Ještě pro přesnost: asi den předtím, než začaly problémy jsem stahoval nové drivery pro ATI, sice nevím, jak by to mohlo pomoct, ale radši to uvedu. Posílám log, bohužel jsem při testování klikl do okénka a test náhle skončil (možná už byl na konci, možná jsem ho omylem ukončil), každopádně se na ploše vytvořil pouze OTL.txt a žádné extras.txt. Posílám tedy log z OTl.txt.
OTL logfile created on: 13.3.2011 9:33:57 - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\gottfried\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 73,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 91,00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298,08 Gb Total Space | 79,08 Gb Free Space | 26,53% Space Free | Partition Type: NTFS
Computer Name: ING-A8E03130CE5 | User Name: gottfried | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\gottfried\Plocha\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\gottfried\Plocha\OTH.scr (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgam.exe (AVG Technologies CZ, s.r.o.)
========== Modules (SafeList) ========== MOD - C:\Documents and Settings\gottfried\Plocha\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (NMSAccess) -- File not found
SRV - (HidServ) -- File not found
SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (UserAccess7) SecuROM User Access Service (V7) -- C:\WINDOWS\system32\UAService7.exe ()
SRV - (IJPLMSVC) -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
========== Driver Services (SafeList) ========== DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Avgldx86) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Tcpip6) -- C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology (StarForce))
DRV - (gdrv) -- C:\WINDOWS\gdrv.sys (Windows (R) 2000 DDK provider)
DRV - (NwlnkIpx) -- C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (nm) -- C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (NwlnkNb) -- C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) -- C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (JRAID) -- C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (speedfan) -- C:\WINDOWS\system32\speedfan.sys (Windows (R) 2000 DDK provider)
DRV - (sfsync02) StarForce Protection Synchronization Driver (version 2.x) -- C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology (StarForce))
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 16.129.0.13:3128
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011.02.13 10:44:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
O1 HOSTS File: ([2009.12.23 21:00:28 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Companion BHO) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_1.dll (Yahoo! Inc.)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3 - HKLM\..\Toolbar: (&Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_1.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_1.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [36X Raid Configurer] C:\WINDOWS\System32\xRaidSetup.exe (Gigabyte Technology Corp.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [boincmgr] C:\Program Files\BOINC\boincmgr.exe (Space Sciences Laboratory)
O4 - HKLM..\Run: [boinctray] C:\Program Files\BOINC\boinctray.exe (Space Sciences Laboratory)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 43 01 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupda ... 1302413656 (WUWebControl Class)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1}
https://www.battlefieldheroes.com/stati ... 0.31.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 90.183.115.6 80.79.29.8 10.0.1.250
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.08.30 20:10:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.112 -- [ NTFS ]
O33 - MountPoints2\{4f9875f1-4ef5-11df-b013-001a4d5e3f02}\Shell - "" = AutoRun
O33 - MountPoints2\{4f9875f1-4ef5-11df-b013-001a4d5e3f02}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)
========== Files/Folders - Created Within 30 Days ========== [2011.03.13 09:32:15 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\gottfried\Plocha\OTL.exe
[2011.03.13 09:32:08 | 000,258,560 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\gottfried\Plocha\OTH.scr
[2011.03.13 00:13:40 | 000,000,000 | ---D | C] -- C:\ERDNT
[2011.03.13 00:13:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2011.03.13 00:13:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011.03.13 00:13:27 | 000,000,000 | ---D | C] -- C:\!FixIEDef
[2011.03.11 17:42:13 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2011.03.11 14:26:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\ATI
[2011.03.10 23:47:42 | 000,000,000 | ---D | C] -- C:\5286e337a95449d82b5d0e
[2011.03.10 20:25:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\ATI Stream SDK v2
[2011.03.10 20:25:46 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Stream
[2011.03.10 20:25:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Catalyst Control Center
[2011.03.10 19:47:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\gottfried\Nabídka Start\Programy\Portal
[2011.03.10 08:00:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\7-Zip
[2011.03.08 15:57:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\gottfried\Dokumenty\knihy
[2011.02.22 23:58:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Fallout
[2011.02.22 23:27:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\gottfried\Data aplikací\Kalypso Media
[2011.02.13 10:46:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\gottfried\Data aplikací\AVG10
[2011.02.13 10:45:44 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2011.02.13 10:45:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\AVG 2011
[2011.02.13 10:44:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\AVG10
[2011.02.13 10:44:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2011.02.13 10:32:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs
[2011.02.13 10:29:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data
[2011.02.13 10:27:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011.03.13 09:32:20 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\gottfried\Plocha\OTL.exe
[2011.03.13 09:32:08 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\gottfried\Plocha\OTH.scr
[2011.03.13 09:29:14 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.03.13 09:28:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.03.13 00:58:19 | 108,511,184 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011.03.12 20:53:29 | 000,000,000 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2011.03.11 21:16:28 | 000,010,109 | ---- | M] () -- C:\Documents and Settings\gottfried\Dokumenty\ČJ-4B-Gottfried Jaroslav.csv
[2011.03.11 14:36:54 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011.03.10 07:43:59 | 000,000,942 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Easy-PhotoPrint EX.lnk
[2011.03.10 07:43:08 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\MP Navigator EX 1.0.lnk
[2011.03.09 22:13:17 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011.03.03 21:37:48 | 001,899,002 | ---- | M] () -- C:\Documents and Settings\gottfried\Dokumenty\Schule.jpg
[2011.02.27 12:12:15 | 000,043,818 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011.02.25 01:51:05 | 000,210,432 | ---- | M] () -- C:\Documents and Settings\gottfried\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.02.13 10:45:36 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\AVG 2011.lnk
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2011.03.13 00:58:19 | 108,511,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011.03.10 18:22:51 | 000,010,109 | ---- | C] () -- C:\Documents and Settings\gottfried\Dokumenty\ČJ-4B-Gottfried Jaroslav.csv
[2011.03.03 21:37:47 | 001,899,002 | ---- | C] () -- C:\Documents and Settings\gottfried\Dokumenty\Schule.jpg
[2011.02.27 12:12:15 | 000,043,818 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011.02.13 10:45:36 | 000,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\AVG 2011.lnk
[2010.11.28 21:09:38 | 000,138,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010.11.28 21:09:16 | 000,215,016 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2010.11.26 20:09:19 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\gottfried\Data aplikací\PnkBstrK.sys
[2010.11.26 20:08:47 | 002,427,248 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_heroes.exe
[2010.11.26 20:08:47 | 000,075,064 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2010.10.29 23:24:58 | 000,078,968 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2010.10.09 13:08:49 | 000,000,025 | ---- | C] () -- C:\WINDOWS\popcinfot.dat
[2010.01.29 20:27:34 | 000,000,024 | ---- | C] () -- C:\WINDOWS\System32\sysogg.dll
[2010.01.29 20:26:02 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2010.01.06 20:45:54 | 000,007,034 | ---- | C] () -- C:\WINDOWS\smacker.ini
[2009.12.24 13:03:30 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2009.12.23 11:15:08 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2009.12.20 11:11:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009.09.22 18:50:50 | 000,132,183 | ---- | C] () -- C:\WINDOWS\War3Unin.dat
[2009.05.16 13:05:41 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2009.05.14 19:16:20 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\DGRip.dll
[2009.02.17 19:39:16 | 000,000,034 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009.01.15 16:12:13 | 000,319,488 | R--- | C] () -- C:\WINDOWS\System32\MafiaSetup.exe
[2008.10.26 15:38:42 | 000,087,040 | ---- | C] () -- C:\WINDOWS\UnGins.exe
[2008.10.20 17:07:53 | 000,000,400 | ---- | C] () -- C:\WINDOWS\T602.INI
[2008.09.13 09:02:08 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\UAService7.exe
[2008.08.31 16:12:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PowerReg.dat
[2008.07.23 15:04:43 | 000,000,028 | ---- | C] () -- C:\WINDOWS\SOK04.ini
[2008.07.14 16:13:35 | 000,000,235 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.07.14 16:10:53 | 000,001,187 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2008.07.06 15:01:21 | 000,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2008.07.06 10:29:49 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2008.07.05 15:16:31 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008.05.31 20:57:35 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2008.05.24 19:05:18 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.05.24 17:37:36 | 000,210,432 | ---- | C] () -- C:\Documents and Settings\gottfried\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.05.23 21:28:39 | 000,000,412 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008.05.23 21:04:17 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008.05.23 21:04:17 | 000,000,063 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2008.05.23 21:04:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2008.05.20 16:50:17 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008.05.20 16:07:56 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008.05.20 16:06:53 | 000,126,112 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008.05.20 16:06:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2008.05.20 16:05:04 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2008.05.20 16:00:16 | 000,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys
[2008.05.20 14:57:01 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008.05.20 14:27:54 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008.05.20 14:23:23 | 000,023,028 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008.02.26 03:41:28 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2008.02.26 03:41:28 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2008.02.26 03:41:28 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2008.02.14 18:35:13 | 000,227,587 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2007.10.29 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2007.10.29 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2007.10.29 13:00:00 | 000,522,066 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2007.10.29 13:00:00 | 000,518,982 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2007.10.29 13:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2007.10.29 13:00:00 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2007.10.29 13:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2007.10.29 13:00:00 | 000,104,866 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2007.10.29 13:00:00 | 000,089,452 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2007.10.29 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2007.10.29 13:00:00 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2007.10.29 13:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2007.10.29 13:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2007.10.29 13:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2007.10.29 13:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2007.10.29 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2005.10.14 10:56:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 10:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 10:56:50 | 000,778,240 | ---- | C] () -- C:\WINDOWS\System32\DivXsm.exe
[2005.10.14 10:56:50 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 10:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 10:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005.10.14 10:56:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 10:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 10:56:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[1999.01.22 19:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1996.04.03 20:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ========== [2011.03.10 07:39:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVG10
[2011.02.13 10:39:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg9
[2010.08.07 21:19:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\BioWare
[2011.03.13 09:29:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\BOINC
[2008.05.23 21:21:17 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2011.02.08 20:19:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonIJPLM
[2011.02.13 10:45:44 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2009.11.01 16:26:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2008.05.23 22:11:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\LightScribe
[2011.02.13 10:34:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2010.07.22 16:11:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PopCap Games
[2008.05.23 21:28:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ScanSoft
[2011.02.02 19:57:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Solidshield
[2011.03.05 21:22:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2011.03.11 17:44:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2011.03.11 17:42:13 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2009.05.27 15:24:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\{92E7A367-8E12-4830-AA70-29C32E331A81}
[2009.10.26 15:34:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2009.09.04 12:25:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\3Stars
[2011.02.13 10:46:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\AVG10
[2011.01.31 16:05:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\AVG9
[2009.12.03 14:38:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\BinarySense
[2010.04.15 17:45:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\Bioshock
[2008.05.23 21:41:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\Canon
[2009.01.13 14:25:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\DAEMON Tools
[2009.05.30 11:07:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\DAEMON Tools Lite
[2009.01.13 14:25:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\DAEMON Tools Pro
[2009.10.26 15:26:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\GetRightToGo
[2011.03.12 20:46:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\ICQ
[2008.09.14 15:28:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\ICQLite
[2011.02.22 23:27:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\Kalypso Media
[2008.08.25 20:30:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\LaxiusForce
[2008.08.31 16:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\Leadertech
[2010.10.01 15:58:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\Meltdown
[2010.01.07 20:23:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\Music Recognition
[2009.01.15 17:35:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\neuroLanguage
[2008.05.23 21:28:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\ScanSoft
[2011.03.11 17:42:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\TuneUp Software
[2011.03.13 09:29:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\uTorrent
[2010.07.15 16:34:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\gottfried\Data aplikací\yang
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* >[2008.08.30 20:10:08 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.112
[2009.12.20 09:25:40 | 000,000,223 | -HS- | M] () -- C:\boot.ini
[2007.10.29 13:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2008.08.30 20:10:08 | 000,000,000 | ---- | M] () -- C:\CONFIG.112
[2008.05.20 14:25:58 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2008.05.20 14:59:06 | 000,000,086 | ---- | M] () -- C:\csb.log
[2009.06.16 15:48:03 | 000,000,017 | ---- | M] () -- C:\gputest.txt
[2008.05.20 14:25:58 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2008.05.20 14:25:58 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2007.10.29 13:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008.12.17 16:11:05 | 000,250,576 | RHS- | M] () -- C:\ntldr
[2008.07.05 17:18:52 | 060,950,631 | ---- | M] () -- C:\Osprey (Warrior no11) - English Longbowman 1330-1515.pdf
[2011.03.13 09:28:36 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2008.05.20 14:57:03 | 000,000,581 | ---- | M] () -- C:\RHDSetup.log
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav >[2009.12.20 10:11:22 | 004,194,304 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009.12.20 08:57:37 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2009.12.20 10:11:22 | 028,835,840 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009.12.20 10:11:22 | 004,718,592 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >[2011.01.27 00:34:30 | 006,406,656 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\ati2mtag.sys
[2010.12.20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys
[2010.12.20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
========== Alternate Data Streams ========== @Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2E05F719
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:B2E5F50D
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:2BE9FEFC
< End of report >