Prosím o kontrolu logu, seká se PC. Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Ivey
Level 1.5
Level 1.5
Příspěvky: 123
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Prosím o kontrolu logu, seká se PC.

Příspěvekod Ivey » 13 led 2010 10:08

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:06:05, on 13.1.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Seznam.cz\postak.exe
C:\Program Files\Jabbim\jabbim.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\DU Meter\DUMeterSvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: softXpansion_de Toolbar - {5f4e4964-2e76-4f80-a012-acb7e63a9ccd} - C:\Program Files\softXpansion_de\tbsof1.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: softXpansion_de Toolbar - {5f4e4964-2e76-4f80-a012-acb7e63a9ccd} - C:\Program Files\softXpansion_de\tbsof1.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: PDF-XChange Viewer IE-Plugin - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Program Files\Tracker Software\PDF Viewer\PDFXCviewIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Seznam.cz\core.2.dll
O3 - Toolbar: softXpansion_de Toolbar - {5f4e4964-2e76-4f80-a012-acb7e63a9ccd} - C:\Program Files\softXpansion_de\tbsof1.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NodEnabler] C:\Program Files\ESET\ESET Smart Security\NodEnabler\NodEnabler.exe /s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Miranda IM] C:\Program Files\Miranda IM KP v5.0.8.5\launcher.exe
O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKCU\..\Run: [Seznam Postak] "C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Seznam.cz\postak.exe" -s
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Jabbim.lnk = C:\Program Files\Jabbim\jabbim.exe
O4 - Global Startup: Aktualizovat ESET licenci.lnk = C:\Program Files\ESET\MiNODLogin\MiNODLogin.exe
O8 - Extra context menu item: Karty - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditPass.html
O8 - Extra context menu item: Uložit formuláře - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Uložit - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Uložit formuláře - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Karty - {45DB34C3-955C-11D3-ABEF-444553540001} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditPass.html
O9 - Extra 'Tools' menuitem: Karty - {45DB34C3-955C-11D3-ABEF-444553540001} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditPass.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (file missing) (HKCU)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 9415495046
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 9407999234
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd. - C:\Program Files\DU Meter\DUMeterSvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 8343 byte

Reklama
Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu, seká se PC.

Příspěvekod Damned » 14 led 2010 14:59

Spusť HJT (HijackThis), vypni prohlížeče, odpoj se od internetu a fixni (spustit HJT, "Do a system scan only",
zatrhnout políčko před hodnotou, zmáčknout "Fix checked" a poté "Ano"):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R3 - URLSearchHook: (no name) - - (no file)
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (file missing) (HKCU)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
*****************************************************************************************************************************************
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner

Ivey
Level 1.5
Level 1.5
Příspěvky: 123
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu, seká se PC.

Příspěvekod Ivey » 15 led 2010 11:53

Malwarebytes' Anti-Malware 1.40
Verze databáze: 2584
Windows 5.1.2600 Service Pack 3

15.1.2010 11:49:52
mbam-log-2010-01-15 (11-49-52).txt

Typ skenu: Rychlý sken
Objektu skenováno: 83180
Uplynulý cas: 3 minute(s), 10 second(s)

Infikované procesy pameti: 0
Infikované pametové moduly: 0
Infikované klíce registru: 0
Infikované hodnoty registru: 0
Infikované položky dat registru: 0
Infikované složky: 0
Infikované soubory: 0

Infikované procesy pameti:
(Žádné zákerné položky nebyly zjišteny)

Infikované pametové moduly:
(Žádné zákerné položky nebyly zjišteny)

Infikované klíce registru:
(Žádné zákerné položky nebyly zjišteny)

Infikované hodnoty registru:
(Žádné zákerné položky nebyly zjišteny)

Infikované položky dat registru:
(Žádné zákerné položky nebyly zjišteny)

Infikované složky:
(Žádné zákerné položky nebyly zjišteny)

Infikované soubory:
(Žádné zákerné položky nebyly zjišteny)

Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu, seká se PC.

Příspěvekod Damned » 15 led 2010 12:48

Vypni rezidentní štít antiviru (pokud máš tak i antispyware).
Stáhni si ComboFix (by sUBs)
nebo ComboFix (subs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner

Ivey
Level 1.5
Level 1.5
Příspěvky: 123
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu, seká se PC.

Příspěvekod Ivey » 15 led 2010 17:15

ComboFix 10-01-14.07 - Ivana 15.01.2010 17:07:49.8.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1636 [GMT 1:00]
Spuštěný z: c:\documents and settings\Ivana\Plocha\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Rezidentní štít AV je zapnutý

.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\struct~.ini

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-15 do 2010-01-15 )))))))))))))))))))))))))))))))
.

2010-01-15 16:03 . 2010-01-15 16:03 390144 ----a-w- c:\windows\system32\CF14986.exe
2010-01-13 04:36 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-07 20:32 . 2010-01-07 20:32 -------- d-----w- c:\program files\Seznam.cz
2010-01-06 17:29 . 2010-01-06 17:31 -------- d-----w- c:\program files\Opera
2010-01-05 07:36 . 2010-01-05 07:36 -------- d-----w- c:\program files\Common Files\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-14 11:49 . 2009-06-30 12:30 196608 ----a-w- c:\windows\system32\drivers\nStandard.bin
2010-01-06 17:11 . 2009-08-29 12:32 -------- d-----w- c:\program files\Opera 10 Beta
2010-01-05 07:36 . 2009-09-21 10:04 -------- d-----w- c:\program files\Safari
2009-12-24 05:16 . 2007-10-29 12:00 78344 ----a-w- c:\windows\system32\perfc005.dat
2009-12-24 05:16 . 2007-10-29 12:00 429626 ----a-w- c:\windows\system32\perfh005.dat
2009-12-22 06:47 . 2009-07-19 18:34 -------- d-----w- c:\program files\Jabbim
2009-11-28 14:02 . 2009-11-28 13:59 -------- d-----w- c:\program files\DU Meter
2009-11-28 13:37 . 2009-11-28 13:16 -------- d-----w- c:\program files\ESET
2009-11-28 11:58 . 2009-11-28 10:22 -------- d-----w- c:\program files\Maxthon2
2009-11-28 11:44 . 2009-07-21 12:53 -------- d-----w- c:\program files\Google
2009-11-28 09:55 . 2009-08-22 09:52 -------- d-----w- c:\program files\softXpansion_de
2009-11-21 16:03 . 2007-10-29 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-02 19:42 . 2009-10-03 04:05 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 07:43 . 2007-10-29 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:40 . 2007-10-29 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:40 . 2007-10-29 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2007-10-29 12:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{5f4e4964-2e76-4f80-a012-acb7e63a9ccd}"= "c:\program files\softXpansion_de\tbsof1.dll" [2009-11-28 2166296]

[HKEY_CLASSES_ROOT\clsid\{5f4e4964-2e76-4f80-a012-acb7e63a9ccd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5f4e4964-2e76-4f80-a012-acb7e63a9ccd}]
2009-11-28 09:55 2166296 ----a-w- c:\program files\softXpansion_de\tbsof1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5f4e4964-2e76-4f80-a012-acb7e63a9ccd}"= "c:\program files\softXpansion_de\tbsof1.dll" [2009-11-28 2166296]

[HKEY_CLASSES_ROOT\clsid\{5f4e4964-2e76-4f80-a012-acb7e63a9ccd}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{5F4E4964-2E76-4F80-A012-ACB7E63A9CCD}"= "c:\program files\softXpansion_de\tbsof1.dll" [2009-11-28 2166296]

[HKEY_CLASSES_ROOT\clsid\{5f4e4964-2e76-4f80-a012-acb7e63a9ccd}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2007-11-13 2585360]
"Seznam Postak"="c:\documents and settings\Ivana\Local Settings\Data aplikací\Seznam.cz\postak.exe" [2009-11-02 448664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"nwiz"="nwiz.exe" [2007-06-28 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"ASUSGamerOSD"="c:\program files\ASUS\GamerOSD\GamerOSD.exe" [2007-07-12 380928]
"SoundMan"="SOUNDMAN.EXE" [2004-12-22 77824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-04-09 2029640]
"NodEnabler"="c:\program files\ESET\ESET Smart Security\NodEnabler\NodEnabler.exe" [2009-04-08 357521]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Ivana\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Jabbim.lnk - c:\program files\Jabbim\jabbim.exe [2009-8-21 211968]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Aktualizovat ESET licenci.lnk - c:\program files\ESET\MiNODLogin\MiNODLogin.exe [2009-10-24 125952]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Instalace\\Portable\\Skype 3.0.0.190 CZ (Portable)\\Phone\\Skype.exe"=
"c:\\Program Files\\TeamViewer3\\TeamViewer.exe"=
"c:\\Program Files\\VoipDiscount.com\\VoipDiscount\\VoipDiscount.exe"=
"c:\\Program Files\\Maxthon2\\Modules\\MxDownloader\\MxDownloadServer.exe"=
"c:\\QIP Infium JadrisPack\\infium.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [9.4.2009 15:18 107256]
R2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [28.11.2009 14:59 1391136]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [9.4.2009 15:19 731840]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 18:19 13592]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [30.6.2009 15:15 721904]
.
Obsah adresáře 'Naplánované úlohy'

2010-01-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-01-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]

2009-11-22 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-07-26 07:22]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Karty - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComEditPass.html
IE: Uložit formuláře - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{45DB34C3-955C-11D3-ABEF-444553540001} - c:\program files\Siber Systems\AI RoboForm\RoboFormComEditPass.html
FF - ProfilePath - c:\documents and settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll
FF - plugin: c:\program files\ACE Mega CoDecS Pack\SystemS\RealMedia\Browser\plugins\nppl3260.dll
FF - plugin: c:\program files\ACE Mega CoDecS Pack\SystemS\RealMedia\Browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npstar.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\NPSWF32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-Miranda IM - c:\program files\Miranda IM KP v5.0.8.5\launcher.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-15 17:11
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet007\Services\DUMeterSvc]
"ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
Celkový čas: 2010-01-15 17:13:03
ComboFix-quarantined-files.txt 2010-01-15 16:12

Před spuštěním: 7 596 212 224
Po spuštění: 9 174 171 648

Current=7 Default=7 Failed=6 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
- - End Of File - - CBA2DE5BE312F58F69BD48B952B61403

Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu, seká se PC.

Příspěvekod Damned » 15 led 2010 17:40

Stáhni si:
Registry Search Tady: Registry Search

Rozbal si soubor do složky a potom poklepej na regsearch.exe ke startu programu.
Do volné linky(linek) nad Enter search string case independent zkopíruj a vlož:

Kód: Vybrat vše

 Kaspersky


A klikni na OK.Otevře se notepad s textem a celý text z něho sem vlož.
*****************************************************************************************************************************************
Stáhni si OTL na Plochu.
Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Output klikni na minimal Output.Pod Standard Registry změň na All. Zatrhni LOP Check a Purity Check. File age změň na 14 days. Klikni na Run Scan. Všechny ostatní nastavení ponech jak jsou. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt
Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner

Ivey
Level 1.5
Level 1.5
Příspěvky: 123
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu, seká se PC.

Příspěvekod Ivey » 15 led 2010 20:42

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.6.0

; Results at 15.1.2010 20:41:08 for strings:
; 'kaspersky'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions]
; Contents of value:
; 1
; 2
; 3
; 4
;
"Kaspersky Anti-Virus NDIS Miniport"=hex(7):31,00,00,00,32,00,00,00,33,00,00,\
00,34,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions]
; Contents of value:
; 1
; 2
; 3
; 4
;
"Kaspersky Anti-Virus NDIS Miniport"=hex(7):31,00,00,00,32,00,00,00,33,00,00,\
00,34,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions]
; Contents of value:
; 1
; 2
; 3
; 4
;
"Kaspersky Anti-Virus NDIS Miniport"=hex(7):31,00,00,00,32,00,00,00,33,00,00,\
00,34,00,00,00,00,00

; End Of The Log...

Ivey
Level 1.5
Level 1.5
Příspěvky: 123
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu, seká se PC.

Příspěvekod Ivey » 15 led 2010 20:48

OTL logfile created on: 15.1.2010 20:46:58 - Run 3
OTL by OldTimer - Version 3.1.25.0 Folder = C:\Documents and Settings\Ivana\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 71,00% Memory free
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 82,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 25,69 Gb Total Space | 8,76 Gb Free Space | 34,11% Space Free | Partition Type: NTFS
Drive D: | 48,83 Gb Total Space | 44,72 Gb Free Space | 91,58% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 147,40 Gb Total Space | 111,53 Gb Free Space | 75,67% Space Free | Partition Type: NTFS
Drive H: | 147,46 Gb Total Space | 144,85 Gb Free Space | 98,23% Space Free | Partition Type: NTFS
Drive I: | 170,90 Gb Total Space | 170,76 Gb Free Space | 99,92% Space Free | Partition Type: NTFS

Computer Name: DOMOV-C63AFF276
Current User Name: Ivana
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 14 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Ivana\Plocha\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Opera\opera.exe (Opera Software)
PRC - C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Seznam.cz\postak.exe ()
PRC - C:\Documents and Settings\Ivana\Dokumenty\Miranda IM\miranda32.exe ( )
PRC - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
PRC - C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Technologies)
PRC - C:\Program Files\DU Meter\DUMeterSvc.exe (Hagel Technologies Ltd.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\DU Meter\DUMeter.exe (Hagel Technologies Ltd)
PRC - C:\Program Files\ASUS\GamerOSD\GamerOSD.exe (ASUSTeK Computer Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Ivana\Plocha\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (DUMeterSvc) -- C:\Program Files\DU Meter\DUMeterSvc.exe (Hagel Technologies Ltd.)
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (EhttpSrv) -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (ESET)
SRV - (ekrn) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
SRV - (Bonjour Service) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (NetTcpPortSharing) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ATKKeyboardService) -- C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
SRV - (NVSvc) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (lxcg_device) -- C:\WINDOWS\System32\lxcgcoms.exe ( )
SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)


========== Driver Services (SafeList) ==========

DRV - (pcouffin) -- C:\WINDOWS\system32\drivers\pcouffin.sys (VSO Software)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (epfwtdi) -- C:\WINDOWS\system32\drivers\epfwtdi.sys (ESET)
DRV - (Epfwndis) -- C:\WINDOWS\system32\drivers\epfwndis.sys (ESET)
DRV - (epfw) -- C:\WINDOWS\system32\drivers\epfw.sys (ESET)
DRV - (ehdrv) -- C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (eamon) -- C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (asusgsb) -- C:\WINDOWS\system32\drivers\asusgsb.sys (ASUSTeK Computer Inc.)
DRV - (Video3D) -- C:\WINDOWS\system32\drivers\Video3D32.sys (ASUSTeK COMPUTER INC.)
DRV - (EIO) -- C:\WINDOWS\system32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (asuskbnt) -- C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata) -- C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {5f4e4964-2e76-4f80-a012-acb7e63a9ccd} - C:\Program Files\softXpansion_de\tbsof1.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://start.icq.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.97
FF - prefs.js..extensions.enabledItems: fastdial@telega.phpnet.us:2.23b1
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:3.2.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
FF - prefs.js..keyword.URL: "http://search.qip.ru/search?from=FF&query="

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009.07.03 07:31:43 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009.07.25 19:27:59 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2009.09.26 14:22:02 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.01.08 15:31:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.01.08 15:31:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2009.11.28 14:16:39 | 00,000,000 | ---D | M]

[2009.08.13 22:01:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Extensions
[2009.08.13 22:01:03 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Extensions\{92650c4d-4b8e-4d2a-b7eb-24ecf4f6b63a}
[2009.06.30 14:16:10 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010.01.14 06:30:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions
[2009.07.04 13:07:28 | 00,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009.07.24 11:21:24 | 00,000,000 | ---D | M] (Speed Dial) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2009.09.21 05:57:31 | 00,000,000 | ---D | M] (ImTranslator) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2009.09.19 07:57:32 | 00,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009.09.19 07:57:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us
[2009.07.02 16:46:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com
[2009.08.13 22:19:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\SeaMonkey\Profiles\ssdtnh0t.default\extensions
[2009.08.13 22:19:49 | 00,000,000 | ---D | M] (FoxLingo) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\SeaMonkey\Profiles\ssdtnh0t.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2009.06.30 15:16:58 | 00,002,399 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\daemon-search.xml
[2010.01.07 21:18:33 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-1.xml
[2009.07.21 07:16:22 | 00,000,950 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-2.xml
[2009.07.21 11:00:07 | 00,000,950 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-3.xml
[2009.08.11 17:17:43 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-4.xml
[2009.09.19 07:38:27 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-5.xml
[2009.10.04 06:46:11 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-6.xml
[2008.11.18 12:56:02 | 00,000,944 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin.xml
[2009.07.21 07:16:29 | 00,009,941 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\mywebsearch.xml
[2009.09.08 05:48:42 | 00,002,061 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\qipsearch.xml
[2010.01.14 06:30:21 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.10.04 06:46:06 | 00,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009.11.11 16:10:35 | 00,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009.07.25 19:28:12 | 00,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2010.01.08 15:31:43 | 00,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010.01.08 15:31:43 | 00,137,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2009.07.25 19:27:58 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
[2003.01.13 15:08:06 | 00,499,712 | ---- | M] (Morgan Multimedia) -- C:\Program Files\Mozilla Firefox\plugins\npjp2.dll
[2010.01.08 15:31:45 | 00,064,984 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2009.02.27 13:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2004.11.09 01:43:08 | 00,139,305 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2004.11.09 01:43:04 | 00,081,967 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
[2004.02.04 18:53:58 | 00,102,400 | ---- | M] (Star Downloader) -- C:\Program Files\Mozilla Firefox\plugins\npstar.dll
[2009.07.15 19:42:42 | 00,002,371 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2009.07.15 19:42:42 | 00,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2009.07.15 19:42:42 | 00,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2009.07.15 19:42:42 | 00,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2009.07.15 19:42:42 | 00,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2009.07.15 19:42:42 | 00,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (softXpansion_de Toolbar) - {5f4e4964-2e76-4f80-a012-acb7e63a9ccd} - C:\Program Files\softXpansion_de\tbsof1.dll (Conduit Ltd.)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (PDF-XChange Viewer IE-Plugin) - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Program Files\Tracker Software\PDF Viewer\PDFXCviewIEPlugin.dll (Tracker Software Products Ltd.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (Ukazatel S-Rank) - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.2.dll ()
O3 - HKLM\..\Toolbar: (softXpansion_de Toolbar) - {5f4e4964-2e76-4f80-a012-acb7e63a9ccd} - C:\Program Files\softXpansion_de\tbsof1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Adresa) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O3 - HKCU\..\Toolbar\WebBrowser: (&Adresa) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O3 - HKCU\..\Toolbar\WebBrowser: (&Odkazy) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (softXpansion_de Toolbar) - {5F4E4964-2E76-4F80-A012-ACB7E63A9CCD} - C:\Program Files\softXpansion_de\tbsof1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NodEnabler] C:\Program Files\ESET\ESET Smart Security\NodEnabler\NodEnabler.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe (Hagel Technologies Ltd)
O4 - HKCU..\Run: [Seznam Postak] C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Seznam.cz\postak.exe ()
O4 - HKCU..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Aktualizovat ESET licenci.lnk = C:\Program Files\ESET\MiNODLogin\MiNODLogin.exe (GuillerSoft)
O4 - Startup: C:\Documents and Settings\Ivana\Nabídka Start\Programy\Po spuštění\Jabbim.lnk = C:\Program Files\Jabbim\jabbim.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Karty - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditPass.html ()
O8 - Extra context menu item: Uložit formuláře - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - Reg Error: Key error. File not found
O9 - Extra Button: Uložit - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Uložit formuláře - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Karty - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditPass.html ()
O9 - Extra 'Tools' menuitem : Karty - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditPass.html ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupda ... 9415495046 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microso ... 9407999234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.46.172.36 213.46.172.37
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Proces mezipaměti kategorií součástí - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

========== Files/Folders - Created Within 14 Days ==========

[2010.01.15 20:39:56 | 00,357,376 | ---- | C] (SteelWerX) -- C:\Documents and Settings\Ivana\Plocha\regsearch.exe
[2010.01.15 20:39:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ivana\Plocha\lala
[2010.01.15 20:27:18 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2010.01.15 20:20:54 | 00,546,816 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ivana\Plocha\OTL.exe
[2010.01.15 17:07:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ivana\Local Settings\Data aplikací\ESET
[2010.01.15 17:06:58 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.01.15 17:06:55 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.01.15 17:06:54 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.01.15 17:06:53 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.01.15 17:03:45 | 00,390,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF14986.exe
[2010.01.15 17:03:45 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.01.15 17:03:42 | 00,000,000 | ---D | C] -- C:\Qoobox
[2010.01.13 05:36:27 | 00,471,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aclayers.dll
[2010.01.12 21:51:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ivana\Plocha\GOLD Webgame_files
[2010.01.10 06:52:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\ESET
[2010.01.09 08:28:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Seznam.cz
[2010.01.07 21:32:24 | 00,000,000 | ---D | C] -- C:\Program Files\Seznam.cz
[2010.01.06 18:29:36 | 00,000,000 | ---D | C] -- C:\Program Files\Opera
[2010.01.05 08:36:10 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010.01.05 08:35:07 | 29,635,880 | ---- | C] (Apple Inc.) -- C:\Documents and Settings\Ivana\Plocha\SafariSetup.exe
[2009.11.28 14:59:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Hagel Technologies
[2009.09.23 06:56:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\softXpansion_de
[2009.09.23 06:56:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Apple
[2009.07.03 09:12:24 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2009.07.03 07:50:10 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2009.07.03 07:05:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.07.02 12:50:38 | 00,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Ivana\Data aplikací\pcouffin.sys
[2009.06.30 13:43:53 | 01,183,744 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgserv.dll
[2009.06.30 13:43:53 | 01,134,592 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgusb1.dll
[2009.06.30 13:43:53 | 00,155,648 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgprox.dll
[2009.06.30 13:43:53 | 00,114,688 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgpplc.dll
[2009.06.30 13:43:52 | 00,704,512 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgcomc.dll
[2009.06.30 13:43:52 | 00,483,328 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcglmpm.dll
[2009.06.30 13:43:52 | 00,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgcomm.dll
[2009.06.30 12:59:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2004.11.24 19:25:52 | 00,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll

========== Files - Modified Within 14 Days ==========

[2010.01.15 20:40:25 | 04,456,448 | ---- | M] () -- C:\Documents and Settings\Ivana\NTUSER.DAT
[2010.01.15 20:39:01 | 00,345,156 | ---- | M] () -- C:\Documents and Settings\Ivana\Plocha\regsearch.zip
[2010.01.15 20:21:03 | 00,546,816 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ivana\Plocha\OTL.exe
[2010.01.15 17:34:01 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010.01.15 17:24:12 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.01.15 17:21:19 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.01.15 17:20:47 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.01.15 17:20:44 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.01.15 17:17:18 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Ivana\ntuser.ini
[2010.01.15 17:11:43 | 00,009,415 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.01.15 17:04:58 | 03,825,876 | R--- | M] () -- C:\Documents and Settings\Ivana\Plocha\ComboFix.exe
[2010.01.15 17:03:39 | 00,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF14986.exe
[2010.01.15 11:41:47 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Ivana\Plocha\HijackThis.lnk
[2010.01.15 07:17:05 | 00,009,744 | ---- | M] () -- C:\WINDOWS\System32\quicktime.qtp
[2010.01.14 12:49:21 | 00,196,608 | ---- | M] () -- C:\WINDOWS\System32\drivers\nStandard.bin
[2010.01.13 07:56:03 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.01.13 05:43:53 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.01.12 21:53:12 | 03,932,214 | ---- | M] () -- C:\Documents and Settings\Ivana\Plocha\Bez názvu.bmp
[2010.01.12 21:51:29 | 00,028,378 | ---- | M] () -- C:\Documents and Settings\Ivana\Plocha\GOLD Webgame.htm
[2010.01.11 18:30:37 | 00,035,840 | ---- | M] () -- C:\Documents and Settings\Ivana\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.01.09 04:59:19 | 01,611,776 | ---- | M] () -- C:\Documents and Settings\Ivana\Plocha\Ziva voda.pps
[2010.01.05 08:36:29 | 00,001,854 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Safari.lnk
[2010.01.05 08:35:45 | 29,635,880 | ---- | M] (Apple Inc.) -- C:\Documents and Settings\Ivana\Plocha\SafariSetup.exe

========== Files Created - No Company Name ==========

[2010.01.15 20:38:56 | 00,345,156 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\regsearch.zip
[2010.01.15 17:06:59 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.01.15 17:06:55 | 00,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.01.15 17:06:55 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.01.15 17:06:54 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.01.15 17:06:54 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.01.15 17:04:32 | 03,825,876 | R--- | C] () -- C:\Documents and Settings\Ivana\Plocha\ComboFix.exe
[2010.01.14 02:25:52 | 73,401,5488 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\dismov-trzr.avi
[2010.01.13 10:05:58 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\HijackThis.lnk
[2010.01.12 21:53:12 | 03,932,214 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\Bez názvu.bmp
[2010.01.12 21:51:29 | 00,028,378 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\GOLD Webgame.htm
[2010.01.09 04:59:19 | 01,611,776 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\Ziva voda.pps
[2010.01.05 08:36:29 | 00,001,854 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Safari.lnk
[2009.07.03 08:25:34 | 00,000,761 | ---- | C] () -- C:\WINDOWS\m3jp2k.ini
[2009.07.03 08:25:34 | 00,000,702 | ---- | C] () -- C:\WINDOWS\mmtvmj.ini
[2009.07.03 08:25:33 | 00,000,714 | ---- | C] () -- C:\WINDOWS\m3jpeg.ini
[2009.07.03 08:25:30 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2009.07.03 07:03:07 | 00,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2009.07.02 19:11:22 | 00,035,840 | ---- | C] () -- C:\Documents and Settings\Ivana\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.07.02 12:50:43 | 00,000,033 | ---- | C] () -- C:\Documents and Settings\Ivana\Data aplikací\pcouffin.log
[2009.07.02 12:50:38 | 00,087,608 | ---- | C] () -- C:\Documents and Settings\Ivana\Data aplikací\inst.exe
[2009.07.02 12:50:38 | 00,007,887 | ---- | C] () -- C:\Documents and Settings\Ivana\Data aplikací\pcouffin.cat
[2009.07.02 12:50:38 | 00,001,144 | ---- | C] () -- C:\Documents and Settings\Ivana\Data aplikací\pcouffin.inf
[2009.06.30 15:15:29 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009.06.30 15:09:24 | 00,000,707 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2009.06.30 14:30:44 | 01,695,744 | ---- | C] () -- C:\WINDOWS\System32\beconvlib.dll
[2009.06.30 14:30:44 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\bprgcomm.dll
[2009.06.30 14:30:44 | 00,131,072 | ---- | C] () -- C:\WINDOWS\System32\CSVSpecialProcessing.dll
[2009.06.30 14:30:43 | 00,221,184 | ---- | C] () -- C:\WINDOWS\System32\SII_PDF.dll
[2009.06.30 14:30:43 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\SARzilla.dll
[2009.06.30 14:30:43 | 00,098,304 | ---- | C] () -- C:\WINDOWS\System32\DVM.dll
[2009.06.30 14:30:43 | 00,000,530 | ---- | C] () -- C:\WINDOWS\System32\tx15_ic.ini
[2009.06.30 13:43:54 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcgvs.dll
[2009.06.30 13:43:48 | 00,126,976 | ---- | C] () -- C:\WINDOWS\System32\lxcgjswr.dll
[2009.06.30 13:43:48 | 00,098,304 | ---- | C] () -- C:\WINDOWS\System32\lxcginsr.dll
[2009.06.30 13:39:35 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2009.06.30 13:39:32 | 00,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2009.06.30 13:30:36 | 00,643,142 | ---- | C] () -- C:\WINDOWS\aticlocklib.dll
[2009.06.30 13:30:36 | 00,110,592 | ---- | C] () -- C:\WINDOWS\R5ClkLib.dll
[2009.06.30 13:30:35 | 00,000,018 | ---- | C] () -- C:\WINDOWS\System32\atkid.ini
[2009.06.30 13:30:34 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009.06.30 13:30:34 | 00,046,592 | ---- | C] () -- C:\WINDOWS\System32\asfrench.dll
[2009.06.30 13:30:34 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\asrussian.dll
[2009.06.30 13:30:34 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\asgerman.dll
[2009.06.30 13:30:34 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\aseng.dll
[2009.06.30 13:30:34 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\askorean.dll
[2009.06.30 13:30:34 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\asjapan.dll
[2009.06.30 13:30:34 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\aschs.dll
[2009.06.30 13:30:33 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\ASCHT.dll
[2008.12.19 15:15:58 | 04,338,246 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008.12.17 17:41:18 | 00,884,237 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2008.12.17 17:22:58 | 00,093,184 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2008.12.17 17:22:48 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008.12.17 17:17:34 | 00,239,247 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2008.12.17 16:59:54 | 00,560,802 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008.12.11 11:27:02 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007.06.28 17:43:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007.06.28 17:43:00 | 01,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007.06.28 17:43:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007.06.28 17:43:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007.06.28 17:43:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2005.10.14 10:56:50 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 10:56:50 | 00,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 10:56:50 | 00,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 10:56:50 | 00,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 10:56:50 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005.10.14 10:56:50 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 10:56:50 | 00,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 10:56:50 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2004.10.03 17:50:54 | 00,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll

========== LOP Check ==========

[2009.06.30 16:35:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ashampoo
[2009.06.30 15:17:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.06.30 14:45:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2009.11.28 14:59:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Hagel Technologies
[2009.07.06 21:18:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2009.09.06 09:53:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\page
[2009.09.06 08:42:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PrettyMay
[2009.08.06 18:03:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\RoboForm
[2009.08.22 10:51:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\soft Xpansion
[2009.08.25 10:34:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\.purple
[2009.06.30 16:35:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Ashampoo
[2009.06.30 15:18:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\DAEMON Tools Lite
[2009.11.28 14:17:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\ESET
[2009.07.26 12:55:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\esmska
[2009.07.06 20:04:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\FLVPlayer4Free
[2009.09.26 12:49:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\GoodSync
[2008.08.24 20:21:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\gtk-2.0
[2009.10.07 12:30:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\ICQ
[2009.07.26 20:31:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\IObit
[2009.12.22 07:47:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\jabbim
[2009.10.01 08:53:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Miranda
[2010.01.15 20:44:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\MxBoost
[2009.07.02 14:55:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\OpenOffice.org
[2009.06.30 14:24:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Opera
[2009.07.11 17:53:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\SecondLife
[2009.08.22 11:32:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\sim
[2009.07.03 08:21:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\TeamViewer
[2009.07.02 16:47:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Trillian
[2009.07.29 07:26:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\VoipDiscount
[2009.07.02 13:08:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Vso
[2009.08.25 12:45:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\ZJSoftware
[2010.01.15 17:24:12 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========


< End of report >

Ivey
Level 1.5
Level 1.5
Příspěvky: 123
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu, seká se PC.

Příspěvekod Ivey » 15 led 2010 20:48

OTL logfile created on: 15.1.2010 20:46:58 - Run 3
OTL by OldTimer - Version 3.1.25.0 Folder = C:\Documents and Settings\Ivana\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 71,00% Memory free
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 82,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 25,69 Gb Total Space | 8,76 Gb Free Space | 34,11% Space Free | Partition Type: NTFS
Drive D: | 48,83 Gb Total Space | 44,72 Gb Free Space | 91,58% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 147,40 Gb Total Space | 111,53 Gb Free Space | 75,67% Space Free | Partition Type: NTFS
Drive H: | 147,46 Gb Total Space | 144,85 Gb Free Space | 98,23% Space Free | Partition Type: NTFS
Drive I: | 170,90 Gb Total Space | 170,76 Gb Free Space | 99,92% Space Free | Partition Type: NTFS

Computer Name: DOMOV-C63AFF276
Current User Name: Ivana
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 14 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Ivana\Plocha\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Opera\opera.exe (Opera Software)
PRC - C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Seznam.cz\postak.exe ()
PRC - C:\Documents and Settings\Ivana\Dokumenty\Miranda IM\miranda32.exe ( )
PRC - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
PRC - C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Technologies)
PRC - C:\Program Files\DU Meter\DUMeterSvc.exe (Hagel Technologies Ltd.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\DU Meter\DUMeter.exe (Hagel Technologies Ltd)
PRC - C:\Program Files\ASUS\GamerOSD\GamerOSD.exe (ASUSTeK Computer Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Ivana\Plocha\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (DUMeterSvc) -- C:\Program Files\DU Meter\DUMeterSvc.exe (Hagel Technologies Ltd.)
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (EhttpSrv) -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (ESET)
SRV - (ekrn) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
SRV - (Bonjour Service) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (NetTcpPortSharing) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ATKKeyboardService) -- C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
SRV - (NVSvc) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (lxcg_device) -- C:\WINDOWS\System32\lxcgcoms.exe ( )
SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)


========== Driver Services (SafeList) ==========

DRV - (pcouffin) -- C:\WINDOWS\system32\drivers\pcouffin.sys (VSO Software)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (epfwtdi) -- C:\WINDOWS\system32\drivers\epfwtdi.sys (ESET)
DRV - (Epfwndis) -- C:\WINDOWS\system32\drivers\epfwndis.sys (ESET)
DRV - (epfw) -- C:\WINDOWS\system32\drivers\epfw.sys (ESET)
DRV - (ehdrv) -- C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (eamon) -- C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (asusgsb) -- C:\WINDOWS\system32\drivers\asusgsb.sys (ASUSTeK Computer Inc.)
DRV - (Video3D) -- C:\WINDOWS\system32\drivers\Video3D32.sys (ASUSTeK COMPUTER INC.)
DRV - (EIO) -- C:\WINDOWS\system32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (asuskbnt) -- C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata) -- C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {5f4e4964-2e76-4f80-a012-acb7e63a9ccd} - C:\Program Files\softXpansion_de\tbsof1.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://start.icq.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.97
FF - prefs.js..extensions.enabledItems: fastdial@telega.phpnet.us:2.23b1
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:3.2.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
FF - prefs.js..keyword.URL: "http://search.qip.ru/search?from=FF&query="

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009.07.03 07:31:43 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009.07.25 19:27:59 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2009.09.26 14:22:02 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.01.08 15:31:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.01.08 15:31:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2009.11.28 14:16:39 | 00,000,000 | ---D | M]

[2009.08.13 22:01:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Extensions
[2009.08.13 22:01:03 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Extensions\{92650c4d-4b8e-4d2a-b7eb-24ecf4f6b63a}
[2009.06.30 14:16:10 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010.01.14 06:30:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions
[2009.07.04 13:07:28 | 00,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009.07.24 11:21:24 | 00,000,000 | ---D | M] (Speed Dial) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2009.09.21 05:57:31 | 00,000,000 | ---D | M] (ImTranslator) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2009.09.19 07:57:32 | 00,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009.09.19 07:57:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us
[2009.07.02 16:46:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com
[2009.08.13 22:19:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\SeaMonkey\Profiles\ssdtnh0t.default\extensions
[2009.08.13 22:19:49 | 00,000,000 | ---D | M] (FoxLingo) -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\SeaMonkey\Profiles\ssdtnh0t.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2009.06.30 15:16:58 | 00,002,399 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\daemon-search.xml
[2010.01.07 21:18:33 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-1.xml
[2009.07.21 07:16:22 | 00,000,950 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-2.xml
[2009.07.21 11:00:07 | 00,000,950 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-3.xml
[2009.08.11 17:17:43 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-4.xml
[2009.09.19 07:38:27 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-5.xml
[2009.10.04 06:46:11 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-6.xml
[2008.11.18 12:56:02 | 00,000,944 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin.xml
[2009.07.21 07:16:29 | 00,009,941 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\mywebsearch.xml
[2009.09.08 05:48:42 | 00,002,061 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\qipsearch.xml
[2010.01.14 06:30:21 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.10.04 06:46:06 | 00,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009.11.11 16:10:35 | 00,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009.07.25 19:28:12 | 00,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2010.01.08 15:31:43 | 00,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010.01.08 15:31:43 | 00,137,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2009.07.25 19:27:58 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
[2003.01.13 15:08:06 | 00,499,712 | ---- | M] (Morgan Multimedia) -- C:\Program Files\Mozilla Firefox\plugins\npjp2.dll
[2010.01.08 15:31:45 | 00,064,984 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2009.02.27 13:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2004.11.09 01:43:08 | 00,139,305 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2004.11.08 19:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2004.11.09 01:43:04 | 00,081,967 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
[2004.02.04 18:53:58 | 00,102,400 | ---- | M] (Star Downloader) -- C:\Program Files\Mozilla Firefox\plugins\npstar.dll
[2009.07.15 19:42:42 | 00,002,371 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2009.07.15 19:42:42 | 00,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2009.07.15 19:42:42 | 00,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2009.07.15 19:42:42 | 00,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2009.07.15 19:42:42 | 00,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2009.07.15 19:42:42 | 00,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (softXpansion_de Toolbar) - {5f4e4964-2e76-4f80-a012-acb7e63a9ccd} - C:\Program Files\softXpansion_de\tbsof1.dll (Conduit Ltd.)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (PDF-XChange Viewer IE-Plugin) - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Program Files\Tracker Software\PDF Viewer\PDFXCviewIEPlugin.dll (Tracker Software Products Ltd.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (Ukazatel S-Rank) - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.2.dll ()
O3 - HKLM\..\Toolbar: (softXpansion_de Toolbar) - {5f4e4964-2e76-4f80-a012-acb7e63a9ccd} - C:\Program Files\softXpansion_de\tbsof1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Adresa) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O3 - HKCU\..\Toolbar\WebBrowser: (&Adresa) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O3 - HKCU\..\Toolbar\WebBrowser: (&Odkazy) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (softXpansion_de Toolbar) - {5F4E4964-2E76-4F80-A012-ACB7E63A9CCD} - C:\Program Files\softXpansion_de\tbsof1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NodEnabler] C:\Program Files\ESET\ESET Smart Security\NodEnabler\NodEnabler.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe (Hagel Technologies Ltd)
O4 - HKCU..\Run: [Seznam Postak] C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Seznam.cz\postak.exe ()
O4 - HKCU..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Aktualizovat ESET licenci.lnk = C:\Program Files\ESET\MiNODLogin\MiNODLogin.exe (GuillerSoft)
O4 - Startup: C:\Documents and Settings\Ivana\Nabídka Start\Programy\Po spuštění\Jabbim.lnk = C:\Program Files\Jabbim\jabbim.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Karty - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditPass.html ()
O8 - Extra context menu item: Uložit formuláře - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - Reg Error: Key error. File not found
O9 - Extra Button: Uložit - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Uložit formuláře - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Karty - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditPass.html ()
O9 - Extra 'Tools' menuitem : Karty - {45DB34C3-955C-11D3-ABEF-444553540001} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditPass.html ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupda ... 9415495046 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microso ... 9407999234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.46.172.36 213.46.172.37
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Proces mezipaměti kategorií součástí - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

========== Files/Folders - Created Within 14 Days ==========

[2010.01.15 20:39:56 | 00,357,376 | ---- | C] (SteelWerX) -- C:\Documents and Settings\Ivana\Plocha\regsearch.exe
[2010.01.15 20:39:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ivana\Plocha\lala
[2010.01.15 20:27:18 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2010.01.15 20:20:54 | 00,546,816 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ivana\Plocha\OTL.exe
[2010.01.15 17:07:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ivana\Local Settings\Data aplikací\ESET
[2010.01.15 17:06:58 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.01.15 17:06:55 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.01.15 17:06:54 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.01.15 17:06:53 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.01.15 17:03:45 | 00,390,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF14986.exe
[2010.01.15 17:03:45 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.01.15 17:03:42 | 00,000,000 | ---D | C] -- C:\Qoobox
[2010.01.13 05:36:27 | 00,471,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aclayers.dll
[2010.01.12 21:51:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ivana\Plocha\GOLD Webgame_files
[2010.01.10 06:52:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\ESET
[2010.01.09 08:28:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Seznam.cz
[2010.01.07 21:32:24 | 00,000,000 | ---D | C] -- C:\Program Files\Seznam.cz
[2010.01.06 18:29:36 | 00,000,000 | ---D | C] -- C:\Program Files\Opera
[2010.01.05 08:36:10 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010.01.05 08:35:07 | 29,635,880 | ---- | C] (Apple Inc.) -- C:\Documents and Settings\Ivana\Plocha\SafariSetup.exe
[2009.11.28 14:59:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Hagel Technologies
[2009.09.23 06:56:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\softXpansion_de
[2009.09.23 06:56:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Apple
[2009.07.03 09:12:24 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2009.07.03 07:50:10 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2009.07.03 07:05:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2009.07.02 12:50:38 | 00,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Ivana\Data aplikací\pcouffin.sys
[2009.06.30 13:43:53 | 01,183,744 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgserv.dll
[2009.06.30 13:43:53 | 01,134,592 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgusb1.dll
[2009.06.30 13:43:53 | 00,155,648 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgprox.dll
[2009.06.30 13:43:53 | 00,114,688 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgpplc.dll
[2009.06.30 13:43:52 | 00,704,512 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgcomc.dll
[2009.06.30 13:43:52 | 00,483,328 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcglmpm.dll
[2009.06.30 13:43:52 | 00,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcgcomm.dll
[2009.06.30 12:59:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2004.11.24 19:25:52 | 00,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll

========== Files - Modified Within 14 Days ==========

[2010.01.15 20:40:25 | 04,456,448 | ---- | M] () -- C:\Documents and Settings\Ivana\NTUSER.DAT
[2010.01.15 20:39:01 | 00,345,156 | ---- | M] () -- C:\Documents and Settings\Ivana\Plocha\regsearch.zip
[2010.01.15 20:21:03 | 00,546,816 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ivana\Plocha\OTL.exe
[2010.01.15 17:34:01 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010.01.15 17:24:12 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010.01.15 17:21:19 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.01.15 17:20:47 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.01.15 17:20:44 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.01.15 17:17:18 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Ivana\ntuser.ini
[2010.01.15 17:11:43 | 00,009,415 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.01.15 17:04:58 | 03,825,876 | R--- | M] () -- C:\Documents and Settings\Ivana\Plocha\ComboFix.exe
[2010.01.15 17:03:39 | 00,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF14986.exe
[2010.01.15 11:41:47 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Ivana\Plocha\HijackThis.lnk
[2010.01.15 07:17:05 | 00,009,744 | ---- | M] () -- C:\WINDOWS\System32\quicktime.qtp
[2010.01.14 12:49:21 | 00,196,608 | ---- | M] () -- C:\WINDOWS\System32\drivers\nStandard.bin
[2010.01.13 07:56:03 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.01.13 05:43:53 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.01.12 21:53:12 | 03,932,214 | ---- | M] () -- C:\Documents and Settings\Ivana\Plocha\Bez názvu.bmp
[2010.01.12 21:51:29 | 00,028,378 | ---- | M] () -- C:\Documents and Settings\Ivana\Plocha\GOLD Webgame.htm
[2010.01.11 18:30:37 | 00,035,840 | ---- | M] () -- C:\Documents and Settings\Ivana\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.01.09 04:59:19 | 01,611,776 | ---- | M] () -- C:\Documents and Settings\Ivana\Plocha\Ziva voda.pps
[2010.01.05 08:36:29 | 00,001,854 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Safari.lnk
[2010.01.05 08:35:45 | 29,635,880 | ---- | M] (Apple Inc.) -- C:\Documents and Settings\Ivana\Plocha\SafariSetup.exe

========== Files Created - No Company Name ==========

[2010.01.15 20:38:56 | 00,345,156 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\regsearch.zip
[2010.01.15 17:06:59 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.01.15 17:06:55 | 00,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.01.15 17:06:55 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.01.15 17:06:54 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.01.15 17:06:54 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.01.15 17:04:32 | 03,825,876 | R--- | C] () -- C:\Documents and Settings\Ivana\Plocha\ComboFix.exe
[2010.01.14 02:25:52 | 73,401,5488 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\dismov-trzr.avi
[2010.01.13 10:05:58 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\HijackThis.lnk
[2010.01.12 21:53:12 | 03,932,214 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\Bez názvu.bmp
[2010.01.12 21:51:29 | 00,028,378 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\GOLD Webgame.htm
[2010.01.09 04:59:19 | 01,611,776 | ---- | C] () -- C:\Documents and Settings\Ivana\Plocha\Ziva voda.pps
[2010.01.05 08:36:29 | 00,001,854 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Safari.lnk
[2009.07.03 08:25:34 | 00,000,761 | ---- | C] () -- C:\WINDOWS\m3jp2k.ini
[2009.07.03 08:25:34 | 00,000,702 | ---- | C] () -- C:\WINDOWS\mmtvmj.ini
[2009.07.03 08:25:33 | 00,000,714 | ---- | C] () -- C:\WINDOWS\m3jpeg.ini
[2009.07.03 08:25:30 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2009.07.03 07:03:07 | 00,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2009.07.02 19:11:22 | 00,035,840 | ---- | C] () -- C:\Documents and Settings\Ivana\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.07.02 12:50:43 | 00,000,033 | ---- | C] () -- C:\Documents and Settings\Ivana\Data aplikací\pcouffin.log
[2009.07.02 12:50:38 | 00,087,608 | ---- | C] () -- C:\Documents and Settings\Ivana\Data aplikací\inst.exe
[2009.07.02 12:50:38 | 00,007,887 | ---- | C] () -- C:\Documents and Settings\Ivana\Data aplikací\pcouffin.cat
[2009.07.02 12:50:38 | 00,001,144 | ---- | C] () -- C:\Documents and Settings\Ivana\Data aplikací\pcouffin.inf
[2009.06.30 15:15:29 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009.06.30 15:09:24 | 00,000,707 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2009.06.30 14:30:44 | 01,695,744 | ---- | C] () -- C:\WINDOWS\System32\beconvlib.dll
[2009.06.30 14:30:44 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\bprgcomm.dll
[2009.06.30 14:30:44 | 00,131,072 | ---- | C] () -- C:\WINDOWS\System32\CSVSpecialProcessing.dll
[2009.06.30 14:30:43 | 00,221,184 | ---- | C] () -- C:\WINDOWS\System32\SII_PDF.dll
[2009.06.30 14:30:43 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\SARzilla.dll
[2009.06.30 14:30:43 | 00,098,304 | ---- | C] () -- C:\WINDOWS\System32\DVM.dll
[2009.06.30 14:30:43 | 00,000,530 | ---- | C] () -- C:\WINDOWS\System32\tx15_ic.ini
[2009.06.30 13:43:54 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcgvs.dll
[2009.06.30 13:43:48 | 00,126,976 | ---- | C] () -- C:\WINDOWS\System32\lxcgjswr.dll
[2009.06.30 13:43:48 | 00,098,304 | ---- | C] () -- C:\WINDOWS\System32\lxcginsr.dll
[2009.06.30 13:39:35 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2009.06.30 13:39:32 | 00,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2009.06.30 13:30:36 | 00,643,142 | ---- | C] () -- C:\WINDOWS\aticlocklib.dll
[2009.06.30 13:30:36 | 00,110,592 | ---- | C] () -- C:\WINDOWS\R5ClkLib.dll
[2009.06.30 13:30:35 | 00,000,018 | ---- | C] () -- C:\WINDOWS\System32\atkid.ini
[2009.06.30 13:30:34 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009.06.30 13:30:34 | 00,046,592 | ---- | C] () -- C:\WINDOWS\System32\asfrench.dll
[2009.06.30 13:30:34 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\asrussian.dll
[2009.06.30 13:30:34 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\asgerman.dll
[2009.06.30 13:30:34 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\aseng.dll
[2009.06.30 13:30:34 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\askorean.dll
[2009.06.30 13:30:34 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\asjapan.dll
[2009.06.30 13:30:34 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\aschs.dll
[2009.06.30 13:30:33 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\ASCHT.dll
[2008.12.19 15:15:58 | 04,338,246 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008.12.17 17:41:18 | 00,884,237 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2008.12.17 17:22:58 | 00,093,184 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2008.12.17 17:22:48 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008.12.17 17:17:34 | 00,239,247 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2008.12.17 16:59:54 | 00,560,802 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008.12.11 11:27:02 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007.06.28 17:43:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007.06.28 17:43:00 | 01,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007.06.28 17:43:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007.06.28 17:43:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007.06.28 17:43:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2005.10.14 10:56:50 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 10:56:50 | 00,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 10:56:50 | 00,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 10:56:50 | 00,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 10:56:50 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005.10.14 10:56:50 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 10:56:50 | 00,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 10:56:50 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2004.10.03 17:50:54 | 00,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll

========== LOP Check ==========

[2009.06.30 16:35:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ashampoo
[2009.06.30 15:17:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.06.30 14:45:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2009.11.28 14:59:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Hagel Technologies
[2009.07.06 21:18:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2009.09.06 09:53:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\page
[2009.09.06 08:42:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PrettyMay
[2009.08.06 18:03:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\RoboForm
[2009.08.22 10:51:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\soft Xpansion
[2009.08.25 10:34:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\.purple
[2009.06.30 16:35:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Ashampoo
[2009.06.30 15:18:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\DAEMON Tools Lite
[2009.11.28 14:17:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\ESET
[2009.07.26 12:55:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\esmska
[2009.07.06 20:04:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\FLVPlayer4Free
[2009.09.26 12:49:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\GoodSync
[2008.08.24 20:21:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\gtk-2.0
[2009.10.07 12:30:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\ICQ
[2009.07.26 20:31:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\IObit
[2009.12.22 07:47:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\jabbim
[2009.10.01 08:53:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Miranda
[2010.01.15 20:44:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\MxBoost
[2009.07.02 14:55:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\OpenOffice.org
[2009.06.30 14:24:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Opera
[2009.07.11 17:53:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\SecondLife
[2009.08.22 11:32:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\sim
[2009.07.03 08:21:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\TeamViewer
[2009.07.02 16:47:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Trillian
[2009.07.29 07:26:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\VoipDiscount
[2009.07.02 13:08:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\Vso
[2009.08.25 12:45:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ivana\Data aplikací\ZJSoftware
[2010.01.15 17:24:12 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========


< End of report >

Ivey
Level 1.5
Level 1.5
Příspěvky: 123
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu, seká se PC.

Příspěvekod Ivey » 15 led 2010 20:49

OTL Extras logfile created on: 15.1.2010 20:23:26 - Run 1
OTL by OldTimer - Version 3.1.25.0 Folder = C:\Documents and Settings\Ivana\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 73,00% Memory free
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 85,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 25,69 Gb Total Space | 8,73 Gb Free Space | 33,96% Space Free | Partition Type: NTFS
Drive D: | 48,83 Gb Total Space | 44,72 Gb Free Space | 91,58% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 147,40 Gb Total Space | 111,53 Gb Free Space | 75,67% Space Free | Partition Type: NTFS
Drive H: | 147,46 Gb Total Space | 144,85 Gb Free Space | 98,23% Space Free | Partition Type: NTFS
Drive I: | 170,90 Gb Total Space | 170,76 Gb Free Space | 99,92% Space Free | Partition Type: NTFS

Computer Name: DOMOV-C63AFF276
Current User Name: Ivana
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 14 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- C:\Program Files\Opera\Opera.exe (Opera Software)

[HKEY_USERS\S-1-5-21-606747145-1897051121-839522115-1003\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Instalace\Portable\Skype 3.0.0.190 CZ (Portable)\Phone\Skype.exe" = D:\Instalace\Portable\Skype 3.0.0.190 CZ (Portable)\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"C:\Program Files\TeamViewer3\TeamViewer.exe" = C:\Program Files\TeamViewer3\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application -- (Krysoft/GmbH)
"C:\Program Files\VoipDiscount.com\VoipDiscount\VoipDiscount.exe" = C:\Program Files\VoipDiscount.com\VoipDiscount\VoipDiscount.exe:*:Enabled:VoipDiscount -- (VoipDiscount)
"C:\Program Files\Maxthon2\Modules\MxDownloader\MxDownloadServer.exe" = C:\Program Files\Maxthon2\Modules\MxDownloader\MxDownloadServer.exe:*:Disabled:MxDownloadServer -- (Maxthon International ltd.)
"C:\QIP Infium JadrisPack\infium.exe" = C:\QIP Infium JadrisPack\infium.exe:*:Enabled:QIP Infium -- (QIP)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager -- (Skype Technologies)
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{23E797E9-F852-4AEA-93F0-772ED2B9D9F9}" = OpenOffice.org 3.1
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 14
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Gamer OSD
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FBEB71-CE94-419B-9F4D-C953B7459C77}" = ESET Smart Security
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{66333C41-085E-4DA1-8273-E2BCA382D766}" = NET Installation Assistance for VB6 App (Runtime Only)
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{93293322-B694-4270-B7FE-DDE1A681ACCA}" = linguatec Voice Reader
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1029-7B44-A92000000001}" = Adobe Reader 9.2 - Czech
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AFAF626C-D2E6-455C-9A5A-ACDF049A6168}" = ASUS nVidia Driver
"{B26B00DA-2E5D-4CF2-83C5-911198C0F009}" = GoodSync
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FB8148DD-C575-4B0A-9F6C-0CFC46937930}" = Opera 10.10
"{FFFF6D5C-E2F1-4B40-BC89-8923312E89EB}}_is1" = ACE Mega CoDecS Pack
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AI RoboForm" = AI RoboForm (All Users)
"A-PDF Text Extractor_is1" = A-PDF Text Extractor 1.3
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE
"CCleaner" = CCleaner (remove only)
"CDex" = CDex extraction audio
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"DUMeter3_is1" = DU Meter
"GTK 2.0" = GTK+ Runtime 2.14.7 rev a (odstranit)
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"Lexmark 2300 Series" = Lexmark 2300 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Maxthon2" = Maxthon2
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MiNODLogin" = ESET Antivirus License Finder (MiNODLogin)
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NodEnabler" = NodEnabler 3.0
"NVIDIA Drivers" = NVIDIA Drivers
"QIP Infium JadrisPack 2.5.0" = QIP Infium JadrisPack 2.5.0
"Revo Uninstaller" = Revo Uninstaller 1.83
"Smart Defrag_is1" = Smart Defrag 1.20
"softXpansion_de Toolbar" = softXpansion_de Toolbar
"STARTzjs" = STARTzjs
"szn-software-postak" = Seznam Pošťák 2 (Všichni uživatelé tohoto počítače.)
"TeamViewer 3" = TeamViewer 3
"Totalcmd" = Total Commander (Remove or Repair)
"Vienna Miranda Pack 1.1.0" = Vienna Miranda Pack 1.1.0
"VLC media player" = VLC media player 1.0.0
"VoipDiscount_is1" = VoipDiscount
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"wxDownload Fast_is1" = wxDownload Fast 0.6.0
"XP Codec Pack" = XP Codec Pack
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"xvid" = XviD MPEG-4 Video Codec

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-606747145-1897051121-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"szn-software-postak" = Seznam Pošťák 2 (Pouze já.)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 20.12.2009 1:32:30 | Computer Name = DOMOV-C63AFF276 | Source = MsiInstaller | ID = 10005
Description = Produkt: Microsoft .NET Framework 2.0 Service Pack 2 - Došlo k potížím
s tímto balíčkem Instalační služby systému Windows. Další informace naleznete v
protokolu instalace.

Error - 20.12.2009 1:32:41 | Computer Name = DOMOV-C63AFF276 | Source = MsiInstaller | ID = 1023
Description = Aktualizaci KB974417 produktu Microsoft .NET Framework 2.0 Service
Pack 2 nebylo možné nainstalovat. Kód chyby: 1603. Další informace naleznete v
souboru protokolu C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\Microsoft .NET
Framework 2.0-KB974417_20091220_053057265-Msi0.txt.

Error - 20.12.2009 1:32:42 | Computer Name = DOMOV-C63AFF276 | Source = HotFixInstaller | ID = 5000
Description = EventType visualstudio8setup, P1 microsoft .net framework 2.0-kb974417,
P2 1029, P3 1603, P4 msi, P5 f, P6 9.0.40302.0, P7 install, P8 x86, P9 xp, P10
0.

Error - 21.12.2009 7:01:38 | Computer Name = DOMOV-C63AFF276 | Source = MsiInstaller | ID = 10005
Description = Produkt: Microsoft .NET Framework 2.0 Service Pack 2 - Došlo k potížím
s tímto balíčkem Instalační služby systému Windows. Další informace naleznete v
protokolu instalace.

Error - 21.12.2009 7:02:07 | Computer Name = DOMOV-C63AFF276 | Source = MsiInstaller | ID = 1023
Description = Aktualizaci KB974417 produktu Microsoft .NET Framework 2.0 Service
Pack 2 nebylo možné nainstalovat. Kód chyby: 1603. Další informace naleznete v
souboru protokolu C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\Microsoft .NET
Framework 2.0-KB974417_20091221_105936484-Msi0.txt.

Error - 21.12.2009 7:02:08 | Computer Name = DOMOV-C63AFF276 | Source = HotFixInstaller | ID = 5000
Description = EventType visualstudio8setup, P1 microsoft .net framework 2.0-kb974417,
P2 1029, P3 1603, P4 msi, P5 f, P6 9.0.40302.0, P7 install, P8 x86, P9 xp, P10
0.

Error - 21.12.2009 17:38:13 | Computer Name = DOMOV-C63AFF276 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace Maxthon.exe, verze 2.5.10.2994, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 22.12.2009 6:38:10 | Computer Name = DOMOV-C63AFF276 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace Maxthon.exe, verze 2.5.10.2994, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 30.12.2009 12:53:28 | Computer Name = DOMOV-C63AFF276 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace chrome.exe, verze 0.0.0.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 11.1.2010 13:41:54 | Computer Name = DOMOV-C63AFF276 | Source = Application Error | ID = 1000
Description = Chybující aplikace iexplore.exe, verze 8.0.6001.18702, chybující modul
ieframe.dll, verze 8.0.6001.18854, adresa chyby 0x000b78e5.

[ Application Events ]
Error - 20.12.2009 1:32:30 | Computer Name = DOMOV-C63AFF276 | Source = MsiInstaller | ID = 10005
Description = Produkt: Microsoft .NET Framework 2.0 Service Pack 2 - Došlo k potížím
s tímto balíčkem Instalační služby systému Windows. Další informace naleznete v
protokolu instalace.

Error - 20.12.2009 1:32:41 | Computer Name = DOMOV-C63AFF276 | Source = MsiInstaller | ID = 1023
Description = Aktualizaci KB974417 produktu Microsoft .NET Framework 2.0 Service
Pack 2 nebylo možné nainstalovat. Kód chyby: 1603. Další informace naleznete v
souboru protokolu C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\Microsoft .NET
Framework 2.0-KB974417_20091220_053057265-Msi0.txt.

Error - 20.12.2009 1:32:42 | Computer Name = DOMOV-C63AFF276 | Source = HotFixInstaller | ID = 5000
Description = EventType visualstudio8setup, P1 microsoft .net framework 2.0-kb974417,
P2 1029, P3 1603, P4 msi, P5 f, P6 9.0.40302.0, P7 install, P8 x86, P9 xp, P10
0.

Error - 21.12.2009 7:01:38 | Computer Name = DOMOV-C63AFF276 | Source = MsiInstaller | ID = 10005
Description = Produkt: Microsoft .NET Framework 2.0 Service Pack 2 - Došlo k potížím
s tímto balíčkem Instalační služby systému Windows. Další informace naleznete v
protokolu instalace.

Error - 21.12.2009 7:02:07 | Computer Name = DOMOV-C63AFF276 | Source = MsiInstaller | ID = 1023
Description = Aktualizaci KB974417 produktu Microsoft .NET Framework 2.0 Service
Pack 2 nebylo možné nainstalovat. Kód chyby: 1603. Další informace naleznete v
souboru protokolu C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\Microsoft .NET
Framework 2.0-KB974417_20091221_105936484-Msi0.txt.

Error - 21.12.2009 7:02:08 | Computer Name = DOMOV-C63AFF276 | Source = HotFixInstaller | ID = 5000
Description = EventType visualstudio8setup, P1 microsoft .net framework 2.0-kb974417,
P2 1029, P3 1603, P4 msi, P5 f, P6 9.0.40302.0, P7 install, P8 x86, P9 xp, P10
0.

Error - 21.12.2009 17:38:13 | Computer Name = DOMOV-C63AFF276 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace Maxthon.exe, verze 2.5.10.2994, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 22.12.2009 6:38:10 | Computer Name = DOMOV-C63AFF276 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace Maxthon.exe, verze 2.5.10.2994, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 30.12.2009 12:53:28 | Computer Name = DOMOV-C63AFF276 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace chrome.exe, verze 0.0.0.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 11.1.2010 13:41:54 | Computer Name = DOMOV-C63AFF276 | Source = Application Error | ID = 1000
Description = Chybující aplikace iexplore.exe, verze 8.0.6001.18702, chybující modul
ieframe.dll, verze 8.0.6001.18854, adresa chyby 0x000b78e5.

[ System Events ]
Error - 15.1.2010 12:06:42 | Computer Name = DOMOV-C63AFF276 | Source = SRService | ID = 104
Description = Proces inicializace nástroje Obnovení systému se nezdařil.

Error - 15.1.2010 12:06:42 | Computer Name = DOMOV-C63AFF276 | Source = Service Control Manager | ID = 7023
Description = Služba Služba obnovení systému byla ukončena s následující chybou:
%%1359

Error - 15.1.2010 12:06:53 | Computer Name = DOMOV-C63AFF276 | Source = SRService | ID = 104
Description = Proces inicializace nástroje Obnovení systému se nezdařil.

Error - 15.1.2010 12:06:53 | Computer Name = DOMOV-C63AFF276 | Source = Service Control Manager | ID = 7023
Description = Služba Služba obnovení systému byla ukončena s následující chybou:
%%1359

Error - 15.1.2010 12:07:38 | Computer Name = DOMOV-C63AFF276 | Source = Service Control Manager | ID = 7034
Description = Služba ATK Keyboard Service byla neočekávaně ukončena. Tento stav
nastal již 1krát.

Error - 15.1.2010 12:18:54 | Computer Name = DOMOV-C63AFF276 | Source = SRService | ID = 104
Description = Proces inicializace nástroje Obnovení systému se nezdařil.

Error - 15.1.2010 12:18:54 | Computer Name = DOMOV-C63AFF276 | Source = Service Control Manager | ID = 7023
Description = Služba Služba obnovení systému byla ukončena s následující chybou:
%%1359

Error - 15.1.2010 12:21:02 | Computer Name = DOMOV-C63AFF276 | Source = SRService | ID = 104
Description = Proces inicializace nástroje Obnovení systému se nezdařil.

Error - 15.1.2010 12:21:02 | Computer Name = DOMOV-C63AFF276 | Source = Service Control Manager | ID = 7023
Description = Služba Služba obnovení systému byla ukončena s následující chybou:
%%1359

Error - 15.1.2010 12:22:04 | Computer Name = DOMOV-C63AFF276 | Source = Service Control Manager | ID = 7034
Description = Služba ATK Keyboard Service byla neočekávaně ukončena. Tento stav
nastal již 1krát.


< End of report >

Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu, seká se PC.

Příspěvekod Damned » 16 led 2010 06:11

Odinstaluj si softXpansion.
*****************************************************************************************************************************************
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions]
"Kaspersky Anti-Virus NDIS Miniport"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions]
"Kaspersky Anti-Virus NDIS Miniport"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions]
"Kaspersky Anti-Virus NDIS Miniport"=-



Ulož si ho jako na Plochu jako fix.reg a jako typ všechny soubory , najdi tento soubor na Ploše a poklepáním ho spusť. Budeš dotázána na přidání hodnoty do registru. Schval.
*****************************************************************************************************************************************
Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Custom Scans/Fixes do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://start.icq.com/"
FF - prefs.js..keyword.URL: "http://search.qip.ru/search?from=FF&query="
[2009.06.30 15:16:58 | 00,002,399 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\daemon-search.xml
[2010.01.07 21:18:33 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-1.xml
[2009.07.21 07:16:22 | 00,000,950 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-2.xml
[2009.07.21 11:00:07 | 00,000,950 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-3.xml
[2009.08.11 17:17:43 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-4.xml
[2009.09.19 07:38:27 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-5.xml
[2009.10.04 06:46:11 | 00,000,961 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-6.xml
[2008.11.18 12:56:02 | 00,000,944 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin.xml
[2009.07.21 07:16:29 | 00,009,941 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\mywebsearch.xml
[2009.09.08 05:48:42 | 00,002,061 | ---- | M] () -- C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\qipsearch.xml
O3 - HKCU\..\Toolbar\WebBrowser: (softXpansion_de Toolbar) - {5F4E4964-2E76-4F80-A012-ACB7E63A9CCD} - C:\Program Files\softXpansion_de\tbsof1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - Reg Error: Key error. File not found
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O24 - Desktop WallPaper: C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp

:Files
C:\Windows\*.tmp
C:\Windows\System32\*.tmp
C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\softXpansion_de
C:\Program Files\softXpansion_de
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\daemon-search.xml
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-1.xml
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-2.xml
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-3.xml
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-4.xml
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-5.xml
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-6.xml
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin.xml
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\mywebsearch.xml
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\qipsearch.xml

:Reg

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]



Poté klikni nahoře na Run Fix. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner

Ivey
Level 1.5
Level 1.5
Příspěvky: 123
Registrován: březen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu, seká se PC.

Příspěvekod Ivey » 16 led 2010 09:11

All processes killed
========== OTL ==========
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "ICQ Search" removed from browser.search.selectedEngine
Prefs.js: true removed from browser.search.useDBForOrder
Prefs.js: "http://start.icq.com/" removed from browser.startup.homepage
Prefs.js: "http://search.qip.ru/search?from=FF&query=" removed from keyword.URL
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\daemon-search.xml moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-1.xml moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-2.xml moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-3.xml moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-4.xml moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-5.xml moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-6.xml moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin.xml moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\mywebsearch.xml moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\qipsearch.xml moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5F4E4964-2E76-4F80-A012-ACB7E63A9CCD} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5F4E4964-2E76-4F80-A012-ACB7E63A9CCD}\ not found.
File C:\Program Files\softXpansion_de\tbsof1.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}\ not found.
Starting removal of ActiveX control {00000055-9980-0010-8000-00AA00389B71}
C:\WINDOWS\Downloaded Program Files\fhg.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000055-9980-0010-8000-00AA00389B71}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000055-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{00000055-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000055-9980-0010-8000-00AA00389B71}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General\\WallPaper deleted successfully.
C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General\\BackupWallPaper deleted successfully.
File C:\Documents and Settings\Ivana\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp not found.
========== FILES ==========
File\Folder C:\Windows\*.tmp not found.
File\Folder C:\Windows\System32\*.tmp not found.
C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\softXpansion_de\Logs folder moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\softXpansion_de folder moved successfully.
File\Folder C:\Program Files\softXpansion_de not found.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\defaults\preferences folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\defaults folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\components folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\skin\themes folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\skin\images folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\skin\icons folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\skin\css folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\skin folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\locale\ru-RU folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\locale\en-US folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\locale folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\content\thumbnail folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\content\template folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\content\java folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\content\about\theme\images folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\content\about\theme\icons folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\content\about\theme folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\content\about folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome\content folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us\chrome folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\fastdial@telega.phpnet.us folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com\searchplugins folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com\defaults\preferences folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com\defaults folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com\chrome\temp\skin.Thu-02-Jul-2009-16-29-28-GMT folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com\chrome\temp folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com\chrome\skin folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com\chrome\content folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com\chrome folder moved successfully.
C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\extensions\toolbar@ask.com folder moved successfully.
File\Folder C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\daemon-search.xml not found.
File\Folder C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-1.xml not found.
File\Folder C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-2.xml not found.
File\Folder C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-3.xml not found.
File\Folder C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-4.xml not found.
File\Folder C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-5.xml not found.
File\Folder C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin-6.xml not found.
File\Folder C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\icqplugin.xml not found.
File\Folder C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\mywebsearch.xml not found.
File\Folder C:\Documents and Settings\Ivana\Data aplikací\Mozilla\Firefox\Profiles\bylcflg3.default\searchplugins\qipsearch.xml not found.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Ivana
->Temp folder emptied: 157998 bytes
->Temporary Internet Files folder emptied: 2608365 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 108985717 bytes
->Google Chrome cache emptied: 43615911 bytes
->Apple Safari cache emptied: 212819132 bytes
->Opera cache emptied: 27566386 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 1768 bytes
->Temporary Internet Files folder emptied: 67 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 634907 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 32768 bytes
RecycleBin emptied: 305822 bytes

Total Files Cleaned = 378,00 mb


OTL by OldTimer - Version 3.1.25.0 log created on 01162010_090712

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: DotNetDotCom.org [Bot] a 80 hostů