Nějaká infekce, prosím o kontrolu.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
rokony
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 02 Lis 2011 18:09

Re: Nějaká infekce, prosím o kontrolu.

#16 Příspěvek od rokony »

OTL logfile created on: 20.11.2011 22:23:23 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = G:\Nové nástroje
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,97 Gb Total Physical Memory | 1,49 Gb Available Physical Memory | 75,61% Memory free
3,82 Gb Paging File | 3,26 Gb Available in Paging File | 85,35% Paging File free
Paging file location(s): E:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = E: | %SystemRoot% = E:\WINDOWS | %ProgramFiles% = E:\Program Files
Drive C: | 18,65 Gb Total Space | 3,34 Gb Free Space | 17,93% Space Free | Partition Type: NTFS
Drive E: | 149,04 Gb Total Space | 71,94 Gb Free Space | 48,27% Space Free | Partition Type: NTFS
Drive G: | 963,70 Mb Total Space | 101,83 Mb Free Space | 10,57% Space Free | Partition Type: FAT

Computer Name: PILA | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Processes (SafeList) ==========

PRC - [2011.11.20 22:18:24 | 000,584,192 | ---- | M] (OldTimer Tools) -- G:\Nové nástroje\OTL.exe
PRC - [2011.10.24 20:29:16 | 002,415,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2011.10.20 12:58:42 | 002,497,352 | ---- | M] (COMODO) -- E:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2011.10.18 06:14:54 | 001,229,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011.10.12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011.10.10 06:23:34 | 000,973,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2011.10.07 18:47:14 | 001,883,328 | ---- | M] (COMODO) -- E:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2011.09.08 19:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011.08.15 05:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011.08.02 05:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011.02.18 10:47:12 | 000,079,192 | ---- | M] (Research In Motion Limited) -- E:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
PRC - [2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\explorer.exe
PRC - [2007.01.03 19:38:44 | 000,207,680 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\GUI.exe
PRC - [2005.10.11 14:03:26 | 000,204,800 | ---- | M] (National Instruments, Inc.) -- E:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
PRC - [2005.10.11 14:00:24 | 000,053,248 | ---- | M] (National Instruments, Inc.) -- E:\WINDOWS\system32\lktsrv.exe
PRC - [2005.10.11 14:00:22 | 000,045,056 | ---- | M] (National Instruments, Inc.) -- E:\WINDOWS\system32\lkads.exe
PRC - [2005.10.10 13:08:32 | 000,049,152 | ---- | M] (National Instruments Corp.) -- E:\WINDOWS\system32\nisvcloc.exe
PRC - [2005.08.25 13:43:14 | 000,688,190 | ---- | M] (National Instruments, Inc.) -- E:\WINDOWS\system32\lkcitdl.exe


========== Modules (No Company Name) ==========

MOD - [2011.08.26 10:03:38 | 011,800,576 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\1fb5d8788c9a9a7f44e2d0fa19c62729\System.Web.ni.dll
MOD - [2011.08.26 10:02:44 | 000,971,264 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\48f8b951a598647dd309ca2031807a5d\System.Configuration.ni.dll
MOD - [2011.08.26 10:02:18 | 000,025,600 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d9228d58804dfd75fd92a4d12ffac8af\Accessibility.ni.dll
MOD - [2011.08.26 09:47:00 | 005,450,752 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\f354057a5b4fad4c399da28449ba0d92\System.Xml.ni.dll
MOD - [2011.08.26 09:46:56 | 012,430,848 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\29d16d2f164fe2263539789ecd0d9d4f\System.Windows.Forms.ni.dll
MOD - [2011.08.26 09:46:48 | 001,587,200 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\a59b17e6040e3f6286a2227dfdb17096\System.Drawing.ni.dll
MOD - [2011.08.26 09:45:55 | 007,950,848 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\f6a9a002526806f3a5b745cf5c407cae\System.ni.dll
MOD - [2011.08.26 09:45:50 | 011,490,816 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll
MOD - [2011.08.21 17:47:33 | 000,303,104 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2010.09.18 19:02:18 | 000,364,544 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3512.36804__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:18 | 000,204,800 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3512.36823__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:18 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3512.36818__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:18 | 000,011,776 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Runtime\2.0.3512.36907__90ba9c70f846762e\CLI.Caste.HydraVision.Runtime.dll
MOD - [2010.09.18 19:02:18 | 000,008,704 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Shared\2.0.3512.36906__90ba9c70f846762e\CLI.Caste.HydraVision.Shared.dll
MOD - [2010.09.18 19:02:18 | 000,007,680 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Wizard\2.0.3512.36910__90ba9c70f846762e\CLI.Caste.HydraVision.Wizard.dll
MOD - [2010.09.18 19:02:18 | 000,007,680 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Dashboard\2.0.3512.36906__90ba9c70f846762e\CLI.Caste.HydraVision.Dashboard.dll
MOD - [2010.09.18 19:02:17 | 001,736,704 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3512.36822__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:17 | 000,692,224 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3512.36866__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:17 | 000,491,520 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3512.36894__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:17 | 000,364,544 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3512.36880__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:17 | 000,077,824 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3512.36875__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:17 | 000,065,536 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3512.36856__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:17 | 000,036,864 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3512.36847__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:17 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3512.36812__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:16 | 000,331,776 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3512.36861__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:16 | 000,094,208 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3512.36862__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:16 | 000,073,728 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3512.36812__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:16 | 000,061,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dashboard\2.0.3512.36823__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:16 | 000,061,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3512.36861__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:16 | 000,045,056 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3512.36895__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:16 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runtime\2.0.3512.36822__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:15 | 000,643,072 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Dashboard\2.0.3512.36905__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:15 | 000,077,824 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Runtime\2.0.3512.36905__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:14 | 000,798,720 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3512.36849__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:14 | 000,409,600 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3512.36869__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:14 | 000,196,608 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3512.36824__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:14 | 000,094,208 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3512.36854__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:14 | 000,090,112 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3512.36848__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:13 | 000,749,568 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3512.36876__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:13 | 000,573,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3512.36824__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:13 | 000,409,600 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3512.36813__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:13 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3512.36854__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:13 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3512.36828__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:12 | 000,630,784 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3512.36857__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:12 | 000,393,216 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3512.36848__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:12 | 000,360,448 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3512.36843__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:12 | 000,270,336 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:12 | 000,061,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3512.36847__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:12 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3512.36848__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:12 | 000,032,768 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3512.36855__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:11 | 000,032,768 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.3498.37515__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2010.09.18 19:02:11 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3498.37517__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2010.09.18 19:02:11 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3498.37534__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3498.37533__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.3498.37551__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3498.37558__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3498.37615__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3498.37612__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3498.37554__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3498.37610__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,007,168 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2010.09.18 19:02:10 | 000,135,168 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3498.37541__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,094,208 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.3498.37518__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2010.09.18 19:02:10 | 000,061,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Shared\2.0.3498.37614__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,053,248 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3498.37582__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,045,056 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2010.09.18 19:02:10 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3498.37603__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3498.37674__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2010.09.18 19:02:10 | 000,024,576 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3498.37536__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0703\2.0.2651.18802__90ba9c70f846762e\DEM.Graphics.I0703.dll
MOD - [2010.09.18 19:02:10 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3498.37540__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3498.37526__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shared\2.0.3498.37575__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.3498.37571__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3498.37544__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3498.37574__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3498.37547__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,651,264 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\ResourceManagement.Foundation.Implementation\2.0.3512.36919__90ba9c70f846762e\ResourceManagement.Foundation.Implementation.dll
MOD - [2010.09.18 19:02:09 | 000,065,536 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3498.37583__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,057,344 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3498.37579__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,053,248 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3498.37578__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,049,152 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3498.37577__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,045,056 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3512.36900__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2010.09.18 19:02:09 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3498.37582__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,032,768 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3498.37557__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3498.37575__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3498.37572__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3498.37552__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,024,576 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3498.37580__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3498.37555__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.3498.37553__90ba9c70f846762e\APM.Foundation.dll
MOD - [2010.09.18 19:02:09 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3498.37535__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,014,848 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll
MOD - [2010.09.18 19:02:09 | 000,013,312 | ---- | M] () -- E:\WINDOWS\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll
MOD - [2010.09.18 19:02:09 | 000,007,168 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3512.36801__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
MOD - [2010.09.18 19:02:08 | 000,552,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3512.36883__90ba9c70f846762e\CLI.Component.Systemtray.dll
MOD - [2010.09.18 19:02:08 | 000,405,504 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3512.36817__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2010.09.18 19:02:08 | 000,106,496 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3512.36889__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2010.09.18 19:02:08 | 000,065,536 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3512.36887__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2010.09.18 19:02:08 | 000,057,344 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3512.36803__90ba9c70f846762e\CLI.Component.SkinFactory.dll
MOD - [2010.09.18 19:02:08 | 000,057,344 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3512.36801__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2010.09.18 19:02:08 | 000,045,056 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3498.37546__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2010.09.18 19:02:08 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3498.37522__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2010.09.18 19:02:08 | 000,036,864 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3498.37528__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2010.09.18 19:02:08 | 000,024,576 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3498.37548__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2010.09.18 19:02:08 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3498.37531__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll
MOD - [2010.09.18 19:02:08 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3498.37547__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2010.09.18 19:02:07 | 001,212,416 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3512.36808__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2010.09.18 19:02:07 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3498.37538__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2010.09.18 19:02:07 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3498.37549__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2010.09.18 19:02:07 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3498.37585__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2010.09.18 19:02:06 | 000,061,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\APM.Server\2.0.3512.36800__90ba9c70f846762e\APM.Server.dll
MOD - [2010.09.18 19:02:06 | 000,045,056 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.3512.36801__90ba9c70f846762e\AEM.Server.dll
MOD - [2010.09.18 19:02:06 | 000,032,768 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2010.09.18 19:02:06 | 000,019,456 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3512.36889__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2010.07.07 22:52:44 | 000,555,624 | ---- | M] () -- E:\Program Files\NVIDIA Corporation\nView\nvShell.dll
MOD - [2009.08.28 15:08:26 | 000,016,384 | R--- | M] () -- E:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
MOD - [2008.10.11 21:18:46 | 000,319,488 | ---- | M] () -- E:\Program Files\WinRAR\rarlng.dll
MOD - [2008.09.16 19:18:06 | 000,132,608 | ---- | M] () -- E:\Program Files\WinRAR\RarExt.dll
MOD - [2007.09.05 13:39:02 | 000,073,728 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\work.dll
MOD - [2007.08.21 10:49:36 | 000,125,504 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\MarkFunDrv.dll
MOD - [2007.08.15 14:34:22 | 000,446,464 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\Normal.dll
MOD - [2007.08.08 13:42:06 | 000,180,224 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\GVTunner.dll
MOD - [2007.05.14 18:47:24 | 000,073,728 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\W83781D.DLL
MOD - [2007.01.05 12:23:20 | 000,151,552 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\etiv.dll
MOD - [2007.01.03 19:38:44 | 000,207,680 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\GUI.exe
MOD - [2006.10.04 14:25:42 | 000,651,334 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\aticlocklib.dll
MOD - [2003.11.19 08:18:52 | 000,028,672 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\mibdata.dll
MOD - [2003.02.14 13:11:46 | 000,102,400 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\Sound.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (wuauserv)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011.11.18 14:22:06 | 000,428,928 | ---- | M] (Sysinternals - www.sysinternals.com) [On_Demand | Stopped] -- E:\Documents and Settings\Paul\Local Settings\temp\ZWGAPDV.exe -- (ZWGAPDV)
SRV - [2011.10.12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- E:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011.10.07 18:47:14 | 001,883,328 | ---- | M] (COMODO) [Auto | Running] -- E:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011.08.02 05:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- E:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2008.05.05 23:25:46 | 000,165,416 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- E:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe -- (GameConsoleService)
SRV - [2005.10.11 14:03:26 | 000,204,800 | ---- | M] (National Instruments, Inc.) [Auto | Running] -- E:\Program Files\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService)
SRV - [2005.10.11 14:00:24 | 000,053,248 | ---- | M] (National Instruments, Inc.) [Auto | Running] -- E:\WINDOWS\system32\lktsrv.exe -- (lkTimeSync)
SRV - [2005.10.11 14:00:22 | 000,045,056 | ---- | M] (National Instruments, Inc.) [Auto | Running] -- E:\WINDOWS\system32\lkads.exe -- (lkClassAds)
SRV - [2005.10.10 13:08:32 | 000,049,152 | ---- | M] (National Instruments Corp.) [Auto | Running] -- E:\WINDOWS\System32\nisvcloc.exe -- (niSvcLoc)
SRV - [2005.08.25 13:43:14 | 000,688,190 | ---- | M] (National Instruments, Inc.) [Auto | Running] -- E:\WINDOWS\system32\lkcitdl.exe -- (LkCitadelServer)


========== Driver Services (SafeList) ==========

DRV - [2011.11.20 22:05:55 | 000,024,944 | ---- | M] () [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\GVTDrv.sys -- (GVTDrv)
DRV - [2011.10.07 18:48:04 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- E:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2011.10.07 18:48:02 | 000,492,768 | ---- | M] (COMODO) [File_System | System | Running] -- E:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2011.10.07 18:48:02 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- E:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2011.10.07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- E:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011.10.04 06:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011.09.13 05:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- E:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011.08.08 05:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- E:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011.07.11 00:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- E:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011.07.11 00:14:28 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011.07.11 00:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- E:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011.07.11 00:14:26 | 000,134,608 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010.09.18 09:35:04 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- E:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2010.09.18 09:35:04 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- E:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010.09.10 18:26:37 | 000,016,512 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2010.07.28 11:27:36 | 006,108,776 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009.11.18 00:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009.11.18 00:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009.08.14 05:27:00 | 004,485,632 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2007.08.21 10:49:28 | 000,017,912 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- E:\Program Files\GIGABYTE\ET5Pro\MARKFUN.W32 -- (MarkFun_NT)
DRV - [2006.11.24 13:47:50 | 000,040,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ET5Drv.sys -- (ET5Drv)
DRV - [2006.07.19 11:25:10 | 000,012,048 | R--- | M] (ATI Technologies Inc.) [Kernel | Disabled | Running] -- E:\Program Files\GIGABYTE\ET5Pro\atidgllk.sys -- (atidgllk)
DRV - [2005.06.10 09:01:00 | 000,007,140 | ---- | M] () [Kernel | Auto | Running] -- E:\WINDOWS\System32\drivers\cvintdrv.sys -- (cvintdrv)
DRV - [2004.10.24 08:11:00 | 000,028,800 | ---- | M] (Deon van der Westhuysen) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\PPortJoy.sys -- (PPortJoystick)
DRV - [2004.10.24 08:11:00 | 000,013,952 | ---- | M] (Deon van der Westhuysen) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\PPJoyBus.sys -- (PPJoyBus)
DRV - [2003.10.31 09:37:12 | 000,027,631 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\system32\drivers\bcbus.sys -- (bcbus)
DRV - [2003.10.31 07:51:22 | 000,031,639 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\bc_tfish.sys -- (BC_TFISH)
DRV - [2003.10.31 07:49:42 | 000,043,101 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\bc_rijn.sys -- (BC_RIJN)
DRV - [2003.10.31 07:46:16 | 000,014,013 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\bc_gost.sys -- (BC_Gost)
DRV - [2003.10.31 07:19:02 | 000,017,991 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\bc_des.sys -- (BC_DES)
DRV - [2003.10.31 07:17:00 | 000,012,747 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\bc_bfish.sys -- (BC_BFish)
DRV - [2003.04.18 10:41:50 | 000,008,448 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\fsh.sys -- (fsh)
DRV - [2002.09.11 07:09:48 | 000,083,456 | ---- | M] (Jetico, Inc.) [Kernel | Disabled | Stopped] -- E:\WINDOWS\System32\drivers\BCSwap.sys -- (BCSWAP)
DRV - [2002.09.11 07:08:52 | 000,003,328 | ---- | M] (Jetico, Inc.) [Kernel | On_Demand | Running] -- E:\WINDOWS\System32\drivers\moh.sys -- (moh)
DRV - [2002.09.11 07:01:16 | 000,006,272 | ---- | M] (Jetico, Inc.) [Kernel | On_Demand | Running] -- E:\WINDOWS\System32\drivers\mhk.sys -- (mhk)
DRV - [2001.01.08 10:53:24 | 000,015,576 | R--- | M] () [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\usbbc.sys -- (Wdm1)
DRV - [1998.04.02 10:36:14 | 000,025,824 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- E:\WINDOWS\System32\drivers\A4SII300.SYS -- (A4SII300)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2025429265-261478967-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKU\S-1-5-21-2025429265-261478967-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: E:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: e:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: E:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: E:\Program Files\AVG\AVG2012\Firefox4\ [2011.11.06 18:08:22 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2011.11.02 16:30:57 | 000,437,882 | R--- | M]) - E:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 15062 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKU\S-1-5-21-2025429265-261478967-682003330-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] E:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BCWipeTM Startup] E:\Program Files\Jetico\BestCrypt\BCWipeTM.exe (Jetico, Inc.)
O4 - HKLM..\Run: [COMODO Internet Security] E:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [EasyTuneVPro] E:\Program Files\GIGABYTE\ET5Pro\ETcall.exe ()
O4 - HKLM..\Run: [NvCplDaemon] E:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] E:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] E:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] E:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [StartCCC] E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - Startup: E:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.exe.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2025429265-261478967-682003330-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2025429265-261478967-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2025429265-261478967-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2025429265-261478967-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O12 - Plugin for: .spop - E:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/aut ... s-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F108EBA-DDA6-4975-9336-D963815B6357}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -E:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (E:\WINDOWS\system32\userinit.exe) -E:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - E:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: E:\WINDOWS\Web\Wallpaper\Nebe.bmp
O24 - Desktop BackupWallPaper: E:\WINDOWS\Web\Wallpaper\Nebe.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\Y\Shell - "" = AutoRun
O33 - MountPoints2\Y\Shell\AutoRun\command - "" = Y:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (E:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - File not found

Drivers32: msacm.iac2 - E:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - E:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - E:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - E:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - E:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - E:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - E:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - E:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - E:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
PhysicalDisk0 MBR saved to E:\PhysicalMBR.bin

rokony
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 02 Lis 2011 18:09

Re: Nějaká infekce, prosím o kontrolu.

#17 Příspěvek od rokony »

========== Files/Folders - Created Within 60 Days ==========

[2011.11.18 14:16:03 | 000,000,000 | ---D | C] -- E:\Program Files\trend micro
[2011.11.18 14:16:01 | 000,000,000 | ---D | C] -- E:\rsit
[2011.11.18 13:56:30 | 000,000,000 | ---D | C] -- E:\Program Files\HijackThis
[2011.11.18 12:43:37 | 000,518,144 | ---- | C] (SteelWerX) -- E:\WINDOWS\SWREG.exe
[2011.11.18 12:43:37 | 000,406,528 | ---- | C] (SteelWerX) -- E:\WINDOWS\SWSC.exe
[2011.11.18 12:43:37 | 000,212,480 | ---- | C] (SteelWerX) -- E:\WINDOWS\SWXCACLS.exe
[2011.11.18 12:43:37 | 000,060,416 | ---- | C] (NirSoft) -- E:\WINDOWS\NIRCMD.exe
[2011.11.18 12:34:31 | 000,000,000 | R--D | C] -- E:\Documents and Settings\Paul\Nabídka Start\Programy\Nástroje pro správu
[2011.11.17 23:27:54 | 000,000,000 | ---D | C] -- E:\WINDOWS\temp
[2011.11.17 23:26:50 | 000,390,144 | ---- | C] (Microsoft Corporation) -- E:\WINDOWS\System32\CF11002.exe
[2011.11.17 23:26:24 | 000,396,288 | ---- | C] (Trend Micro Inc.) -- E:\hijackthis.exe
[2011.11.17 22:48:19 | 000,000,000 | ---D | C] -- E:\WINDOWS\ERDNT
[2011.11.17 22:48:18 | 000,390,144 | ---- | C] (Microsoft Corporation) -- E:\WINDOWS\System32\CF3455.exe
[2011.11.17 22:48:15 | 000,000,000 | ---D | C] -- E:\Qoobox
[2011.11.17 11:56:17 | 000,000,000 | ---D | C] -- E:\Záloha SD karty 2G
[2011.11.07 19:40:07 | 000,000,000 | ---D | C] -- E:\WINDOWS\pss
[2011.11.03 18:07:27 | 000,000,000 | ---D | C] -- E:\WINDOWS\Sun
[2011.11.03 17:08:22 | 000,000,000 | ---D | C] -- E:\Program Files\NORTON UTILITIES 14
[2011.11.02 00:07:42 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Dokumenty\COMODO
[2011.11.01 23:53:28 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Nabídka Start\Programy\COMODO
[2011.11.01 23:53:28 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Data aplikací\Comodo
[2011.11.01 23:53:24 | 000,000,000 | ---D | C] -- E:\Program Files\COMODO
[2011.11.01 23:53:23 | 001,700,352 | ---- | C] (Microsoft Corporation) -- E:\WINDOWS\System32\gdiplus.dll
[2011.11.01 23:52:30 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
[2011.11.01 23:39:41 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Nabídka Start\Programy\Spybot - Search & Destroy
[2011.11.01 23:39:36 | 000,000,000 | ---D | C] -- E:\Program Files\Spybot - Search & Destroy
[2011.11.01 23:39:36 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
[2011.10.30 19:25:55 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Data aplikací\AVG
[2011.10.29 20:36:35 | 000,000,000 | ---D | C] -- E:\WINDOWS\System32\NtmsData
[2011.10.29 17:42:24 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\Opera
[2011.10.29 17:42:24 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Data aplikací\Opera
[2011.10.29 17:42:15 | 000,000,000 | ---D | C] -- E:\Program Files\Opera
[2011.10.29 17:41:32 | 011,355,704 | ---- | C] (Opera Software ASA) -- E:\Opera_1152_int_Setup.exe
[2011.10.29 16:18:54 | 000,000,000 | ---D | C] -- E:\XP Dell
[2011.10.23 19:47:58 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\tific
[2011.10.23 19:47:58 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Data aplikací\Tific
[2011.10.18 19:29:28 | 000,000,000 | -H-D | C] -- E:\$AVG
[2011.10.18 19:13:10 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Data aplikací\AVG2012
[2011.10.18 19:11:19 | 000,000,000 | -H-D | C] -- E:\Documents and Settings\All Users\Data aplikací\Common Files
[2011.10.18 19:11:13 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Nabídka Start\Programy\AVG 2012
[2011.10.18 19:10:38 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Data aplikací\AVG2012
[2011.10.18 19:10:38 | 000,000,000 | ---D | C] -- E:\WINDOWS\System32\drivers\AVG
[2011.10.18 19:10:10 | 000,000,000 | ---D | C] -- E:\Program Files\AVG
[2011.10.18 19:09:49 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Data aplikací\MFAData
[2011.10.07 18:48:04 | 000,097,760 | ---- | C] (COMODO) -- E:\WINDOWS\System32\drivers\inspect.sys
[2011.10.07 18:48:02 | 000,492,768 | ---- | C] (COMODO) -- E:\WINDOWS\System32\drivers\cmdGuard.sys
[2011.10.07 18:48:02 | 000,031,704 | ---- | C] (COMODO) -- E:\WINDOWS\System32\drivers\cmdhlp.sys
[2011.10.07 18:48:00 | 000,018,056 | ---- | C] (COMODO) -- E:\WINDOWS\System32\drivers\cmderd.sys
[2011.10.07 18:47:12 | 000,300,200 | ---- | C] (COMODO) -- E:\WINDOWS\System32\guard32.dll
[2011.10.07 18:47:12 | 000,033,984 | ---- | C] (COMODO) -- E:\WINDOWS\System32\cmdcsr.dll
[2011.10.03 20:35:12 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\NP3
[2011.10.03 20:33:23 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Data aplikací\NeuroProgrammer3
[2011.10.03 20:33:23 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Dokumenty\Neuro-Programmer 3 Documents
[2011.10.03 20:33:20 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\Xenocode
[2011.10.03 20:33:17 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Nabídka Start\Programy\Neuro-Programmer 3
[2011.10.03 20:33:08 | 000,000,000 | ---D | C] -- E:\Program Files\Neuro-Programmer 3
[2011.01.22 20:24:57 | 000,047,360 | ---- | C] (VSO Software) -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.sys
[9 E:\WINDOWS\*.tmp files -> E:\WINDOWS\*.tmp -> ]
[1 E:\WINDOWS\System32\*.tmp files -> E:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 60 Days ==========

[2011.11.20 22:24:40 | 000,000,512 | ---- | M] () -- E:\PhysicalMBR.bin
[2011.11.20 22:18:24 | 000,584,192 | ---- | M] () -- E:\Documents and Settings\Paul\Plocha\OTL.exe
[2011.11.20 22:05:55 | 000,024,944 | ---- | M] () -- E:\WINDOWS\System32\drivers\GVTDrv.sys
[2011.11.20 22:05:54 | 000,000,004 | ---- | M] () -- E:\WINDOWS\System32\GVTunner.ref
[2011.11.20 22:04:50 | 000,002,048 | --S- | M] () -- E:\WINDOWS\bootstat.dat
[2011.11.19 23:50:42 | 000,000,000 | ---- | M] () -- E:\Documents and Settings\Paul\defogger_reenable
[2011.11.19 19:46:30 | 000,050,477 | ---- | M] () -- E:\Documents and Settings\Paul\Plocha\Defogger.exe
[2011.11.18 20:56:08 | 071,353,389 | ---- | M] () -- E:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011.11.18 16:26:00 | 000,003,302 | ---- | M] () -- E:\WINDOWS\WTRAN32.INI
[2011.11.18 16:26:00 | 000,000,000 | ---- | M] () -- E:\WINDOWS\XXLGSC
[2011.11.18 14:25:28 | 000,440,820 | ---- | M] () -- E:\WINDOWS\System32\perfh009.dat
[2011.11.18 14:25:28 | 000,437,336 | ---- | M] () -- E:\WINDOWS\System32\perfh005.dat
[2011.11.18 14:25:28 | 000,082,642 | ---- | M] () -- E:\WINDOWS\System32\perfc005.dat
[2011.11.18 14:25:28 | 000,071,138 | ---- | M] () -- E:\WINDOWS\System32\perfc009.dat
[2011.11.17 23:26:43 | 000,390,144 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\System32\CF11002.exe
[2011.11.17 22:48:13 | 000,390,144 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\System32\CF3455.exe
[2011.11.17 11:42:26 | 000,002,206 | ---- | M] () -- E:\WINDOWS\System32\wpa.dbl
[2011.11.06 18:08:22 | 000,000,714 | ---- | M] () -- E:\Documents and Settings\All Users\Plocha\AVG 2012.lnk
[2011.11.02 19:25:12 | 000,396,288 | ---- | M] (Trend Micro Inc.) -- E:\hijackthis.exe
[2011.11.02 16:30:57 | 000,437,882 | R--- | M] () -- E:\WINDOWS\System32\drivers\etc\hosts
[2011.11.01 23:53:48 | 000,001,653 | ---- | M] () -- E:\Documents and Settings\All Users\Plocha\COMODO Firewall.lnk
[2011.11.01 23:53:24 | 001,700,352 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\System32\gdiplus.dll
[2011.11.01 23:39:42 | 000,000,933 | ---- | M] () -- E:\Documents and Settings\Paul\Plocha\Spybot - Search & Destroy.lnk
[2011.10.29 18:45:48 | 000,000,671 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\vso_ts_preview.xml
[2011.10.29 17:50:50 | 000,024,061 | ---- | M] () -- E:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011.10.29 17:50:00 | 000,354,709 | ---- | M] () -- E:\Documents and Settings\Paul\Dokumenty\Vytvoření recovery consoly.mht
[2011.10.29 17:42:19 | 000,001,492 | ---- | M] () -- E:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.10.29 17:41:32 | 011,355,704 | ---- | M] (Opera Software ASA) -- E:\Opera_1152_int_Setup.exe
[2011.10.26 20:04:15 | 001,461,600 | ---- | M] () -- E:\Documents and Settings\Paul\Dokumenty\Návod k použití ComboFixu.mht
[2011.10.09 16:32:01 | 000,024,576 | ---- | M] () -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.10.07 18:48:04 | 000,097,760 | ---- | M] (COMODO) -- E:\WINDOWS\System32\drivers\inspect.sys
[2011.10.07 18:48:02 | 000,492,768 | ---- | M] (COMODO) -- E:\WINDOWS\System32\drivers\cmdGuard.sys
[2011.10.07 18:48:02 | 000,031,704 | ---- | M] (COMODO) -- E:\WINDOWS\System32\drivers\cmdhlp.sys
[2011.10.07 18:48:00 | 000,018,056 | ---- | M] (COMODO) -- E:\WINDOWS\System32\drivers\cmderd.sys
[2011.10.07 18:47:12 | 000,300,200 | ---- | M] (COMODO) -- E:\WINDOWS\System32\guard32.dll
[2011.10.07 18:47:12 | 000,033,984 | ---- | M] (COMODO) -- E:\WINDOWS\System32\cmdcsr.dll
[2011.10.07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\WINDOWS\System32\drivers\avgldx86.sys
[2011.10.04 06:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- E:\WINDOWS\System32\drivers\AVGIDSShim.sys
[2011.10.03 20:33:17 | 000,000,730 | ---- | M] () -- E:\Documents and Settings\All Users\Plocha\Neuro-Programmer 3.lnk
[2011.10.02 18:07:14 | 000,000,075 | ---- | M] () -- E:\WINDOWS\USBBC.ini
[9 E:\WINDOWS\*.tmp files -> E:\WINDOWS\*.tmp -> ]
[1 E:\WINDOWS\System32\*.tmp files -> E:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.11.20 22:24:40 | 000,000,512 | ---- | C] () -- E:\PhysicalMBR.bin
[2011.11.20 22:20:28 | 000,584,192 | ---- | C] () -- E:\Documents and Settings\Paul\Plocha\OTL.exe
[2011.11.19 23:50:42 | 000,000,000 | ---- | C] () -- E:\Documents and Settings\Paul\defogger_reenable
[2011.11.19 23:49:43 | 000,050,477 | ---- | C] () -- E:\Documents and Settings\Paul\Plocha\Defogger.exe
[2011.11.19 23:49:21 | 000,302,592 | ---- | C] () -- E:\Documents and Settings\Paul\Plocha\gmer.exe
[2011.11.18 20:56:08 | 071,353,389 | ---- | C] () -- E:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011.11.18 14:24:33 | 000,000,004 | ---- | C] () -- E:\WINDOWS\System32\GVTunner.ref
[2011.11.18 12:43:37 | 000,256,000 | ---- | C] () -- E:\WINDOWS\PEV.exe
[2011.11.18 12:43:37 | 000,098,816 | ---- | C] () -- E:\WINDOWS\sed.exe
[2011.11.18 12:43:37 | 000,080,412 | ---- | C] () -- E:\WINDOWS\grep.exe
[2011.11.18 12:43:37 | 000,068,096 | ---- | C] () -- E:\WINDOWS\zip.exe
[2011.11.01 23:53:48 | 000,001,653 | ---- | C] () -- E:\Documents and Settings\All Users\Plocha\COMODO Firewall.lnk
[2011.11.01 23:39:42 | 000,000,933 | ---- | C] () -- E:\Documents and Settings\Paul\Plocha\Spybot - Search & Destroy.lnk
[2011.10.29 17:50:50 | 000,024,061 | ---- | C] () -- E:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011.10.29 17:49:57 | 000,354,709 | ---- | C] () -- E:\Documents and Settings\Paul\Dokumenty\Vytvoření recovery consoly.mht
[2011.10.29 17:42:19 | 000,001,498 | ---- | C] () -- E:\Documents and Settings\All Users\Nabídka Start\Programy\Opera.lnk
[2011.10.29 17:42:19 | 000,001,492 | ---- | C] () -- E:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.10.26 20:04:12 | 001,461,600 | ---- | C] () -- E:\Documents and Settings\Paul\Dokumenty\Návod k použití ComboFixu.mht
[2011.10.18 19:11:13 | 000,000,714 | ---- | C] () -- E:\Documents and Settings\All Users\Plocha\AVG 2012.lnk
[2011.10.03 20:33:17 | 000,000,730 | ---- | C] () -- E:\Documents and Settings\All Users\Plocha\Neuro-Programmer 3.lnk
[2011.07.14 19:14:34 | 001,239,680 | ---- | C] () -- E:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2011.05.05 21:39:12 | 000,225,280 | ---- | C] () -- E:\WINDOWS\System32\net_rim_plazmic_flint_dialog.dll
[2011.03.18 23:39:58 | 000,000,217 | ---- | C] () -- E:\WINDOWS\MPPAGER.INI
[2011.03.16 18:12:32 | 000,000,871 | ---- | C] () -- E:\WINDOWS\QIII.INI
[2011.02.08 16:48:13 | 000,002,591 | ---- | C] () -- E:\WINDOWS\SE.INI
[2011.01.22 20:25:08 | 000,000,671 | ---- | C] () -- E:\Documents and Settings\Paul\Data aplikací\vso_ts_preview.xml
[2011.01.22 20:24:57 | 000,087,608 | ---- | C] () -- E:\Documents and Settings\Paul\Data aplikací\inst.exe
[2011.01.22 20:24:57 | 000,007,887 | ---- | C] () -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.cat
[2011.01.22 20:24:57 | 000,001,144 | ---- | C] () -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.inf
[2010.12.08 13:15:03 | 000,004,096 | ---- | C] () -- E:\WINDOWS\d3dx.dat
[2010.11.09 18:22:36 | 000,024,576 | ---- | C] () -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.09.23 08:34:37 | 000,000,124 | ---- | C] () -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\fusioncache.dat
[2010.09.22 12:15:21 | 000,022,328 | ---- | C] () -- E:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010.09.22 12:15:21 | 000,022,328 | ---- | C] () -- E:\Documents and Settings\Paul\Data aplikací\PnkBstrK.sys
[2010.09.22 12:15:06 | 000,103,736 | ---- | C] () -- E:\WINDOWS\System32\PnkBstrB.exe
[2010.09.22 12:15:05 | 000,669,184 | ---- | C] () -- E:\WINDOWS\System32\pbsvc.exe
[2010.09.22 12:15:05 | 000,066,872 | ---- | C] () -- E:\WINDOWS\System32\PnkBstrA.exe
[2010.09.21 17:34:51 | 000,003,302 | ---- | C] () -- E:\WINDOWS\WTRAN32.INI
[2010.09.18 19:00:15 | 004,289,024 | ---- | C] () -- E:\Program Files\trial_setup.msi
[2010.09.18 19:00:15 | 000,040,448 | ---- | C] () -- E:\Program Files\trial_setup.exe
[2010.09.18 19:00:15 | 000,000,777 | ---- | C] () -- E:\Program Files\trial_setup.ini
[2010.09.18 09:35:04 | 000,281,760 | ---- | C] () -- E:\WINDOWS\System32\drivers\atksgt.sys
[2010.09.18 09:35:04 | 000,025,888 | ---- | C] () -- E:\WINDOWS\System32\drivers\lirsgt.sys
[2010.09.18 08:30:29 | 000,015,576 | R--- | C] () -- E:\WINDOWS\System32\drivers\usbbc.sys
[2010.09.18 08:30:29 | 000,003,953 | R--- | C] () -- E:\WINDOWS\System32\coinst.dll
[2010.09.18 08:22:15 | 000,000,075 | ---- | C] () -- E:\WINDOWS\USBBC.ini
[2010.09.18 08:22:15 | 000,000,000 | ---- | C] () -- E:\WINDOWS\MDI.INI
[2010.09.14 17:42:49 | 000,000,000 | ---- | C] () -- E:\WINDOWS\ativpsrm.bin
[2010.09.14 17:40:48 | 000,593,920 | ---- | C] () -- E:\WINDOWS\System32\ati2sgag.exe
[2010.09.11 20:10:48 | 000,024,944 | ---- | C] () -- E:\WINDOWS\System32\drivers\GVTDrv.sys
[2010.09.11 12:48:03 | 000,208,896 | ---- | C] () -- E:\WINDOWS\System32\igxpun.exe
[2010.09.11 12:32:21 | 000,232,968 | ---- | C] () -- E:\WINDOWS\System32\nvdrsdb0.bin
[2010.09.11 12:32:19 | 000,232,968 | ---- | C] () -- E:\WINDOWS\System32\nvdrsdb1.bin
[2010.09.11 12:32:19 | 000,000,001 | ---- | C] () -- E:\WINDOWS\System32\nvdrssel.bin
[2010.09.10 19:51:39 | 000,004,249 | ---- | C] () -- E:\WINDOWS\ODBCINST.INI
[2010.09.10 19:50:33 | 000,120,544 | ---- | C] () -- E:\WINDOWS\System32\FNTCACHE.DAT
[2010.09.10 19:41:47 | 000,004,990 | ---- | C] () -- E:\Documents and Settings\All Users\Data aplikací\mtbjfghn.xbe
[2010.09.10 19:09:12 | 000,182,275 | ---- | C] () -- E:\WINDOWS\System32\d3d10core.dll
[2010.09.10 19:09:11 | 000,376,832 | ---- | C] () -- E:\WINDOWS\System32\M2000Twn.dll
[2010.09.10 19:09:10 | 000,728,858 | ---- | C] () -- E:\Program Files\Common Files\unins000.exe
[2010.09.10 19:09:10 | 000,073,728 | ---- | C] () -- E:\WINDOWS\System32\CompressATI2.dll
[2010.09.10 19:09:10 | 000,002,884 | ---- | C] () -- E:\Program Files\Common Files\unins000.dat
[2010.09.10 19:04:50 | 002,195,030 | ---- | C] () -- E:\WINDOWS\System32\nvdata.bin
[2010.09.10 18:00:37 | 000,002,048 | --S- | C] () -- E:\WINDOWS\bootstat.dat
[2010.09.10 17:56:06 | 000,021,812 | ---- | C] () -- E:\WINDOWS\System32\emptyregdb.dat
[2009.08.14 02:42:20 | 000,887,724 | ---- | C] () -- E:\WINDOWS\System32\ativva6x.dat
[2009.08.14 02:42:20 | 000,000,003 | ---- | C] () -- E:\WINDOWS\System32\ativva5x.dat
[2009.07.14 16:09:12 | 000,197,654 | ---- | C] () -- E:\WINDOWS\System32\atiicdxx.dat
[2009.02.18 18:55:20 | 000,294,912 | ---- | C] () -- E:\WINDOWS\System32\ATIODE.exe
[2009.02.03 21:52:02 | 000,045,056 | ---- | C] () -- E:\WINDOWS\System32\ATIODCLI.exe
[2008.10.07 08:13:30 | 000,197,912 | ---- | C] () -- E:\WINDOWS\System32\physxcudart_20.dll
[2008.10.07 08:13:22 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSwedish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSpanish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelPortugese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelKorean.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelJapanese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelGerman.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelFrench.dll
[2008.04.15 03:20:46 | 000,237,568 | ---- | C] () -- E:\WINDOWS\glut32.dll
[2008.04.14 08:16:08 | 000,001,804 | ---- | C] () -- E:\WINDOWS\System32\Dcache.bin
[2006.12.31 06:57:08 | 000,004,569 | ---- | C] () -- E:\WINDOWS\System32\secupd.dat
[2005.06.10 09:00:00 | 000,102,400 | ---- | C] () -- E:\WINDOWS\System32\cviUSI.dll
[2005.06.10 09:00:00 | 000,007,140 | ---- | C] () -- E:\WINDOWS\System32\drivers\cvintdrv.sys
[2004.12.31 18:35:42 | 000,000,237 | ---- | C] () -- E:\WINDOWS\System32\oeminfo.ini
[2002.10.03 14:42:27 | 000,000,034 | ---- | C] () -- E:\WINDOWS\Q3version.ini
[2001.10.25 17:00:00 | 013,107,200 | ---- | C] () -- E:\WINDOWS\System32\oembios.bin
[2001.10.25 17:00:00 | 000,673,088 | ---- | C] () -- E:\WINDOWS\System32\mlang.dat
[2001.10.25 17:00:00 | 000,440,820 | ---- | C] () -- E:\WINDOWS\System32\perfh009.dat
[2001.10.25 17:00:00 | 000,437,336 | ---- | C] () -- E:\WINDOWS\System32\perfh005.dat
[2001.10.25 17:00:00 | 000,272,128 | ---- | C] () -- E:\WINDOWS\System32\perfi009.dat
[2001.10.25 17:00:00 | 000,269,162 | ---- | C] () -- E:\WINDOWS\System32\perfi005.dat
[2001.10.25 17:00:00 | 000,218,003 | ---- | C] () -- E:\WINDOWS\System32\dssec.dat
[2001.10.25 17:00:00 | 000,082,642 | ---- | C] () -- E:\WINDOWS\System32\perfc005.dat
[2001.10.25 17:00:00 | 000,071,138 | ---- | C] () -- E:\WINDOWS\System32\perfc009.dat
[2001.10.25 17:00:00 | 000,046,258 | ---- | C] () -- E:\WINDOWS\System32\mib.bin
[2001.10.25 17:00:00 | 000,032,072 | ---- | C] () -- E:\WINDOWS\System32\perfd005.dat
[2001.10.25 17:00:00 | 000,028,626 | ---- | C] () -- E:\WINDOWS\System32\perfd009.dat
[2001.10.25 17:00:00 | 000,004,463 | ---- | C] () -- E:\WINDOWS\System32\oembios.dat
[2001.10.25 17:00:00 | 000,000,741 | ---- | C] () -- E:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011.10.18 19:27:00 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\AVG2012
[2011.10.18 19:11:19 | 000,000,000 | -H-D | M] -- E:\Documents and Settings\All Users\Data aplikací\Common Files
[2011.09.02 15:38:01 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\GameXzone
[2011.11.18 20:56:13 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\MFAData
[2011.07.14 17:48:27 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\Research In Motion
[2011.11.07 19:48:37 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.12.09 22:12:36 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\WildTangent
[2011.10.30 19:26:25 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\AVG
[2011.10.18 19:13:10 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\AVG2012
[2010.09.10 19:41:47 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Carambis
[2011.08.05 20:43:22 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Composer
[2011.07.20 19:30:07 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\ImgBurn
[2010.12.13 16:48:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\InterTrust
[2011.10.05 21:56:12 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\NeuroProgrammer3
[2011.10.29 17:42:24 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Opera
[2010.09.10 20:31:02 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Poser 7
[2011.08.05 20:36:08 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Research In Motion
[2011.09.01 21:18:56 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Rovio
[2011.10.23 19:47:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Tific
[2010.09.10 18:50:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Uniblue
[2011.10.29 18:43:05 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Vso
[2010.12.08 22:50:01 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\WildTangent

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = E:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 07:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)

< >


< MD5 for: AGP440.SYS >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys

< MD5 for: ATAPI.SYS >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- E:\WINDOWS\system32\dllcache\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- E:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- E:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- E:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 07:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- E:\WINDOWS\system32\autochk.exe
[2008.04.14 07:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- E:\WINDOWS\system32\dllcache\autochk.exe

< MD5 for: CDROM.SYS >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.13 23:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- E:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2008.04.14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- E:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- E:\WINDOWS\system32\dllcache\cryptsvc.dll

< MD5 for: CSRSS.EXE >
[2008.04.14 07:52:18 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- E:\WINDOWS\system32\csrss.exe
[2008.04.14 07:52:18 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- E:\WINDOWS\system32\dllcache\csrss.exe

< MD5 for: EVENTLOG.DLL >
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- E:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- E:\WINDOWS\system32\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- E:\WINDOWS\explorer.exe
[2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- E:\WINDOWS\system32\dllcache\explorer.exe
[2010.09.12 15:09:18 | 000,017,408 | ---- | M] () MD5=315E8398DFF13A6CA45A2B6C189E7284 -- E:\Documents and Settings\Paul\Plocha\Data\Native\STUBEXE\8.0.1135\@WINDIR@\explorer.exe

< MD5 for: FASTFAT.SYS >
[2008.04.13 23:44:30 | 000,143,744 | ---- | M] (Microsoft Corporation) MD5=38D332A6D56AF32635675F132548343E -- E:\WINDOWS\system32\dllcache\fastfat.sys
[2008.04.13 23:44:30 | 000,143,744 | ---- | M] (Microsoft Corporation) MD5=38D332A6D56AF32635675F132548343E -- E:\WINDOWS\system32\drivers\fastfat.sys

< MD5 for: HAL.DLL >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.13 23:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- E:\WINDOWS\system32\hal.dll

< MD5 for: CHANGER.SYS >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys

< MD5 for: IASTOR.SYS >
[2008.06.23 13:12:16 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- E:\WINDOWS\NLDRV\001\iastor.sys

< MD5 for: ISAPNP.SYS >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- E:\WINDOWS\system32\dllcache\isapnp.sys
[2008.04.14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- E:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- E:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\isapnp.sys

< MD5 for: LSASS.EXE >
[2008.04.14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- E:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- E:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- E:\WINDOWS\system32\dllcache\ndis.sys
[2008.04.13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- E:\WINDOWS\system32\drivers\ndis.sys
[1994.09.04 07:07:02 | 000,107,812 | ---- | M] () MD5=EDE3814D47F3F103771DBC1590D6B177 -- E:\RŮZNÉ OVLADAČE\E2000-origDisketa\WINNT31\NDIS.SYS

< MD5 for: NETLOGON.DLL >
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- E:\WINDOWS\system32\dllcache\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- E:\WINDOWS\system32\netlogon.dll

< MD5 for: NTFS.SYS >
[2008.04.13 23:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- E:\WINDOWS\system32\dllcache\ntfs.sys
[2008.04.13 23:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- E:\WINDOWS\system32\drivers\ntfs.sys

< MD5 for: SCECLI.DLL >
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- E:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- E:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2009.02.09 12:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- E:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- E:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- E:\WINDOWS\system32\services.exe

< MD5 for: SMSS.EXE >
[2008.04.14 07:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- E:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 07:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- E:\WINDOWS\system32\smss.exe

< MD5 for: SPOOLSV.EXE >
[2010.08.17 14:19:36 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 -- E:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- E:\WINDOWS\system32\dllcache\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- E:\WINDOWS\system32\spoolsv.exe

< MD5 for: SVCHOST.EXE >
[2008.04.14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- E:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- E:\WINDOWS\system32\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- E:\Záloha SD karty 2G\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- E:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- E:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- E:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- E:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- E:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- E:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008.04.14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- E:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- E:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2008.04.14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- E:\WINDOWS\system32\dllcache\ws2_32.dll
[2008.04.14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- E:\WINDOWS\system32\ws2_32.dll

< >

< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >

< %systemroot%\system32\drivers\*.sys /5 >
[2011.11.20 22:05:55 | 000,024,944 | ---- | M] () -- E:\WINDOWS\system32\drivers\GVTDrv.sys

< %systemroot%\system32\drivers\*.sys /X >
[2009.08.14 02:17:58 | 000,053,248 | ---- | M] (ATI Technologies Inc.) -- E:\WINDOWS\system32\drivers\ati2erec.dll
[2001.10.25 17:00:00 | 003,440,660 | ---- | M] () -- E:\WINDOWS\system32\drivers\gm.dls
[2001.10.25 17:00:00 | 000,000,646 | ---- | M] () -- E:\WINDOWS\system32\drivers\gmreadme.txt
[2011.07.14 17:50:45 | 000,000,000 | -H-- | M] () -- E:\WINDOWS\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011.07.14 17:50:47 | 000,000,000 | -H-- | M] () -- E:\WINDOWS\system32\drivers\Msft_Kernel_RimUsb_01009.Wdf

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\*.* /5 >
[2011.11.17 23:26:43 | 000,390,144 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\system32\CF11002.exe
[2011.11.17 22:48:13 | 000,390,144 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\system32\CF3455.exe
[2011.11.20 22:05:54 | 000,000,004 | ---- | M] () -- E:\WINDOWS\system32\GVTunner.ref
[2011.11.18 14:25:28 | 000,082,642 | ---- | M] () -- E:\WINDOWS\system32\perfc005.dat
[2011.11.18 14:25:28 | 000,071,138 | ---- | M] () -- E:\WINDOWS\system32\perfc009.dat
[2011.11.18 14:25:28 | 000,437,336 | ---- | M] () -- E:\WINDOWS\system32\perfh005.dat
[2011.11.18 14:25:28 | 000,440,820 | ---- | M] () -- E:\WINDOWS\system32\perfh009.dat
[2011.11.18 14:25:28 | 001,046,050 | ---- | M] () -- E:\WINDOWS\system32\PerfStringBackup.INI
[2011.11.17 11:42:26 | 000,002,206 | ---- | M] () -- E:\WINDOWS\system32\wpa.dbl
[1 E:\WINDOWS\system32\*.tmp files -> E:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\*.dll /lockedfiles >
[1 E:\WINDOWS\system32\*.tmp files -> E:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\config\*.sav >
[2010.09.10 19:49:51 | 000,094,208 | ---- | M] () -- E:\WINDOWS\system32\config\default.sav
[2010.09.10 19:49:51 | 001,093,632 | ---- | M] () -- E:\WINDOWS\system32\config\software.sav
[2010.09.10 19:49:51 | 000,507,904 | ---- | M] () -- E:\WINDOWS\system32\config\system.sav

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\*.* /U /s >
[9 E:\WINDOWS\*.tmp files -> E:\WINDOWS\*.tmp -> ]
[11 E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[8 E:\WINDOWS\Installer\*.tmp files -> E:\WINDOWS\Installer\*.tmp -> ]
[1 E:\WINDOWS\SoftwareDistribution\Download\43aa18ebd60ddd747e3a838509abcd92\download\*.tmp files -> E:\WINDOWS\SoftwareDistribution\Download\43aa18ebd60ddd747e3a838509abcd92\download\*.tmp -> ]
[1 E:\WINDOWS\SoftwareDistribution\Download\6d0c89a36b9ebeb9a8ad3924b5c9131f\download\*.tmp files -> E:\WINDOWS\SoftwareDistribution\Download\6d0c89a36b9ebeb9a8ad3924b5c9131f\download\*.tmp -> ]
[1 E:\WINDOWS\SoftwareDistribution\Download\83f89bf741551173774b5c6c29adff30\download\*.tmp files -> E:\WINDOWS\SoftwareDistribution\Download\83f89bf741551173774b5c6c29adff30\download\*.tmp -> ]
[1 E:\WINDOWS\SoftwareDistribution\Download\b4ccf90cba244e6dadbae18938ad1aee\*.tmp files -> E:\WINDOWS\SoftwareDistribution\Download\b4ccf90cba244e6dadbae18938ad1aee\*.tmp -> ]
[1 E:\WINDOWS\SoftwareDistribution\Download\f3146c7a92d8fac266514a452b7053fb\*.tmp files -> E:\WINDOWS\SoftwareDistribution\Download\f3146c7a92d8fac266514a452b7053fb\*.tmp -> ]
[1 E:\WINDOWS\system32\*.tmp files -> E:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\*. /mp /s >

< %ALLUSERSPROFILE%\Data Aplikací\*.* >
[2010.09.10 19:51:14 | 000,000,062 | -HS- | M] () -- E:\Documents and Settings\All Users\Data Aplikací\desktop.ini
[2010.09.10 19:41:47 | 000,004,990 | ---- | M] () -- E:\Documents and Settings\All Users\Data Aplikací\mtbjfghn.xbe

< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
[2011.10.26 16:32:07 | 005,595,488 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Documents and Settings\All Users\Data Aplikací\AVG2012\update\backup\avgmfapx.exe
[2011.11.01 23:53:19 | 007,245,888 | ---- | M] (COMODO) -- E:\Documents and Settings\All Users\Data Aplikací\Comodo Downloader\geekbuddy.exe
[2011.10.07 18:46:50 | 000,198,984 | ---- | M] () -- E:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\ComodoCleanup.exe
[5 E:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\*.tmp files -> E:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\*.tmp -> ]

< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >

< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >

< %APPDATA%\*. >
[2011.07.20 22:53:42 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Adobe
[2011.08.06 13:08:58 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\AdobeUM
[2010.09.18 19:02:20 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\ATI
[2011.10.30 19:26:25 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\AVG
[2011.10.18 19:13:10 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\AVG2012
[2010.09.10 19:41:47 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Carambis
[2011.08.05 20:43:22 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Composer
[2010.09.19 17:00:24 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Help
[2010.09.10 18:02:35 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Identities
[2011.07.20 19:30:07 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\ImgBurn
[2010.12.13 16:22:39 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\InstallShield
[2010.12.13 16:48:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\InterTrust
[2011.07.20 22:53:42 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Macromedia
[2011.07.14 18:02:28 | 000,000,000 | --SD | M] -- E:\Documents and Settings\Paul\Data aplikací\Microsoft
[2011.10.05 21:56:12 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\NeuroProgrammer3
[2011.10.29 17:42:24 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Opera
[2010.09.10 20:31:02 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Poser 7
[2011.08.05 20:36:08 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Research In Motion
[2011.09.01 21:18:56 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Rovio
[2011.08.01 17:41:51 | 000,000,000 | RH-D | M] -- E:\Documents and Settings\Paul\Data aplikací\SecuROM
[2011.04.25 16:44:08 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Sun
[2011.10.23 19:47:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Tific
[2010.09.10 18:50:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Uniblue
[2011.10.29 18:43:05 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Vso
[2010.12.08 22:50:01 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\WildTangent
[2010.09.18 19:57:05 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\WinRAR

< %APPDATA%\*.* >
[2010.09.10 19:51:14 | 000,000,062 | -HS- | M] () -- E:\Documents and Settings\Paul\Data aplikací\desktop.ini
[2011.01.22 20:24:57 | 000,087,608 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\inst.exe
[2011.01.22 20:24:57 | 000,007,887 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.cat
[2011.01.22 20:24:57 | 000,001,144 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.inf
[2011.01.22 20:25:00 | 000,000,034 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.log
[2011.01.22 20:24:57 | 000,047,360 | ---- | M] (VSO Software) -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.sys
[2010.09.22 12:15:21 | 000,022,328 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\PnkBstrK.sys
[2011.08.14 21:17:14 | 000,002,785 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Rim.Desktop.Exception.log
[2011.07.14 17:48:33 | 000,001,105 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Rim.Desktop.HttpServerSetup.log
[2011.08.14 21:17:14 | 000,001,848 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Rim.DesktopHelper.Exception.log
[2011.10.29 18:45:48 | 000,000,671 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\vso_ts_preview.xml

< %APPDATA%\*.exe /s >
[2011.01.22 20:24:57 | 000,087,608 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\inst.exe
[2011.07.14 18:02:28 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- E:\Documents and Settings\Paul\Data aplikací\Microsoft\Installer\{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}\ARPPRODUCTICON.exe
[2011.08.03 18:00:21 | 000,001,078 | R--- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Microsoft\Installer\{6F1AE16C-769D-4574-A813-F2ABB27FD6E1}\device.exe
[2011.08.03 18:00:21 | 000,000,766 | R--- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Microsoft\Installer\{6F1AE16C-769D-4574-A813-F2ABB27FD6E1}\ess.exe
[2011.08.03 18:00:21 | 000,001,078 | R--- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Microsoft\Installer\{6F1AE16C-769D-4574-A813-F2ABB27FD6E1}\mds.exe
[2011.08.03 18:00:21 | 000,001,078 | R--- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Microsoft\Installer\{6F1AE16C-769D-4574-A813-F2ABB27FD6E1}\sdk.exe

< %SYSTEMDRIVE%\*.exe >
[2011.11.02 19:25:12 | 000,396,288 | ---- | M] (Trend Micro Inc.) -- E:\hijackthis.exe
[2011.10.29 17:41:32 | 011,355,704 | ---- | M] (Opera Software ASA) -- E:\Opera_1152_int_Setup.exe

< >

< >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-27 15:32:59

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS /s >
"StateIndex" = 0

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0E:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart\0\0

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER

< >

< type c:\boot.ini >> test.txt /c >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2011.11.20 22:24:40 | 000,000,512 | ---- | M] () MD5=7D06030DED6A6D4612137AE02DF8E565 -- E:\PhysicalMBR.bin

========== Alternate Data Streams ==========

@Alternate Data Stream - 147 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:D287FACF
@Alternate Data Stream - 139 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:157E1AD3
@Alternate Data Stream - 137 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4

< End of report >

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Nějaká infekce, prosím o kontrolu.

#18 Příspěvek od motji »

:arrow: Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
@Alternate Data Stream - 147 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:D287FACF
@Alternate Data Stream - 139 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:157E1AD3
@Alternate Data Stream - 137 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4

:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
E:\WINDOWS\system32\CF11002.exe
E:\WINDOWS\system32\CF3455.exe

:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]
[clearallrestorepoints]
[Reboot]

-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rokony
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 02 Lis 2011 18:09

Re: Nějaká infekce, prosím o kontrolu.

#19 Příspěvek od rokony »

Včera jsem byl v práci do večera, proto dávám log až dneska.

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
ADS E:\Documents and Settings\All Users\Data aplikací\TEMP:D287FACF deleted successfully.
ADS E:\Documents and Settings\All Users\Data aplikací\TEMP:157E1AD3 deleted successfully.
ADS E:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
E:\WINDOWS\system32\CF11002.exe moved successfully.
E:\WINDOWS\system32\CF3455.exe moved successfully.
========== COMMANDS ==========
E:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Paul
->Temp folder emptied: 1574275 bytes
->Temporary Internet Files folder emptied: 200899 bytes
->Java cache emptied: 18617 bytes
->Opera cache emptied: 27580327 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2941556 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 406057 bytes
RecycleBin emptied: 2157928 bytes

Total Files Cleaned = 33,00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: Paul
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb

Restore points cleared and new OTL Restore Point set!

OTL by OldTimer - Version 3.2.31.0 log created on 11222011_161630

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Nějaká infekce, prosím o kontrolu.

#20 Příspěvek od motji »

Jak to vypadá s počítačem?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rokony
Návštěvník
Návštěvník
Příspěvky: 67
Registrován: 02 Lis 2011 18:09

Re: Nějaká infekce, prosím o kontrolu.

#21 Příspěvek od rokony »

Zatím vše v pořádku, dneska se ten trojan neobjevil, tak je to snad už pryč.
Děkuji za Vaši pomoc!
Mohl bych zde dát ještě log s tátového počítače? Nebo mám založit raději jiné téma?
Velmi dlouho mu Xp startují, po přihlášení do systému se tak 3 minuty nedá pracovat.

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Nějaká infekce, prosím o kontrolu.

#22 Příspěvek od motji »

:arrow: Ještě znovu spustte OTL, klikněte na tlačítko vyčisti, uklidí po sobě :)


Založte topic s názvem pro Motji, ale mrknu na to asi až zítra :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět