HJT - neustále zapnutý program, chci ho zrušit

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: 11 úno 2009 15:44
Bydliště: Jihlava
Kontaktovat uživatele:

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvek od Stene »

VirusTotal
http://www.virustotal.com/file-scan/rep ... 1318410054
C:\Windows\System32\Drivers\sprg.sys - jsem ve složce nenašel..
C:\Windows\system32\psxss.exe - jsem ve složce také nenašel..


Dále bude nutno odstranit:
C:\Windows\system32\DRIVERS\24752363.sys
C:\Windows\system32\DRIVERS\35631669.sys
C:\Windows\System32\Drivers\dump_atapi.sys
C:\Windows\System32\Drivers\dump_dumpata.sys
C:\Windows\System32\Drivers\dump_dumpfve.sys
-> mám smazat ručně?

24752363
35631669
catchme
S tímto mám dělat co?


Spouštím olt
Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: 11 úno 2009 15:44
Bydliště: Jihlava
Kontaktovat uživatele:

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvek od Stene »

OTL Extras logfile created on: 12.10.2011 11:23:18 - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Stene\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 2,61 Gb Available Physical Memory | 65,35% Memory free
7,99 Gb Paging File | 6,57 Gb Available in Paging File | 82,20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 489,03 Gb Total Space | 337,48 Gb Free Space | 69,01% Space Free | Partition Type: NTFS
Drive D: | 100,00 Mb Total Space | 70,37 Mb Free Space | 70,37% Space Free | Partition Type: NTFS
Drive E: | 246,09 Gb Total Space | 202,64 Gb Free Space | 82,34% Space Free | Partition Type: NTFS
Drive F: | 213,47 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
Drive G: | 196,29 Gb Total Space | 134,27 Gb Free Space | 68,40% Space Free | Partition Type: NTFS
Drive H: | 5,68 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: STENE-PC | User Name: Stene | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- Reg Error: Key error. File not found
.cmd [@ = cmdfile] -- Reg Error: Key error. File not found
.com [@ = ComFile] -- Reg Error: Key error. File not found
.exe [@ = exefile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.pif [@ = piffile] -- Reg Error: Key error. File not found
.vbs [@ = VBSFile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{38DCF0E4-948D-262D-88E6-57CDE6BB982A}" = ccc-utility64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{62BDA98E-352B-5244-FA5C-5C441EF799EB}" = ATI AVIVO64 Codecs
"{7EFF6FF7-45DE-A868-8300-615D7038879E}" = ATI Catalyst Install Manager
"{7F05E704-30A6-421A-97A7-8EEB1C7FF011}" = Corel Shell Extension - 64Bit
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0405-1000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2010
"{90140000-0016-0405-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2010
"{90140000-0018-0405-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2010
"{90140000-0019-0405-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2010
"{90140000-001A-0405-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2010
"{90140000-001B-0405-1000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2010
"{90140000-001F-0405-1000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2010
"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-041B-1000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2010
"{90140000-002C-0405-1000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0405-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Czech) 2010
"{90140000-0044-0405-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2010
"{90140000-006E-0405-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2010
"{90140000-00A1-0405-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2010
"{90140000-00BA-0405-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2010
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F62B016F-677E-0079-0052-18D45F186798}" = AMD Drag and Drop Transcoding
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.56
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.17
"FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"MAXONB6EC381C" = CINEMA 4D 11.532
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{7F05E704-30A6-421A-97A7-8EEB1C7FF010}" = CorelDRAW(R) Graphics Suite X4
"_{CE2DA11A-917F-4CF5-AB55-755EC115DD10}" = CorelDRAW(R) Graphics Suite X4 - Windows Shell Extension
"{03496F77-5835-D529-1ED8-044FCD372E0F}" = HydraVision
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08600005-5228-4BF6-845E-E9A957AFDCB4}" = OviMPlatform
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{1370D655-9DA3-EF82-FB57-BC5A2DCCD020}" = CCC Help Japanese
"{17D6207F-F9F4-1FDE-3F6B-C5B67CFD87C9}" = Catalyst Control Center Graphics Full New
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1DA18566-1084-CE33-5BC5-A214B8FC0CA4}" = CCC Help Norwegian
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22B4D0B5-81C5-ACE0-94CB-72E875B447A4}" = Catalyst Control Center Graphics Previews Common
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 23
"{293D5729-7C01-4FA4-A4DE-BB6A1587BBB9}" = PDF Settings
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{3553E875-F00E-4031-BDEC-75FB1DFEB093}" = Nokia Ovi Suite Software Updater
"{3557DE52-1836-4421-962C-F5C323FA57B7}" = Adobe Creative Suite 3 Design Premium
"{36ABE32F-D7D4-4A5E-AADD-589F506B1B50}" = Nokia Ovi Suite
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{39B00E05-32F6-4BC3-943E-EDEFD4CA3ACB}" = Adobe Version Cue CS3 Server
"{3D4AEA8C-3FD2-AB03-9E3A-F040B42E0BA3}" = CCC Help Portuguese
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}" = FIFA 11
"{4216D328-0FE8-48B8-85B8-BD300E6F080F}" = Nokia Connectivity Cable Driver
"{44136AFD-2559-F68C-10E3-AC269CE942A7}" = CCC Help Danish
"{44A27085-0616-4181-A0C3-81C7ECA17F73}" = CorelDRAW Graphics Suite X4
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46942F53-F6B5-E272-6989-0C75BBDF2668}" = CCC Help Chinese Standard
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EE4C1F0-B0BF-37CA-2555-ED586F17C5C9}" = Catalyst Control Center Graphics Previews Vista
"{5178C1BB-1EB1-4468-894B-7DE964DDCAA2}" = Adobe Photoshop CS3
"{53EBA2A9-50F2-16EB-3A44-C99BFF927032}" = Catalyst Control Center Graphics Light
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5629D545-08E1-516E-F498-082A72A5269D}" = CCC Help Polish
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5C329FB8-04D8-D32B-18B8-FA7594040FC0}" = CCC Help Dutch
"{6179A7D2-A668-4F1D-BC9A-DCC6A10C7871}" = Adobe Color NA Extra Settings
"{69916AD2-3710-4C86-895E-8F475290AA64}" = Ovi Desktop Sync Engine
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A0AEB7F-E55B-809B-0D05-F843032B75F7}" = Catalyst Control Center Graphics Full Existing
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
"{6D12B99F-EAAA-49D8-8E2F-74FA7459CCB2}" = Adobe Asset Services CS3
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6F05FB49-2086-2FED-E2CC-824C189E9C75}" = CCC Help Russian
"{75F440C9-C292-1BA6-9755-C94F800657E9}" = ccc-core-static
"{7694E0B1-2332-448B-9235-929F84B41E3F}" = Active@ ISO Burner
"{77FD4E2C-EDDA-D622-6DAA-6DDE7B17DE85}" = Catalyst Control Center Localization All
"{7ACC5E2B-B543-2E93-F37D-A1390847FF29}" = CCC Help Thai
"{7B4A5C13-069F-4AFE-AE57-C497B4E33C7E}" = Call of Duty(R) 2 Patch 1.3
"{7EDFCB74-81C0-4FB6-9FDF-1BC7CD098638}" = Adobe InDesign CS3
"{7F05E704-30A6-421A-97A7-8EEB1C7FF010}" = CorelDRAW Graphics SUite X4 - ICA
"{7F05E704-30A6-421A-97A7-8EEB1C7FF012}" = CorelDRAW Graphics Suite X4 - Capture
"{7F05E704-30A6-421A-97A7-8EEB1C7FF013}" = CorelDRAW Graphics Suite X4 - Draw
"{7F05E704-30A6-421A-97A7-8EEB1C7FF014}" = CorelDRAW Graphics Suite X4 - PP
"{7F05E704-30A6-421A-97A7-8EEB1C7FF016}" = CorelDRAW Graphics Suite X4 - Content
"{7F05E704-30A6-421A-97A7-8EEB1C7FF017}" = CorelDRAW Graphics Suite X4 - Filters
"{7F05E704-30A6-421A-97A7-8EEB1C7FF019}" = CorelDRAW Graphics Suite X4 - FontNav
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{82EF29B1-9B60-4142-A155-0599216DD053}" = LightScribe System Software
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87323561-58BA-4D5B-BADA-A791B69D1705}" = Catalyst Control Center - Branding
"{878C6821-18F9-F6A2-42A7-1ACB1A14AF5C}" = CCC Help Hungarian
"{87AE7C09-B0B4-4BAC-AADB-50A1EAD03768}" = Adobe Flash Video Encoder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{919635D1-5C0D-4B64-B724-BDDB31D11029}" = Nero 8
"{946CC1D8-6E30-2A7C-3AC1-D433ED4FB00B}" = CCC Help Finnish
"{9773450C-E2F3-46C3-9464-1D7EDE5EFB63}" = Pro Evolution Soccer 2011
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9CDF34B4-B53E-54B5-9BA9-7FAA41693BF0}" = CCC Help Czech
"{9D0798D0-AF6C-4E62-94B1-AEBF1A43E00A}" = CorelDRAW Graphics Suite X4 - IPM
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A60ABB01-915B-E5A4-5120-0976C0D7697F}" = CCC Help English
"{A7238DAD-BF6A-3D96-8436-065A1175B39A}" = CCC Help Chinese Traditional
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1029-0000-7760-000000000003}" = Adobe Acrobat 8 Professional - Czech, Greek, Hungarian, Polish, Slovak
"{AC76BA86-7AD7-1029-7B44-AA0000000001}" = Adobe Reader X (10.0.1) - Czech
"{AE6BE2FE-5D3D-4FA0-98BC-57B7B78493F4}" = Adobe Flash CS3
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B2B123D3-E780-4EB0-B540-18F5FCC6EFE9}_is1" = ISO Image Burner 1.1
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B61D21B6-469D-4423-B161-62DB20B8A70E}" = Visual Basic for Applications (R) Core - English
"{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
"{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}" = Adobe BridgeTalk Plugin CS3
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}" = Adobe Flash Player 9 ActiveX
"{BD087F50-46B2-43E4-BD73-5DB3DC20B47C}" = Adobe Color EU Recommended Settings
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{BF439B41-0252-48DE-8B8B-0430CB26A181}" = CorelDRAW Graphics Suite X4 - VBA
"{C05290B3-B125-2481-BC4D-7C4BE5126DD5}" = CCC Help Korean
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C310995F-B785-4252-6A3B-333BA411DE6B}" = CCC Help French
"{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
"{CE2DA11A-917F-4CF5-AB55-755EC115DD10}" = CorelDRAW(R) Graphics Suite X4 - Windows Shell Extension
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D4AEC53C-1720-41D9-B6D7-6A60DE62D444}" = PC Connectivity Solution
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D6CD1A90-1421-4F19-AFD8-BE4E28A1D6D5}" = Adobe Illustrator CS3
"{D92B72E2-C854-4738-8ED6-4C3661CC17AE}" = Adobe Color JA Extra Settings
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DB81779E-7CC5-4630-BCFC-754004956444}" = Visual Basic for Applications (R) Core
"{E2082A6B-2334-2533-A5ED-41B537ECD02A}" = CCC Help German
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E84FA784-3305-5E34-16C8-51949D03C059}" = Catalyst Control Center InstallProxy
"{E9A28E0B-F85A-FFDA-C486-C0D34AD506AF}" = CCC Help Turkish
"{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
"{EC318F8C-CECC-B31E-44C4-55A1A63E41D5}" = CCC Help Greek
"{ECAD020B-3418-E868-FC8D-668FA6C6A019}" = Catalyst Control Center HydraVision Full
"{ED95B55C-4759-4242-85DE-EAD1DA7AB090}" = Adobe Dreamweaver CS3
"{F4B6FE67-B077-472E-1B06-0D50C8B05206}" = CCC Help Swedish
"{F4B70AA9-AA91-4894-4AC5-61A6934CD85B}" = Catalyst Control Center Core Implementation
"{F525FDB5-C9D4-6505-ACB9-90C921C83ACD}" = CCC Help Italian
"{FCEC4C5A-ACED-4644-B561-D7A3FB76ABEB}" = Adobe Setup
"{FE83F56A-D87F-E70E-AE6E-749DFBE27666}" = CCC Help Spanish
"{FFFE7261-2318-4227-B827-E9E05E16DFE5}" = CorelDRAW Graphics Suite X4 - Lang CZ
"Adobe Acrobat 8 Professional - Czech, Greek, Hungarian, Polish, Slovak" = Adobe Acrobat 8 Professional - Czech, Greek, Hungarian, Polish, Slovak
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_5d77a08a09fb71a9f854912b198353c" = Přidat nebo odebrat Adobe Creative Suite 3 Design Premium
"Altap Salamander 2.54" = Altap Salamander 2.54
"avast" = avast! Free Antivirus
"BitLord" = BitLord 1.1
"DAEMON Tools Lite" = DAEMON Tools Lite
"HD Tune Pro_is1" = HD Tune Pro 4.61
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty(R) 2
"Mafia II_is1" = Mafia II
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware verze 1.51.2.1300
"Mozilla Firefox (3.6.23)" = Mozilla Firefox (3.6.23)
"Mozilla Thunderbird (7.0.1)" = Mozilla Thunderbird (7.0.1)
"Nokia Ovi Suite" = Nokia Ovi Suite
"PSPad editor_is1" = PSPad editor
"SLABCOMM&10C4&EA60" = Leadtek GPS USB to UART Bridge (Driver Removal)
"SpeedFan" = SpeedFan (remove only)
"WinRAR archiver" = WinRAR
"ZonerPhotoStudio12_CZ_is1" = Zoner Photo Studio 12

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"QIP Infium" = QIP Infium 3.0.9040

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11.10.2011 5:45:51 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 11.10.2011 5:45:51 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 11.10.2011 5:45:51 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 11.10.2011 5:45:51 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 4:05:53 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 4:05:53 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 4:05:53 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 4:05:53 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 5:19:48 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .

Error - 12.10.2011 5:21:42 | Computer Name = Stene-PC | Source = Application Error | ID = 1000
Description = Název chybující aplikace: OTL.exe, verze: 3.2.29.1, časové razítko:
0x2a425e19 Název chybujícího modulu: KERNELBASE.dll, verze: 6.1.7601.17651, časové
razítko: 0x4e211319 Kód výjimky: 0x0eedfade Posun chyby: 0x0000b9bc ID chybujícího
procesu: 0x454 Čas spuštění chybující aplikace: 0x01cc88c058359cfa Cesta k chybující
aplikaci: C:\Users\Stene\Downloads\OTL.exe Cesta k chybujícímu modulu: C:\Windows\syswow64\KERNELBASE.dll
ID
zprávy: 983027c6-f4b3-11e0-b591-1c6f65488479

[ Media Center Events ]
Error - 14.3.2011 4:34:52 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 9:34:52 - Chyba při připojování k Internetu 9:34:52 - Nelze kontaktovat
server..

Error - 14.3.2011 4:34:58 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 9:34:57 - Chyba při připojování k Internetu 9:34:57 - Nelze kontaktovat
server..

Error - 14.3.2011 5:35:41 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 10:35:37 - Načtení položky Broadband se nezdařilo. (Chyba: Nadřízené
připojení bylo uzavřeno: Došlo k neočekávané chybě při příjmu.)

Error - 14.3.2011 6:35:47 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 11:35:46 - Chyba při připojování k Internetu 11:35:46 - Nelze kontaktovat
server..

Error - 3.4.2011 4:55:52 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 10:55:51 - Chyba při připojování k Internetu 10:55:52 - Nelze kontaktovat
server..

Error - 3.4.2011 4:56:00 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 10:55:57 - Chyba při připojování k Internetu 10:55:57 - Nelze kontaktovat
server..

Error - 7.5.2011 0:03:39 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 6:03:38 - Chyba při připojování k Internetu 6:03:38 - Nelze kontaktovat
server..

Error - 7.5.2011 0:03:48 | Computer Name = Stene-PC | Source = MCUpdate | ID = 0
Description = 6:03:44 - Chyba při připojování k Internetu 6:03:44 - Nelze kontaktovat
server..

[ System Events ]
Error - 3.10.2011 15:46:56 | Computer Name = Stene-PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.

Error - 3.10.2011 15:48:40 | Computer Name = Stene-PC | Source = Application Popup | ID = 1060
Description = Načtení \??\C:\ComboFix\catchme.sys bylo zablokováno kvůli nekompatibilitě
s tímto systémem. Požádejte dodavatele softwaru o kompatibilní verzi ovladače.

Error - 3.10.2011 15:48:41 | Computer Name = Stene-PC | Source = Application Popup | ID = 1060
Description = Načtení \??\C:\ComboFix\catchme.sys bylo zablokováno kvůli nekompatibilitě
s tímto systémem. Požádejte dodavatele softwaru o kompatibilní verzi ovladače.

Error - 3.10.2011 15:49:12 | Computer Name = Stene-PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.

Error - 8.10.2011 10:34:36 | Computer Name = Stene-PC | Source = DCOM | ID = 10010
Description =

Error - 10.10.2011 4:30:04 | Computer Name = Stene-PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.

Error - 10.10.2011 4:31:52 | Computer Name = Stene-PC | Source = Application Popup | ID = 1060
Description = Načtení \??\C:\ComboFix\catchme.sys bylo zablokováno kvůli nekompatibilitě
s tímto systémem. Požádejte dodavatele softwaru o kompatibilní verzi ovladače.

Error - 10.10.2011 4:31:52 | Computer Name = Stene-PC | Source = Application Popup | ID = 1060
Description = Načtení \??\C:\ComboFix\catchme.sys bylo zablokováno kvůli nekompatibilitě
s tímto systémem. Požádejte dodavatele softwaru o kompatibilní verzi ovladače.

Error - 10.10.2011 4:32:19 | Computer Name = Stene-PC | Source = Service Control Manager | ID = 7030
Description = Služba PEVSystemStart je označena jako interaktivní služba. Avšak
systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba
nebude fungovat správně.

Error - 11.10.2011 4:13:56 | Computer Name = Stene-PC | Source = DCOM | ID = 10010
Description =


< End of report >
Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: 11 úno 2009 15:44
Bydliště: Jihlava
Kontaktovat uživatele:

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvek od Stene »

OTL logfile created on: 12.10.2011 11:23:18 - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Stene\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 2,61 Gb Available Physical Memory | 65,35% Memory free
7,99 Gb Paging File | 6,57 Gb Available in Paging File | 82,20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 489,03 Gb Total Space | 337,48 Gb Free Space | 69,01% Space Free | Partition Type: NTFS
Drive D: | 100,00 Mb Total Space | 70,37 Mb Free Space | 70,37% Space Free | Partition Type: NTFS
Drive E: | 246,09 Gb Total Space | 202,64 Gb Free Space | 82,34% Space Free | Partition Type: NTFS
Drive F: | 213,47 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: UDF
Drive G: | 196,29 Gb Total Space | 134,27 Gb Free Space | 68,40% Space Free | Partition Type: NTFS
Drive H: | 5,68 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: STENE-PC | User Name: Stene | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Stene\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\js3250.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (ServiceLayer) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (Adobe Version Cue CS3) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (usbser) -- C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (UsbserFilt) -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys (Nokia)
DRV:64bit: - (upperdev) -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (nmwcdc) -- C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (nmwcd) -- C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (pccsmcfd) -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (silabser) -- C:\Windows\SysNative\drivers\silabser.sys (Silicon Laboratories)
DRV:64bit: - (silabenm) -- C:\Windows\SysNative\drivers\silabenm.sys (Silicon Laboratories, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (speedfan) -- C:\Windows\SysWOW64\speedfan.sys (Windows (R) Server 2003 DDK provider)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "QIP Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.2.2
FF - prefs.js..extensions.enabledItems: ranky@ranky.cz:0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.10.2
FF - prefs.js..extensions.enabledItems: {3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}:0.8.6.1
FF - prefs.js..extensions.enabledItems: cs@dictionaries.addons.mozilla.org:1.0.2
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Stene\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Stene\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010.12.25 10:56:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011.09.29 16:31:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011.09.29 16:31:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.09.23 23:28:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010.12.25 10:56:50 | 000,000,000 | ---D | M]

[2011.03.06 19:32:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions
[2011.03.06 19:32:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.11.02 18:11:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2011.10.11 22:53:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions
[2011.02.26 12:11:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
[2011.05.25 21:14:06 | 000,000,000 | ---D | M] (Html Validator) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}
[2010.11.12 12:12:26 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2011.02.26 12:11:40 | 000,000,000 | ---D | M] (Page Speed) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2011.06.24 20:02:28 | 000,000,000 | ---D | M] (České slovníky pro kontrolu pravopisu) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\cs@dictionaries.addons.mozilla.org
[2011.01.22 19:18:07 | 000,000,000 | ---D | M] (Ranky) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\ranky@ranky.cz
[2011.03.09 17:23:05 | 000,002,059 | ---- | M] () -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\searchplugins\daemon-search.xml
[2010.11.06 18:31:33 | 000,002,062 | ---- | M] () -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\searchplugins\qip-search.xml
[2011.10.03 16:01:04 | 000,001,391 | ---- | M] () -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\searchplugins\yahoo-zugo.xml
[2011.01.25 19:27:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011.09.29 16:31:11 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011.01.25 19:27:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.09.29 16:31:10 | 000,025,048 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2011.09.29 16:31:10 | 000,140,248 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2007.04.10 18:21:08 | 000,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll
[2011.01.25 19:27:01 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011.09.29 16:31:10 | 000,066,520 | ---- | M] (mozilla.org) -- C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2011.01.30 17:45:12 | 000,135,568 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2011.08.21 21:18:35 | 000,002,371 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2011.08.21 21:18:35 | 000,000,638 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\jyxo-cz.xml
[2011.08.21 21:18:35 | 000,001,687 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\mall-cz.xml
[2011.08.21 21:18:35 | 000,001,367 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\seznam-cz.xml
[2011.08.21 21:18:35 | 000,000,654 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.08.21 21:18:35 | 000,001,179 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-cz.xml

========== Chrome ==========

CHR - default_search_provider: Yahoo (Enabled)
CHR - default_search_provider: search_url = http://www.etypestart.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=697&product_id=730&affiliate_id=&channel=&toolbar_id=205&toolbar_version=2.3.0&install_country=CZ&install_date=20111003&user_guid=93D1C7CAC2BF44DE9C2E21F710E5670E&machine_id=51d5f038087191619d0d0687cdd24d34&browser=CR&os=win&os_version=6.1-x64-SP1
CHR - default_search_provider: suggest_url = ,
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Stene\AppData\Local\Google\Chrome\Application\8.0.552.224\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\Stene\AppData\Local\Google\Chrome\Application\8.0.552.224\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Stene\AppData\Local\Google\Chrome\Application\8.0.552.224\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Users\Stene\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2011.10.10 10:33:42 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Podpora odkazu pro Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\SysWow64\grpconv.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Thunderbird.lnk = C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
O4 - Startup: C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk = C:\Users\Stene\AppData\Local\Temp\_uninst_77286306.bat ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Od&eslat do aplikace OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8:64bit: - Extra context menu item: Převést cíl vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést cíl vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést výběr do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést výběr do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést vybrané vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Převést vybrané vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Přidat do stávajícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Od&eslat do aplikace OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést výběr do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést výběr do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Přidat do stávajícího PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9:64bit: - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{538B7099-999C-48D3-A0BF-FEE2AC80D8DC}: NameServer = 10.0.0.138
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysNative\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O29:64bit: - HKLM SecurityProviders - (credssp.dll) -C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) -C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) -C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) -C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) -C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) -C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) -C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) -C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) -C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.05.25 15:35:32 | 000,000,030 | R--- | M] () - F:\Autorun.inf -- [ UDF ]
O32 - AutoRun File - [2011.03.09 18:49:10 | 000,000,000 | ---- | M] () - G:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.08.17 06:32:28 | 000,000,047 | R--- | M] () - H:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2010.08.17 06:32:28 | 000,335,752 | R--- | M] (Konami Digital Entertainment Co., Ltd.) - H:\autorun.exe -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...com [@ = ComFile] -- Reg Error: Key error. File not found
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011.10.12 11:21:23 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Users\Stene\Desktop\OTL.exe
[2011.10.11 10:26:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2011.10.10 10:50:17 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011.10.03 16:18:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011.10.03 16:18:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011.10.03 16:13:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2011.10.03 16:13:09 | 000,000,000 | ---D | C] -- C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011.10.03 16:01:13 | 000,000,000 | ---D | C] -- C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eType
[2011.10.03 16:00:30 | 000,000,000 | ---D | C] -- C:\Users\Stene\AppData\Roaming\eType
[2011.09.22 21:03:07 | 000,000,000 | R--D | C] -- C:\Users\Stene\Desktop\písničky
[2011.09.21 15:48:01 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2011.09.21 15:47:06 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders

========== Files - Modified Within 30 Days ==========

[2011.10.12 11:21:26 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Stene\Desktop\OTL.exe
[2011.10.12 11:09:06 | 000,000,952 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.10.12 10:33:01 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1679234959-3771141595-1235745478-1001UA.job
[2011.10.12 10:09:57 | 000,014,832 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.10.12 10:09:57 | 000,014,832 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.10.12 10:09:00 | 000,000,948 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.10.12 10:02:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.10.12 10:02:11 | 3219,300,352 | -HS- | M] () -- C:\hiberfil.sys
[2011.10.12 00:38:42 | 000,011,310 | ---- | M] () -- C:\Users\Stene\Desktop\avptool_sysinfo.zip
[2011.10.11 18:33:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1679234959-3771141595-1235745478-1001Core.job
[2011.10.11 10:33:18 | 000,001,010 | ---- | M] () -- C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk
[2011.10.11 10:26:25 | 098,427,064 | ---- | M] () -- C:\Users\Stene\Desktop\setup_11.0.0.1245.x01_2011_10_11_09_31.exe
[2011.10.10 10:33:42 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011.10.08 16:34:33 | 000,001,471 | ---- | M] () -- C:\Users\Stene\Desktop\ComboFix – zástupce.lnk
[2011.10.08 16:34:08 | 000,095,622 | ---- | M] () -- C:\Users\Stene\Desktop\3.jpg
[2011.10.08 16:34:07 | 000,088,940 | ---- | M] () -- C:\Users\Stene\Desktop\5.jpg
[2011.10.08 16:34:07 | 000,088,920 | ---- | M] () -- C:\Users\Stene\Desktop\4.jpg
[2011.10.08 16:34:07 | 000,072,817 | ---- | M] () -- C:\Users\Stene\Desktop\6.jpg
[2011.10.03 16:18:59 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.10.03 16:13:09 | 000,002,975 | ---- | M] () -- C:\Users\Stene\Desktop\HiJackThis.lnk
[2011.10.01 20:24:44 | 000,001,400 | ---- | M] () -- C:\Users\Stene\AppData\Local\SRDownloader.nast
[2011.09.28 19:25:10 | 002,381,802 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2011.09.28 19:25:10 | 001,222,980 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.09.28 19:25:10 | 000,712,846 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2011.09.28 19:25:10 | 000,680,344 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.09.28 19:25:10 | 000,005,374 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.09.24 17:06:44 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011.09.22 15:22:59 | 002,349,040 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.09.21 15:56:00 | 000,175,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msclmd.dll
[2011.09.21 15:56:00 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msclmd.dll

========== Files Created - No Company Name ==========

[2011.10.12 00:40:06 | 000,011,310 | ---- | C] () -- C:\Users\Stene\Desktop\avptool_sysinfo.zip
[2011.10.11 10:33:18 | 000,001,010 | ---- | C] () -- C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk
[2011.10.11 10:25:05 | 098,427,064 | ---- | C] () -- C:\Users\Stene\Desktop\setup_11.0.0.1245.x01_2011_10_11_09_31.exe
[2011.10.08 20:03:32 | 1254,821,888 | ---- | C] () -- C:\Users\Stene\Desktop\Letopisy Narnie - Lev, čarodějnice a skříň (2005) .avi
[2011.10.08 16:34:07 | 000,095,622 | ---- | C] () -- C:\Users\Stene\Desktop\3.jpg
[2011.10.08 16:34:06 | 000,088,920 | ---- | C] () -- C:\Users\Stene\Desktop\4.jpg
[2011.10.08 16:34:05 | 000,088,940 | ---- | C] () -- C:\Users\Stene\Desktop\5.jpg
[2011.10.08 16:34:05 | 000,072,817 | ---- | C] () -- C:\Users\Stene\Desktop\6.jpg
[2011.10.03 21:42:14 | 000,001,471 | ---- | C] () -- C:\Users\Stene\Desktop\ComboFix – zástupce.lnk
[2011.10.03 16:18:59 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011.10.03 16:13:09 | 000,002,975 | ---- | C] () -- C:\Users\Stene\Desktop\HiJackThis.lnk
[2011.10.03 15:52:23 | 1806,571,519 | ---- | C] () -- C:\Users\Stene\Desktop\rld-pe11.iso
[2011.09.23 23:28:38 | 000,002,106 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2011.08.15 19:13:15 | 000,001,400 | ---- | C] () -- C:\Users\Stene\AppData\Local\SRDownloader.nast
[2011.08.10 11:29:13 | 000,000,600 | ---- | C] () -- C:\Users\Stene\AppData\Roaming\winscp.rnd
[2011.08.01 21:08:54 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011.08.01 21:08:54 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011.08.01 21:08:54 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.08.01 21:08:54 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.08.01 21:08:54 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.06.02 21:46:41 | 000,005,994 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.05.12 10:40:31 | 000,004,608 | ---- | C] () -- C:\Users\Stene\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.04.05 09:54:20 | 000,000,008 | RHS- | C] () -- C:\ProgramData\DB013D6F68.sys
[2011.04.01 16:19:59 | 000,000,194 | ---- | C] () -- C:\Users\Stene\AppData\Roaming\varicad-work.ini
[2011.03.30 19:26:22 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011.03.13 13:15:59 | 000,000,161 | ---- | C] () -- C:\Windows\AutoKMS.ini
[2011.01.21 16:44:17 | 000,000,126 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.12.21 18:01:22 | 000,000,026 | ---- | C] () -- C:\Windows\Irremote.ini
[2010.11.05 19:29:01 | 002,463,976 | ---- | C] () -- C:\Windows\SysWow64\NPSWF32.dll
[2010.11.02 18:40:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010.11.02 18:27:07 | 000,000,256 | ---- | C] () -- C:\Windows\game.ini
[2010.11.02 18:11:20 | 000,002,110 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2009.07.14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009.07.14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009.07.14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2010.11.09 09:49:55 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Atrise
[2010.11.09 11:42:40 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\DAEMON Tools Lite
[2011.02.19 11:12:31 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Emergency Soft
[2011.10.03 21:48:41 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\eType
[2011.08.17 19:36:56 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\HD Tune Pro
[2011.04.16 19:38:58 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Hulubulu
[2011.04.16 21:52:03 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Jpeg Resampler
[2010.12.12 22:02:17 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Leadertech
[2011.04.01 15:53:21 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\MAXON
[2010.12.25 11:05:27 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\PC Suite
[2011.03.06 19:32:51 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Thunderbird
[2011.04.01 16:20:00 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\VariCAD
[2010.12.29 11:41:48 | 000,000,000 | ---D | M] -- C:\Users\Stene\AppData\Roaming\Zoner
[2011.07.29 09:04:58 | 000,032,522 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
Uživatelský avatar
jaro3
člen Security týmu
Příspěvky: 43379
Registrován: 16 čer 2007 18:58
Bydliště: Jižní Čechy

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvek od jaro3 »

Toto otestuj na Virustotal
C:\Program Files\Alwil Software\Avast5\defs\11101102\algo.dll
C:\Windows\System32\Drivers\sprg.sys
C:\Windows\system32\psxss.exe


vlož jen tu cestu a nehledej ty soubory...

Error - 11.10.2011 5:45:51 | Computer Name = Stene-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Selhala extrakce kořenového seznamu jiného výrobce ze souboru CAB
pro automatickou aktualizaci v: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>.
Došlo k chybě: Při ověření se systémovými hodinami nebo časovým razítkem podepsaného
souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti. .


nemáš problém s aktualizacemi?? Napiš , jinak s tím nic dělat nebudu..

Po VT vložím script.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: 11 úno 2009 15:44
Bydliště: Jihlava
Kontaktovat uživatele:

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvek od Stene »

I když vložím jenom cestu, nic to nenajde..
tyhle dna soubory prostě nemůžu najít.. Na ty aktualizace kouknu..

// Tak nějakej problém to hlásilo, ale po ručním nainstalování nějakého fixu to noc nehlásí (jinak aktualizace se podle historie stahuju bez problému)
Uživatelský avatar
jaro3
člen Security týmu
Příspěvky: 43379
Registrován: 16 čer 2007 18:58
Bydliště: Jižní Čechy

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvek od jaro3 »

Fajn!

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
FF - prefs.js..browser.search.defaultenginename: "QIP Search"
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.2.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.10.2
FF - prefs.js..extensions.enabledItems: {3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}:0.8.6.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
[2011.03.06 19:32:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions
[2011.03.06 19:32:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.11.02 18:11:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2011.10.11 22:53:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions
[2011.02.26 12:11:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}
[2011.01.25 19:27:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
CHR - default_search_provider: search_url = http://www.etypestart.com/s/?q={searchTerms}&src=defsearch&provider=&provider_name=yahoo&provider_code=&partner_id=697&product_id=730&affiliate_id=&channel=&toolbar_id=205&toolbar_version=2.3.0&install_country=CZ&install_date=20111003&user_guid=93D1C7CAC2BF44DE9C2E21F710E5670E&machine_id=51d5f038087191619d0d0687cdd24d34&browser=CR&os=win&os_version=6.1-x64-SP1
CHR - default_search_provider: suggest_url = ,
O1 HOSTS File: ([2011.10.10 10:33:42 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {95289393-33EA-4F8D-B952-483415B9C955} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - Startup: C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk = C:\Users\Stene\AppData\Local\Temp\_uninst_77286306.bat ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_23)
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - AutoRun File - [2010.05.25 15:35:32 | 000,000,030 | R--- | M] () - F:\Autorun.inf -- [ UDF ]
O32 - AutoRun File - [2011.03.09 18:49:10 | 000,000,000 | ---- | M] () - G:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.08.17 06:32:28 | 000,000,047 | R--- | M] () - H:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2010.08.17 06:32:28 | 000,335,752 | R--- | M] (Konami Digital Entertainment Co., Ltd.) - H:\autorun.exe -- [ CDFS ]
[2011.09.28 19:25:10 | 002,381,802 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2011.09.28 19:25:10 | 001,222,980 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.09.28 19:25:10 | 000,712,846 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2011.09.28 19:25:10 | 000,680,344 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
c:\windows\Tasks\*.job
C:\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Windows\SysNative\drivers\*.tmp
C:\Windows\SysWow64\drivers\*.tmp
C:\Program Files (x86)\*.tmp
C:\Windows\SysWow64\*.tmp
C:\Windows\SysNative\*.tmp
C:\ProgramData\Kaspersky Lab
C:\Users\Stene\AppData\Roaming\eType
C:\Users\Stene\Desktop\avptool_sysinfo.zip
C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk
C:\Users\Stene\Desktop\setup_11.0.0.1245.x01_2011_10_11_09_31.exe
C:\Windows\PEV.exe
C:\Windows\MBR.exe
C:\Windows\sed.exe
C:\Windows\grep.exe
C:\Windows\zip.exe
C:\Users\Stene\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\ProgramData\DB013D6F68.sys
C:\Windows\ativpsrm.bin
C:\Windows\system32\DRIVERS\24752363.sys
C:\Windows\system32\DRIVERS\35631669.sys
C:\Windows\System32\Drivers\dump_atapi.sys
C:\Windows\System32\Drivers\dump_dumpata.sys
C:\Windows\System32\Drivers\dump_dumpfve.sys

:Services
24752363
35631669
catchme

:Reg
:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

Aktualizuj javu:
Java SE Runtime Environment 7

Klikni na Accept License Agreement
Vyber si OS (Windows nebo Windows x64, Offline Installation)
jre-7-windows-i586-p.exe nebo
jre-7-windows-x64.exe
Stáhni ( download) a nainstaluj.
Ostatní javy odeber v přidat/odebrat programy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: 11 úno 2009 15:44
Bydliště: Jihlava
Kontaktovat uživatele:

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvek od Stene »

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Prefs.js: "QIP Search" removed from browser.search.defaultenginename
Prefs.js: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.2.2 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 removed from extensions.enabledItems
Prefs.js: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.10.2 removed from extensions.enabledItems
Prefs.js: {3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}:0.8.6.1 removed from extensions.enabledItems
Prefs.js: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23 removed from extensions.enabledItems
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Extensions folder moved successfully.
Folder C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}\ not found.
Folder C:\Users\Stene\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\ not found.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\WINNT_x86-msvc\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\WINNT_x86-msvc folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Linux_x86_64-gcc3\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Linux_x86_64-gcc3 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Linux_x86-gcc3\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Linux_x86-gcc3 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Darwin_x86-gcc3\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\Darwin_x86-gcc3 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\defaults\preferences folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\defaults folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\chrome\third_party\content folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\chrome\third_party folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\chrome\pagespeed\content folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\chrome\pagespeed folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\chrome folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\Linux\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\Linux folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\Darwin\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\Darwin folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\defaults\preferences folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\defaults\palettes folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\defaults folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\chrome folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\skin folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\WD-XHTMLplusMathMLplusSVG-20020809 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\WD-xhtml11-20070216 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\WD-xhtml-basic-20060705 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-xhtml11-20010531 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-xhtml1-20020801 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-xhtml-print-20060920 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-xhtml-basic-20080729 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-xhtml-basic-20001219 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-SVG11-20030114 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-SVG-20010904 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-smil20-20050107 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-SMIL2-20051213 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-smil-19980615 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-MathML2-20031021\mathml folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-MathML2-20031021\iso9573-13 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-MathML2-20031021\iso8879 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-MathML2-20031021\html folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-MathML2-20031021 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-html401-19991224 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-html40-19980424 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\REC-html32-19970114 folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\ISO-HTML folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib\IETF folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\sgml-lib folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\zh-TW\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\zh-TW folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\zh-CN\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\zh-CN folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\sl-SI\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\sl-SI folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\sk-SK\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\sk-SK folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ru-RU\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ru-RU folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ro-RO\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ro-RO folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\pt-BR\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\pt-BR folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\pl-PL\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\pl-PL folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\nl-NL\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\nl-NL folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\lt-LT\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\lt-LT folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ko-KR\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ko-KR folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ja-JP\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\ja-JP folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\it-IT\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\it-IT folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\hu-HU\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\hu-HU folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\fr-FR\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\fr-FR folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\fi-FI\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\fi-FI folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\en-US\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\en-US folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\de-DE\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\de-DE folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\da-DK\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\da-DK folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\cs-CZ\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale\cs-CZ folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\locale folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\content\tidy\help\fr-FR folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\content\tidy\help\en-US folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\content\tidy\help folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\content\tidy folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\content folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\defaults\preferences folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\defaults folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\components folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\chrome\locale\en-US folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\chrome\locale folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\chrome\content folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\chrome folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89} folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\ranky@ranky.cz\chrome\skin folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\ranky@ranky.cz\chrome\content folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\ranky@ranky.cz\chrome folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\ranky@ranky.cz folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\cs@dictionaries.addons.mozilla.org\dictionaries folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\cs@dictionaries.addons.mozilla.org folder moved successfully.
C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions folder moved successfully.
Folder C:\Users\Stene\AppData\Roaming\Mozilla\Firefox\Profiles\e6s5ay5g.default\extensions\{32a1fd71-835e-4b11-8e54-886fda0b4c89}\ not found.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-TW\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-TW folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-CN\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\zh-CN folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\sv-SE\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\sv-SE folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ko-KR\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ko-KR folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ja-JP\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\ja-JP folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\it-IT\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\it-IT folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\fr-FR\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\fr-FR folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\es-ES\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\es-ES folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\en-US\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\en-US folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\de-DE\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale\de-DE folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\locale folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\content\ffjcext folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome\content folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\chrome folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions folder moved successfully.
Unable to fix default_search_provider items.
Unable to fix default_search_provider items.
127.0.0.1 localhost removed from HOSTS file successfully
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95289393-33EA-4F8D-B952-483415B9C955}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
File move failed. C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk scheduled to be moved on reboot.
File C:\Users\Stene\AppData\Local\Temp\_uninst_77286306.bat not found.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
File move failed. F:\Autorun.inf scheduled to be moved on reboot.
G:\AUTOEXEC.BAT moved successfully.
File move failed. H:\Autorun.inf scheduled to be moved on reboot.
File move failed. H:\autorun.exe scheduled to be moved on reboot.
C:\Windows\SysNative\perfh005.dat moved successfully.
C:\Windows\SysNative\perfh009.dat moved successfully.
C:\Windows\SysNative\perfc005.dat moved successfully.
C:\Windows\SysNative\perfc009.dat moved successfully.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1679234959-3771141595-1235745478-1001Core.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1679234959-3771141595-1235745478-1001UA.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
File\Folder C:\Windows\SysNative\drivers\*.tmp not found.
File\Folder C:\Windows\SysWow64\drivers\*.tmp not found.
File\Folder C:\Program Files (x86)\*.tmp not found.
File\Folder C:\Windows\SysWow64\*.tmp not found.
File\Folder C:\Windows\SysNative\*.tmp not found.
C:\ProgramData\Kaspersky Lab folder moved successfully.
C:\Users\Stene\AppData\Roaming\eType folder moved successfully.
C:\Users\Stene\Desktop\avptool_sysinfo.zip moved successfully.
File\Folder C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk not found.
C:\Users\Stene\Desktop\setup_11.0.0.1245.x01_2011_10_11_09_31.exe moved successfully.
C:\Windows\PEV.exe moved successfully.
C:\Windows\MBR.exe moved successfully.
C:\Windows\sed.exe moved successfully.
C:\Windows\grep.exe moved successfully.
C:\Windows\zip.exe moved successfully.
C:\Users\Stene\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\ProgramData\DB013D6F68.sys moved successfully.
C:\Windows\ativpsrm.bin moved successfully.
File\Folder C:\Windows\system32\DRIVERS\24752363.sys not found.
File\Folder C:\Windows\system32\DRIVERS\35631669.sys not found.
File\Folder C:\Windows\System32\Drivers\dump_atapi.sys not found.
File\Folder C:\Windows\System32\Drivers\dump_dumpata.sys not found.
File\Folder C:\Windows\System32\Drivers\dump_dumpfve.sys not found.
========== SERVICES/DRIVERS ==========
Error: No service named 24752363 was found to stop!
Service\Driver key 24752363 not found.
Error: No service named 35631669 was found to stop!
Service\Driver key 35631669 not found.
Service catchme stopped successfully!
Service catchme deleted successfully!
========== REGISTRY ==========
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Stene
->Temp folder emptied: 287410 bytes
->Temporary Internet Files folder emptied: 635704 bytes
->Java cache emptied: 397798 bytes
->FireFox cache emptied: 92652787 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 4476 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 16447498 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50708 bytes
RecycleBin emptied: 1254882576 bytes

Total Files Cleaned = 1 302,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: Stene
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.29.1 log created on 10132011_104251

Files\Folders moved on Reboot...
File\Folder C:\Users\Stene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_77286306.lnk not found!
File move failed. F:\Autorun.inf scheduled to be moved on reboot.
File\Folder H:\Autorun.inf not found!
File\Folder H:\autorun.exe not found!
C:\Users\Stene\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...



Javu jsem aktualizoval...
Uživatelský avatar
jaro3
člen Security týmu
Příspěvky: 43379
Registrován: 16 čer 2007 18:58
Bydliště: Jižní Čechy

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvek od jaro3 »

Spusť OTL a klikni na Vyčisti.
Pak můžeš OTL smazat , C:\_OTL

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Uživatelský avatar
gordonisk
nováček
Příspěvky: 5
Registrován: 12 říj 2011 18:45

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvek od gordonisk »

myslim ze ked das reinstal , budes to mat jednoduchsie :)
Uživatelský avatar
jaro3
člen Security týmu
Příspěvky: 43379
Registrován: 16 čer 2007 18:58
Bydliště: Jižní Čechy

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvek od jaro3 »

gordonisk: přečti si laskavě pravidla sekce HJT:
viewtopic.php?f=70&t=29204

Rady typu přeinstaluj si systém ap. si raději nech pro sebe!
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Uživatelský avatar
Stene
Level 6
Level 6
Příspěvky: 3124
Registrován: 11 úno 2009 15:44
Bydliště: Jihlava
Kontaktovat uživatele:

Re: HJT - neustále zapnutý program, chci ho zrušit

Příspěvek od Stene »

Jaro3, mnohokrát děkuji!! :inlove:

gordonisk: Máš trefné rady. Přeinstaluju windows a budu ho měsíc dávat do stavu, v jakém ho mám dnes..
Zamčeno

Zpět na „HiJackThis“