HJT - neustále zapnutý program, chci ho zrušit Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: únor 09
Bydliště: Jihlava
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvekod Stene » 12 říj 2011 11:23

VirusTotal
http://www.virustotal.com/file-scan/rep ... 1318410054
C:\Windows\System32\Drivers\sprg.sys - jsem ve složce nenašel..
C:\Windows\system32\psxss.exe - jsem ve složce také nenašel..


Dále bude nutno odstranit:
C:\Windows\system32\DRIVERS\24752363.sys
C:\Windows\system32\DRIVERS\35631669.sys
C:\Windows\System32\Drivers\dump_atapi.sys
C:\Windows\System32\Drivers\dump_dumpata.sys
C:\Windows\System32\Drivers\dump_dumpfve.sys
-> mám smazat ručně?

24752363
35631669
catchme
S tímto mám dělat co?


Spouštím olt

Reklama
Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: únor 09
Bydliště: Jihlava
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvekod Stene » 12 říj 2011 11:28

OTL Extras logfile created on: 12.10.2011 11:23:18 - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Stene\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 2,61 Gb Available Physical Memory | 65,35% Memory free
7,99 Gb Paging File | 6,57 Gb Available in Paging File | 82,20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 489,03 Gb Total Space | 337,48 Gb Free Space | 69,01% Space Free | Partition Type: NTFS
Drive D: | 100,00 Mb Total Space | 70,37 Mb Free Space | 70,37% Space Free | Partition Type: NTFS
Drive E: | 246,09 Gb Total Space | 202,64 Gb Free Space | 82,34% Space Free | Partition Type: NTFS
Drive F: | 213,47 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
Drive G: | 196,29 Gb Total Space | 134,27 Gb Free Space | 68,40% Space Free | Partition Type: NTFS
Drive H: | 5,68 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: STENE-PC | User Name: Stene | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- Reg Error: Key error. File not found
.cmd [@ = cmdfile] -- Reg Error: Key error. File not found
.com [@ = ComFile] -- Reg Error: Key error. File not found
.exe [@ = exefile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.pif [@ = piffile] -- Reg Error: Key error. File not found
.vbs [@ = VBSFile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{38DCF0E4-948D-262D-88E6-57CDE6BB982A}" = ccc-utility64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{62BDA98E-352B-5244-FA5C-5C441EF799EB}" = ATI AVIVO64 Codecs
"{7EFF6FF7-45DE-A868-8300-615D7038879E}" = ATI Catalyst Install Manager
"{7F05E704-30A6-421A-97A7-8EEB1C7FF011}" = Corel Shell Extension - 64Bit
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0405-1000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2010
"{90140000-0016-0405-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2010
"{90140000-0018-0405-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2010
"{90140000-0019-0405-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2010
"{90140000-001A-0405-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2010
"{90140000-001B-0405-1000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2010
"{90140000-001F-0405-1000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2010
"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-041B-1000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2010
"{90140000-002C-0405-1000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0405-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Czech) 2010
"{90140000-0044-0405-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2010
"{90140000-006E-0405-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2010
"{90140000-00A1-0405-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2010
"{90140000-00BA-0405-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2010
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F62B016F-677E-0079-0052-18D45F186798}" = AMD Drag and Drop Transcoding
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.56
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.17
"FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"MAXONB6EC381C" = CINEMA 4D 11.532
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{7F05E704-30A6-421A-97A7-8EEB1C7FF010}" = CorelDRAW(R) Graphics Suite X4
"_{CE2DA11A-917F-4CF5-AB55-755EC115DD10}" = CorelDRAW(R) Graphics Suite X4 - Windows Shell Extension
"{03496F77-5835-D529-1ED8-044FCD372E0F}" = HydraVision
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08600005-5228-4BF6-845E-E9A957AFDCB4}" = OviMPlatform
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{1370D655-9DA3-EF82-FB57-BC5A2DCCD020}" = CCC Help Japanese
"{17D6207F-F9F4-1FDE-3F6B-C5B67CFD87C9}" = Catalyst Control Center Graphics Full New
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1DA18566-1084-CE33-5BC5-A214B8FC0CA4}" = CCC Help Norwegian
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22B4D0B5-81C5-ACE0-94CB-72E875B447A4}" = Catalyst Control Center Graphics Previews Common
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 23
"{293D5729-7C01-4FA4-A4DE-BB6A1587BBB9}" = PDF Settings
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{3553E875-F00E-4031-BDEC-75FB1DFEB093}" = Nokia Ovi Suite Software Updater
"{3557DE52-1836-4421-962C-F5C323FA57B7}" = Adobe Creative Suite 3 Design Premium
"{36ABE32F-D7D4-4A5E-AADD-589F506B1B50}" = Nokia Ovi Suite
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{39B00E05-32F6-4BC3-943E-EDEFD4CA3ACB}" = Adobe Version Cue CS3 Server
"{3D4AEA8C-3FD2-AB03-9E3A-F040B42E0BA3}" = CCC Help Portuguese
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}" = FIFA 11
"{4216D328-0FE8-48B8-85B8-BD300E6F080F}" = Nokia Connectivity Cable Driver
"{44136AFD-2559-F68C-10E3-AC269CE942A7}" = CCC Help Danish
"{44A27085-0616-4181-A0C3-81C7ECA17F73}" = CorelDRAW Graphics Suite X4
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46942F53-F6B5-E272-6989-0C75BBDF2668}" = CCC Help Chinese Standard
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EE4C1F0-B0BF-37CA-2555-ED586F17C5C9}" = Catalyst Control Center Graphics Previews Vista
"{5178C1BB-1EB1-4468-894B-7DE964DDCAA2}" = Adobe Photoshop CS3
"{53EBA2A9-50F2-16EB-3A44-C99BFF927032}" = Catalyst Control Center Graphics Light
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5629D545-08E1-516E-F498-082A72A5269D}" = CCC Help Polish
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5C329FB8-04D8-D32B-18B8-FA7594040FC0}" = CCC Help Dutch
"{6179A7D2-A668-4F1D-BC9A-DCC6A10C7871}" = Adobe Color NA Extra Settings
"{69916AD2-3710-4C86-895E-8F475290AA64}" = Ovi Desktop Sync Engine
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A0AEB7F-E55B-809B-0D05-F843032B75F7}" = Catalyst Control Center Graphics Full Existing
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6D12B99F-EAAA-49D8-8E2F-74FA7459CCB2}" = Adobe Asset Services CS3
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6F05FB49-2086-2FED-E2CC-824C189E9C75}" = CCC Help Russian
"{75F440C9-C292-1BA6-9755-C94F800657E9}" = ccc-core-static
"{7694E0B1-2332-448B-9235-929F84B41E3F}" = Active@ ISO Burner
"{77FD4E2C-EDDA-D622-6DAA-6DDE7B17DE85}" = Catalyst Control Center Localization All
"{7ACC5E2B-B543-2E93-F37D-A1390847FF29}" = CCC Help Thai
"{7B4A5C13-069F-4AFE-AE57-C497B4E33C7E}" = Call of Duty(R) 2 Patch 1.3
"{7EDFCB74-81C0-4FB6-9FDF-1BC7CD098638}" = Adobe InDesign CS3
"{7F05E704-30A6-421A-97A7-8EEB1C7FF010}" = CorelDRAW Graphics SUite X4 - ICA
"{7F05E704-30A6-421A-97A7-8EEB1C7FF012}" = CorelDRAW Graphics Suite X4 - Capture
"{7F05E704-30A6-421A-97A7-8EEB1C7FF013}" = CorelDRAW Graphics Suite X4 - Draw
"{7F05E704-30A6-421A-97A7-8EEB1C7FF014}" = CorelDRAW Graphics Suite X4 - PP
"{7F05E704-30A6-421A-97A7-8EEB1C7FF016}" = CorelDRAW Graphics Suite X4 - Content
"{7F05E704-30A6-421A-97A7-8EEB1C7FF017}" = CorelDRAW Graphics Suite X4 - Filters
"{7F05E704-30A6-421A-97A7-8EEB1C7FF019}" = CorelDRAW Graphics Suite X4 - FontNav
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{82EF29B1-9B60-4142-A155-0599216DD053}" = LightScribe System Software
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87323561-58BA-4D5B-BADA-A791B69D1705}" = Catalyst Control Center - Branding
"{878C6821-18F9-F6A2-42A7-1ACB1A14AF5C}" = CCC Help Hungarian
"{87AE7C09-B0B4-4BAC-AADB-50A1EAD03768}" = Adobe Flash Video Encoder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{919635D1-5C0D-4B64-B724-BDDB31D11029}" = Nero 8
"{946CC1D8-6E30-2A7C-3AC1-D433ED4FB00B}" = CCC Help Finnish
"{9773450C-E2F3-46C3-9464-1D7EDE5EFB63}" = Pro Evolution Soccer 2011
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9CDF34B4-B53E-54B5-9BA9-7FAA41693BF0}" = CCC Help Czech
"{9D0798D0-AF6C-4E62-94B1-AEBF1A43E00A}" = CorelDRAW Graphics Suite X4 - IPM
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A60ABB01-915B-E5A4-5120-0976C0D7697F}" = CCC Help English
"{A7238DAD-BF6A-3D96-8436-065A1175B39A}" = CCC Help Chinese Traditional
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1029-0000-7760-000000000003}" = Adobe Acrobat 8 Professional - Czech, Greek, Hungarian, Polish, Slovak
"{AC76BA86-7AD7-1029-7B44-AA0000000001}" = Adobe Reader X (10.0.1) - Czech
"{AE6BE2FE-5D3D-4FA0-98BC-57B7B78493F4}" = Adobe Flash CS3
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B2B123D3-E780-4EB0-B540-18F5FCC6EFE9}_is1" = ISO Image Burner 1.1
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B61D21B6-469D-4423-B161-62DB20B8A70E}" = Visual Basic for Applications (R) Core - English
"{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
"{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}" = Adobe BridgeTalk Plugin CS3
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}" = Adobe Flash Player 9 ActiveX
"{BD087F50-46B2-43E4-BD73-5DB3DC20B47C}" = Adobe Color EU Recommended Settings
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{BF439B41-0252-48DE-8B8B-0430CB26A181}" = CorelDRAW Graphics Suite X4 - VBA
"{C05290B3-B125-2481-BC4D-7C4BE5126DD5}" = CCC Help Korean
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C310995F-B785-4252-6A3B-333BA411DE6B}" = CCC Help French
"{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
"{CE2DA11A-917F-4CF5-AB55-755EC115DD10}" = CorelDRAW(R) Graphics Suite X4 - Windows Shell Extension
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D4AEC53C-1720-41D9-B6D7-6A60DE62D444}" = PC Connectivity Solution
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D6CD1A90-1421-4F19-AFD8-BE4E28A1D6D5}" = Adobe Illustrator CS3
"{D92B72E2-C854-4738-8ED6-4C3661CC17AE}" = Adobe Color JA Extra Settings
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DB81779E-7CC5-4630-BCFC-754004956444}" = Visual Basic for Applications (R) Core
"{E2082A6B-2334-2533-A5ED-41B537ECD02A}" = CCC Help German
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E84FA784-3305-5E34-16C8-51949D03C059}" = Catalyst Control Center InstallProxy
"{E9A28E0B-F85A-FFDA-C486-C0D34AD506AF}" = CCC Help Turkish
"{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
"{EC318F8C-CECC-B31E-44C4-55A1A63E41D5}" = CCC Help Greek
"{ECAD020B-3418-E868-FC8D-668FA6C6A019}" = Catalyst Control Center HydraVision Full
"{ED95B55C-4759-4242-85DE-EAD1DA7AB090}" = Adobe Dreamweaver CS3
"{F4B6FE67-B077-472E-1B06-0D50C8B05206}" = CCC Help Swedish
"{F4B70AA9-AA91-4894-4AC5-61A6934CD85B}" = Catalyst Control Center Core Implementation
"{F525FDB5-C9D4-6505-ACB9-90C921C83ACD}" = CCC Help Italian
"{FCEC4C5A-ACED-4644-B561-D7A3FB76ABEB}" = Adobe Setup
"{FE83F56A-D87F-E70E-AE6E-749DFBE27666}" = CCC Help Spanish
"{FFFE7261-2318-4227-B827-E9E05E16DFE5}" = CorelDRAW Graphics Suite X4 - Lang CZ
"Adobe Acrobat 8 Professional - Czech, Greek, Hungarian, Polish, Slovak" = Adobe Acrobat 8 Professional - Czech, Greek, Hungarian, Polish, Slovak
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_5d77a08a09fb71a9f854912b198353c" = Přidat nebo odebrat Adobe Creative Suite 3 Design Premium
"Altap Salamander 2.54" = Altap Salamander 2.54
"avast" = avast! Free Antivirus
"BitLord" = BitLord 1.1
"DAEMON Tools Lite" = DAEMON Tools Lite
"HD Tune Pro_is1" = HD Tune Pro 4.61
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"Mafia II_is1" = Mafia II
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware verze 1.51.2.1300
"Mozilla Firefox (3.6.23)" = Mozilla Firefox (3.6.23)
"Mozilla Thunderbird (7.0.1)" = Mozilla Thunderbird (7.0.1)
"Nokia Ovi Suite" = Nokia Ovi Suite
"PSPad editor_is1" = PSPad editor
"SLABCOMM&10C4&EA60" = Leadtek GPS USB to UART Bridge (Driver Removal)
"SpeedFan" = SpeedFan (remove only)
"WinRAR archiver" = WinRAR
"ZonerPhotoStudio12_CZ_is1" = Zoner Photo Studio 12

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"QIP Infium" = QIP Infium 3.0.9040

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11.10.2011 5:45:51 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 11.10.2011 5:45:51 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 11.10.2011 5:45:51 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 11.10.2011 5:45:51 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 4:05:53 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 4:05:53 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 4:05:53 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 4:05:53 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 5:19:48 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 5:21:42 | Computer Name = Stene-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: OTL.exe, verze: 3.2.29.1, časové razítko:
0x2a425e19 Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7601.17651, časové
razítko: 0x4e211319 Kód výjimky: 0x0eedfade Posun chyby: 0x0000b9bc ID chybujícího
procesu: 0x454 Čas spuštění chybující aplikace: 0x01cc88c058359cfa Cesta k chybující
aplikaci: C:\Users\Stene\Downloads\OTL.exe Cesta k chybujícímu modulu: C:\Windows\syswow64\KERNELBASE.dll
ID
zprávy: 983027c6-f4b3-11e0-b591-1c6f65488479

[ Media Center Events ]
Error - 14.3.2011 4:34:52 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 9:34:52 - Chyba při připojování k Internetu 9:34:52 - Nelze kontaktovat
server..

Error - 14.3.2011 4:34:58 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 9:34:57 - Chyba při připojování k Internetu 9:34:57 - Nelze kontaktovat
server..

Error - 14.3.2011 5:35:41 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 10:35:37 - Načtení položky Broadband se nezdařilo. (Chyba: Nadřízené
připojení bylo uzavřeno: Došlo k neočekávané chybě při příjmu.)

Error - 14.3.2011 6:35:47 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 11:35:46 - Chyba při připojování k Internetu 11:35:46 - Nelze kontaktovat
server..

Error - 3.4.2011 4:55:52 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 10:55:51 - Chyba při připojování k Internetu 10:55:52 - Nelze kontaktovat
server..

Error - 3.4.2011 4:56:00 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 10:55:57 - Chyba při připojování k Internetu 10:55:57 - Nelze kontaktovat
server..

Error - 7.5.2011 0:03:39 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 6:03:38 - Chyba při připojování k Internetu 6:03:38 - Nelze kontaktovat
server..

Error - 7.5.2011 0:03:48 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 6:03:44 - Chyba při připojování k Internetu 6:03:44 - Nelze kontaktovat
server..

[ System Events ]
Error - 3.10.2011 15:46:56 | Computer Name = Stene-PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.

Error - 3.10.2011 15:48:40 | Computer Name = Stene-PC | Source = Application Popup | ID = 1060
Description = Načtení \??\C:\ComboFix\catchme.sys bylo zablokováno kvůli nekompatibilitě
s tímto systémem. Požádejte dodavatele softwaru o kompatibilní verzi ovladače.

Error - 3.10.2011 15:48:41 | Computer Name = Stene-PC | Source = Application Popup | ID = 1060
Description = Načtení \??\C:\ComboFix\catchme.sys bylo zablokováno kvůli nekompatibilitě
s tímto systémem. Požádejte dodavatele softwaru o kompatibilní verzi ovladače.

Error - 3.10.2011 15:49:12 | Computer Name = Stene-PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.

Error - 8.10.2011 10:34:36 | Computer Name = Stene-PC | Source = DCOM | ID = 10010
Description =

Error - 10.10.2011 4:30:04 | Computer Name = Stene-PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.

Error - 10.10.2011 4:31:52 | Computer Name = Stene-PC | Source = Application Popup | ID = 1060
Description = Načtení \??\C:\ComboFix\catchme.sys bylo zablokováno kvůli nekompatibilitě
s tímto systémem. Požádejte dodavatele softwaru o kompatibilní verzi ovladače.

Error - 10.10.2011 4:31:52 | Computer Name = Stene-PC | Source = Application Popup | ID = 1060
Description = Načtení \??\C:\ComboFix\catchme.sys bylo zablokováno kvůli nekompatibilitě
s tímto systémem. Požádejte dodavatele softwaru o kompatibilní verzi ovladače.

Error - 10.10.2011 4:32:19 | Computer Name = Stene-PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.

Error - 11.10.2011 4:13:56 | Computer Name = Stene-PC | Source = DCOM | ID = 10010
Description =


< End of report >

Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: únor 09
Bydliště: Jihlava
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvekod Stene » 12 říj 2011 11:29

OTL logfile created on: 12.10.2011 11:23:18 - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Stene\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 2,61 Gb Available Physical Memory | 65,35% Memory free
7,99 Gb Paging File | 6,57 Gb Available in Paging File | 82,20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 489,03 Gb Total Space | 337,48 Gb Free Space | 69,01% Space Free | Partition Type: NTFS
Drive D: | 100,00 Mb Total Space | 70,37 Mb Free Space | 70,37% Space Free | Partition Type: NTFS
Drive E: | 246,09 Gb Total Space | 202,64 Gb Free Space | 82,34% Space Free | Partition Type: NTFS
Drive F: | 213,47 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
Drive G: | 196,29 Gb Total Space | 134,27 Gb Free Space | 68,40% Space Free | Partition Type: NTFS
Drive H: | 5,68 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: STENE-PC | User Name: Stene | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Stene\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\js3250.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (Adobe Version Cue CS3) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys (Nokia)
DRV:64bit: - (upperdev) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (nmwcdc) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (nmwcd) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (silabser) -- C:\Windows\SysNative\drivers\silabser.sys (Silicon Laboratories)
DRV:64bit: - (silabenm) -- C:\Windows\SysNative\drivers\silabenm.sys (Silicon Laboratories, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (speedfan) -- C:\Windows\SysWOW64\speedfan.sys (Windows (R) Server 2003 DDK provider)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "QIP Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.2.2
FF - prefs.js..extensions.enabledItems: ranky@ranky.cz:0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.10.2
FF - prefs.js..extensions.enabledItems: {3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}:0.8.6.1
FF - prefs.js..extensions.enabledItems: cs@dictionaries.addons.mozilla.org:1.0.2
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Stene\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Stene\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010.12.25 10:56:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.09.29 16:31:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.09.29 16:31:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.09.23 23:28:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010.12.25 10:56:50 | 000,000,000 | ---D | M]

[2011.03.06 19:32:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions
[2011.03.06 19:32:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.11.02 18:11:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2011.10.11 22:53:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions
[2011.02.26 12:11:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
[2011.05.25 21:14:06 | 000,000,000 | ---D | M] (Html Validator) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}
[2010.11.12 12:12:26 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2011.02.26 12:11:40 | 000,000,000 | ---D | M] (Page Speed) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2011.06.24 20:02:28 | 000,000,000 | ---D | M] (České slovníky pro kontrolu pravopisu) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\cs@dictionaries.addons.mozilla.org
[2011.01.22 19:18:07 | 000,000,000 | ---D | M] (Ranky) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\ranky@ranky.cz
[2011.03.09 17:23:05 | 000,002,059 | ---- | M] () -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\searchplugins\daemon-search.xml
[2010.11.06 18:31:33 | 000,002,062 | ---- | M] () -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\searchplugins\qip-search.xml
[2011.10.03 16:01:04 | 000,001,391 | ---- | M] () -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\searchplugins\yahoo-zugo.xml
[2011.01.25 19:27:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011.09.29 16:31:11 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011.01.25 19:27:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.09.29 16:31:10 | 000,025,048 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2011.09.29 16:31:10 | 000,140,248 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2007.04.10 18:21:08 | 000,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll
[2011.01.25 19:27:01 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.09.29 16:31:10 | 000,066,520 | ---- | M] (mozilla.org) -- C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2011.01.30 17:45:12 | 000,135,568 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2011.08.21 21:18:35 | 000,002,371 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2011.08.21 21:18:35 | 000,000,638 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\jyxo-cz.xml
[2011.08.21 21:18:35 | 000,001,687 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\mall-cz.xml
[2011.08.21 21:18:35 | 000,001,367 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\seznam-cz.xml
[2011.08.21 21:18:35 | 000,000,654 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.08.21 21:18:35 | 000,001,179 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-cz.xml

========== Chrome ==========

CHR - default_search_provider: Yahoo (Enabled)
CHR - default_search_provider: search_url = http://www.etypestart.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=697&product_id=730&affiliate_id=&channel=&toolbar_id=205&toolbar_version=2.3.0&install_country=CZ&install_date=20111003&user_guid=93D1C7CAC2BF44DE9C2E21F710E5670E&machine_id=51d5f038087191619d0d0687cdd24d34&browser=CR&os=win&os_version=6.1-x64-SP1
CHR - default_search_provider: suggest_url = ,
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Stene\AppData\Local\Google\Chrome\Application\8.0.552.224\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\Stene\AppData\Local\Google\Chrome\Application\8.0.552.224\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Stene\AppData\Local\Google\Chrome\Application\8.0.552.224\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Users\Stene\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2011.10.10 10:33:42 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Podpora odkazu pro Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\SysWow64\grpconv.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Thunderbird.lnk = C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
O4 - Startup: C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk = C:\Users\Stene\AppData\Local\Temp\_uninst_77286306.bat ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Od&eslat do aplikace OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8:64bit: - Extra context menu item: Převést cíl vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést cíl vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést výběr do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést výběr do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést vybrané vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést vybrané vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Přidat do stávajícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Od&eslat do aplikace OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést výběr do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést výběr do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Přidat do stávajícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9:64bit: - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{538B7099-999C-48D3-A0BF-FEE2AC80D8DC}: NameServer = 10.0.0.138
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysNative\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O29:64bit: - HKLM SecurityProviders - (credssp.dll) -C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) -C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) -C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) -C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) -C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) -C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) -C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) -C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) -C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.05.25 15:35:32 | 000,000,030 | R--- | M] () - F:\Autorun.inf -- [ UDF ]
O32 - AutoRun File - [2011.03.09 18:49:10 | 000,000,000 | ---- | M] () - G:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.08.17 06:32:28 | 000,000,047 | R--- | M] () - H:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2010.08.17 06:32:28 | 000,335,752 | R--- | M] (Konami Digital Entertainment Co., Ltd.) - H:\autorun.exe -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...com [@ = ComFile] -- Reg Error: Key error. File not found
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011.10.12 11:21:23 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Users\Stene\Desktop\OTL.exe
[2011.10.11 10:26:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2011.10.10 10:50:17 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011.10.03 16:18:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.10.03 16:18:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.10.03 16:13:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2011.10.03 16:13:09 | 000,000,000 | ---D | C] -- C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011.10.03 16:01:13 | 000,000,000 | ---D | C] -- C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eType
[2011.10.03 16:00:30 | 000,000,000 | ---D | C] -- C:\Users\Stene\AppData\Roaming\eType
[2011.09.22 21:03:07 | 000,000,000 | R--D | C] -- C:\Users\Stene\Desktop\písničky
[2011.09.21 15:48:01 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2011.09.21 15:47:06 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders

========== Files - Modified Within 30 Days ==========

[2011.10.12 11:21:26 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Stene\Desktop\OTL.exe
[2011.10.12 11:09:06 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.10.12 10:33:01 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1679234959-3771141595-1235745478-1001UA.job
[2011.10.12 10:09:57 | 000,014,832 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.10.12 10:09:57 | 000,014,832 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.10.12 10:09:00 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.10.12 10:02:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.10.12 10:02:11 | 3219,300,352 | -HS- | M] () -- C:\hiberfil.sys
[2011.10.12 00:38:42 | 000,011,310 | ---- | M] () -- C:\Users\Stene\Desktop\avptool_sysinfo.zip
[2011.10.11 18:33:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1679234959-3771141595-1235745478-1001Core.job
[2011.10.11 10:33:18 | 000,001,010 | ---- | M] () -- C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk
[2011.10.11 10:26:25 | 098,427,064 | ---- | M] () -- C:\Users\Stene\Desktop\setup_11.0.0.1245.x01_2011_10_11_09_31.exe
[2011.10.10 10:33:42 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011.10.08 16:34:33 | 000,001,471 | ---- | M] () -- C:\Users\Stene\Desktop\ComboFix – zástupce.lnk
[2011.10.08 16:34:08 | 000,095,622 | ---- | M] () -- C:\Users\Stene\Desktop\3.jpg
[2011.10.08 16:34:07 | 000,088,940 | ---- | M] () -- C:\Users\Stene\Desktop\5.jpg
[2011.10.08 16:34:07 | 000,088,920 | ---- | M] () -- C:\Users\Stene\Desktop\4.jpg
[2011.10.08 16:34:07 | 000,072,817 | ---- | M] () -- C:\Users\Stene\Desktop\6.jpg
[2011.10.03 16:18:59 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.10.03 16:13:09 | 000,002,975 | ---- | M] () -- C:\Users\Stene\Desktop\HiJackThis.lnk
[2011.10.01 20:24:44 | 000,001,400 | ---- | M] () -- C:\Users\Stene\AppData\Local\SRDownloader.nast
[2011.09.28 19:25:10 | 002,381,802 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2011.09.28 19:25:10 | 001,222,980 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.09.28 19:25:10 | 000,712,846 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2011.09.28 19:25:10 | 000,680,344 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.09.28 19:25:10 | 000,005,374 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.09.24 17:06:44 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011.09.22 15:22:59 | 002,349,040 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.09.21 15:56:00 | 000,175,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msclmd.dll
[2011.09.21 15:56:00 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msclmd.dll

========== Files Created - No Company Name ==========

[2011.10.12 00:40:06 | 000,011,310 | ---- | C] () -- C:\Users\Stene\Desktop\avptool_sysinfo.zip
[2011.10.11 10:33:18 | 000,001,010 | ---- | C] () -- C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk
[2011.10.11 10:25:05 | 098,427,064 | ---- | C] () -- C:\Users\Stene\Desktop\setup_11.0.0.1245.x01_2011_10_11_09_31.exe
[2011.10.08 20:03:32 | 1254,821,888 | ---- | C] () -- C:\Users\Stene\Desktop\Letopisy Narnie - Lev, čarodějnice a skříň (2005) .avi
[2011.10.08 16:34:07 | 000,095,622 | ---- | C] () -- C:\Users\Stene\Desktop\3.jpg
[2011.10.08 16:34:06 | 000,088,920 | ---- | C] () -- C:\Users\Stene\Desktop\4.jpg
[2011.10.08 16:34:05 | 000,088,940 | ---- | C] () -- C:\Users\Stene\Desktop\5.jpg
[2011.10.08 16:34:05 | 000,072,817 | ---- | C] () -- C:\Users\Stene\Desktop\6.jpg
[2011.10.03 21:42:14 | 000,001,471 | ---- | C] () -- C:\Users\Stene\Desktop\ComboFix – zástupce.lnk
[2011.10.03 16:18:59 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.10.03 16:13:09 | 000,002,975 | ---- | C] () -- C:\Users\Stene\Desktop\HiJackThis.lnk
[2011.10.03 15:52:23 | 1806,571,519 | ---- | C] () -- C:\Users\Stene\Desktop\rld-pe11.iso
[2011.09.23 23:28:38 | 000,002,106 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2011.08.15 19:13:15 | 000,001,400 | ---- | C] () -- C:\Users\Stene\AppData\Local\SRDownloader.nast
[2011.08.10 11:29:13 | 000,000,600 | ---- | C] () -- C:\Users\Stene\AppData\Roaming\winscp.rnd
[2011.08.01 21:08:54 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011.08.01 21:08:54 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011.08.01 21:08:54 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.08.01 21:08:54 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.08.01 21:08:54 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.06.02 21:46:41 | 000,005,994 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.05.12 10:40:31 | 000,004,608 | ---- | C] () -- C:\Users\Stene\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.05 09:54:20 | 000,000,008 | RHS- | C] () -- C:\ProgramData\DB013D6F68.sys
[2011.04.01 16:19:59 | 000,000,194 | ---- | C] () -- C:\Users\Stene\AppData\Roaming\varicad-work.ini
[2011.03.30 19:26:22 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011.03.13 13:15:59 | 000,000,161 | ---- | C] () -- C:\Windows\AutoKMS.ini
[2011.01.21 16:44:17 | 000,000,126 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.12.21 18:01:22 | 000,000,026 | ---- | C] () -- C:\Windows\Irremote.ini
[2010.11.05 19:29:01 | 002,463,976 | ---- | C] () -- C:\Windows\SysWow64\NPSWF32.dll
[2010.11.02 18:40:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.11.02 18:27:07 | 000,000,256 | ---- | C] () -- C:\Windows\game.ini
[2010.11.02 18:11:20 | 000,002,110 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2010.11.09 09:49:55 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Atrise
[2010.11.09 11:42:40 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\DAEMON Tools Lite
[2011.02.19 11:12:31 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Emergency Soft
[2011.10.03 21:48:41 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\eType
[2011.08.17 19:36:56 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\HD Tune Pro
[2011.04.16 19:38:58 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Hulubulu
[2011.04.16 21:52:03 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Jpeg Resampler
[2010.12.12 22:02:17 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Leadertech
[2011.04.01 15:53:21 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\MAXON
[2010.12.25 11:05:27 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\PC Suite
[2011.03.06 19:32:51 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Thunderbird
[2011.04.01 16:20:00 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\VariCAD
[2010.12.29 11:41:48 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Zoner
[2011.07.29 09:04:58 | 000,032,522 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvekod jaro3 » 12 říj 2011 15:00

Toto otestuj na Virustotal
C:\Program Files\Alwil Software\Avast5\defs\11101102\algo.dll
C:\Windows\System32\Drivers\sprg.sys
C:\Windows\system32\psxss.exe


vlož jen tu cestu a nehledej ty soubory...

Error - 11.10.2011 5:45:51 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .


nemáš problém s aktualizacemi?? Napiš , jinak s tím nic dělat nebudu..

Po VT vložím script.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: únor 09
Bydliště: Jihlava
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvekod Stene » 12 říj 2011 22:36

I když vložím jenom cestu, nic to nenajde..
tyhle dna soubory prostě nemůžu najít.. Na ty aktualizace kouknu..

// Tak nějakej problém to hlásilo, ale po ručním nainstalování nějakého fixu to noc nehlásí (jinak aktualizace se podle historie stahuju bez problému)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvekod jaro3 » 12 říj 2011 23:48

Fajn!

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
FF - prefs.js..browser.search.defaultenginename: "QIP Search"
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.2.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.10.2
FF - prefs.js..extensions.enabledItems: {3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}:0.8.6.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
[2011.03.06 19:32:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions
[2011.03.06 19:32:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.11.02 18:11:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2011.10.11 22:53:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions
[2011.02.26 12:11:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
[2011.01.25 19:27:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
CHR - default_search_provider: search_url = http://www.etypestart.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=697&product_id=730&affiliate_id=&channel=&toolbar_id=205&toolbar_version=2.3.0&install_country=CZ&install_date=20111003&user_guid=93D1C7CAC2BF44DE9C2E21F710E5670E&machine_id=51d5f038087191619d0d0687cdd24d34&browser=CR&os=win&os_version=6.1-x64-SP1
CHR - default_search_provider: suggest_url = ,
O1 HOSTS File: ([2011.10.10 10:33:42 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - Startup: C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk = C:\Users\Stene\AppData\Local\Temp\_uninst_77286306.bat ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - AutoRun File - [2010.05.25 15:35:32 | 000,000,030 | R--- | M] () - F:\Autorun.inf -- [ UDF ]
O32 - AutoRun File - [2011.03.09 18:49:10 | 000,000,000 | ---- | M] () - G:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.08.17 06:32:28 | 000,000,047 | R--- | M] () - H:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2010.08.17 06:32:28 | 000,335,752 | R--- | M] (Konami Digital Entertainment Co., Ltd.) - H:\autorun.exe -- [ CDFS ]
[2011.09.28 19:25:10 | 002,381,802 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2011.09.28 19:25:10 | 001,222,980 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.09.28 19:25:10 | 000,712,846 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2011.09.28 19:25:10 | 000,680,344 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
c:\windows\Tasks\*.job
C:\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\ProgramData\Kaspersky Lab
C:\Users\Stene\AppData\Roaming\eType
C:\Users\Stene\Desktop\avptool_sysinfo.zip
C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk
C:\Users\Stene\Desktop\setup_11.0.0.1245.x01_2011_10_11_09_31.exe
C:\Windows\PEV.exe
C:\Windows\MBR.exe
C:\Windows\sed.exe
C:\Windows\grep.exe
C:\Windows\zip.exe
C:\Users\Stene\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\ProgramData\DB013D6F68.sys
C:\Windows\ativpsrm.bin
C:\Windows\system32\DRIVERS\24752363.sys
C:\Windows\system32\DRIVERS\35631669.sys
C:\Windows\System32\Drivers\dump_atapi.sys
C:\Windows\System32\Drivers\dump_dumpata.sys
C:\Windows\System32\Drivers\dump_dumpfve.sys

:Services
24752363
35631669
catchme

:Reg
:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

Aktualizuj javu:
Java SE Runtime Environment 7

Klikni na Accept License Agreement
Vyber si OS (Windows nebo Windows x64, Offline Installation)
jre-7-windows-i586-p.exe nebo
jre-7-windows-x64.exe
Stáhni ( download) a nainstaluj.
Ostatní javy odeber v přidat/odebrat programy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: únor 09
Bydliště: Jihlava
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvekod Stene » 13 říj 2011 10:46

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Prefs.js: "QIP Search" removed from browser.search.defaultenginename
Prefs.js: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.2.2 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 removed from extensions.enabledItems
Prefs.js: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.10.2 removed from extensions.enabledItems
Prefs.js: {3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}:0.8.6.1 removed from extensions.enabledItems
Prefs.js: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23 removed from extensions.enabledItems
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Extensions folder moved successfully.
Folder C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}\ not found.
Folder C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\ not found.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\WINNT_x86-msvc\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\WINNT_x86-msvc folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Linux_x86_64-gcc3\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Linux_x86_64-gcc3 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Linux_x86-gcc3\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Linux_x86-gcc3 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Darwin_x86-gcc3\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Darwin_x86-gcc3 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\defaults\preferences folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\defaults folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\chrome\third_party\content folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\chrome\third_party folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\chrome\pagespeed\content folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\chrome\pagespeed folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\chrome folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\Linux\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\Linux folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\Darwin\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\Darwin folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\defaults\preferences folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\defaults\palettes folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\defaults folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\chrome folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\skin folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\WD-XHTMLplusMathMLplusSVG-20020809 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\WD-xhtml11-20070216 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\WD-xhtml-basic-20060705 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-xhtml11-20010531 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-xhtml1-20020801 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-xhtml-print-20060920 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-xhtml-basic-20080729 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-xhtml-basic-20001219 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-SVG11-20030114 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-SVG-20010904 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-smil20-20050107 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-SMIL2-20051213 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-smil-19980615 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-MathML2-20031021\mathml folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-MathML2-20031021\iso9573-13 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-MathML2-20031021\iso8879 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-MathML2-20031021\html folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-MathML2-20031021 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-html401-19991224 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-html40-19980424 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-html32-19970114 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\ISO-HTML folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\IETF folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\zh-TW\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\zh-TW folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\zh-CN\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\zh-CN folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\sl-SI\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\sl-SI folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\sk-SK\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\sk-SK folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ru-RU\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ru-RU folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ro-RO\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ro-RO folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\pt-BR\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\pt-BR folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\pl-PL\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\pl-PL folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\nl-NL\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\nl-NL folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\lt-LT\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\lt-LT folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ko-KR\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ko-KR folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ja-JP\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ja-JP folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\it-IT\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\it-IT folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\hu-HU\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\hu-HU folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\fr-FR\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\fr-FR folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\fi-FI\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\fi-FI folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\en-US\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\en-US folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\de-DE\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\de-DE folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\da-DK\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\da-DK folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\cs-CZ\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\cs-CZ folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\content\tidy\help\fr-FR folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\content\tidy\help\en-US folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\content\tidy\help folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\content\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\content folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\defaults\preferences folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\defaults folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\chrome\locale\en-US folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\chrome\locale folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\chrome\content folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\chrome folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\ranky@ranky.cz\chrome\skin folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\ranky@ranky.cz\chrome\content folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\ranky@ranky.cz\chrome folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\ranky@ranky.cz folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\cs@dictionaries.addons.mozilla.org\dictionaries folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\cs@dictionaries.addons.mozilla.org folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions folder moved successfully.
Folder C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\ not found.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-TW folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-CN folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\sv-SE folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ko-KR folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ja-JP folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\it-IT folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\fr-FR folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\es-ES folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\en-US folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\de-DE folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\content\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\content folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions folder moved successfully.
Unable to fix default_search_provider items.
Unable to fix default_search_provider items.
127.0.0.1 localhost removed from HOSTS file successfully
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95289393-33EA-4F8D-B952-483415B9C955}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
File move failed. C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk scheduled to be moved on reboot.
File C:\Users\Stene\AppData\Local\Temp\_uninst_77286306.bat not found.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
File move failed. F:\Autorun.inf scheduled to be moved on reboot.
G:\AUTOEXEC.BAT moved successfully.
File move failed. H:\Autorun.inf scheduled to be moved on reboot.
File move failed. H:\autorun.exe scheduled to be moved on reboot.
C:\Windows\SysNative\perfh005.dat moved successfully.
C:\Windows\SysNative\perfh009.dat moved successfully.
C:\Windows\SysNative\perfc005.dat moved successfully.
C:\Windows\SysNative\perfc009.dat moved successfully.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1679234959-3771141595-1235745478-1001Core.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1679234959-3771141595-1235745478-1001UA.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
File\Folder C:\Windows\SysNative\drivers\*.tmp not found.
File\Folder C:\Windows\SysWow64\drivers\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
File\Folder C:\Windows\SysWow64\*.tmp not found.
File\Folder C:\Windows\SysNative\*.tmp not found.
C:\ProgramData\Kaspersky Lab folder moved successfully.
C:\Users\Stene\AppData\Roaming\eType folder moved successfully.
C:\Users\Stene\Desktop\avptool_sysinfo.zip moved successfully.
File\Folder C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk not found.
C:\Users\Stene\Desktop\setup_11.0.0.1245.x01_2011_10_11_09_31.exe moved successfully.
C:\Windows\PEV.exe moved successfully.
C:\Windows\MBR.exe moved successfully.
C:\Windows\sed.exe moved successfully.
C:\Windows\grep.exe moved successfully.
C:\Windows\zip.exe moved successfully.
C:\Users\Stene\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\ProgramData\DB013D6F68.sys moved successfully.
C:\Windows\ativpsrm.bin moved successfully.
File\Folder C:\Windows\system32\DRIVERS\24752363.sys not found.
File\Folder C:\Windows\system32\DRIVERS\35631669.sys not found.
File\Folder C:\Windows\System32\Drivers\dump_atapi.sys not found.
File\Folder C:\Windows\System32\Drivers\dump_dumpata.sys not found.
File\Folder C:\Windows\System32\Drivers\dump_dumpfve.sys not found.
========== SERVICES/DRIVERS ==========
Error: No service named 24752363 was found to stop!
Service\Driver key 24752363 not found.
Error: No service named 35631669 was found to stop!
Service\Driver key 35631669 not found.
Service catchme stopped successfully!
Service catchme deleted successfully!
========== REGISTRY ==========
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Stene
->Temp folder emptied: 287410 bytes
->Temporary Internet Files folder emptied: 635704 bytes
->Java cache emptied: 397798 bytes
->FireFox cache emptied: 92652787 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 4476 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16447498 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50708 bytes
RecycleBin emptied: 1254882576 bytes

Total Files Cleaned = 1 302,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: Stene
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.29.1 log created on 10132011_104251

Files\Folders moved on Reboot...
File\Folder C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk not found!
File move failed. F:\Autorun.inf scheduled to be moved on reboot.
File\Folder H:\Autorun.inf not found!
File\Folder H:\autorun.exe not found!
C:\Users\Stene\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...



Javu jsem aktualizoval...

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvekod jaro3 » 13 říj 2011 11:29

Spusť OTL a klikni na Vyčisti.
Pak můžeš OTL smazat , C:\_OTL

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
gordonisk
nováček
Příspěvky: 5
Registrován: říjen 11
Pohlaví: Muž
Stav:
Offline

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvekod gordonisk » 13 říj 2011 11:33

myslim ze ked das reinstal , budes to mat jednoduchsie :)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvekod jaro3 » 13 říj 2011 19:02

gordonisk: přečti si laskavě pravidla sekce HJT:
viewtopic.php?f=70&t=29204

Rady typu přeinstaluj si systém ap. si raději nech pro sebe!
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: únor 09
Bydliště: Jihlava
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: HJT - neustále zapnutý program, chci ho zrušit  Vyřešeno

Příspěvekod Stene » 14 říj 2011 13:51

Jaro3, mnohokrát děkuji!! :inlove:

gordonisk: Máš trefné rady. Přeinstaluju windows a budu ho měsíc dávat do stavu, v jakém ho mám dnes..


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 36 hostů