OK, neinstaluju. Našla jsem si jeste removery Nortna a Avasta, tak si něco odnesly. Pak jsem ještě zkusila dát výchozí nastavení FW, ale žádný rozdíl, ona funguje jak kdy, i bez AV.
Jak jsem smázla tu složku zavirovaný karantény od Nortona Unlockerem (nešla normálně), tak ted nejde smazat ani z koše, vždy si vytvoří novou kopii s jiným jmenem, Dc56, Dc59...Přitom se hlásí jako prázdná... Nemuze to bejt vir a jak s tim pryc?
- combofix odinstalováno
- vyčištěno obouma
- první instalaci CrystalDiskInfo přerušila BSOD
- OTL se v normálním režimu pokaždý zaseklo, takze nouzak... a přeju přájemný počteníčko :-) (nezávidím) a dík za čas :-)
----------------------------------------------------------------------------
CrystalDiskInfo 4.0.1 (C) 2008-2011 hiyohiyo
Crystal Dew World :
http://crystalmark.info/----------------------------------------------------------------------------
OS : Windows XP Professional SP3 [5.1 Build 2600] (x86)
Date : 2011/06/06 20:38:17
-- Controller Map ----------------------------------------------------------
+ Intel(R) ICH8M Ultra ATA Storage Controllers - 2850 [ATA]
+ Primární kanál IDE (0)
- HL-DT-ST DVDRAM GSA-T20N
- Sekundární kanál IDE (1)
+ Intel(R) 82801HEM/HBM SATA AHCI Controller [ATA]
- Hitachi HTS541680J9SA00
-- Disk List ---------------------------------------------------------------
(1) Hitachi HTS541680J9SA00 : 80.0 GB [0-1-0, pd1]
----------------------------------------------------------------------------
(1) Hitachi HTS541680J9SA00
----------------------------------------------------------------------------
Model : Hitachi HTS541680J9SA00
Firmware : SB2OC70P
Serial Number : SB2241KGE60BUE
Disk Size : 80.0 GB (8.4/80.0/80.0)
Buffer Size : 7516 KB
Queue Depth : 32
# of Sectors : 156301488
Rotation Rate : Neznámy údaj
Interface : Serial ATA
Major Version : ATA/ATAPI-7
Minor Version : ATA/ATAPI-7 T13 1532D version 1
Transfer Mode : SATA/150
Power On Hours : 13688 hod.
Power On Count : 2047 krát
Temparature : 47 C (116 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, AAM, 48bit LBA, NCQ
APM Level : 4080h [ON]
AAM Level : 80FEh [OFF]
-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _62 000000000000 Počet chyb čtení
02 100 100 _40 000000000000 Průchodnost disku
03 253 253 _33 000E00000001 Čas na roztočení ploten
04 _99 _99 __0 000000000873 Počet spuštění/zastavení
05 100 100 __5 000000000000 Počet přemapovaných sektorů
07 100 100 _67 000000000000 Počet chybných hledání
08 100 100 _40 000000000000 Čas potřebný na vyhledání
09 _69 _69 __0 000000003578 Hodin v činnosti
0A 100 100 _60 000000000000 Počet opakovaných pokusů o roztočení ploten
0C _99 _99 __0 0000000007FF Počet cyklů zapnutí zařízení
BF 100 100 __0 000000000000 Počet udalostí zaznamenaných otřesovým senzorem
C0 100 100 __0 000000000036 Počet vypnutí disku
C1 _82 _82 __0 00000002DA57 Počet cyklů načítání/vymazání
C2 117 117 __0 0035000E002F Teplota
C4 100 100 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 100 100 __0 000000000000 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 200 253 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
DF 100 100 __0 000000000000 Zatížení budiče magnetických hlav způsobené opakovanými úkony
-- IDENTIFY_DEVICE ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 04 5A 3F FF C8 37 00 10 00 00 00 00 00 3F 00 00
010: 00 00 00 00 20 20 20 20 20 20 53 42 32 32 34 31
020: 4B 47 45 36 30 42 55 45 00 03 3A B8 00 04 53 42
030: 32 4F 43 37 30 50 48 69 74 61 63 68 69 20 48 54
040: 53 35 34 31 36 38 30 4A 39 53 41 30 30 20 20 20
050: 20 20 20 20 20 20 20 20 20 20 20 20 20 20 80 10
060: 00 00 0F 00 40 00 02 00 02 00 00 07 3F FF 00 10
070: 00 3F FC 10 00 FB 01 10 F8 B0 09 50 00 00 00 07
080: 00 03 00 78 00 78 00 78 00 78 00 00 00 00 00 00
090: 00 00 00 00 00 00 00 1F 07 02 00 00 00 5E 00 4C
0A0: 00 FC 00 1A 74 6B 7F 69 61 63 74 69 3C 49 61 63
0B0: 20 3F 00 15 00 00 40 80 FF FE 00 00 80 FE 00 00
0C0: 00 00 00 00 00 00 00 00 F8 B0 09 50 00 00 00 00
0D0: 00 00 00 00 00 00 88 48 50 00 CC A5 51 DE EA AA
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00
0F0: 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 09 00 0B 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 40 01 00 00 80 00 00 00
130: 32 4A 00 00 00 00 42 51 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 80 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 9E A5
OTL logfile created on: 8.6.2011 7:03:51 - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Ester\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
502,36 Mb Total Physical Memory | 326,50 Mb Available Physical Memory | 64,99% Memory free
1,44 Gb Paging File | 1,35 Gb Available in Paging File | 94,25% Paging File free
Paging file location(s): C:\pagefile.sys 1000 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34,08 Gb Total Space | 19,09 Gb Free Space | 56,00% Space Free | Partition Type: NTFS
Drive D: | 34,58 Gb Total Space | 5,98 Gb Free Space | 17,30% Space Free | Partition Type: FAT32
Computer Name: ACER-109CD108E4 | User Name: Ester | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011.06.07 07:31:35 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ester\Plocha\OTL.exe
PRC - [2011.06.06 19:58:13 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ester\Plocha\OTH.scr
========== Modules (SafeList) ========== MOD - [2011.06.07 07:31:35 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ester\Plocha\OTL.exe
MOD - [2011.01.11 10:59:44 | 000,653,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcr90.dll
MOD - [2011.01.11 10:59:44 | 000,569,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.5570_x-ww_0517bbc6\msvcp90.dll
MOD - [2010.11.15 21:02:22 | 000,390,552 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.dll
MOD - [2010.10.23 02:47:27 | 001,748,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\GdiPlus.dll
MOD - [2010.08.23 18:12:33 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2010.02.16 17:03:24 | 000,398,848 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
MOD - [2010.02.15 13:27:12 | 000,597,504 | ---- | M] (STLport Consulting, Inc.) -- C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\stlport_vc7145.dll
MOD - [2008.04.14 05:21:51 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\netui1.dll
MOD - [2008.04.14 05:21:51 | 000,141,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\nwprovau.dll
MOD - [2008.04.14 05:21:51 | 000,080,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\netui0.dll
MOD - [2008.04.14 05:21:51 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntlanman.dll
MOD - [2008.04.14 05:21:50 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\netrap.dll
MOD - [2008.04.14 05:21:46 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msacm32.dll
MOD - [2008.04.14 05:21:39 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\davclnt.dll
MOD - [2008.04.14 05:21:39 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drprov.dll
MOD - [2008.04.14 05:21:36 | 001,852,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\AppPatch\acgenral.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011.03.01 09:56:36 | 000,052,288 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus(R)
SRV - [2007.03.21 13:00:04 | 000,355,096 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2005.07.08 17:24:46 | 000,871,424 | ---- | M] (Nero AG) [Auto | Stopped] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
========== Driver Services (SafeList) ========== DRV - [2011.05.14 15:15:13 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2008.04.13 20:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008.04.13 20:46:22 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE)
DRV - [2007.05.30 20:04:56 | 004,424,192 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.05.02 03:52:00 | 000,290,816 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2007.02.16 15:46:00 | 000,160,256 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2006.12.22 20:56:44 | 000,988,800 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2006.12.22 20:56:00 | 000,209,664 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2006.12.22 20:55:56 | 000,730,112 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2006.10.13 00:28:42 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2005.07.08 17:17:54 | 000,099,584 | ---- | M] (Nero AG) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005.07.08 17:17:36 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2005.07.08 17:17:31 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)
DRV - [2005.01.13 15:46:16 | 000,069,632 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15.sys)
DRV - [2004.08.18 05:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2004.08.18 05:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://start.icq.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://start.icq.com/"
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5
FF - prefs.js..extensions.enabledItems:
personas@christopher.beard:1.5.3
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.6.0
FF - prefs.js..extensions.enabledItems:
wrc@avast.com:20110101
FF - prefs.js..extensions.enabledItems:
engine@conduit.com:3.3.2.1
FF - prefs.js..extensions.enabledItems: {942cd1d4-9cc1-4d31-876a-ea8f489f7a59}:3.3.2.1
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q="
[2008.12.21 08:25:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Extensions
[2011.05.22 07:48:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\extensions
[2011.05.15 14:06:33 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-1.xml
[2010.02.19 07:29:08 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-10.xml
[2010.03.28 02:58:07 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-11.xml
[2010.04.03 15:12:59 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-12.xml
[2010.05.04 11:26:17 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-13.xml
[2011.01.06 21:32:20 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-14.xml
[2008.03.31 09:52:00 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-15.xml
[2011.03.27 01:58:48 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-16.xml
[2011.03.27 02:11:07 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-17.xml
[2008.12.21 05:45:51 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-2.xml
[2008.12.21 08:26:16 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-3.xml
[2009.05.04 23:08:11 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-4.xml
[2009.10.17 14:09:15 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-5.xml
[2009.10.17 15:38:52 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-6.xml
[2009.11.22 04:14:14 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-7.xml
[2009.12.18 01:24:36 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-8.xml
[2010.01.24 12:28:24 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin-9.xml
[2011.05.05 14:03:46 | 000,000,168 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin.gif
[2011.05.05 14:03:46 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin.src
[2011.03.30 15:14:34 | 000,001,042 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\icqplugin.xml
[2008.06.22 22:13:22 | 000,000,656 | ---- | M] () -- C:\Documents and Settings\Ester\Data aplikací\Mozilla\Firefox\Profiles\sgetugha.default\searchplugins\yahoo.xml
File not found (No name found) --
[2011.04.10 14:51:44 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
O1 HOSTS File: ([2011.06.02 23:30:41 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll (HiTRUST)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll (HiTRUST)
O4 - HKLM..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe ()
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe (HiTRUST)
O4 - HKLM..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe ()
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [preload] C:\WINDOWS\RunXMLPL.exe (Wistron Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer Empowering Technology.lnk = C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe (Acer Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to &Evernote - C:\Program Files\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Místní intranet)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microso ... 7808216734 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Ester\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ester\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Unable to start service SrService!
========== Files/Folders - Created Within 30 Days ========== [2011.06.07 07:31:47 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ester\Plocha\OTL.exe
[2011.06.06 20:19:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2011.06.06 20:18:41 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
[2011.06.06 20:18:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Real
[2011.06.06 20:18:30 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2011.06.06 20:18:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Real
[2011.06.06 20:18:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Data aplikací\Real
[2011.06.06 20:16:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Local Settings\Data aplikací\OpenCandy
[2011.06.06 20:16:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Data aplikací\OpenCandy
[2011.06.06 20:16:55 | 000,000,000 | ---D | C] -- C:\Program Files\CrystalDiskInfo
[2011.06.06 20:16:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\CrystalDiskInfo
[2011.06.06 19:58:21 | 000,258,560 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ester\Plocha\OTH.scr
[2011.06.05 15:57:19 | 000,306,736 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Ester\Plocha\aswclear.exe
[2011.06.05 15:14:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Norton
[2011.06.05 15:13:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Local Settings\Data aplikací\NPE
[2011.06.05 14:52:32 | 006,141,880 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Ester\Plocha\NPE.exe
[2011.06.05 05:29:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Data aplikací\HD Tune Pro
[2011.06.05 05:29:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\HD Tune Pro
[2011.06.05 05:29:25 | 000,000,000 | ---D | C] -- C:\Program Files\HD Tune Pro
[2011.06.04 23:48:54 | 000,000,000 | ---D | C] -- C:\Program Files\Unlocker
[2011.06.04 23:48:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Nabídka Start\Programy\Unlocker
[2011.06.04 21:33:30 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011.06.04 21:32:38 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ester\Recent
[2011.06.02 23:26:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011.05.30 21:08:09 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011.05.30 19:28:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011.05.29 15:05:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Data aplikací\Malwarebytes
[2011.05.29 15:05:34 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.05.29 15:05:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
[2011.05.29 15:05:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.05.29 15:05:28 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.05.29 15:05:27 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.05.28 19:22:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2011.05.25 11:53:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Skype Extras
[2011.05.25 11:53:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2011.05.25 11:53:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Skype
[2011.05.24 12:16:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\DoctorWeb
[2011.05.23 01:01:22 | 000,045,056 | ---- | C] (Acer Labs USA) -- C:\WINDOWS\System32\Epm-Po.dll
[2011.05.22 18:55:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\IObit
[2011.05.22 13:48:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Data aplikací\IObit
[2011.05.22 13:48:31 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2011.05.22 12:55:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\HijackThis
[2011.05.22 12:55:33 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011.05.22 12:05:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
[2011.05.22 12:05:34 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.05.22 11:24:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Dokumenty\CyberLink
[2011.05.22 09:50:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Uniblue
[2011.05.22 09:50:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Data aplikací\Uniblue
[2011.05.22 09:42:23 | 000,023,456 | ---- | C] (Phoenix Technologies) -- C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2011.05.22 09:42:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Local Settings\Data aplikací\eSupport.com
[2011.05.22 09:01:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Local Settings\Data aplikací\PackageAware
[2011.05.21 01:15:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Dokumenty\iobit_toolbox_1,2
[2011.05.17 20:28:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ester\Nabídka Start\Programy\NirSoft BlueScreenView
[2011.05.17 20:28:22 | 000,000,000 | ---D | C] -- C:\Program Files\NirSoft
[2008.02.02 03:42:00 | 000,016,384 | ---- | C] ( ) -- C:\WINDOWS\System32\ClearEvent.exe
[2008.02.02 03:39:19 | 000,049,152 | ---- | C] ( ) -- C:\WINDOWS\System32\SysMonitor.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011.06.08 06:57:20 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.06.08 06:56:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.06.08 06:53:42 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc04f064f0bce4.job
[2011.06.07 21:23:11 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.06.07 18:19:47 | 000,002,539 | ---- | M] () -- C:\Documents and Settings\Ester\Plocha\Microsoft Word.lnk
[2011.06.07 17:41:00 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{8FDA357B-9004-4B4C-91DA-E15FEFCEFBDF}.job
[2011.06.07 17:38:47 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1871938407-2727508527-3954083314-1008.job
[2011.06.07 17:37:00 | 000,000,460 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{DF03FE93-B93A-401F-99D3-3A5550EE3C8F}.job
[2011.06.07 08:04:53 | 000,492,770 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.06.07 08:04:53 | 000,489,572 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2011.06.07 08:04:53 | 000,102,612 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2011.06.07 08:04:53 | 000,090,790 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.06.07 07:31:35 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ester\Plocha\OTL.exe
[2011.06.06 20:19:56 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1871938407-2727508527-3954083314-1008.job
[2011.06.06 20:19:25 | 000,001,605 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Free Offers.lnk
[2011.06.06 20:19:25 | 000,000,933 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\RealPlayer.lnk
[2011.06.06 20:18:41 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
[2011.06.06 20:16:56 | 000,001,647 | ---- | M] () -- C:\Documents and Settings\Ester\Plocha\CrystalDiskInfo.lnk
[2011.06.06 19:58:13 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ester\Plocha\OTH.scr
[2011.06.05 17:35:20 | 000,000,788 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.06.05 16:32:32 | 000,002,504 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011.06.05 15:57:20 | 000,306,736 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Ester\Plocha\aswclear.exe
[2011.06.05 15:19:23 | 000,000,328 | RHS- | M] () -- C:\boot.ini
[2011.06.05 15:03:45 | 000,932,400 | ---- | M] () -- C:\Documents and Settings\Ester\Plocha\Norton_Removal_Tool.exe
[2011.06.05 14:52:41 | 006,141,880 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Ester\Plocha\NPE.exe
[2011.06.05 05:29:26 | 000,000,712 | ---- | M] () -- C:\Documents and Settings\Ester\Plocha\HD Tune Pro.lnk
[2011.06.02 23:30:41 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011.06.02 22:34:20 | 000,000,686 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[2011.05.30 21:40:59 | 000,000,426 | ---- | M] () -- C:\Documents and Settings\Ester\Plocha\Zástupce - Systém.lnk
[2011.05.29 21:16:27 | 000,434,065 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110529-211858.backup
[2011.05.29 21:13:11 | 000,434,065 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110529-211627.backup
[2011.05.29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.05.29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.05.28 14:26:48 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2011.05.24 13:09:05 | 000,000,789 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110529-211311.backup
[2011.05.23 04:19:25 | 000,000,212 | ---- | M] () -- C:\Boot.bak
[2011.05.23 01:06:20 | 000,283,729 | ---- | M] () -- C:\WINDOWS\System32\setup.inx
[2011.05.23 00:56:13 | 000,001,573 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Empowering Technology.lnk
[2011.05.22 12:55:34 | 000,001,738 | ---- | M] () -- C:\Documents and Settings\Ester\Plocha\HijackThis.lnk
[2011.05.22 11:15:29 | 000,001,762 | ---- | M] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer Empowering Technology.lnk
[2011.05.22 09:49:18 | 000,080,147 | ---- | M] () -- C:\Documents and Settings\Ester\Plocha\DriverAgent_scan_results.mhtml
[2011.05.22 09:42:25 | 000,001,045 | ---- | M] () -- C:\Documents and Settings\Ester\Plocha\Find Drivers with DriverAgent.lnk
[2011.05.22 08:19:23 | 000,001,097 | ---- | M] () -- C:\Documents and Settings\Ester\Plocha\BlueScreenView.lnk
[2011.05.22 02:03:28 | 000,000,189 | ---- | M] () -- C:\Documents and Settings\Ester\Plocha\Zástupce - ADATA SH93 (F).lnk
[2011.05.21 01:15:59 | 000,000,698 | ---- | M] () -- C:\Documents and Settings\Ester\Plocha\Zástupce - Toolbox.exe.lnk
[2011.05.16 18:23:04 | 000,000,783 | ---- | M] () -- C:\WINDOWS\NTIWVEDT.INI
[2011.05.15 17:55:42 | 000,874,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110517-181435.backup
[2011.05.14 15:15:13 | 000,023,456 | ---- | M] (Phoenix Technologies) -- C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2011.05.13 00:44:52 | 000,874,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110515-175542.backup
[2011.05.12 23:20:07 | 000,874,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110513-004452.backup
[2011.05.12 23:18:28 | 000,874,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110512-232007.backup
[2011.05.12 23:17:45 | 000,874,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110512-231828.backup
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ========== [2011.06.08 06:53:42 | 000,000,936 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc04f064f0bce4.job
[2011.06.06 20:19:56 | 000,000,278 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1871938407-2727508527-3954083314-1008.job
[2011.06.06 20:19:55 | 000,000,286 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1871938407-2727508527-3954083314-1008.job
[2011.06.06 20:19:25 | 000,001,605 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Free Offers.lnk
[2011.06.06 20:19:25 | 000,000,933 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\RealPlayer.lnk
[2011.06.06 20:16:56 | 000,001,647 | ---- | C] () -- C:\Documents and Settings\Ester\Plocha\CrystalDiskInfo.lnk
[2011.06.05 15:03:44 | 000,932,400 | ---- | C] () -- C:\Documents and Settings\Ester\Plocha\Norton_Removal_Tool.exe
[2011.06.05 05:29:26 | 000,000,712 | ---- | C] () -- C:\Documents and Settings\Ester\Plocha\HD Tune Pro.lnk
[2011.05.30 21:40:59 | 000,000,426 | ---- | C] () -- C:\Documents and Settings\Ester\Plocha\Zástupce - Systém.lnk
[2011.05.30 21:08:14 | 000,000,212 | ---- | C] () -- C:\Boot.bak
[2011.05.30 21:08:10 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2011.05.29 20:23:44 | 000,204,800 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4837.dll
[2011.05.29 18:39:53 | 000,910,464 | R--- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2011.05.29 18:39:53 | 000,026,320 | R--- | C] () -- C:\WINDOWS\System32\igxpxs32.vp
[2011.05.29 18:39:53 | 000,002,096 | R--- | C] () -- C:\WINDOWS\System32\igxpxk32.vp
[2011.05.29 15:05:34 | 000,000,788 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.05.23 04:19:27 | 000,001,762 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer Empowering Technology.lnk
[2011.05.23 01:07:13 | 000,283,729 | ---- | C] () -- C:\WINDOWS\System32\setup.inx
[2011.05.23 00:56:13 | 000,001,573 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Empowering Technology.lnk
[2011.05.22 12:55:34 | 000,001,738 | ---- | C] () -- C:\Documents and Settings\Ester\Plocha\HijackThis.lnk
[2011.05.22 12:05:35 | 000,000,686 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[2011.05.22 09:49:16 | 000,080,147 | ---- | C] () -- C:\Documents and Settings\Ester\Plocha\DriverAgent_scan_results.mhtml
[2011.05.22 09:42:25 | 000,001,045 | ---- | C] () -- C:\Documents and Settings\Ester\Plocha\Find Drivers with DriverAgent.lnk
[2011.05.22 08:19:23 | 000,001,097 | ---- | C] () -- C:\Documents and Settings\Ester\Plocha\BlueScreenView.lnk
[2011.05.22 02:03:28 | 000,000,189 | ---- | C] () -- C:\Documents and Settings\Ester\Plocha\Zástupce - ADATA SH93 (F).lnk
[2011.05.21 01:15:59 | 000,000,698 | ---- | C] () -- C:\Documents and Settings\Ester\Plocha\Zástupce - Toolbox.exe.lnk
[2011.05.06 01:28:26 | 000,000,032 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsidmv.dat
[2011.03.16 20:43:28 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2011.02.05 01:41:51 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011.01.30 20:30:35 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\N360BUOptions.ini
[2011.01.25 17:36:53 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2011.01.07 00:26:39 | 001,189,496 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2010.11.20 18:57:54 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\igfxtvcx.dll
[2010.07.25 12:58:40 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.07.24 23:58:37 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010.07.24 21:50:51 | 000,000,361 | ---- | C] () -- C:\WINDOWS\lgfwup.ini
[2010.07.24 21:32:07 | 000,040,960 | ---- | C] () -- C:\Program Files\Uninstall_CDS.exe
[2010.03.07 19:43:41 | 000,057,936 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010.01.24 18:15:39 | 000,000,082 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008.05.25 11:17:21 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008.04.13 13:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Jcmkr32.INI
[2008.03.24 02:53:25 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ImageItEncrypt.exe
[2008.03.22 01:05:18 | 000,001,492 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2008.03.16 17:27:02 | 000,000,783 | ---- | C] () -- C:\WINDOWS\NTIWVEDT.INI
[2008.03.13 20:58:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\graphedit.INI
[2008.03.12 16:51:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008.03.01 13:59:26 | 000,000,188 | ---- | C] () -- C:\WINDOWS\System32\eDataSecurity.dat
[2008.02.16 17:44:59 | 000,000,761 | ---- | C] () -- C:\WINDOWS\m3jp2k.ini
[2008.02.16 17:44:59 | 000,000,702 | ---- | C] () -- C:\WINDOWS\mmtvmj.ini
[2008.02.16 17:44:58 | 000,000,714 | ---- | C] () -- C:\WINDOWS\m3jpeg.ini
[2008.02.16 17:44:54 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2008.02.16 17:44:52 | 000,152,064 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008.02.09 21:02:18 | 000,028,160 | ---- | C] () -- C:\Documents and Settings\Ester\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.02.02 21:15:48 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008.02.02 12:27:48 | 000,000,037 | ---- | C] () -- C:\WINDOWS\PreLaunch.ini
[2008.02.02 03:34:45 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\Ester\Local Settings\Data aplikací\fusioncache.dat
[2008.01.18 00:33:12 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\APISlice.dll
[2008.01.18 00:32:30 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\InstallCheck.dll
[2008.01.15 18:33:14 | 001,504,768 | ---- | C] () -- C:\WINDOWS\System32\UIVCL.dll
[2007.08.14 09:09:38 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2007.08.14 09:09:10 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007.08.14 08:53:20 | 000,492,770 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2007.08.14 08:53:20 | 000,489,572 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2007.08.14 08:53:20 | 000,102,612 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2007.08.14 08:53:20 | 000,090,790 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2007.08.14 08:48:34 | 000,288,496 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007.08.14 08:10:04 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIBUN4.dll
[2007.08.14 08:09:32 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMPEG2.dll
[2007.08.14 08:09:32 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMP3.dll
[2007.08.14 08:09:32 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTICDMK7.dll
[2007.04.26 20:54:14 | 000,071,680 | ---- | C] () -- C:\WINDOWS\System32\HTCA_SelfExtract.bin
[2006.08.28 19:30:04 | 000,013,952 | ---- | C] () -- C:\WINDOWS\System32\drivers\UBHelper.sys
[2006.08.01 15:02:32 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2006.07.24 13:33:30 | 000,003,218 | ---- | C] () -- C:\WINDOWS\System32\drivers\WINIO.sys
[2006.03.10 14:18:16 | 000,036,404 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004.10.15 08:46:18 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004.10.15 08:43:46 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004.08.18 05:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004.08.18 05:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004.08.18 05:00:00 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2004.08.18 05:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004.08.18 05:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004.08.18 05:00:00 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2004.08.18 05:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004.08.18 05:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004.08.18 05:00:00 | 000,003,568 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004.08.18 05:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004.08.18 05:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004.05.14 13:04:36 | 000,049,152 | ---- | C] () -- C:\WINDOWS\XMLaunch.exe
[2003.11.24 15:55:48 | 000,743,424 | ---- | C] () -- C:\WINDOWS\libxml2.dll
[2003.11.24 15:55:32 | 000,872,448 | ---- | C] () -- C:\WINDOWS\iconv.dll
[2002.09.12 22:41:26 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2002.09.12 22:41:26 | 000,004,524 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.12.26 16:12:30 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll
[2001.09.03 23:46:38 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\Hmpg12.dll
[2001.07.30 16:33:56 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll
[2001.07.23 22:04:36 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
========== LOP Check ========== [2011.06.04 20:55:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2010.11.21 03:25:48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2011.05.05 14:03:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2011.05.22 18:55:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IObit
[2008.04.13 13:04:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\LightScribe
[2011.01.08 20:14:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2010.07.25 01:47:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NtiDvdCopy
[2011.05.03 03:38:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2008.02.02 12:21:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[2010.04.07 21:06:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010.03.07 17:36:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011.05.15 20:07:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ester\Data aplikací\EssentialPIM
[2011.06.05 05:29:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ester\Data aplikací\HD Tune Pro
[2011.05.22 06:46:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ester\Data aplikací\ICQ
[2008.07.12 18:54:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ester\Data aplikací\ICQ Toolbar
[2010.07.24 21:44:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ester\Data aplikací\InterTrust
[2011.05.22 13:48:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ester\Data aplikací\IObit
[2011.05.03 03:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ester\Data aplikací\langmaster.sz
[2011.06.06 20:16:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ester\Data aplikací\OpenCandy
[2010.03.05 11:17:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ester\Data aplikací\OpenOffice.org
[2010.12.30 16:05:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ester\Data aplikací\Tific
[2011.05.22 10:10:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ester\Data aplikací\Uniblue
[2011.06.07 17:41:00 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{8FDA357B-9004-4B4C-91DA-E15FEFCEFBDF}.job
[2011.06.07 17:37:00 | 000,000,460 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{DF03FE93-B93A-401F-99D3-3A5550EE3C8F}.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* >[2008.03.12 17:59:25 | 000,000,036 | RHS- | M] () -- C:\.uid_xxx
[2011.05.23 04:19:25 | 000,000,212 | ---- | M] () -- C:\Boot.bak
[2011.06.05 15:19:23 | 000,000,328 | RHS- | M] () -- C:\boot.ini
[2004.08.18 05:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2004.10.15 08:26:46 | 000,000,512 | -HS- | M] () -- C:\BOOTSECT.DOS
[2004.08.03 23:00:04 | 000,261,312 | RHS- | M] () -- C:\cmldr
[2011.06.04 21:05:30 | 000,000,114 | ---- | M] () -- C:\delrepxp.log
[2008.03.02 07:27:30 | 115,343,872 | -HS- | M] () -- C:\eDS_PSD_drive.vmdf
[2004.10.15 08:46:40 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2008.03.24 06:02:55 | 000,000,007 | ---- | M] () -- C:\ISACER.id
[2004.10.15 08:46:40 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004.08.18 05:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009.02.22 08:31:43 | 000,250,576 | RHS- | M] () -- C:\ntldr
[2011.06.08 06:56:43 | 1048,576,000 | -HS- | M] () -- C:\pagefile.sys
[2007.10.25 06:52:52 | 000,003,179 | -HS- | M] () -- C:\Patch.rev
[2007.04.26 08:45:58 | 000,000,631 | ---- | M] () -- C:\PDVD.iss
[2007.08.14 18:16:26 | 000,000,072 | RHS- | M] () -- C:\preload.aaa
[2007.08.14 18:16:26 | 000,000,072 | RHS- | M] () -- C:\Preload.rev
[2007.08.14 07:49:18 | 000,000,004 | ---- | M] () -- C:\wps.dat
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav >[2004.10.15 08:37:06 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004.10.15 08:37:06 | 000,663,552 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004.10.15 08:37:06 | 000,471,040 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >[2011.05.14 15:15:13 | 000,023,456 | ---- | M] (Phoenix Technologies) -- C:\WINDOWS\system32\drivers\DrvAgent32.sys
[2011.05.29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys
[2011.05.29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
========== Alternate Data Streams ========== @Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D724DE2C
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
< End of report >