DE3-835D-36CB47C6069F} -
http://213.159.117.150/1/rdgCZ10.exe
O16 - DPF: {7B066B63-807A-7AE9-7920-0DF1692FAFCE} -
http://213.159.117.150/1/rdgCZ10.exe
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
http://www.netvenda.com/sites/games-cz/cz/games4.cab
O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B23E0CC} -
http://66.117.37.13/cza1767.exe
O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B23E0CD} -
http://66.117.37.13/cza1767.exe
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag 2000 (OOD2000) - O&O Software GmbH - C:\WINDOWS\system32\OOD2000.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: US30Service - Unknown owner - C:\Program Files\Universal Shield 4.1\US30Service.exe
O23 - Service: Network Security Service (NSS) (Ź%AF夶Ŕ¨) - Unknown owner - C:\WINDOWS\ieam.exe (file missing)
O24 - Desktop Component 0: (no name) - (no file)
--
End of file - 11720 bytes
-----------------------------------------------------------
SDFix: Version 1.107
Run by Jarda on źt 04.10.2007 at 15:53
Microsoft Windows XP [Verze 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\SYSTEM32\FTPUPD.EXE - Deleted
C:\WINDOWS\SYSTEM32\IEQF.EXE - Deleted
C:\WINDOWS\SYSTEM32\INTFFD~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\INTFSD~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\INTRON.EXE - Deleted
C:\WINDOWS\SYSTEM32\INTRON~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\IR.EXE - Deleted
C:\WINDOWS\SYSTEM32\SDKWA32.EXE - Deleted
C:\WINDOWS\SYSTEM32\USB.EXE - Deleted
C:\WINDOWS\SYSTEM32\WINOY.EXE - Deleted
C:\WINDOWS\SYSTEM32\CRXL32.DLL - Deleted
C:\WINDOWS\SYSTEM32\IEVL.DLL - Deleted
C:\WINDOWS\SYSTEM32\KACNP.DLL - Deleted
C:\WINDOWS\SYSTEM32\MSWL32.DLL - Deleted
C:\WINDOWS\SYSTEM32\NEPBF.DLL - Deleted
C:\WINDOWS\system32\cmd.com - Deleted
C:\WINDOWS\system32\ping.com - Deleted
C:\WINDOWS\system32\tasklist.com - Deleted
C:\WINDOWS\system32\TFTP1060 - Deleted
C:\WINDOWS\system32\TFTP1084 - Deleted
C:\WINDOWS\system32\TFTP1096 - Deleted
C:\WINDOWS\system32\TFTP11296 - Deleted
C:\WINDOWS\system32\TFTP1252 - Deleted
C:\WINDOWS\system32\TFTP1412 - Deleted
C:\WINDOWS\system32\TFTP1628 - Deleted
C:\WINDOWS\system32\TFTP1700 - Deleted
C:\WINDOWS\system32\TFTP1740 - Deleted
C:\WINDOWS\system32\TFTP1784 - Deleted
C:\WINDOWS\system32\TFTP184 - Deleted
C:\WINDOWS\system32\TFTP2564 - Deleted
C:\WINDOWS\system32\TFTP2908 - Deleted
C:\WINDOWS\system32\TFTP3208 - Deleted
C:\WINDOWS\system32\TFTP3332 - Deleted
C:\WINDOWS\system32\TFTP3488 - Deleted
C:\WINDOWS\system32\TFTP364 - Deleted
C:\WINDOWS\system32\TFTP3708 - Deleted
C:\WINDOWS\system32\TFTP384 - Deleted
C:\WINDOWS\system32\TFTP3960 - Deleted
C:\WINDOWS\system32\TFTP3988 - Deleted
C:\WINDOWS\system32\TFTP4020 - Deleted
C:\WINDOWS\system32\TFTP4076 - Deleted
C:\WINDOWS\system32\TFTP4456 - Deleted
C:\WINDOWS\system32\TFTP4532 - Deleted
C:\WINDOWS\system32\TFTP5196 - Deleted
C:\WINDOWS\system32\TFTP5604 - Deleted
C:\WINDOWS\system32\TFTP5908 - Deleted
C:\WINDOWS\system32\TFTP5912 - Deleted
C:\WINDOWS\system32\TFTP760 - Deleted
C:\WINDOWS\system32\TFTP7820 - Deleted
C:\WINDOWS\system32\TFTP9392 - Deleted
C:\WINDOWS\system32\TFTP944 - Deleted
C:\WINDOWS\system32\tracert.com - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Xfire\\Xfire.exe"="C:\\Program Files\\Xfire\\Xfire.exe:*:Enabled:Xfire"
"C:\\Program Files\\Quake III Arena\\quake3.exe"="C:\\Program Files\\Quake III Arena\\quake3.exe:*:Enabled:quake3"
"C:\\Program Files\\Steam\\SteamApps\\fanat1c873\\counter-strike\\hl.exe"="C:\\Program Files\\Steam\\SteamApps\\fanat1c873\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Steam\\SteamApps\\fanat1c873\\condition zero\\hl.exe"="C:\\Program Files\\Steam\\SteamApps\\fanat1c873\\condition zero\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Steam\\SteamApps\\fanat1c873\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\fanat1c873\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Steam\\SteamApps\\fanat1c873\\day of defeat source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\fanat1c873\\day of defeat source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Steam\\SteamApps\\fanat1c873\\half-life 2 deathmatch\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\fanat1c873\\half-life 2 deathmatch\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\LucasArts\\Star Wars Battlefront II\\GameData\\BattlefrontII.exe"="C:\\Program Files\\LucasArts\\Star Wars Battlefront II\\GameData\\BattlefrontII.exe:*:Enabled:BattlefrontII"
"C:\\Program Files\\Soldat\\Soldat.exe"="C:\\Program Files\\Soldat\\Soldat.exe:*:Enabled:Soldat"
"C:\\Program Files\\NewSoft\\Presto! PageManager 6\\NetGroup.exe"="C:\\Program Files\\NewSoft\\Presto! PageManager 6\\NetGroup.exe:*:Enabled:NewSoft Network Group"
"C:\\Program Files\\The All-Seeing Eye\\eye.exe"="C:\\Program Files\\The All-Seeing Eye\\eye.exe:*:Enabled:Yahoo! All-Seeing Eye"
"C:\\Documents and Settings\\Jarda\\Plocha\\Kryçtof\\HrY\\warsow\\warsow.exe"="C:\\Documents and Settings\\Jarda\\Plocha\\Kryçtof\\HrY\\warsow\\warsow.exe:*:Enabled:Warsow"
"C:\\Program Files\\utorrent\\utorrent.exe"="C:\\Program Files\\utorrent\\utorrent.exe:*:Enabled:uTorrent"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enGB-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enGB-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enGB-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enGB-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enGB-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enGB-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enGB-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\LittleFighter2\\LF2_v1.9\\lf2.exe"="C:\\Program Files\\LittleFighter2\\LF2_v1.9\\lf2.exe:*:Enabled:lf2"
"C:\\Program Files\\Little Fighters 2.5\\lf2.5.exe"="C:\\Program Files\\Little Fighters 2.5\\lf2.5.exe:*:Enabled:lf2.5"
"C:\\Program Files\\World of Warcraft\\Repair.exe"="C:\\Program Files\\World of Warcraft\\Repair.exe:*:Enabled:Blizzard Repair Utility"
"C:\\Program Files\\World of Padman\\wop.exe"="C:\\Program Files\\World of Padman\\wop.exe:*:Enabled:wop"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"="C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe:*:Enabled:ET"
"C:\\Program Files\\RndLabs\\BaboViolent 2\\bv2.exe"="C:\\Program Files\\RndLabs\\BaboViolent 2\\bv2.exe:*:Enabled:bv2"
"C:\\Program Files\\QIP\\qip.exe"="C:\\Program Files\\QIP\\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\\Documents and Settings\\Jarda\\Plocha\\Kryçtof\\HrY\\FPScore\\ioquake3.exe"="C:\\Documents and Settings\\Jarda\\Plocha\\Kryçtof\\HrY\\FPScore\\ioquake3.exe:*:Enabled:ioquake3"
"C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"="C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"C:\\Documents and Settings\\Jarda\\Plocha\\HL2\\hl2.exe"="C:\\Documents and Settings\\Jarda\\Plocha\\HL2\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Jarda\\Plocha\\Kryçtof\\HrY\\FPScore\\FPScore.exe"="C:\\Documents and Settings\\Jarda\\Plocha\\Kryçtof\\HrY\\FPScore\\FPScore.exe:*:Enabled:FPScore"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Fri 10 Dec 2004 85 A.SH. --- "C:\WINDOWS\crnq32.exe"
Fri 10 Dec 2004 85 A.SH. --- "C:\WINDOWS\crnq32(2).exe"
Wed 31 Jul 2002 235 A.SH. --- "C:\WINDOWS\WSYS049.SYS"
Sun 21 Nov 2004 235 A.SH. --- "C:\WINDOWS\WSYS049(2).SYS"
Wed 13 Oct 2004 1,694,208 ...H. --- "C:\Program Files\Messenger\msmsgs.exe"
Sun 12 Jun 2005 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sun 3 Oct 2004 23,552 ...H. --- "C:\Documents and Settings\Jarda\Data aplikacˇ\Microsoft\Word\~WRL0004.tmp"
Thu 22 Feb 2007 43,201 A..HR --- "C:\Documents and Settings\Jarda\Data aplikacˇ\NSBackup\PageManager 6\PM60DB.DB.bak"
Fri 15 Jun 2007 888 ...HR --- "C:\Documents and Settings\Jarda\Data aplikacˇ\SecuROM\UserData\securom_v7_01.bak"
Mon 26 Jun 2006 83,456 ...H. --- "C:\Documents and Settings\Jarda\Plocha\Kryçtof\Lineage ][\~WRL0004.tmp"
Mon 4 Dec 2000 126,976 ...H. --- "C:\Documents and Settings\Jarda\Plocha\Kryçtof\QUAKE\Quake 3 Arena\Kopie - Quake III Arena\Team Arena Help\KeyCheckDLL.dll"
Finished!