Zdravim,
poprosim o kotrolu logu, notebook sa mi v posledych dnoch zacal vyrazne spomalovat.. System zahlcuje ram, po starte systemu byva vyuzitie pamate 70-80% , to sa s casom este stupnuje az je praca na notebooku nemozna. System som presiel NOD-om, Spybotom a Malwarebytes, po skenoch som odstranil nejake drobnosti ktore z mojho pohladu dany problem nevytvarali. Taktiez pravidelne pouzivam CCleaner. Sam si uz dalej neviem rady.
Vopred dakujem za pripadnu pomoc.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:31:39, on 20. 9. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\PROGRA~1\DUMETE~1\DUMeter.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\vsnp2uvc.exe
C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\Program Files\Compal\Smart Battery\SMBTray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Razer\DeathAdder\razertra.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKLM\..\Run: [Wow Video&Audio] C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SMBTray] C:\Program Files\Compal\Smart Battery\SMBTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKCU\..\Run: [Thunderbird] "C:\Program Files\Mozilla Thunderbird\thunderbird" -turbo
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010 JadrisPack\qip.exe" /nosrv /isolated /smiles 40 /autorun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd. - C:\Program Files\DU Meter\DUMeterSvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
--
End of file - 4921 bytes
taktiez pridavam log z programu ComboFix :
ComboFix 10-09-20.01 - DANIK . 09. 2010 22:34:31.2.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1029.18.1022.347 [GMT 2:00]
Running from: c:\users\DANIK\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2010-08-20 to 2010-09-20 )))))))))))))))))))))))))))))))
.
2010-09-20 20:40 . 2010-09-20 20:40 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-20 20:40 . 2010-09-20 20:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-20 20:04 . 2010-09-20 20:04 388096 ----a-r- c:\users\DANIK\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-20 20:04 . 2010-09-20 20:04 -------- d-----w- c:\program files\Trend Micro
2010-09-20 19:46 . 2010-09-20 20:40 -------- d-----w- c:\users\DANIK\AppData\Local\temp
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\users\DANIK\AppData\Roaming\Malwarebytes
2010-09-19 22:00 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\programdata\Malwarebytes
2010-09-19 22:00 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-19 21:01 . 2010-09-20 17:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-19 21:01 . 2010-09-19 21:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-19 18:06 . 2010-09-19 18:06 -------- d-----w- c:\users\DANIK\AppData\Local\Opera
2010-09-19 18:05 . 2010-09-19 18:05 -------- d-----w- c:\program files\Opera
2010-09-19 15:01 . 2010-09-20 13:58 -------- d-----w- c:\users\DANIK\AppData\Roaming\vlc
2010-09-19 10:35 . 2010-09-19 10:36 -------- d-----w- c:\program files\uTorrent
2010-09-19 10:34 . 2010-09-19 10:50 -------- d-----w- c:\users\DANIK\AppData\Roaming\uTorrent
2010-09-17 11:56 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-12 16:30 . 2010-09-12 16:30 162816 ----a-w- c:\windows\system32\fmod.dll
2010-09-12 12:24 . 2010-07-24 19:24 344064 ----a-w- c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
2010-09-12 11:31 . 2009-04-30 07:53 2970112 ----a-w- c:\windows\system32\PhoenixDll.dll
2010-09-11 08:46 . 2010-09-11 08:55 -------- d-----w- c:\windows\WindowsMobile
2010-09-04 11:40 . 2010-09-04 11:40 -------- d-----w- c:\program files\Motorola
2010-09-04 11:33 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-09-04 11:33 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-09-04 11:33 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-09-03 10:49 . 2010-09-03 10:52 -------- d-----w- c:\program files\TNODUP
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\programdata\Hagel Technologies
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\program files\DU Meter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-20 19:55 . 2009-07-14 08:44 626398 ----a-w- c:\windows\system32\perfh005.dat
2010-09-20 19:55 . 2009-07-14 08:44 122978 ----a-w- c:\windows\system32\perfc005.dat
2010-09-20 15:34 . 2010-07-05 18:57 -------- d-----w- c:\program files\QIP 2010 JadrisPack
2010-09-20 08:44 . 2010-06-18 23:31 -------- d-----w- c:\program files\SpeedFan
2010-09-19 13:15 . 2010-06-20 00:40 -------- d-----w- c:\program files\CzDC-0699[C]
2010-09-17 15:57 . 2010-06-18 23:04 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-09-17 12:01 . 2010-06-19 04:37 -------- d-----w- c:\programdata\Microsoft Help
2010-09-12 15:32 . 2010-06-18 19:45 84512 ----a-w- c:\users\DANIK\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-11 08:48 . 2010-09-11 08:48 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2010-09-04 11:43 . 2010-06-19 04:38 -------- d-----w- c:\program files\Microsoft.NET
2010-09-03 13:27 . 2010-07-14 21:43 -------- d-----w- c:\program files\The KMPlayer
2010-08-07 22:52 . 2010-08-07 22:52 -------- d-----w- c:\program files\Common Files\Java
2010-08-07 22:51 . 2010-06-19 03:37 -------- d-----w- c:\program files\Java
2010-08-06 20:31 . 2010-08-06 20:30 -------- d-----w- c:\program files\qip2005pack
2010-08-01 11:38 . 2010-06-19 04:41 -------- d-----w- c:\users\DANIK\AppData\Roaming\Skype
2010-07-29 06:30 . 2010-08-12 15:40 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-12 15:40 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 03:00 . 2010-06-19 03:37 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 06:25 . 2010-09-04 11:32 978432 ----a-w- c:\windows\system32\wininet.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-09-20_19.43.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:55 . 2010-09-20 19:53 33104 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 04:55 . 2010-09-20 18:37 33104 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-06-18 22:07 . 2010-09-20 19:51 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-18 22:07 . 2010-09-20 18:39 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-06-19 05:08 . 2010-09-20 19:03 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-19 05:08 . 2010-09-20 20:00 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-19 05:08 . 2010-09-20 20:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
- 2010-06-19 05:08 . 2010-09-20 19:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
- 2010-06-19 05:08 . 2010-09-20 19:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
+ 2010-06-19 05:08 . 2010-09-20 20:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
+ 2010-06-18 22:07 . 2010-09-20 20:00 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-06-18 22:07 . 2010-09-20 19:03 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-18 22:07 . 2010-09-20 19:51 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-06-18 22:07 . 2010-09-20 18:39 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-06-18 19:45 . 2010-09-20 15:36 7030 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2786143777-1472676354-2263527552-1000_UserData.bin
+ 2010-06-18 19:45 . 2010-09-20 19:53 7030 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2786143777-1472676354-2263527552-1000_UserData.bin
- 2010-09-20 18:39 . 2010-09-20 18:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-09-20 18:39 . 2010-09-20 19:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-09-20 18:39 . 2010-09-20 18:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-09-20 18:39 . 2010-09-20 19:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:05 . 2010-09-20 19:55 618912 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2010-09-20 18:44 618912 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2010-09-20 18:44 107232 c:\windows\System32\perfc009.dat
+ 2009-07-14 02:05 . 2010-09-20 19:55 107232 c:\windows\System32\perfc009.dat
+ 2009-07-14 02:03 . 2010-09-20 20:09 6815744 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 02:03 . 2010-09-20 19:16 6815744 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2010-09-20 20:03 . 2010-09-20 20:03 1402880 c:\windows\Installer\c70bf.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Thunderbird"="c:\program files\Mozilla Thunderbird\thunderbird -turbo" [X]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2010-08-21 2931744]
"Infium"="c:\program files\QIP 2010 JadrisPack\qip.exe" [2010-06-16 5813200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-06-08 9267816]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2006-12-29 569344]
"Wow Video&Audio"="c:\program files\Compal\Wow Video&Audio\WVAMain.exe" [2007-05-03 951856]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-04-07 2145000]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"SMBTray"="c:\program files\Compal\Smart Battery\SMBTray.exe" [2007-06-04 521776]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 1466368]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 13:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-19 1343400]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-18 691696]
S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS [2007-03-14 9856]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
S2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [2010-08-21 1411616]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-04-07 133512]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-04-07 810120]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-04-07 96896]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-08-02 22784]
S3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver;c:\program files\DU Meter\DUMETR32.SYS [2010-08-19 19368]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
S3 netw5v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2010-01-13 6628352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
2010-09-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000Core.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]
2010-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000UA.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]
.
.
------- Supplementary Scan -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\
FF - prefs.js: browser.startup.homepage - chrome://fastdial/content/fastdial.html
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\users\DANIK\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
---- FIREFOX POLICIES ----
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\DUMeterSvc]
"ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-09-20 22:42:56
ComboFix-quarantined-files.txt 2010-09-20 20:42
Pre-Run: Volných bajtů: 38 395 375 616
Post-Run: Volných bajtů: 38 179 954 688
- - End Of File - - 4AA68D3DA4ADC70D368AEA52CDC2BE00
Prosim o kontrolu logu - system zahlcuje ram Vyřešeno
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43290
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosim o kontrolu logu - system zahlcuje ram
Máš používat Combofix jen na radu rádce!!
Stahni AVPtool
-nainstaluj, nech provést sken všechn jednotek
-co najde nech léčit
-pak sem vlož log.
Malwarebytes' Anti-Malware:
Spusť ho a aktualizuj.
- program se po té spustí a nech vybranou možnost Provést úplný sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Pokud budou problémy , spusť v nouz. režimu.
+
Memtest:
http://www.stahuj.centrum.cz/utility_a_ ... i/memtest/
Do políčka vlož největší velikost Tvé jednotlivé paměti RAM (256,512 nebo 1024,2048) dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
Stahni AVPtool
-nainstaluj, nech provést sken všechn jednotek
-co najde nech léčit
-pak sem vlož log.
Malwarebytes' Anti-Malware:
Spusť ho a aktualizuj.
- program se po té spustí a nech vybranou možnost Provést úplný sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.
Pokud budou problémy , spusť v nouz. režimu.
+
Memtest:
http://www.stahuj.centrum.cz/utility_a_ ... i/memtest/
Do políčka vlož největší velikost Tvé jednotlivé paměti RAM (256,512 nebo 1024,2048) dej Start , nech nejméně 2h běžet , pokud bude po 2h stále 0 errors , jsou v pořádku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosim o kontrolu logu - system zahlcuje ram
tak konecne sa mi podarilo skoncit vsetky skeny ...
AVPtool nasiel par smeti ktore som vymazal ..neskor aj TNODUP to uz ale v logu spomenute nieje ..log je rozdeleny pretoze mi vypadla elektrika pri testovani externeho disku, tak som ho testoval zvlast ..viz log

Malwarebytes taktiez nasiel nejake drobnosti ..nieco som uz vsak predtym hodil do karanteny viz screen ..neskor log z hladania.

Memtest prebehol bez chyb no zatial bol pusteny len 30min ..neskor mozem spravit dlhsi test ...
Cez noc som este obnovil win zo zalohy z pred par dni, no bez naznakv napravy .. pre pripadne zmeny sem hadzem log z HJT
Vsetky testy uvedene vyssie boli prevadzane po obnoveni zalohy. Problem so zahlcovanim stale pokracuje.
AVPtool nasiel par smeti ktore som vymazal ..neskor aj TNODUP to uz ale v logu spomenute nieje ..log je rozdeleny pretoze mi vypadla elektrika pri testovani externeho disku, tak som ho testoval zvlast ..viz log

Malwarebytes taktiez nasiel nejake drobnosti ..nieco som uz vsak predtym hodil do karanteny viz screen ..neskor log z hladania.

- Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org
Verzia databázy: 4662
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
21. 9. 2010 12:33:29
mbam-log-2010-09-21 (12-33-29).txt
Typ kontroly: Úplná kontrola (C:\|D:\|H:\|)
Objektov kontrolovaných: 281354
Uplynulý čas: 2 hod, 8 min, 41 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 3
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
H:\zaloha\! nechat e\fun programs\notor_motor.exe (Application.Joke) -> No action taken.
H:\zaloha\! nechat e\fun programs\paranoia.exe (Application.Badjoke) -> No action taken.
H:\zaloha\! nechat e\fun programs\viagra.exe (Joke.VV) -> No action taken.
Memtest prebehol bez chyb no zatial bol pusteny len 30min ..neskor mozem spravit dlhsi test ...
Cez noc som este obnovil win zo zalohy z pred par dni, no bez naznakv napravy .. pre pripadne zmeny sem hadzem log z HJT
- Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:31:43, on 21. 9. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\PROGRA~1\DUMETE~1\DUMeter.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\vsnp2uvc.exe
C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Compal\Smart Battery\SMBTray.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\QIP 2010 JadrisPack\qip.exe
C:\Program Files\Razer\DeathAdder\razertra.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKLM\..\Run: [Wow Video&Audio] C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SMBTray] C:\Program Files\Compal\Smart Battery\SMBTray.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKCU\..\Run: [Thunderbird] "C:\Program Files\Mozilla Thunderbird\thunderbird" -turbo
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010 JadrisPack\qip.exe" /nosrv /isolated /smiles 40 /autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd. - C:\Program Files\DU Meter\DUMeterSvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
--
End of file - 5467 bytes
Vsetky testy uvedene vyssie boli prevadzane po obnoveni zalohy. Problem so zahlcovanim stale pokracuje.
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43290
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosim o kontrolu logu - system zahlcuje ram
Memtest aspon 2h..
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall
Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosim o kontrolu logu - system zahlcuje ram
scan combofixu prebehol no po nom mi zacal hadzat error Daemon tools ..asi zbytocna informacia ..mam nechat combofix v pc alebo ho teraz odinstalovat ?
log:
ComboFix 10-09-20.07 - DANIK . 09. 2010 19:23:47.1.2 - x86 MINIMAL
Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1029.18.1022.565 [GMT 2:00]
Running from: c:\users\DANIK\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Config.ini
.
((((((((((((((((((((((((( Files Created from 2010-08-21 to 2010-09-21 )))))))))))))))))))))))))))))))
.
2010-09-21 13:30 . 2010-09-21 13:31 7168 ----a-w- c:\windows\system32\drivers\uti5nju4.sys
2010-09-21 08:18 . 2010-09-21 08:20 -------- d-----w- c:\programdata\Kaspersky Lab
2010-09-20 22:20 . 2010-09-20 22:20 388096 ----a-r- c:\users\DANIK\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-20 21:39 . 2010-09-20 21:39 -------- d-----w- c:\program files\tea-timer-2.1
2010-09-20 21:34 . 2010-09-20 21:43 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-20 21:30 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-20 21:30 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-20 21:30 . 2010-09-20 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-20 20:04 . 2010-09-20 20:04 -------- d-----w- c:\program files\Trend Micro
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\users\DANIK\AppData\Roaming\Malwarebytes
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\programdata\Malwarebytes
2010-09-19 21:01 . 2010-09-21 17:13 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-19 18:06 . 2010-09-19 18:06 -------- d-----w- c:\users\DANIK\AppData\Local\Opera
2010-09-19 15:01 . 2010-09-20 21:24 -------- d-----w- c:\users\DANIK\AppData\Roaming\vlc
2010-09-19 10:35 . 2010-09-19 10:36 -------- d-----w- c:\program files\uTorrent
2010-09-19 10:34 . 2010-09-19 10:50 -------- d-----w- c:\users\DANIK\AppData\Roaming\uTorrent
2010-09-17 12:00 . 2010-09-20 21:24 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-17 11:56 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-12 16:30 . 2010-09-12 16:30 162816 ----a-w- c:\windows\system32\fmod.dll
2010-09-12 12:24 . 2010-07-24 19:24 344064 ----a-w- c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
2010-09-12 11:31 . 2009-04-30 07:53 2970112 ----a-w- c:\windows\system32\PhoenixDll.dll
2010-09-11 08:46 . 2010-09-11 08:55 -------- d-----w- c:\windows\WindowsMobile
2010-09-04 11:40 . 2010-09-04 11:40 -------- d-----w- c:\program files\Motorola
2010-09-04 11:33 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-09-04 11:33 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-09-04 11:33 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-09-03 10:49 . 2010-09-21 11:45 -------- d-----w- c:\program files\TNODUP
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\programdata\Hagel Technologies
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\program files\DU Meter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-21 17:26 . 2009-07-14 08:44 626200 ----a-w- c:\windows\system32\perfh005.dat
2010-09-21 17:26 . 2009-07-14 08:44 122780 ----a-w- c:\windows\system32\perfc005.dat
2010-09-20 21:24 . 2010-06-18 23:25 -------- d-----w- c:\users\DANIK\AppData\Roaming\Winamp
2010-09-20 21:24 . 2010-06-18 23:31 -------- d-----w- c:\program files\SpeedFan
2010-09-20 21:24 . 2010-06-18 22:35 -------- d-----w- c:\users\DANIK\AppData\Roaming\GHISLER
2010-09-20 21:23 . 2010-07-05 18:57 -------- d-----w- c:\program files\QIP 2010 JadrisPack
2010-09-19 13:15 . 2010-06-20 00:40 -------- d-----w- c:\program files\CzDC-0699[C]
2010-09-17 15:57 . 2010-06-18 23:04 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-09-17 12:01 . 2010-06-19 04:37 -------- d-----w- c:\programdata\Microsoft Help
2010-09-12 15:32 . 2010-06-18 19:45 84512 ----a-w- c:\users\DANIK\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-11 08:48 . 2010-09-11 08:48 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2010-09-04 11:43 . 2010-06-19 04:38 -------- d-----w- c:\program files\Microsoft.NET
2010-09-03 13:27 . 2010-07-14 21:43 -------- d-----w- c:\program files\The KMPlayer
2010-08-07 22:52 . 2010-08-07 22:52 -------- d-----w- c:\program files\Common Files\Java
2010-08-07 22:51 . 2010-06-19 03:37 -------- d-----w- c:\program files\Java
2010-08-06 20:31 . 2010-08-06 20:30 -------- d-----w- c:\program files\qip2005pack
2010-08-01 11:38 . 2010-06-19 04:41 -------- d-----w- c:\users\DANIK\AppData\Roaming\Skype
2010-07-29 06:30 . 2010-08-12 15:40 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-12 15:40 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 03:00 . 2010-06-19 03:37 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 06:25 . 2010-09-04 11:32 978432 ----a-w- c:\windows\system32\wininet.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Thunderbird"="c:\program files\Mozilla Thunderbird\thunderbird -turbo" [X]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2010-08-21 2931744]
"Infium"="c:\program files\QIP 2010 JadrisPack\qip.exe" [2010-06-16 5813200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-06-08 9267816]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2006-12-29 569344]
"Wow Video&Audio"="c:\program files\Compal\Wow Video&Audio\WVAMain.exe" [2007-05-03 951856]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-04-07 2145000]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"SMBTray"="c:\program files\Compal\Smart Battery\SMBTray.exe" [2007-06-04 521776]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 1466368]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-06-19 23:19 136176 ----atw- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 13:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
R1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [2010-08-21 1411616]
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-04-07 133512]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-04-07 810120]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-04-07 96896]
R3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver;c:\program files\DU Meter\DUMETR32.SYS [2010-08-19 19368]
R3 netw5v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2010-01-13 6628352]
R3 uti5nju4;AVZ Kernel Driver;c:\windows\system32\Drivers\uti5nju4.sys [2010-09-21 7168]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-19 1343400]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-18 691696]
S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS [2007-03-14 9856]
S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-08-02 22784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
2010-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000Core.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]
2010-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000UA.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]
.
.
------- Supplementary Scan -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\
FF - prefs.js: browser.startup.homepage - chrome://fastdial/content/fastdial.html
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\users\DANIK\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
---- FIREFOX POLICIES ----
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-RunOnce-<NO NAME> - (no file)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DUMeterSvc]
"ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-09-21 19:29:55
ComboFix-quarantined-files.txt 2010-09-21 17:29
Pre-Run: Volných bajtů: 38 418 505 728
Post-Run: Volných bajtů: 38 208 987 136
- - End Of File - - 35B5D7E5F0DC216EA0F2FDA8AE87B7C6
log:
ComboFix 10-09-20.07 - DANIK . 09. 2010 19:23:47.1.2 - x86 MINIMAL
Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1029.18.1022.565 [GMT 2:00]
Running from: c:\users\DANIK\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Config.ini
.
((((((((((((((((((((((((( Files Created from 2010-08-21 to 2010-09-21 )))))))))))))))))))))))))))))))
.
2010-09-21 13:30 . 2010-09-21 13:31 7168 ----a-w- c:\windows\system32\drivers\uti5nju4.sys
2010-09-21 08:18 . 2010-09-21 08:20 -------- d-----w- c:\programdata\Kaspersky Lab
2010-09-20 22:20 . 2010-09-20 22:20 388096 ----a-r- c:\users\DANIK\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-20 21:39 . 2010-09-20 21:39 -------- d-----w- c:\program files\tea-timer-2.1
2010-09-20 21:34 . 2010-09-20 21:43 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-20 21:30 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-20 21:30 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-20 21:30 . 2010-09-20 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-20 20:04 . 2010-09-20 20:04 -------- d-----w- c:\program files\Trend Micro
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\users\DANIK\AppData\Roaming\Malwarebytes
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\programdata\Malwarebytes
2010-09-19 21:01 . 2010-09-21 17:13 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-19 18:06 . 2010-09-19 18:06 -------- d-----w- c:\users\DANIK\AppData\Local\Opera
2010-09-19 15:01 . 2010-09-20 21:24 -------- d-----w- c:\users\DANIK\AppData\Roaming\vlc
2010-09-19 10:35 . 2010-09-19 10:36 -------- d-----w- c:\program files\uTorrent
2010-09-19 10:34 . 2010-09-19 10:50 -------- d-----w- c:\users\DANIK\AppData\Roaming\uTorrent
2010-09-17 12:00 . 2010-09-20 21:24 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-17 11:56 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-12 16:30 . 2010-09-12 16:30 162816 ----a-w- c:\windows\system32\fmod.dll
2010-09-12 12:24 . 2010-07-24 19:24 344064 ----a-w- c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
2010-09-12 11:31 . 2009-04-30 07:53 2970112 ----a-w- c:\windows\system32\PhoenixDll.dll
2010-09-11 08:46 . 2010-09-11 08:55 -------- d-----w- c:\windows\WindowsMobile
2010-09-04 11:40 . 2010-09-04 11:40 -------- d-----w- c:\program files\Motorola
2010-09-04 11:33 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-09-04 11:33 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-09-04 11:33 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-09-03 10:49 . 2010-09-21 11:45 -------- d-----w- c:\program files\TNODUP
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\programdata\Hagel Technologies
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\program files\DU Meter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-21 17:26 . 2009-07-14 08:44 626200 ----a-w- c:\windows\system32\perfh005.dat
2010-09-21 17:26 . 2009-07-14 08:44 122780 ----a-w- c:\windows\system32\perfc005.dat
2010-09-20 21:24 . 2010-06-18 23:25 -------- d-----w- c:\users\DANIK\AppData\Roaming\Winamp
2010-09-20 21:24 . 2010-06-18 23:31 -------- d-----w- c:\program files\SpeedFan
2010-09-20 21:24 . 2010-06-18 22:35 -------- d-----w- c:\users\DANIK\AppData\Roaming\GHISLER
2010-09-20 21:23 . 2010-07-05 18:57 -------- d-----w- c:\program files\QIP 2010 JadrisPack
2010-09-19 13:15 . 2010-06-20 00:40 -------- d-----w- c:\program files\CzDC-0699[C]
2010-09-17 15:57 . 2010-06-18 23:04 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-09-17 12:01 . 2010-06-19 04:37 -------- d-----w- c:\programdata\Microsoft Help
2010-09-12 15:32 . 2010-06-18 19:45 84512 ----a-w- c:\users\DANIK\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-11 08:48 . 2010-09-11 08:48 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2010-09-04 11:43 . 2010-06-19 04:38 -------- d-----w- c:\program files\Microsoft.NET
2010-09-03 13:27 . 2010-07-14 21:43 -------- d-----w- c:\program files\The KMPlayer
2010-08-07 22:52 . 2010-08-07 22:52 -------- d-----w- c:\program files\Common Files\Java
2010-08-07 22:51 . 2010-06-19 03:37 -------- d-----w- c:\program files\Java
2010-08-06 20:31 . 2010-08-06 20:30 -------- d-----w- c:\program files\qip2005pack
2010-08-01 11:38 . 2010-06-19 04:41 -------- d-----w- c:\users\DANIK\AppData\Roaming\Skype
2010-07-29 06:30 . 2010-08-12 15:40 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-12 15:40 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 03:00 . 2010-06-19 03:37 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 06:25 . 2010-09-04 11:32 978432 ----a-w- c:\windows\system32\wininet.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Thunderbird"="c:\program files\Mozilla Thunderbird\thunderbird -turbo" [X]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2010-08-21 2931744]
"Infium"="c:\program files\QIP 2010 JadrisPack\qip.exe" [2010-06-16 5813200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-06-08 9267816]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2006-12-29 569344]
"Wow Video&Audio"="c:\program files\Compal\Wow Video&Audio\WVAMain.exe" [2007-05-03 951856]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-04-07 2145000]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"SMBTray"="c:\program files\Compal\Smart Battery\SMBTray.exe" [2007-06-04 521776]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 1466368]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-06-19 23:19 136176 ----atw- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 13:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
R1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [2010-08-21 1411616]
R2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-04-07 133512]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-04-07 810120]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-04-07 96896]
R3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver;c:\program files\DU Meter\DUMETR32.SYS [2010-08-19 19368]
R3 netw5v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2010-01-13 6628352]
R3 uti5nju4;AVZ Kernel Driver;c:\windows\system32\Drivers\uti5nju4.sys [2010-09-21 7168]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-19 1343400]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-18 691696]
S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS [2007-03-14 9856]
S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-08-02 22784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
2010-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000Core.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]
2010-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000UA.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]
.
.
------- Supplementary Scan -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\
FF - prefs.js: browser.startup.homepage - chrome://fastdial/content/fastdial.html
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\users\DANIK\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
---- FIREFOX POLICIES ----
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-RunOnce-<NO NAME> - (no file)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DUMeterSvc]
"ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-09-21 19:29:55
ComboFix-quarantined-files.txt 2010-09-21 17:29
Pre-Run: Volných bajtů: 38 418 505 728
Post-Run: Volných bajtů: 38 208 987 136
- - End Of File - - 35B5D7E5F0DC216EA0F2FDA8AE87B7C6
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43290
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosim o kontrolu logu - system zahlcuje ram
Odinstaluj AVP Tool.+AVZ ( jestli tam máš..)
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
c:\program files\DU Meter\DUMETR32.SYS
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/40 , nebo 1/40. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
KillAll::
Collect::
c:\windows\system32\drivers\uti5nju4.sys
File::
c:\windows\system32\perfh005.dat
c:\windows\system32\perfc005.dat
Driver::
uti5nju4
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT
V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému
Toto otestuj na Virustotal
c:\program files\DU Meter\DUMETR32.SYS
Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/40 , nebo 1/40. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosim o kontrolu logu - system zahlcuje ram
nasledoval som tvoj postup a tu su vysledky ...
log Combofix :
log HJT :
test na Virustotal
Result: 0 /43 (0.0%)
...vytazenie RAM-ky stale obrovske ..
log Combofix :
- ComboFix 10-09-20.07 - DANIK . 09. 2010 20:22:09.2.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1029.18.1022.236 [GMT 2:00]
Running from: c:\users\DANIK\Desktop\ComboFix.exe
Command switches used :: c:\users\DANIK\Desktop\CFScript.txt
FILE ::
"c:\windows\system32\perfc005.dat"
"c:\windows\system32\perfh005.dat"
file zipped: c:\windows\system32\drivers\uti5nju4.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\uti5nju4.sys
c:\windows\system32\perfc005.dat
c:\windows\system32\perfh005.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_UTI5NJU4
-------\Service_uti5nju4
((((((((((((((((((((((((( Files Created from 2010-08-21 to 2010-09-21 )))))))))))))))))))))))))))))))
.
2010-09-21 18:29 . 2010-09-21 18:31 -------- d-----w- c:\users\DANIK\AppData\Local\temp
2010-09-21 18:29 . 2010-09-21 18:29 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-21 18:29 . 2010-09-21 18:29 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-21 08:18 . 2010-09-21 08:20 -------- d-----w- c:\programdata\Kaspersky Lab
2010-09-20 22:20 . 2010-09-20 22:20 388096 ----a-r- c:\users\DANIK\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-20 21:39 . 2010-09-20 21:39 -------- d-----w- c:\program files\tea-timer-2.1
2010-09-20 21:34 . 2010-09-20 21:43 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-20 21:30 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-20 21:30 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-20 21:30 . 2010-09-20 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-20 20:04 . 2010-09-20 20:04 -------- d-----w- c:\program files\Trend Micro
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\users\DANIK\AppData\Roaming\Malwarebytes
2010-09-19 22:00 . 2010-09-19 22:00 -------- d-----w- c:\programdata\Malwarebytes
2010-09-19 21:01 . 2010-09-21 17:13 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-19 18:06 . 2010-09-19 18:06 -------- d-----w- c:\users\DANIK\AppData\Local\Opera
2010-09-19 15:01 . 2010-09-20 21:24 -------- d-----w- c:\users\DANIK\AppData\Roaming\vlc
2010-09-19 10:35 . 2010-09-19 10:36 -------- d-----w- c:\program files\uTorrent
2010-09-19 10:34 . 2010-09-19 10:50 -------- d-----w- c:\users\DANIK\AppData\Roaming\uTorrent
2010-09-17 12:00 . 2010-09-20 21:24 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-17 11:56 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-12 16:30 . 2010-09-12 16:30 162816 ----a-w- c:\windows\system32\fmod.dll
2010-09-12 12:24 . 2010-07-24 19:24 344064 ----a-w- c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
2010-09-12 11:31 . 2009-04-30 07:53 2970112 ----a-w- c:\windows\system32\PhoenixDll.dll
2010-09-11 08:46 . 2010-09-11 08:55 -------- d-----w- c:\windows\WindowsMobile
2010-09-04 11:40 . 2010-09-04 11:40 -------- d-----w- c:\program files\Motorola
2010-09-04 11:33 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-09-04 11:33 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll
2010-09-04 11:33 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-09-03 10:49 . 2010-09-21 11:45 -------- d-----w- c:\program files\TNODUP
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\programdata\Hagel Technologies
2010-09-01 12:36 . 2010-09-01 12:36 -------- d-----w- c:\program files\DU Meter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-20 21:24 . 2010-06-18 23:25 -------- d-----w- c:\users\DANIK\AppData\Roaming\Winamp
2010-09-20 21:24 . 2010-06-18 23:31 -------- d-----w- c:\program files\SpeedFan
2010-09-20 21:24 . 2010-06-18 22:35 -------- d-----w- c:\users\DANIK\AppData\Roaming\GHISLER
2010-09-20 21:23 . 2010-07-05 18:57 -------- d-----w- c:\program files\QIP 2010 JadrisPack
2010-09-19 13:15 . 2010-06-20 00:40 -------- d-----w- c:\program files\CzDC-0699[C]
2010-09-17 15:57 . 2010-06-18 23:04 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-09-17 12:01 . 2010-06-19 04:37 -------- d-----w- c:\programdata\Microsoft Help
2010-09-12 15:32 . 2010-06-18 19:45 84512 ----a-w- c:\users\DANIK\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-11 08:48 . 2010-09-11 08:48 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2010-09-04 11:43 . 2010-06-19 04:38 -------- d-----w- c:\program files\Microsoft.NET
2010-09-03 13:27 . 2010-07-14 21:43 -------- d-----w- c:\program files\The KMPlayer
2010-08-07 22:52 . 2010-08-07 22:52 -------- d-----w- c:\program files\Common Files\Java
2010-08-07 22:51 . 2010-06-19 03:37 -------- d-----w- c:\program files\Java
2010-08-06 20:31 . 2010-08-06 20:30 -------- d-----w- c:\program files\qip2005pack
2010-08-01 11:38 . 2010-06-19 04:41 -------- d-----w- c:\users\DANIK\AppData\Roaming\Skype
2010-07-29 06:30 . 2010-08-12 15:40 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-12 15:40 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 03:00 . 2010-06-19 03:37 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 06:25 . 2010-09-04 11:32 978432 ----a-w- c:\windows\system32\wininet.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-09-21_17.28.18 )))))))))))))))))))))))))))))))))))))))))
.
- 2010-06-18 19:49 . 2010-09-21 15:32 22174 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2010-06-18 19:49 . 2010-09-21 17:33 22174 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 04:55 . 2010-09-21 15:32 33188 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2010-09-21 18:32 33188 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:34 . 2010-09-21 18:13 83848 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2010-06-18 22:07 . 2010-09-21 15:30 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-18 22:07 . 2010-09-21 18:31 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-19 05:08 . 2010-09-21 18:02 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2010-06-19 05:08 . 2010-09-21 17:12 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2010-06-19 05:08 . 2010-09-21 17:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2010-06-19 05:08 . 2010-09-21 18:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2010-06-19 05:08 . 2010-09-21 18:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
- 2010-06-19 05:08 . 2010-09-21 17:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
- 2010-06-18 22:07 . 2010-09-21 17:12 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-18 22:07 . 2010-09-21 18:31 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-18 22:07 . 2010-09-21 18:31 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-06-18 22:07 . 2010-09-21 15:30 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-06-18 19:45 . 2010-09-21 18:32 7448 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2786143777-1472676354-2263527552-1000_UserData.bin
+ 2010-09-21 17:31 . 2010-09-21 18:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-09-21 17:21 . 2010-09-21 17:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-09-21 17:31 . 2010-09-21 18:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-09-21 17:21 . 2010-09-21 17:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:05 . 2010-09-21 17:36 618912 c:\windows\System32\perfh009.dat
+ 2009-07-14 02:05 . 2010-09-21 17:36 107232 c:\windows\System32\perfc009.dat
- 2009-07-14 02:03 . 2010-09-21 15:43 6815744 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:03 . 2010-09-21 17:43 6815744 c:\windows\System32\SMI\Store\Machine\schema.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Thunderbird"="c:\program files\Mozilla Thunderbird\thunderbird -turbo" [X]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2010-08-21 2931744]
"Infium"="c:\program files\QIP 2010 JadrisPack\qip.exe" [2010-06-16 5813200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-06-08 9267816]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2006-12-29 569344]
"Wow Video&Audio"="c:\program files\Compal\Wow Video&Audio\WVAMain.exe" [2007-05-03 951856]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-04-07 2145000]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"SMBTray"="c:\program files\Compal\Smart Battery\SMBTray.exe" [2007-06-04 521776]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 1466368]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-06-19 23:19 136176 ----atw- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 13:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-19 1343400]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-18 691696]
S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS [2007-03-14 9856]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
S2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [2010-08-21 1411616]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-04-07 133512]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-04-07 810120]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-04-07 96896]
S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-08-02 22784]
S3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver;c:\program files\DU Meter\DUMETR32.SYS [2010-08-19 19368]
S3 netw5v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2010-01-13 6628352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
2010-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000Core.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]
2010-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000UA.job
- c:\users\DANIK\AppData\Local\Google\Update\GoogleUpdate.exe [2010-06-19 23:19]
.
.
------- Supplementary Scan -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\
FF - prefs.js: browser.startup.homepage - chrome://fastdial/content/fastdial.html
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\users\DANIK\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
---- FIREFOX POLICIES ----
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 250
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DUMeterSvc]
"ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\progra~1\DUMETE~1\DUMeter.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Mozilla Thunderbird\thunderbird.exe
c:\program files\Razer\DeathAdder\razertra.exe
c:\program files\Razer\DeathAdder\razerofa.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\sppsvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2010-09-21 20:35:05 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-21 18:35
ComboFix2.txt 2010-09-21 17:29
Pre-Run: Volných bajtů: 38 372 315 136
Post-Run: Volných bajtů: 38 166 970 368
- - End Of File - - 36F88E45C5E679121BCD83643A133DC1
Upload was successful
log HJT :
- Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:37:54, on 21. 9. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\PROGRA~1\DUMETE~1\DUMeter.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\Program Files\Compal\Smart Battery\SMBTray.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\QIP 2010 JadrisPack\qip.exe
C:\Program Files\Razer\DeathAdder\razertra.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\Windows\Explorer.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKLM\..\Run: [Wow Video&Audio] C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SMBTray] C:\Program Files\Compal\Smart Battery\SMBTray.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKCU\..\Run: [Thunderbird] "C:\Program Files\Mozilla Thunderbird\thunderbird" -turbo
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010 JadrisPack\qip.exe" /nosrv /isolated /smiles 40 /autorun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd. - C:\Program Files\DU Meter\DUMeterSvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
--
End of file - 4684 bytes
test na Virustotal
Result: 0 /43 (0.0%)
...vytazenie RAM-ky stale obrovske ..
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43290
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosim o kontrolu logu - system zahlcuje ram
c:\program files\DU Meter\DUMETR32.SYS
zkus to ještě tady:
http://www.kaspersky.com/scanforvirus
a
http://www.bitdefender.com/scanner/online/free.html
http://www.virscan.org/
Ještě jednou:
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
toto sis nastavoval sám:
??
Na nákazu to nevypadá , spíš HW --HDD.. RAM proběhl bez jediné chyby??
Kontrola HDD na chyby
otevři Tento počítač- pravým na disk-vlastnosti-záložka nástroje-kontrola chyb-zkontrolovat-v okně zatrhni obě políčka-klikni na spustit- tam to napíše , že kontrola bude provedena po příštím spuštění...
Restartuj PC, kontrola s opravou někdy trvá i několik hodin...
zkus to ještě tady:
http://www.kaspersky.com/scanforvirus
a
http://www.bitdefender.com/scanner/online/free.html
http://www.virscan.org/
Ještě jednou:
Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod
Kód: Vybrat vše
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
toto sis nastavoval sám:
Kód: Vybrat vše
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
Na nákazu to nevypadá , spíš HW --HDD.. RAM proběhl bez jediné chyby??
Kontrola HDD na chyby
otevři Tento počítač- pravým na disk-vlastnosti-záložka nástroje-kontrola chyb-zkontrolovat-v okně zatrhni obě políčka-klikni na spustit- tam to napíše , že kontrola bude provedena po příštím spuštění...
Restartuj PC, kontrola s opravou někdy trvá i několik hodin...
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosim o kontrolu logu - system zahlcuje ram
----> ciste
Kód: Vybrat vše
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
test HDD prebehol bez chyby ... RAM-ku dalej testujem ale zatial stale bez chyby (necham to bezat cez noc)
..co sa tyka tych registrov tak si niesom isty ci som nieco take menil, ani si niesom isty o co presne ide ..priamy zasah do registrov som urcite nerobil ..jedine cez nejake nastavenia winu
..a co sa tyka HW tak mam trosku vadnu grafarnu ..2x mi uz odysla a opravoval som ju tymto sposobom. Cakam uz ale na novu a neviem ci by za tym mohla byt, pretoze vzdy ked odysla, tak ani nenabehol notas a tento problem so zahlcovanim zacal po nejakom case (1-2dni) ked som sa napojil do siete kablom, neviem ci to moze nejako suvisiet .. ked sa pozriem do spravca uloh tak mnozstvo ramky ktoru pouzivaju spustene procesy neodpoveda vytazeniu 80-90% ktore su tam uvedene.
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43290
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Prosim o kontrolu logu - system zahlcuje ram
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Klikni na soubor a vyber: uložit jako, v okně vyber:
Název souboru: fixme.reg
Typ souboru : všechny soubory
Kam: na svojí plochu
Klikni na uložit .Poklepej na ploše na soubor fixme.reg. Win se zeptá , zdali chceš přidat do registru, klikni na Ano.
Restart PC.
*****************************************************************************************************************************************
S tou GK to jsem si nepouštěl...Jakou máš GK , její paměť?
Celá sestava? celkový počet RAM?
*****************************************************************************************************************************************
Stáhni si OTH
na svojí plochu( pokud používáš Firefox , pravým klikni na OTH link a vyber uložit jako (Save as..).
Stáhni si OTL
na svojí plochu (pokud používáš Firefox , pravým klikni na OTL link a vyber uložit jako (Save as..).
Stáhni si soubor Scan.txt
na svojí plochu (pokud používáš Firefox , pravým klikni na OTL link a vyber uložit jako (Save as..).
Poklepej na soubor OTH na ploše , po spuštění programu klikni na Kill All Processes.Poté klikni na Start OTL .Poklepej Do prázdného okna pod Vlastní skenování /opravy ( Custom Scans box). Objeví se zpráva: Kliknutím na OK vyberete cestu k souboru, kliknutím na Zrušit zrušíte výběr.
Klikni na OK. Objeví se okno průzkumníku , zde klikneš na plochu a najdeš na ní soubor Scan.txt .Klikni na Otevřít.
Poté klikni na Rychle prohledat (Quick Scan). Neměň žádná jiná nastavení . Sken může trvat dlouho.
Kdy sken skončí , objeví se na ploše dva logy:
OTL.Txt a Extras.Txt , jsou uloženy ve stejném místě jako OTL.
Zkopíruj sem prosím celý obsah obou logů.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
Klikni na soubor a vyber: uložit jako, v okně vyber:
Název souboru: fixme.reg
Typ souboru : všechny soubory
Kam: na svojí plochu
Klikni na uložit .Poklepej na ploše na soubor fixme.reg. Win se zeptá , zdali chceš přidat do registru, klikni na Ano.
Restart PC.
*****************************************************************************************************************************************
S tou GK to jsem si nepouštěl...Jakou máš GK , její paměť?
Celá sestava? celkový počet RAM?
*****************************************************************************************************************************************
Stáhni si OTH
na svojí plochu( pokud používáš Firefox , pravým klikni na OTH link a vyber uložit jako (Save as..).
Stáhni si OTL
na svojí plochu (pokud používáš Firefox , pravým klikni na OTL link a vyber uložit jako (Save as..).
Stáhni si soubor Scan.txt
na svojí plochu (pokud používáš Firefox , pravým klikni na OTL link a vyber uložit jako (Save as..).
Poklepej na soubor OTH na ploše , po spuštění programu klikni na Kill All Processes.Poté klikni na Start OTL .Poklepej Do prázdného okna pod Vlastní skenování /opravy ( Custom Scans box). Objeví se zpráva: Kliknutím na OK vyberete cestu k souboru, kliknutím na Zrušit zrušíte výběr.
Klikni na OK. Objeví se okno průzkumníku , zde klikneš na plochu a najdeš na ní soubor Scan.txt .Klikni na Otevřít.
Poté klikni na Rychle prohledat (Quick Scan). Neměň žádná jiná nastavení . Sken může trvat dlouho.
Kdy sken skončí , objeví se na ploše dva logy:
OTL.Txt a Extras.Txt , jsou uloženy ve stejném místě jako OTL.
Zkopíruj sem prosím celý obsah obou logů.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Prosim o kontrolu logu - system zahlcuje ram
test ramky ktoru som pustal cez noc prebehol bez chyb... zmenu registrov som aplikoval ... co sa tyka GK tak mam GeForce 8600M GT 256MB DDR3 ... a zostavu mam pisanu aj v infe ked si ma rozklikas ( Compal FL90, C2D T7250 2Ghz, 1GB RAM, GeForce 8600M GT, WIN7 32bit )
..ked som pustil OTL prvy krat zabudol som tam hodit scan.txt,tak som ho pustil znova s doplnujucimi udajmi zo suboru scan.txt, ale nevyhodil mi uz log extras.txt takze ho nemam..
log OTL.txt
..ked som pustil OTL prvy krat zabudol som tam hodit scan.txt,tak som ho pustil znova s doplnujucimi udajmi zo suboru scan.txt, ale nevyhodil mi uz log extras.txt takze ho nemam..
log OTL.txt
- OTL logfile created on: 22. 9. 2010 10:44:50 - Run 3
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\DANIK\Desktop
An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000041b | Country: Slovenská republika | Language: SKY | Date Format: d. M. yyyy
1 022,00 Mb Total Physical Memory | 477,00 Mb Available Physical Memory | 47,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 64,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 50,78 Gb Total Space | 35,12 Gb Free Space | 69,17% Space Free | Partition Type: NTFS
Drive D: | 61,01 Gb Total Space | 15,83 Gb Free Space | 25,95% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 7,58 Gb Total Space | 6,15 Gb Free Space | 81,10% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
Drive H: | 596,17 Gb Total Space | 36,43 Gb Free Space | 6,11% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Computer Name: DANIK-PC
Current User Name: DANIK
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/09/22 10:43:19 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\DANIK\Desktop\otl.exe
PRC - [2010/09/22 10:43:10 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Users\DANIK\Desktop\OTH.scr
PRC - [2010/08/21 21:58:11 | 001,411,616 | ---- | M] (Hagel Technologies Ltd.) -- C:\Program Files\DU Meter\DUMeterSvc.exe
PRC - [2010/04/07 21:07:24 | 000,810,120 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2010/04/07 21:07:04 | 002,145,000 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2010/01/19 17:00:26 | 000,858,384 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe
PRC - [2010/01/19 16:41:46 | 000,473,360 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2009/07/14 03:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
========== Modules (SafeList) ==========
MOD - [2010/09/22 10:43:19 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\DANIK\Desktop\otl.exe
MOD - [2010/06/30 08:21:47 | 000,163,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\ieproxy.dll
MOD - [2009/07/14 03:17:54 | 000,242,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rsaenh.dll
MOD - [2009/07/14 03:16:18 | 001,011,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WindowsCodecs.dll
MOD - [2009/07/14 03:16:16 | 000,082,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\thumbcache.dll
MOD - [2009/07/14 03:16:15 | 000,363,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\StructuredQuery.dll
MOD - [2009/07/14 03:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspicli.dll
MOD - [2009/07/14 03:16:15 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srvcli.dll
MOD - [2009/07/14 03:16:15 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\slc.dll
MOD - [2009/07/14 03:16:13 | 000,643,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchFolder.dll
MOD - [2009/07/14 03:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sechost.dll
MOD - [2009/07/14 03:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samcli.dll
MOD - [2009/07/14 03:16:13 | 000,045,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RpcRtRemote.dll
MOD - [2009/07/14 03:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\profapi.dll
MOD - [2009/07/14 03:16:03 | 001,661,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\networkexplorer.dll
MOD - [2009/07/14 03:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netutils.dll
MOD - [2009/07/14 03:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\KernelBase.dll
MOD - [2009/07/14 03:15:14 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\EhStorShell.dll
MOD - [2009/07/14 03:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
MOD - [2009/07/14 03:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devobj.dll
MOD - [2009/07/14 03:15:07 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptsp.dll
MOD - [2009/07/14 03:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptbase.dll
MOD - [2009/07/14 03:15:07 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cscapi.dll
MOD - [2009/07/14 03:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll
MOD - [2009/07/14 03:14:52 | 000,309,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\actxprxy.dll
MOD - [2009/07/14 03:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
MOD - [2009/07/14 03:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/08/21 21:58:11 | 001,411,616 | ---- | M] (Hagel Technologies Ltd.) [Auto | Running] -- C:\Program Files\DU Meter\DUMeterSvc.exe -- (DUMeterSvc)
SRV - [2010/06/19 03:05:59 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/04/07 21:10:38 | 000,033,560 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010/04/07 21:07:24 | 000,810,120 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/19 17:00:26 | 000,858,384 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2010/01/19 16:41:46 | 000,473,360 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2009/07/14 03:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wwansvc.dll -- (WwanSvc)
SRV - [2009/07/14 03:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbiosrvc.dll -- (WbioSrvc)
SRV - [2009/07/14 03:16:17 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpo.dll -- (Power)
SRV - [2009/07/14 03:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2009/07/14 03:16:15 | 000,053,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sppuinotify.dll -- (sppuinotify)
SRV - [2009/07/14 03:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/14 03:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper)
SRV - [2009/07/14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 03:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (PNRPsvc) Protokol PNRP (Peer Name Resolution Protocol)
SRV - [2009/07/14 03:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (p2pimsvc)
SRV - [2009/07/14 03:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\provsvc.dll -- (HomeGroupProvider)
SRV - [2009/07/14 03:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg)
SRV - [2009/07/14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/14 03:15:36 | 000,194,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ListSvc.dll -- (HomeGroupListener)
SRV - [2009/07/14 03:15:21 | 000,797,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/07/14 03:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2009/07/14 03:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\defragsvc.dll -- (defragsvc)
SRV - [2009/07/14 03:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\bdesvc.dll -- (BDESVC)
SRV - [2009/07/14 03:14:58 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AxInstSv.dll -- (AxInstSV) Instalační program ovládacích prvků ActiveX (AxInstSV)
SRV - [2009/07/14 03:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appidsvc.dll -- (AppIDSvc)
SRV - [2009/07/14 03:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\sppsvc.exe -- (sppsvc)
SRV - [2009/06/10 23:14:05 | 000,128,848 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2007/05/31 09:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 09:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\DANIK\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2010/08/19 12:13:50 | 000,019,368 | ---- | M] (Hagel Technologies Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DU Meter\DUMetr32.sys -- (DUMeterDrv)
DRV - [2010/06/19 01:15:52 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2010/06/08 17:19:26 | 003,112,360 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2010/04/07 21:08:12 | 000,096,896 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV - [2010/04/07 21:07:08 | 000,114,984 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010/04/07 21:03:46 | 000,133,512 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\System32\drivers\eamonm.sys -- (eamonm)
DRV - [2010/01/13 08:29:56 | 006,628,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (netw5v32) Ovladač adaptéru Intel(R)
DRV - [2009/12/11 09:44:02 | 000,133,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecpkg.sys -- (KSecPkg)
DRV - [2009/11/21 04:34:54 | 011,515,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/07/14 03:26:21 | 000,015,952 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\cmdide.sys -- (cmdide)
DRV - [2009/07/14 03:26:17 | 000,297,552 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpahci.sys -- (adpahci)
DRV - [2009/07/14 03:26:15 | 000,422,976 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adp94xx.sys -- (adp94xx)
DRV - [2009/07/14 03:26:15 | 000,159,312 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsbs.sys -- (amdsbs)
DRV - [2009/07/14 03:26:15 | 000,146,512 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpu320.sys -- (adpu320)
DRV - [2009/07/14 03:26:15 | 000,086,608 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arcsas.sys -- (arcsas)
DRV - [2009/07/14 03:26:15 | 000,079,952 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsata.sys -- (amdsata)
DRV - [2009/07/14 03:26:15 | 000,076,368 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arc.sys -- (arc)
DRV - [2009/07/14 03:26:15 | 000,023,616 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\amdxata.sys -- (amdxata)
DRV - [2009/07/14 03:26:15 | 000,014,400 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\aliide.sys -- (aliide)
DRV - [2009/07/14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvstor.sys -- (nvstor)
DRV - [2009/07/14 03:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvraid.sys -- (nvraid)
DRV - [2009/07/14 03:20:44 | 000,044,624 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nfrd960.sys -- (nfrd960)
DRV - [2009/07/14 03:20:37 | 000,089,168 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas.sys -- (LSI_SAS)
DRV - [2009/07/14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iaStorV.sys -- (iaStorV)
DRV - [2009/07/14 03:20:36 | 000,235,584 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MegaSR.sys -- (MegaSR)
DRV - [2009/07/14 03:20:36 | 000,096,848 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2009/07/14 03:20:36 | 000,095,824 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_fc.sys -- (LSI_FC)
DRV - [2009/07/14 03:20:36 | 000,054,864 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas2.sys -- (LSI_SAS2)
DRV - [2009/07/14 03:20:36 | 000,041,040 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iirsp.sys -- (iirsp)
DRV - [2009/07/14 03:20:36 | 000,030,800 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\megasas.sys -- (megasas)
DRV - [2009/07/14 03:20:36 | 000,013,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hwpolicy.sys -- (hwpolicy)
DRV - [2009/07/14 03:20:28 | 000,453,712 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\elxstor.sys -- (elxstor)
DRV - [2009/07/14 03:20:28 | 000,070,720 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\djsvs.sys -- (aic78xx)
DRV - [2009/07/14 03:20:28 | 000,067,152 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HpSAMD.sys -- (HpSAMD)
DRV - [2009/07/14 03:20:28 | 000,046,160 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\fsdepends.sys -- (FsDepends)
DRV - [2009/07/14 03:19:11 | 000,141,904 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vsmraid.sys -- (vsmraid)
DRV - [2009/07/14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/14 03:19:10 | 000,159,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vhdmp.sys -- (vhdmp)
DRV - [2009/07/14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 03:19:10 | 000,032,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vdrvroot.sys -- (vdrvroot)
DRV - [2009/07/14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\wimmount.sys -- (WIMMount)
DRV - [2009/07/14 03:19:10 | 000,016,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\viaide.sys -- (viaide)
DRV - [2009/07/14 03:19:04 | 001,383,488 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql2300.sys -- (ql2300)
DRV - [2009/07/14 03:19:04 | 000,173,648 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\rdyboost.sys -- (rdyboost)
DRV - [2009/07/14 03:19:04 | 000,106,064 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql40xx.sys -- (ql40xx)
DRV - [2009/07/14 03:19:04 | 000,077,888 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\sisraid4.sys -- (SiSRaid4)
DRV - [2009/07/14 03:19:04 | 000,043,088 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pcw.sys -- (pcw)
DRV - [2009/07/14 03:19:04 | 000,040,016 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\SiSRaid2.sys -- (SiSRaid2)
DRV - [2009/07/14 03:19:04 | 000,021,072 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\stexstor.sys -- (stexstor)
DRV - [2009/07/14 03:17:54 | 000,369,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\cng.sys -- (CNG)
DRV - [2009/07/14 02:57:25 | 000,272,128 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\Brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2009/07/14 02:02:41 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rdpbus.sys -- (rdpbus)
DRV - [2009/07/14 02:01:41 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV - [2009/07/14 01:55:25 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MODEMCSA.sys -- (MODEMCSA)
DRV - [2009/07/14 01:55:00 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)
DRV - [2009/07/14 01:53:51 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\wfplwf.sys -- (WfpLwf)
DRV - [2009/07/14 01:52:44 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ndiscap.sys -- (NdisCap)
DRV - [2009/07/14 01:52:02 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vwifibus.sys -- (vwifibus)
DRV - [2009/07/14 01:52:00 | 000,163,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\1394ohci.sys -- (1394ohci)
DRV - [2009/07/14 01:51:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\umpass.sys -- (UmPass)
DRV - [2009/07/14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2009/07/14 01:51:08 | 000,004,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV - [2009/07/14 01:46:55 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MTConfig.sys -- (MTConfig)
DRV - [2009/07/14 01:45:26 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CompositeBus.sys -- (CompositeBus)
DRV - [2009/07/14 01:36:52 | 000,050,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\appid.sys -- (AppID)
DRV - [2009/07/14 01:33:50 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\scfilter.sys -- (scfilter)
DRV - [2009/07/14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/14 01:24:05 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\discache.sys -- (discache)
DRV - [2009/07/14 01:19:21 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HidBatt.sys -- (HidBatt)
DRV - [2009/07/14 01:16:36 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\acpipmi.sys -- (AcpiPmi)
DRV - [2009/07/14 01:11:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdppm.sys -- (AmdPPM)
DRV - [2009/07/14 00:54:14 | 000,026,624 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/14 00:53:33 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbMdm.sys -- (BrUsbMdm)
DRV - [2009/07/14 00:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbSer.sys -- (BrUsbSer)
DRV - [2009/07/14 00:53:32 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrSerWdm.sys -- (BrSerWdm)
DRV - [2009/07/14 00:53:28 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltLo.sys -- (BrFiltLo)
DRV - [2009/07/14 00:53:28 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltUp.sys -- (BrFiltUp)
DRV - [2009/07/14 00:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2009/07/14 00:02:48 | 003,100,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\evbdx.sys -- (ebdrv)
DRV - [2009/07/14 00:02:48 | 000,430,080 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\bxvbdx.sys -- (b06bdrv)
DRV - [2009/05/05 12:15:58 | 001,095,808 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial)
DRV - [2008/09/10 00:22:00 | 000,048,640 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2008/04/21 15:26:12 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/08/08 18:54:10 | 000,028,968 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\ATITool.sys -- (ATITool)
DRV - [2007/08/02 17:32:26 | 000,022,784 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dadder.sys -- (DAdderFltr)
DRV - [2007/03/14 10:16:40 | 000,009,856 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\EMSC.SYS -- (EMSC)
DRV - [2007/01/17 03:04:46 | 009,599,872 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV - [2006/09/24 15:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\Windows\system32\speedfan.sys -- (speedfan)
DRV - [1996/04/03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CB 80 91 76 2E 5A CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "chrome://fastdial/content/fastdial.html"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
FF - prefs.js..extensions.enabledItems: fastdial@telega.phpnet.us:2.23b2
FF - prefs.js..extensions.enabledItems: ietab@ip.cn:1.94.20100904
FF - prefs.js..extensions.enabledItems: sitedelta@schierla.de:0.11.1
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: tabscope@xuldev.org:0.3.7
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {20cc25e2-48c9-45e1-9a1f-1ccc1882b81b}:1.7
FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.0.6
FF - prefs.js..extensions.enabledItems: {ee56ecf0-6e7a-479a-8162-e123a991c7e7}:0.4.7
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: tabsontop-darthpalpatine@dummy.addons.mozilla.org:1.4.4
FF - prefs.js..extensions.enabledItems: hidecaptionplus-dp@dummy.addons.mozilla.org:1.1.2
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.13
FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.6.5
FF - prefs.js..network.proxy.backup.ftp: "cache.fi.muni.cz"
FF - prefs.js..network.proxy.backup.ftp_port: 5555
FF - prefs.js..network.proxy.backup.gopher: "cache.fi.muni.cz"
FF - prefs.js..network.proxy.backup.gopher_port: 5555
FF - prefs.js..network.proxy.backup.socks: "cache.fi.muni.cz"
FF - prefs.js..network.proxy.backup.socks_port: 5555
FF - prefs.js..network.proxy.backup.ssl: "cache.fi.muni.cz"
FF - prefs.js..network.proxy.backup.ssl_port: 5555
FF - prefs.js..network.proxy.ftp: "cache34.ics.muni.cz"
FF - prefs.js..network.proxy.ftp_port: 5555
FF - prefs.js..network.proxy.gopher: "cache34.ics.muni.cz"
FF - prefs.js..network.proxy.gopher_port: 5555
FF - prefs.js..network.proxy.http: "cache34.ics.muni.cz"
FF - prefs.js..network.proxy.http_port: 5555
FF - prefs.js..network.proxy.no_proxies_on: "localhost, 127.0.0.1, mail.muni.cz:110, pop3.azet.sk:110"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "cache34.ics.muni.cz"
FF - prefs.js..network.proxy.socks_port: 5555
FF - prefs.js..network.proxy.ssl: "cache34.ics.muni.cz"
FF - prefs.js..network.proxy.ssl_port: 5555
FF - user.js..browser.search.openintab: false
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/16 11:11:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/16 11:11:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/09/17 17:57:10 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/06/19 00:26:20 | 000,000,000 | ---D | M]
[2010/06/19 02:22:07 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Extensions
[2010/06/19 02:22:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/09/21 17:47:17 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions
[2010/08/06 21:03:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{20cc25e2-48c9-45e1-9a1f-1ccc1882b81b}
[2010/09/14 11:48:31 | 000,000,000 | ---D | M] (Flashblock) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2010/07/28 19:59:06 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/08/27 11:26:18 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/08/27 11:26:18 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/06/19 02:22:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/08/07 17:39:24 | 000,000,000 | ---D | M] (autoHideStatusbar) -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\{ee56ecf0-6e7a-479a-8162-e123a991c7e7}
[2010/08/19 19:26:30 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\cfxe@Triton
[2010/08/19 19:26:38 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\cfxHelper@Triton
[2010/08/07 16:35:53 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\elemhidehelper@adblockplus.org
[2010/07/20 20:22:41 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\fastdial@telega.phpnet.us
[2010/08/18 10:16:29 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\hidecaptionplus-dp@dummy.addons.mozilla.org
[2010/08/19 19:28:07 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\chromifox@altmusictv.com
[2010/09/12 14:24:07 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\ietab@ip.cn
[2010/06/19 02:22:11 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\sitedelta@schierla.de
[2010/09/18 14:50:08 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\tabscope@xuldev.org
[2010/08/18 10:13:03 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Mozilla\Firefox\Profiles\ksqklzeo.default\extensions\tabsontop-darthpalpatine@dummy.addons.mozilla.org
[2010/09/21 17:47:17 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/06/19 05:37:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/08 00:51:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/05/25 18:09:48 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2010/04/01 19:40:34 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2010/04/01 19:40:34 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2010/04/01 19:40:34 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2010/04/01 19:40:34 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2010/04/01 19:40:34 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2010/04/01 19:40:34 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml
O1 HOSTS File: ([2010/09/21 20:30:56 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe ()
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SMBTray] C:\Program Files\Compal\Smart Battery\SMBTray.exe (Compal Electronics, Inc.)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix)
O4 - HKLM..\Run: [Wow Video&Audio] C:\Program Files\Compal\Wow Video&Audio\WVAMain.exe ()
O4 - HKCU..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe (Hagel Technologies Ltd.)
O4 - HKCU..\Run: [Infium] C:\Program Files\QIP 2010 JadrisPack\qip.exe (QIP)
O4 - HKCU..\Run: [Thunderbird] C:\Program Files\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 147.229.192.2 147.229.190.134 147.229.191.135
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 90 Days ==========
[2010/09/22 10:43:16 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\DANIK\Desktop\OTL.exe
[2010/09/22 10:43:04 | 000,258,560 | ---- | C] (OldTimer Tools) -- C:\Users\DANIK\Desktop\OTH.scr
[2010/09/22 10:42:44 | 000,000,000 | ---D | C] -- C:\Users\DANIK\Desktop\log
[2010/09/22 10:19:12 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2010/09/21 22:16:57 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Roaming\QuickScan
[2010/09/21 20:31:00 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2010/09/21 20:29:15 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2010/09/21 20:29:15 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Local\temp
[2010/09/21 20:20:30 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/09/21 19:23:11 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/09/21 19:23:11 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/09/21 19:23:11 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/09/21 10:18:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2010/09/20 23:39:19 | 000,000,000 | ---D | C] -- C:\Program Files\tea-timer-2.1
[2010/09/20 23:34:23 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/09/20 23:30:29 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/09/20 23:30:28 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/09/20 23:30:27 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/20 22:04:30 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/09/20 21:36:55 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/09/20 20:37:41 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/09/20 00:00:19 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Roaming\Malwarebytes
[2010/09/20 00:00:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/09/19 23:01:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010/09/19 20:06:07 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Roaming\Opera
[2010/09/19 20:06:07 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Local\Opera
[2010/09/19 17:01:40 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Roaming\vlc
[2010/09/19 12:35:34 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2010/09/19 12:34:21 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Roaming\uTorrent
[2010/09/17 14:00:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2010/09/12 18:30:42 | 000,162,816 | ---- | C] (Firelight Technologies Pty, Ltd) -- C:\Windows\System32\fmod.dll
[2010/09/12 13:31:55 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/09/12 13:31:17 | 002,970,112 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\System32\PhoenixDll.dll
[2010/09/11 10:46:37 | 000,000,000 | ---D | C] -- C:\Windows\WindowsMobile
[2010/09/04 13:40:32 | 000,000,000 | ---D | C] -- C:\Program Files\Motorola
[2010/09/03 12:49:07 | 000,000,000 | ---D | C] -- C:\Program Files\TNODUP
[2010/09/01 14:36:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Hagel Technologies
[2010/09/01 14:36:29 | 000,000,000 | ---D | C] -- C:\Program Files\DU Meter
[2010/08/18 12:23:58 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Local\ESET
[2010/08/08 00:52:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/08/06 22:30:54 | 000,000,000 | ---D | C] -- C:\Program Files\qip2005pack
[2010/07/14 23:43:08 | 000,000,000 | ---D | C] -- C:\Program Files\The KMPlayer
[2010/07/10 15:40:16 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Local\Microangelo Toolset 6
[2010/07/10 15:40:16 | 000,000,000 | ---D | C] -- D:\Dokumenty\Icons and Cursors
[2010/07/10 15:39:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microangelo Toolset 6
[2010/07/07 16:17:27 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2010/07/05 20:57:05 | 000,000,000 | ---D | C] -- C:\Program Files\QIP 2010 JadrisPack
[2010/07/05 01:41:01 | 000,000,000 | ---D | C] -- C:\Program Files\ATITool
[2010/07/05 01:23:05 | 000,000,000 | ---D | C] -- C:\Program Files\Ray Adams
[2010/06/24 22:07:33 | 000,000,000 | ---D | C] -- C:\Users\DANIK\AppData\Local\ElevatedDiagnostics
[2010/06/18 21:58:35 | 000,081,920 | ---- | C] ( ) -- C:\Windows\System32\rsnp2uvc.dll
[2010/06/18 21:58:35 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnp2uvc.dll
========== Files - Modified Within 90 Days ==========
[2010/09/22 10:44:48 | 007,340,032 | -HS- | M] () -- C:\Users\DANIK\ntuser.dat
[2010/09/22 10:43:19 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\DANIK\Desktop\OTL.exe
[2010/09/22 10:43:10 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Users\DANIK\Desktop\OTH.scr
[2010/09/22 10:40:14 | 000,015,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/22 10:40:14 | 000,015,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/22 10:37:29 | 000,730,320 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/09/22 10:37:29 | 000,618,912 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/09/22 10:37:29 | 000,107,232 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/09/22 10:33:04 | 000,000,435 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2010/09/22 10:32:46 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/09/22 10:32:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/09/22 10:32:37 | 804,069,376 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/22 10:30:16 | 000,001,022 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000UA.job
[2010/09/22 10:19:08 | 279,208,243 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/09/22 10:05:17 | 000,938,505 | -H-- | M] () -- C:\Users\DANIK\AppData\Local\IconCache.db
[2010/09/22 09:59:01 | 000,000,340 | ---- | M] () -- C:\Users\DANIK\Desktop\fixme.reg
[2010/09/21 23:52:26 | 000,003,536 | ---- | M] () -- C:\bootsqm.dat
[2010/09/21 20:31:15 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/09/21 20:30:56 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/09/21 18:58:32 | 003,848,793 | R--- | M] () -- C:\Users\DANIK\Desktop\ComboFix.exe
[2010/09/21 16:26:07 | 000,524,288 | -HS- | M] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TMContainer00000000000000000002.regtrans-ms
[2010/09/21 16:26:07 | 000,524,288 | -HS- | M] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TMContainer00000000000000000001.regtrans-ms
[2010/09/21 16:26:07 | 000,065,536 | -HS- | M] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TM.blf
[2010/09/21 16:14:00 | 000,000,492 | -HS- | M] () -- C:\Windows\setup_9.0.0.722_21.09.2010_10-25(2)drv.spi
[2010/09/21 01:30:03 | 000,000,970 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2786143777-1472676354-2263527552-1000Core.job
[2010/09/21 00:20:12 | 000,002,963 | ---- | M] () -- C:\Users\DANIK\Desktop\HiJackThis.lnk
[2010/09/21 00:04:35 | 000,012,768 | ---- | M] () -- D:\Dokumenty\cc_20100921_000428.reg
[2010/09/20 23:36:54 | 000,419,429 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20100920-234541.backup
[2010/09/20 23:34:34 | 000,001,220 | ---- | M] () -- C:\Users\DANIK\Desktop\Spybot - Search & Destroy.lnk
[2010/09/20 23:30:32 | 000,000,983 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/20 20:24:21 | 000,007,608 | ---- | M] () -- C:\Users\DANIK\AppData\Local\Resmon.ResmonCfg
[2010/09/19 22:36:15 | 000,012,768 | ---- | M] () -- D:\Dokumenty\cc_20100919_223604.reg
[2010/09/19 12:35:36 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2010/09/18 10:30:47 | 000,002,363 | ---- | M] () -- C:\Users\DANIK\Desktop\Google Chrome.lnk
[2010/09/17 03:33:24 | 000,004,287 | ---- | M] () -- D:\Dokumenty\DU Meter Report.html
[2010/09/17 03:31:26 | 000,005,590 | ---- | M] () -- D:\Dokumenty\DU Meter Report.pdf
[2010/09/17 03:27:40 | 000,339,760 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/09/16 19:48:44 | 000,005,566 | ---- | M] () -- D:\Dokumenty\cc_20100916_194826.reg
[2010/09/16 10:10:45 | 000,759,819 | ---- | M] () -- D:\Dokumenty\Oznamenie_poistenca_platitela_poistneho-vyplnitelne.pdf
[2010/09/13 10:54:56 | 000,010,752 | ---- | M] () -- C:\Users\DANIK\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/12 18:30:42 | 000,162,816 | ---- | M] (Firelight Technologies Pty, Ltd) -- C:\Windows\System32\fmod.dll
[2010/09/12 17:32:01 | 000,084,512 | ---- | M] () -- C:\Users\DANIK\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/09/11 11:56:01 | 000,000,922 | ---- | M] () -- C:\Users\DANIK\Desktop\Centrum zařízení Windows Mobile.lnk
[2010/09/11 11:06:32 | 000,000,478 | ---- | M] () -- C:\Windows\win.ini
[2010/09/11 10:48:40 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[2010/09/05 09:57:43 | 000,018,080 | ---- | M] () -- D:\Dokumenty\cc_20100905_095725.reg
[2010/09/03 15:28:11 | 000,001,984 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/08/31 20:23:00 | 000,000,036 | ---- | M] () -- C:\Windows\usdthank.ini
[2010/08/31 20:23:00 | 000,000,031 | ---- | M] () -- C:\Windows\idc.ini
[2010/08/30 00:13:13 | 000,144,816 | ---- | M] () -- D:\Dokumenty\vyhl_2010_zapis_studentu_elektron_B-BK.pdf
[2010/08/06 22:31:10 | 000,001,284 | ---- | M] () -- C:\Users\DANIK\Desktop\qip guest.lnk
[2010/07/14 23:43:33 | 000,000,997 | ---- | M] () -- C:\Users\DANIK\Desktop\KMPlayer.lnk
[2010/07/14 22:26:13 | 000,000,711 | ---- | M] () -- C:\Users\Public\Desktop\Half-Life 2 Episode One.lnk
[2010/07/14 16:40:50 | 000,000,693 | ---- | M] () -- C:\Users\Public\Desktop\Half-Life 2 Episode Two.lnk
[2010/07/10 15:29:56 | 000,001,953 | ---- | M] () -- C:\Users\DANIK\Desktop\QIP.lnk
[2010/07/08 16:30:04 | 000,059,392 | ---- | M] () -- D:\Dokumenty\Otazky_ABCH_ke_zkousce_091.doc
[2010/06/25 01:13:26 | 000,000,158 | ---- | M] () -- C:\Users\Public\Documents\SMBSettings.ini
========== Files Created - No Company Name ==========
[2010/09/22 10:19:08 | 279,208,243 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/09/22 09:59:01 | 000,000,340 | ---- | C] () -- C:\Users\DANIK\Desktop\fixme.reg
[2010/09/21 23:52:26 | 000,003,536 | ---- | C] () -- C:\bootsqm.dat
[2010/09/21 19:23:11 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/09/21 19:23:11 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/09/21 19:23:11 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/09/21 19:23:11 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/09/21 19:23:11 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/09/21 19:12:18 | 003,848,793 | R--- | C] () -- C:\Users\DANIK\Desktop\ComboFix.exe
[2010/09/21 13:24:25 | 000,000,492 | -HS- | C] () -- C:\Windows\setup_9.0.0.722_21.09.2010_10-25(2)drv.spi
[2010/09/21 00:20:12 | 000,002,963 | ---- | C] () -- C:\Users\DANIK\Desktop\HiJackThis.lnk
[2010/09/21 00:04:34 | 000,012,768 | ---- | C] () -- D:\Dokumenty\cc_20100921_000428.reg
[2010/09/20 23:34:34 | 000,001,220 | ---- | C] () -- C:\Users\DANIK\Desktop\Spybot - Search & Destroy.lnk
[2010/09/20 23:30:32 | 000,000,983 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/20 23:25:43 | 000,524,288 | -HS- | C] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TMContainer00000000000000000002.regtrans-ms
[2010/09/20 23:25:43 | 000,524,288 | -HS- | C] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TMContainer00000000000000000001.regtrans-ms
[2010/09/20 23:25:43 | 000,065,536 | -HS- | C] () -- C:\Users\DANIK\ntuser.dat{988f9cb2-c4fb-11df-bc13-001b385c4831}.TM.blf
[2010/09/19 22:50:14 | 000,007,608 | ---- | C] () -- C:\Users\DANIK\AppData\Local\Resmon.ResmonCfg
[2010/09/19 22:36:13 | 000,012,768 | ---- | C] () -- D:\Dokumenty\cc_20100919_223604.reg
[2010/09/19 12:35:36 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2010/09/17 03:32:38 | 000,004,287 | ---- | C] () -- D:\Dokumenty\DU Meter Report.html
[2010/09/17 03:31:25 | 000,005,590 | ---- | C] () -- D:\Dokumenty\DU Meter Report.pdf
[2010/09/16 19:48:42 | 000,005,566 | ---- | C] () -- D:\Dokumenty\cc_20100916_194826.reg
[2010/09/16 10:10:45 | 000,759,819 | ---- | C] () -- D:\Dokumenty\Oznamenie_poistenca_platitela_poistneho-vyplnitelne.pdf
[2010/09/11 11:56:01 | 000,000,922 | ---- | C] () -- C:\Users\DANIK\Desktop\Centrum zařízení Windows Mobile.lnk
[2010/09/11 10:48:40 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[2010/09/05 09:57:31 | 000,018,080 | ---- | C] () -- D:\Dokumenty\cc_20100905_095725.reg
[2010/08/31 20:23:00 | 000,000,036 | ---- | C] () -- C:\Windows\usdthank.ini
[2010/08/31 20:23:00 | 000,000,031 | ---- | C] () -- C:\Windows\idc.ini
[2010/08/30 00:13:13 | 000,144,816 | ---- | C] () -- D:\Dokumenty\vyhl_2010_zapis_studentu_elektron_B-BK.pdf
[2010/08/06 22:31:10 | 000,001,284 | ---- | C] () -- C:\Users\DANIK\Desktop\qip guest.lnk
[2010/07/14 23:43:33 | 000,000,997 | ---- | C] () -- C:\Users\DANIK\Desktop\KMPlayer.lnk
[2010/07/14 16:40:50 | 000,000,693 | ---- | C] () -- C:\Users\Public\Desktop\Half-Life 2 Episode Two.lnk
[2010/07/14 16:34:36 | 000,000,711 | ---- | C] () -- C:\Users\Public\Desktop\Half-Life 2 Episode One.lnk
[2010/07/05 20:57:20 | 000,001,953 | ---- | C] () -- C:\Users\DANIK\Desktop\QIP.lnk
[2010/07/05 01:05:40 | 000,004,224 | ---- | C] () -- C:\Windows\System32\drivers\NVStrap.sys
[2010/06/25 01:12:42 | 000,004,688 | -H-- | C] () -- D:\Dokumenty\WVAProp.xml
[2010/06/20 03:12:11 | 000,000,108 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010/06/19 20:47:11 | 000,010,752 | ---- | C] () -- C:\Users\DANIK\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/19 00:55:06 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/06/18 21:58:36 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini
[2010/06/18 21:58:35 | 009,599,872 | ---- | C] () -- C:\Windows\System32\drivers\snp2uvc.sys
[2009/07/14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2007/08/08 18:54:10 | 000,028,968 | ---- | C] () -- C:\Windows\System32\drivers\ATITool.sys
[2007/04/17 09:44:28 | 000,266,240 | ---- | C] () -- C:\Windows\System32\EMSC.DLL
[2007/03/14 10:16:40 | 000,009,856 | ---- | C] () -- C:\Windows\System32\drivers\EMSC.sys
[1996/04/03 21:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys
========== LOP Check ==========
[2010/06/20 03:48:21 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\365dni
[2010/07/04 13:14:55 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\DAEMON Tools Lite
[2010/09/20 23:24:01 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\GHISLER
[2010/06/19 01:05:55 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\IrfanView
[2010/09/19 20:06:07 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Opera
[2010/09/21 22:17:17 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\QuickScan
[2010/06/19 02:22:36 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\Thunderbird
[2010/09/19 12:50:22 | 000,000,000 | ---D | M] -- C:\Users\DANIK\AppData\Roaming\uTorrent
[2009/07/14 06:53:46 | 000,016,444 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/10 23:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2009/07/14 03:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2010/06/18 22:10:47 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2010/09/21 23:52:26 | 000,003,536 | ---- | M] () -- C:\bootsqm.dat
[2010/09/21 20:36:22 | 000,016,692 | ---- | M] () -- C:\ComboFix.txt
[2009/06/10 23:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2010/09/22 10:32:37 | 804,069,376 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/22 10:32:41 | 1073,741,824 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\drivers\*.sys /90 >
========== Alternate Data Streams ==========
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:D44A64FE
< End of report >
Re: Prosim o kontrolu logu - system zahlcuje ram
tak nakoniec ked som si precital tutorial a po nejakych zmenach v nastaveni mi to vyplulo aj extras.txt viz:
..v pripade potreby sem mozem hodit aj log OTL z toho konkretneho runu kedy mi k nemu vyplulo aj EXTRAS
- OTL Extras logfile created on: 22. 9. 2010 11:33:16 - Run 5
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Users\DANIK\Desktop
An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000041b | Country: Slovenská republika | Language: SKY | Date Format: d. M. yyyy
1 022,00 Mb Total Physical Memory | 409,00 Mb Available Physical Memory | 40,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 64,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 50,78 Gb Total Space | 35,13 Gb Free Space | 69,17% Space Free | Partition Type: NTFS
Drive D: | 61,01 Gb Total Space | 15,83 Gb Free Space | 25,95% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 7,58 Gb Total Space | 6,15 Gb Free Space | 81,10% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
Drive H: | 596,17 Gb Total Space | 36,43 Gb Free Space | 6,11% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Computer Name: DANIK-PC
Current User Name: DANIK
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (All) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf [@ = inffile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
.js [@ = JSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\System32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [KMPlayer.Enqueue] -- "C:\Program Files\The KMPlayer\KMPlayer.exe"/ADD "%1"
Directory [KMPlayer.Play] -- "C:\Program Files\The KMPlayer\KMPlayer.exe" "%1" (Pandora.TV)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 21
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = USB Video Device
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{449A16C4-83B3-426C-AA4A-00A34E80C093}" = Smart Battery
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47609E69-4C5E-48B1-A889-24C6B82B5C04}" = Vista Shortcut Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.57.01
"{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{71414EC2-0684-4A15-A85A-E0E259D117AF}" = Microangelo Toolset 6
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{294B4278-CF7B-40B9-86A1-2D3FF0C2C524}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{10EC59E5-9BCE-4884-BB1A-E28627220232}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Centrum zařízení Windows Mobile
"{9A4CBA78-CFAD-4058-9AB8-532F5DF44682}_is1" = Program 365dní
"{9EF7918F-6283-48D4-8648-9FE84BE9FB41}" = The Orange Box
"{AC76BA86-7AD7-1051-7B44-A93000000001}" = Adobe Reader 9.3.4 - Slovak
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B90E5EBE-DF18-44D5-9D18-689ADEE9DA6C}" = Intel(R) PROSet/Wireless WiFi Software
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DE7E6DBF-ABEE-43FF-A3A1-4DCF46411736}" = ESET NOD32 Antivirus
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile Device Center Driver Update
"{EB1B8449-CD8F-485B-ADB6-02FBCFE180D3}" = Razer DeathAdder(TM) Mouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F408DA6B-DA75-4D95-B87D-49AFF0B4EBB0}" = Wow Video&Audio utility
"{FEF06E73-A519-4510-8CF3-B66041B91D8A}" = EMSC
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ATITool" = ATITool Overclocking Utility
"CCleaner" = CCleaner
"DUMeter3_is1" = DU Meter
"ENTERPRISE" = Microsoft Office Enterprise 2007
"InstallShield_{449A16C4-83B3-426C-AA4A-00A34E80C093}" = Smart Battery
"InstallShield_{F408DA6B-DA75-4D95-B87D-49AFF0B4EBB0}" = Wow Video&Audio utility
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"Mozilla Thunderbird (3.1.4)" = Mozilla Thunderbird (3.1.4)
"Orneta Notepad Mobile v3.1.1" = Orneta Notepad Mobile v3.1.1
"ProInst" = Intel PROSet Wireless
"QIP 2010 JadrisPack 1.0.0" = QIP 2010 JadrisPack 1.0.0
"SMSERIAL" = Motorola SM56 Speakerphone Modem
"SpeedFan" = SpeedFan (remove only)
"The KMPlayer" = The KMPlayer (remove only)
"Totalcmd" = Total Commander (Remove or Repair)
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.4
"Winamp" = Winamp
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 22. 9. 2010 4:12:58 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
hodnota DWORD v datové oblasti obsahuje kód chyby Win32.
Error - 22. 9. 2010 4:12:58 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
hodnota DWORD v datové oblasti obsahuje kód chyby Win32.
Error - 22. 9. 2010 4:25:41 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
hodnota DWORD v datové oblasti obsahuje kód chyby Win32.
Error - 22. 9. 2010 4:25:41 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
hodnota DWORD v datové oblasti obsahuje kód chyby Win32.
Error - 22. 9. 2010 4:37:29 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
hodnota DWORD v datové oblasti obsahuje kód chyby Win32.
Error - 22. 9. 2010 4:37:29 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
hodnota DWORD v datové oblasti obsahuje kód chyby Win32.
Error - 22. 9. 2010 4:56:54 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
hodnota DWORD v datové oblasti obsahuje kód chyby Win32.
Error - 22. 9. 2010 4:56:55 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
hodnota DWORD v datové oblasti obsahuje kód chyby Win32.
Error - 22. 9. 2010 5:24:47 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
hodnota DWORD v datové oblasti obsahuje kód chyby Win32.
Error - 22. 9. 2010 5:24:47 | Computer Name = DANIK-PC | Source = Microsoft-Windows-LoadPerf | ID = 3006
Description = Nelze číst řetězce čítačů výkonu definované pro ID jazyka 005. První
hodnota DWORD v datové oblasti obsahuje kód chyby Win32.
[ System Events ]
Error - 22. 9. 2010 4:22:37 | Computer Name = DANIK-PC | Source = Service Control Manager | ID = 7034
Description = Služba NVIDIA Display Driver Service byla neočekávaně ukončena. Tento
stav nastal již 1krát.
Error - 22. 9. 2010 4:33:04 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 34001
Description =
Error - 22. 9. 2010 4:33:04 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 30013
Description =
Error - 22. 9. 2010 4:44:32 | Computer Name = DANIK-PC | Source = Service Control Manager | ID = 7034
Description = Služba NVIDIA Display Driver Service byla neočekávaně ukončena. Tento
stav nastal již 1krát.
Error - 22. 9. 2010 4:52:21 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 34001
Description =
Error - 22. 9. 2010 4:52:21 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 30013
Description =
Error - 22. 9. 2010 5:12:14 | Computer Name = DANIK-PC | Source = Service Control Manager | ID = 7034
Description = Služba NVIDIA Display Driver Service byla neočekávaně ukončena. Tento
stav nastal již 1krát.
Error - 22. 9. 2010 5:20:25 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 34001
Description =
Error - 22. 9. 2010 5:20:25 | Computer Name = DANIK-PC | Source = ipnathlp | ID = 30013
Description =
Error - 22. 9. 2010 5:32:39 | Computer Name = DANIK-PC | Source = Service Control Manager | ID = 7034
Description = Služba NVIDIA Display Driver Service byla neočekávaně ukončena. Tento
stav nastal již 1krát.
< End of report >
..v pripade potreby sem mozem hodit aj log OTL z toho konkretneho runu kedy mi k nemu vyplulo aj EXTRAS
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 112 hostů