Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:10:32, on 17.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Programy\Photoshop\PhotoshopElementsFileAgent.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Documents and Settings\Mulis\Plocha\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1750559
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Startup Cleaner] C:\Program Files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Aukro.lnk = E:\aukce\substitdisk.bat
O4 - Startup: Java.lnk = E:\Pavel\Java\substitdisk.bat
O4 - Startup: Web.lnk = E:\Pavel\www\substitdisk.bat
O4 - Global Startup: Microsoft Office.lnk = D:\Programy\MSOffice\Office10\OSA.EXE
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\Programy\MSOffice\Office10\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Programy\MSOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{343894D9-425C-44D6-B65A-827449F31D81}: NameServer = 85.13.126.75,77.236.208.82
O17 - HKLM\System\CS1\Services\Tcpip\..\{343894D9-425C-44D6-B65A-827449F31D81}: NameServer = 85.13.126.75,77.236.208.82
O17 - HKLM\System\CS2\Services\Tcpip\..\{343894D9-425C-44D6-B65A-827449F31D81}: NameServer = 77.236.209.35,77.236.208.82
O17 - HKLM\System\CS3\Services\Tcpip\..\{343894D9-425C-44D6-B65A-827449F31D81}: NameServer = 85.13.126.75,77.236.208.82
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - D:\Programy\Photoshop\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 7554 bytes
log HJT - prosím o kontrolu
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: log HJT - prosím o kontrolu
Odinstaluj si Crawler Toolbar. Vypni si štít Spyware Terminatora.
Spusť HJT (HijackThis), vypni prohlížeče, odpoj se od internetu a fixni (spustit HJT, "Do a system scan only",
zatrhnout políčko před hodnotou, zmáčknout "Fix checked" a poté "Ano"):
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1750559
R3 - URLSearchHook: (no name) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - (no file)
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - Startup: Aukro.lnk = E:\aukce\substitdisk.bat
O4 - Startup: Java.lnk = E:\Pavel\Java\substitdisk.bat
O4 - Startup: Web.lnk = E:\Pavel\www\substitdisk.bat
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
*****************************************************************************************************************************************
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Spusť HJT (HijackThis), vypni prohlížeče, odpoj se od internetu a fixni (spustit HJT, "Do a system scan only",
zatrhnout políčko před hodnotou, zmáčknout "Fix checked" a poté "Ano"):
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1750559
R3 - URLSearchHook: (no name) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - (no file)
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - Startup: Aukro.lnk = E:\aukce\substitdisk.bat
O4 - Startup: Java.lnk = E:\Pavel\Java\substitdisk.bat
O4 - Startup: Web.lnk = E:\Pavel\www\substitdisk.bat
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
*****************************************************************************************************************************************
Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Re: log HJT - prosím o kontrolu
Malwarebytes' Anti-Malware 1.44
Verze databáze: 3876
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
17.3.2010 18:17:02
mbam-log-2010-03-17 (18-17-02).txt
Typ kontroly: Rychlá kontrola
Zkontrolované objekty: 114127
Uplynulý čas: 3 minute(s), 47 second(s)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované adresáře: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)
Infikované soubory:
(Nebyly nalezeny žádné škodlivé položky)
Verze databáze: 3876
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
17.3.2010 18:17:02
mbam-log-2010-03-17 (18-17-02).txt
Typ kontroly: Rychlá kontrola
Zkontrolované objekty: 114127
Uplynulý čas: 3 minute(s), 47 second(s)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované adresáře: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované datové položky registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)
Infikované soubory:
(Nebyly nalezeny žádné škodlivé položky)
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: log HJT - prosím o kontrolu
Vypni rezidentní štít antiviru (pokud máš tak i antispyware).
Stáhni si ComboFix (by sUBs)
nebo ComboFix (subs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Stáhni si ComboFix (by sUBs)
nebo ComboFix (subs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Re: log HJT - prosím o kontrolu
ComboFix 10-03-16.05 - Mulis 17.03.2010 18:36:51.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3070.2589 [GMT 1:00]
Spuštěný z: c:\documents and settings\Mulis\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100317-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\regedit.com
c:\windows\system32\ieuinit.inf
c:\windows\system32\SHELLLNK.TLB
c:\windows\system32\taskmgr.com
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 17:06 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-17 17:06 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-27 08:26 . 2003-02-02 10:01 516656 ------w- c:\windows\system32\XceedCry.dll
2010-02-25 10:26 . 2010-02-25 10:26 -------- d---a-w- c:\windows\VDLL.DLL
2010-02-25 10:26 . 2010-02-25 10:26 -------- d---a-w- c:\windows\system32\runouce.exe
2010-02-25 10:26 . 2010-02-25 10:26 -------- d---a-w- c:\windows\RUNDL132.EXE
2010-02-25 10:26 . 2010-02-25 10:26 -------- d---a-w- c:\windows\logo_1.exe
2010-02-25 10:22 . 2010-02-25 10:22 632064 ----a-w- c:\windows\system32\msvcr80.dll
2010-02-25 10:22 . 2010-02-25 10:22 554240 ----a-w- c:\windows\system32\msvcp80.dll
2010-02-25 10:22 . 2010-02-25 10:22 34048 ----a-w- c:\windows\system32\eEmpty.exe
2010-02-25 10:21 . 2008-04-14 03:22 137216 ----a-w- c:\windows\system32\T.COM
2010-02-25 10:21 . 2008-04-14 03:22 147968 ----a-w- c:\windows\R.COM
2010-02-25 10:21 . 2010-02-25 10:21 -------- d-----w- c:\program files\Common Files\MicroWorld
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-17 17:00 . 2008-12-28 10:03 -------- d-----w- c:\program files\America's Army Server Manager
2010-03-16 17:35 . 2007-12-06 14:32 10 ----a-w- c:\windows\popcinfo.dat
2010-03-14 21:29 . 2010-02-03 10:23 -------- d-----w- c:\program files\WinClamAVShield
2010-03-13 19:13 . 2008-10-09 12:06 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-03-12 20:47 . 2010-02-03 15:15 -------- d-----w- c:\program files\SpeedFan
2010-03-12 19:14 . 2010-02-03 09:42 -------- d-----w- c:\program files\Spyware Terminator
2010-03-10 18:34 . 2007-12-05 19:24 94208 ----a-w- c:\windows\DUMP4601.tmp
2010-02-28 18:06 . 2007-12-05 19:24 94208 ----a-w- c:\windows\DUMP5ef8.tmp
2010-02-27 19:00 . 2007-12-05 18:26 -------- d-----w- c:\program files\ATI Technologies
2010-02-21 19:45 . 2008-12-27 15:13 138016 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-21 19:45 . 2008-12-27 15:13 189392 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-11 07:38 . 2006-08-02 22:07 3565056 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-02-11 05:17 . 2006-08-02 21:45 11845632 ----a-w- c:\windows\system32\atioglxx.dll
2010-02-11 05:07 . 2007-12-05 18:27 307200 ----a-w- c:\windows\system32\atiiiexx.dll
2010-02-11 04:46 . 2009-09-30 02:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-02-11 04:45 . 2006-08-02 22:08 325120 ----a-w- c:\windows\system32\ati2dvag.dll
2010-02-11 04:37 . 2009-09-30 01:26 290816 ----a-w- c:\windows\system32\atiok3x2.dll
2010-02-11 04:36 . 2006-08-02 22:02 204800 ----a-w- c:\windows\system32\atipdlxx.dll
2010-02-11 04:35 . 2006-08-02 22:02 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-02-11 04:35 . 2006-08-02 22:02 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-02-11 04:35 . 2006-08-02 22:02 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-02-11 04:35 . 2006-08-02 22:02 155648 ----a-w- c:\windows\system32\ati2evxx.dll
2010-02-11 04:33 . 2006-08-02 22:01 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2010-02-11 04:32 . 2006-08-02 22:00 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-02-11 04:25 . 2006-08-02 21:55 3818144 ----a-w- c:\windows\system32\ati3duag.dll
2010-02-11 04:23 . 2009-09-30 01:27 45056 ----a-w- c:\windows\system32\aticalrt.dll
2010-02-11 04:22 . 2009-09-30 01:27 45056 ----a-w- c:\windows\system32\aticalcl.dll
2010-02-11 04:21 . 2009-09-30 01:26 3227648 ----a-w- c:\windows\system32\aticaldd.dll
2010-02-11 04:19 . 2006-08-02 21:38 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-02-11 04:12 . 2006-08-02 21:51 2670592 ----a-w- c:\windows\system32\ativvaxx.dll
2010-02-11 04:12 . 2009-09-30 01:46 887724 ----a-w- c:\windows\system32\ativva6x.dat
2010-02-11 04:12 . 2009-09-30 01:46 3107788 ----a-w- c:\windows\system32\ativva5x.dat
2010-02-11 03:59 . 2009-09-30 01:34 49664 ----a-w- c:\windows\system32\amdpcom32.dll
2010-02-11 03:55 . 2006-08-02 21:41 475136 ----a-w- c:\windows\system32\atikvmag.dll
2010-02-11 03:54 . 2009-09-30 01:28 126976 ----a-w- c:\windows\system32\atiadlxx.dll
2010-02-11 03:53 . 2006-08-02 21:40 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-02-11 03:47 . 2006-08-02 21:35 626688 ----a-w- c:\windows\system32\ati2cqag.dll
2010-02-10 20:20 . 2007-12-05 18:27 593920 ------w- c:\windows\system32\ati2sgag.exe
2010-02-03 15:09 . 2010-02-03 15:09 -------- d-----w- c:\program files\Lavalys
2010-02-03 09:42 . 2010-02-03 09:42 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-01-31 20:36 . 2007-12-05 19:24 94208 ----a-w- c:\windows\DUMP3d47.tmp
2010-01-26 13:33 . 2010-01-26 13:33 0 ----a-w- c:\windows\ativpsrm.bin
2010-01-26 13:30 . 2007-12-05 18:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-31 16:50 . 2006-03-02 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:09 . 2006-03-02 12:00 668160 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:09 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2008-08-04 13:43 . 2008-08-04 13:43 14285 -c--a-w- c:\program files\settings.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2007-08-25 23090984]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2004-09-07 1871872]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2010-02-03 3037696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Startup Cleaner"="c:\program files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe" [2006-07-14 118784]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - d:\programy\MSOffice\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck xmnt2002 /bat=c:\windows\TEMP\PQ_BATCH.PQB /win=c:\windows /dbg=c:\WINDOWS\TEMP\PQ_DEBUG.TXT /ver=262144 /prd=PartitionMagic\0autocheck autochk *
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"d:\\Programy\\eMule\\emule.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Alc\\Stronghold\\Stronghold 2\\Stronghold2.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"d:\\Programy\\Java_Devl_kit_6_11\\jre\\bin\\java.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [7.12.2007 15:48 5248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [11.4.2008 15:50 114768]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [3.2.2010 10:42 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.4.2008 15:50 20560]
S0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [7.12.2007 15:48 160640]
S3 huadio;huadio;c:\windows\system32\huadio.tmp [5.12.2007 20:14 5318]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.7wolf.net
IE: E&xportovat do aplikace Microsoft Excel - d:\programy\MSOffice\Office10\EXCEL.EXE/3000
TCP: {343894D9-425C-44D6-B65A-827449F31D81} = 85.13.126.75,77.236.208.82
FF - ProfilePath - c:\documents and settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... ource=2&q=
FF - plugin: d:\program files\AdobeReader9\Reader\browser\nppdf32.dll
FF - plugin: d:\programy\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: d:\programy\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin2.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin3.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin4.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin5.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin6.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
FF - user.js: capability.policy.policynames - allowclipboard
FF - user.js: capability.policy.allowclipboard.sites - hxxp://mail1005.centrum.cz
FF - user.js: capability.policy.allowclipboard.Clipboard.cutcopy - allAccess
FF - user.js: capability.policy.allowclipboard.Clipboard.paste - allAccess
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-SkyTel - SkyTel.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 18:39
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\huadio]
"ImagePath"="\??\c:\windows\system32\huadio.tmp"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-03-17 18:40:07
ComboFix-quarantined-files.txt 2010-03-17 17:40
Před spuštěním: 1 380 593 664
Po spuštění: 1 410 781 184
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 17D323ABCE7A886C2B7970AF1368E526
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3070.2589 [GMT 1:00]
Spuštěný z: c:\documents and settings\Mulis\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100317-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\regedit.com
c:\windows\system32\ieuinit.inf
c:\windows\system32\SHELLLNK.TLB
c:\windows\system32\taskmgr.com
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 17:06 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-17 17:06 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-27 08:26 . 2003-02-02 10:01 516656 ------w- c:\windows\system32\XceedCry.dll
2010-02-25 10:26 . 2010-02-25 10:26 -------- d---a-w- c:\windows\VDLL.DLL
2010-02-25 10:26 . 2010-02-25 10:26 -------- d---a-w- c:\windows\system32\runouce.exe
2010-02-25 10:26 . 2010-02-25 10:26 -------- d---a-w- c:\windows\RUNDL132.EXE
2010-02-25 10:26 . 2010-02-25 10:26 -------- d---a-w- c:\windows\logo_1.exe
2010-02-25 10:22 . 2010-02-25 10:22 632064 ----a-w- c:\windows\system32\msvcr80.dll
2010-02-25 10:22 . 2010-02-25 10:22 554240 ----a-w- c:\windows\system32\msvcp80.dll
2010-02-25 10:22 . 2010-02-25 10:22 34048 ----a-w- c:\windows\system32\eEmpty.exe
2010-02-25 10:21 . 2008-04-14 03:22 137216 ----a-w- c:\windows\system32\T.COM
2010-02-25 10:21 . 2008-04-14 03:22 147968 ----a-w- c:\windows\R.COM
2010-02-25 10:21 . 2010-02-25 10:21 -------- d-----w- c:\program files\Common Files\MicroWorld
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-17 17:00 . 2008-12-28 10:03 -------- d-----w- c:\program files\America's Army Server Manager
2010-03-16 17:35 . 2007-12-06 14:32 10 ----a-w- c:\windows\popcinfo.dat
2010-03-14 21:29 . 2010-02-03 10:23 -------- d-----w- c:\program files\WinClamAVShield
2010-03-13 19:13 . 2008-10-09 12:06 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-03-12 20:47 . 2010-02-03 15:15 -------- d-----w- c:\program files\SpeedFan
2010-03-12 19:14 . 2010-02-03 09:42 -------- d-----w- c:\program files\Spyware Terminator
2010-03-10 18:34 . 2007-12-05 19:24 94208 ----a-w- c:\windows\DUMP4601.tmp
2010-02-28 18:06 . 2007-12-05 19:24 94208 ----a-w- c:\windows\DUMP5ef8.tmp
2010-02-27 19:00 . 2007-12-05 18:26 -------- d-----w- c:\program files\ATI Technologies
2010-02-21 19:45 . 2008-12-27 15:13 138016 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-21 19:45 . 2008-12-27 15:13 189392 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-11 07:38 . 2006-08-02 22:07 3565056 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-02-11 05:17 . 2006-08-02 21:45 11845632 ----a-w- c:\windows\system32\atioglxx.dll
2010-02-11 05:07 . 2007-12-05 18:27 307200 ----a-w- c:\windows\system32\atiiiexx.dll
2010-02-11 04:46 . 2009-09-30 02:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-02-11 04:45 . 2006-08-02 22:08 325120 ----a-w- c:\windows\system32\ati2dvag.dll
2010-02-11 04:37 . 2009-09-30 01:26 290816 ----a-w- c:\windows\system32\atiok3x2.dll
2010-02-11 04:36 . 2006-08-02 22:02 204800 ----a-w- c:\windows\system32\atipdlxx.dll
2010-02-11 04:35 . 2006-08-02 22:02 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-02-11 04:35 . 2006-08-02 22:02 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-02-11 04:35 . 2006-08-02 22:02 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-02-11 04:35 . 2006-08-02 22:02 155648 ----a-w- c:\windows\system32\ati2evxx.dll
2010-02-11 04:33 . 2006-08-02 22:01 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2010-02-11 04:32 . 2006-08-02 22:00 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-02-11 04:25 . 2006-08-02 21:55 3818144 ----a-w- c:\windows\system32\ati3duag.dll
2010-02-11 04:23 . 2009-09-30 01:27 45056 ----a-w- c:\windows\system32\aticalrt.dll
2010-02-11 04:22 . 2009-09-30 01:27 45056 ----a-w- c:\windows\system32\aticalcl.dll
2010-02-11 04:21 . 2009-09-30 01:26 3227648 ----a-w- c:\windows\system32\aticaldd.dll
2010-02-11 04:19 . 2006-08-02 21:38 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-02-11 04:12 . 2006-08-02 21:51 2670592 ----a-w- c:\windows\system32\ativvaxx.dll
2010-02-11 04:12 . 2009-09-30 01:46 887724 ----a-w- c:\windows\system32\ativva6x.dat
2010-02-11 04:12 . 2009-09-30 01:46 3107788 ----a-w- c:\windows\system32\ativva5x.dat
2010-02-11 03:59 . 2009-09-30 01:34 49664 ----a-w- c:\windows\system32\amdpcom32.dll
2010-02-11 03:55 . 2006-08-02 21:41 475136 ----a-w- c:\windows\system32\atikvmag.dll
2010-02-11 03:54 . 2009-09-30 01:28 126976 ----a-w- c:\windows\system32\atiadlxx.dll
2010-02-11 03:53 . 2006-08-02 21:40 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-02-11 03:47 . 2006-08-02 21:35 626688 ----a-w- c:\windows\system32\ati2cqag.dll
2010-02-10 20:20 . 2007-12-05 18:27 593920 ------w- c:\windows\system32\ati2sgag.exe
2010-02-03 15:09 . 2010-02-03 15:09 -------- d-----w- c:\program files\Lavalys
2010-02-03 09:42 . 2010-02-03 09:42 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-01-31 20:36 . 2007-12-05 19:24 94208 ----a-w- c:\windows\DUMP3d47.tmp
2010-01-26 13:33 . 2010-01-26 13:33 0 ----a-w- c:\windows\ativpsrm.bin
2010-01-26 13:30 . 2007-12-05 18:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-31 16:50 . 2006-03-02 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:09 . 2006-03-02 12:00 668160 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:09 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2008-08-04 13:43 . 2008-08-04 13:43 14285 -c--a-w- c:\program files\settings.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2007-08-25 23090984]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2004-09-07 1871872]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2010-02-03 3037696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Startup Cleaner"="c:\program files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe" [2006-07-14 118784]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - d:\programy\MSOffice\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck xmnt2002 /bat=c:\windows\TEMP\PQ_BATCH.PQB /win=c:\windows /dbg=c:\WINDOWS\TEMP\PQ_DEBUG.TXT /ver=262144 /prd=PartitionMagic\0autocheck autochk *
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"d:\\Programy\\eMule\\emule.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Alc\\Stronghold\\Stronghold 2\\Stronghold2.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"d:\\Programy\\Java_Devl_kit_6_11\\jre\\bin\\java.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [7.12.2007 15:48 5248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [11.4.2008 15:50 114768]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [3.2.2010 10:42 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.4.2008 15:50 20560]
S0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [7.12.2007 15:48 160640]
S3 huadio;huadio;c:\windows\system32\huadio.tmp [5.12.2007 20:14 5318]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.7wolf.net
IE: E&xportovat do aplikace Microsoft Excel - d:\programy\MSOffice\Office10\EXCEL.EXE/3000
TCP: {343894D9-425C-44D6-B65A-827449F31D81} = 85.13.126.75,77.236.208.82
FF - ProfilePath - c:\documents and settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... ource=2&q=
FF - plugin: d:\program files\AdobeReader9\Reader\browser\nppdf32.dll
FF - plugin: d:\programy\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: d:\programy\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin2.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin3.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin4.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin5.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin6.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
FF - user.js: capability.policy.policynames - allowclipboard
FF - user.js: capability.policy.allowclipboard.sites - hxxp://mail1005.centrum.cz
FF - user.js: capability.policy.allowclipboard.Clipboard.cutcopy - allAccess
FF - user.js: capability.policy.allowclipboard.Clipboard.paste - allAccess
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-SkyTel - SkyTel.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 18:39
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\huadio]
"ImagePath"="\??\c:\windows\system32\huadio.tmp"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-03-17 18:40:07
ComboFix-quarantined-files.txt 2010-03-17 17:40
Před spuštěním: 1 380 593 664
Po spuštění: 1 410 781 184
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 17D323ABCE7A886C2B7970AF1368E526
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: log HJT - prosím o kontrolu
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok).
Zkopíruj do něj následující celý text označený zeleně:
File::
c:\windows\system32\eEmpty.exe
c:\windows\popcinfo.dat
c:\windows\DUMP4601.tmp
c:\windows\DUMP5ef8.tmp
c:\windows\DUMP3d47.tmp
c:\windows\ativpsrm.bin
c:\program files\settings.dat
Folder::
c:\windows\VDLL.DLL
c:\windows\system32\runouce.exe
c:\windows\RUNDL132.EXE
c:\windows\logo_1.exe
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminatorUpdate"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\dpvsetup.exe"=-
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=-
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe
a když se oba soubory překryjí, skript upusť.

- Automaticky se spustí ComboFix, oprava může trvat i déle než 10 minut. ! Nech ComboFix dokončit svou práci !
- Vlož sem log, který vyběhne v závěru čistícího procesu
Zkopíruj do něj následující celý text označený zeleně:
File::
c:\windows\system32\eEmpty.exe
c:\windows\popcinfo.dat
c:\windows\DUMP4601.tmp
c:\windows\DUMP5ef8.tmp
c:\windows\DUMP3d47.tmp
c:\windows\ativpsrm.bin
c:\program files\settings.dat
Folder::
c:\windows\VDLL.DLL
c:\windows\system32\runouce.exe
c:\windows\RUNDL132.EXE
c:\windows\logo_1.exe
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminatorUpdate"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\dpvsetup.exe"=-
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=-
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe
a když se oba soubory překryjí, skript upusť.

- Automaticky se spustí ComboFix, oprava může trvat i déle než 10 minut. ! Nech ComboFix dokončit svou práci !
- Vlož sem log, který vyběhne v závěru čistícího procesu
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Re: log HJT - prosím o kontrolu
ComboFix 10-03-16.05 - Mulis 17.03.2010 19:19:03.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3070.2606 [GMT 1:00]
Spuštěný z: c:\documents and settings\Mulis\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Mulis\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100317-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\program files\settings.dat"
"c:\windows\ativpsrm.bin"
"c:\windows\DUMP3d47.tmp"
"c:\windows\DUMP4601.tmp"
"c:\windows\DUMP5ef8.tmp"
"c:\windows\popcinfo.dat"
"c:\windows\system32\eEmpty.exe"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\settings.dat
c:\windows\ativpsrm.bin
c:\windows\DUMP3d47.tmp
c:\windows\DUMP4601.tmp
c:\windows\DUMP5ef8.tmp
c:\windows\logo_1.exe
c:\windows\popcinfo.dat
c:\windows\RUNDL132.EXE
c:\windows\system32\eEmpty.exe
c:\windows\system32\runouce.exe
c:\windows\VDLL.DLL
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 17:06 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-17 17:06 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-27 08:26 . 2003-02-02 10:01 516656 ------w- c:\windows\system32\XceedCry.dll
2010-02-25 10:22 . 2010-02-25 10:22 632064 ----a-w- c:\windows\system32\msvcr80.dll
2010-02-25 10:22 . 2010-02-25 10:22 554240 ----a-w- c:\windows\system32\msvcp80.dll
2010-02-25 10:21 . 2008-04-14 03:22 137216 ----a-w- c:\windows\system32\T.COM
2010-02-25 10:21 . 2008-04-14 03:22 147968 ----a-w- c:\windows\R.COM
2010-02-25 10:21 . 2010-02-25 10:21 -------- d-----w- c:\program files\Common Files\MicroWorld
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-17 17:00 . 2008-12-28 10:03 -------- d-----w- c:\program files\America's Army Server Manager
2010-03-14 21:29 . 2010-02-03 10:23 -------- d-----w- c:\program files\WinClamAVShield
2010-03-13 19:13 . 2008-10-09 12:06 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-03-12 20:47 . 2010-02-03 15:15 -------- d-----w- c:\program files\SpeedFan
2010-03-12 19:14 . 2010-02-03 09:42 -------- d-----w- c:\program files\Spyware Terminator
2010-02-27 19:00 . 2007-12-05 18:26 -------- d-----w- c:\program files\ATI Technologies
2010-02-21 19:45 . 2008-12-27 15:13 138016 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-21 19:45 . 2008-12-27 15:13 189392 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-11 07:38 . 2006-08-02 22:07 3565056 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-02-11 05:17 . 2006-08-02 21:45 11845632 ----a-w- c:\windows\system32\atioglxx.dll
2010-02-11 05:07 . 2007-12-05 18:27 307200 ----a-w- c:\windows\system32\atiiiexx.dll
2010-02-11 04:46 . 2009-09-30 02:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-02-11 04:45 . 2006-08-02 22:08 325120 ----a-w- c:\windows\system32\ati2dvag.dll
2010-02-11 04:37 . 2009-09-30 01:26 290816 ----a-w- c:\windows\system32\atiok3x2.dll
2010-02-11 04:36 . 2006-08-02 22:02 204800 ----a-w- c:\windows\system32\atipdlxx.dll
2010-02-11 04:35 . 2006-08-02 22:02 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-02-11 04:35 . 2006-08-02 22:02 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-02-11 04:35 . 2006-08-02 22:02 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-02-11 04:35 . 2006-08-02 22:02 155648 ----a-w- c:\windows\system32\ati2evxx.dll
2010-02-11 04:33 . 2006-08-02 22:01 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2010-02-11 04:32 . 2006-08-02 22:00 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-02-11 04:25 . 2006-08-02 21:55 3818144 ----a-w- c:\windows\system32\ati3duag.dll
2010-02-11 04:23 . 2009-09-30 01:27 45056 ----a-w- c:\windows\system32\aticalrt.dll
2010-02-11 04:22 . 2009-09-30 01:27 45056 ----a-w- c:\windows\system32\aticalcl.dll
2010-02-11 04:21 . 2009-09-30 01:26 3227648 ----a-w- c:\windows\system32\aticaldd.dll
2010-02-11 04:19 . 2006-08-02 21:38 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-02-11 04:12 . 2006-08-02 21:51 2670592 ----a-w- c:\windows\system32\ativvaxx.dll
2010-02-11 04:12 . 2009-09-30 01:46 887724 ----a-w- c:\windows\system32\ativva6x.dat
2010-02-11 04:12 . 2009-09-30 01:46 3107788 ----a-w- c:\windows\system32\ativva5x.dat
2010-02-11 03:59 . 2009-09-30 01:34 49664 ----a-w- c:\windows\system32\amdpcom32.dll
2010-02-11 03:55 . 2006-08-02 21:41 475136 ----a-w- c:\windows\system32\atikvmag.dll
2010-02-11 03:54 . 2009-09-30 01:28 126976 ----a-w- c:\windows\system32\atiadlxx.dll
2010-02-11 03:53 . 2006-08-02 21:40 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-02-11 03:47 . 2006-08-02 21:35 626688 ----a-w- c:\windows\system32\ati2cqag.dll
2010-02-10 20:20 . 2007-12-05 18:27 593920 ------w- c:\windows\system32\ati2sgag.exe
2010-02-03 15:09 . 2010-02-03 15:09 -------- d-----w- c:\program files\Lavalys
2010-02-03 09:42 . 2010-02-03 09:42 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-01-26 13:30 . 2007-12-05 18:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-31 16:50 . 2006-03-02 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:09 . 2006-03-02 12:00 668160 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:09 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-03-17_17.39.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-17 18:17 . 2010-03-17 18:17 16384 c:\windows\Temp\Perflib_Perfdata_584.dat
+ 2010-03-17 18:17 . 2010-03-17 18:17 16384 c:\windows\Temp\Perflib_Perfdata_4a8.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2007-08-25 23090984]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2004-09-07 1871872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Startup Cleaner"="c:\program files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe" [2006-07-14 118784]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - d:\programy\MSOffice\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck xmnt2002 /bat=c:\windows\TEMP\PQ_BATCH.PQB /win=c:\windows /dbg=c:\WINDOWS\TEMP\PQ_DEBUG.TXT /ver=262144 /prd=PartitionMagic\0autocheck autochk *
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"d:\\Programy\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Alc\\Stronghold\\Stronghold 2\\Stronghold2.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"d:\\Programy\\Java_Devl_kit_6_11\\jre\\bin\\java.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [7.12.2007 15:48 5248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [11.4.2008 15:50 114768]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [3.2.2010 10:42 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.4.2008 15:50 20560]
S0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [7.12.2007 15:48 160640]
S3 huadio;huadio;c:\windows\system32\huadio.tmp [5.12.2007 20:14 5318]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.7wolf.net
IE: E&xportovat do aplikace Microsoft Excel - d:\programy\MSOffice\Office10\EXCEL.EXE/3000
TCP: {343894D9-425C-44D6-B65A-827449F31D81} = 85.13.126.75,77.236.208.82
FF - ProfilePath - c:\documents and settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... ource=2&q=
FF - plugin: d:\program files\AdobeReader9\Reader\browser\nppdf32.dll
FF - plugin: d:\programy\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: d:\programy\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin2.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin3.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin4.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin5.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin6.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
FF - user.js: capability.policy.policynames - allowclipboard
FF - user.js: capability.policy.allowclipboard.sites - hxxp://mail1005.centrum.cz
FF - user.js: capability.policy.allowclipboard.Clipboard.cutcopy - allAccess
FF - user.js: capability.policy.allowclipboard.Clipboard.paste - allAccess
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 19:21
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\huadio]
"ImagePath"="\??\c:\windows\system32\huadio.tmp"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-03-17 19:22:44
ComboFix-quarantined-files.txt 2010-03-17 18:22
ComboFix2.txt 2010-03-17 17:40
Před spuštěním: 1 415 606 272
Po spuštění: 1 406 238 720
- - End Of File - - 4862E16B5E072B9C254A8E3E8E25F61B
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3070.2606 [GMT 1:00]
Spuštěný z: c:\documents and settings\Mulis\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Mulis\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100317-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\program files\settings.dat"
"c:\windows\ativpsrm.bin"
"c:\windows\DUMP3d47.tmp"
"c:\windows\DUMP4601.tmp"
"c:\windows\DUMP5ef8.tmp"
"c:\windows\popcinfo.dat"
"c:\windows\system32\eEmpty.exe"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\settings.dat
c:\windows\ativpsrm.bin
c:\windows\DUMP3d47.tmp
c:\windows\DUMP4601.tmp
c:\windows\DUMP5ef8.tmp
c:\windows\logo_1.exe
c:\windows\popcinfo.dat
c:\windows\RUNDL132.EXE
c:\windows\system32\eEmpty.exe
c:\windows\system32\runouce.exe
c:\windows\VDLL.DLL
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-17 do 2010-03-17 )))))))))))))))))))))))))))))))
.
2010-03-17 17:06 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-17 17:06 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-27 08:26 . 2003-02-02 10:01 516656 ------w- c:\windows\system32\XceedCry.dll
2010-02-25 10:22 . 2010-02-25 10:22 632064 ----a-w- c:\windows\system32\msvcr80.dll
2010-02-25 10:22 . 2010-02-25 10:22 554240 ----a-w- c:\windows\system32\msvcp80.dll
2010-02-25 10:21 . 2008-04-14 03:22 137216 ----a-w- c:\windows\system32\T.COM
2010-02-25 10:21 . 2008-04-14 03:22 147968 ----a-w- c:\windows\R.COM
2010-02-25 10:21 . 2010-02-25 10:21 -------- d-----w- c:\program files\Common Files\MicroWorld
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-17 17:00 . 2008-12-28 10:03 -------- d-----w- c:\program files\America's Army Server Manager
2010-03-14 21:29 . 2010-02-03 10:23 -------- d-----w- c:\program files\WinClamAVShield
2010-03-13 19:13 . 2008-10-09 12:06 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-03-12 20:47 . 2010-02-03 15:15 -------- d-----w- c:\program files\SpeedFan
2010-03-12 19:14 . 2010-02-03 09:42 -------- d-----w- c:\program files\Spyware Terminator
2010-02-27 19:00 . 2007-12-05 18:26 -------- d-----w- c:\program files\ATI Technologies
2010-02-21 19:45 . 2008-12-27 15:13 138016 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-21 19:45 . 2008-12-27 15:13 189392 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-02-11 07:38 . 2006-08-02 22:07 3565056 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-02-11 05:17 . 2006-08-02 21:45 11845632 ----a-w- c:\windows\system32\atioglxx.dll
2010-02-11 05:07 . 2007-12-05 18:27 307200 ----a-w- c:\windows\system32\atiiiexx.dll
2010-02-11 04:46 . 2009-09-30 02:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-02-11 04:45 . 2006-08-02 22:08 325120 ----a-w- c:\windows\system32\ati2dvag.dll
2010-02-11 04:37 . 2009-09-30 01:26 290816 ----a-w- c:\windows\system32\atiok3x2.dll
2010-02-11 04:36 . 2006-08-02 22:02 204800 ----a-w- c:\windows\system32\atipdlxx.dll
2010-02-11 04:35 . 2006-08-02 22:02 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-02-11 04:35 . 2006-08-02 22:02 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-02-11 04:35 . 2006-08-02 22:02 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-02-11 04:35 . 2006-08-02 22:02 155648 ----a-w- c:\windows\system32\ati2evxx.dll
2010-02-11 04:33 . 2006-08-02 22:01 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2010-02-11 04:32 . 2006-08-02 22:00 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-02-11 04:25 . 2006-08-02 21:55 3818144 ----a-w- c:\windows\system32\ati3duag.dll
2010-02-11 04:23 . 2009-09-30 01:27 45056 ----a-w- c:\windows\system32\aticalrt.dll
2010-02-11 04:22 . 2009-09-30 01:27 45056 ----a-w- c:\windows\system32\aticalcl.dll
2010-02-11 04:21 . 2009-09-30 01:26 3227648 ----a-w- c:\windows\system32\aticaldd.dll
2010-02-11 04:19 . 2006-08-02 21:38 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-02-11 04:12 . 2006-08-02 21:51 2670592 ----a-w- c:\windows\system32\ativvaxx.dll
2010-02-11 04:12 . 2009-09-30 01:46 887724 ----a-w- c:\windows\system32\ativva6x.dat
2010-02-11 04:12 . 2009-09-30 01:46 3107788 ----a-w- c:\windows\system32\ativva5x.dat
2010-02-11 03:59 . 2009-09-30 01:34 49664 ----a-w- c:\windows\system32\amdpcom32.dll
2010-02-11 03:55 . 2006-08-02 21:41 475136 ----a-w- c:\windows\system32\atikvmag.dll
2010-02-11 03:54 . 2009-09-30 01:28 126976 ----a-w- c:\windows\system32\atiadlxx.dll
2010-02-11 03:53 . 2006-08-02 21:40 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-02-11 03:47 . 2006-08-02 21:35 626688 ----a-w- c:\windows\system32\ati2cqag.dll
2010-02-10 20:20 . 2007-12-05 18:27 593920 ------w- c:\windows\system32\ati2sgag.exe
2010-02-03 15:09 . 2010-02-03 15:09 -------- d-----w- c:\program files\Lavalys
2010-02-03 09:42 . 2010-02-03 09:42 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-01-26 13:30 . 2007-12-05 18:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-31 16:50 . 2006-03-02 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:09 . 2006-03-02 12:00 668160 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:09 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-03-17_17.39.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-17 18:17 . 2010-03-17 18:17 16384 c:\windows\Temp\Perflib_Perfdata_584.dat
+ 2010-03-17 18:17 . 2010-03-17 18:17 16384 c:\windows\Temp\Perflib_Perfdata_4a8.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2007-08-25 23090984]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2004-09-07 1871872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Startup Cleaner"="c:\program files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe" [2006-07-14 118784]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - d:\programy\MSOffice\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck xmnt2002 /bat=c:\windows\TEMP\PQ_BATCH.PQB /win=c:\windows /dbg=c:\WINDOWS\TEMP\PQ_DEBUG.TXT /ver=262144 /prd=PartitionMagic\0autocheck autochk *
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"d:\\Programy\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Alc\\Stronghold\\Stronghold 2\\Stronghold2.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"d:\\Programy\\Java_Devl_kit_6_11\\jre\\bin\\java.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [7.12.2007 15:48 5248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [11.4.2008 15:50 114768]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [3.2.2010 10:42 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.4.2008 15:50 20560]
S0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [7.12.2007 15:48 160640]
S3 huadio;huadio;c:\windows\system32\huadio.tmp [5.12.2007 20:14 5318]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.7wolf.net
IE: E&xportovat do aplikace Microsoft Excel - d:\programy\MSOffice\Office10\EXCEL.EXE/3000
TCP: {343894D9-425C-44D6-B65A-827449F31D81} = 85.13.126.75,77.236.208.82
FF - ProfilePath - c:\documents and settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... ource=2&q=
FF - plugin: d:\program files\AdobeReader9\Reader\browser\nppdf32.dll
FF - plugin: d:\programy\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: d:\programy\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin2.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin3.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin4.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin5.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin6.dll
FF - plugin: d:\programy\quicktime\Plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
FF - user.js: capability.policy.policynames - allowclipboard
FF - user.js: capability.policy.allowclipboard.sites - hxxp://mail1005.centrum.cz
FF - user.js: capability.policy.allowclipboard.Clipboard.cutcopy - allAccess
FF - user.js: capability.policy.allowclipboard.Clipboard.paste - allAccess
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-17 19:21
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\huadio]
"ImagePath"="\??\c:\windows\system32\huadio.tmp"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-03-17 19:22:44
ComboFix-quarantined-files.txt 2010-03-17 18:22
ComboFix2.txt 2010-03-17 17:40
Před spuštěním: 1 415 606 272
Po spuštění: 1 406 238 720
- - End Of File - - 4862E16B5E072B9C254A8E3E8E25F61B
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: log HJT - prosím o kontrolu
Odinstaluj ComboFix ( nutné ) .
ComboFix se odinstaluje takto:
Start-Spustit a zadej: Combofix[mezera]/uninstall
Stáhni si T-Cleaner ( nutné - smaže vše po Combu,SDFixu,Avengeru,MWAVu atd.-stáhneš->spustíš)
(pozn.Pokud máš AVG nebo Aviru, před stažením T-Cleaneru a po dobu čištění deaktivuj AVG i Aviru (i rezidenty), následně T-Cleaner smaž a zapni si AVG, Aviru.)
*****************************************************************************************************************************************
Stáhni si OTL na Plochu.
Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Output klikni na minimal Output.Pod Standard Registry změň na All. Zatrhni LOP Check a Purity Check. File age změň na 14 days. Všechny ostatní nastavení ponech jak jsou. Klikni na Run Scan. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt
Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj
ComboFix se odinstaluje takto:
Start-Spustit a zadej: Combofix[mezera]/uninstall
Stáhni si T-Cleaner ( nutné - smaže vše po Combu,SDFixu,Avengeru,MWAVu atd.-stáhneš->spustíš)
(pozn.Pokud máš AVG nebo Aviru, před stažením T-Cleaneru a po dobu čištění deaktivuj AVG i Aviru (i rezidenty), následně T-Cleaner smaž a zapni si AVG, Aviru.)
*****************************************************************************************************************************************
Stáhni si OTL na Plochu.
Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Output klikni na minimal Output.Pod Standard Registry změň na All. Zatrhni LOP Check a Purity Check. File age změň na 14 days. Všechny ostatní nastavení ponech jak jsou. Klikni na Run Scan. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt
Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Re: log HJT - prosím o kontrolu
OTL logfile created on: 19.3.2010 18:06:53 - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Mulis\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 84,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9,77 Gb Total Space | 1,43 Gb Free Space | 14,65% Space Free | Partition Type: NTFS
Drive D: | 135,22 Gb Total Space | 16,93 Gb Free Space | 12,52% Space Free | Partition Type: NTFS
Drive E: | 87,89 Gb Total Space | 5,27 Gb Free Space | 5,99% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
Drive G: | 4,34 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive H: | 142,05 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
I: Drive not present or media not loaded
Computer Name: P-B6CB0A05E8944
Current User Name: Mulis
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 14 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Mulis\Plocha\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - D:\Programy\Photoshop\PhotoshopElementsFileAgent.exe ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Mulis\Plocha\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (sp_rssrv) -- C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (NetTcpPortSharing) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (AdobeActiveFileMonitor5.0) -- D:\Programy\Photoshop\PhotoshopElementsFileAgent.exe ()
SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
========== Driver Services (SafeList) ==========
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (sp_rsdrv2) -- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ()
DRV - (aswMon2) -- C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) -- C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) -- C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) -- C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) -- C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (huadio) -- C:\WINDOWS\system32\huadio.tmp (Windows (R) 2000 DDK provider)
DRV - (speedfan) -- C:\WINDOWS\system32\speedfan.sys (Windows (R) 2000 DDK provider)
DRV - (GVCplDrv) -- C:\WINDOWS\system32\drivers\GVCplDrv.sys ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (JRAID) -- C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (yukonwxp) -- C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (HPFXBULK) -- C:\WINDOWS\system32\drivers\hpfxbulk.sys (Hewlett Packard)
DRV - (ET5Drv) -- C:\WINDOWS\system32\drivers\ET5Drv.sys (Microsoft Corporation)
DRV - (JGOGO) -- C:\WINDOWS\system32\DRIVERS\JGOGO.sys (JMicron )
DRV - (prohlp02) -- C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prodrv06) -- C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (a347bus) -- C:\WINDOWS\system32\DRIVERS\a347bus.sys ( )
DRV - (a347scsi) -- C:\WINDOWS\System32\Drivers\a347scsi.sys ( )
DRV - (cdrbsdrv) -- C:\WINDOWS\system32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (sfhlp01) -- C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (prosync1) -- C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology)
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.7wolf.net
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "BS_Player Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.cz/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.18
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&q="
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008.11.18 21:03:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009.09.02 21:59:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.03.10 20:48:36 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.02.19 23:44:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009.12.03 16:28:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2009.06.25 15:02:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Extensions
[2009.04.18 10:21:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009.06.25 15:02:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Extensions\MediaCoder
[2010.03.16 22:41:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\extensions
[2009.09.03 09:37:52 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008.11.15 04:28:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009.06.25 11:37:39 | 000,000,000 | ---D | M] (BS Player Toolbar) -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
[2009.02.26 13:22:28 | 000,000,880 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\conduit.xml
[2010.03.16 18:46:14 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-1.xml
[2009.04.18 10:21:49 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-10.xml
[2009.04.25 20:19:55 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-11.xml
[2009.04.29 10:47:35 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-12.xml
[2009.06.13 09:16:00 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-13.xml
[2009.07.23 08:15:35 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-14.xml
[2009.08.04 21:02:59 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-15.xml
[2009.09.12 11:02:51 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-16.xml
[2008.09.21 20:54:30 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-2.xml
[2008.04.17 20:23:09 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-3.xml
[2008.07.04 17:40:57 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-4.xml
[2008.07.16 21:33:55 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-5.xml
[2008.11.14 17:40:19 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-6.xml
[2008.11.15 04:29:00 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-7.xml
[2008.12.18 23:32:26 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-8.xml
[2008.12.19 22:42:44 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-9.xml
[2008.02.08 21:44:19 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin.xml
[2010.03.16 22:41:23 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.02.19 23:43:55 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007.12.07 11:43:24 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2007.12.10 14:14:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008.03.20 16:55:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008.11.18 21:03:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2008.12.06 17:50:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2010.02.19 23:43:55 | 000,023,000 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010.02.19 23:43:55 | 000,134,616 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2007.08.07 13:35:32 | 000,049,152 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
[2008.11.10 05:43:30 | 000,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
[2010.02.19 23:43:57 | 000,065,496 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2009.02.27 12:13:42 | 000,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2007.10.25 03:00:00 | 000,144,720 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2007.10.25 03:00:00 | 000,081,920 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
[2009.08.25 08:32:38 | 000,001,340 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
[2008.04.16 05:08:20 | 000,001,706 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2008.03.31 20:06:24 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2008.03.31 20:06:24 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2008.01.27 10:57:20 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2008.01.27 10:57:20 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2008.03.31 20:06:24 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2006.03.02 13:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Adresa) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O3 - HKCU\..\Toolbar\WebBrowser: (&Odkazy) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Startup Cleaner] C:\Program Files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe (CM DiskCleaner)
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKCU..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk = D:\Programy\MSOffice\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - D:\Programy\MSOffice\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Proces mezipaměti kategorií součástí - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Mulis\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mulis\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005.07.01 07:39:37 | 000,000,059 | R--- | M] () - H:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck xmnt2002 /bat=C:\WINDOWS\TEMP\PQ_BATCH.PQB /win=C:\WINDOWS /dbg=C:\WINDOWS\TEMP\PQ_DEBUG.TXT /ver=262144 /prd=PartitionMagic) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 14 Days ==========
[2010.03.19 18:05:23 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mulis\Plocha\OTL.exe
[2010.03.19 18:04:45 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.03.17 18:36:06 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.03.17 18:10:18 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browserchoice.exe
[2010.03.17 18:06:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mulis\Data aplikací\Malwarebytes
[2010.03.17 18:06:04 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.03.17 18:06:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.03.17 18:06:02 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.03.17 17:55:22 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Mulis\Recent
[2010.03.17 17:50:44 | 005,115,832 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mulis\Plocha\mbam-setup.exe
[2010.03.17 17:49:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mulis\Plocha\backups
[2010.03.17 16:09:07 | 000,396,288 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Mulis\Plocha\hijackthis.exe
[2010.03.16 18:48:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mulis\Plocha\Sv.šaty
[2010.03.13 19:58:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mulis\Plocha\Dandy
[2008.12.28 16:36:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Xfire
[2008.10.16 07:52:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2007.12.07 15:48:48 | 000,160,640 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347bus.sys
[2007.12.07 15:48:48 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347scsi.sys
[2007.12.06 15:00:06 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2007.12.05 18:59:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2007.12.05 18:56:48 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[10 C:\Documents and Settings\Mulis\Dokumenty\*.tmp files -> C:\Documents and Settings\Mulis\Dokumenty\*.tmp -> ]
========== Files - Modified Within 14 Days ==========
[2010.03.19 18:05:29 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mulis\Plocha\OTL.exe
[2010.03.19 17:59:48 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.03.19 17:58:53 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.03.19 17:58:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.03.19 17:58:02 | 005,767,168 | -H-- | M] () -- C:\Documents and Settings\Mulis\NTUSER.DAT
[2010.03.19 17:58:02 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Mulis\ntuser.ini
[2010.03.19 17:54:28 | 000,000,264 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.03.17 22:12:57 | 000,000,000 | ---- | M] () -- C:\WINDOWS\ativpsrm.bin
[2010.03.17 21:50:48 | 000,000,010 | ---- | M] () -- C:\WINDOWS\popcinfo.dat
[2010.03.17 18:40:27 | 000,001,475 | ---- | M] () -- C:\Documents and Settings\Mulis\Plocha\Průzkumník Windows.lnk
[2010.03.17 18:36:08 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.03.17 18:06:06 | 000,000,562 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.03.17 17:52:34 | 005,115,832 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mulis\Plocha\mbam-setup.exe
[2010.03.17 17:38:46 | 000,004,172 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.03.17 16:09:07 | 000,396,288 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Mulis\Plocha\hijackthis.exe
[2010.03.15 22:13:51 | 000,081,920 | ---- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\andal nová.doc
[2010.03.15 21:52:59 | 000,081,920 | ---- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\6.doc
[2010.03.13 21:15:19 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\~$6.doc
[2010.03.13 21:15:13 | 000,073,216 | ---- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\Andal2.doc
[2010.03.11 21:27:03 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\~$Andal2.doc
[2010.03.09 22:52:00 | 002,111,840 | -H-- | M] () -- C:\Documents and Settings\Mulis\Local Settings\Data aplikací\IconCache.db
[2010.03.08 21:12:27 | 000,028,672 | ---- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\Adresy.doc
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[10 C:\Documents and Settings\Mulis\Dokumenty\*.tmp files -> C:\Documents and Settings\Mulis\Dokumenty\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.03.17 22:12:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2010.03.17 21:12:55 | 000,000,010 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2010.03.17 18:36:08 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.03.17 18:36:06 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.03.17 18:06:06 | 000,000,562 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.03.15 22:09:15 | 000,081,920 | ---- | C] () -- C:\Documents and Settings\Mulis\Dokumenty\andal nová.doc
[2010.03.13 21:15:19 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Mulis\Dokumenty\~$6.doc
[2010.03.13 00:02:26 | 000,081,920 | ---- | C] () -- C:\Documents and Settings\Mulis\Dokumenty\6.doc
[2010.03.11 21:27:03 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Mulis\Dokumenty\~$Andal2.doc
[2010.03.10 20:31:15 | 000,073,216 | ---- | C] () -- C:\Documents and Settings\Mulis\Dokumenty\Andal2.doc
[2010.02.25 09:19:55 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
[2010.02.03 10:42:27 | 000,142,592 | ---- | C] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008.12.27 16:13:54 | 000,138,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.12.27 16:13:54 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Mulis\Data aplikací\PnkBstrK.sys
[2008.12.11 21:37:44 | 000,042,320 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2008.02.25 15:50:36 | 000,000,037 | ---- | C] () -- C:\WINDOWS\WTRDCTM.INI
[2008.02.25 15:43:27 | 000,000,526 | ---- | C] () -- C:\WINDOWS\TRNCOM.INI
[2008.02.25 15:42:34 | 000,000,666 | ---- | C] () -- C:\WINDOWS\WEBTRAN4.INI
[2008.02.25 15:42:05 | 000,004,114 | ---- | C] () -- C:\WINDOWS\WTRAN32.INI
[2008.02.25 15:40:48 | 000,004,956 | ---- | C] () -- C:\WINDOWS\ENGLMENU.INI
[2008.02.18 16:24:36 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\Mulis\Local Settings\Data aplikací\fusioncache.dat
[2008.02.18 16:18:06 | 000,000,462 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2008.02.18 16:17:55 | 000,001,343 | ---- | C] () -- C:\WINDOWS\hpbvnstp.ini
[2008.02.18 16:09:59 | 000,000,967 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
[2008.02.10 14:30:28 | 000,002,114 | ---- | C] () -- C:\WINDOWS\WDICT32.INI
[2008.02.10 14:30:08 | 000,002,376 | ---- | C] () -- C:\WINDOWS\WINTRAN.INI
[2008.02.04 22:19:41 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.01.20 11:17:35 | 000,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\.zreglib
[2007.12.16 20:13:11 | 000,000,222 | ---- | C] () -- C:\WINDOWS\RomeTW.ini
[2007.12.16 13:20:24 | 000,034,304 | ---- | C] () -- C:\Documents and Settings\Mulis\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.12.06 15:20:08 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.12.06 15:03:46 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2007.12.06 15:03:44 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007.12.06 15:03:44 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007.12.06 15:03:44 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007.12.06 15:03:43 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007.12.06 15:03:43 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007.12.06 14:51:02 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2007.12.05 20:49:44 | 000,000,156 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2007.12.05 20:33:07 | 000,004,172 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2007.12.05 19:25:20 | 000,016,899 | R--- | C] () -- C:\WINDOWS\System32\drivers\GVCplDrv.sys
[2007.12.05 19:09:50 | 000,143,360 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006.06.12 11:36:30 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\hppapr04.DLL
[2002.03.13 14:46:46 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2001.07.06 16:30:00 | 000,003,165 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI
[1996.04.03 20:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2009.03.15 13:16:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
[2008.01.19 11:08:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ashampoo
[2007.12.24 14:39:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\espionServerData
[2009.03.15 14:14:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\FarmFrenzy2
[2008.07.26 17:57:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Drivers HeadQuarters
[2008.12.27 15:36:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sports Interactive
[2010.03.12 20:11:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
[2008.01.19 11:08:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Ashampoo Photo Commander 4
[2009.06.25 15:00:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Broad Intelligence
[2009.06.25 11:37:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\BSplayer Pro
[2007.12.07 10:13:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\COWON
[2008.07.17 08:58:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Dev-Cpp
[2007.12.10 16:39:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Firaxis Games
[2009.03.02 12:33:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\ICQ
[2007.12.07 12:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\ICQ Toolbar
[2007.12.07 12:15:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\ICQLite
[2008.12.27 14:53:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\LANGMaster
[2009.10.18 11:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\My Games
[2008.08.06 17:50:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\OLYMPUS
[2008.01.19 08:48:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Opera
[2008.12.27 15:36:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Sports Interactive
[2010.03.17 17:40:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Spyware Terminator
[2008.08.03 08:15:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Stellarium
[2009.11.07 10:13:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Systweak
[2008.10.09 13:06:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Thunderbird
========== Purity Check ==========
< End of report >
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Mulis\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 84,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9,77 Gb Total Space | 1,43 Gb Free Space | 14,65% Space Free | Partition Type: NTFS
Drive D: | 135,22 Gb Total Space | 16,93 Gb Free Space | 12,52% Space Free | Partition Type: NTFS
Drive E: | 87,89 Gb Total Space | 5,27 Gb Free Space | 5,99% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
Drive G: | 4,34 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive H: | 142,05 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
I: Drive not present or media not loaded
Computer Name: P-B6CB0A05E8944
Current User Name: Mulis
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 14 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Mulis\Plocha\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - D:\Programy\Photoshop\PhotoshopElementsFileAgent.exe ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Mulis\Plocha\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (sp_rssrv) -- C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (NetTcpPortSharing) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (AdobeActiveFileMonitor5.0) -- D:\Programy\Photoshop\PhotoshopElementsFileAgent.exe ()
SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
========== Driver Services (SafeList) ==========
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (sp_rsdrv2) -- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ()
DRV - (aswMon2) -- C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) -- C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) -- C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) -- C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) -- C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (huadio) -- C:\WINDOWS\system32\huadio.tmp (Windows (R) 2000 DDK provider)
DRV - (speedfan) -- C:\WINDOWS\system32\speedfan.sys (Windows (R) 2000 DDK provider)
DRV - (GVCplDrv) -- C:\WINDOWS\system32\drivers\GVCplDrv.sys ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (JRAID) -- C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (yukonwxp) -- C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (HPFXBULK) -- C:\WINDOWS\system32\drivers\hpfxbulk.sys (Hewlett Packard)
DRV - (ET5Drv) -- C:\WINDOWS\system32\drivers\ET5Drv.sys (Microsoft Corporation)
DRV - (JGOGO) -- C:\WINDOWS\system32\DRIVERS\JGOGO.sys (JMicron )
DRV - (prohlp02) -- C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prodrv06) -- C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (a347bus) -- C:\WINDOWS\system32\DRIVERS\a347bus.sys ( )
DRV - (a347scsi) -- C:\WINDOWS\System32\Drivers\a347scsi.sys ( )
DRV - (cdrbsdrv) -- C:\WINDOWS\system32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (sfhlp01) -- C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (prosync1) -- C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology)
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.7wolf.net
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "BS_Player Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.cz/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.18
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&q="
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008.11.18 21:03:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009.09.02 21:59:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.03.10 20:48:36 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.02.19 23:44:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009.12.03 16:28:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2009.06.25 15:02:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Extensions
[2009.04.18 10:21:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009.06.25 15:02:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Extensions\MediaCoder
[2010.03.16 22:41:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\extensions
[2009.09.03 09:37:52 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008.11.15 04:28:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009.06.25 11:37:39 | 000,000,000 | ---D | M] (BS Player Toolbar) -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
[2009.02.26 13:22:28 | 000,000,880 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\conduit.xml
[2010.03.16 18:46:14 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-1.xml
[2009.04.18 10:21:49 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-10.xml
[2009.04.25 20:19:55 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-11.xml
[2009.04.29 10:47:35 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-12.xml
[2009.06.13 09:16:00 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-13.xml
[2009.07.23 08:15:35 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-14.xml
[2009.08.04 21:02:59 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-15.xml
[2009.09.12 11:02:51 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-16.xml
[2008.09.21 20:54:30 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-2.xml
[2008.04.17 20:23:09 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-3.xml
[2008.07.04 17:40:57 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-4.xml
[2008.07.16 21:33:55 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-5.xml
[2008.11.14 17:40:19 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-6.xml
[2008.11.15 04:29:00 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-7.xml
[2008.12.18 23:32:26 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-8.xml
[2008.12.19 22:42:44 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-9.xml
[2008.02.08 21:44:19 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin.xml
[2010.03.16 22:41:23 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.02.19 23:43:55 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007.12.07 11:43:24 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2007.12.10 14:14:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008.03.20 16:55:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008.11.18 21:03:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2008.12.06 17:50:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2010.02.19 23:43:55 | 000,023,000 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010.02.19 23:43:55 | 000,134,616 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2007.08.07 13:35:32 | 000,049,152 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
[2008.11.10 05:43:30 | 000,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
[2010.02.19 23:43:57 | 000,065,496 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2009.02.27 12:13:42 | 000,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2007.10.25 03:00:00 | 000,144,720 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2008.08.06 17:45:42 | 000,098,304 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2007.10.25 03:00:00 | 000,081,920 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
[2009.08.25 08:32:38 | 000,001,340 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
[2008.04.16 05:08:20 | 000,001,706 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2008.03.31 20:06:24 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2008.03.31 20:06:24 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2008.01.27 10:57:20 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2008.01.27 10:57:20 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2008.03.31 20:06:24 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2006.03.02 13:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Adresa) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O3 - HKCU\..\Toolbar\WebBrowser: (&Odkazy) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Startup Cleaner] C:\Program Files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe (CM DiskCleaner)
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKCU..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Microsoft Office.lnk = D:\Programy\MSOffice\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - D:\Programy\MSOffice\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_11)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Proces mezipaměti kategorií součástí - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Mulis\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mulis\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005.07.01 07:39:37 | 000,000,059 | R--- | M] () - H:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck xmnt2002 /bat=C:\WINDOWS\TEMP\PQ_BATCH.PQB /win=C:\WINDOWS /dbg=C:\WINDOWS\TEMP\PQ_DEBUG.TXT /ver=262144 /prd=PartitionMagic) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 14 Days ==========
[2010.03.19 18:05:23 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mulis\Plocha\OTL.exe
[2010.03.19 18:04:45 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.03.17 18:36:06 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.03.17 18:10:18 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browserchoice.exe
[2010.03.17 18:06:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mulis\Data aplikací\Malwarebytes
[2010.03.17 18:06:04 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.03.17 18:06:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.03.17 18:06:02 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.03.17 17:55:22 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Mulis\Recent
[2010.03.17 17:50:44 | 005,115,832 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mulis\Plocha\mbam-setup.exe
[2010.03.17 17:49:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mulis\Plocha\backups
[2010.03.17 16:09:07 | 000,396,288 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Mulis\Plocha\hijackthis.exe
[2010.03.16 18:48:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mulis\Plocha\Sv.šaty
[2010.03.13 19:58:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mulis\Plocha\Dandy
[2008.12.28 16:36:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Xfire
[2008.10.16 07:52:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2007.12.07 15:48:48 | 000,160,640 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347bus.sys
[2007.12.07 15:48:48 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347scsi.sys
[2007.12.06 15:00:06 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2007.12.05 18:59:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2007.12.05 18:56:48 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[10 C:\Documents and Settings\Mulis\Dokumenty\*.tmp files -> C:\Documents and Settings\Mulis\Dokumenty\*.tmp -> ]
========== Files - Modified Within 14 Days ==========
[2010.03.19 18:05:29 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mulis\Plocha\OTL.exe
[2010.03.19 17:59:48 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.03.19 17:58:53 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.03.19 17:58:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.03.19 17:58:02 | 005,767,168 | -H-- | M] () -- C:\Documents and Settings\Mulis\NTUSER.DAT
[2010.03.19 17:58:02 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Mulis\ntuser.ini
[2010.03.19 17:54:28 | 000,000,264 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.03.17 22:12:57 | 000,000,000 | ---- | M] () -- C:\WINDOWS\ativpsrm.bin
[2010.03.17 21:50:48 | 000,000,010 | ---- | M] () -- C:\WINDOWS\popcinfo.dat
[2010.03.17 18:40:27 | 000,001,475 | ---- | M] () -- C:\Documents and Settings\Mulis\Plocha\Průzkumník Windows.lnk
[2010.03.17 18:36:08 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.03.17 18:06:06 | 000,000,562 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.03.17 17:52:34 | 005,115,832 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mulis\Plocha\mbam-setup.exe
[2010.03.17 17:38:46 | 000,004,172 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.03.17 16:09:07 | 000,396,288 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Mulis\Plocha\hijackthis.exe
[2010.03.15 22:13:51 | 000,081,920 | ---- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\andal nová.doc
[2010.03.15 21:52:59 | 000,081,920 | ---- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\6.doc
[2010.03.13 21:15:19 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\~$6.doc
[2010.03.13 21:15:13 | 000,073,216 | ---- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\Andal2.doc
[2010.03.11 21:27:03 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\~$Andal2.doc
[2010.03.09 22:52:00 | 002,111,840 | -H-- | M] () -- C:\Documents and Settings\Mulis\Local Settings\Data aplikací\IconCache.db
[2010.03.08 21:12:27 | 000,028,672 | ---- | M] () -- C:\Documents and Settings\Mulis\Dokumenty\Adresy.doc
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[10 C:\Documents and Settings\Mulis\Dokumenty\*.tmp files -> C:\Documents and Settings\Mulis\Dokumenty\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.03.17 22:12:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2010.03.17 21:12:55 | 000,000,010 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2010.03.17 18:36:08 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.03.17 18:36:06 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.03.17 18:06:06 | 000,000,562 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.03.15 22:09:15 | 000,081,920 | ---- | C] () -- C:\Documents and Settings\Mulis\Dokumenty\andal nová.doc
[2010.03.13 21:15:19 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Mulis\Dokumenty\~$6.doc
[2010.03.13 00:02:26 | 000,081,920 | ---- | C] () -- C:\Documents and Settings\Mulis\Dokumenty\6.doc
[2010.03.11 21:27:03 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Mulis\Dokumenty\~$Andal2.doc
[2010.03.10 20:31:15 | 000,073,216 | ---- | C] () -- C:\Documents and Settings\Mulis\Dokumenty\Andal2.doc
[2010.02.25 09:19:55 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
[2010.02.03 10:42:27 | 000,142,592 | ---- | C] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008.12.27 16:13:54 | 000,138,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.12.27 16:13:54 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Mulis\Data aplikací\PnkBstrK.sys
[2008.12.11 21:37:44 | 000,042,320 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2008.02.25 15:50:36 | 000,000,037 | ---- | C] () -- C:\WINDOWS\WTRDCTM.INI
[2008.02.25 15:43:27 | 000,000,526 | ---- | C] () -- C:\WINDOWS\TRNCOM.INI
[2008.02.25 15:42:34 | 000,000,666 | ---- | C] () -- C:\WINDOWS\WEBTRAN4.INI
[2008.02.25 15:42:05 | 000,004,114 | ---- | C] () -- C:\WINDOWS\WTRAN32.INI
[2008.02.25 15:40:48 | 000,004,956 | ---- | C] () -- C:\WINDOWS\ENGLMENU.INI
[2008.02.18 16:24:36 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\Mulis\Local Settings\Data aplikací\fusioncache.dat
[2008.02.18 16:18:06 | 000,000,462 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2008.02.18 16:17:55 | 000,001,343 | ---- | C] () -- C:\WINDOWS\hpbvnstp.ini
[2008.02.18 16:09:59 | 000,000,967 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
[2008.02.10 14:30:28 | 000,002,114 | ---- | C] () -- C:\WINDOWS\WDICT32.INI
[2008.02.10 14:30:08 | 000,002,376 | ---- | C] () -- C:\WINDOWS\WINTRAN.INI
[2008.02.04 22:19:41 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.01.20 11:17:35 | 000,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\.zreglib
[2007.12.16 20:13:11 | 000,000,222 | ---- | C] () -- C:\WINDOWS\RomeTW.ini
[2007.12.16 13:20:24 | 000,034,304 | ---- | C] () -- C:\Documents and Settings\Mulis\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.12.06 15:20:08 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.12.06 15:03:46 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2007.12.06 15:03:44 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007.12.06 15:03:44 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007.12.06 15:03:44 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007.12.06 15:03:43 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007.12.06 15:03:43 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007.12.06 14:51:02 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2007.12.05 20:49:44 | 000,000,156 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2007.12.05 20:33:07 | 000,004,172 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2007.12.05 19:25:20 | 000,016,899 | R--- | C] () -- C:\WINDOWS\System32\drivers\GVCplDrv.sys
[2007.12.05 19:09:50 | 000,143,360 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006.06.12 11:36:30 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\hppapr04.DLL
[2002.03.13 14:46:46 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2001.07.06 16:30:00 | 000,003,165 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI
[1996.04.03 20:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2009.03.15 13:16:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
[2008.01.19 11:08:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ashampoo
[2007.12.24 14:39:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\espionServerData
[2009.03.15 14:14:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\FarmFrenzy2
[2008.07.26 17:57:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Drivers HeadQuarters
[2008.12.27 15:36:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sports Interactive
[2010.03.12 20:11:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
[2008.01.19 11:08:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Ashampoo Photo Commander 4
[2009.06.25 15:00:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Broad Intelligence
[2009.06.25 11:37:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\BSplayer Pro
[2007.12.07 10:13:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\COWON
[2008.07.17 08:58:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Dev-Cpp
[2007.12.10 16:39:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Firaxis Games
[2009.03.02 12:33:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\ICQ
[2007.12.07 12:39:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\ICQ Toolbar
[2007.12.07 12:15:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\ICQLite
[2008.12.27 14:53:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\LANGMaster
[2009.10.18 11:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\My Games
[2008.08.06 17:50:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\OLYMPUS
[2008.01.19 08:48:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Opera
[2008.12.27 15:36:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Sports Interactive
[2010.03.17 17:40:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Spyware Terminator
[2008.08.03 08:15:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Stellarium
[2009.11.07 10:13:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Systweak
[2008.10.09 13:06:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mulis\Data aplikací\Thunderbird
========== Purity Check ==========
< End of report >
Re: log HJT - prosím o kontrolu
OTL Extras logfile created on: 19.3.2010 18:06:53 - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Mulis\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 84,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9,77 Gb Total Space | 1,43 Gb Free Space | 14,65% Space Free | Partition Type: NTFS
Drive D: | 135,22 Gb Total Space | 16,93 Gb Free Space | 12,52% Space Free | Partition Type: NTFS
Drive E: | 87,89 Gb Total Space | 5,27 Gb Free Space | 5,99% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
Drive G: | 4,34 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive H: | 142,05 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
I: Drive not present or media not loaded
Computer Name: P-B6CB0A05E8944
Current User Name: Mulis
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 14 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "D:\Programy\MSOffice\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "D:\Programy\MSOffice\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\totalcmd\TOTALCMD.EXE" = C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows -- (C. Ghisler & Co.)
"D:\Programy\eMule\emule.exe" = D:\Programy\eMule\emule.exe:*:Enabled:eMule -- (http://www.emule-project.net)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"D:\Alc\Stronghold\Stronghold 2\Stronghold2.exe" = D:\Alc\Stronghold\Stronghold 2\Stronghold2.exe:*:Disabled:Stronghold 2 -- (Firefly Studios)
"C:\WINDOWS\system32\PnkBstrA.exe" = C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA -- ()
"C:\WINDOWS\system32\PnkBstrB.exe" = C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB -- ()
"D:\Program Files\GameSpy Arcade\Aphex.exe" = D:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade -- (IGN Entertainment, Inc.)
"D:\Programy\Java_Devl_kit_6_11\jre\bin\java.exe" = D:\Programy\Java_Devl_kit_6_11\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03ADC8AB-C130-0C3D-1FF9-2C385DF25689}" = CCC Help Czech
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{07021185-008D-ABF9-7716-475AC035F8B3}" = CCC Help Spanish
"{0F8D0406-7755-AC37-6529-73AD649DBE32}" = Catalyst Control Center Graphics Previews Common
"{135BA9A6-495A-4FE9-B1A1-AB4DA449CAB1}" = hppLJP2015
"{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS
"{1F73D672-6175-4A1D-B3C1-420439D03D0F}" = Product_SF_Full_QFolder
"{22072CC8-7230-96F8-52F4-05EAF3F906B6}" = CCC Help Polish
"{2368ADBD-6FDF-4B9F-FE41-E20B4D78E79E}" = CCC Help Chinese Standard
"{25569723-DC5A-4467-A639-79535BF01B71}" = Adobe Help Center 2.1
"{25EF0DC4-B072-2E04-4581-A13C91423CE6}" = CCC Help Portuguese
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java(TM) 6 Update 11
"{26F7855C-443B-00A6-F7B8-A97A5403F617}" = CCC Help Danish
"{2CB4A925-48A7-DA65-DCEE-D4DE224B7D84}" = CCC Help English
"{306D75B9-7FFF-FF65-0C76-57F2FE4FE1D6}" = Catalyst Control Center Core Implementation
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{32A3A4F4-B792-11D6-A78A-00B0D0160110}" = Java(TM) SE Development Kit 6 Update 11
"{32B12FE4-5A51-751A-1FB6-A14E97EBDD5C}" = CCC Help German
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{351512E5-01BD-E878-6F57-AA3E517D9ECE}" = Skins
"{354A387E-0374-21A3-6832-335674A6D7D1}" = CCC Help French
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Configurer
"{3C00BEE9-26D0-D9E0-A2D1-62F70D412A12}" = CCC Help Turkish
"{414C803A-6115-4DB6-BD4E-FD81EA6BC71C}" = Product_SF_Min_QFolder
"{4346F7AA-3D56-0941-424C-4454E04D37F6}" = CCC Help Italian
"{4CAE2F2C-75CD-A0DE-7520-449BCBBCC833}" = CCC Help Korean
"{561D20B1-766E-4EA5-8A1D-B7357D903673}" = hppIOFiles
"{57F7F0A5-8F22-8E63-E819-803B5C9CA3A5}" = CCC Help Dutch
"{58ECE031-9AAD-4011-B34A-BC78E77527E2}" = hppMSRedist
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.5
"{5E65E94D-69F2-4850-9E93-6459C53A0F50}" = Microsoft .NET Framework 1.1 Czech Language Pack
"{5EA437D2-7A57-B60E-E8F2-76BFAC0895A5}" = CCC Help Chinese Traditional
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{61AF4E75-050E-0304-3417-8BC16417FEB1}" = CCC Help Greek
"{632005DA-C291-5275-284C-5EE96B05C714}" = Catalyst Control Center HydraVision Full
"{634F6989-4BB5-4EF2-AF6F-C15700F81494}}_is1" = Advanced System Optimizer 2.10
"{6441FECE-0E73-4326-81BF-68503E897820}" = CorePLS_Min_QFolder
"{69E6C13B-CF6B-47A6-B7A5-77FE82B2CB40}" = hppFonts
"{6BC0CDD6-E0C2-434D-9365-23E79E42DA95}" = Battlestations: Midway
"{6C72BE0C-3E25-CACD-0070-2FD9C02ABA14}" = ccc-core-preinstall
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7A178F2E-92F6-437C-A709-69685D1C0F2B}" = hppTLBXFXP2015
"{880BB617-914E-17E8-D877-A96BAC5794D2}" = Catalyst Control Center Graphics Full New
"{8897CF22-DB6C-8248-895C-12BFA2677F51}" = CCC Help Hungarian
"{8C0118CC-F720-45FF-A4DA-44AD77B2E73C}" = CorePLS_Full_QFolder
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{91120405-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Standard
"{93C069D4-2F86-4570-A6DF-BFABBA1E4AFD}" = hpzTLBXFX
"{998D6972-F58E-479D-9248-8F179E55AE38}" = Java DB 10.4.1.3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C6105B4-2A33-4ADB-89A0-F423D562F3B9}" = ETC B06.0828.01
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War(TM)
"{A7B609FB-83D8-4FC3-8477-1BC65ECFE85B}" = Adobe Photoshop Elements 5.0
"{AAA11090-6E99-4655-AAF5-57EB5F677D0C}" = MarketResearch
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{AF710FDE-2815-8C8D-5281-8004C2654AA6}" = CCC Help Russian
"{AFF2D965-C6F2-A210-FBF7-532612AA1D23}" = CCC Help Swedish
"{B21336EE-4AEF-9940-4AC7-EDB89854B8D3}" = CCC Help Thai
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS B06.0721.01
"{B6C2569C-E2AA-4AB9-8C26-AC2487A2BFFC}" = Sid Meier's Civilization 4
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"{BBA69346-61A1-BD34-E75A-4D81232DB1FE}" = Catalyst Control Center Localization All
"{BFD5ED08-F066-92D5-BE67-3B9AE5DCFF0C}" = CCC Help Japanese
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4609F15-FB3C-D97E-BAA1-4F10815039C2}" = Catalyst Control Center Graphics Full Existing
"{C941F1F1-25B3-4DF5-83E6-888C51A1AAB6}" = AVIVO Codecs
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFB61D8C-D651-4D7C-80B4-C78676A0AF1F}" = hppusgP2015
"{D01FAC3D-86B4-3A19-9D10-9156A0EB3EBE}" = CCC Help Finnish
"{D73722C8-3F65-C75B-A631-5D36894DAB92}" = ccc-core-static
"{DDAD33B6-8C00-428D-087B-A7088355B9BE}" = Catalyst Control Center Graphics Light
"{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = jetAudio
"{DFAE9340-E8BB-4433-9A08-C8334DAFE1B9}" = Star Wars Republic Commando
"{E333F074-FC7F-596D-3D61-44F0EC28E8C0}" = ccc-utility
"{E9F81423-211E-46B6-9AE0-38568BC5CF6F}" =
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"{EDAE4F43-833C-443B-8DB5-129F897DF3E8}" = hppWebRegMM
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F38D0F99-1BFC-47AB-AC36-8D9D43700CFB}" = hppManualsP2015
"{FA38F9E4-BED7-E021-B660-8FDFF7EC6E1A}" = CCC Help Norwegian
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 5" = Adobe Photoshop Elements 5.0
"Adobe Shockwave Player" = Adobe Shockwave Player
"All ATI Software" = Softarová utilita ATI - Odinstalovat
"Ashampoo Photo Commander 4" = Ashampoo Photo Commander 4
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"BlueJ_is1" = BlueJ 2.5.0
"CCleaner" = CCleaner (remove only)
"CM_DiskCleaner" = CM DiskCleaner
"Cygni Software Výkazy ERÚ pro výrobce do 0.5MW" = Cygni Software Výkazy ERÚ pro výrobce do 0.5MW
"Defraggler" = Defraggler
"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)
"Empty Temp Folders 2.8.3" = Empty Temp Folders 2.8.3
"eMule" = eMule
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"GameSpy Arcade" = GameSpy Arcade
"HijackThis" = HijackThis 2.0.2
"HP LaserJet P2015" = HP LaserJet P2015 Series 1.0
"HPExtendedCapabilities" = HP Extended Capabilities 6.0
"CheckDrive_is1" = CheckDrive
"InstallShield_{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War(TM)
"InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"IrfanView" = IrfanView (remove only)
"iriver plus 3" = iriver plus 3 (remove only)
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 3.5.3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.18)" = Mozilla Firefox (3.0.18)
"Mozilla Thunderbird (2.0.0.23)" = Mozilla Thunderbird (2.0.0.23)
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"PSPad editor_is1" = PSPad editor
"PunkBusterSvc" = PunkBuster Services
"QuickTime" = QuickTime
"Shop for HP Supplies" = Shop for HP Supplies
"SpeedFan" = SpeedFan (remove only)
"Spyware Terminator_is1" = Spyware Terminator
"suc10_is1" = Stereo 2008 - ekonomický software, v.10.5.7
"suc41_is1" = Stereo 2003 - ekonomický software, v.4.1.5
"TopStyle Lite (Version 3.0)" = TopStyle Lite (Version 3.0)
"Totalcmd" = Total Commander (Remove or Repair)
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"Zuma_Deluxe!_1.0" = Zuma Deluxe! 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ==========
[ Antivirus Events ]
Error - 19.1.2009 4:34:41 | Computer Name = P-B6CB0A05E8944 | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of http://jizdnirady.idnes.cz/ScriptResour ... 0853437500
failed, 0000A413.
[ Application Events ]
Error - 25.1.2010 23:52:29 | Computer Name = P-B6CB0A05E8944 | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 26.1.2010 9:02:52 | Computer Name = P-B6CB0A05E8944 | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 3.2.2010 8:15:08 | Computer Name = P-B6CB0A05E8944 | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 3.2.2010 11:15:06 | Computer Name = P-B6CB0A05E8944 | Source = crypt32 | ID = 131083
Description = Extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou
aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
se nezdařilo. Chyba: Při ověření se systémovými hodinami nebo časovým razítkem
podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.
Error - 3.2.2010 11:15:06 | Computer Name = P-B6CB0A05E8944 | Source = crypt32 | ID = 131083
Description = Extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou
aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
se nezdařilo. Chyba: Při ověření se systémovými hodinami nebo časovým razítkem
podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.
Error - 16.2.2010 15:07:40 | Computer Name = P-B6CB0A05E8944 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace WINWORD.EXE, verze 10.0.2627.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.
Error - 16.2.2010 15:07:50 | Computer Name = P-B6CB0A05E8944 | Source = Application Hang | ID = 1001
Description = Chybný blok 01880210
Error - 16.2.2010 15:10:36 | Computer Name = P-B6CB0A05E8944 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace WINWORD.EXE, verze 10.0.2627.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.
Error - 16.2.2010 15:13:43 | Computer Name = P-B6CB0A05E8944 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace WINWORD.EXE, verze 10.0.2627.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.
Error - 27.2.2010 14:11:21 | Computer Name = P-B6CB0A05E8944 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace TBPANEL.exe, verze 4.0.0.4, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.
[ System Events ]
Error - 16.3.2010 12:45:24 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ffe62697, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 16.3.2010 12:56:42 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ffdaa11b, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 17.3.2010 10:43:52 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ff66a0e3, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 17.3.2010 11:03:35 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ff21d223, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 17.3.2010 11:03:39 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ff371697, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 17.3.2010 13:08:54 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ff7bb4a3, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 17.3.2010 13:36:44 | Computer Name = P-B6CB0A05E8944 | Source = Service Control Manager | ID = 7034
Description = Služba Spyware Terminator Realtime Shield Service byla neočekávaně
ukončena. Tento stav nastal již 1krát.
Error - 17.3.2010 14:18:48 | Computer Name = P-B6CB0A05E8944 | Source = Service Control Manager | ID = 7034
Description = Služba Spyware Terminator Realtime Shield Service byla neočekávaně
ukončena. Tento stav nastal již 1krát.
Error - 17.3.2010 17:14:19 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ff889a37, parametr2 00000000, parametr3
b9f68deb, parametr4 00000000.
Error - 19.3.2010 12:51:37 | Computer Name = P-B6CB0A05E8944 | Source = Service Control Manager | ID = 7034
Description = Služba Spyware Terminator Realtime Shield Service byla neočekávaně
ukončena. Tento stav nastal již 1krát.
< End of report >
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Mulis\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 84,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9,77 Gb Total Space | 1,43 Gb Free Space | 14,65% Space Free | Partition Type: NTFS
Drive D: | 135,22 Gb Total Space | 16,93 Gb Free Space | 12,52% Space Free | Partition Type: NTFS
Drive E: | 87,89 Gb Total Space | 5,27 Gb Free Space | 5,99% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
Drive G: | 4,34 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive H: | 142,05 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
I: Drive not present or media not loaded
Computer Name: P-B6CB0A05E8944
Current User Name: Mulis
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 14 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "D:\Programy\MSOffice\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "D:\Programy\MSOffice\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\totalcmd\TOTALCMD.EXE" = C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows -- (C. Ghisler & Co.)
"D:\Programy\eMule\emule.exe" = D:\Programy\eMule\emule.exe:*:Enabled:eMule -- (http://www.emule-project.net)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"D:\Alc\Stronghold\Stronghold 2\Stronghold2.exe" = D:\Alc\Stronghold\Stronghold 2\Stronghold2.exe:*:Disabled:Stronghold 2 -- (Firefly Studios)
"C:\WINDOWS\system32\PnkBstrA.exe" = C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA -- ()
"C:\WINDOWS\system32\PnkBstrB.exe" = C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB -- ()
"D:\Program Files\GameSpy Arcade\Aphex.exe" = D:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade -- (IGN Entertainment, Inc.)
"D:\Programy\Java_Devl_kit_6_11\jre\bin\java.exe" = D:\Programy\Java_Devl_kit_6_11\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03ADC8AB-C130-0C3D-1FF9-2C385DF25689}" = CCC Help Czech
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{07021185-008D-ABF9-7716-475AC035F8B3}" = CCC Help Spanish
"{0F8D0406-7755-AC37-6529-73AD649DBE32}" = Catalyst Control Center Graphics Previews Common
"{135BA9A6-495A-4FE9-B1A1-AB4DA449CAB1}" = hppLJP2015
"{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS
"{1F73D672-6175-4A1D-B3C1-420439D03D0F}" = Product_SF_Full_QFolder
"{22072CC8-7230-96F8-52F4-05EAF3F906B6}" = CCC Help Polish
"{2368ADBD-6FDF-4B9F-FE41-E20B4D78E79E}" = CCC Help Chinese Standard
"{25569723-DC5A-4467-A639-79535BF01B71}" = Adobe Help Center 2.1
"{25EF0DC4-B072-2E04-4581-A13C91423CE6}" = CCC Help Portuguese
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java(TM) 6 Update 11
"{26F7855C-443B-00A6-F7B8-A97A5403F617}" = CCC Help Danish
"{2CB4A925-48A7-DA65-DCEE-D4DE224B7D84}" = CCC Help English
"{306D75B9-7FFF-FF65-0C76-57F2FE4FE1D6}" = Catalyst Control Center Core Implementation
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{32A3A4F4-B792-11D6-A78A-00B0D0160110}" = Java(TM) SE Development Kit 6 Update 11
"{32B12FE4-5A51-751A-1FB6-A14E97EBDD5C}" = CCC Help German
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{351512E5-01BD-E878-6F57-AA3E517D9ECE}" = Skins
"{354A387E-0374-21A3-6832-335674A6D7D1}" = CCC Help French
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Configurer
"{3C00BEE9-26D0-D9E0-A2D1-62F70D412A12}" = CCC Help Turkish
"{414C803A-6115-4DB6-BD4E-FD81EA6BC71C}" = Product_SF_Min_QFolder
"{4346F7AA-3D56-0941-424C-4454E04D37F6}" = CCC Help Italian
"{4CAE2F2C-75CD-A0DE-7520-449BCBBCC833}" = CCC Help Korean
"{561D20B1-766E-4EA5-8A1D-B7357D903673}" = hppIOFiles
"{57F7F0A5-8F22-8E63-E819-803B5C9CA3A5}" = CCC Help Dutch
"{58ECE031-9AAD-4011-B34A-BC78E77527E2}" = hppMSRedist
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.5
"{5E65E94D-69F2-4850-9E93-6459C53A0F50}" = Microsoft .NET Framework 1.1 Czech Language Pack
"{5EA437D2-7A57-B60E-E8F2-76BFAC0895A5}" = CCC Help Chinese Traditional
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{61AF4E75-050E-0304-3417-8BC16417FEB1}" = CCC Help Greek
"{632005DA-C291-5275-284C-5EE96B05C714}" = Catalyst Control Center HydraVision Full
"{634F6989-4BB5-4EF2-AF6F-C15700F81494}}_is1" = Advanced System Optimizer 2.10
"{6441FECE-0E73-4326-81BF-68503E897820}" = CorePLS_Min_QFolder
"{69E6C13B-CF6B-47A6-B7A5-77FE82B2CB40}" = hppFonts
"{6BC0CDD6-E0C2-434D-9365-23E79E42DA95}" = Battlestations: Midway
"{6C72BE0C-3E25-CACD-0070-2FD9C02ABA14}" = ccc-core-preinstall
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7A178F2E-92F6-437C-A709-69685D1C0F2B}" = hppTLBXFXP2015
"{880BB617-914E-17E8-D877-A96BAC5794D2}" = Catalyst Control Center Graphics Full New
"{8897CF22-DB6C-8248-895C-12BFA2677F51}" = CCC Help Hungarian
"{8C0118CC-F720-45FF-A4DA-44AD77B2E73C}" = CorePLS_Full_QFolder
"{8D7133DE-27D2-47E5-B248-4180278D32AA}" = Catalyst Control Center - Branding
"{91120405-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Standard
"{93C069D4-2F86-4570-A6DF-BFABBA1E4AFD}" = hpzTLBXFX
"{998D6972-F58E-479D-9248-8F179E55AE38}" = Java DB 10.4.1.3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C6105B4-2A33-4ADB-89A0-F423D562F3B9}" = ETC B06.0828.01
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War(TM)
"{A7B609FB-83D8-4FC3-8477-1BC65ECFE85B}" = Adobe Photoshop Elements 5.0
"{AAA11090-6E99-4655-AAF5-57EB5F677D0C}" = MarketResearch
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{AF710FDE-2815-8C8D-5281-8004C2654AA6}" = CCC Help Russian
"{AFF2D965-C6F2-A210-FBF7-532612AA1D23}" = CCC Help Swedish
"{B21336EE-4AEF-9940-4AC7-EDB89854B8D3}" = CCC Help Thai
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS B06.0721.01
"{B6C2569C-E2AA-4AB9-8C26-AC2487A2BFFC}" = Sid Meier's Civilization 4
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"{BBA69346-61A1-BD34-E75A-4D81232DB1FE}" = Catalyst Control Center Localization All
"{BFD5ED08-F066-92D5-BE67-3B9AE5DCFF0C}" = CCC Help Japanese
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4609F15-FB3C-D97E-BAA1-4F10815039C2}" = Catalyst Control Center Graphics Full Existing
"{C941F1F1-25B3-4DF5-83E6-888C51A1AAB6}" = AVIVO Codecs
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFB61D8C-D651-4D7C-80B4-C78676A0AF1F}" = hppusgP2015
"{D01FAC3D-86B4-3A19-9D10-9156A0EB3EBE}" = CCC Help Finnish
"{D73722C8-3F65-C75B-A631-5D36894DAB92}" = ccc-core-static
"{DDAD33B6-8C00-428D-087B-A7088355B9BE}" = Catalyst Control Center Graphics Light
"{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = jetAudio
"{DFAE9340-E8BB-4433-9A08-C8334DAFE1B9}" = Star Wars Republic Commando
"{E333F074-FC7F-596D-3D61-44F0EC28E8C0}" = ccc-utility
"{E9F81423-211E-46B6-9AE0-38568BC5CF6F}" =
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"{EDAE4F43-833C-443B-8DB5-129F897DF3E8}" = hppWebRegMM
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F38D0F99-1BFC-47AB-AC36-8D9D43700CFB}" = hppManualsP2015
"{FA38F9E4-BED7-E021-B660-8FDFF7EC6E1A}" = CCC Help Norwegian
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 5" = Adobe Photoshop Elements 5.0
"Adobe Shockwave Player" = Adobe Shockwave Player
"All ATI Software" = Softarová utilita ATI - Odinstalovat
"Ashampoo Photo Commander 4" = Ashampoo Photo Commander 4
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"BlueJ_is1" = BlueJ 2.5.0
"CCleaner" = CCleaner (remove only)
"CM_DiskCleaner" = CM DiskCleaner
"Cygni Software Výkazy ERÚ pro výrobce do 0.5MW" = Cygni Software Výkazy ERÚ pro výrobce do 0.5MW
"Defraggler" = Defraggler
"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)
"Empty Temp Folders 2.8.3" = Empty Temp Folders 2.8.3
"eMule" = eMule
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"GameSpy Arcade" = GameSpy Arcade
"HijackThis" = HijackThis 2.0.2
"HP LaserJet P2015" = HP LaserJet P2015 Series 1.0
"HPExtendedCapabilities" = HP Extended Capabilities 6.0
"CheckDrive_is1" = CheckDrive
"InstallShield_{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War(TM)
"InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"IrfanView" = IrfanView (remove only)
"iriver plus 3" = iriver plus 3 (remove only)
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 3.5.3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.18)" = Mozilla Firefox (3.0.18)
"Mozilla Thunderbird (2.0.0.23)" = Mozilla Thunderbird (2.0.0.23)
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"PSPad editor_is1" = PSPad editor
"PunkBusterSvc" = PunkBuster Services
"QuickTime" = QuickTime
"Shop for HP Supplies" = Shop for HP Supplies
"SpeedFan" = SpeedFan (remove only)
"Spyware Terminator_is1" = Spyware Terminator
"suc10_is1" = Stereo 2008 - ekonomický software, v.10.5.7
"suc41_is1" = Stereo 2003 - ekonomický software, v.4.1.5
"TopStyle Lite (Version 3.0)" = TopStyle Lite (Version 3.0)
"Totalcmd" = Total Commander (Remove or Repair)
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"Zuma_Deluxe!_1.0" = Zuma Deluxe! 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ==========
[ Antivirus Events ]
Error - 19.1.2009 4:34:41 | Computer Name = P-B6CB0A05E8944 | Source = avast! | ID = 33554522
Description = AAVM - chyba při testování: x_AavmCheckFileDirectEx: avfilesScanReal
of http://jizdnirady.idnes.cz/ScriptResour ... 0853437500
failed, 0000A413.
[ Application Events ]
Error - 25.1.2010 23:52:29 | Computer Name = P-B6CB0A05E8944 | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 26.1.2010 9:02:52 | Computer Name = P-B6CB0A05E8944 | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 3.2.2010 8:15:08 | Computer Name = P-B6CB0A05E8944 | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.
Error - 3.2.2010 11:15:06 | Computer Name = P-B6CB0A05E8944 | Source = crypt32 | ID = 131083
Description = Extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou
aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
se nezdařilo. Chyba: Při ověření se systémovými hodinami nebo časovým razítkem
podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.
Error - 3.2.2010 11:15:06 | Computer Name = P-B6CB0A05E8944 | Source = crypt32 | ID = 131083
Description = Extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou
aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
se nezdařilo. Chyba: Při ověření se systémovými hodinami nebo časovým razítkem
podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.
Error - 16.2.2010 15:07:40 | Computer Name = P-B6CB0A05E8944 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace WINWORD.EXE, verze 10.0.2627.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.
Error - 16.2.2010 15:07:50 | Computer Name = P-B6CB0A05E8944 | Source = Application Hang | ID = 1001
Description = Chybný blok 01880210
Error - 16.2.2010 15:10:36 | Computer Name = P-B6CB0A05E8944 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace WINWORD.EXE, verze 10.0.2627.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.
Error - 16.2.2010 15:13:43 | Computer Name = P-B6CB0A05E8944 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace WINWORD.EXE, verze 10.0.2627.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.
Error - 27.2.2010 14:11:21 | Computer Name = P-B6CB0A05E8944 | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace TBPANEL.exe, verze 4.0.0.4, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.
[ System Events ]
Error - 16.3.2010 12:45:24 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ffe62697, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 16.3.2010 12:56:42 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ffdaa11b, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 17.3.2010 10:43:52 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ff66a0e3, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 17.3.2010 11:03:35 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ff21d223, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 17.3.2010 11:03:39 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ff371697, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 17.3.2010 13:08:54 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ff7bb4a3, parametr2 00000000, parametr3
b9f40deb, parametr4 00000000.
Error - 17.3.2010 13:36:44 | Computer Name = P-B6CB0A05E8944 | Source = Service Control Manager | ID = 7034
Description = Služba Spyware Terminator Realtime Shield Service byla neočekávaně
ukončena. Tento stav nastal již 1krát.
Error - 17.3.2010 14:18:48 | Computer Name = P-B6CB0A05E8944 | Source = Service Control Manager | ID = 7034
Description = Služba Spyware Terminator Realtime Shield Service byla neočekávaně
ukončena. Tento stav nastal již 1krát.
Error - 17.3.2010 17:14:19 | Computer Name = P-B6CB0A05E8944 | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 ff889a37, parametr2 00000000, parametr3
b9f68deb, parametr4 00000000.
Error - 19.3.2010 12:51:37 | Computer Name = P-B6CB0A05E8944 | Source = Service Control Manager | ID = 7034
Description = Služba Spyware Terminator Realtime Shield Service byla neočekávaně
ukončena. Tento stav nastal již 1krát.
< End of report >
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: log HJT - prosím o kontrolu
Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Custom Scans/Fixes do okénka vlož následující text, zobrazený zeleně:
Poté klikni nahoře na Run Fix. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Pod Custom Scans/Fixes do okénka vlož následující text, zobrazený zeleně:
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
SRV - (huadio) -- C:\WINDOWS\system32\huadio.tmp (Windows (R) 2000 DDK provider)
DRV - (huadio) -- C:\WINDOWS\system32\huadio.tmp (Windows (R) 2000 DDK provider)
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaultthis.engineName: "BS_Player Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q="
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&q="
[2009.06.25 11:37:39 | 000,000,000 | ---D | M] (BS Player Toolbar) -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
[2009.02.26 13:22:28 | 000,000,880 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\conduit.xml
[2010.03.16 18:46:14 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-1.xml
[2009.04.18 10:21:49 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-10.xml
[2009.04.25 20:19:55 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-11.xml
[2009.04.29 10:47:35 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-12.xml
[2009.06.13 09:16:00 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-13.xml
[2009.07.23 08:15:35 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-14.xml
[2009.08.04 21:02:59 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-15.xml
[2009.09.12 11:02:51 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-16.xml
[2008.09.21 20:54:30 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-2.xml
[2008.04.17 20:23:09 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-3.xml
[2008.07.04 17:40:57 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-4.xml
[2008.07.16 21:33:55 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-5.xml
[2008.11.14 17:40:19 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-6.xml
[2008.11.15 04:29:00 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-7.xml
[2008.12.18 23:32:26 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-8.xml
[2008.12.19 22:42:44 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin-9.xml
[2008.02.08 21:44:19 | 000,000,951 | ---- | M] () -- C:\Documents and Settings\Mulis\Data aplikací\Mozilla\Firefox\Profiles\993el2bv.default\searchplugins\icqplugin.xml
[2009.08.25 08:32:38 | 000,001,340 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O32 - AutoRun File - [2005.07.01 07:39:37 | 000,000,059 | R--- | M] () - H:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck xmnt2002 /bat=C:\WINDOWS\TEMP\PQ_BATCH.PQB /win=C:\WINDOWS /dbg=C:\WINDOWS\TEMP\PQ_DEBUG.TXT /ver=262144 /prd=PartitionMagic) - File not found
:Services
huadio
:Files
C:\WINDOWS\*.tmp
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\system32\SET*.tmp
C:\Documents and Settings\Mulis\Dokumenty\*.tmp
c:\windows\system32\huadio.tmp
C:\RECYCLER
C:\$RECYCLE.BIN
C:\Documents and Settings\NetworkService\Data aplikací\rbuwzv.dat
C:\Windows\tasks\SA.DAT
:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\huadio]
:Commands
[purity]
[emptytemp]
[emptyflash]
[start explorer]
[Reboot]
Poté klikni nahoře na Run Fix. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Naposledy upravil(a) Damned dne 19 bře 2010 20:02, celkem upraveno 2 x.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Re: log HJT - prosím o kontrolu
Bohužel, zkoušel jsem to několikrát, ale vždy se mi to sekne na "SRV - huadio".
Díky
Díky
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 91 hostů