prosím o kontrolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

mafian
Level 3.5
Level 3.5
Příspěvky: 770
Registrován: leden 07
Pohlaví: Muž
Stav:
Offline

prosím o kontrolu logu

Příspěvekod mafian » 28 črc 2012 18:33

zdravím prosím o kontrolu logu opět mi nefunguje google a internet je zpomalený.děkuji za případnou pomoc.pc projeto a vyčištěno ATF a CCleaner

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:32:32, on 28.7.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe
C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\OO Software\Defrag\oodag.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
C:\Program Files\Acronis\DiskDirector\OSS\reinstall_svc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe
C:\Documents and Settings\uživatel\Dokumenty\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\NUCLEA~1\VideoGet\Plugins\VIDEOG~1.DLL
O9 - Extra 'Tools' menuitem: Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\NUCLEA~1\VideoGet\Plugins\VIDEOG~1.DLL
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E0A2D612-9559-4215-AAD7-1B34697AC779}: NameServer = 10.0.0.138
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: ABBYY FineReader 11 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.11.0) - ABBYY - C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe
O23 - Service: ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: O&O Defrag Agent (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: Aktivátor Správce výběru OS Acronis (Správce výběru OS) - Unknown owner - C:\Program Files\Acronis\DiskDirector\OSS\reinstall_svc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: vToolbarUpdater11.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe

--
End of file - 8344 bytes

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Verze databáze: v2012.07.22.08

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
uživatel :: ADMIN [administrátor]

28.7.2012 18:35:16
mbam-log-2012-07-28 (18-35-16).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 219474
Uplynulý čas: 2 minut, 28 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)
Naposledy upravil(a) mafian dne 28 črc 2012 18:38, celkem upraveno 1 x.

Reklama
Uživatelský avatar
bledulka
Level 5
Level 5
Příspěvky: 2242
Registrován: srpen 09
Pohlaví: Žena
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod bledulka » 28 črc 2012 23:31

Ahoj,
na google uděláš ping nebo ne?

Stáhni OTL
http://oldtimer.geekstogo.com/OTL.exe
-do spodního okénka vlož tento skript:

Kód: Vybrat vše

netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
/md5stop
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c

-dej fajfku do čtverečku u řádku Pro všechny uživatele
-nech ostatní položky jak je nastaveno na screenu
- potvrď tlačítko Prohledat.
-provede se sken, log OTL.Txt sem vlož

Obrázek

mafian
Level 3.5
Level 3.5
Příspěvky: 770
Registrován: leden 07
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod mafian » 29 črc 2012 09:51

jo
ping udělat jde.je divný že všechny ostatní stránky jdou jen google ne a to jsem zkoušel jak v opeře,tak IE,chrome.


OTL logfile created on: 29.7.2012 9:52:10 - Run 2
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Documents and Settings\uživatel\Dokumenty
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,25 Gb Total Physical Memory | 2,54 Gb Available Physical Memory | 78,15% Memory free
5,09 Gb Paging File | 4,35 Gb Available in Paging File | 85,50% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68,36 Gb Total Space | 29,89 Gb Free Space | 43,72% Space Free | Partition Type: NTFS
Drive D: | 59,63 Gb Total Space | 37,03 Gb Free Space | 62,11% Space Free | Partition Type: NTFS
Drive F: | 337,77 Gb Total Space | 117,35 Gb Free Space | 34,74% Space Free | Partition Type: NTFS
Drive G: | 127,99 Gb Total Space | 46,14 Gb Free Space | 36,05% Space Free | Partition Type: NTFS
Drive I: | 68,36 Gb Total Space | 40,20 Gb Free Space | 58,80% Space Free | Partition Type: NTFS
Drive K: | 171,77 Gb Total Space | 42,29 Gb Free Space | 24,62% Space Free | Partition Type: NTFS
Drive L: | 97,65 Gb Total Space | 47,98 Gb Free Space | 49,13% Space Free | Partition Type: NTFS

Computer Name: ADMIN | User Name: uživatel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2012.07.29 09:42:56 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\uživatel\Dokumenty\OTL.exe
PRC - [2012.07.09 15:19:15 | 000,935,008 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
PRC - [2012.07.09 15:19:14 | 001,107,552 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2012.07.09 10:14:24 | 000,874,384 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2012.07.09 10:14:24 | 000,800,656 | ---- | M] (Opera Software) -- C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe
PRC - [2012.01.24 17:24:26 | 002,416,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2011.12.12 15:07:00 | 000,793,048 | ---- | M] (PC Tools) -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
PRC - [2011.11.28 01:19:04 | 001,229,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011.11.17 19:03:50 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2011.11.17 18:18:00 | 002,773,328 | ---- | M] (O&O Software GmbH) -- C:\Program Files\OO Software\Defrag\oodtray.exe
PRC - [2011.11.17 18:17:46 | 002,489,680 | ---- | M] (O&O Software GmbH) -- C:\Program Files\OO Software\Defrag\oodag.exe
PRC - [2011.10.10 12:55:04 | 000,085,344 | ---- | M] (Software602 a.s.) -- C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
PRC - [2011.09.08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011.08.18 15:47:48 | 000,819,976 | ---- | M] (ABBYY) -- C:\Program Files\ABBYY FineReader 11\NetworkLicenseServer.exe
PRC - [2011.08.15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011.08.12 01:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2011.08.02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2010.10.28 20:31:58 | 002,156,952 | ---- | M] () -- C:\Program Files\Acronis\DiskDirector\OSS\reinstall_svc.exe
PRC - [2009.12.23 23:34:20 | 000,370,688 | ---- | M] (StarWind Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2009.12.03 10:12:12 | 000,976,320 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\Event Manager\EEventManager.exe
PRC - [2009.05.14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
PRC - [2008.04.14 09:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.12.06 22:03:41 | 000,660,768 | ---- | M] (ABBYY (BIT Software)) -- C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012.07.27 13:34:27 | 009,465,032 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll
MOD - [2012.07.09 15:19:16 | 000,132,704 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\SiteSafety.dll
MOD - [2012.07.09 15:19:15 | 000,935,008 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
MOD - [2012.07.09 15:19:14 | 001,107,552 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2010.10.28 20:31:58 | 002,156,952 | ---- | M] () -- C:\Program Files\Acronis\DiskDirector\OSS\reinstall_svc.exe
MOD - [2008.04.14 09:51:48 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2001.10.28 18:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2012.07.27 13:34:27 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.07.09 15:19:15 | 000,935,008 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe -- (vToolbarUpdater11.2.0)
SRV - [2011.12.12 15:07:00 | 000,793,048 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2011.11.17 19:03:50 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2011.11.17 18:17:46 | 002,489,680 | ---- | M] (O&O Software GmbH) [Auto | Running] -- C:\Program Files\OO Software\Defrag\oodag.exe -- (OODefragAgent)
SRV - [2011.10.10 12:55:04 | 000,085,344 | ---- | M] (Software602 a.s.) [Auto | Running] -- C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe -- (602XML Updater)
SRV - [2011.08.12 01:38:07 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore.exe -- (!SASCORE)
SRV - [2011.08.02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2010.10.28 20:31:58 | 002,156,952 | ---- | M] () [Auto | Running] -- C:\Program Files\Acronis\DiskDirector\OSS\reinstall_svc.exe -- (Správce výběru OS)
SRV - [2009.12.23 23:34:20 | 000,370,688 | ---- | M] (StarWind Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2009.05.14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2012.05.14 08:12:12 | 000,103,040 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtihdXP3.sys -- (AtiHDAudioService)
DRV - [2012.03.09 08:22:00 | 007,586,304 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2012.02.13 15:32:24 | 000,094,064 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mdm.sys -- (w810mdm)
DRV - [2012.02.13 15:32:24 | 000,085,408 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mgmt.sys -- (w810mgmt)
DRV - [2012.02.13 15:32:24 | 000,083,344 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810obex.sys -- (w810obex)
DRV - [2012.02.13 15:32:24 | 000,058,288 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810bus.sys -- (w810bus)
DRV - [2012.02.13 15:32:24 | 000,008,336 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w810mdfl.sys -- (w810mdfl)
DRV - [2012.01.10 18:21:50 | 000,239,168 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012.01.04 17:12:19 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2011.12.29 12:29:20 | 000,166,976 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\snapman.sys -- (snapman)
DRV - [2011.10.07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011.09.13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2011.08.08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011.07.22 18:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011.07.12 23:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011.07.11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011.07.11 01:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV - [2009.06.29 15:32:28 | 000,054,792 | ---- | M] (Warp Nine Engineering) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\Par1284.sys -- (PAR1284)
DRV - [2009.06.29 15:32:24 | 000,193,696 | ---- | M] (Jungo) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\windrvr6.sys -- (WinDriver6)
DRV - [2008.08.27 11:22:24 | 004,754,432 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2008.08.26 05:28:10 | 003,684,352 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtHDMI.sys -- (RTHDMIAzAudService)
DRV - [2008.08.07 13:14:56 | 000,111,360 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007.10.12 03:40:12 | 000,009,096 | R--- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\amdide.sys -- (amdide)
DRV - [2007.04.16 21:46:00 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope =


IE - HKU\.DEFAULT\..\URLSearchHook: - No CLSID value found
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-854245398-1383384898-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKU\S-1-5-21-854245398-1383384898-839522115-1003\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKU\S-1-5-21-854245398-1383384898-839522115-1003\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={9C762310-60A9-4440-A079-50D5D6CEA11C}&mid=7ce83ad2afd347d085a3d16d5bf4e71b-be9cae56c991590da7bfd634d8263a5e234d8eb2&lang=cs&ds=gm011&pr=sa&d=2012-05-23 19:38:35&v=11.1.0.7&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-854245398-1383384898-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[color=#E56717]========== FireFox ==========[/color]

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@software602.cz/602XML Filler: C:\Program Files\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\uživatel\Local Settings\Data aplikací\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\uživatel\Local Settings\Data aplikací\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012.03.29 21:24:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Data aplikací\AVG Secure Search\11.1.0.12\ [2012.07.09 15:19:27 | 000,000,000 | ---D | M]


[color=#E56717]========== Chrome ==========[/color]

CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\u\u017Eivatel\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\u\u017Eivatel\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\u\u017Eivatel\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\u\u017Eivatel\Local Settings\Data aplikac\u00ED\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 7.0.0.147 (Enabled) = C:\Program Files\Java\jre7\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 7 U2 (Enabled) = C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\u\u017Eivatel\Local Settings\Data aplikac\u00ED\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\\npsitesafety.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll
CHR - plugin: Software602 Form Filler (Enabled) = C:\Program Files\Software602\602XML\Filler\npfiller.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Documents and Settings\uživatel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\uživatel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: 1Click Downloader = C:\Documents and Settings\uživatel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jplinpmadfkdgipabgcdchbdikologlh\1.1_0\

O1 HOSTS File: ([2012.07.28 18:27:45 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [OODefragTray] C:\Program Files\OO Software\Defrag\oodtray.exe (O&O Software GmbH)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-854245398-1383384898-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-854245398-1383384898-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-854245398-1383384898-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKU\S-1-5-21-854245398-1383384898-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-854245398-1383384898-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra 'Tools' menuitem : Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E0A2D612-9559-4215-AAD7-1B34697AC779}: NameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F8B99982-EFB9-4C64-B43C-FA0CDD747D4D}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O34 - HKLM BootExecute: (OODBS)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

[color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color]

[2012.07.29 09:42:56 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\uživatel\Dokumenty\OTL.exe
[2012.07.28 19:04:08 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012.07.28 18:09:53 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\uživatel\Recent
[2012.07.23 21:40:44 | 000,000,000 | ---D | C] -- C:\janka
[2012.07.13 19:16:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
[2012.07.09 21:14:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\uživatel\Dokumenty\Downloads
[2012.07.09 10:34:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\uživatel\Nabídka Start\Programy\Google Chrome
[2012.07.09 10:32:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\uživatel\Local Settings\Data aplikací\Google
[2012.07.09 10:14:24 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
[2012.07.09 10:03:56 | 012,351,992 | ---- | C] (Opera Software ASA) -- C:\Documents and Settings\uživatel\Plocha\Opera_1200_int_Setup.exe
[2012.07.08 11:01:29 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Documents and Settings\uživatel\Dokumenty\ATF-Cleaner.exe
[2012.07.07 19:26:47 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012.07.07 19:25:55 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012.07.07 19:25:55 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012.07.07 19:25:55 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012.07.07 19:25:55 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012.07.07 19:25:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2012.07.07 19:19:40 | 004,719,842 | R--- | C] (Swearware) -- C:\Documents and Settings\uživatel\Plocha\ComboFix.exe
[2012.07.07 19:15:43 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\uživatel\Dokumenty\TFC.exe
[2012.07.06 20:13:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\runouce.exe
[2012.07.06 20:03:28 | 000,632,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2012.07.06 20:03:27 | 000,554,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2012.07.06 20:03:25 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\R.COM
[2012.07.06 20:03:25 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\T.COM
[2012.07.06 20:03:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MicroWorld
[2012.07.06 20:03:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2012.07.06 12:58:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\uživatel\Data aplikací\Realore All My Gods
[2012.07.05 14:28:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Swiff Player
[2012.07.05 14:28:18 | 000,000,000 | ---D | C] -- C:\Program Files\GlobFX
[2012.07.05 11:33:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oodag
[2012.07.05 11:30:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\uživatel\Dokumenty\oo-15.0.107
[2012.07.05 11:29:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\uživatel\Local Settings\Data aplikací\O&O
[2012.07.05 11:28:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\O&O Software
[2012.07.05 11:28:54 | 000,000,000 | ---D | C] -- C:\Program Files\OO Software
[2012.07.05 11:28:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\uživatel\Local Settings\Data aplikací\Downloaded Installations
[2012.07.03 10:48:16 | 026,665,000 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Documents and Settings\uživatel\Plocha\12-6_xp32-64_hydravision.exe
[2012.07.03 10:47:05 | 104,842,352 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Documents and Settings\uživatel\Plocha\12-6_xp32_dd_ccc.exe
[2012.07.02 13:24:00 | 000,426,184 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012.07.02 13:24:00 | 000,070,344 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012.06.30 20:28:59 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidserv.dll
[2012.06.30 20:28:55 | 000,014,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhid.sys
[2012.06.29 19:49:16 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Installer Clean Up
[2012.06.29 19:45:53 | 000,000,000 | ---D | C] -- C:\Program Files\Copernic Desktop Search - Pro
[2012.06.29 19:45:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\uživatel\Local Settings\Data aplikací\Copernic
[2012.06.29 19:45:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\uživatel\Data aplikací\Copernic
[2012.06.29 19:45:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Copernic
[2012.06.25 19:16:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\CadStd
[2012.06.25 19:16:54 | 000,000,000 | ---D | C] -- C:\Program Files\Apperson
[2012.06.13 09:33:15 | 000,521,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2012.06.04 11:10:46 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012.06.04 11:02:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\uživatel\Data aplikací\SUPERAntiSpyware.com
[2012.06.04 11:01:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
[2012.06.04 11:00:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\uživatel\Dokumenty\SUPERAntiSpyware.Pro.v5.0.1148.Incl.Keygen.and.Patch-P2P
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 60 Days ==========[/color]

[2012.07.29 09:42:56 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\uživatel\Dokumenty\OTL.exe
[2012.07.29 09:34:44 | 102,391,247 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012.07.29 09:34:15 | 000,000,914 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.07.29 09:31:39 | 000,013,002 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.07.29 09:30:57 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.07.29 09:30:53 | 000,146,740 | ---- | M] () -- C:\WINDOWS\System32\oodbs.lor
[2012.07.28 21:05:17 | 000,000,091 | ---- | M] () -- C:\WINDOWS\A19Bowl.cfg
[2012.07.28 20:44:50 | 000,030,720 | ---- | M] () -- C:\Documents and Settings\uživatel\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.07.28 18:27:45 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012.07.28 18:23:36 | 004,719,842 | R--- | M] (Swearware) -- C:\Documents and Settings\uživatel\Plocha\ComboFix.exe
[2012.07.28 18:02:37 | 000,000,029 | ---- | M] () -- C:\WINDOWS\Lic.xxx
[2012.07.28 17:55:55 | 000,207,378 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\pinfect.zip
[2012.07.28 17:29:16 | 000,000,783 | ---- | M] () -- C:\Documents and Settings\uživatel\Plocha\MWAVSCAN.lnk
[2012.07.27 13:34:27 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012.07.27 13:34:27 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012.07.26 09:39:32 | 000,002,495 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\ABBYY FineReader 11.lnk
[2012.07.25 10:09:34 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012.07.23 11:41:17 | 691,994,575 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\cz_m_s_16_part_3_720.wmv
[2012.07.22 18:11:13 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes Anti-Malware.lnk
[2012.07.22 13:51:51 | 000,004,113 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\DPHEVD-8706302110-20120722-134753-538630986-potvrzeni.p7s
[2012.07.13 19:16:36 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[2012.07.12 21:59:26 | 821,979,136 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\John Carter - Mezi dvěma světy.avi
[2012.07.12 20:38:58 | 000,002,282 | ---- | M] () -- C:\Documents and Settings\uživatel\Plocha\Google Chrome.lnk
[2012.07.12 16:52:51 | 1113,877,427 | ---- | M] () -- C:\HTPS
[2012.07.11 07:31:38 | 000,200,936 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.07.09 10:14:30 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2012.07.09 10:04:48 | 012,351,992 | ---- | M] (Opera Software ASA) -- C:\Documents and Settings\uživatel\Plocha\Opera_1200_int_Setup.exe
[2012.07.08 11:01:29 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Documents and Settings\uživatel\Dokumenty\ATF-Cleaner.exe
[2012.07.07 19:26:49 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012.07.07 19:15:43 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\uživatel\Dokumenty\TFC.exe
[2012.07.06 20:03:27 | 000,632,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2012.07.06 20:03:26 | 000,554,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2012.07.06 12:40:45 | 723,221,695 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\czmswin_16_part_2_720.wmv
[2012.07.05 20:52:44 | 000,415,733 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012.07.05 14:28:18 | 000,000,738 | ---- | M] () -- C:\Documents and Settings\uživatel\Plocha\Swiff Player.lnk
[2012.07.05 14:25:32 | 008,587,966 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\2597.swf
[2012.07.05 11:28:55 | 000,001,914 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\O&O Defrag.lnk
[2012.07.03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.07.03 10:53:42 | 104,842,352 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Documents and Settings\uživatel\Plocha\12-6_xp32_dd_ccc.exe
[2012.07.03 10:50:57 | 026,665,000 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Documents and Settings\uživatel\Plocha\12-6_xp32-64_hydravision.exe
[2012.07.02 13:22:33 | 000,001,282 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\cc_20120702_132230.reg
[2012.06.29 11:54:57 | 006,090,752 | ---- | M] () -- C:\Documents and Settings\uživatel\s-1-5-21-854245398-1383384898-839522115-1003.rrr
[2012.06.25 19:26:24 | 015,555,990 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\CorelDRAWGraphicsSuiteX5v15.2.0.661CZ-ElninoSlov.rar
[2012.06.25 19:16:55 | 000,000,763 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\CadStd.lnk
[2012.06.24 09:06:49 | 000,413,625 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\přiznání švec 2011.pdf
[2012.06.24 08:52:59 | 000,771,347 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\přiznání švec 2011 1 stránka.pdf
[2012.06.22 21:58:04 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[2012.06.18 09:33:00 | 736,321,536 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\Signal.2011.DVDrip.XviD.CZ.avi
[2012.06.13 15:55:23 | 001,866,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\win32k.sys
[2012.06.13 15:55:23 | 001,866,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys
[2012.06.08 16:25:48 | 008,466,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shell32.dll
[2012.06.05 17:49:58 | 001,372,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6.dll
[2012.06.05 17:49:57 | 001,172,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml3.dll
[2012.06.05 12:58:10 | 000,000,520 | ---- | M] () -- C:\Documents and Settings\uživatel\Dokumenty\spider.sav
[2012.06.04 11:10:49 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\SUPERAntiSpyware Free Edition.lnk
[2012.06.04 11:01:47 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\uživatel\Plocha\SUPERAntiSpyware Professional.lnk
[2012.06.04 06:32:38 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\schannel.dll
[2012.06.02 15:19:44 | 000,022,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll.mui
[2012.06.02 15:19:38 | 000,329,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll
[2012.06.02 15:19:38 | 000,329,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wucltui.dll
[2012.06.02 15:19:38 | 000,219,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuaucpl.cpl
[2012.06.02 15:19:38 | 000,210,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuweb.dll
[2012.06.02 15:19:34 | 000,097,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cdm.dll
[2012.06.02 15:19:34 | 000,097,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\cdm.dll
[2012.06.02 15:19:34 | 000,053,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuauclt.exe
[2012.06.02 15:19:34 | 000,045,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wups2.dll
[2012.06.02 15:19:34 | 000,035,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wups.dll
[2012.06.02 15:19:34 | 000,035,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wups.dll
[2012.06.02 15:19:34 | 000,015,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll.mui
[2012.06.02 15:19:24 | 000,577,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll
[2012.06.02 15:19:24 | 000,577,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuapi.dll
[2012.06.02 15:19:18 | 001,933,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuaueng.dll
[2012.06.02 06:50:23 | 000,077,214 | ---- | M] () -- C:\Documents and Settings\uživatel\Plocha\576a0ec4-956a-4e16-bdce-a67d6ee7cd48.png
[2012.05.31 15:22:06 | 000,602,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2012.07.28 18:02:37 | 000,000,029 | ---- | C] () -- C:\WINDOWS\Lic.xxx
[2012.07.28 17:29:16 | 000,000,783 | ---- | C] () -- C:\Documents and Settings\uživatel\Plocha\MWAVSCAN.lnk
[2012.07.23 10:13:06 | 691,994,575 | ---- | C] () -- C:\Documents and Settings\uživatel\Dokumenty\cz_m_s_16_part_3_720.wmv
[2012.07.22 13:51:51 | 000,004,113 | ---- | C] () -- C:\Documents and Settings\uživatel\Dokumenty\DPHEVD-8706302110-20120722-134753-538630986-potvrzeni.p7s
[2012.07.19 20:11:46 | 000,000,091 | ---- | C] () -- C:\WINDOWS\A19Bowl.cfg
[2012.07.12 20:13:48 | 821,979,136 | ---- | C] () -- C:\Documents and Settings\uživatel\Dokumenty\John Carter - Mezi dvěma světy.avi
[2012.07.12 16:52:27 | 1113,877,427 | ---- | C] () -- C:\HTPS
[2012.07.09 10:34:04 | 000,002,282 | ---- | C] () -- C:\Documents and Settings\uživatel\Plocha\Google Chrome.lnk
[2012.07.09 10:14:30 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Opera.lnk
[2012.07.09 10:14:30 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2012.07.07 19:25:55 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012.07.07 19:25:55 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012.07.07 19:25:55 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012.07.07 19:25:55 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012.07.07 19:25:55 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012.07.06 11:47:20 | 723,221,695 | ---- | C] () -- C:\Documents and Settings\uživatel\Dokumenty\czmswin_16_part_2_720.wmv
[2012.07.05 19:05:32 | 000,146,740 | ---- | C] () -- C:\WINDOWS\System32\oodbs.lor
[2012.07.05 14:28:18 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\uživatel\Plocha\Swiff Player.lnk
[2012.07.05 14:25:16 | 008,587,966 | ---- | C] () -- C:\Documents and Settings\uživatel\Dokumenty\2597.swf
[2012.07.05 11:28:55 | 000,001,914 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\O&O Defrag.lnk
[2012.07.02 13:24:02 | 000,000,914 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.07.02 13:22:32 | 000,001,282 | ---- | C] () -- C:\Documents and Settings\uživatel\Dokumenty\cc_20120702_132230.reg
[2012.06.29 19:49:16 | 000,002,345 | ---- | C] () -- C:\Documents and Settings\uživatel\Nabídka Start\Programy\Windows Install Clean Up.lnk
[2012.06.25 19:25:45 | 015,555,990 | ---- | C] () -- C:\Documents and Settings\uživatel\Dokumenty\CorelDRAWGraphicsSuiteX5v15.2.0.661CZ-ElninoSlov.rar
[2012.06.25 19:16:55 | 000,000,763 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\CadStd.lnk
[2012.06.24 09:06:40 | 000,413,625 | ---- | C] () -- C:\Documents and Settings\uživatel\Dokumenty\přiznání švec 2011.pdf
[2012.06.24 08:52:58 | 000,771,347 | ---- | C] () -- C:\Documents and Settings\uživatel\Dokumenty\přiznání švec 2011 1 stránka.pdf
[2012.06.18 08:44:27 | 736,321,536 | ---- | C] () -- C:\Documents and Settings\uživatel\Dokumenty\Signal.2011.DVDrip.XviD.CZ.avi
[2012.06.04 11:10:49 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\SUPERAntiSpyware Free Edition.lnk
[2012.06.04 11:01:47 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\uživatel\Plocha\SUPERAntiSpyware Professional.lnk
[2012.06.02 06:50:23 | 000,077,214 | ---- | C] () -- C:\Documents and Settings\uživatel\Plocha\576a0ec4-956a-4e16-bdce-a67d6ee7cd48.png
[2012.05.23 11:40:27 | 000,030,720 | ---- | C] () -- C:\Documents and Settings\uživatel\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.05.22 11:04:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2012.05.13 16:46:11 | 006,090,752 | ---- | C] () -- C:\Documents and Settings\uživatel\s-1-5-21-854245398-1383384898-839522115-1003.rrr
[2012.04.17 09:03:49 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\uživatel\Local Settings\Data aplikací\fusioncache.dat
[2012.04.04 11:51:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI
[2012.02.27 20:05:14 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2012.02.27 20:05:13 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2012.02.24 11:23:47 | 000,001,312 | ---- | C] () -- C:\Documents and Settings\uživatel\Local Settings\Data aplikací\SRDownloader.nast
[2012.02.19 12:16:22 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\HMIPCore.dll
[2012.02.17 17:43:14 | 000,001,057 | ---- | C] () -- C:\Documents and Settings\uživatel\Data aplikací\vso_ts_preview.xml
[2012.02.15 10:06:46 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.02.12 19:16:25 | 000,000,183 | ---- | C] () -- C:\WINDOWS\aimpr.ini
[2012.02.01 18:39:56 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\uživatel\netstat
[2012.01.29 18:28:59 | 000,000,054 | ---- | C] () -- C:\WINDOWS\RP121032.INI
[2012.01.29 18:28:57 | 000,008,937 | ---- | C] () -- C:\WINDOWS\dx121032.ini
[2012.01.29 18:28:57 | 000,007,851 | ---- | C] () -- C:\WINDOWS\NXEDL32.ini
[2012.01.29 18:28:57 | 000,001,053 | ---- | C] () -- C:\WINDOWS\SerialDV.INI
[2012.01.29 18:28:57 | 000,000,286 | ---- | C] () -- C:\WINDOWS\BTConnectUtility.ini
[2012.01.29 18:28:48 | 000,001,336 | ---- | C] () -- C:\WINDOWS\ExceptionReport.ini
[2012.01.29 18:28:48 | 000,001,198 | ---- | C] () -- C:\WINDOWS\xVDSClientCntrl.ini
[2012.01.29 18:28:48 | 000,000,583 | ---- | C] () -- C:\WINDOWS\xVDSMgr.ini
[2012.01.29 18:27:05 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2012.01.29 18:26:54 | 000,000,617 | ---- | C] () -- C:\WINDOWS\ECULP.ini
[2012.01.29 18:26:52 | 000,000,191 | ---- | C] () -- C:\WINDOWS\FaultMon.INI
[2012.01.29 18:26:50 | 000,569,439 | ---- | C] () -- C:\WINDOWS\System32\JDLegacyCfgReader.dll
[2012.01.29 18:25:27 | 000,001,399 | ---- | C] () -- C:\WINDOWS\PayloadProcessor.Ini
[2012.01.29 18:24:28 | 000,479,232 | ---- | C] () -- C:\WINDOWS\System32\JDMemAccessController.dll
[2012.01.29 18:24:28 | 000,323,657 | ---- | C] () -- C:\WINDOWS\System32\JDComm.dll
[2012.01.29 18:24:28 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\JDPFController.dll
[2012.01.29 18:24:28 | 000,270,336 | ---- | C] () -- C:\WINDOWS\System32\JDPhoenixController.dll
[2012.01.29 18:24:28 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\JDEnhancedSecurity.dll
[2012.01.29 18:24:28 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\PWDJDOW.dll
[2012.01.29 18:24:28 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\PWDJDCFD.dll
[2012.01.29 18:24:28 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\PWDHarvestorWorks.dll
[2012.01.29 18:24:28 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\JDSupplierSecurity.dll
[2012.01.29 18:24:28 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\JDSimpleSecurity.dll
[2012.01.29 18:24:28 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\JDSimple2Security.dll
[2012.01.29 18:24:28 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\PWDPhoenix.dll
[2012.01.29 18:23:26 | 000,221,255 | ---- | C] () -- C:\WINDOWS\System32\JDLog.dll
[2012.01.29 18:23:26 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\JDNetCommSerial.dll
[2012.01.29 18:23:26 | 000,168,011 | ---- | C] () -- C:\WINDOWS\System32\JDError.dll
[2012.01.29 18:21:25 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\VersionInfo.dll
[2012.01.29 18:21:25 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\JDBinaryRecords.dll
[2012.01.29 18:21:25 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\JDArrayUtils.dll
[2012.01.29 18:21:24 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\JDHarvesterController.dll
[2012.01.29 18:21:24 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\JDPlus1Controller.dll
[2012.01.15 13:29:30 | 000,000,055 | ---- | C] () -- C:\WINDOWS\WinInit.Ini
[2012.01.13 19:44:36 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2012.01.08 19:15:41 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2011.12.31 16:52:34 | 000,000,111 | ---- | C] () -- C:\WINDOWS\posta2.ini
[2011.12.31 16:14:53 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\uživatel\default.pls
[2011.12.31 11:00:05 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2011.12.29 13:29:12 | 000,004,952 | ---- | C] () -- C:\WINDOWS\BOOTFONT.BIN
[2011.12.28 17:17:24 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS53.DLL
[2011.12.28 12:28:42 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2011.12.28 12:28:32 | 003,107,788 | R--- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2011.12.28 12:28:32 | 000,601,728 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2011.12.28 12:23:06 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2011.12.28 12:12:22 | 000,004,265 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011.12.28 12:11:04 | 000,200,936 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.12.28 11:25:24 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011.12.28 11:21:49 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011.12.05 23:04:00 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\OpenVideo.dll
[2011.12.05 23:03:52 | 000,054,784 | ---- | C] () -- C:\WINDOWS\System32\OVDecode.dll

[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >[/color]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Disabled (Startup Manager)]
"UpdateMes" = C:\Documents and Settings\uživatel\Data aplikací\Updatem\update_days\zupdate.exe -- [2012.03.15 19:26:30 | 000,030,720 | ---- | M] ()

[color=#A23BEC]< c:\windows\*.* /U >[/color]

[color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
[2004.08.17 16:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004.08.17 16:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\erdnt\cache\agp440.sys
[2008.04.14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004.08.04 00:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

[color=#A23BEC]< MD5 for: AHCIX86.SYS >[/color]
[2009.04.08 23:46:22 | 000,189,968 | ---- | M] (Advanced Micro Devices, Inc) MD5=3936A49ECB74CF23BBB6979CD683DD56 -- C:\Documents and Settings\uživatel\Plocha\SB750\x86\ahcix86.sys

[color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
[2004.08.17 16:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004.08.17 16:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\erdnt\cache\atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2001.10.25 14:00:00 | 000,086,656 | ---- | M] (Microsoft Corporation) MD5=A64013E98426E1877CB653685C5C0009 -- C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys
[2001.10.25 14:00:00 | 000,086,656 | ---- | M] (Microsoft Corporation) MD5=A64013E98426E1877CB653685C5C0009 -- C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys
[2004.08.03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

[color=#A23BEC]< MD5 for: EVENTLOG.DLL >[/color]
[2008.04.14 09:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\erdnt\cache\eventlog.dll
[2008.04.14 09:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 09:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2004.08.17 16:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

[color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
[2008.04.14 09:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\erdnt\cache\explorer.exe
[2008.04.14 09:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 09:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004.08.17 16:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

[color=#A23BEC]< MD5 for: HAL.DLL >[/color]
[2004.08.17 16:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2004.08.17 16:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:hal.dll
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.14 01:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.14 01:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2004.08.03 23:59:14 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll

[color=#A23BEC]< MD5 for: LSASS.EXE >[/color]
[2004.08.17 16:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 09:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\erdnt\cache\lsass.exe
[2008.04.14 09:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 09:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

[color=#A23BEC]< MD5 for: NDIS.SYS >[/color]
[2008.04.14 01:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\erdnt\cache\ndis.sys
[2008.04.14 01:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.14 01:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2004.08.04 00:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

[color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color]
[2004.08.17 16:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 09:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\erdnt\cache\netlogon.dll
[2008.04.14 09:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 09:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll

[color=#A23BEC]< MD5 for: SCECLI.DLL >[/color]
[2004.08.17 16:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 09:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\erdnt\cache\scecli.dll
[2008.04.14 09:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 09:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

[color=#A23BEC]< MD5 for: SMSS.EXE >[/color]
[2004.08.17 16:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 09:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 09:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe

mafian
Level 3.5
Level 3.5
Příspěvky: 770
Registrován: leden 07
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod mafian » 29 črc 2012 09:55

[color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
[2012.07.03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008.04.14 09:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\erdnt\cache\svchost.exe
[2008.04.14 09:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 09:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004.08.17 16:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

[color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
[2008.04.14 09:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\erdnt\cache\userinit.exe
[2008.04.14 09:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 09:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004.08.17 16:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2004.08.17 16:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012.07.03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.04.14 09:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\erdnt\cache\winlogon.exe
[2008.04.14 09:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 09:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

[color=#A23BEC]< MD5 for: WS2_32.DLL >[/color]
[2004.08.17 16:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 09:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\erdnt\cache\ws2_32.dll
[2008.04.14 09:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 09:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll

[color=#A23BEC]< %systemroot%\*. /mp /s >[/color]

[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

[color=#A23BEC]< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >[/color]
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1

< End of report >

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43070
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 30 črc 2012 09:57

Fix v HJT:

Kód: Vybrat vše

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab

Odinstaluj:
MWAV
SUPERAntiSpyware


Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\catchme.sys -- (catchme)
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\..\URLSearchHook: - No CLSID value found
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - No CLSID value found
IE - HKU\S-1-5-21-854245398-1383384898-839522115-1003\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKU\S-1-5-21-854245398-1383384898-839522115-1003\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={9C762310-60A9-4440-A079-50D5D6CEA11C}&mid=7ce83ad2afd347d085a3d16d5bf4e71b-be9cae56c991590da7bfd634d8263a5e234d8eb2&lang=cs&ds=gm011&pr=sa&d=2012-05-23 19:38:35&v=11.1.0.7&sap=dsp&q={searchTerms}
O1 HOSTS File: ([2012.07.28 18:27:45 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-854245398-1383384898-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
c:\windows\Tasks\*.job
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\WINDOWS\SWREG.exe
C:\WINDOWS\SWSC.exe
C:\WINDOWS\SWXCACLS.exe
C:\WINDOWS\NIRCMD.exe
C:\Documents and Settings\uživatel\Plocha\ComboFix.exe
C:\WINDOWS\System32\runouce.exe
C:\WINDOWS\A19Bowl.cfg
C:\Documents and Settings\uživatel\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\WINDOWS\PEV.exe
C:\WINDOWS\MBR.exe
C:\WINDOWS\sed.exe
C:\WINDOWS\grep.exe
C:\WINDOWS\zip.exe
C:\WINDOWS\ativpsrm.bin
C:\WINDOWS\System32\zlib1.dll
ipconfig /flushdns /c

:Reg
:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
C:\WINDOWS\xVDSClientCntrl.ini
C:\WINDOWS\xVDSMgr.ini

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

mafian
Level 3.5
Level 3.5
Příspěvky: 770
Registrován: leden 07
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod mafian » 30 črc 2012 15:43

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Service PCIDump stopped successfully!
Service PCIDump deleted successfully!
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\catchme.sys not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
HKEY_USERS\S-1-5-21-854245398-1383384898-839522115-1003\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-854245398-1383384898-839522115-1003\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
127.0.0.1 localhost removed from HOSTS file successfully
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-854245398-1383384898-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
C:\WINDOWS\System32\PerfStringBackup.TMP deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
c:\windows\Tasks\Adobe Flash Player Updater.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
C:\WINDOWS\SWREG.exe moved successfully.
C:\WINDOWS\SWSC.exe moved successfully.
C:\WINDOWS\SWXCACLS.exe moved successfully.
C:\WINDOWS\NIRCMD.exe moved successfully.
C:\Documents and Settings\uživatel\Plocha\ComboFix.exe moved successfully.
C:\WINDOWS\System32\runouce.exe folder moved successfully.
C:\WINDOWS\A19Bowl.cfg moved successfully.
C:\Documents and Settings\uživatel\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\WINDOWS\PEV.exe moved successfully.
C:\WINDOWS\MBR.exe moved successfully.
C:\WINDOWS\sed.exe moved successfully.
C:\WINDOWS\grep.exe moved successfully.
C:\WINDOWS\zip.exe moved successfully.
C:\WINDOWS\ativpsrm.bin moved successfully.
C:\WINDOWS\System32\zlib1.dll moved successfully.
[color=#A23BEC]< ipconfig /flushdns /c >[/color]
No captured output from command...
C:\Documents and Settings\uživatel\Dokumenty\cmd.bat deleted successfully.
========== REGISTRY ==========
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: User

User: uživatel

User: uživatel
->Temp folder emptied: 1994657 bytes
->Temporary Internet Files folder emptied: 14452366 bytes
->Google Chrome cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 2649 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 104502 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 16,00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: User

User: uživatel

User: uživatel
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.55.0 log created on 07302012_153120

Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\uživatel\Local Settings\Temp\SAS161.tmp not found!
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_a44.dat not found!

PendingFileRenameOperations files...
File C:\Documents and Settings\uživatel\Local Settings\Temp\SAS161.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_a44.dat not found!

Registry entries deleted on Reboot...

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43070
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 30 črc 2012 15:46

Toto otestuj na Virustotal
C:\WINDOWS\xVDSClientCntrl.ini
C:\WINDOWS\xVDSMgr.ini
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43070
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 30 črc 2012 22:43

Stáhni si Farbar Service Scanner
a spust ho.
Ujisti se , jestli máš zatrženo :
Internet Services
Windows Firewall
System Restore
Security Center
Windows Update
Klikni na "Scan".
Po čase se objeví log (FSS.txt) , ve stejném adresáři jako máš tento nástroj.
Prosím , zkopíruj sem celý jeho obsah.

Ještě jsou problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

mafian
Level 3.5
Level 3.5
Příspěvky: 770
Registrován: leden 07
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod mafian » 31 črc 2012 11:26

Farbar Service Scanner Version: 26-07-2012
Ran by uživatel (administrator) on 31-07-2012 at 11:24:41
Running from "C:\Documents and Settings\uživatel\Dokumenty"
Systém Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================
ATTENTION!=====> Unable to retrieve HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\\EnableFirewall value. The value does not exist.


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll
[2001-10-25 14:00] - [2008-04-14 09:51] - 0125952 ____A (Microsoft Corporation) 8C9A53E285AC5E6704844D0459EC85BE

C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll
[2001-10-25 14:00] - [2009-04-20 19:19] - 0045568 ____A (Microsoft Corporation) DFAA406BF19F4EE806A6F8D4342137F7

C:\WINDOWS\system32\ipnathlp.dll
[2001-10-25 14:00] - [2008-04-14 09:51] - 0329728 ____A (Microsoft Corporation) F58FACA9621D2DB01BD0927D9A0A208E

C:\WINDOWS\system32\netman.dll
[2001-10-25 14:00] - [2008-04-14 09:51] - 0198144 ____A (Microsoft Corporation) 72E1E9E2977BE08BDEEDB6D8FD9D4D40

C:\WINDOWS\system32\wbem\WMIsvc.dll
[2011-12-28 11:20] - [2008-04-14 09:52] - 0144896 ____A (Microsoft Corporation) E488332126E3B1182D2B8A0C35408EC6

C:\WINDOWS\system32\srsvc.dll
[2011-12-28 11:22] - [2008-04-14 09:52] - 0171008 ____A (Microsoft Corporation) 35B91147124F64AC8081A2EDB9EA4DEE

C:\WINDOWS\system32\Drivers\sr.sys
[2011-12-28 11:22] - [2008-04-14 09:11] - 0073344 ____A (Microsoft Corporation) 94610C8653635E4459316A0050D55CE7

C:\WINDOWS\system32\wscsvc.dll
[2011-12-28 12:55] - [2008-04-14 09:52] - 0080896 ____A (Microsoft Corporation) 4C86D5FAF78194995AF9CC1075F65DD3

C:\WINDOWS\system32\wbem\WMIsvc.dll
[2011-12-28 11:20] - [2008-04-14 09:52] - 0144896 ____A (Microsoft Corporation) E488332126E3B1182D2B8A0C35408EC6

C:\WINDOWS\system32\wuauserv.dll
[2011-12-28 11:20] - [2008-04-14 09:52] - 0006656 ____A (Microsoft Corporation) C1364564800EE9784192145324A23308

C:\WINDOWS\system32\qmgr.dll
[2011-12-28 11:22] - [2008-04-14 09:51] - 0409088 ____A (Microsoft Corporation) 19395D092FD85DDC2D9C7729CF5A2AC8

C:\WINDOWS\system32\es.dll
[2001-10-25 14:00] - [2008-07-07 22:29] - 0253952 ____A (Microsoft Corporation) A371F11EF07653591C8DE26AFB13CE7F

C:\WINDOWS\system32\cryptsvc.dll
[2001-10-25 14:00] - [2008-04-14 09:51] - 0062464 ____A (Microsoft Corporation) F3AB0933CBD166D271992F411C27CCAF

C:\WINDOWS\system32\svchost.exe
[2001-10-25 14:00] - [2008-04-14 09:52] - 0014336 ____A (Microsoft Corporation) BE4A520E29B6391F49E79CCC52044D93

C:\WINDOWS\system32\rpcss.dll
[2001-10-25 14:00] - [2009-02-09 12:56] - 0401408 ____A (Microsoft Corporation) BE27674D1CBC3214AEC84B4336A38BBF

C:\WINDOWS\system32\services.exe
[2001-10-25 14:00] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 9EF697AF07BB8DD82C3B02CA953A95B7


Extra List:
=======
Avgtdix(8) Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4)
0x09000000050000000100000002000000030000000400000009000000080000000600000007000000
IpSec Tag value is correct.

**** End of log ****


no ted to už vipadá v pohoděještě to párkrát vyzkouším.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43070
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod jaro3 » 31 črc 2012 22:15

Stáhni si MiniToolBox
a spusť ho.
V okně zaškrtni čtverečky:
Report IE Proxy Settings
Report FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size

Potom klikni na GO , po chvíli skenu se objeví log s názvem „Result“ , zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

mafian
Level 3.5
Level 3.5
Příspěvky: 770
Registrován: leden 07
Pohlaví: Muž
Stav:
Offline

Re: prosím o kontrolu logu

Příspěvekod mafian » 01 srp 2012 09:24

MiniToolBox by Farbar Version: 23-07-2012
Ran by uživatel (administrator) on 01-08-2012 at 09:22:28
Systém Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================
::1 localhost

127.0.0.1 localhost

========================= IP Configuration: ================================

1394 Net Adapter = 1394 Připojení (Disconnected)
Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC = Připojení k místní síti (Connected)


# ----------------------------------
#Konfigurace rozhraní protokolu IP
# ----------------------------------
pushd interface ip


# Konfigurace protokolu IP rozhraní pro "Připojení k místní síti"

set address name="Připojení k místní síti" source=dhcp
set dns name="Připojení k místní síti" source=dhcp register=PRIMARY
set wins name="Připojení k místní síti" source=dhcp


popd
# Konec konfigurace protokolu IP rozhraní




Konfigurace protokolu IP systému Windows



Název hostitele . . . . . . . . . : admin

Primární přípona DNS. . . . . . . :

Typ uzlu . . . . . . . . . . . . : neznámý

Povoleno směrování IP . . . . . . : Ne

WINS Proxy povoleno . . . . . . . : Ne



Adaptér sítě Ethernet Připojení k místní síti:



Přípona DNS podle připojení . . . :

Popis . . . . . . . . . . . . . . : Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC

Fyzická Adresa. . . . . . . . . . : 00-24-1D-10-0E-E8

Protokol DHCP povolen . . . . . . : Ano

Automatická konfigurace povolena : Ano

Adresa IP . . . . . . . . . . . . : 10.0.0.139

Maska podsítě . . . . . . . . . . : 255.255.255.0

Výchozí brána . . . . . . . . . . : 10.0.0.138

Server DHCP . . . . . . . . . . . : 10.0.0.138

Servery DNS . . . . . . . . . . . : 10.0.0.138

Zapůjčeno . . . . . . . . . . . . : 1. srpna 2012 8:54:27

Zápůjčka vyprší . . . . . . . . . : 1. srpna 2012 9:54:27

Server: mygateway1.ar7
Address: 10.0.0.138

N˙zev: google.com
Addresses: 173.194.39.132, 173.194.39.133, 173.194.39.134, 173.194.39.135
173.194.39.136, 173.194.39.137, 173.194.39.142, 173.194.39.128, 173.194.39.129
173.194.39.130, 173.194.39.131



Pýˇkaz PING na google.com [173.194.39.132] s d‚lkou 32 bajt…:



OdpovŘÔ od 173.194.39.132: bajty=32 źas=51ms TTL=55

OdpovŘÔ od 173.194.39.132: bajty=32 źas=50ms TTL=55



Statistika ping pro 173.194.39.132:

Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),

Pýibli§n  doba do pýijetˇ odezvy v milisekund ch:

Minimum = 50ms, Maximum = 51ms, Pr…mŘr = 50ms

Server: mygateway1.ar7
Address: 10.0.0.138

N˙zev: yahoo.com
Addresses: 72.30.38.140, 98.139.183.24, 209.191.122.70



Pýˇkaz PING na yahoo.com [72.30.38.140] s d‚lkou 32 bajt…:



OdpovŘÔ od 72.30.38.140: bajty=32 źas=216ms TTL=48

OdpovŘÔ od 72.30.38.140: bajty=32 źas=276ms TTL=48



Statistika ping pro 72.30.38.140:

Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),

Pýibli§n  doba do pýijetˇ odezvy v milisekund ch:

Minimum = 216ms, Maximum = 276ms, Pr…mŘr = 246ms

Server: mygateway1.ar7
Address: 10.0.0.138

N˙zev: bleepingcomputer.com
Address: 208.43.87.2



Pýˇkaz PING na bleepingcomputer.com [208.43.87.2] s d‚lkou 32 bajt…:



OdpovŘÔ od 208.43.87.2: Cˇlově hostitel nenˇ dostupně.

OdpovŘÔ od 208.43.87.2: Cˇlově hostitel nenˇ dostupně.



Statistika ping pro 208.43.87.2:

Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),

Pýibli§n  doba do pýijetˇ odezvy v milisekund ch:

Minimum = 0ms, Maximum = 0ms, Pr…mŘr = 0ms



Pýˇkaz PING na 127.0.0.1 s d‚lkou 32 bajt…:



OdpovŘÔ od 127.0.0.1: bajty=32 źas < 1ms TTL=128

OdpovŘÔ od 127.0.0.1: bajty=32 źas < 1ms TTL=128



Statistika ping pro 127.0.0.1:

Pakety: Odeslan‚ = 2, Pýijat‚ = 2, Ztracen‚ = 0 (ztr ta 0%),

Pýibli§n  doba do pýijetˇ odezvy v milisekund ch:

Minimum = 0ms, Maximum = 0ms, Pr…mŘr = 0ms

===========================================================================
Seznam rozhranˇ
0x1 ........................... MS TCP Loopback interface
0x2 ...00 24 1d 10 0e e8 ...... Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC - Packet Scheduler Miniport
===========================================================================
===========================================================================
Aktivnˇ smŘrov nˇ:
Cˇl v sˇti Sˇśov  maska Br na Rozhranˇ Metrika
0.0.0.0 0.0.0.0 10.0.0.138 10.0.0.139 20
10.0.0.0 255.255.255.0 10.0.0.139 10.0.0.139 20
10.0.0.139 255.255.255.255 127.0.0.1 127.0.0.1 20
10.255.255.255 255.255.255.255 10.0.0.139 10.0.0.139 20
81.91.82.97 255.255.255.255 10.0.0.138 10.0.0.139 20
89.187.141.121 255.255.255.255 10.0.0.138 10.0.0.139 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
224.0.0.0 240.0.0.0 10.0.0.139 10.0.0.139 20
255.255.255.255 255.255.255.255 10.0.0.139 10.0.0.139 1
Věchozˇ br na: 10.0.0.138
===========================================================================
Trval‚ trasy:
¦ dn‚
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\System32\mswsock.dll [247296] (Microsoft Corporation)
Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\Windows\System32\mswsock.dll [247296] (Microsoft Corporation)
Catalog9 01 C:\Windows\system32\mswsock.dll [247296] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [247296] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [247296] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [247296] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [247296] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [247296] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [247296] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [247296] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [247296] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [247296] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [247296] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (08/01/2012 08:28:51 AM) (Source: LoadPerf) (User: )
Description: Nelze číst řetězce čítače výkonu ID jazyka 005.
Stav Win32 vrácený voláním je v první hodnotě DWORD v datové oblasti.

Error: (08/01/2012 08:28:48 AM) (Source: LoadPerf) (User: )
Description: Nezdařilo se uvolnění řetězců čítače výkonu pro WmiApRpl (WmiApRpl).
Kód chyby je v první hodnotě DWORD v datové oblasti.

Error: (08/01/2012 08:24:43 AM) (Source: MSSQLSERVER) (User: )
Description: Performance counter shared memory setup failed with error -1. Reinstall sqlctr.ini for this instance, and ensure that the instance login account has correct registry permissions.

Error: (08/01/2012 08:24:43 AM) (Source: MSSQLSERVER) (User: )
Description: Error in mapping SQL Server performance object/counter indexes to object/counter names. SQL Server performance counters are disabled.

Error: (07/31/2012 07:34:10 PM) (Source: LoadPerf) (User: )
Description: Nelze číst řetězce čítače výkonu ID jazyka 005.
Stav Win32 vrácený voláním je v první hodnotě DWORD v datové oblasti.

Error: (07/31/2012 07:34:07 PM) (Source: LoadPerf) (User: )
Description: Nezdařilo se uvolnění řetězců čítače výkonu pro WmiApRpl (WmiApRpl).
Kód chyby je v první hodnotě DWORD v datové oblasti.

Error: (07/31/2012 07:29:52 PM) (Source: MSSQLSERVER) (User: )
Description: Performance counter shared memory setup failed with error -1. Reinstall sqlctr.ini for this instance, and ensure that the instance login account has correct registry permissions.

Error: (07/31/2012 07:29:52 PM) (Source: MSSQLSERVER) (User: )
Description: Error in mapping SQL Server performance object/counter indexes to object/counter names. SQL Server performance counters are disabled.

Error: (07/31/2012 07:03:15 PM) (Source: LoadPerf) (User: )
Description: Nelze číst řetězce čítače výkonu ID jazyka 005.
Stav Win32 vrácený voláním je v první hodnotě DWORD v datové oblasti.

Error: (07/31/2012 07:03:11 PM) (Source: LoadPerf) (User: )
Description: Nezdařilo se uvolnění řetězců čítače výkonu pro WmiApRpl (WmiApRpl).
Kód chyby je v první hodnotě DWORD v datové oblasti.


System errors:
=============
Error: (08/01/2012 08:24:53 AM) (Source: Service Control Manager) (User: )
Description: Služba PAR1284 neuspěla při spuštění v důsledku následující chyby:
%%20

Error: (07/31/2012 07:30:10 PM) (Source: Service Control Manager) (User: )
Description: Služba PAR1284 neuspěla při spuštění v důsledku následující chyby:
%%20

Error: (07/31/2012 06:59:04 PM) (Source: Service Control Manager) (User: )
Description: Služba PAR1284 neuspěla při spuštění v důsledku následující chyby:
%%20

Error: (07/31/2012 04:59:18 PM) (Source: Service Control Manager) (User: )
Description: Služba PAR1284 neuspěla při spuštění v důsledku následující chyby:
%%20

Error: (07/31/2012 03:43:32 PM) (Source: Service Control Manager) (User: )
Description: Služba PAR1284 neuspěla při spuštění v důsledku následující chyby:
%%20

Error: (07/31/2012 01:39:33 PM) (Source: Service Control Manager) (User: )
Description: Služba PAR1284 neuspěla při spuštění v důsledku následující chyby:
%%20

Error: (07/31/2012 11:04:43 AM) (Source: Service Control Manager) (User: )
Description: Služba PAR1284 neuspěla při spuštění v důsledku následující chyby:
%%20

Error: (07/31/2012 10:04:50 AM) (Source: Dhcp) (User: )
Description: Zapůjčení adresy IP počítače 10.0.0.139 pro
síťovou kartu se síťovou adresou 00241D100EE8 byla ukončena.

Error: (07/31/2012 09:02:20 AM) (Source: Service Control Manager) (User: )
Description: Služba PAR1284 neuspěla při spuštění v důsledku následující chyby:
%%20

Error: (07/30/2012 07:45:48 PM) (Source: Service Control Manager) (User: )
Description: Služba PAR1284 neuspěla při spuštění v důsledku následující chyby:
%%20


Microsoft Office Sessions:
=========================
Error: (08/01/2012 08:28:51 AM) (Source: LoadPerf)(User: )
Description: 005

Error: (08/01/2012 08:28:48 AM) (Source: LoadPerf)(User: )
Description: WmiApRplWmiApRpl

Error: (08/01/2012 08:24:43 AM) (Source: MSSQLSERVER)(User: )
Description: -1

Error: (08/01/2012 08:24:43 AM) (Source: MSSQLSERVER)(User: )
Description:

Error: (07/31/2012 07:34:10 PM) (Source: LoadPerf)(User: )
Description: 005

Error: (07/31/2012 07:34:07 PM) (Source: LoadPerf)(User: )
Description: WmiApRplWmiApRpl

Error: (07/31/2012 07:29:52 PM) (Source: MSSQLSERVER)(User: )
Description: -1

Error: (07/31/2012 07:29:52 PM) (Source: MSSQLSERVER)(User: )
Description:

Error: (07/31/2012 07:03:15 PM) (Source: LoadPerf)(User: )
Description: 005

Error: (07/31/2012 07:03:11 PM) (Source: LoadPerf)(User: )
Description: WmiApRplWmiApRpl


=========================== Installed Programs ============================

1ClickDownloader (Version: 2.1 Build 26473)
ABBYY FineReader 11 (Version: 11.0.289)
ABBYY FineReader 9.0 Professional Edition (Version: 9.00.724.5507)
ABBYY FineReader 9.0 Sprint (Version: 9.01.513.58212)
Acronis Disk Director (Version: 11.0.2121)
Adobe Flash Player 11 ActiveX (Version: 11.3.300.268)
Adobe Flash Player 11 Plugin (Version: 11.3.300.268)
Adobe Reader X (10.1.3) - Czech (Version: 10.1.3)
Aktualizace systému Windows Internet Explorer 8 (KB2598845) (Version: 1)
Aktualizace systému Windows Internet Explorer 8 (KB2632503) (Version: 1)
Aktualizace systému Windows XP (KB2718704) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2510531) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2544521) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2618444) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2647516) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2675157) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB2699988) (Version: 1)
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB982381) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2685939) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2707511) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB2709162) (Version: 1)
Aktualizace zabezpečení systému Windows XP (KB923789)
AMD Catalyst Install Manager (Version: 8.0.881.0)
ATI AVIVO Codecs (Version: 10.0.0.31121)
ATI Parental Control & Encoder (Version: 3.0)
ATI Problem Report Wizard (Version: 8.10)
AVG 2012 (Version: 12.0.1913)
AVG 2012 (Version: 12.0.2437)
AVG 2012 (Version: 2012.0.1913)
AVG PC Tuneup (Version: 10.0.0.27)
AVG Security Toolbar (Version: 11.1.0.12)
Browser Configuration Utility (Version: 1.0.4.9)
CadStd (Version: 3.7.0)
Canon i350
Canon Utilities Easy-PhotoPrint
ccc-utility (Version: 2009.0113.2222.40119)
ccc-utility (Version: 2011.1109.2146.39010)
ccc-utility (Version: 2011.1205.2146.38999)
CCC Help Czech (Version: 2009.0113.2221.40119)
CCC Help Czech (Version: 2011.1205.2145.38999)
CCC Help Danish (Version: 2009.0113.2221.40119)
CCC Help Danish (Version: 2011.1205.2145.38999)
CCC Help Dutch (Version: 2009.0113.2221.40119)
CCC Help Dutch (Version: 2011.1205.2145.38999)
CCC Help English (Version: 2009.0113.2221.40119)
CCC Help English (Version: 2011.1109.2145.39010)
CCC Help English (Version: 2011.1205.2145.38999)
CCC Help Finnish (Version: 2009.0113.2221.40119)
CCC Help Finnish (Version: 2011.1205.2145.38999)
CCC Help French (Version: 2009.0113.2221.40119)
CCC Help French (Version: 2011.1205.2145.38999)
CCC Help German (Version: 2009.0113.2221.40119)
CCC Help German (Version: 2011.1205.2145.38999)
CCC Help Greek (Version: 2009.0113.2221.40119)
CCC Help Greek (Version: 2011.1205.2145.38999)
CCC Help Hungarian (Version: 2009.0113.2221.40119)
CCC Help Hungarian (Version: 2011.1205.2145.38999)
CCC Help Chinese Standard (Version: 2009.0113.2221.40119)
CCC Help Chinese Standard (Version: 2011.1205.2145.38999)
CCC Help Chinese Traditional (Version: 2009.0113.2221.40119)
CCC Help Chinese Traditional (Version: 2011.1205.2145.38999)
CCC Help Italian (Version: 2009.0113.2221.40119)
CCC Help Italian (Version: 2011.1205.2145.38999)
CCC Help Japanese (Version: 2009.0113.2221.40119)
CCC Help Japanese (Version: 2011.1205.2145.38999)
CCC Help Korean (Version: 2009.0113.2221.40119)
CCC Help Korean (Version: 2011.1205.2145.38999)
CCC Help Norwegian (Version: 2009.0113.2221.40119)
CCC Help Norwegian (Version: 2011.1205.2145.38999)
CCC Help Polish (Version: 2009.0113.2221.40119)
CCC Help Polish (Version: 2011.1205.2145.38999)
CCC Help Portuguese (Version: 2009.0113.2221.40119)
CCC Help Portuguese (Version: 2011.1205.2145.38999)
CCC Help Russian (Version: 2009.0113.2221.40119)
CCC Help Russian (Version: 2011.1205.2145.38999)
CCC Help Spanish (Version: 2009.0113.2221.40119)
CCC Help Spanish (Version: 2011.1205.2145.38999)
CCC Help Swedish (Version: 2009.0113.2221.40119)
CCC Help Swedish (Version: 2011.1205.2145.38999)
CCC Help Thai (Version: 2009.0113.2221.40119)
CCC Help Thai (Version: 2011.1205.2145.38999)
CCC Help Turkish (Version: 2009.0113.2221.40119)
CCC Help Turkish (Version: 2011.1205.2145.38999)
CCleaner (Version: 3.20)
Combined Community Codec Pack 2011-11-11 (Version: 2011.11.11.0)
Connectivity Abstraction Layer (Version: 1.3.014)
Crysis® 2 (Version: 1.0.0.0)
CrystalDiskInfo 4.2.0a (Version: 4.2.0a)
CZShare Manager (Version: 0.0.1.35)
DAEMON Tools Lite (Version: 4.45.1.0236)
ECULP 4.0
Epson Easy Photo Print 2 (Version: 2.2.3.0)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (Version: 1.00.0000)
Epson Event Manager (Version: 2.40.0001)
EPSON Scan
EPSON SX420W Series Manuál
EPSON SX420W Series Printer Uninstall
EPSON SX420W Series Síťová příručka
EpsonNet Print (Version: 2.4j)
EpsonNet Setup 3.2 (Version: 3.2a)
ESET Online Scanner v3
EVEREST Ultimate Edition v5.50 (Version: 5.50)
FCleaner 1.3.1.621
File Scavenger 3.2 (Version: 3.2)
FormatFactory 2.95 (Version: 2.95)
GetDataBack for NTFS (Version: 4.25.000)
GOM Player (Version: 2.1.40.5106)
Google Chrome (Version: 20.0.1132.57)
HD Tune 2.55
HijackThis 2.0.2 (Version: 2.0.2)
ICQ7.7 (Version: 7.7)
Java Auto Updater (Version: 2.1.5.3)
Java(TM) 7 Update 2 (Version: 7.0.20)
JD Common Loader (Version: 1.15.0005)
JD Field General (Version: 3.01.0001)
JD NetComm Serial (Version: 2.02.0001)
JD NetComm V2 (Version: 2.02.0008)
JD Payload Processor (Version: 3.05.0006)
Malwarebytes Anti-Malware verze 1.62.0.1300 (Version: 1.62.0.1300)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Czech Language Pack (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB2656370)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - CSY (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - CSY (Version: 3.2.30729)
Microsoft .NET Framework 3.5 Language Pack SP1 - csy (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1)
Microsoft Office Standard Edition 2003 (Version: 11.0.8173.0)
Microsoft Silverlight (Version: 5.0.61118.0)
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (Version: 9.2.3042.00)
Microsoft SQL Server Native Client (Version: 9.00.3042.00)
Microsoft SQL Server Setup Support Files (English) (Version: 9.00.3042.00)
Microsoft SQL Server VSS Writer (Version: 9.00.3042.00)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
MiraScan 6.1(5150C) (Version: V6.1(5150C))
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0)
MSXML 6.0 Parser (Version: 6.10.1129.0)
Nero 7 Ultra Edition (Version: 7.02.9752)
neroxml (Version: 1.0.0)
NEXIQ Readings (Version: 3.01.320)
nLite 1.4.8 (Version: 1.4.8)
Nuclear Coffee - VideoGet (Version: 2012)
NVIDIA PhysX (Version: 9.10.0513)
O&O Defrag Professional (Version: 15.0.107)
OpenOffice.org 3.0 (Version: 3.0.9358)
Opera 12.00 (Version: 12.00.1467)
PC Tools Registry Mechanic 11.0 (Version: 11.0)
PDFCreator (Version: 1.2.3)
Polda III karty
Polda III čára
Pošta a kancelář 3.6
REALTEK GbE & FE Ethernet PCI-E NIC Driver (Version: 1.17.0000)
Realtek High Definition Audio Driver (Version: 5.10.0.5694)
Sada Compatibility Pack pro systém Office 2007 (Version: 12.0.6514.5001)
Seemage Players (Version: 4.2.0.1180)
Software602 Form Filler (Version: 4.13)
Software602 Print2PDF (Version: 9.1.11.0421)
Sony Ericsson PC Suite 1.20.173 (Version: 1.20.173)
StreamTransport version: 1.0.2.2171
SweetIM for Messenger 3.6 (Version: 3.6.0008)
Swiff Player 1.5 (Version: 1.54)
Traktor 2 (Version: 1.0)
Trine 2
Ubisoft Game Launcher (Version: 1.0.0.0)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update Manager for SweetPacks 1.0 (Version: 1.0.0005)
VMR Client Install (Version: 1.00.0000)
Výpočet DPH podle §37 (Version: 1.0.0.1)
WebFldrs XP (Version: 9.50.5318)
Windows Installer Clean Up (Version: 3.00.00.0000)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3 (Version: 20080414.031517)
WinRAR 4.01 (32-bit) (Version: 4.01.0)
XML Paper Specification Shared Components Language Pack 1.0
Yontoo 1.10.02 (Version: 1.10.02)

========================= Memory info: ===================================

Percentage of memory in use: 24%
Total physical RAM: 3326.42 MB
Available physical RAM: 2527.51 MB
Total Pagefile: 5210.33 MB
Available Pagefile: 4389.52 MB
Total Virtual: 2047.88 MB
Available Virtual: 1973.96 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:68.36 GB) (Free:29.46 GB) NTFS
2 Drive d: () (Fixed) (Total:59.63 GB) (Free:37.03 GB) NTFS
4 Drive f: () (Fixed) (Total:337.77 GB) (Free:117.35 GB) NTFS
5 Drive g: (system) (Fixed) (Total:127.99 GB) (Free:46.14 GB) NTFS
6 Drive i: (starý disk) (Fixed) (Total:68.36 GB) (Free:40.2 GB) NTFS
8 Drive k: (vše ostatní) (Fixed) (Total:171.77 GB) (Free:42.29 GB) NTFS
9 Drive l: (programy) (Fixed) (Total:97.65 GB) (Free:47.98 GB) NTFS

========================= Users: ========================================

U§ivatelsk‚ Łźty pro \\ADMIN

Administrator ASPNET Guest
HelpAssistant SUPPORT_388945a0 u§ivatel
Pýˇkaz byl ŁspŘçnŘ dokonźen.


**** End of log ****


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 7 hostů