Prosim o kontrolu logu - system zahlcuje ram Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

DANIK6
nováček
Příspěvky: 25
Registrován: září 10
Pohlaví: Muž
Stav:
Offline

Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod DANIK6 » 20 zář 2010 22:57

Zdravim,

poprosim o kotrolu logu, notebook sa mi v posledych dnoch zacal vyrazne spomalovat.. System zahlcuje ram, po starte systemu byva vyuzitie pamate 70-80% , to sa s casom este stupnuje az je praca na notebooku nemozna. System som presiel NOD-om, Spybotom a Malwarebytes, po skenoch som odstranil nejake drobnosti ktore z mojho pohladu dany problem nevytvarali. Taktiez pravidelne pouzivam CCleaner. Sam si uz dalej neviem rady.

Vopred dakujem za pripadnu pomoc.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:31:39, on 20. 9. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\PROGRA~1\DUMETE~1\DUMeter.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\vsnp2uvc.exe
C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\Program Files\Compal\Smart Battery\SMBTray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Razer\DeathAdder\razertra.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKLM\..\Run: [Wow Video&Audio] C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SMBTray] C:\Program Files\Compal\Smart Battery\SMBTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKCU\..\Run: [Thunderbird] "C:\Program Files\Mozilla Thunderbird\thunderbird" -turbo
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010 JadrisPack\qip.exe" /nosrv /isolated /smiles 40 /autorun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd. - C:\Program Files\DU Meter\DUMeterSvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

--
End of file - 4921 bytes


taktiez pridavam log z programu ComboFix :


ComboFix 10-09-20.01 - DANIK . 09. 2010 22:34:31.2.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1029.18.1022.347 [GMT 2:00]
Running from: c:\users\DANIK\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2010-08-20 to 2010-09-20 )))))))))))))))))))))))))))))))
.

2010-09-20 20:40 . 2010-09-20 20:40 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-20 20:40 . 2010-09-20 20:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-20 20:04 . 2010-09-20 20:04 388096 ----a-r- c:\users\DANIK\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-20 20:04 . 2010-09-20 20:04 -------- d-----w- c:\program files\Trend Micro
2010-09-20 19:46 . 2010-09-20 20:40 -------- d-----w- c:\users\DANIK\AppData\Local\temp
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\users\DANIK\AppData\Roaming\Malwarebytes
2010-09-19 22:00 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\programdata\Malwarebytes
2010-09-19 22:00 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-19 21:01 . 2010-09-20 17:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-19 21:01 . 2010-09-19 21:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-19 18:06 . 2010-09-19 18:06 -------- d-----w- c:\users\DANIK\AppData\Local\Opera
2010-09-19 18:05 . 2010-09-19 18:05 -------- d-----w- c:\program files\Opera
2010-09-19 15:01 . 2010-09-20 13:58 -------- d-----w- c:\users\DANIK\AppData\Roaming\vlc
2010-09-19 10:35 . 2010-09-19 10:36 -------- d-----w- c:\program files\uTorrent
2010-09-19 10:34 . 2010-09-19 10:50 -------- d-----w- c:\users\DANIK\AppData\Roaming\uTorrent
2010-09-17 11:56 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-12 16:30 . 2010-09-12 16:30 162816 ----a-w- c:\windows\system32\fmod.dll
2010-09-12 12:24 . 2010-07-24 19:24 344064 ----a-w- c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
2010-09-12 11:31 . 2009-04-30 07:53 2970112 ----a-w- c:\windows\system32\PhoenixDll.dll
2010-09-11 08:46 . 2010-09-11 08:55 -------- d-----w- c:\windows\WindowsMobile
2010-09-04 11:40 . 2010-09-04 11:40 -------- d-----w- c:\program files\Motorola
2010-09-04 11:33 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-09-04 11:33 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-09-04 11:33 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-09-03 10:49 . 2010-09-03 10:52 -------- d-----w- c:\program files\TNODUP
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\programdata\Hagel Technologies
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\program files\DU Meter

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-20 19:55 . 2009-07-14 08:44 626398 ----a-w- c:\windows\system32\perfh005.dat
2010-09-20 19:55 . 2009-07-14 08:44 122978 ----a-w- c:\windows\system32\perfc005.dat
2010-09-20 15:34 . 2010-07-05 18:57 -------- d-----w- c:\program files\QIP 2010 JadrisPack
2010-09-20 08:44 . 2010-06-18 23:31 -------- d-----w- c:\program files\SpeedFan
2010-09-19 13:15 . 2010-06-20 00:40 -------- d-----w- c:\program files\CzDC-0699[C]
2010-09-17 15:57 . 2010-06-18 23:04 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-09-17 12:01 . 2010-06-19 04:37 -------- d-----w- c:\programdata\Microsoft Help
2010-09-12 15:32 . 2010-06-18 19:45 84512 ----a-w- c:\users\DANIK\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-11 08:48 . 2010-09-11 08:48 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2010-09-04 11:43 . 2010-06-19 04:38 -------- d-----w- c:\program files\Microsoft.NET
2010-09-03 13:27 . 2010-07-14 21:43 -------- d-----w- c:\program files\The KMPlayer
2010-08-07 22:52 . 2010-08-07 22:52 -------- d-----w- c:\program files\Common Files\Java
2010-08-07 22:51 . 2010-06-19 03:37 -------- d-----w- c:\program files\Java
2010-08-06 20:31 . 2010-08-06 20:30 -------- d-----w- c:\program files\qip2005pack
2010-08-01 11:38 . 2010-06-19 04:41 -------- d-----w- c:\users\DANIK\AppData\Roaming\Skype
2010-07-29 06:30 . 2010-08-12 15:40 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-12 15:40 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 03:00 . 2010-06-19 03:37 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 06:25 . 2010-09-04 11:32 978432 ----a-w- c:\windows\system32\wininet.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-09-20_19.43.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:55 . 2010-09-20 19:53 33104 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 04:55 . 2010-09-20 18:37 33104 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-06-18 22:07 . 2010-09-20 19:51 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-18 22:07 . 2010-09-20 18:39 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-19 05:08 . 2010-09-20 19:03 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-19 05:08 . 2010-09-20 20:00 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-19 05:08 . 2010-09-20 20:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
- 2010-06-19 05:08 . 2010-09-20 19:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
- 2010-06-19 05:08 . 2010-09-20 19:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
+ 2010-06-19 05:08 . 2010-09-20 20:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
+ 2010-06-18 22:07 . 2010-09-20 20:00 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-06-18 22:07 . 2010-09-20 19:03 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-18 22:07 . 2010-09-20 19:51 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-06-18 22:07 . 2010-09-20 18:39 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-06-18 19:45 . 2010-09-20 15:36 7030 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2786143777-1472676354-2263527552-1000_UserData.bin
+ 2010-06-18 19:45 . 2010-09-20 19:53 7030 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2786143777-1472676354-2263527552-1000_UserData.bin
- 2010-09-20 18:39 . 2010-09-20 18:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-09-20 18:39 . 2010-09-20 19:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-09-20 18:39 . 2010-09-20 18:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-09-20 18:39 . 2010-09-20 19:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:05 . 2010-09-20 19:55 618912 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2010-09-20 18:44 618912 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2010-09-20 18:44 107232 c:\windows\System32\perfc009.dat
+ 2009-07-14 02:05 . 2010-09-20 19:55 107232 c:\windows\System32\perfc009.dat
+ 2009-07-14 02:03 . 2010-09-20 20:09 6815744 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 02:03 . 2010-09-20 19:16 6815744 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2010-09-20 20:03 . 2010-09-20 20:03 1402880 c:\windows\Installer\c70bf.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Thunderbird"="c:\program files\Mozilla Thunderbird\thunderbird -turbo" [X]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2010-08-21 2931744]
"Infium"="c:\program files\QIP 2010 JadrisPack\qip.exe" [2010-06-16 5813200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-06-08 9267816]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2006-12-29 569344]
"Wow Video&Audio"="c:\program files\Compal\Wow Video&Audio\WVAMain.exe" [2007-05-03 951856]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-04-07 2145000]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"SMBTray"="c:\program files\Compal\Smart Battery\SMBTray.exe" [2007-06-04 521776]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 1466368]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 13:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-19 1343400]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-18 691696]
S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS [2007-03-14 9856]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
S2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [2010-08-21 1411616]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-04-07 133512]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-04-07 810120]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-04-07 96896]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-08-02 22784]
S3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver;c:\program files\DU Meter\DUMETR32.SYS [2010-08-19 19368]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
S3 netw5v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2010-01-13 6628352]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder

2010-09-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000Core.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]

2010-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000UA.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]
.
.
------- Supplementary Scan -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\
FF - prefs.js: browser.startup.homepage - chrome://fastdial/content/fastdial.html
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\users\DANIK\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll

---- FIREFOX POLICIES ----
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\DUMeterSvc]
"ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-09-20 22:42:56
ComboFix-quarantined-files.txt 2010-09-20 20:42

Pre-Run: Volných bajtů: 38 395 375 616
Post-Run: Volných bajtů: 38 179 954 688

- - End Of File - - 4AA68D3DA4ADC70D368AEA52CDC2BE00

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43289
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod jaro3 » 21 zář 2010 08:56

Máš používat Combofix jen na radu rádce!!

Stahni AVPtool
-nainstaluj, nech provést sken všechn jednotek
-co najde nech léčit
-pak sem vlož log.

Malwarebytes' Anti-Malware:
Spusť ho a aktualizuj.
- program se po té spustí a nech vybranou možnost Provést úplný sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Pokud budou problémy , spusť v nouz. režimu.

+
Memtest:
http://www.stahuj.centrum.cz/utility_a_ ... i/memtest/

Do políčka vlož největší velikost Tvé jednotlivé paměti RAM (256,512 nebo 1024,2048) dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

DANIK6
nováček
Příspěvky: 25
Registrován: září 10
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod DANIK6 » 21 zář 2010 17:26

tak konecne sa mi podarilo skoncit vsetky skeny ...

AVPtool nasiel par smeti ktore som vymazal ..neskor aj TNODUP to uz ale v logu spomenute nieje ..log je rozdeleny pretoze mi vypadla elektrika pri testovani externeho disku, tak som ho testoval zvlast ..viz log

Obrázek

Malwarebytes taktiez nasiel nejake drobnosti ..nieco som uz vsak predtym hodil do karanteny viz screen ..neskor log z hladania.

Obrázek

    Malwarebytes' Anti-Malware 1.46
    http://www.malwarebytes.org

    Verzia databázy: 4662

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    21. 9. 2010 12:33:29
    mbam-log-2010-09-21 (12-33-29).txt

    Typ kontroly: Úplná kontrola (C:\|D:\|H:\|)
    Objektov kontrolovaných: 281354
    Uplynulý čas: 2 hod, 8 min, 41 sek

    Infikované služby pamäte: 0
    Infikované moduly pamäte: 0
    Infikované registračné kľúče: 0
    Infikované registračné hodnoty: 0
    Infikované položky registračných dát: 0
    Infikované priečinky: 0
    Infikované súbory: 3

    Infikované služby pamäte:
    (Škodlivé položky neboli zistené)

    Infikované moduly pamäte:
    (Škodlivé položky neboli zistené)

    Infikované registračné kľúče:
    (Škodlivé položky neboli zistené)

    Infikované registračné hodnoty:
    (Škodlivé položky neboli zistené)

    Infikované položky registračných dát:
    (Škodlivé položky neboli zistené)

    Infikované priečinky:
    (Škodlivé položky neboli zistené)

    Infikované súbory:
    H:\zaloha\! nechat e\fun programs\notor_motor.exe (Application.Joke) -> No action taken.
    H:\zaloha\! nechat e\fun programs\paranoia.exe (Application.Badjoke) -> No action taken.
    H:\zaloha\! nechat e\fun programs\viagra.exe (Joke.VV) -> No action taken.

Memtest prebehol bez chyb no zatial bol pusteny len 30min ..neskor mozem spravit dlhsi test ...

Cez noc som este obnovil win zo zalohy z pred par dni, no bez naznakv napravy .. pre pripadne zmeny sem hadzem log z HJT

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 16:31:43, on 21. 9. 2010
    Platform: Windows 7 (WinNT 6.00.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16385)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskhost.exe
    C:\PROGRA~1\DUMETE~1\DUMeter.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Windows\vsnp2uvc.exe
    C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
    C:\Program Files\Razer\DeathAdder\razerhid.exe
    C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
    C:\Program Files\Compal\Smart Battery\SMBTray.exe
    C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    C:\Windows\WindowsMobile\wmdc.exe
    C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    C:\Program Files\DAEMON Tools Lite\DTLite.exe
    C:\Program Files\QIP 2010 JadrisPack\qip.exe
    C:\Program Files\Razer\DeathAdder\razertra.exe
    C:\Program Files\Razer\DeathAdder\razerofa.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
    O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
    O4 - HKLM\..\Run: [Wow Video&Audio] C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
    O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SMBTray] C:\Program Files\Compal\Smart Battery\SMBTray.exe
    O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
    O4 - HKCU\..\Run: [Thunderbird] "C:\Program Files\Mozilla Thunderbird\thunderbird" -turbo
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
    O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
    O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010 JadrisPack\qip.exe" /nosrv /isolated /smiles 40 /autorun
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd. - C:\Program Files\DU Meter\DUMeterSvc.exe
    O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

    --
    End of file - 5467 bytes

Vsetky testy uvedene vyssie boli prevadzane po obnoveni zalohy. Problem so zahlcovanim stale pokracuje.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43289
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod jaro3 » 21 zář 2010 18:48

Memtest aspon 2h..

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

DANIK6
nováček
Příspěvky: 25
Registrován: září 10
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod DANIK6 » 21 zář 2010 19:39

scan combofixu prebehol no po nom mi zacal hadzat error Daemon tools ..asi zbytocna informacia ..mam nechat combofix v pc alebo ho teraz odinstalovat ?

log:


ComboFix 10-09-20.07 - DANIK . 09. 2010 19:23:47.1.2 - x86 MINIMAL
Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1029.18.1022.565 [GMT 2:00]
Running from: c:\users\DANIK\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\Config.ini

.
((((((((((((((((((((((((( Files Created from 2010-08-21 to 2010-09-21 )))))))))))))))))))))))))))))))
.

2010-09-21 13:30 . 2010-09-21 13:31 7168 ----a-w- c:\windows\system32\drivers\uti5nju4.sys
2010-09-21 08:18 . 2010-09-21 08:20 -------- d-----w- c:\programdata\Kaspersky Lab
2010-09-20 22:20 . 2010-09-20 22:20 388096 ----a-r- c:\users\DANIK\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-20 21:39 . 2010-09-20 21:39 -------- d-----w- c:\program files\tea-timer-2.1
2010-09-20 21:34 . 2010-09-20 21:43 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-20 21:30 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-20 21:30 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-20 21:30 . 2010-09-20 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-20 20:04 . 2010-09-20 20:04 -------- d-----w- c:\program files\Trend Micro
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\users\DANIK\AppData\Roaming\Malwarebytes
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\programdata\Malwarebytes
2010-09-19 21:01 . 2010-09-21 17:13 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-19 18:06 . 2010-09-19 18:06 -------- d-----w- c:\users\DANIK\AppData\Local\Opera
2010-09-19 15:01 . 2010-09-20 21:24 -------- d-----w- c:\users\DANIK\AppData\Roaming\vlc
2010-09-19 10:35 . 2010-09-19 10:36 -------- d-----w- c:\program files\uTorrent
2010-09-19 10:34 . 2010-09-19 10:50 -------- d-----w- c:\users\DANIK\AppData\Roaming\uTorrent
2010-09-17 12:00 . 2010-09-20 21:24 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-17 11:56 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-12 16:30 . 2010-09-12 16:30 162816 ----a-w- c:\windows\system32\fmod.dll
2010-09-12 12:24 . 2010-07-24 19:24 344064 ----a-w- c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
2010-09-12 11:31 . 2009-04-30 07:53 2970112 ----a-w- c:\windows\system32\PhoenixDll.dll
2010-09-11 08:46 . 2010-09-11 08:55 -------- d-----w- c:\windows\WindowsMobile
2010-09-04 11:40 . 2010-09-04 11:40 -------- d-----w- c:\program files\Motorola
2010-09-04 11:33 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-09-04 11:33 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-09-04 11:33 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-09-03 10:49 . 2010-09-21 11:45 -------- d-----w- c:\program files\TNODUP
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\programdata\Hagel Technologies
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\program files\DU Meter

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-21 17:26 . 2009-07-14 08:44 626200 ----a-w- c:\windows\system32\perfh005.dat
2010-09-21 17:26 . 2009-07-14 08:44 122780 ----a-w- c:\windows\system32\perfc005.dat
2010-09-20 21:24 . 2010-06-18 23:25 -------- d-----w- c:\users\DANIK\AppData\Roaming\Winamp
2010-09-20 21:24 . 2010-06-18 23:31 -------- d-----w- c:\program files\SpeedFan
2010-09-20 21:24 . 2010-06-18 22:35 -------- d-----w- c:\users\DANIK\AppData\Roaming\GHISLER
2010-09-20 21:23 . 2010-07-05 18:57 -------- d-----w- c:\program files\QIP 2010 JadrisPack
2010-09-19 13:15 . 2010-06-20 00:40 -------- d-----w- c:\program files\CzDC-0699[C]
2010-09-17 15:57 . 2010-06-18 23:04 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-09-17 12:01 . 2010-06-19 04:37 -------- d-----w- c:\programdata\Microsoft Help
2010-09-12 15:32 . 2010-06-18 19:45 84512 ----a-w- c:\users\DANIK\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-11 08:48 . 2010-09-11 08:48 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2010-09-04 11:43 . 2010-06-19 04:38 -------- d-----w- c:\program files\Microsoft.NET
2010-09-03 13:27 . 2010-07-14 21:43 -------- d-----w- c:\program files\The KMPlayer
2010-08-07 22:52 . 2010-08-07 22:52 -------- d-----w- c:\program files\Common Files\Java
2010-08-07 22:51 . 2010-06-19 03:37 -------- d-----w- c:\program files\Java
2010-08-06 20:31 . 2010-08-06 20:30 -------- d-----w- c:\program files\qip2005pack
2010-08-01 11:38 . 2010-06-19 04:41 -------- d-----w- c:\users\DANIK\AppData\Roaming\Skype
2010-07-29 06:30 . 2010-08-12 15:40 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-12 15:40 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 03:00 . 2010-06-19 03:37 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 06:25 . 2010-09-04 11:32 978432 ----a-w- c:\windows\system32\wininet.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Thunderbird"="c:\program files\Mozilla Thunderbird\thunderbird -turbo" [X]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2010-08-21 2931744]
"Infium"="c:\program files\QIP 2010 JadrisPack\qip.exe" [2010-06-16 5813200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-06-08 9267816]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2006-12-29 569344]
"Wow Video&Audio"="c:\program files\Compal\Wow Video&Audio\WVAMain.exe" [2007-05-03 951856]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-04-07 2145000]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"SMBTray"="c:\program files\Compal\Smart Battery\SMBTray.exe" [2007-06-04 521776]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 1466368]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-06-19 23:19 136176 ----atw- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 13:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

R1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [2010-08-21 1411616]
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-04-07 133512]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-04-07 810120]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-04-07 96896]
R3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver;c:\program files\DU Meter\DUMETR32.SYS [2010-08-19 19368]
R3 netw5v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2010-01-13 6628352]
R3 uti5nju4;AVZ Kernel Driver;c:\windows\system32\Drivers\uti5nju4.sys [2010-09-21 7168]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-19 1343400]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-18 691696]
S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS [2007-03-14 9856]
S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-08-02 22784]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder

2010-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000Core.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]

2010-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000UA.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]
.
.
------- Supplementary Scan -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\
FF - prefs.js: browser.startup.homepage - chrome://fastdial/content/fastdial.html
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\users\DANIK\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll

---- FIREFOX POLICIES ----
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-RunOnce-<NO NAME> - (no file)



[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DUMeterSvc]
"ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-09-21 19:29:55
ComboFix-quarantined-files.txt 2010-09-21 17:29

Pre-Run: Volných bajtů: 38 418 505 728
Post-Run: Volných bajtů: 38 208 987 136

- - End Of File - - 35B5D7E5F0DC216EA0F2FDA8AE87B7C6

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43289
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod jaro3 » 21 zář 2010 20:01

Odinstaluj AVP Tool.+AVZ ( jestli tam máš..)

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

KillAll::
Collect::
c:\windows\system32\drivers\uti5nju4.sys

File::
c:\windows\system32\perfh005.dat
c:\windows\system32\perfc005.dat

Driver::
uti5nju4

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]


Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
c:\program files\DU Meter\DUMETR32.SYS

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/40 , nebo 1/40. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

DANIK6
nováček
Příspěvky: 25
Registrován: září 10
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod DANIK6 » 21 zář 2010 20:45

nasledoval som tvoj postup a tu su vysledky ...

log Combofix :
    ComboFix 10-09-20.07 - DANIK . 09. 2010 20:22:09.2.2 - x86
    Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1029.18.1022.236 [GMT 2:00]
    Running from: c:\users\DANIK\Desktop\ComboFix.exe
    Command switches used :: c:\users\DANIK\Desktop\CFScript.txt

    FILE ::
    "c:\windows\system32\perfc005.dat"
    "c:\windows\system32\perfh005.dat"

    file zipped: c:\windows\system32\drivers\uti5nju4.sys
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\drivers\uti5nju4.sys
    c:\windows\system32\perfc005.dat
    c:\windows\system32\perfh005.dat

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_UTI5NJU4
    -------\Service_uti5nju4


    ((((((((((((((((((((((((( Files Created from 2010-08-21 to 2010-09-21 )))))))))))))))))))))))))))))))
    .

    2010-09-21 18:29 . 2010-09-21 18:31 -------- d-----w- c:\users\DANIK\AppData\Local\temp
    2010-09-21 18:29 . 2010-09-21 18:29 -------- d-----w- c:\users\Public\AppData\Local\temp
    2010-09-21 18:29 . 2010-09-21 18:29 -------- d-----w- c:\users\Default\AppData\Local\temp
    2010-09-21 08:18 . 2010-09-21 08:20 -------- d-----w- c:\programdata\Kaspersky Lab
    2010-09-20 22:20 . 2010-09-20 22:20 388096 ----a-r- c:\users\DANIK\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2010-09-20 21:39 . 2010-09-20 21:39 -------- d-----w- c:\program files\tea-timer-2.1
    2010-09-20 21:34 . 2010-09-20 21:43 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-09-20 21:30 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-09-20 21:30 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-09-20 21:30 . 2010-09-20 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-09-20 20:04 . 2010-09-20 20:04 -------- d-----w- c:\program files\Trend Micro
    2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\users\DANIK\AppData\Roaming\Malwarebytes
    2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\programdata\Malwarebytes
    2010-09-19 21:01 . 2010-09-21 17:13 -------- d-----w- c:\programdata\Spybot - Search & Destroy
    2010-09-19 18:06 . 2010-09-19 18:06 -------- d-----w- c:\users\DANIK\AppData\Local\Opera
    2010-09-19 15:01 . 2010-09-20 21:24 -------- d-----w- c:\users\DANIK\AppData\Roaming\vlc
    2010-09-19 10:35 . 2010-09-19 10:36 -------- d-----w- c:\program files\uTorrent
    2010-09-19 10:34 . 2010-09-19 10:50 -------- d-----w- c:\users\DANIK\AppData\Roaming\uTorrent
    2010-09-17 12:00 . 2010-09-20 21:24 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-09-17 11:56 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
    2010-09-12 16:30 . 2010-09-12 16:30 162816 ----a-w- c:\windows\system32\fmod.dll
    2010-09-12 12:24 . 2010-07-24 19:24 344064 ----a-w- c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
    2010-09-12 11:31 . 2009-04-30 07:53 2970112 ----a-w- c:\windows\system32\PhoenixDll.dll
    2010-09-11 08:46 . 2010-09-11 08:55 -------- d-----w- c:\windows\WindowsMobile
    2010-09-04 11:40 . 2010-09-04 11:40 -------- d-----w- c:\program files\Motorola
    2010-09-04 11:33 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
    2010-09-04 11:33 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
    2010-09-04 11:33 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
    2010-09-03 10:49 . 2010-09-21 11:45 -------- d-----w- c:\program files\TNODUP
    2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\programdata\Hagel Technologies
    2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\program files\DU Meter

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-09-20 21:24 . 2010-06-18 23:25 -------- d-----w- c:\users\DANIK\AppData\Roaming\Winamp
    2010-09-20 21:24 . 2010-06-18 23:31 -------- d-----w- c:\program files\SpeedFan
    2010-09-20 21:24 . 2010-06-18 22:35 -------- d-----w- c:\users\DANIK\AppData\Roaming\GHISLER
    2010-09-20 21:23 . 2010-07-05 18:57 -------- d-----w- c:\program files\QIP 2010 JadrisPack
    2010-09-19 13:15 . 2010-06-20 00:40 -------- d-----w- c:\program files\CzDC-0699[C]
    2010-09-17 15:57 . 2010-06-18 23:04 -------- d-----w- c:\program files\Mozilla Thunderbird
    2010-09-17 12:01 . 2010-06-19 04:37 -------- d-----w- c:\programdata\Microsoft Help
    2010-09-12 15:32 . 2010-06-18 19:45 84512 ----a-w- c:\users\DANIK\AppData\Local\GDIPFONTCACHEV1.DAT
    2010-09-11 08:48 . 2010-09-11 08:48 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
    2010-09-04 11:43 . 2010-06-19 04:38 -------- d-----w- c:\program files\Microsoft.NET
    2010-09-03 13:27 . 2010-07-14 21:43 -------- d-----w- c:\program files\The KMPlayer
    2010-08-07 22:52 . 2010-08-07 22:52 -------- d-----w- c:\program files\Common Files\Java
    2010-08-07 22:51 . 2010-06-19 03:37 -------- d-----w- c:\program files\Java
    2010-08-06 20:31 . 2010-08-06 20:30 -------- d-----w- c:\program files\qip2005pack
    2010-08-01 11:38 . 2010-06-19 04:41 -------- d-----w- c:\users\DANIK\AppData\Roaming\Skype
    2010-07-29 06:30 . 2010-08-12 15:40 197632 ----a-w- c:\windows\system32\ir32_32.dll
    2010-07-29 06:30 . 2010-08-12 15:40 82944 ----a-w- c:\windows\system32\iccvid.dll
    2010-07-17 03:00 . 2010-06-19 03:37 423656 ----a-w- c:\windows\system32\deployJava1.dll
    2010-06-30 06:25 . 2010-09-04 11:32 978432 ----a-w- c:\windows\system32\wininet.dll
    2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
    2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
    .

    ((((((((((((((((((((((((((((( SnapShot@2010-09-21_17.28.18 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2010-06-18 19:49 . 2010-09-21 15:32 22174 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2010-06-18 19:49 . 2010-09-21 17:33 22174 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
    - 2009-07-14 04:55 . 2010-09-21 15:32 33188 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
    + 2009-07-14 04:55 . 2010-09-21 18:32 33188 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
    + 2009-07-14 04:34 . 2010-09-21 18:13 83848 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
    - 2010-06-18 22:07 . 2010-09-21 15:30 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2010-06-18 22:07 . 2010-09-21 18:31 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2010-06-19 05:08 . 2010-09-21 18:02 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
    - 2010-06-19 05:08 . 2010-09-21 17:12 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
    - 2010-06-19 05:08 . 2010-09-21 17:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
    + 2010-06-19 05:08 . 2010-09-21 18:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
    + 2010-06-19 05:08 . 2010-09-21 18:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
    - 2010-06-19 05:08 . 2010-09-21 17:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
    - 2010-06-18 22:07 . 2010-09-21 17:12 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2010-06-18 22:07 . 2010-09-21 18:31 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2010-06-18 22:07 . 2010-09-21 18:31 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2010-06-18 22:07 . 2010-09-21 15:30 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2010-06-18 19:45 . 2010-09-21 18:32 7448 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2786143777-1472676354-2263527552-1000_UserData.bin
    + 2010-09-21 17:31 . 2010-09-21 18:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2010-09-21 17:21 . 2010-09-21 17:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2010-09-21 17:31 . 2010-09-21 18:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2010-09-21 17:21 . 2010-09-21 17:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2009-07-14 02:05 . 2010-09-21 17:36 618912 c:\windows\System32\perfh009.dat
    + 2009-07-14 02:05 . 2010-09-21 17:36 107232 c:\windows\System32\perfc009.dat
    - 2009-07-14 02:03 . 2010-09-21 15:43 6815744 c:\windows\System32\SMI\Store\Machine\schema.dat
    + 2009-07-14 02:03 . 2010-09-21 17:43 6815744 c:\windows\System32\SMI\Store\Machine\schema.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Thunderbird"="c:\program files\Mozilla Thunderbird\thunderbird -turbo" [X]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
    "DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2010-08-21 2931744]
    "Infium"="c:\program files\QIP 2010 JadrisPack\qip.exe" [2010-06-16 5813200]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-06-08 9267816]
    "snp2uvc"="c:\windows\vsnp2uvc.exe" [2006-12-29 569344]
    "Wow Video&Audio"="c:\program files\Compal\Wow Video&Audio\WVAMain.exe" [2007-05-03 951856]
    "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-04-07 2145000]
    "DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
    "SMBTray"="c:\program files\Compal\Smart Battery\SMBTray.exe" [2007-06-04 521776]
    "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 1466368]
    "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2010-06-19 23:19 136176 ----atw- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
    2010-04-29 13:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-19 1343400]
    R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-18 691696]
    S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS [2007-03-14 9856]
    S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
    S2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [2010-08-21 1411616]
    S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-04-07 133512]
    S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-04-07 810120]
    S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-04-07 96896]
    S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-08-02 22784]
    S3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver;c:\program files\DU Meter\DUMETR32.SYS [2010-08-19 19368]
    S3 netw5v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2010-01-13 6628352]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    WindowsMobile REG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
    .
    Contents of the 'Scheduled Tasks' folder

    2010-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000Core.job
    - c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]

    2010-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000UA.job
    - c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]
    .
    .
    ------- Supplementary Scan -------
    .
    IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
    FF - ProfilePath - c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\
    FF - prefs.js: browser.startup.homepage - chrome://fastdial/content/fastdial.html
    FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
    FF - plugin: c:\users\DANIK\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll

    ---- FIREFOX POLICIES ----
    FF - user.js: network.prefetch-next - true
    FF - user.js: nglayout.initialpaint.delay - 250
    FF - user.js: layout.spellcheckDefault - 1
    FF - user.js: browser.urlbar.autoFill - false
    FF - user.js: browser.search.openintab - false
    FF - user.js: browser.tabs.closeButtons - 1
    FF - user.js: browser.tabs.opentabfor.middleclick - true
    FF - user.js: browser.tabs.tabMinWidth - 100
    FF - user.js: browser.urlbar.hideGoButton - false
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DUMeterSvc]
    "ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\nvvsvc.exe
    c:\windows\system32\nvvsvc.exe
    c:\windows\system32\WLANExt.exe
    c:\windows\system32\conhost.exe
    c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    c:\program files\Intel\WiFi\bin\EvtEng.exe
    c:\windows\system32\taskhost.exe
    c:\windows\system32\conhost.exe
    c:\progra~1\DUMETE~1\DUMeter.exe
    c:\windows\system32\wbem\unsecapp.exe
    c:\program files\Mozilla Thunderbird\thunderbird.exe
    c:\program files\Razer\DeathAdder\razertra.exe
    c:\program files\Razer\DeathAdder\razerofa.exe
    c:\windows\system32\WUDFHost.exe
    c:\windows\system32\sppsvc.exe
    c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
    .
    **************************************************************************
    .
    Completion time: 2010-09-21 20:35:05 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-09-21 18:35
    ComboFix2.txt 2010-09-21 17:29

    Pre-Run: Volných bajtů: 38 372 315 136
    Post-Run: Volných bajtů: 38 166 970 368

    - - End Of File - - 36F88E45C5E679121BCD83643A133DC1
    Upload was successful

log HJT :

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 20:37:54, on 21. 9. 2010
    Platform: Windows 7 (WinNT 6.00.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16385)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\PROGRA~1\DUMETE~1\DUMeter.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
    C:\Program Files\Razer\DeathAdder\razerhid.exe
    C:\Program Files\Compal\Smart Battery\SMBTray.exe
    C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    C:\Windows\WindowsMobile\wmdc.exe
    C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    C:\Program Files\QIP 2010 JadrisPack\qip.exe
    C:\Program Files\Razer\DeathAdder\razertra.exe
    C:\Program Files\Razer\DeathAdder\razerofa.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
    O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
    O4 - HKLM\..\Run: [Wow Video&Audio] C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
    O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SMBTray] C:\Program Files\Compal\Smart Battery\SMBTray.exe
    O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
    O4 - HKCU\..\Run: [Thunderbird] "C:\Program Files\Mozilla Thunderbird\thunderbird" -turbo
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
    O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
    O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010 JadrisPack\qip.exe" /nosrv /isolated /smiles 40 /autorun
    O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd. - C:\Program Files\DU Meter\DUMeterSvc.exe
    O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

    --
    End of file - 4684 bytes

test na Virustotal
Result: 0 /43 (0.0%)

...vytazenie RAM-ky stale obrovske ..

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43289
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod jaro3 » 21 zář 2010 21:48

c:\program files\DU Meter\DUMETR32.SYS

zkus to ještě tady:
http://www.kaspersky.com/scanforvirus
a
http://www.bitdefender.com/scanner/online/free.html
http://www.virscan.org/


Ještě jednou:
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab



toto sis nastavoval sám:

Kód: Vybrat vše

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
??

Na nákazu to nevypadá , spíš HW --HDD.. RAM proběhl bez jediné chyby??

Kontrola HDD na chyby
otevři Tento počítač- pravým na disk-vlastnosti-záložka nástroje-kontrola chyb-zkontrolovat-v okně zatrhni obě políčka-klikni na spustit- tam to napíše , že kontrola bude provedena po příštím spuštění...
Restartuj PC, kontrola s opravou někdy trvá i několik hodin...
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

DANIK6
nováček
Příspěvky: 25
Registrován: září 10
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod DANIK6 » 22 zář 2010 00:45

----> ciste

Kód: Vybrat vše

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
----> fixnute

test HDD prebehol bez chyby ... RAM-ku dalej testujem ale zatial stale bez chyby (necham to bezat cez noc)

..co sa tyka tych registrov tak si niesom isty ci som nieco take menil, ani si niesom isty o co presne ide ..priamy zasah do registrov som urcite nerobil ..jedine cez nejake nastavenia winu

..a co sa tyka HW tak mam trosku vadnu grafarnu ..2x mi uz odysla a opravoval som ju tymto sposobom. Cakam uz ale na novu a neviem ci by za tym mohla byt, pretoze vzdy ked odysla, tak ani nenabehol notas a tento problem so zahlcovanim zacal po nejakom case (1-2dni) ked som sa napojil do siete kablom, neviem ci to moze nejako suvisiet .. ked sa pozriem do spravca uloh tak mnozstvo ramky ktoru pouzivaju spustene procesy neodpoveda vytazeniu 80-90% ktore su tam uvedene.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43289
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod jaro3 » 22 zář 2010 08:35

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001

Klikni na soubor a vyber: uložit jako, v okně vyber:
Název souboru: fixme.reg
Typ souboru : všechny soubory
Kam: na svojí plochu
Klikni na uložit .Poklepej na ploše na soubor fixme.reg. Win se zeptá , zdali chceš přidat do registru, klikni na Ano.
Restart PC.
*****************************************************************************************************************************************
S tou GK to jsem si nepouštěl...Jakou máš GK , její paměť?
Celá sestava? celkový počet RAM?
*****************************************************************************************************************************************
Stáhni si OTH
na svojí plochu( pokud používáš Firefox , pravým klikni na OTH link a vyber uložit jako (Save as..).

Stáhni si OTL
na svojí plochu (pokud používáš Firefox , pravým klikni na OTL link a vyber uložit jako (Save as..).

Stáhni si soubor Scan.txt
na svojí plochu (pokud používáš Firefox , pravým klikni na OTL link a vyber uložit jako (Save as..).

Poklepej na soubor OTH na ploše , po spuštění programu klikni na Kill All Processes.Poté klikni na Start OTL .Poklepej Do prázdného okna pod Vlastní skenování /opravy ( Custom Scans box). Objeví se zpráva: Kliknutím na OK vyberete cestu k souboru, kliknutím na Zrušit zrušíte výběr.
Klikni na OK. Objeví se okno průzkumníku , zde klikneš na plochu a najdeš na ní soubor Scan.txt .Klikni na Otevřít.
Poté klikni na Rychle prohledat (Quick Scan). Neměň žádná jiná nastavení . Sken může trvat dlouho.
Kdy sken skončí , objeví se na ploše dva logy:
OTL.Txt a Extras.Txt , jsou uloženy ve stejném místě jako OTL.
Zkopíruj sem prosím celý obsah obou logů.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

DANIK6
nováček
Příspěvky: 25
Registrován: září 10
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod DANIK6 » 22 zář 2010 11:03

test ramky ktoru som pustal cez noc prebehol bez chyb... zmenu registrov som aplikoval ... co sa tyka GK tak mam GeForce 8600M GT 256MB DDR3 ... a zostavu mam pisanu aj v infe ked si ma rozklikas ( Compal FL90, C2D T7250 2Ghz, 1GB RAM, GeForce 8600M GT, WIN7 32bit )

..ked som pustil OTL prvy krat zabudol som tam hodit scan.txt,tak som ho pustil znova s doplnujucimi udajmi zo suboru scan.txt, ale nevyhodil mi uz log extras.txt takze ho nemam..

log OTL.txt
    OTL logfile created on: 22. 9. 2010 10:44:50 - Run 3
    OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\DANIK\Desktop
    An unknown product (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.7600.16385)
    Locale: 0000041b | Country: Slovenská republika | Language: SKY | Date Format: d. M. yyyy

    1 022,00 Mb Total Physical Memory | 477,00 Mb Available Physical Memory | 47,00% Memory free
    2,00 Gb Paging File | 1,00 Gb Available in Paging File | 64,00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 50,78 Gb Total Space | 35,12 Gb Free Space | 69,17% Space Free | Partition Type: NTFS
    Drive D: | 61,01 Gb Total Space | 15,83 Gb Free Space | 25,95% Space Free | Partition Type: NTFS
    E: Drive not present or media not loaded
    Drive F: | 7,58 Gb Total Space | 6,15 Gb Free Space | 81,10% Space Free | Partition Type: FAT32
    G: Drive not present or media not loaded
    Drive H: | 596,17 Gb Total Space | 36,43 Gb Free Space | 6,11% Space Free | Partition Type: NTFS
    I: Drive not present or media not loaded

    Computer Name: DANIK-PC
    Current User Name: DANIK
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Processes (SafeList) ==========

    PRC - [2010/09/22 10:43:19 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\DANIK\Desktop\otl.exe
    PRC - [2010/09/22 10:43:10 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Users\DANIK\Desktop\OTH.scr
    PRC - [2010/08/21 21:58:11 | 001,411,616 | ---- | M] (Hagel Technologies Ltd.) -- C:\Program Files\DU Meter\DUMeterSvc.exe
    PRC - [2010/04/07 21:07:24 | 000,810,120 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    PRC - [2010/04/07 21:07:04 | 002,145,000 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
    PRC - [2010/01/19 17:00:26 | 000,858,384 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    PRC - [2010/01/19 16:41:46 | 000,473,360 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    PRC - [2009/07/14 03:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe


    ========== Modules (SafeList) ==========

    MOD - [2010/09/22 10:43:19 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\DANIK\Desktop\otl.exe
    MOD - [2010/06/30 08:21:47 | 000,163,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\ieproxy.dll
    MOD - [2009/07/14 03:17:54 | 000,242,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rsaenh.dll
    MOD - [2009/07/14 03:16:18 | 001,011,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecs.dll
    MOD - [2009/07/14 03:16:16 | 000,082,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\thumbcache.dll
    MOD - [2009/07/14 03:16:15 | 000,363,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\StructuredQuery.dll
    MOD - [2009/07/14 03:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspicli.dll
    MOD - [2009/07/14 03:16:15 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srvcli.dll
    MOD - [2009/07/14 03:16:15 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\slc.dll
    MOD - [2009/07/14 03:16:13 | 000,643,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchFolder.dll
    MOD - [2009/07/14 03:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sechost.dll
    MOD - [2009/07/14 03:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samcli.dll
    MOD - [2009/07/14 03:16:13 | 000,045,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RpcRtRemote.dll
    MOD - [2009/07/14 03:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\profapi.dll
    MOD - [2009/07/14 03:16:03 | 001,661,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\networkexplorer.dll
    MOD - [2009/07/14 03:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netutils.dll
    MOD - [2009/07/14 03:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\KernelBase.dll
    MOD - [2009/07/14 03:15:14 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\EhStorShell.dll
    MOD - [2009/07/14 03:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
    MOD - [2009/07/14 03:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devobj.dll
    MOD - [2009/07/14 03:15:07 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptsp.dll
    MOD - [2009/07/14 03:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptbase.dll
    MOD - [2009/07/14 03:15:07 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cscapi.dll
    MOD - [2009/07/14 03:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll
    MOD - [2009/07/14 03:14:52 | 000,309,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\actxprxy.dll
    MOD - [2009/07/14 03:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
    MOD - [2009/07/14 03:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV - [2010/08/21 21:58:11 | 001,411,616 | ---- | M] (Hagel Technologies Ltd.) [Auto | Running] -- C:\Program Files\DU Meter\DUMeterSvc.exe -- (DUMeterSvc)
    SRV - [2010/06/19 03:05:59 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
    SRV - [2010/04/07 21:10:38 | 000,033,560 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
    SRV - [2010/04/07 21:07:24 | 000,810,120 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
    SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/01/19 17:00:26 | 000,858,384 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R)
    SRV - [2010/01/19 16:41:46 | 000,473,360 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R)
    SRV - [2009/07/14 03:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wwansvc.dll -- (WwanSvc)
    SRV - [2009/07/14 03:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbiosrvc.dll -- (WbioSrvc)
    SRV - [2009/07/14 03:16:17 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpo.dll -- (Power)
    SRV - [2009/07/14 03:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
    SRV - [2009/07/14 03:16:15 | 000,053,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sppuinotify.dll -- (sppuinotify)
    SRV - [2009/07/14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
    SRV - [2009/07/14 03:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper)
    SRV - [2009/07/14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
    SRV - [2009/07/14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
    SRV - [2009/07/14 03:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (PNRPsvc) Protokol PNRP (Peer Name Resolution Protocol)
    SRV - [2009/07/14 03:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (p2pimsvc)
    SRV - [2009/07/14 03:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\provsvc.dll -- (HomeGroupProvider)
    SRV - [2009/07/14 03:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg)
    SRV - [2009/07/14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV - [2009/07/14 03:15:36 | 000,194,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ListSvc.dll -- (HomeGroupListener)
    SRV - [2009/07/14 03:15:21 | 000,797,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
    SRV - [2009/07/14 03:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
    SRV - [2009/07/14 03:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\defragsvc.dll -- (defragsvc)
    SRV - [2009/07/14 03:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\bdesvc.dll -- (BDESVC)
    SRV - [2009/07/14 03:14:58 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AxInstSv.dll -- (AxInstSV) Instalační program ovládacích prvků ActiveX (AxInstSV)
    SRV - [2009/07/14 03:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appidsvc.dll -- (AppIDSvc)
    SRV - [2009/07/14 03:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\sppsvc.exe -- (sppsvc)
    SRV - [2009/06/10 23:14:05 | 000,128,848 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
    SRV - [2007/05/31 09:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
    SRV - [2007/05/31 09:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\DANIK\AppData\Local\Temp\catchme.sys -- (catchme)
    DRV - [2010/08/19 12:13:50 | 000,019,368 | ---- | M] (Hagel Technologies Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DU Meter\DUMetr32.sys -- (DUMeterDrv)
    DRV - [2010/06/19 01:15:52 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
    DRV - [2010/06/08 17:19:26 | 003,112,360 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
    DRV - [2010/04/07 21:08:12 | 000,096,896 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfpr.sys -- (epfwwfpr)
    DRV - [2010/04/07 21:07:08 | 000,114,984 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
    DRV - [2010/04/07 21:03:46 | 000,133,512 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\System32\drivers\eamonm.sys -- (eamonm)
    DRV - [2010/01/13 08:29:56 | 006,628,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (netw5v32) Ovladač adaptéru Intel(R)
    DRV - [2009/12/11 09:44:02 | 000,133,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecpkg.sys -- (KSecPkg)
    DRV - [2009/11/21 04:34:54 | 011,515,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
    DRV - [2009/07/14 03:26:21 | 000,015,952 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\cmdide.sys -- (cmdide)
    DRV - [2009/07/14 03:26:17 | 000,297,552 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpahci.sys -- (adpahci)
    DRV - [2009/07/14 03:26:15 | 000,422,976 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adp94xx.sys -- (adp94xx)
    DRV - [2009/07/14 03:26:15 | 000,159,312 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsbs.sys -- (amdsbs)
    DRV - [2009/07/14 03:26:15 | 000,146,512 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpu320.sys -- (adpu320)
    DRV - [2009/07/14 03:26:15 | 000,086,608 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arcsas.sys -- (arcsas)
    DRV - [2009/07/14 03:26:15 | 000,079,952 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsata.sys -- (amdsata)
    DRV - [2009/07/14 03:26:15 | 000,076,368 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arc.sys -- (arc)
    DRV - [2009/07/14 03:26:15 | 000,023,616 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\amdxata.sys -- (amdxata)
    DRV - [2009/07/14 03:26:15 | 000,014,400 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\aliide.sys -- (aliide)
    DRV - [2009/07/14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvstor.sys -- (nvstor)
    DRV - [2009/07/14 03:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvraid.sys -- (nvraid)
    DRV - [2009/07/14 03:20:44 | 000,044,624 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nfrd960.sys -- (nfrd960)
    DRV - [2009/07/14 03:20:37 | 000,089,168 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas.sys -- (LSI_SAS)
    DRV - [2009/07/14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iaStorV.sys -- (iaStorV)
    DRV - [2009/07/14 03:20:36 | 000,235,584 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MegaSR.sys -- (MegaSR)
    DRV - [2009/07/14 03:20:36 | 000,096,848 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_scsi.sys -- (LSI_SCSI)
    DRV - [2009/07/14 03:20:36 | 000,095,824 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_fc.sys -- (LSI_FC)
    DRV - [2009/07/14 03:20:36 | 000,054,864 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas2.sys -- (LSI_SAS2)
    DRV - [2009/07/14 03:20:36 | 000,041,040 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iirsp.sys -- (iirsp)
    DRV - [2009/07/14 03:20:36 | 000,030,800 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\megasas.sys -- (megasas)
    DRV - [2009/07/14 03:20:36 | 000,013,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hwpolicy.sys -- (hwpolicy)
    DRV - [2009/07/14 03:20:28 | 000,453,712 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\elxstor.sys -- (elxstor)
    DRV - [2009/07/14 03:20:28 | 000,070,720 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\djsvs.sys -- (aic78xx)
    DRV - [2009/07/14 03:20:28 | 000,067,152 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HpSAMD.sys -- (HpSAMD)
    DRV - [2009/07/14 03:20:28 | 000,046,160 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\fsdepends.sys -- (FsDepends)
    DRV - [2009/07/14 03:19:11 | 000,141,904 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vsmraid.sys -- (vsmraid)
    DRV - [2009/07/14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
    DRV - [2009/07/14 03:19:10 | 000,159,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vhdmp.sys -- (vhdmp)
    DRV - [2009/07/14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
    DRV - [2009/07/14 03:19:10 | 000,032,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vdrvroot.sys -- (vdrvroot)
    DRV - [2009/07/14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
    DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\wimmount.sys -- (WIMMount)
    DRV - [2009/07/14 03:19:10 | 000,016,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\viaide.sys -- (viaide)
    DRV - [2009/07/14 03:19:04 | 001,383,488 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql2300.sys -- (ql2300)
    DRV - [2009/07/14 03:19:04 | 000,173,648 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\rdyboost.sys -- (rdyboost)
    DRV - [2009/07/14 03:19:04 | 000,106,064 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql40xx.sys -- (ql40xx)
    DRV - [2009/07/14 03:19:04 | 000,077,888 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\sisraid4.sys -- (SiSRaid4)
    DRV - [2009/07/14 03:19:04 | 000,043,088 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pcw.sys -- (pcw)
    DRV - [2009/07/14 03:19:04 | 000,040,016 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\SiSRaid2.sys -- (SiSRaid2)
    DRV - [2009/07/14 03:19:04 | 000,021,072 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\stexstor.sys -- (stexstor)
    DRV - [2009/07/14 03:17:54 | 000,369,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\cng.sys -- (CNG)
    DRV - [2009/07/14 02:57:25 | 000,272,128 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\Brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
    DRV - [2009/07/14 02:02:41 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rdpbus.sys -- (rdpbus)
    DRV - [2009/07/14 02:01:41 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\RDPREFMP.sys -- (RDPREFMP)
    DRV - [2009/07/14 01:55:25 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MODEMCSA.sys -- (MODEMCSA)
    DRV - [2009/07/14 01:55:00 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)
    DRV - [2009/07/14 01:53:51 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\wfplwf.sys -- (WfpLwf)
    DRV - [2009/07/14 01:52:44 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ndiscap.sys -- (NdisCap)
    DRV - [2009/07/14 01:52:02 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vwifibus.sys -- (vwifibus)
    DRV - [2009/07/14 01:52:00 | 000,163,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\1394ohci.sys -- (1394ohci)
    DRV - [2009/07/14 01:51:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\umpass.sys -- (UmPass)
    DRV - [2009/07/14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
    DRV - [2009/07/14 01:51:08 | 000,004,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mshidkmdf.sys -- (mshidkmdf)
    DRV - [2009/07/14 01:46:55 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MTConfig.sys -- (MTConfig)
    DRV - [2009/07/14 01:45:26 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CompositeBus.sys -- (CompositeBus)
    DRV - [2009/07/14 01:36:52 | 000,050,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\appid.sys -- (AppID)
    DRV - [2009/07/14 01:33:50 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\scfilter.sys -- (scfilter)
    DRV - [2009/07/14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
    DRV - [2009/07/14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
    DRV - [2009/07/14 01:24:05 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\discache.sys -- (discache)
    DRV - [2009/07/14 01:19:21 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HidBatt.sys -- (HidBatt)
    DRV - [2009/07/14 01:16:36 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\acpipmi.sys -- (AcpiPmi)
    DRV - [2009/07/14 01:11:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdppm.sys -- (AmdPPM)
    DRV - [2009/07/14 00:54:14 | 000,026,624 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\hcw85cir.sys -- (hcw85cir)
    DRV - [2009/07/14 00:53:33 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbMdm.sys -- (BrUsbMdm)
    DRV - [2009/07/14 00:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbSer.sys -- (BrUsbSer)
    DRV - [2009/07/14 00:53:32 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrSerWdm.sys -- (BrSerWdm)
    DRV - [2009/07/14 00:53:28 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltLo.sys -- (BrFiltLo)
    DRV - [2009/07/14 00:53:28 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltUp.sys -- (BrFiltUp)
    DRV - [2009/07/14 00:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
    DRV - [2009/07/14 00:02:48 | 003,100,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\evbdx.sys -- (ebdrv)
    DRV - [2009/07/14 00:02:48 | 000,430,080 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\bxvbdx.sys -- (b06bdrv)
    DRV - [2009/05/05 12:15:58 | 001,095,808 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial)
    DRV - [2008/09/10 00:22:00 | 000,048,640 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
    DRV - [2008/04/21 15:26:12 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
    DRV - [2007/08/08 18:54:10 | 000,028,968 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\ATITool.sys -- (ATITool)
    DRV - [2007/08/02 17:32:26 | 000,022,784 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dadder.sys -- (DAdderFltr)
    DRV - [2007/03/14 10:16:40 | 000,009,856 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\EMSC.SYS -- (EMSC)
    DRV - [2007/01/17 03:04:46 | 009,599,872 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
    DRV - [2006/09/24 15:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\Windows\system32\speedfan.sys -- (speedfan)
    DRV - [1996/04/03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\giveio.sys -- (giveio)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========


    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CB 80 91 76 2E 5A CB 01 [binary data]
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "chrome://fastdial/content/fastdial.html"
    FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
    FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.1
    FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
    FF - prefs.js..extensions.enabledItems: fastdial@telega.phpnet.us:2.23b2
    FF - prefs.js..extensions.enabledItems: ietab@ip.cn:1.94.20100904
    FF - prefs.js..extensions.enabledItems: sitedelta@schierla.de:0.11.1
    FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
    FF - prefs.js..extensions.enabledItems: tabscope@xuldev.org:0.3.7
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
    FF - prefs.js..extensions.enabledItems: {20cc25e2-48c9-45e1-9a1f-1ccc1882b81b}:1.7
    FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.0.6
    FF - prefs.js..extensions.enabledItems: {ee56ecf0-6e7a-479a-8162-e123a991c7e7}:0.4.7
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
    FF - prefs.js..extensions.enabledItems: tabsontop-darthpalpatine@dummy.addons.mozilla.org:1.4.4
    FF - prefs.js..extensions.enabledItems: hidecaptionplus-dp@dummy.addons.mozilla.org:1.1.2
    FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.13
    FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.6.5
    FF - prefs.js..network.proxy.backup.ftp: "cache.fi.muni.cz"
    FF - prefs.js..network.proxy.backup.ftp_port: 5555
    FF - prefs.js..network.proxy.backup.gopher: "cache.fi.muni.cz"
    FF - prefs.js..network.proxy.backup.gopher_port: 5555
    FF - prefs.js..network.proxy.backup.socks: "cache.fi.muni.cz"
    FF - prefs.js..network.proxy.backup.socks_port: 5555
    FF - prefs.js..network.proxy.backup.ssl: "cache.fi.muni.cz"
    FF - prefs.js..network.proxy.backup.ssl_port: 5555
    FF - prefs.js..network.proxy.ftp: "cache34.ics.muni.cz"
    FF - prefs.js..network.proxy.ftp_port: 5555
    FF - prefs.js..network.proxy.gopher: "cache34.ics.muni.cz"
    FF - prefs.js..network.proxy.gopher_port: 5555
    FF - prefs.js..network.proxy.http: "cache34.ics.muni.cz"
    FF - prefs.js..network.proxy.http_port: 5555
    FF - prefs.js..network.proxy.no_proxies_on: "localhost, 127.0.0.1, mail.muni.cz:110, pop3.azet.sk:110"
    FF - prefs.js..network.proxy.share_proxy_settings: true
    FF - prefs.js..network.proxy.socks: "cache34.ics.muni.cz"
    FF - prefs.js..network.proxy.socks_port: 5555
    FF - prefs.js..network.proxy.ssl: "cache34.ics.muni.cz"
    FF - prefs.js..network.proxy.ssl_port: 5555

    FF - user.js..browser.search.openintab: false

    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/16 11:11:12 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/16 11:11:12 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/09/17 17:57:10 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
    FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/06/19 00:26:20 | 000,000,000 | ---D | M]

    [2010/06/19 02:22:07 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Extensions
    [2010/06/19 02:22:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
    [2010/09/21 17:47:17 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions
    [2010/08/06 21:03:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{20cc25e2-48c9-45e1-9a1f-1ccc1882b81b}
    [2010/09/14 11:48:31 | 000,000,000 | ---D | M] (Flashblock) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
    [2010/07/28 19:59:06 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2010/08/27 11:26:18 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    [2010/08/27 11:26:18 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
    [2010/06/19 02:22:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
    [2010/08/07 17:39:24 | 000,000,000 | ---D | M] (autoHideStatusbar) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{ee56ecf0-6e7a-479a-8162-e123a991c7e7}
    [2010/08/19 19:26:30 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\cfxe@Triton
    [2010/08/19 19:26:38 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\cfxHelper@Triton
    [2010/08/07 16:35:53 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\elemhidehelper@adblockplus.org
    [2010/07/20 20:22:41 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\fastdial@telega.phpnet.us
    [2010/08/18 10:16:29 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\hidecaptionplus-dp@dummy.addons.mozilla.org
    [2010/08/19 19:28:07 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\chromifox@altmusictv.com
    [2010/09/12 14:24:07 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn
    [2010/06/19 02:22:11 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\sitedelta@schierla.de
    [2010/09/18 14:50:08 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\tabscope@xuldev.org
    [2010/08/18 10:13:03 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\tabsontop-darthpalpatine@dummy.addons.mozilla.org
    [2010/09/21 17:47:17 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
    [2010/06/19 05:37:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    [2010/08/08 00:51:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
    [2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
    [2010/05/25 18:09:48 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
    [2010/04/01 19:40:34 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
    [2010/04/01 19:40:34 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
    [2010/04/01 19:40:34 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
    [2010/04/01 19:40:34 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
    [2010/04/01 19:40:34 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
    [2010/04/01 19:40:34 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml

    O1 HOSTS File: ([2010/09/21 20:30:56 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O4 - HKLM..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe ()
    O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
    O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
    O4 - HKLM..\Run: [SMBTray] C:\Program Files\Compal\Smart Battery\SMBTray.exe (Compal Electronics, Inc.)
    O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
    O4 - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix)
    O4 - HKLM..\Run: [Wow Video&Audio] C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe ()
    O4 - HKCU..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe (Hagel Technologies Ltd.)
    O4 - HKCU..\Run: [Infium] C:\Program Files\QIP 2010 JadrisPack\qip.exe (QIP)
    O4 - HKCU..\Run: [Thunderbird] C:\Program Files\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
    O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
    O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 147.229.192.2 147.229.190.134 147.229.191.135
    O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
    O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
    O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: FastUserSwitchingCompatibility - File not found
    NetSvcs: Ias - File not found
    NetSvcs: Nla - File not found
    NetSvcs: Ntmssvc - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: SRService - File not found
    NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
    NetSvcs: WmdmPmSp - File not found
    NetSvcs: LogonHours - File not found
    NetSvcs: PCAudit - File not found
    NetSvcs: helpsvc - File not found
    NetSvcs: uploadmgr - File not found
    NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
    NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

    ========== Files/Folders - Created Within 90 Days ==========

    [2010/09/22 10:43:16 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\DANIK\Desktop\OTL.exe
    [2010/09/22 10:43:04 | 000,258,560 | ---- | C] (OldTimer Tools) -- C:\Users\DANIK\Desktop\OTH.scr
    [2010/09/22 10:42:44 | 000,000,000 | ---D | C] -- C:\Users\DANIK\Desktop\log
    [2010/09/22 10:19:12 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
    [2010/09/21 22:16:57 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Roaming\QuickScan
    [2010/09/21 20:31:00 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
    [2010/09/21 20:29:15 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2010/09/21 20:29:15 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Local\temp
    [2010/09/21 20:20:30 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
    [2010/09/21 19:23:11 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2010/09/21 19:23:11 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2010/09/21 19:23:11 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2010/09/21 10:18:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
    [2010/09/20 23:39:19 | 000,000,000 | ---D | C] -- C:\Program Files\tea-timer-2.1
    [2010/09/20 23:34:23 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
    [2010/09/20 23:30:29 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
    [2010/09/20 23:30:28 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
    [2010/09/20 23:30:27 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/09/20 22:04:30 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
    [2010/09/20 21:36:55 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
    [2010/09/20 20:37:41 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2010/09/20 00:00:19 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Roaming\Malwarebytes
    [2010/09/20 00:00:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2010/09/19 23:01:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
    [2010/09/19 20:06:07 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Roaming\Opera
    [2010/09/19 20:06:07 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Local\Opera
    [2010/09/19 17:01:40 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Roaming\vlc
    [2010/09/19 12:35:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
    [2010/09/19 12:34:21 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Roaming\uTorrent
    [2010/09/17 14:00:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
    [2010/09/12 18:30:42 | 000,162,816 | ---- | C] (Firelight Technologies Pty, Ltd) -- C:\Windows\System32\fmod.dll
    [2010/09/12 13:31:55 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
    [2010/09/12 13:31:17 | 002,970,112 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\System32\PhoenixDll.dll
    [2010/09/11 10:46:37 | 000,000,000 | ---D | C] -- C:\Windows\WindowsMobile
    [2010/09/04 13:40:32 | 000,000,000 | ---D | C] -- C:\Program Files\Motorola
    [2010/09/03 12:49:07 | 000,000,000 | ---D | C] -- C:\Program Files\TNODUP
    [2010/09/01 14:36:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Hagel Technologies
    [2010/09/01 14:36:29 | 000,000,000 | ---D | C] -- C:\Program Files\DU Meter
    [2010/08/18 12:23:58 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Local\ESET
    [2010/08/08 00:52:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
    [2010/08/06 22:30:54 | 000,000,000 | ---D | C] -- C:\Program Files\qip2005pack
    [2010/07/14 23:43:08 | 000,000,000 | ---D | C] -- C:\Program Files\The KMPlayer
    [2010/07/10 15:40:16 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Local\Microangelo Toolset 6
    [2010/07/10 15:40:16 | 000,000,000 | ---D | C] -- D:\Dokumenty\Icons and Cursors
    [2010/07/10 15:39:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microangelo Toolset 6
    [2010/07/07 16:17:27 | 000,000,000 | ---D | C] -- C:\Windows\Sun
    [2010/07/05 20:57:05 | 000,000,000 | ---D | C] -- C:\Program Files\QIP 2010 JadrisPack
    [2010/07/05 01:41:01 | 000,000,000 | ---D | C] -- C:\Program Files\ATITool
    [2010/07/05 01:23:05 | 000,000,000 | ---D | C] -- C:\Program Files\Ray Adams
    [2010/06/24 22:07:33 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Local\ElevatedDiagnostics
    [2010/06/18 21:58:35 | 000,081,920 | ---- | C] ( ) -- C:\Windows\System32\rsnp2uvc.dll
    [2010/06/18 21:58:35 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnp2uvc.dll

    ========== Files - Modified Within 90 Days ==========

    [2010/09/22 10:44:48 | 007,340,032 | -HS- | M] () -- C:\Users\DANIK\ntuser.dat
    [2010/09/22 10:43:19 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\DANIK\Desktop\OTL.exe
    [2010/09/22 10:43:10 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Users\DANIK\Desktop\OTH.scr
    [2010/09/22 10:40:14 | 000,015,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2010/09/22 10:40:14 | 000,015,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2010/09/22 10:37:29 | 000,730,320 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
    [2010/09/22 10:37:29 | 000,618,912 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2010/09/22 10:37:29 | 000,107,232 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2010/09/22 10:33:04 | 000,000,435 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
    [2010/09/22 10:32:46 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
    [2010/09/22 10:32:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2010/09/22 10:32:37 | 804,069,376 | -HS- | M] () -- C:\hiberfil.sys
    [2010/09/22 10:30:16 | 000,001,022 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000UA.job
    [2010/09/22 10:19:08 | 279,208,243 | ---- | M] () -- C:\Windows\MEMORY.DMP
    [2010/09/22 10:05:17 | 000,938,505 | -H-- | M] () -- C:\Users\DANIK\AppData\Local\IconCache.db
    [2010/09/22 09:59:01 | 000,000,340 | ---- | M] () -- C:\Users\DANIK\Desktop\fixme.reg
    [2010/09/21 23:52:26 | 000,003,536 | ---- | M] () -- C:\bootsqm.dat
    [2010/09/21 20:31:15 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
    [2010/09/21 20:30:56 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
    [2010/09/21 18:58:32 | 003,848,793 | R--- | M] () -- C:\Users\DANIK\Desktop\ComboFix.exe
    [2010/09/21 16:26:07 | 000,524,288 | -HS- | M] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TMContainer00000000000000000002.regtrans-ms
    [2010/09/21 16:26:07 | 000,524,288 | -HS- | M] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TMContainer00000000000000000001.regtrans-ms
    [2010/09/21 16:26:07 | 000,065,536 | -HS- | M] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TM.blf
    [2010/09/21 16:14:00 | 000,000,492 | -HS- | M] () -- C:\Windows\setup_9.0.0.722_21.09.2010_10-25(2)drv.spi
    [2010/09/21 01:30:03 | 000,000,970 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000Core.job
    [2010/09/21 00:20:12 | 000,002,963 | ---- | M] () -- C:\Users\DANIK\Desktop\HiJackThis.lnk
    [2010/09/21 00:04:35 | 000,012,768 | ---- | M] () -- D:\Dokumenty\cc_20100921_000428.reg
    [2010/09/20 23:36:54 | 000,419,429 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100920-234541.backup
    [2010/09/20 23:34:34 | 000,001,220 | ---- | M] () -- C:\Users\DANIK\Desktop\Spybot - Search & Destroy.lnk
    [2010/09/20 23:30:32 | 000,000,983 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/09/20 20:24:21 | 000,007,608 | ---- | M] () -- C:\Users\DANIK\AppData\Local\Resmon.ResmonCfg
    [2010/09/19 22:36:15 | 000,012,768 | ---- | M] () -- D:\Dokumenty\cc_20100919_223604.reg
    [2010/09/19 12:35:36 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
    [2010/09/18 10:30:47 | 000,002,363 | ---- | M] () -- C:\Users\DANIK\Desktop\Google Chrome.lnk
    [2010/09/17 03:33:24 | 000,004,287 | ---- | M] () -- D:\Dokumenty\DU Meter Report.html
    [2010/09/17 03:31:26 | 000,005,590 | ---- | M] () -- D:\Dokumenty\DU Meter Report.pdf
    [2010/09/17 03:27:40 | 000,339,760 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [2010/09/16 19:48:44 | 000,005,566 | ---- | M] () -- D:\Dokumenty\cc_20100916_194826.reg
    [2010/09/16 10:10:45 | 000,759,819 | ---- | M] () -- D:\Dokumenty\Oznamenie_poistenca_platitela_poistneho-vyplnitelne.pdf
    [2010/09/13 10:54:56 | 000,010,752 | ---- | M] () -- C:\Users\DANIK\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/09/12 18:30:42 | 000,162,816 | ---- | M] (Firelight Technologies Pty, Ltd) -- C:\Windows\System32\fmod.dll
    [2010/09/12 17:32:01 | 000,084,512 | ---- | M] () -- C:\Users\DANIK\AppData\Local\GDIPFONTCACHEV1.DAT
    [2010/09/11 11:56:01 | 000,000,922 | ---- | M] () -- C:\Users\DANIK\Desktop\Centrum zařízení Windows Mobile.lnk
    [2010/09/11 11:06:32 | 000,000,478 | ---- | M] () -- C:\Windows\win.ini
    [2010/09/11 10:48:40 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
    [2010/09/05 09:57:43 | 000,018,080 | ---- | M] () -- D:\Dokumenty\cc_20100905_095725.reg
    [2010/09/03 15:28:11 | 000,001,984 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
    [2010/08/31 20:23:00 | 000,000,036 | ---- | M] () -- C:\Windows\usdthank.ini
    [2010/08/31 20:23:00 | 000,000,031 | ---- | M] () -- C:\Windows\idc.ini
    [2010/08/30 00:13:13 | 000,144,816 | ---- | M] () -- D:\Dokumenty\vyhl_2010_zapis_studentu_elektron_B-BK.pdf
    [2010/08/06 22:31:10 | 000,001,284 | ---- | M] () -- C:\Users\DANIK\Desktop\qip guest.lnk
    [2010/07/14 23:43:33 | 000,000,997 | ---- | M] () -- C:\Users\DANIK\Desktop\KMPlayer.lnk
    [2010/07/14 22:26:13 | 000,000,711 | ---- | M] () -- C:\Users\Public\Desktop\Half-Life 2 Episode One.lnk
    [2010/07/14 16:40:50 | 000,000,693 | ---- | M] () -- C:\Users\Public\Desktop\Half-Life 2 Episode Two.lnk
    [2010/07/10 15:29:56 | 000,001,953 | ---- | M] () -- C:\Users\DANIK\Desktop\QIP.lnk
    [2010/07/08 16:30:04 | 000,059,392 | ---- | M] () -- D:\Dokumenty\Otazky_ABCH_ke_zkousce_091.doc
    [2010/06/25 01:13:26 | 000,000,158 | ---- | M] () -- C:\Users\Public\Documents\SMBSettings.ini

    ========== Files Created - No Company Name ==========

    [2010/09/22 10:19:08 | 279,208,243 | ---- | C] () -- C:\Windows\MEMORY.DMP
    [2010/09/22 09:59:01 | 000,000,340 | ---- | C] () -- C:\Users\DANIK\Desktop\fixme.reg
    [2010/09/21 23:52:26 | 000,003,536 | ---- | C] () -- C:\bootsqm.dat
    [2010/09/21 19:23:11 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
    [2010/09/21 19:23:11 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2010/09/21 19:23:11 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2010/09/21 19:23:11 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
    [2010/09/21 19:23:11 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2010/09/21 19:12:18 | 003,848,793 | R--- | C] () -- C:\Users\DANIK\Desktop\ComboFix.exe
    [2010/09/21 13:24:25 | 000,000,492 | -HS- | C] () -- C:\Windows\setup_9.0.0.722_21.09.2010_10-25(2)drv.spi
    [2010/09/21 00:20:12 | 000,002,963 | ---- | C] () -- C:\Users\DANIK\Desktop\HiJackThis.lnk
    [2010/09/21 00:04:34 | 000,012,768 | ---- | C] () -- D:\Dokumenty\cc_20100921_000428.reg
    [2010/09/20 23:34:34 | 000,001,220 | ---- | C] () -- C:\Users\DANIK\Desktop\Spybot - Search & Destroy.lnk
    [2010/09/20 23:30:32 | 000,000,983 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/09/20 23:25:43 | 000,524,288 | -HS- | C] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TMContainer00000000000000000002.regtrans-ms
    [2010/09/20 23:25:43 | 000,524,288 | -HS- | C] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TMContainer00000000000000000001.regtrans-ms
    [2010/09/20 23:25:43 | 000,065,536 | -HS- | C] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TM.blf
    [2010/09/19 22:50:14 | 000,007,608 | ---- | C] () -- C:\Users\DANIK\AppData\Local\Resmon.ResmonCfg
    [2010/09/19 22:36:13 | 000,012,768 | ---- | C] () -- D:\Dokumenty\cc_20100919_223604.reg
    [2010/09/19 12:35:36 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
    [2010/09/17 03:32:38 | 000,004,287 | ---- | C] () -- D:\Dokumenty\DU Meter Report.html
    [2010/09/17 03:31:25 | 000,005,590 | ---- | C] () -- D:\Dokumenty\DU Meter Report.pdf
    [2010/09/16 19:48:42 | 000,005,566 | ---- | C] () -- D:\Dokumenty\cc_20100916_194826.reg
    [2010/09/16 10:10:45 | 000,759,819 | ---- | C] () -- D:\Dokumenty\Oznamenie_poistenca_platitela_poistneho-vyplnitelne.pdf
    [2010/09/11 11:56:01 | 000,000,922 | ---- | C] () -- C:\Users\DANIK\Desktop\Centrum zařízení Windows Mobile.lnk
    [2010/09/11 10:48:40 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
    [2010/09/05 09:57:31 | 000,018,080 | ---- | C] () -- D:\Dokumenty\cc_20100905_095725.reg
    [2010/08/31 20:23:00 | 000,000,036 | ---- | C] () -- C:\Windows\usdthank.ini
    [2010/08/31 20:23:00 | 000,000,031 | ---- | C] () -- C:\Windows\idc.ini
    [2010/08/30 00:13:13 | 000,144,816 | ---- | C] () -- D:\Dokumenty\vyhl_2010_zapis_studentu_elektron_B-BK.pdf
    [2010/08/06 22:31:10 | 000,001,284 | ---- | C] () -- C:\Users\DANIK\Desktop\qip guest.lnk
    [2010/07/14 23:43:33 | 000,000,997 | ---- | C] () -- C:\Users\DANIK\Desktop\KMPlayer.lnk
    [2010/07/14 16:40:50 | 000,000,693 | ---- | C] () -- C:\Users\Public\Desktop\Half-Life 2 Episode Two.lnk
    [2010/07/14 16:34:36 | 000,000,711 | ---- | C] () -- C:\Users\Public\Desktop\Half-Life 2 Episode One.lnk
    [2010/07/05 20:57:20 | 000,001,953 | ---- | C] () -- C:\Users\DANIK\Desktop\QIP.lnk
    [2010/07/05 01:05:40 | 000,004,224 | ---- | C] () -- C:\Windows\System32\drivers\NVStrap.sys
    [2010/06/25 01:12:42 | 000,004,688 | -H-- | C] () -- D:\Dokumenty\WVAProp.xml
    [2010/06/20 03:12:11 | 000,000,108 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
    [2010/06/19 20:47:11 | 000,010,752 | ---- | C] () -- C:\Users\DANIK\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/06/19 00:55:06 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
    [2010/06/18 21:58:36 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini
    [2010/06/18 21:58:35 | 009,599,872 | ---- | C] () -- C:\Windows\System32\drivers\snp2uvc.sys
    [2009/07/14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
    [2009/07/14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
    [2007/08/08 18:54:10 | 000,028,968 | ---- | C] () -- C:\Windows\System32\drivers\ATITool.sys
    [2007/04/17 09:44:28 | 000,266,240 | ---- | C] () -- C:\Windows\System32\EMSC.DLL
    [2007/03/14 10:16:40 | 000,009,856 | ---- | C] () -- C:\Windows\System32\drivers\EMSC.sys
    [1996/04/03 21:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys

    ========== LOP Check ==========

    [2010/06/20 03:48:21 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\365dni
    [2010/07/04 13:14:55 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\DAEMON Tools Lite
    [2010/09/20 23:24:01 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\GHISLER
    [2010/06/19 01:05:55 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\IrfanView
    [2010/09/19 20:06:07 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Opera
    [2010/09/21 22:17:17 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\QuickScan
    [2010/06/19 02:22:36 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Thunderbird
    [2010/09/19 12:50:22 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\uTorrent
    [2009/07/14 06:53:46 | 000,016,444 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
    [2009/07/14 03:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
    [2010/06/18 22:10:47 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
    [2010/09/21 23:52:26 | 000,003,536 | ---- | M] () -- C:\bootsqm.dat
    [2010/09/21 20:36:22 | 000,016,692 | ---- | M] () -- C:\ComboFix.txt
    [2009/06/10 23:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
    [2010/09/22 10:32:37 | 804,069,376 | -HS- | M] () -- C:\hiberfil.sys
    [2010/09/22 10:32:41 | 1073,741,824 | -HS- | M] () -- C:\pagefile.sys

    < %systemroot%\*. /mp /s >

    < %systemroot%\system32\*.dll /lockedfiles >

    < %systemroot%\Tasks\*.job /lockedfiles >

    < %systemroot%\System32\config\*.sav >

    < %systemroot%\system32\drivers\*.sys /90 >

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:D44A64FE

    < End of report >

DANIK6
nováček
Příspěvky: 25
Registrován: září 10
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu logu - system zahlcuje ram

Příspěvekod DANIK6 » 22 zář 2010 11:52

tak nakoniec ked som si precital tutorial a po nejakych zmenach v nastaveni mi to vyplulo aj extras.txt viz:

    OTL Extras logfile created on: 22. 9. 2010 11:33:16 - Run 5
    OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\DANIK\Desktop
    An unknown product (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.7600.16385)
    Locale: 0000041b | Country: Slovenská republika | Language: SKY | Date Format: d. M. yyyy

    1 022,00 Mb Total Physical Memory | 409,00 Mb Available Physical Memory | 40,00% Memory free
    2,00 Gb Paging File | 1,00 Gb Available in Paging File | 64,00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 50,78 Gb Total Space | 35,13 Gb Free Space | 69,17% Space Free | Partition Type: NTFS
    Drive D: | 61,01 Gb Total Space | 15,83 Gb Free Space | 25,95% Space Free | Partition Type: NTFS
    E: Drive not present or media not loaded
    Drive F: | 7,58 Gb Total Space | 6,15 Gb Free Space | 81,10% Space Free | Partition Type: FAT32
    G: Drive not present or media not loaded
    Drive H: | 596,17 Gb Total Space | 36,43 Gb Free Space | 6,11% Space Free | Partition Type: NTFS
    I: Drive not present or media not loaded

    Computer Name: DANIK-PC
    Current User Name: DANIK
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Extra Registry (All) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
    .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
    .hta [@ = htafile] -- C:\Windows\System32\mshta.exe (Microsoft Corporation)
    .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
    .inf [@ = inffile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
    .ini [@ = inifile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
    .url [@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
    .js [@ = JSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
    .jse [@ = JSEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
    .reg [@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
    .txt [@ = txtfile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
    .vbe [@ = VBEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
    .vbs [@ = VBSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
    .wsf [@ = WSFFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
    .wsh [@ = WSHFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = ChromeHTML] -- Reg Error: Key error. File not found

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
    batfile [open] -- "%1" %*
    batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
    cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
    cmdfile [open] -- "%1" %*
    cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    htafile [open] -- C:\Windows\System32\mshta.exe "%1" %* (Microsoft Corporation)
    htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
    htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
    htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
    http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
    https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
    inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
    inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
    inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
    jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
    jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
    jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
    jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
    jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
    regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
    regfile [merge] -- Reg Error: Key error.
    regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
    txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
    vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
    vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
    vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
    vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
    vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
    vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
    wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
    wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
    wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
    wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [KMPlayer.Enqueue] -- "C:\Program Files\The KMPlayer\KMPlayer.exe"/ADD "%1"
    Directory [KMPlayer.Play] -- "C:\Program Files\The KMPlayer\KMPlayer.exe" "%1" (Pandora.TV)
    Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
    Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
    Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 21
    "{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = USB Video Device
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{449A16C4-83B3-426C-AA4A-00A34E80C093}" = Smart Battery
    "{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
    "{47609E69-4C5E-48B1-A889-24C6B82B5C04}" = Vista Shortcut Manager
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.57.01
    "{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
    "{71414EC2-0684-4A15-A85A-E0E259D117AF}" = Microangelo Toolset 6
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
    "{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
    "{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
    "{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
    "{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
    "{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
    "{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
    "{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{294B4278-CF7B-40B9-86A1-2D3FF0C2C524}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
    "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
    "{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{10EC59E5-9BCE-4884-BB1A-E28627220232}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
    "{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
    "{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
    "{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
    "{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{904CCF62-818D-4675-BC76-D37EB399F917}" = Centrum zařízení Windows Mobile
    "{9A4CBA78-CFAD-4058-9AB8-532F5DF44682}_is1" = Program 365dní
    "{9EF7918F-6283-48D4-8648-9FE84BE9FB41}" = The Orange Box
    "{AC76BA86-7AD7-1051-7B44-A93000000001}" = Adobe Reader 9.3.4 - Slovak
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{B90E5EBE-DF18-44D5-9D18-689ADEE9DA6C}" = Intel(R) PROSet/Wireless WiFi Software
    "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
    "{DE7E6DBF-ABEE-43FF-A3A1-4DCF46411736}" = ESET NOD32 Antivirus
    "{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile Device Center Driver Update
    "{EB1B8449-CD8F-485B-ADB6-02FBCFE180D3}" = Razer DeathAdder(TM) Mouse
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F408DA6B-DA75-4D95-B87D-49AFF0B4EBB0}" = Wow Video&Audio utility
    "{FEF06E73-A519-4510-8CF3-B66041B91D8A}" = EMSC
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
    "ATITool" = ATITool Overclocking Utility
    "CCleaner" = CCleaner
    "DUMeter3_is1" = DU Meter
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "InstallShield_{449A16C4-83B3-426C-AA4A-00A34E80C093}" = Smart Battery
    "InstallShield_{F408DA6B-DA75-4D95-B87D-49AFF0B4EBB0}" = Wow Video&Audio utility
    "IrfanView" = IrfanView (remove only)
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
    "Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
    "Mozilla Thunderbird (3.1.4)" = Mozilla Thunderbird (3.1.4)
    "Orneta Notepad Mobile v3.1.1" = Orneta Notepad Mobile v3.1.1
    "ProInst" = Intel PROSet Wireless
    "QIP 2010 JadrisPack 1.0.0" = QIP 2010 JadrisPack 1.0.0
    "SMSERIAL" = Motorola SM56 Speakerphone Modem
    "SpeedFan" = SpeedFan (remove only)
    "The KMPlayer" = The KMPlayer (remove only)
    "Totalcmd" = Total Commander (Remove or Repair)
    "uTorrent" = µTorrent
    "VLC media player" = VLC media player 1.1.4
    "Winamp" = Winamp
    "WinRAR archiver" = WinRAR archiver

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Google Chrome" = Google Chrome
    "Winamp Detect" = Winamp Detector Plug-in

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 22. 9. 2010 4:12:58 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
    Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
    hodnota DWORD v datové oblasti obsahuje kód chyby Win32.

    Error - 22. 9. 2010 4:12:58 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
    Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
    hodnota DWORD v datové oblasti obsahuje kód chyby Win32.

    Error - 22. 9. 2010 4:25:41 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
    Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
    hodnota DWORD v datové oblasti obsahuje kód chyby Win32.

    Error - 22. 9. 2010 4:25:41 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
    Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
    hodnota DWORD v datové oblasti obsahuje kód chyby Win32.

    Error - 22. 9. 2010 4:37:29 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
    Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
    hodnota DWORD v datové oblasti obsahuje kód chyby Win32.

    Error - 22. 9. 2010 4:37:29 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
    Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
    hodnota DWORD v datové oblasti obsahuje kód chyby Win32.

    Error - 22. 9. 2010 4:56:54 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
    Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
    hodnota DWORD v datové oblasti obsahuje kód chyby Win32.

    Error - 22. 9. 2010 4:56:55 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
    Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
    hodnota DWORD v datové oblasti obsahuje kód chyby Win32.

    Error - 22. 9. 2010 5:24:47 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
    Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
    hodnota DWORD v datové oblasti obsahuje kód chyby Win32.

    Error - 22. 9. 2010 5:24:47 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
    Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
    hodnota DWORD v datové oblasti obsahuje kód chyby Win32.

    [ System Events ]
    Error - 22. 9. 2010 4:22:37 | Computer Name = DANIK-PC | Source = Service Control Manager | ID = 7034
    Description = Služba NVIDIA Display Driver Service byla neočekávaně ukončena. Tento
    stav nastal již 1krát.

    Error - 22. 9. 2010 4:33:04 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 34001
    Description =

    Error - 22. 9. 2010 4:33:04 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 30013
    Description =

    Error - 22. 9. 2010 4:44:32 | Computer Name = DANIK-PC | Source = Service Control Manager | ID = 7034
    Description = Služba NVIDIA Display Driver Service byla neočekávaně ukončena. Tento
    stav nastal již 1krát.

    Error - 22. 9. 2010 4:52:21 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 34001
    Description =

    Error - 22. 9. 2010 4:52:21 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 30013
    Description =

    Error - 22. 9. 2010 5:12:14 | Computer Name = DANIK-PC | Source = Service Control Manager | ID = 7034
    Description = Služba NVIDIA Display Driver Service byla neočekávaně ukončena. Tento
    stav nastal již 1krát.

    Error - 22. 9. 2010 5:20:25 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 34001
    Description =

    Error - 22. 9. 2010 5:20:25 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 30013
    Description =

    Error - 22. 9. 2010 5:32:39 | Computer Name = DANIK-PC | Source = Service Control Manager | ID = 7034
    Description = Služba NVIDIA Display Driver Service byla neočekávaně ukončena. Tento
    stav nastal již 1krát.


    < End of report >

..v pripade potreby sem mozem hodit aj log OTL z toho konkretneho runu kedy mi k nemu vyplulo aj EXTRAS


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 73 hostů