This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows update hijack [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello tech team,

MWB picks up two Windows update infections but cannot remove them. Something also seems to be overriding MWB updates because whenever MWB is opened it says my definitions are eg 175 days out of date but when I try to update, it immediately says I have the latest definitions. Sounds a bit fishy….I cannot play any YouTube videos either= laptop shuts down after blue screen of death.
Here is first result of OTL scan


OTL logfile created on: 10/02/2012 06:36:31 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = \\HPSERVER\Users\\Dokumenty\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: Spojené království | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.46% Memory free
3.85 Gb Paging File | 3.31 Gb Available in Paging File | 85.94% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 116.44 Gb Total Space | 71.53 Gb Free Space | 61.43% Space Free | Partition Type: NTFS
Drive D: | 108.63 Gb Total Space | 108.13 Gb Free Space | 99.54% Space Free | Partition Type: NTFS
Drive Z: | 116.44 Gb Total Space | 71.53 Gb Free Space | 61.43% Space Free | Partition Type: *NT5CSC

Computer Name: | User Name: | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - \\HPSERVER\Users\\Dokumenty\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe (IObit)
PRC - C:\Program Files\TO2SSM\McciTrayApp.exe (Motive Communications, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\asghost.exe (Cognizance Corporation)
PRC - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)
PRC - C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe (ACD Systems, Ltd.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Alwil Software\Avast5\defs\12020903\algo.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - c:\Program Files\Common Files\Akamai\netsession_win_e286960.dll ()
MOD - C:\Program Files\IObit\Smart Defrag 2\NtfsData.dll ()
MOD - C:\Program Files\IObit\Smart Defrag 2\madbasic_.bpl ()
MOD - C:\Program Files\IObit\Smart Defrag 2\maddisAsm_.bpl ()
MOD - C:\Program Files\IObit\Smart Defrag 2\madexcept_.bpl ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56ita.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56ger.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56fra.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56esp.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56dnk.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56brz.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56jpn.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56kor.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56cht.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56chs.dll ()


========== Win32 Services (SafeList) ==========

SRV - (Akamai) – c:\program files\common files\akamai/netsession_win_e286960.dll ()
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (pml driver hpz12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (ASBroker) – C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll (Cognizance Corporation)
SRV - (ASChannel) – C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASChnl.dll (Cognizance Corporation)
SRV - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)


========== Driver Services (SafeList) ==========

DRV - (atitray) – Reg Error: Invalid data type. File not found
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (Inspect) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (SmartDefragDriver) – C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys ()
DRV - (8064a1bf) – C:\WINDOWS\System32\drivers\8064a1bf.sys ()
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\system32\drivers\snp2uvc.sys ()
DRV - (NETw4x32) Ovladač adaptéru Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor) – C:\WINDOWS\system32\drivers\atswpdrv.sys (AuthenTec, Inc.)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (TosRfSnd) – C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (ItSDisk) – C:\WINDOWS\system32\drivers\itsdisk.sys (Cognizance Corporation)
DRV - (k510bus) Sony Ericsson K510 Driver driver (WDM) – C:\WINDOWS\system32\drivers\k510bus.sys (MCCI)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cz.o2.com/welcome/cz/index.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\tbZone.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "WebHledani"
FF - prefs.js..browser.search.defaultthis.engineName: "ZoneAlarm Security Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "WebHledani"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: [removed]:1.5.3
FF - prefs.js..extensions.enabledItems: {91da5e8a-3318-4f8c-b67e-5964de3ab546}:[removed]
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:[removed]
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..keyword.URL: "http://www.webhledani.cz/results.aspx?i=39&tp;=ab&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/02 23:57:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/24 15:03:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\thunderbird\extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2009/12/14 12:42:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\benetkova\Data aplikací\Mozilla\Extensions
[2012/01/06 23:22:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\benetkova\Data aplikací\Mozilla\Firefox\Profiles\07l6625y.default\extensions
[2011/11/19 14:20:21 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\benetkova\Data aplikací\Mozilla\Firefox\Profiles\07l6625y.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/09/12 17:04:30 | 000,000,000 | —D | M] ("602XML Filler") – C:\Documents and Settings\benetkova\Data aplikací\Mozilla\Firefox\Profiles\07l6625y.default\extensions\[removed]
[2010/08/19 21:08:14 | 000,000,939 | —- | M] () – C:\Documents and Settings\benetkova\Data aplikací\Mozilla\Firefox\Profiles\07l6625y.default\searchplugins\conduit.xml
[2012/01/14 20:19:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/14 18:38:26 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/02/08 10:30:23 | 000,000,000 | —D | M] ("602XML Filler") – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\BENETKOVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\07L6625Y.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\BENETKOVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\07L6625Y.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\BENETKOVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\07L6625Y.DEFAULT\EXTENSIONS\[removed]
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\BENETKOVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\07L6625Y.DEFAULT\EXTENSIONS\[removed]
[2010/02/17 12:08:39 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/02/02 23:57:26 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/12/17 15:39:34 | 000,090,112 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npfiller.dll
[2012/01/14 20:19:36 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/01/14 20:19:36 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/14 20:19:36 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/01/14 20:19:36 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/10/10 08:25:31 | 000,002,208 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2011/10/10 08:25:31 | 000,000,638 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2010/09/10 09:22:32 | 000,001,687 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2011/10/10 08:25:31 | 000,001,367 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011/10/10 08:25:31 | 000,000,654 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011/10/10 08:25:31 | 000,001,179 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
[2012/01/14 20:19:36 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\benetkova\Local Settings\Data aplikac\u00ED\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npfiller.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Gmail = C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\

O1 HOSTS File: ([2009/04/20 15:15:06 | 000,000,761 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 192.168.1.10 NPIE92E71
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (ASUS Security Protect Manager) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
O2 - BHO: (Lištička) - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\listicka.dll ()
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Toolbar) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\tbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CognizanceTS] C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASTSVCC.dll (Cognizance Corporation)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [Device Detector] DevDetect.exe -autorun File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe (Motive Communications, Inc.)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: Nastavení Lištičky … - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra 'Tools' menuitem : Nastavení Lištičky … - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra Button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra 'Tools' menuitem : Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {29A5AD50-B128-4506-A7D1-DBB69B0157DE} http://192.168.3.202/Pan%20and%20Tilt%20In…et%20Camera.cab (PanandTiltInternetCamera Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} https://www.netrex.cz/portal/components/AMC.cab (AxisMediaControlEmb Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = interproject.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B9B22358-E5E9-4342-A595-C8870467BBFC}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (APSHook.dll) -C:\WINDOWS\System32\APSHook.dll (Cognizance Corporation)
O20 - AppInit_DLLs: (acaptuser32.dll) -C:\WINDOWS\System32\acaptuser32.dll (Adobe Systems, Inc.)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) -C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\OneCard: DllName - (C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll) - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll (Cognizance Corporation)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/BENETK~1/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg
O24 - Desktop Components:1 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/25 20:36:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: wave4 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/10 00:34:07 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/02/10 00:25:05 | 000,098,224 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\67506313.sys
[2012/02/09 23:38:31 | 000,000,000 | RH-D | C] – C:\Documents and Settings\benetkova\Recent
[2012/02/03 17:50:57 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Plocha\minasleva
[2012/02/03 12:56:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Nabídka Start\Programy\PhotoScape
[2012/02/03 12:51:38 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Data aplikací\PhotoScape
[2012/02/03 12:51:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Chrome
[2012/02/03 12:49:18 | 000,000,000 | —D | C] – C:\Program Files\PhotoScape
[2012/01/27 11:09:50 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Plocha\traveldiscount
[2012/01/23 18:49:36 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Data aplikací\Apple Computer
[2012/01/18 08:42:56 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Nabídka Start\Programy\Accessories
[2012/01/18 08:42:40 | 000,000,000 | -HSD | C] – C:\Documents and Settings\benetkova\IETldCache
[2012/01/18 08:39:32 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2012/01/18 08:37:55 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2012/01/18 08:37:55 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2012/01/15 11:25:49 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Plocha\tdsskiller
[2012/01/11 22:03:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2012/01/11 22:03:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2009/11/12 14:58:31 | 002,893,952 | —- | C] (Microsoft Corporation) – C:\Program Files\PPView97.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\benetkova\Plocha\*.tmp files -> C:\Documents and Settings\benetkova\Plocha\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/10 06:34:11 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/10 06:34:07 | 000,000,942 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/10 06:34:03 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2012/02/10 06:33:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/10 06:33:32 | 2146,668,544 | -HS- | M] () – C:\hiberfil.sys
[2012/02/10 05:59:06 | 000,000,946 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/10 00:25:05 | 000,098,224 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\67506313.sys
[2012/02/09 19:43:11 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/02/09 19:20:57 | 000,080,512 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_6.jpg
[2012/02/09 19:20:55 | 000,304,995 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_5.jpg
[2012/02/09 19:20:54 | 000,398,751 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_4.jpg
[2012/02/09 15:46:48 | 004,879,977 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\nabidka sleva.psd
[2012/02/09 14:03:13 | 000,002,561 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\Word.lnk
[2012/02/09 13:46:33 | 000,001,640 | —- | M] () – C:\Documents and Settings\benetkova\intlname.ols
[2012/02/07 15:12:00 | 000,025,932 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\invoice-1200123261.pdf
[2012/02/04 08:33:32 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/03 12:57:40 | 000,016,384 | -H– | M] () – \\HPSERVER\Users\zasmanova\Dokumenty\photothumb.db
[2012/02/03 12:51:06 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
[2012/02/03 11:46:13 | 001,566,442 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\zasman-trvaly pobytkopie.pdf
[2012/02/03 09:05:19 | 000,002,529 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\Outlook.lnk
[2012/02/02 12:48:20 | 000,202,175 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\nabídka_optimalizace_webu.pdf
[2012/02/01 20:56:00 | 001,291,763 | R— | M] () – C:\Documents and Settings\benetkova\Plocha\Bohemia Energy.pdf
[2012/01/25 15:17:06 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/01/24 18:38:26 | 000,045,056 | —- | M] () – C:\Documents and Settings\benetkova\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/17 22:00:48 | 000,494,968 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmdGuard.sys
[2012/01/17 21:30:48 | 000,000,000 | —- | M] () – \\HPSERVER\Users\zasmanova\Dokumenty\PDVD_MediaDisc.PlayList
[2012/01/15 11:25:10 | 001,280,208 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\tdsskiller.zip
[2012/01/13 19:33:18 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/01/11 22:04:09 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\benetkova\Plocha\*.tmp files -> C:\Documents and Settings\benetkova\Plocha\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/09 19:20:55 | 000,304,995 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_5.jpg
[2012/02/09 19:20:55 | 000,080,512 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_6.jpg
[2012/02/09 19:20:53 | 000,398,751 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_4.jpg
[2012/02/09 15:46:48 | 004,879,977 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\nabidka sleva.psd
[2012/02/07 15:12:00 | 000,025,932 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\invoice-1200123261.pdf
[2012/02/03 12:51:06 | 000,001,813 | —- | C] () – C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
[2012/02/03 12:49:42 | 000,000,946 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/03 12:49:41 | 000,000,942 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/03 11:46:06 | 001,566,442 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\zasman-trvaly pobytkopie.pdf
[2012/02/02 12:48:18 | 000,202,175 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\nabídka_optimalizace_webu.pdf
[2012/02/01 20:56:34 | 001,291,763 | R— | C] () – C:\Documents and Settings\benetkova\Plocha\Bohemia Energy.pdf
[2012/01/15 11:25:07 | 001,280,208 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\tdsskiller.zip
[2012/01/11 22:04:09 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2011/12/25 23:13:05 | 000,012,288 | —- | C] () – C:\WINDOWS\impborl.dll
[2011/05/03 19:04:46 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/05/03 19:04:46 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/02/04 22:57:15 | 000,028,496 | —- | C] () – C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/02/04 22:57:15 | 000,014,776 | —- | C] () – C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2010/12/14 17:29:44 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/05/05 10:38:28 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/06/18 08:01:29 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\8064a1bf.sys
[2009/04/22 15:26:53 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2009/04/20 15:44:09 | 000,000,129 | —- | C] () – C:\Documents and Settings\benetkova\Local Settings\Data aplikací\fusioncache.dat
[2009/04/20 15:19:25 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\PMLJNI.dll
[2009/04/20 15:19:25 | 000,074,752 | —- | C] () – C:\WINDOWS\System32\jst.dll
[2009/04/20 15:19:25 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\compJNI.dll
[2009/04/20 15:14:39 | 000,000,132 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/04/20 15:14:38 | 000,003,399 | R— | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2009/04/20 15:13:48 | 000,000,699 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/04/20 15:12:06 | 000,053,946 | —- | C] () – C:\WINDOWS\hppins01.dat
[2009/04/20 15:12:06 | 000,002,364 | —- | C] () – C:\WINDOWS\hppmdl01.dat
[2009/04/09 14:58:53 | 000,019,316 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2008/09/02 10:57:28 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/05/26 17:02:01 | 000,000,600 | —- | C] () – C:\Documents and Settings\benetkova\Local Settings\Data aplikací\PUTTY.RND
[2008/04/25 15:48:31 | 000,045,056 | —- | C] () – C:\Documents and Settings\benetkova\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/04/14 15:15:37 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2008/03/07 09:21:57 | 000,000,390 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/02/25 21:24:55 | 000,004,249 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/02/25 21:23:40 | 003,503,728 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/02/25 20:42:43 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/02/25 20:33:44 | 000,021,812 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/02/25 14:49:48 | 000,001,158 | —- | C] () – C:\WINDOWS\mozver.dat
[2008/02/25 14:48:36 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/02/25 14:31:35 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2008/02/25 14:31:08 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2008/02/25 14:30:04 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2008/02/25 14:30:03 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2008/02/25 14:30:03 | 000,972,072 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2008/02/25 14:30:02 | 000,144,357 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2008/02/25 14:23:26 | 000,000,000 | —- | C] () – C:\WINDOWS\tosOBEX.INI
[2008/02/25 14:13:17 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2007/10/01 14:59:00 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2007/05/09 15:16:00 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2006/12/05 13:05:04 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2005/10/14 11:56:50 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/10/14 11:56:50 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2005/10/14 11:56:50 | 000,778,240 | —- | C] () – C:\WINDOWS\System32\DivXsm.exe
[2005/10/14 11:56:50 | 000,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/10/14 11:56:50 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2005/10/14 11:56:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2005/10/14 11:56:50 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2005/10/14 11:56:50 | 000,155,136 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2005/10/14 11:56:50 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2005/07/22 21:30:18 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2005/04/03 07:30:00 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\scardsyn.dll
[2005/01/21 12:41:26 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\HPP2800V.DLL
[2005/01/20 13:18:56 | 000,000,484 | —- | C] () – C:\WINDOWS\System32\HPP2800V.DAT
[2004/08/18 13:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/18 13:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/18 13:00:00 | 000,383,588 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/18 13:00:00 | 000,383,060 | —- | C] () – C:\WINDOWS\System32\perfh005.dat
[2004/08/18 13:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/18 13:00:00 | 000,269,162 | —- | C] () – C:\WINDOWS\System32\perfi005.dat
[2004/08/18 13:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/18 13:00:00 | 000,063,526 | —- | C] () – C:\WINDOWS\System32\perfc005.dat
[2004/08/18 13:00:00 | 000,053,942 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/18 13:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/18 13:00:00 | 000,032,072 | —- | C] () – C:\WINDOWS\System32\perfd005.dat
[2004/08/18 13:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/18 13:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/18 13:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/18 13:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/18 13:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2003/04/09 15:38:04 | 000,005,664 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/03/28 11:37:14 | 000,000,033 | —- | C] () – C:\WINDOWS\hppcap.ini
[1999/08/12 00:00:00 | 001,708,032 | —- | C] () – C:\WINDOWS\System32\MSO97V.DLL
[1999/08/12 00:00:00 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1999/08/12 00:00:00 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\MSORFS.DLL
[1999/08/12 00:00:00 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1998/05/06 12:10:00 | 000,069,632 | R— | C] () – C:\WINDOWS\System32\ODMA32.dll

========== LOP Check ==========

[2009/04/22 15:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\ACD Systems
[2010/10/23 11:19:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2012/01/21 17:56:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\CPA_VA
[2009/06/26 11:23:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\ESET
[2011/10/28 14:14:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\IObit
[2010/08/27 20:17:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\regid.1986-12.com.adobe
[2009/04/22 15:31:24 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\ACD Systems
[2010/08/27 20:59:59 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/09/22 08:27:05 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\CheckPoint
[2011/10/26 10:56:19 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\IObit
[2008/05/15 14:37:39 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\Leadertech
[2008/03/11 12:53:09 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\Opera
[2012/02/03 12:53:09 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\PhotoScape
[2012/02/09 19:43:11 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2012/02/10 06:34:03 | 000,000,288 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag_Startup.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/02/25 20:36:48 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/12/01 11:15:23 | 000,044,741 | —- | M] () – C:\Beautiful-ES.zip
[2008/02/25 20:30:35 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2004/08/18 13:00:00 | 000,004,952 | RHS- | M] () – C:\Bootfont.bin
[2009/12/01 13:55:36 | 000,027,680 | —- | M] () – C:\christmas_bells.gif
[2008/02/25 20:36:48 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/02/25 20:57:12 | 000,286,720 | —- | M] () – C:\Debug.txt
[2012/02/10 06:33:32 | 2146,668,544 | -HS- | M] () – C:\hiberfil.sys
[2011/11/19 14:38:36 | 000,000,252 | —- | M] () – C:\INSTALL.LOG
[2008/02/25 20:36:48 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/17 21:38:16 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008/02/25 20:36:48 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/18 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/22 08:09:31 | 000,250,576 | RHS- | M] () – C:\ntldr
[2012/02/10 06:33:31 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2006/12/08 08:32:28 | 000,000,952 | —- | M] () – C:\sbscert.cer
[2011/11/04 08:55:50 | 000,460,824 | —- | M] () – C:\snp2uvc-001.raw
[2012/01/15 11:26:21 | 000,000,412 | —- | M] () – C:\TDSSKiller.2.5.1.0_15.01.2012_11.26.15_log.txt
[2012/01/15 11:26:47 | 000,000,412 | —- | M] () – C:\TDSSKiller.2.5.1.0_15.01.2012_11.26.43_log.txt
[2012/01/15 11:28:00 | 000,043,864 | —- | M] () – C:\TDSSKiller.2.5.1.0_15.01.2012_11.27.41_log.txt
[2011/09/30 13:09:24 | 000,054,088 | —- | M] () – C:\TDSSKiller.2.6.2.0_30.09.2011_14.08.42_log.txt
[2012/02/10 00:18:27 | 000,000,346 | —- | M] () – C:\TDSSKiller.2.7.1.0_10.02.2012_00.18.21_log.txt
[2012/02/10 00:22:16 | 000,000,346 | —- | M] () – C:\TDSSKiller.2.7.1.0_10.02.2012_00.21.38_log.txt
[2012/02/10 00:25:38 | 000,075,846 | —- | M] () – C:\TDSSKiller.2.7.1.0_10.02.2012_00.25.02_log.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/02/25 20:36:27 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/05/13 11:40:56 | 000,051,712 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\HPZPP034.DLL
[2003/06/19 01:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/11/28 19:01:25 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2011/12/25 23:13:15 | 000,192,000 | —- | M] (ScreenTime Media) – C:\WINDOWS\screensaver.scr
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/11/12 14:58:32 | 002,893,952 | —- | M] (Microsoft Corporation) – C:\Program Files\PPView97.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/02/25 21:22:43 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/02/25 21:22:43 | 000,663,552 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/02/25 21:22:43 | 000,495,616 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >
[2011/02/05 13:29:38 | 000,000,000 | —D | M] – C:\Program Files\IObit\Advanced SystemCare 3\Bak

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/03/06 19:05:06 | 000,000,125 | -HS- | M] () – C:\Documents and Settings\benetkova\Data aplikací\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/03/06 19:05:04 | 000,000,079 | —- | M] () – C:\Documents and Settings\benetkova\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zobrazit plochu.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-06-11 01:05:17
Hi Zen7 and welcome to WhatTheTech forums!
I'm Sunyata and I will be helping you with your computer problems.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.

Please read the following guidelines which will help to make cleaning your machine easier:

  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
  • Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
  • Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
  • PLEASE DO NOT install/uninstall any programs unless asked to.
  • PLEASE DO NOT run any malware scans other than those requested.
  • Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
  • I will reply back shortly with instructions

Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
Hello Zen7

Your OTL log looks incomplete. Please post the complete log. Also, there should be an Extras.txt in the same place where OTL was downloaded. Please post that as well.

Something also seems to be overriding MWB updates

By "MWB" are you referring to Malware Byte's Anti Malware (MBAM)? Please post the log that finds the Windows Update infections you write of.


And while we are collecting logs, please let's get an anti - rootkit scan as well:

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]



To summarize, in your next post, please include:
  • OTL.txt
  • Extras.txt
  • The log that shows the Windows Update infections
  • aswMBR.txt
Hi Sunyata, yes, it seems the log is incomplete. I will send you both logs in separate posts, hope that is ok. This will be followed by the MBR. If there is anything missing, please let me know. Many thanks for your support.
OTL logfile created on: 10/02/2012 06:36:31 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = \\HPSERVER\Users\zasmanova\Dokumenty\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: Spojené království | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.46% Memory free
3.85 Gb Paging File | 3.31 Gb Available in Paging File | 85.94% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 116.44 Gb Total Space | 71.53 Gb Free Space | 61.43% Space Free | Partition Type: NTFS
Drive D: | 108.63 Gb Total Space | 108.13 Gb Free Space | 99.54% Space Free | Partition Type: NTFS
Drive Z: | 116.44 Gb Total Space | 71.53 Gb Free Space | 61.43% Space Free | Partition Type: *NT5CSC

Computer Name: MARIE | User Name: zasmanova | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - \\HPSERVER\Users\zasmanova\Dokumenty\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe (IObit)
PRC - C:\Program Files\TO2SSM\McciTrayApp.exe (Motive Communications, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\asghost.exe (Cognizance Corporation)
PRC - C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)
PRC - C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe (ACD Systems, Ltd.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Alwil Software\Avast5\defs\12020903\algo.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - c:\Program Files\Common Files\Akamai\netsession_win_e286960.dll ()
MOD - C:\Program Files\IObit\Smart Defrag 2\NtfsData.dll ()
MOD - C:\Program Files\IObit\Smart Defrag 2\madbasic_.bpl ()
MOD - C:\Program Files\IObit\Smart Defrag 2\maddisAsm_.bpl ()
MOD - C:\Program Files\IObit\Smart Defrag 2\madexcept_.bpl ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56ita.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56ger.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56fra.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56esp.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56dnk.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56brz.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56jpn.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56kor.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56cht.dll ()
MOD - C:\Program Files\Motorola\SMSERIAL\sm56chs.dll ()


========== Win32 Services (SafeList) ==========

SRV - (Akamai) – c:\program files\common files\akamai/netsession_win_e286960.dll ()
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (pml driver hpz12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (ASBroker) – C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll (Cognizance Corporation)
SRV - (ASChannel) – C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASChnl.dll (Cognizance Corporation)
SRV - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)


========== Driver Services (SafeList) ==========

DRV - (atitray) – Reg Error: Invalid data type. File not found
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (Inspect) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (SmartDefragDriver) – C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys ()
DRV - (8064a1bf) – C:\WINDOWS\System32\drivers\8064a1bf.sys ()
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\system32\drivers\snp2uvc.sys ()
DRV - (NETw4x32) Ovladač adaptéru Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor) – C:\WINDOWS\system32\drivers\atswpdrv.sys (AuthenTec, Inc.)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (TosRfSnd) – C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (smserial) – C:\WINDOWS\system32\drivers\smserial.sys (Motorola Inc.)
DRV - (tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (ItSDisk) – C:\WINDOWS\system32\drivers\itsdisk.sys (Cognizance Corporation)
DRV - (k510bus) Sony Ericsson K510 Driver driver (WDM) – C:\WINDOWS\system32\drivers\k510bus.sys (MCCI)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cz.o2.com/welcome/cz/index.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\tbZone.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "WebHledani"
FF - prefs.js..browser.search.defaultthis.engineName: "ZoneAlarm Security Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "WebHledani"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: [removed]:1.5.3
FF - prefs.js..extensions.enabledItems: {91da5e8a-3318-4f8c-b67e-5964de3ab546}:[removed]
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:[removed]
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..keyword.URL: "http://www.webhledani.cz/results.aspx?i=39&tp;=ab&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/02 23:57:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/24 15:03:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\thunderbird\extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2009/12/14 12:42:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\benetkova\Data aplikací\Mozilla\Extensions
[2012/01/06 23:22:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\benetkova\Data aplikací\Mozilla\Firefox\Profiles\07l6625y.default\extensions
[2011/11/19 14:20:21 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\benetkova\Data aplikací\Mozilla\Firefox\Profiles\07l6625y.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/09/12 17:04:30 | 000,000,000 | —D | M] ("602XML Filler") – C:\Documents and Settings\benetkova\Data aplikací\Mozilla\Firefox\Profiles\07l6625y.default\extensions\[removed]
[2010/08/19 21:08:14 | 000,000,939 | —- | M] () – C:\Documents and Settings\benetkova\Data aplikací\Mozilla\Firefox\Profiles\07l6625y.default\searchplugins\conduit.xml
[2012/01/14 20:19:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/14 18:38:26 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/02/08 10:30:23 | 000,000,000 | —D | M] ("602XML Filler") – C:\Program Files\Mozilla Firefox\extensions\[removed]
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\BENETKOVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\07L6625Y.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\BENETKOVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\07L6625Y.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\BENETKOVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\07L6625Y.DEFAULT\EXTENSIONS\[removed]
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\BENETKOVA\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\07L6625Y.DEFAULT\EXTENSIONS\[removed]
[2010/02/17 12:08:39 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/02/02 23:57:26 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/12/17 15:39:34 | 000,090,112 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npfiller.dll
[2012/01/14 20:19:36 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/01/14 20:19:36 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/14 20:19:36 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/01/14 20:19:36 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/10/10 08:25:31 | 000,002,208 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2011/10/10 08:25:31 | 000,000,638 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2010/09/10 09:22:32 | 000,001,687 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2011/10/10 08:25:31 | 000,001,367 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011/10/10 08:25:31 | 000,000,654 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011/10/10 08:25:31 | 000,001,179 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
[2012/01/14 20:19:36 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\benetkova\Local Settings\Data aplikac\u00ED\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npfiller.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Gmail = C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\

O1 HOSTS File: ([2009/04/20 15:15:06 | 000,000,761 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 192.168.1.10 NPIE92E71
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (ASUS Security Protect Manager) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
O2 - BHO: (Lištička) - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\listicka.dll ()
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Toolbar) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\tbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CognizanceTS] C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASTSVCC.dll (Cognizance Corporation)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [Device Detector] DevDetect.exe -autorun File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe (Motive Communications, Inc.)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: Nastavení Lištičky … - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra 'Tools' menuitem : Nastavení Lištičky … - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra Button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra 'Tools' menuitem : Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {29A5AD50-B128-4506-A7D1-DBB69B0157DE} http://192.168.3.202/Pan%20and%20Tilt%20In…et%20Camera.cab (PanandTiltInternetCamera Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} https://www.netrex.cz/portal/components/AMC.cab (AxisMediaControlEmb Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = interproject.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B9B22358-E5E9-4342-A595-C8870467BBFC}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (APSHook.dll) -C:\WINDOWS\System32\APSHook.dll (Cognizance Corporation)
O20 - AppInit_DLLs: (acaptuser32.dll) -C:\WINDOWS\System32\acaptuser32.dll (Adobe Systems, Inc.)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) -C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\OneCard: DllName - (C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll) - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll (Cognizance Corporation)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/BENETK~1/LOCALS~1/Temp/msohtml1/01/clip_image001.jpg
O24 - Desktop Components:1 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/25 20:36:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: wave4 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/10 00:34:07 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/02/10 00:25:05 | 000,098,224 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\67506313.sys
[2012/02/09 23:38:31 | 000,000,000 | RH-D | C] – C:\Documents and Settings\benetkova\Recent
[2012/02/03 17:50:57 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Plocha\minasleva
[2012/02/03 12:56:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Nabídka Start\Programy\PhotoScape
[2012/02/03 12:51:38 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Data aplikací\PhotoScape
[2012/02/03 12:51:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Nabídka Start\Programy\Google Chrome
[2012/02/03 12:49:18 | 000,000,000 | —D | C] – C:\Program Files\PhotoScape
[2012/01/27 11:09:50 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Plocha\traveldiscount
[2012/01/23 18:49:36 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Data aplikací\Apple Computer
[2012/01/18 08:42:56 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Nabídka Start\Programy\Accessories
[2012/01/18 08:42:40 | 000,000,000 | -HSD | C] – C:\Documents and Settings\benetkova\IETldCache
[2012/01/18 08:39:32 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2012/01/18 08:37:55 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2012/01/18 08:37:55 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2012/01/15 11:25:49 | 000,000,000 | —D | C] – C:\Documents and Settings\benetkova\Plocha\tdsskiller
[2012/01/11 22:03:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2012/01/11 22:03:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2009/11/12 14:58:31 | 002,893,952 | —- | C] (Microsoft Corporation) – C:\Program Files\PPView97.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\benetkova\Plocha\*.tmp files -> C:\Documents and Settings\benetkova\Plocha\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/10 06:34:11 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/10 06:34:07 | 000,000,942 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/10 06:34:03 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2012/02/10 06:33:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/10 06:33:32 | 2146,668,544 | -HS- | M] () – C:\hiberfil.sys
[2012/02/10 05:59:06 | 000,000,946 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/10 00:25:05 | 000,098,224 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\67506313.sys
[2012/02/09 19:43:11 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/02/09 19:20:57 | 000,080,512 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_6.jpg
[2012/02/09 19:20:55 | 000,304,995 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_5.jpg
[2012/02/09 19:20:54 | 000,398,751 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_4.jpg
[2012/02/09 15:46:48 | 004,879,977 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\nabidka sleva.psd
[2012/02/09 14:03:13 | 000,002,561 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\Word.lnk
[2012/02/09 13:46:33 | 000,001,640 | —- | M] () – C:\Documents and Settings\benetkova\intlname.ols
[2012/02/07 15:12:00 | 000,025,932 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\invoice-1200123261.pdf
[2012/02/04 08:33:32 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/02/03 12:57:40 | 000,016,384 | -H– | M] () – \\HPSERVER\Users\zasmanova\Dokumenty\photothumb.db
[2012/02/03 12:51:06 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
[2012/02/03 11:46:13 | 001,566,442 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\zasman-trvaly pobytkopie.pdf
[2012/02/03 09:05:19 | 000,002,529 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\Outlook.lnk
[2012/02/02 12:48:20 | 000,202,175 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\nabídka_optimalizace_webu.pdf
[2012/02/01 20:56:00 | 001,291,763 | R— | M] () – C:\Documents and Settings\benetkova\Plocha\Bohemia Energy.pdf
[2012/01/25 15:17:06 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/01/24 18:38:26 | 000,045,056 | —- | M] () – C:\Documents and Settings\benetkova\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/17 22:00:48 | 000,494,968 | —- | M] (COMODO) – C:\WINDOWS\System32\drivers\cmdGuard.sys
[2012/01/17 21:30:48 | 000,000,000 | —- | M] () – \\HPSERVER\Users\zasmanova\Dokumenty\PDVD_MediaDisc.PlayList
[2012/01/15 11:25:10 | 001,280,208 | —- | M] () – C:\Documents and Settings\benetkova\Plocha\tdsskiller.zip
[2012/01/13 19:33:18 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/01/11 22:04:09 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\benetkova\Plocha\*.tmp files -> C:\Documents and Settings\benetkova\Plocha\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/09 19:20:55 | 000,304,995 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_5.jpg
[2012/02/09 19:20:55 | 000,080,512 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_6.jpg
[2012/02/09 19:20:53 | 000,398,751 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\Traveldiscount.cz - náhled smlouvy_Page_4.jpg
[2012/02/09 15:46:48 | 004,879,977 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\nabidka sleva.psd
[2012/02/07 15:12:00 | 000,025,932 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\invoice-1200123261.pdf
[2012/02/03 12:51:06 | 000,001,813 | —- | C] () – C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
[2012/02/03 12:49:42 | 000,000,946 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/03 12:49:41 | 000,000,942 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/03 11:46:06 | 001,566,442 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\zasman-trvaly pobytkopie.pdf
[2012/02/02 12:48:18 | 000,202,175 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\nabídka_optimalizace_webu.pdf
[2012/02/01 20:56:34 | 001,291,763 | R— | C] () – C:\Documents and Settings\benetkova\Plocha\Bohemia Energy.pdf
[2012/01/15 11:25:07 | 001,280,208 | —- | C] () – C:\Documents and Settings\benetkova\Plocha\tdsskiller.zip
[2012/01/11 22:04:09 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2011/12/25 23:13:05 | 000,012,288 | —- | C] () – C:\WINDOWS\impborl.dll
[2011/05/03 19:04:46 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/05/03 19:04:46 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/02/04 22:57:15 | 000,028,496 | —- | C] () – C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/02/04 22:57:15 | 000,014,776 | —- | C] () – C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2010/12/14 17:29:44 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/05/05 10:38:28 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/06/18 08:01:29 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\8064a1bf.sys
[2009/04/22 15:26:53 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2009/04/20 15:44:09 | 000,000,129 | —- | C] () – C:\Documents and Settings\benetkova\Local Settings\Data aplikací\fusioncache.dat
[2009/04/20 15:19:25 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\PMLJNI.dll
[2009/04/20 15:19:25 | 000,074,752 | —- | C] () – C:\WINDOWS\System32\jst.dll
[2009/04/20 15:19:25 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\compJNI.dll
[2009/04/20 15:14:39 | 000,000,132 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/04/20 15:14:38 | 000,003,399 | R— | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2009/04/20 15:13:48 | 000,000,699 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/04/20 15:12:06 | 000,053,946 | —- | C] () – C:\WINDOWS\hppins01.dat
[2009/04/20 15:12:06 | 000,002,364 | —- | C] () – C:\WINDOWS\hppmdl01.dat
[2009/04/09 14:58:53 | 000,019,316 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2008/09/02 10:57:28 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/05/26 17:02:01 | 000,000,600 | —- | C] () – C:\Documents and Settings\benetkova\Local Settings\Data aplikací\PUTTY.RND
[2008/04/25 15:48:31 | 000,045,056 | —- | C] () – C:\Documents and Settings\benetkova\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/04/14 15:15:37 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2008/03/07 09:21:57 | 000,000,390 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/02/25 21:24:55 | 000,004,249 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/02/25 21:23:40 | 003,503,728 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/02/25 20:42:43 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/02/25 20:33:44 | 000,021,812 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/02/25 14:49:48 | 000,001,158 | —- | C] () – C:\WINDOWS\mozver.dat
[2008/02/25 14:48:36 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/02/25 14:31:35 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2008/02/25 14:31:08 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2008/02/25 14:30:04 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2008/02/25 14:30:03 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2008/02/25 14:30:03 | 000,972,072 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2008/02/25 14:30:02 | 000,144,357 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2008/02/25 14:23:26 | 000,000,000 | —- | C] () – C:\WINDOWS\tosOBEX.INI
[2008/02/25 14:13:17 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2007/10/01 14:59:00 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2007/05/09 15:16:00 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2006/12/05 13:05:04 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2005/10/14 11:56:50 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/10/14 11:56:50 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2005/10/14 11:56:50 | 000,778,240 | —- | C] () – C:\WINDOWS\System32\DivXsm.exe
[2005/10/14 11:56:50 | 000,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/10/14 11:56:50 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2005/10/14 11:56:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2005/10/14 11:56:50 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2005/10/14 11:56:50 | 000,155,136 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2005/10/14 11:56:50 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2005/07/22 21:30:18 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2005/04/03 07:30:00 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\scardsyn.dll
[2005/01/21 12:41:26 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\HPP2800V.DLL
[2005/01/20 13:18:56 | 000,000,484 | —- | C] () – C:\WINDOWS\System32\HPP2800V.DAT
[2004/08/18 13:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/18 13:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/18 13:00:00 | 000,383,588 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/18 13:00:00 | 000,383,060 | —- | C] () – C:\WINDOWS\System32\perfh005.dat
[2004/08/18 13:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/18 13:00:00 | 000,269,162 | —- | C] () – C:\WINDOWS\System32\perfi005.dat
[2004/08/18 13:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/18 13:00:00 | 000,063,526 | —- | C] () – C:\WINDOWS\System32\perfc005.dat
[2004/08/18 13:00:00 | 000,053,942 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/18 13:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/18 13:00:00 | 000,032,072 | —- | C] () – C:\WINDOWS\System32\perfd005.dat
[2004/08/18 13:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/18 13:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/18 13:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/18 13:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/18 13:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2003/04/09 15:38:04 | 000,005,664 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/03/28 11:37:14 | 000,000,033 | —- | C] () – C:\WINDOWS\hppcap.ini
[1999/08/12 00:00:00 | 001,708,032 | —- | C] () – C:\WINDOWS\System32\MSO97V.DLL
[1999/08/12 00:00:00 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1999/08/12 00:00:00 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\MSORFS.DLL
[1999/08/12 00:00:00 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1998/05/06 12:10:00 | 000,069,632 | R— | C] () – C:\WINDOWS\System32\ODMA32.dll

========== LOP Check ==========

[2009/04/22 15:27:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\ACD Systems
[2010/10/23 11:19:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2012/01/21 17:56:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\CPA_VA
[2009/06/26 11:23:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\ESET
[2011/10/28 14:14:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\IObit
[2010/08/27 20:17:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Data aplikací\regid.1986-12.com.adobe
[2009/04/22 15:31:24 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\ACD Systems
[2010/08/27 20:59:59 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/09/22 08:27:05 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\CheckPoint
[2011/10/26 10:56:19 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\IObit
[2008/05/15 14:37:39 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\Leadertech
[2008/03/11 12:53:09 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\Opera
[2012/02/03 12:53:09 | 000,000,000 | —D | M] – C:\Documents and Settings\benetkova\Data aplikací\PhotoScape
[2012/02/09 19:43:11 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2012/02/10 06:34:03 | 000,000,288 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag_Startup.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/02/25 20:36:48 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/12/01 11:15:23 | 000,044,741 | —- | M] () – C:\Beautiful-ES.zip
[2008/02/25 20:30:35 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2004/08/18 13:00:00 | 000,004,952 | RHS- | M] () – C:\Bootfont.bin
[2009/12/01 13:55:36 | 000,027,680 | —- | M] () – C:\christmas_bells.gif
[2008/02/25 20:36:48 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/02/25 20:57:12 | 000,286,720 | —- | M] () – C:\Debug.txt
[2012/02/10 06:33:32 | 2146,668,544 | -HS- | M] () – C:\hiberfil.sys
[2011/11/19 14:38:36 | 000,000,252 | —- | M] () – C:\INSTALL.LOG
[2008/02/25 20:36:48 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/17 21:38:16 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008/02/25 20:36:48 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/18 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/22 08:09:31 | 000,250,576 | RHS- | M] () – C:\ntldr
[2012/02/10 06:33:31 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2006/12/08 08:32:28 | 000,000,952 | —- | M] () – C:\sbscert.cer
[2011/11/04 08:55:50 | 000,460,824 | —- | M] () – C:\snp2uvc-001.raw
[2012/01/15 11:26:21 | 000,000,412 | —- | M] () – C:\TDSSKiller.2.5.1.0_15.01.2012_11.26.15_log.txt
[2012/01/15 11:26:47 | 000,000,412 | —- | M] () – C:\TDSSKiller.2.5.1.0_15.01.2012_11.26.43_log.txt
[2012/01/15 11:28:00 | 000,043,864 | —- | M] () – C:\TDSSKiller.2.5.1.0_15.01.2012_11.27.41_log.txt
[2011/09/30 13:09:24 | 000,054,088 | —- | M] () – C:\TDSSKiller.2.6.2.0_30.09.2011_14.08.42_log.txt
[2012/02/10 00:18:27 | 000,000,346 | —- | M] () – C:\TDSSKiller.2.7.1.0_10.02.2012_00.18.21_log.txt
[2012/02/10 00:22:16 | 000,000,346 | —- | M] () – C:\TDSSKiller.2.7.1.0_10.02.2012_00.21.38_log.txt
[2012/02/10 00:25:38 | 000,075,846 | —- | M] () – C:\TDSSKiller.2.7.1.0_10.02.2012_00.25.02_log.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/02/25 20:36:27 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/05/13 11:40:56 | 000,051,712 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\HPZPP034.DLL
[2003/06/19 01:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/11/28 19:01:25 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2011/12/25 23:13:15 | 000,192,000 | —- | M] (ScreenTime Media) – C:\WINDOWS\screensaver.scr
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/11/12 14:58:32 | 002,893,952 | —- | M] (Microsoft Corporation) – C:\Program Files\PPView97.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/02/25 21:22:43 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/02/25 21:22:43 | 000,663,552 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/02/25 21:22:43 | 000,495,616 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >
[2011/02/05 13:29:38 | 000,000,000 | —D | M] – C:\Program Files\IObit\Advanced SystemCare 3\Bak

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/03/06 19:05:06 | 000,000,125 | -HS- | M] () – C:\Documents and Settings\benetkova\Data aplikací\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/03/06 19:05:04 | 000,000,079 | —- | M] () – C:\Documents and Settings\benetkova\Data aplikací\Microsoft\Internet Explorer\Quick Launch\Zobrazit plochu.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-06-11 01:05:17

< End of report >
Extras txt.


OTL Extras logfile created on: 10/02/2012 06:36:31 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = \\HPSERVER\Users\zasmanova\Dokumenty\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: Spojené království | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.46% Memory free
3.85 Gb Paging File | 3.31 Gb Available in Paging File | 85.94% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 116.44 Gb Total Space | 71.53 Gb Free Space | 61.43% Space Free | Partition Type: NTFS
Drive D: | 108.63 Gb Total Space | 108.13 Gb Free Space | 99.54% Space Free | Partition Type: NTFS
Drive Z: | 116.44 Gb Total Space | 71.53 Gb Free Space | 61.43% Space Free | Partition Type: *NT5CSC

Computer Name: MARIE | User Name: zasmanova | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\Program Files\ACD Systems\ACDSee\8.0\ACDSee8.exe" "%1" (ACD Systems Ltd.)
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\domainprofile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\domainprofile\authorizedapplications]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\domainprofile\globallyopenports]
"Enabled" = 1
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\domainprofile\globallyopenports\list]
"135:TCP:*:Enabled:Offer Remote Assistance - Port" = 135:TCP:*:Enabled:Offer Remote Assistance - Port

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\domainprofile\services]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\domainprofile\services\fileandprint]
"Enabled" = 1
"RemoteAddresses" = LocalSubnet

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\domainprofile\services\remotedesktop]
"Enabled" = 1
"RemoteAddresses" = *

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\standardprofile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\standardprofile\authorizedapplications]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\standardprofile\globallyopenports]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1066:TCP" = 1066:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1071:TCP" = 1071:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\HPLJ2840CDinstall\setup\HPZnet01.exe" = C:\HPLJ2840CDinstall\setup\HPZnet01.exe:*:Enabled:Install Consumer Experience Network Plug in – (Hewlett-Packard)
"C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe" = C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe:*:Enabled:javaw – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe" = C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe:*:Disabled:javaw – ()
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon
"C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Akamai\netsession_win.exe" = C:\Documents and Settings\benetkova\Local Settings\Data aplikací\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Interface – (Akamai Technologies, Inc)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{05ADEEC8-BD58-43D9-A9E3-1F53B0DA117A}" = Opera 10.51
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{1030DCDC-2425-407d-BEE1-13558B837FCA}" = HP Color LaserJet 2820/2830/2840 2.0
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 29
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{55508A44-8225-47AB-9666-1F57A5B5CE2E}" = CP_PLSBusinessFlyers
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{59073DF9-3D3D-4FFC-AF41-C2C268A1A31E}" = hppTooCool
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{606E5C0D-6039-42A7-988E-9D51DE773AFF}" = hppFonts
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{688EC50D-0155-4490-8DBF-686CD3B2893F}" = hppScanTo
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations
"{68D91375-4D6F-2287-9888-C1415AE491C3}" = ccc-core-preinstall
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E32B134-CA8D-49DD-B94C-0DB155CE70B5}" = ccc-Branding
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm
"{74E5E862-F1FF-412B-B824-9582ED7DE84A}" = hppSendFax
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics
"{7D7F2CB5-F9A4-4E86-853D-1BADD936DDAD}" = hppscan2800
"{8043D1B8-81AE-4597-AAA8-1E1F49D6E4DF}" = hppManuals2800
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{851D5410-0851-46F0-8836-74E0D8D20196}" = hppDustDevil
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B2EF64A-1D1F-4AD8-91BF-7B5F1BC36E00}" = hppFaxDrv
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc
"{901f0409-6000-11d3-8cfe-0150048383c9}" = Microsoft Office 2003 Proofing Tools
"{91130405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B97EC91-B3FD-4BFF-88FC-5345A26AC2E7}" = Adobe Illustrator CS5
"{9BAF043B-82FC-43E2-96EA-5F68015F4FA2}" = AuthenTec Fingerprint Sensor Minimum Install
"{A28F43DA-258F-42EC-9C95-E6C9A7475670}" = hppIOFiles
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A5354861-6ADE-A85D-E6C8-AC9C23A4E72E}" = Catalyst Control Center Graphics Full Existing
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-7AD7-1029-7B44-A81200000003}" = Adobe Reader 8 - Czech
"{AE80641A-0C8D-4670-A518-B4EC154B1027}" = ACDSee 8
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director
"{BB861B8B-A84F-BF7A-F82F-8BBD2814B751}" = ccc-utility
"{C3E6DC57-473A-4424-9617-AF60BA8403C3}" = hppCLJ2800
"{CACB5081-948F-B47D-1B36-CA8627485D76}" = Skins
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D6AB1F5B-FED6-49A9-9747-327BD28FB3C7}" = COMODO Internet Security
"{D8D4AF9A-6ADE-4B14-A7F5-BA858792729E}" = ASUS Security Protect Manager
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DAF193A7-8BCB-8B9B-B2D7-A84E2810C35E}" = Catalyst Control Center Graphics Light
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E38644ED-1932-DEBD-4773-D3FF63AD2F98}" = Catalyst Control Center Graphics Full New
"{E692347E-2AFA-44AE-8197-5A34308B84CC}" = 602XML Filler rozšíření pro Mozilla Firefox
"{E84D30F2-5F7B-E216-8F57-C758F19746D6}" = Catalyst Control Center Core Implementation
"{EC5679E8-DCAE-D64D-A8F2-59687BCF7B1D}" = Catalyst Control Center Graphics Previews Common
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f333a33d-125c-32a2-8dce-5c5d14231e27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{f333a33d-125c-32a2-8dce-5c5d14231e27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FE3F3C9B-2C29-4FEE-A74F-11E436729F2C}" = Scan
"0BF49E9448DA0DFB69DB9D673379652AB9087171" = Windows Driver Package - Intel net (09/26/2007 11.5.0.32)
"5D81FBED6E61194F43FF1556F43BD8309BA44634" = Windows Driver Package - Intel (NETw4x32) net (09/26/2007 11.5.0.32)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop 7.0.1 CE" = Adobe Photoshop 7.0.1 CE
"Akamai" = Akamai NetSession Interface Service
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = DNA-ATi 5.1.7.5x32
"avast" = avast! Free Antivirus
"AXIS Media Control Embedded" = AXIS Media Control Embedded
"CCleaner" = CCleaner
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2011-06-26
"Comodo Dragon" = Comodo Dragon
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"DNA-ATi Files Uninstall" = DNA-ATi Files Uninstall
"EFD65E7CD7A28D00217941F33C5CA55964F96136" = Windows Driver Package - Intel (w29n51) net (07/25/2007 9.0.4.37)
"Google Chrome" = Google Chrome
"HP Photo & Imaging" = HP Image Zone 4.7
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 10.0 (x86 en-GB)" = Mozilla Firefox 10.0 (x86 en-GB)
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"O2 Internet Konfigurator" = O2 Internet Konfigurator
"PhotoScape" = PhotoScape
"PPTView97" = Microsoft PowerPoint Viewer 97
"rajče.net_is1" = rajče beta50
"RealVNC_is1" = VNC Free Edition 4.1.2
"screensaver" = screensaver
"Smart Defrag 2_is1" = Smart Defrag 2
"SMSERIAL" = Motorola SM56 Speakerphone Modem
"szn-software-listicka" = Seznam Lištička 2 (Všichni uživatelé tohoto počítače.)
"USB 2.0 1.3M UVC WebCam" = USB 2.0 1.3M UVC WebCam
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 09/02/2012 17:15:35 | Computer Name = MARIE | Source = Userenv | ID = 1054
Description = Systém Windows nemůže získat název řadiče domény vaší sítě. (Zadaná
doména neexistuje nebo není k dispozici. ). Zpracovávání zásad skupin bylo zastaveno.


Error - 09/02/2012 19:25:35 | Computer Name = MARIE | Source = Application Error | ID = 1000
Description = Chybující aplikace tdsskiller.exe, verze 2.7.1.0, chybující modul
tdsskiller.exe, verze 2.7.1.0, adresa chyby 0x000a4172.

Error - 10/02/2012 00:26:50 | Computer Name = MARIE | Source = Userenv | ID = 1054
Description = Systém Windows nemůže získat název řadiče domény vaší sítě. (Není
nainstalován ovladač Pracovní stanice. ). Zpracovávání zásad skupin bylo zastaveno.


Error - 10/02/2012 00:26:55 | Computer Name = MARIE | Source = AutoEnrollment | ID = 15
Description = Automatickému zápisu certifikátu pro Local System se nezdařilo kontaktovat
adresář Active Directory(0x80070836). Není nainstalován ovladač Pracovní stanice.

Zápis nebude proveden.

Error - 10/02/2012 00:27:24 | Computer Name = MARIE | Source = Userenv | ID = 1054
Description = Systém Windows nemůže získat název řadiče domény vaší sítě. (Zadaná
doména neexistuje nebo není k dispozici. ). Zpracovávání zásad skupin bylo zastaveno.


Error - 10/02/2012 01:13:03 | Computer Name = MARIE | Source = Userenv | ID = 1054
Description = Systém Windows nemůže získat název řadiče domény vaší sítě. (Umístění
v síti není dosažitelné. Informace týkající se řešení problémů se sítěmi naleznete
v Nápovědě systému Windows. ). Zpracovávání zásad skupin bylo zastaveno.

Error - 10/02/2012 01:13:07 | Computer Name = MARIE | Source = AutoEnrollment | ID = 15
Description = Automatickému zápisu certifikátu pro Local System se nezdařilo kontaktovat
adresář Active Directory(0x800704cf). Umístění v síti není dosažitelné. Informace
týkající se řešení problémů se sítěmi naleznete v Nápovědě systému Windows. Zápis
nebude proveden.

Error - 10/02/2012 01:15:00 | Computer Name = MARIE | Source = Userenv | ID = 1054
Description = Systém Windows nemůže získat název řadiče domény vaší sítě. (Zadaná
doména neexistuje nebo není k dispozici. ). Zpracovávání zásad skupin bylo zastaveno.


Error - 10/02/2012 01:33:46 | Computer Name = MARIE | Source = Userenv | ID = 1054
Description = Systém Windows nemůže získat název řadiče domény vaší sítě. (Umístění
v síti není dosažitelné. Informace týkající se řešení problémů se sítěmi naleznete
v Nápovědě systému Windows. ). Zpracovávání zásad skupin bylo zastaveno.

Error - 10/02/2012 01:33:48 | Computer Name = MARIE | Source = AutoEnrollment | ID = 15
Description = Automatickému zápisu certifikátu pro Local System se nezdařilo kontaktovat
adresář Active Directory(0x800704cf). Umístění v síti není dosažitelné. Informace
týkající se řešení problémů se sítěmi naleznete v Nápovědě systému Windows. Zápis
nebude proveden.

[ System Events ]
Error - 10/02/2012 00:35:12 | Computer Name = MARIE | Source = atapi | ID = 262153
Description = Zařízení \Device\Ide\IdePort1 neodpovídá v periodě časového limitu.

Error - 10/02/2012 00:35:35 | Computer Name = MARIE | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %2 při pokusu o spuštění služby wuauserv
s argumenty za účelem spuštění serveru: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 10/02/2012 00:35:35 | Computer Name = MARIE | Source = Service Control Manager | ID = 7000
Description = Služba Automatické aktualizace neuspěla při spuštění v důsledku následující
chyby: %%2

Error - 10/02/2012 00:35:39 | Computer Name = MARIE | Source = atapi | ID = 262153
Description = Zařízení \Device\Ide\IdePort1 neodpovídá v periodě časového limitu.

Error - 10/02/2012 00:53:49 | Computer Name = MARIE | Source = atapi | ID = 262153
Description = Zařízení \Device\Ide\IdePort1 neodpovídá v periodě časového limitu.

Error - 10/02/2012 01:13:10 | Computer Name = MARIE | Source = Service Control Manager | ID = 7000
Description = Služba Automatické aktualizace neuspěla při spuštění v důsledku následující
chyby: %%2

Error - 10/02/2012 01:13:11 | Computer Name = MARIE | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: lbd

Error - 10/02/2012 01:15:53 | Computer Name = MARIE | Source = Service Control Manager | ID = 7034
Description = Služba VNC Server Version 4 byla neočekávaně ukončena. Tento stav
nastal již 1krát.

Error - 10/02/2012 01:33:50 | Computer Name = MARIE | Source = Service Control Manager | ID = 7000
Description = Služba Automatické aktualizace neuspěla při spuštění v důsledku následující
chyby: %%2

Error - 10/02/2012 01:33:51 | Computer Name = MARIE | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: lbd


< End of report >
MBAM log file Malwarebytes' Anti-Malware www.malwarebytes.org Database version: Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 10/02/2012 22:33:13 mbam-log-2012-02-10 (22-33-00).txt Scan type: Quick scan Objects scanned: 251903 Time elapsed: 4 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Other info that may be useful to you: Internet Explorer does not open when I try to log on to Microsoft Windows update site. Super anti-spyware doesn't scan either and shuts down. Kaspersky tdss killer doesn't pick up anything malicious but GMER does. Let me know if you want the GMER log. Last Windows update took place in 2009!! This is my wife's notebook and since she can't play any youtube clips, she asked me to take a look and I came to you.
Hello Zen7

Let me know if you want the GMER log.

Yes, please post your GMER log and the aswMBR log…

Please download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI