Odolná havěť v systému s mnoha projevy - prosím o kontrolu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
W.Mia
Návštěvník
Návštěvník
Příspěvky: 42
Registrován: 24 Lis 2011 08:29

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#31 Příspěvek od W.Mia »

Provedeno, posílám logy. Je to na víc částí:

OTL.Txt 1/3

OTL logfile created on: 2.12.2011 19:41:04 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Mike\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,75 Gb Total Physical Memory | 1,73 Gb Available Physical Memory | 62,75% Memory free
8,10 Gb Paging File | 7,02 Gb Available in Paging File | 86,70% Paging File free
Paging file location(s): C:\pagefile.sys 0 0D:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 113,76 Gb Total Space | 41,27 Gb Free Space | 36,28% Space Free | Partition Type: NTFS
Drive D: | 114,22 Gb Total Space | 32,45 Gb Free Space | 28,41% Space Free | Partition Type: FAT32

Computer Name: ACER-64B9BF4930 | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011.12.02 18:57:11 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mike\Plocha\OTL.exe
PRC - [2011.11.23 11:27:04 | 001,052,472 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
PRC - [2011.11.20 15:37:34 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2011.11.16 12:09:18 | 002,996,784 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe
PRC - [2011.11.09 09:30:43 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011.10.20 12:58:42 | 002,497,352 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2011.10.08 05:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011.10.07 18:47:14 | 001,883,328 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2011.06.24 07:54:46 | 000,020,880 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2011.06.18 17:29:21 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\real\realplayer\Update\realsched.exe
PRC - [2011.03.11 15:17:30 | 000,093,360 | ---- | M] (OLYMPUS IMAGING CORP.) -- C:\Program Files\OLYMPUS\ib\olycamdetect.exe
PRC - [2011.02.21 22:17:32 | 000,066,560 | ---- | M] (Nalpeiron Ltd.) -- C:\WINDOWS\system32\nlssrv32.exe
PRC - [2010.12.08 20:17:46 | 001,226,608 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.10.25 10:03:52 | 000,217,088 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2010.01.15 15:51:04 | 000,025,600 | ---- | M] (pdfconverter.com) -- C:\Program Files\pdfconverter.com\FreePDF Creator\itFPCPrnDisp.exe
PRC - [2009.05.29 15:58:46 | 000,479,232 | ---- | M] (Nikon Corporation) -- C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
PRC - [2009.03.05 15:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008.04.14 07:52:24 | 001,541,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.06.05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
PRC - [2006.08.11 16:14:28 | 000,110,592 | ---- | M] (Acer Inc.) -- C:\Program Files\Acer\Acer eMode Management\AspireService.exe
PRC - [2006.07.26 21:43:16 | 000,114,784 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
PRC - [2006.07.26 21:43:14 | 000,266,338 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
PRC - [2006.07.26 21:42:56 | 000,143,360 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerCinema\PCMService.exe
PRC - [2006.07.26 21:42:46 | 001,073,152 | ---- | M] (Cyberlink) -- C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
PRC - [2005.11.16 19:25:14 | 000,745,472 | ---- | M] (X-Micro Technology Corp.) -- C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe


========== Modules (No Company Name) ==========

MOD - [2011.11.27 09:35:16 | 000,055,816 | ---- | M] () -- C:\Documents and Settings\Mike\Local Settings\temp\b01d42a6-0948-4bd0-8dea-54d68f50a791\CliSecureRT.dll
MOD - [2011.11.20 15:40:05 | 014,410,024 | ---- | M] () -- C:\Program Files\Steam\bin\libcef.dll
MOD - [2011.11.20 15:40:02 | 000,914,216 | ---- | M] () -- C:\Program Files\Steam\bin\avcodec-52.dll
MOD - [2011.11.20 15:40:02 | 000,194,344 | ---- | M] () -- C:\Program Files\Steam\bin\chromehtml.dll
MOD - [2011.11.20 15:40:02 | 000,155,432 | ---- | M] () -- C:\Program Files\Steam\bin\avformat-52.dll
MOD - [2011.11.20 15:40:02 | 000,091,432 | ---- | M] () -- C:\Program Files\Steam\bin\avutil-50.dll
MOD - [2011.11.09 09:30:41 | 001,989,592 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011.10.12 12:27:04 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\4013a4d303761138606a952901b0f590\System.Management.ni.dll
MOD - [2011.10.12 12:23:22 | 000,770,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\59418ce1082157fbf6dbbbe85fa8d78e\System.Runtime.Remoting.ni.dll
MOD - [2011.10.12 12:22:17 | 001,781,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\0e06eb1acf979d6dfd95c9ebcf5550bb\System.Xaml.ni.dll
MOD - [2011.10.12 12:04:45 | 000,284,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\5ad95fffd68c6c29ead74009f3d89ec0\PresentationFramework.Classic.ni.dll
MOD - [2011.10.12 12:04:11 | 017,673,728 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\1418a81b6da08d4735b83a60f7525c8b\PresentationFramework.ni.dll
MOD - [2011.10.12 12:03:32 | 013,137,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\52e237bd9dcf62782e477d3caf451210\System.Windows.Forms.ni.dll
MOD - [2011.10.12 12:03:07 | 001,652,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\9f3d6ed58636f00b008eb84c2fecfffe\System.Drawing.ni.dll
MOD - [2011.10.12 12:02:50 | 011,106,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\fb7a70d4f5b2df437d456ec82d658fea\PresentationCore.ni.dll
MOD - [2011.10.12 12:02:28 | 003,798,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\81046d70594f88758b8b9b698d510fa8\WindowsBase.ni.dll
MOD - [2011.10.12 12:01:51 | 007,053,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\d3dab9ff9af3acc625d79329fc143357\System.Core.ni.dll
MOD - [2011.10.12 12:01:33 | 009,085,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\e3914597ed0a6c9bc82824f874ca21be\System.ni.dll
MOD - [2011.10.12 12:01:12 | 014,409,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\e5de681ee33ae6535462d070428f4f1b\mscorlib.ni.dll
MOD - [2011.10.08 22:48:56 | 008,522,400 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011.10.07 18:46:30 | 000,068,424 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav
MOD - [2011.06.24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.06.24 07:54:46 | 000,020,880 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
MOD - [2010.12.08 20:18:26 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2010.12.08 20:17:46 | 001,226,608 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2008.04.14 07:51:48 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2007.06.05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
MOD - [2006.07.26 21:43:24 | 000,065,634 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSchMgr.dll
MOD - [2006.07.26 21:43:24 | 000,024,576 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSchedps.dll
MOD - [2006.07.26 21:43:22 | 000,225,384 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapEngine.dll
MOD - [2006.07.26 21:43:22 | 000,032,768 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvcps.dll
MOD - [2006.07.26 21:43:16 | 000,114,784 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
MOD - [2006.07.26 21:43:14 | 000,266,338 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
MOD - [2005.11.01 16:36:28 | 000,045,056 | ---- | M] () -- C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.dll
MOD - [2005.09.21 20:39:52 | 000,212,992 | ---- | M] () -- C:\Program Files\Acer WLAN 11g USB Dongle\dot1x_dll.dll
MOD - [2004.03.05 14:00:58 | 000,155,648 | ---- | M] () -- C:\Program Files\Acer WLAN 11g USB Dongle\ssleay32.dll
MOD - [2004.03.05 14:00:26 | 000,827,392 | ---- | M] () -- C:\Program Files\Acer WLAN 11g USB Dongle\libeay32.dll
MOD - [2001.10.28 17:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (SwitchBoard)
SRV - File not found [On_Demand | Stopped] -- -- (ServiceLayer)
SRV - File not found [Auto | Stopped] -- -- (PCSpeedUpService)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - File not found [Auto | Stopped] -- -- (Application Updater)
SRV - [2011.11.23 11:27:04 | 001,052,472 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe -- (CLPSLS)
SRV - [2011.11.16 12:09:18 | 002,996,784 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe -- (a2AntiMalware)
SRV - [2011.10.08 05:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011.10.07 18:47:14 | 001,883,328 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011.04.24 21:55:00 | 004,066,168 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2011.03.16 10:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.02.21 22:17:32 | 000,066,560 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\WINDOWS\system32\nlssrv32.exe -- (nlsX86cc)
SRV - [2010.10.25 10:03:52 | 000,217,088 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010.02.17 15:34:07 | 000,015,872 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\OpenVPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2008.11.06 12:37:22 | 000,093,848 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite (Eval) 2012\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2007.06.05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing)
SRV - [2006.11.03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2006.07.26 21:43:16 | 000,114,784 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe -- (CLSched) CyberLink Task Scheduler (CTS)
SRV - [2006.07.26 21:43:14 | 000,266,338 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe -- (CLCapSvc) CyberLink Background Capture Service (CBCS)
SRV - [2006.07.26 21:42:46 | 001,073,152 | ---- | M] (Cyberlink) [Auto | Running] -- C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe -- (CyberLink Media Library Service)
SRV - [2004.09.29 12:14:36 | 000,069,632 | ---- | M] (HP) [Auto | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - [2011.10.07 18:48:04 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\Windows\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2011.10.07 18:48:02 | 000,492,768 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2011.10.07 18:48:02 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2011.05.19 13:10:34 | 000,017,904 | ---- | M] (Emsi Software GmbH) [Kernel | System | Running] -- C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys -- (A2DDA)
DRV - [2011.01.29 17:00:20 | 000,020,032 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - [2010.10.25 10:03:52 | 000,036,640 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010.02.17 15:34:07 | 000,025,216 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tap0901.sys -- (tap0901)
DRV - [2009.08.07 22:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite (Eval) 2012\WNt500x86\sandra.sys -- (SANDRA)
DRV - [2009.07.07 11:34:13 | 000,278,984 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2009.02.24 17:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2008.10.09 14:42:42 | 000,017,408 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KMWDFILTER.sys -- (KMWDFILTER)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.05.16 11:33:14 | 000,115,752 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016unic.sys -- (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM)
DRV - [2008.05.16 11:33:14 | 000,025,512 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016nd5.sys -- (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS)
DRV - [2008.05.16 11:33:14 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016mdfl.sys -- (s0016mdfl)
DRV - [2008.05.16 11:33:12 | 000,120,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016mdm.sys -- (s0016mdm)
DRV - [2008.05.16 11:33:12 | 000,114,216 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016mgmt.sys -- (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM)
DRV - [2008.05.16 11:33:12 | 000,110,632 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016obex.sys -- (s0016obex)
DRV - [2008.05.16 11:33:12 | 000,089,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016bus.sys -- (s0016bus) Sony Ericsson Device 0016 driver (WDM)
DRV - [2008.03.11 16:38:43 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2008.03.11 00:51:36 | 000,162,432 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ithsgt.sys -- (ithsgt)
DRV - [2008.03.11 00:51:36 | 000,012,032 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lilsgt.sys -- (lilsgt)
DRV - [2008.03.10 13:16:54 | 000,715,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2007.11.14 21:50:04 | 000,025,544 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2006.06.29 09:53:00 | 000,244,864 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2006.06.28 18:38:56 | 000,105,088 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\nvatabus.sys -- (nvatabus)
DRV - [2006.06.28 16:38:56 | 000,105,088 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2006.06.18 22:59:28 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006.06.05 21:09:26 | 004,284,928 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005.10.28 10:38:18 | 000,402,432 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZD1211BU.sys -- (ZD1211BU(ZyDAS)) ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS)
DRV - [2005.10.04 14:38:24 | 000,280,064 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZD1211U.sys -- (ZD1211U(ZyDAS)) ZyDAS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyDAS)
DRV - [2005.07.08 14:44:18 | 000,159,616 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vax347b.sys -- (vax347b)
DRV - [2005.02.23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2005.02.09 10:59:00 | 000,014,165 | ---- | M] (Pinnacle Systems GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Pclepci.sys -- (PCLEPCI)
DRV - [2005.01.01 10:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\npptNT2.sys -- (NPPTNT2)
DRV - [2004.10.25 12:40:58 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZDPSp50.sys -- (ZDPSp50)
DRV - [2004.09.29 21:36:29 | 000,015,360 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NetMotCM.sys -- (ndiscm)
DRV - [2004.04.30 09:33:00 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\vax347s.sys -- (vax347s)
DRV - [2003.12.29 18:27:04 | 000,008,576 | ---- | M] (Waytech Development, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\UsbFltr.sys -- (UsbFltr)
DRV - [2002.07.11 12:00:44 | 000,012,856 | ---- | M] (WayTech Development, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\kbfilter.sys -- (kbfilter)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local;<local>

IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com
IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledItems: {cbafdacb-a320-4294-9516-494f93d5d1b3}:1.0.6
FF - prefs.js..extensions.enabledItems: googletube@googletube.com:2.0.2
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: cs@dictionaries.addons.mozilla.org:1.0.2
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: exif_viewer@mozilla.doslash.org:1.60
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: buckts@buckts.com:0.18
FF - prefs.js..extensions.enabledItems: {261a7cc7-4cbe-4741-bd5f-1ebdd0c63f7b}:0.2.2
FF - prefs.js..extensions.enabledItems: en-GB@dictionaries.addons.mozilla.org:1.19.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://search.centrum.cz/index.php?tool ... m-1.0.0&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Centrum.cz Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "http://cs.www.mozilla.com/cs/"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\Mike\Data aplikací\Facebook\npfbplugin_1_0_1.dll File not found
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Mike\Data aplikací\Facebook\npfbplugin_1_0_3.dll File not found
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Mike\Data aplikací\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Mike\Data aplikací\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Update\1.2.183.39\npGoogleOneClick8.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.06.18 17:29:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.18 20:38:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.18 20:38:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2010.05.11 15:55:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Extensions
[2011.11.25 22:34:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions
[2011.11.25 22:34:22 | 000,000,000 | ---D | M] (Flagfox) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011.11.08 02:32:09 | 000,000,000 | ---D | M] (Digsby) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\{cbafdacb-a320-4294-9516-494f93d5d1b3}
[2011.03.02 23:32:46 | 000,000,000 | ---D | M] (ÄŚeskĂ© slovnĂ­ky pro kontrolu pravopisu) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\cs@dictionaries.addons.mozilla.org
[2011.02.28 12:07:09 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\en-GB@dictionaries.addons.mozilla.org
[2010.05.20 21:52:05 | 000,000,000 | ---D | M] (GoogleTube) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\googletube@googletube.com
[2011.05.06 21:47:19 | 000,000,000 | ---D | M] (Media Plugin) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\plugin3@gameplaylabs.com
[2011.04.16 13:58:58 | 000,002,247 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\searchplugins\slovnk-encz.xml
[2010.10.01 08:00:48 | 000,001,330 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\searchplugins\wikipedia-en.xml
[2011.11.09 09:31:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.10.23 08:09:04 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\{1018E4D6-728F-4B20-AD56-37578A4DE76B}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\{CBAFDACB-A320-4294-9516-494F93D5D1B3}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\CS@DICTIONARIES.ADDONS.MOZILLA.ORG
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\EN-GB@DICTIONARIES.ADDONS.MOZILLA.ORG
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\EXIF_VIEWER@MOZILLA.DOSLASH.ORG.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\PLUGIN3@GAMEPLAYLABS.COM
[2010.10.25 18:20:06 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011.11.09 09:30:43 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2005.04.27 21:10:49 | 000,102,400 | ---- | M] (RealNetworks) -- C:\Program Files\mozilla firefox\plugins\npracplug.dll
[2010.12.09 11:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2011.09.29 02:30:58 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2011.09.29 02:30:58 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2011.09.29 02:30:58 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011.09.29 02:30:58 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.09.29 02:30:58 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Mike\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Data aplikac\u00ED\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Data aplikac\u00ED\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Mike\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Mike\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Mike\Data aplikac\u00ED\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Mike\Data aplikac\u00ED\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: RealArcade Mozilla Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\Mike\Data aplikac\u00ED\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Mike\Local Settings\Data aplikac\u00ED\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: DivX OVS Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.4_0\
CHR - Extension: Yontoo Layers = C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.1_0\
CHR - Extension: Evolved Online hry = C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nkdaebmimnhlmgpjoppmdeokffoahpan\3.0.3_0\

O1 HOSTS File: ([2011.11.27 09:33:12 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {055FD26D-3A88-4e15-963D-DC8493744B1D} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O2 - BHO: (no name) - {998A3C0C-8914-4D2A-AE36-BFA2E5AE6D5D} - No CLSID value found.
O2 - BHO: (no name) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No CLSID value found.
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTo2.dll (Conduit Ltd.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" File not found
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe (Acer Inc.)
O4 - HKLM..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe (COMODO)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe (COMODO)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe File not found
O4 - HKLM..\Run: [Free PDF Print Dispatcher] C:\Program Files\pdfconverter.com\FreePDF Creator\itFPCPrnDisp.exe (pdfconverter.com)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\Windows\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files\Olympus\ib\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [MSPY2002] C:\Windows\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
O4 - HKLM..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [Olympus ib] C:\Program Files\Olympus\ib\olycamdetect.exe (OLYMPUS IMAGING CORP.)
O4 - HKLM..\Run: [PC-Checkup] "C:\Program Files\Speeditup Free\PCCheckUp\PCCheckUp.exe" -mini File not found
O4 - HKLM..\Run: [PCMService] C:\Program Files\CyberLink\PowerCinema\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\Windows\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\Windows\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SMail] "C:\Program Files\Seznam\Postak\Postak.exe" File not found
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe File not found
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe (X-Micro Technology Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/200 ... oader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDow ... ab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {3190CE28-0B6E-4133-A7D3-87D29CB92120} http://software.seznam.cz/listicka/toolbar.cab (ToolbarInetInstall Control)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/v ... .2.4.8.cab (DLM Control)
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab (ImageShack Toolbar)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/200 ... ader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} http://service.futuremark.com/gom/receiver/tc/FMSI.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{83720A68-9FD4-4E19-B389-7845301CA38B}: DhcpNameServer = 81.27.192.33 81.27.192.97 89.102.0.238
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D96309E3-C34D-47E5-A426-1F7ABBF87FF8}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D96309E3-C34D-47E5-A426-1F7ABBF87FF8}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - File not found
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {097F10A7-487F-4457-AB1F-827C59479A72} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\Windows\System32\alf2cd.acm (NCT Company)
Drivers32: Msacm.dvacm - C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.mpegacm - mpegacm.acm File not found
Drivers32: msacm.scg726 - C:\Windows\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\Windows\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\Windows\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.ulmp3acm - ulmp3acm.acm File not found
Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
Drivers32: VIDC.ACDV - ACDV.dll File not found
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\Windows\System32\mcdvd_32.dll (MainConcept)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\Windows\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\Windows\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP40 - vp4vfw.dll File not found
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (EA.com/On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (EA.com/On2.com)
Drivers32: vidc.VP62 - C:\Windows\System32\vp6vfw.dll (EA.com/On2.com)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: wave1 - C:\Windows\System32\serwvdrv.dll (Microsoft Corporation)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2011.12.02 18:57:08 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mike\Plocha\OTL.exe
[2011.12.01 21:17:14 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011.11.30 03:03:51 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Mike\Recent
[2011.11.30 02:56:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Nabídka Start\Programy\CCleaner
[2011.11.30 02:56:34 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.11.30 02:55:58 | 001,187,896 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Mike\Plocha\ccleaner.exe
[2011.11.30 02:49:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\CPA_VA
[2011.11.30 02:41:52 | 000,155,536 | ---- | C] (Protection Technology (StarForce)) -- C:\Documents and Settings\Mike\Plocha\sfdrvrem.exe
[2011.11.29 20:50:49 | 063,338,168 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Mike\Plocha\PowerPointViewer.exe
[2011.11.28 23:40:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Dokumenty\My Digital Editions
[2011.11.27 10:25:32 | 000,000,000 | -H-D | C] -- C:\VritualRoot
[2011.11.27 10:24:21 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011.11.27 10:18:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\COMODO
[2011.11.27 10:16:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Comodo
[2011.11.27 10:16:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\COMODO
[2011.11.27 10:16:02 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2011.11.27 10:14:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
[2011.11.27 10:12:59 | 061,667,536 | ---- | C] (COMODO) -- C:\Documents and Settings\Mike\Plocha\cav_installer.exe
[2011.11.27 09:31:50 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011.11.26 21:08:04 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab
[2011.11.26 00:21:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\blabla
[2011.11.24 15:43:54 | 000,222,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2011.11.24 15:41:45 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Defender
[2011.11.24 15:20:50 | 000,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
[2011.11.24 15:10:54 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011.11.24 15:09:12 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011.11.24 15:09:12 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011.11.24 15:09:12 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011.11.24 15:09:12 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011.11.24 15:09:04 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.11.24 15:09:01 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.11.24 15:04:08 | 004,324,789 | R--- | C] (Swearware) -- C:\Documents and Settings\Mike\Plocha\ComboFix.exe
[2011.11.24 14:22:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\RK_Quarantine
[2011.11.24 14:12:37 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2011.11.24 14:09:27 | 001,566,512 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Mike\Plocha\tdsskiller.exe
[2011.11.24 12:07:29 | 000,000,000 | -H-D | C] -- C:\Windows\ie8
[2011.11.24 10:46:06 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NIS
[2011.11.24 10:46:06 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NIS\1301000.01C
[2011.11.24 10:10:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\NPE
[2011.11.24 08:21:38 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.11.24 08:21:38 | 000,000,000 | ---D | C] -- C:\rsit
[2011.11.23 22:37:44 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NAV
[2011.11.23 22:37:44 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NAV\1301000.01C
[2011.11.23 15:27:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\PCSettings
[2011.11.23 14:41:07 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2011.11.23 12:33:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Data aplikací\EurekaLog
[2011.11.23 07:42:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\EmsisoftEmergencyKit
[2011.11.23 03:05:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Data aplikací\Uniblue
[2011.11.23 03:05:51 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2011.11.23 03:05:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\PackageAware
[2011.11.23 02:40:26 | 000,000,000 | ---D | C] -- C:\RRTVAULT
[2011.11.23 02:35:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Emsisoft Anti-Malware
[2011.11.23 02:35:35 | 000,000,000 | ---D | C] -- C:\Program Files\Emsisoft Anti-Malware
[2011.11.23 02:35:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Dokumenty\Anti-Malware
[2011.11.21 21:19:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Data aplikací\Malwarebytes
[2011.11.21 21:19:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.11.21 21:07:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Data aplikací\QuickScan
[2011.11.20 22:29:37 | 000,000,000 | ---D | C] -- C:\WeruFoto
[2011.11.20 22:19:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Media Get LLC
[2011.11.20 15:37:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam
[2011.11.20 15:37:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabdka Start
[2011.11.20 15:37:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Steam
[2011.11.20 15:37:01 | 000,000,000 | ---D | C] -- C:\Program Files\Steam
[2011.11.20 11:43:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Data aplikací\NVIDIA
[2011.11.20 11:07:25 | 000,602,432 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\easyupdatusapiu.dll
[2011.11.20 11:05:55 | 000,877,376 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvgenco32.dll
[2011.11.20 11:05:54 | 000,919,872 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco32.dll
[2011.11.20 11:01:20 | 089,643,496 | ---- | C] (NVIDIA Corporation) -- C:\Documents and Settings\Mike\Plocha\285.58-desktop-winxp-32bit-english-whql.exe
[2011.11.20 10:54:32 | 000,000,000 | ---D | C] -- C:\ATI
[2011.11.19 11:30:09 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll
[2011.11.19 11:30:09 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll
[2011.11.19 11:30:08 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll
[2011.11.19 11:30:07 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll
[2011.11.19 11:30:07 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll
[2011.11.19 11:30:06 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll
[2011.11.19 11:30:06 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll
[2011.11.19 11:30:05 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll
[2011.11.18 20:37:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\QuickTime
[2011.11.18 20:37:19 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011.11.18 20:30:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\iTunes
[2011.11.18 20:28:56 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.11.18 20:28:49 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011.11.18 09:40:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\FreeRapid-0.86u1
[2011.11.14 22:02:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\Výstava TOP 10
[2011.11.14 21:13:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\FOTO výstava
[2011.11.12 23:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\bbtcz-s05e09_v1
[2011.11.10 16:45:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\PACK
[2011.11.06 16:46:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\bbtcz-s05e08_v1
[2011.11.02 22:37:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\SUPERSetup
[2010.09.27 16:24:50 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[2008.06.16 01:39:45 | 000,032,768 | ---- | C] ( ) -- C:\Windows\System32\Interop.ShockwaveFlashObjects.dll
[2008.02.10 21:52:34 | 000,159,616 | ---- | C] ( ) -- C:\Windows\System32\drivers\vax347b.sys
[2008.02.10 21:52:34 | 000,005,248 | ---- | C] ( ) -- C:\Windows\System32\drivers\vax347s.sys
[2007.05.11 08:57:21 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Mike\Data aplikací\pcouffin.sys
[2007.01.08 19:54:55 | 000,016,384 | ---- | C] ( ) -- C:\Windows\System32\ClearEvent.exe
[2007.01.08 19:53:15 | 000,049,152 | ---- | C] ( ) -- C:\Windows\System32\SysMonitor.exe
[4 C:\Documents and Settings\All Users\Data aplikací\*.tmp files -> C:\Documents and Settings\All Users\Data aplikací\*.tmp -> ]
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

W.Mia
Návštěvník
Návštěvník
Příspěvky: 42
Registrován: 24 Lis 2011 08:29

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#32 Příspěvek od W.Mia »

OTL.Txt 2/3

========== Files - Modified Within 30 Days ==========

[2011.12.02 19:45:17 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011.12.02 19:41:18 | 000,000,284 | ---- | M] () -- C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-1509661768-2596670817-2537616161-1006.job
[2011.12.02 19:41:17 | 000,000,276 | ---- | M] () -- C:\Windows\tasks\RealUpgradeLogonTaskS-1-5-21-1509661768-2596670817-2537616161-1006.job
[2011.12.02 19:39:05 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.12.02 18:57:11 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mike\Plocha\OTL.exe
[2011.12.02 13:39:00 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.12.01 21:35:29 | 000,177,871 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\CF02.jpg
[2011.12.01 21:34:43 | 000,473,227 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\CF01.jpg
[2011.12.01 21:29:05 | 000,000,442 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2011.12.01 21:27:38 | 000,000,294 | ---- | M] () -- C:\Windows\tasks\RealUpgradeLogonTaskS-1-5-21-1509661768-2596670817-2537616161-500.job
[2011.12.01 21:27:27 | 000,002,048 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.01 21:27:21 | 2952,318,976 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.01 21:16:11 | 004,324,789 | R--- | M] (Swearware) -- C:\Documents and Settings\Mike\Plocha\ComboFix.exe
[2011.12.01 21:15:17 | 001,474,832 | ---- | M] () -- C:\Windows\System32\drivers\sfi.dat
[2011.11.30 03:02:49 | 104,118,768 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\setup_11.0.0.1245.x01_2011_11_30_04_06.exe
[2011.11.30 02:56:35 | 000,000,686 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\CCleaner.lnk
[2011.11.30 02:56:00 | 001,187,896 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Mike\Plocha\ccleaner.exe
[2011.11.30 02:46:22 | 003,783,864 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.11.30 02:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\AdobeAAMUpdater-1.0-ACER-64B9BF4930-Mike.job
[2011.11.29 21:10:49 | 063,338,168 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Mike\Plocha\PowerPointViewer.exe
[2011.11.29 20:29:09 | 000,177,602 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\scsi-raid.jpg
[2011.11.28 23:39:48 | 000,001,823 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Adobe Digital Editions.lnk
[2011.11.27 23:21:05 | 000,241,664 | ---- | M] () -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.11.27 22:34:41 | 000,108,057 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Comodo-2011-11-27.jpg
[2011.11.27 10:16:17 | 000,001,653 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\COMODO Internet Security.lnk
[2011.11.27 10:13:03 | 061,667,536 | ---- | M] (COMODO) -- C:\Documents and Settings\Mike\Plocha\cav_installer.exe
[2011.11.27 09:51:18 | 000,001,158 | ---- | M] () -- C:\Windows\System32\wpa.dbl
[2011.11.27 09:33:12 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011.11.25 22:31:19 | 000,002,504 | ---- | M] () -- C:\Windows\System32\CONFIG.NT
[2011.11.25 22:01:11 | 061,657,056 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\setup_av_free.exe
[2011.11.24 15:20:59 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-1509661768-2596670817-2537616161-500.job
[2011.11.24 15:11:00 | 000,001,067 | RHS- | M] () -- C:\BOOT.INI
[2011.11.24 14:56:55 | 000,218,081 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\310950_292433550789279_183813598317942_966443_201572440_n.jpg
[2011.11.24 14:21:50 | 000,766,976 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\RogueKiller.exe
[2011.11.24 14:09:28 | 001,566,512 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Mike\Plocha\tdsskiller.exe
[2011.11.24 11:24:46 | 000,663,017 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1301000.01C\Cat.DB
[2011.11.23 22:44:57 | 000,663,017 | ---- | M] () -- C:\Windows\System32\drivers\NAV\1301000.01C\Cat.DB
[2011.11.23 12:28:09 | 000,279,097 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Emsisoft_resume.jpg
[2011.11.23 12:24:41 | 000,155,355 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Emsisoft_upozorneni.jpg
[2011.11.23 09:10:17 | 000,195,258 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\emisoft-malware.jpg
[2011.11.23 07:02:41 | 000,000,950 | ---- | M] () -- C:\Boot.bak
[2011.11.23 03:11:33 | 000,575,040 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.11.23 03:11:33 | 000,570,302 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2011.11.23 03:11:33 | 000,132,326 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2011.11.23 03:11:33 | 000,117,220 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.11.23 02:40:26 | 000,004,107 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\ihfeumzb.qzk
[2011.11.23 02:35:55 | 000,000,770 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Emsisoft Anti-Malware.lnk
[2011.11.21 17:23:38 | 000,000,215 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Might and Magic Clash of Heroes.url
[2011.11.21 17:05:24 | 000,001,324 | ---- | M] () -- C:\Windows\System32\d3d9caps.dat
[2011.11.21 09:53:23 | 029,431,948 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Applied_Multivariate_Statistics_for_the_Social_Sciences__Fifth_Edition.pdf
[2011.11.21 09:41:30 | 002,566,722 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advanced_Quantative_Data_Analysis__Understanding_Socialresearch_.pdf
[2011.11.20 17:28:54 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdw.DAT
[2011.11.20 15:37:04 | 000,000,668 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Steam.lnk
[2011.11.20 11:07:17 | 000,285,176 | ---- | M] () -- C:\Windows\System32\nvdrsdb0.bin
[2011.11.20 11:07:17 | 000,000,001 | ---- | M] () -- C:\Windows\System32\nvdrssel.bin
[2011.11.20 11:07:13 | 000,285,176 | ---- | M] () -- C:\Windows\System32\nvdrsdb1.bin
[2011.11.20 11:07:13 | 000,000,000 | ---- | M] () -- C:\Windows\System32\nvdrswr.lk
[2011.11.20 11:04:19 | 089,643,496 | ---- | M] (NVIDIA Corporation) -- C:\Documents and Settings\Mike\Plocha\285.58-desktop-winxp-32bit-english-whql.exe
[2011.11.20 10:56:27 | 000,276,951 | ---- | M] () -- C:\Windows\System32\NvApps.xml
[2011.11.19 11:42:34 | 011,276,288 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\sandra.mda
[2011.11.19 11:28:55 | 000,001,049 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\SiSoftware Sandra Lite (Eval) 2012.lnk
[2011.11.18 23:44:04 | 000,026,120 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\The.Big.Bang.Theory.S05E10.The.Flaming.Spittoon.Acquisitoin.720p.WEB-DL.DD5.1.H.264-CtrlHD.srt
[2011.11.18 23:41:46 | 000,026,116 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\The.Big.Bang.Theory.S05E10.HDTV.XviD-ASAP.srt
[2011.11.18 20:30:29 | 000,001,546 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\iTunes.lnk
[2011.11.18 16:58:03 | 000,000,284 | ---- | M] () -- C:\Windows\tasks\AppleSoftwareUpdate.job
[2011.11.17 17:21:31 | 001,306,913 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__The_Foundations_of_Statistics__A_Simulation_based_Approach.pdf
[2011.11.17 17:21:04 | 006,388,481 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advances_in_Social_Science_Research_Using_R.pdf
[2011.11.17 17:20:59 | 007,783,134 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advances_in_Social_Science_Research_Using_R__Lecture_Notes_in_Statistics___Lecture_Notes_in_Statistics___Proceedings_.pdf
[2011.11.17 17:20:04 | 005,447,860 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__A_First_Course_in_Bayesian_Statistical_Methods__Springer_Texts_in_Statistics_.pdf
[2011.11.17 17:19:38 | 002,337,366 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Semiparametric_Regression_for_the_Social_Sciences.pdf
[2011.11.17 17:19:19 | 004,359,769 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Introduction_to_Applied_Bayesian_Statistics_and_Estimation_for_Social_Scientists__Statistics_for_Social_and_Behavioral_Sciences_.pdf
[2011.11.15 23:01:38 | 000,151,120 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Mia&DAx.JPG
[2011.11.15 09:23:32 | 000,000,116 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2011.11.14 12:21:00 | 002,538,109 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\DSC_0313.JPG
[2011.11.14 11:57:12 | 025,871,016 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\SilverEfexPro2-l-ver2.002all.exe
[2011.11.13 23:28:14 | 000,204,340 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\cats.jpg
[2011.11.13 23:27:48 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\padFB.jpg
[2011.11.13 23:27:14 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\pádFB.jpg
[2011.11.11 23:48:11 | 000,648,331 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\DSC_0313_SilverEf_2.jpg
[2011.11.10 18:33:21 | 000,004,714 | ---- | M] () -- C:\Windows\wincmd.ini
[2011.11.10 08:33:07 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLet.DAT
[2011.11.07 22:53:17 | 000,108,544 | -H-- | M] () -- C:\Documents and Settings\Mike\Plocha\photothumb.db
[2011.11.06 14:12:43 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdu.DAT
[2011.11.06 13:55:41 | 000,000,734 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Mozilla Firefox.lnk
[2011.11.04 16:58:28 | 000,000,434 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\popular.kml
[4 C:\Documents and Settings\All Users\Data aplikací\*.tmp files -> C:\Documents and Settings\All Users\Data aplikací\*.tmp -> ]
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.12.02 19:45:17 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2011.12.01 21:35:29 | 000,177,871 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\CF02.jpg
[2011.12.01 21:34:42 | 000,473,227 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\CF01.jpg
[2011.11.30 02:57:09 | 104,118,768 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\setup_11.0.0.1245.x01_2011_11_30_04_06.exe
[2011.11.30 02:56:35 | 000,000,686 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\CCleaner.lnk
[2011.11.29 21:16:23 | 000,001,946 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Microsoft PowerPoint Viewer .lnk
[2011.11.29 20:29:09 | 000,177,602 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\scsi-raid.jpg
[2011.11.28 23:39:48 | 000,001,823 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Adobe Digital Editions.lnk
[2011.11.27 22:34:41 | 000,108,057 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\Comodo-2011-11-27.jpg
[2011.11.27 10:17:52 | 001,474,832 | ---- | C] () -- C:\Windows\System32\drivers\sfi.dat
[2011.11.27 10:16:17 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\COMODO Internet Security.lnk
[2011.11.27 09:32:35 | 2952,318,976 | -HS- | C] () -- C:\hiberfil.sys
[2011.11.25 21:58:50 | 061,657,056 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\setup_av_free.exe
[2011.11.24 15:41:45 | 000,000,981 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Windows Defender.lnk
[2011.11.24 15:11:00 | 000,000,950 | ---- | C] () -- C:\Boot.bak
[2011.11.24 15:10:58 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2011.11.24 15:09:12 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011.11.24 15:09:12 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011.11.24 15:09:12 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.11.24 15:09:12 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.11.24 15:09:12 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.11.24 14:56:54 | 000,218,081 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\310950_292433550789279_183813598317942_966443_201572440_n.jpg
[2011.11.24 14:21:49 | 000,766,976 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\RogueKiller.exe
[2011.11.24 12:13:21 | 000,000,302 | ---- | C] () -- C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-1509661768-2596670817-2537616161-500.job
[2011.11.24 12:13:21 | 000,000,294 | ---- | C] () -- C:\Windows\tasks\RealUpgradeLogonTaskS-1-5-21-1509661768-2596670817-2537616161-500.job
[2011.11.24 11:24:27 | 000,663,017 | ---- | C] () -- C:\Windows\System32\drivers\NIS\1301000.01C\Cat.DB
[2011.11.23 23:52:17 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\Mike\Nabídka Start\Programy\Outlook Express.lnk
[2011.11.23 22:44:44 | 000,663,017 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1301000.01C\Cat.DB
[2011.11.23 12:28:09 | 000,279,097 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\Emsisoft_resume.jpg
[2011.11.23 12:24:41 | 000,155,355 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\Emsisoft_upozorneni.jpg
[2011.11.23 09:10:17 | 000,195,258 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\emisoft-malware.jpg
[2011.11.23 07:02:38 | 000,000,800 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer WLAN 11g USB Dongle.lnk
[2011.11.23 03:11:30 | 000,000,807 | ---- | C] () -- C:\Documents and Settings\Mike\Nabídka Start\Programy\Internet Explorer.lnk
[2011.11.23 02:40:26 | 000,004,107 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ihfeumzb.qzk
[2011.11.23 02:35:54 | 000,000,770 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Emsisoft Anti-Malware.lnk
[2011.11.21 17:23:36 | 000,000,215 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\Might and Magic Clash of Heroes.url
[2011.11.21 09:52:22 | 029,431,948 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Applied_Multivariate_Statistics_for_the_Social_Sciences__Fifth_Edition.pdf
[2011.11.21 09:41:27 | 002,566,722 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advanced_Quantative_Data_Analysis__Understanding_Socialresearch_.pdf
[2011.11.20 17:49:13 | 004,318,049 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0027_002.JPG
[2011.11.20 17:49:12 | 011,021,141 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0027_002.NEF
[2011.11.20 17:49:09 | 004,148,902 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0023_001.JPG
[2011.11.20 17:49:08 | 010,801,184 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0023_001.NEF
[2011.11.20 17:48:04 | 003,448,376 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0052.JPG
[2011.11.20 17:48:03 | 010,602,195 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0052.NEF
[2011.11.20 17:48:01 | 010,558,701 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0051.NEF
[2011.11.20 17:48:01 | 003,406,205 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0051.JPG
[2011.11.20 17:48:01 | 003,283,367 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0047.JPG
[2011.11.20 17:47:59 | 010,623,342 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0047.NEF
[2011.11.20 17:47:59 | 003,294,739 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0039.JPG
[2011.11.20 17:47:58 | 010,530,015 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0039.NEF
[2011.11.20 17:47:58 | 003,822,680 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0036.JPG
[2011.11.20 17:47:56 | 010,718,800 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0036.NEF
[2011.11.20 17:47:56 | 003,862,069 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0035.JPG
[2011.11.20 17:47:54 | 010,729,932 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0035.NEF
[2011.11.20 17:47:54 | 003,575,502 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0033.JPG
[2011.11.20 17:47:53 | 010,688,515 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0033.NEF
[2011.11.20 17:47:52 | 004,088,438 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0030.JPG
[2011.11.20 17:47:51 | 010,900,742 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0030.NEF
[2011.11.20 17:47:51 | 004,318,049 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0027.JPG
[2011.11.20 17:47:44 | 004,148,902 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0023.JPG
[2011.11.20 17:37:24 | 008,757,039 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0027.NEF
[2011.11.20 17:37:21 | 009,663,154 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0025.NEF
[2011.11.20 17:37:19 | 009,866,269 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0024.NEF
[2011.11.20 17:37:19 | 009,745,193 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0023.NEF
[2011.11.20 17:37:18 | 009,797,663 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0022.NEF
[2011.11.20 15:37:04 | 000,000,668 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Steam.lnk
[2011.11.20 11:07:13 | 000,285,176 | ---- | C] () -- C:\Windows\System32\nvdrsdb1.bin
[2011.11.20 11:07:13 | 000,285,176 | ---- | C] () -- C:\Windows\System32\nvdrsdb0.bin
[2011.11.20 11:07:13 | 000,000,001 | ---- | C] () -- C:\Windows\System32\nvdrssel.bin
[2011.11.20 11:07:13 | 000,000,000 | ---- | C] () -- C:\Windows\System32\nvdrswr.lk
[2011.11.20 11:05:55 | 000,003,250 | ---- | C] () -- C:\Windows\System32\nvinfo.pb
[2011.11.20 11:05:54 | 002,130,002 | ---- | C] () -- C:\Windows\System32\nvdata.data
[2011.11.19 21:01:37 | 000,026,120 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\The.Big.Bang.Theory.S05E10.The.Flaming.Spittoon.Acquisitoin.720p.WEB-DL.DD5.1.H.264-CtrlHD.srt
[2011.11.19 21:01:37 | 000,026,116 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\The.Big.Bang.Theory.S05E10.HDTV.XviD-ASAP.srt
[2011.11.19 11:28:55 | 000,001,049 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\SiSoftware Sandra Lite (Eval) 2012.lnk
[2011.11.18 20:30:29 | 000,001,546 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\iTunes.lnk
[2011.11.17 17:21:30 | 001,306,913 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__The_Foundations_of_Statistics__A_Simulation_based_Approach.pdf
[2011.11.17 17:21:03 | 006,388,481 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advances_in_Social_Science_Research_Using_R.pdf
[2011.11.17 17:20:59 | 007,783,134 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advances_in_Social_Science_Research_Using_R__Lecture_Notes_in_Statistics___Lecture_Notes_in_Statistics___Proceedings_.pdf
[2011.11.17 17:19:59 | 005,447,860 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__A_First_Course_in_Bayesian_Statistical_Methods__Springer_Texts_in_Statistics_.pdf
[2011.11.17 17:19:37 | 002,337,366 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Semiparametric_Regression_for_the_Social_Sciences.pdf
[2011.11.17 17:19:17 | 004,359,769 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Introduction_to_Applied_Bayesian_Statistics_and_Estimation_for_Social_Scientists__Statistics_for_Social_and_Behavioral_Sciences_.pdf
[2011.11.15 23:01:38 | 000,151,120 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\Mia&DAx.JPG
[2011.11.14 11:53:32 | 025,871,016 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\SilverEfexPro2-l-ver2.002all.exe
[2011.11.13 23:28:14 | 000,204,340 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\cats.jpg
[2011.11.13 23:27:48 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\padFB.jpg
[2011.11.13 23:27:14 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\pádFB.jpg
[2011.11.11 23:46:47 | 000,648,331 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0313_SilverEf_2.jpg
[2011.11.11 23:21:46 | 002,538,109 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0313.JPG
[2011.11.04 16:58:27 | 000,000,434 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\popular.kml
[2011.10.27 08:33:04 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Kernel Extension
[2011.10.27 08:33:04 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Iterate Items
[2011.10.27 08:31:21 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Keyboard Layouts
[2011.10.27 08:31:20 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Jingles
[2011.06.25 07:55:42 | 000,000,788 | RH-- | C] () -- C:\Windows\System32\ttri.dat
[2011.05.27 07:50:15 | 000,288,048 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2011.05.26 14:28:25 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Adobe Formát GIF CS5 – předvolby
[2011.05.25 11:59:56 | 001,896,234 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1509661768-2596670817-2537616161-1006-0.dat
[2011.05.21 23:58:53 | 000,478,898 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
[2011.05.15 08:22:30 | 000,138,264 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.05.15 08:22:30 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\PnkBstrK.sys
[2011.05.15 08:22:09 | 000,234,768 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.05.15 08:22:06 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011.05.02 10:46:03 | 000,004,096 | ---- | C] () -- C:\Windows\System32\HDREfexProFC64.dll
[2011.04.18 07:03:10 | 000,004,608 | ---- | C] () -- C:\Windows\System32\SilverEfexPro2FC64.dll
[2011.04.13 19:16:16 | 039,289,424 | -HS- | C] () -- C:\Windows\setupa.exe
[2011.03.29 23:17:10 | 000,316,928 | ---- | C] () -- C:\Windows\System32\HDREfexProFC32.dll
[2011.03.28 21:36:51 | 000,000,848 | ---- | C] () -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\SRDownloader.nast
[2011.03.11 10:27:20 | 000,000,754 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2011.02.21 22:17:34 | 000,003,584 | ---- | C] () -- C:\Windows\System32\SilverEfexPro2FC32.dll
[2011.01.29 17:00:24 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011.01.29 17:00:22 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011.01.29 17:00:22 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011.01.29 17:00:22 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011.01.29 17:00:22 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2010.12.12 00:45:16 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2010.12.12 00:45:16 | 000,036,640 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2010.12.11 22:38:36 | 000,139,264 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010.12.11 16:00:59 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\$_hpcst$.hpc
[2010.12.01 17:27:19 | 000,108,032 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010.11.06 18:08:31 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2010.10.04 06:39:45 | 000,000,000 | ---- | C] () -- C:\Windows\ViewNX2.INI
[2010.10.04 06:34:41 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Jazz
[2010.10.04 06:34:41 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Internet Services
[2010.10.04 06:34:41 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLev.DAT
[2010.10.04 06:34:41 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLet.DAT
[2010.10.04 06:34:41 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLes.DAT
[2010.10.03 18:02:21 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Rule Actions
[2010.10.03 18:02:21 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Reverb
[2010.10.03 18:02:21 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLck.DAT
[2010.10.03 18:02:21 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Alerts
[2010.10.03 18:02:19 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Sample Delay
[2010.10.03 18:02:19 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Ambient
[2010.10.03 14:28:15 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Hybrid Basic
[2010.10.03 14:09:15 | 000,057,344 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\chrtmp
[2010.10.03 13:42:45 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Robot
[2010.10.03 12:26:58 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLbx.DAT
[2010.06.19 19:30:20 | 000,000,000 | ---- | C] () -- C:\Windows\ViewNX.INI
[2010.06.19 19:15:53 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Internet Plug-Ins
[2010.06.19 19:15:53 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Importer
[2010.06.19 19:15:53 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdw.DAT
[2010.06.19 19:14:35 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Installer Plugin
[2010.06.19 19:14:35 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Image Units
[2010.06.19 19:14:35 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdu.DAT
[2010.06.06 10:10:44 | 011,276,288 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\sandra.mda
[2010.05.11 15:55:26 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010.04.03 21:55:32 | 002,183,470 | ---- | C] () -- C:\Windows\System32\nvdata.bin
[2010.03.25 12:41:45 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\inst.exe
[2010.01.16 21:30:31 | 000,001,196 | ---- | C] () -- C:\Windows\VFO.INI
[2009.12.30 15:00:32 | 000,146,412 | ---- | C] () -- C:\Windows\System32\vilaunch.exe
[2009.12.30 14:56:58 | 000,111,104 | ---- | C] () -- C:\Windows\System32\Uharc.exe
[2009.12.30 14:56:58 | 000,069,632 | ---- | C] () -- C:\Windows\System32\moveex.exe
[2009.12.30 14:56:58 | 000,008,636 | ---- | C] () -- C:\Windows\System32\modifype.exe
[2009.12.25 22:42:42 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\25136B1607.sys
[2009.12.25 22:42:41 | 000,003,140 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
[2009.07.07 10:27:33 | 000,000,324 | ---- | C] () -- C:\Windows\game.ini
[2009.05.04 19:53:53 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2009.02.13 15:54:46 | 000,008,192 | ---- | C] () -- C:\Windows\d3dx.dat
[2009.01.24 15:14:29 | 000,000,059 | ---- | C] () -- C:\Windows\pdf2image.INI
[2009.01.24 02:05:16 | 000,001,024 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\imgpdf2.dll
[2008.12.28 13:31:00 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat
[2008.12.06 19:07:24 | 000,000,000 | ---- | C] () -- C:\Windows\pcfriend.INI
[2008.11.12 13:48:37 | 000,000,168 | RHS- | C] () -- C:\Windows\System32\D404ACE5F9.sys
[2008.11.12 13:43:24 | 000,002,828 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2008.11.12 13:16:15 | 000,114,351 | ---- | C] () -- C:\Windows\hpqins13.dat
[2008.10.26 15:17:12 | 000,000,014 | ---- | C] () -- C:\Windows\dswplug.ini
[2008.10.20 21:36:52 | 000,000,186 | ---- | C] () -- C:\Windows\wininit.ini
[2008.10.20 16:30:22 | 000,069,632 | R--- | C] () -- C:\Windows\System32\xmltok.dll
[2008.10.20 16:30:22 | 000,036,864 | R--- | C] () -- C:\Windows\System32\xmlparse.dll
[2008.10.20 08:55:43 | 000,000,751 | ---- | C] () -- C:\Windows\Rtcwplat.INI
[2008.10.07 08:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008.10.07 08:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008.08.31 08:59:23 | 000,000,176 | ---- | C] () -- C:\Windows\Swish.INI
[2008.08.20 02:07:02 | 000,035,328 | ---- | C] () -- C:\Windows\System32\ztLib.dll
[2008.08.10 19:30:05 | 000,000,010 | ---- | C] () -- C:\Windows\THECRO~1.DAT
[2008.08.10 19:29:46 | 000,188,043 | ---- | C] () -- C:\Windows\The Crow Comic Screen Saver.exe
[2008.08.10 19:29:46 | 000,058,690 | ---- | C] () -- C:\Windows\BINS.EXE
[2008.08.10 19:29:46 | 000,000,817 | ---- | C] () -- C:\Windows\The Crow Comic Screen Saver.ini
[2008.08.10 17:51:33 | 000,076,288 | ---- | C] () -- C:\Windows\System32\OneWaySerial.dll
[2008.07.07 13:50:00 | 000,354,816 | ---- | C] () -- C:\Windows\System32\psisdecd.dll
[2008.06.16 01:39:45 | 000,028,672 | ---- | C] () -- C:\Windows\System32\AxInterop.ShockwaveFlashObjects.dll
[2008.03.29 15:32:23 | 000,000,040 | ---- | C] () -- C:\Windows\DCheck95.ini
[2008.03.11 16:38:43 | 000,278,984 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2008.03.11 16:38:43 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2008.03.11 00:51:36 | 000,162,432 | ---- | C] () -- C:\Windows\System32\drivers\ithsgt.sys
[2008.03.11 00:51:36 | 000,012,032 | ---- | C] () -- C:\Windows\System32\drivers\lilsgt.sys
[2008.01.29 17:04:59 | 000,074,703 | ---- | C] () -- C:\Windows\System32\mfc45.dll
[2008.01.05 22:48:45 | 000,003,972 | ---- | C] () -- C:\Windows\System32\drivers\PciBus.sys
[2007.12.23 17:53:01 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2007.12.22 11:05:34 | 000,000,107 | ---- | C] () -- C:\Windows\Sansa Media Converter.INI
[2007.12.09 13:05:25 | 000,000,525 | ---- | C] () -- C:\Windows\eReg.dat
[2007.10.23 08:56:52 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2007.10.23 08:56:51 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2007.10.23 08:56:51 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
[2007.10.23 08:56:51 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
[2007.10.23 08:56:51 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2007.10.23 08:56:51 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2007.10.23 08:56:51 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2007.10.23 08:56:51 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2007.10.23 08:56:51 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2007.10.23 08:56:51 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2007.10.23 08:56:51 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
[2007.10.23 08:56:51 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2007.10.23 08:56:51 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2007.10.23 08:56:51 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2007.10.23 08:56:51 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2007.10.23 08:56:51 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2007.10.23 08:56:51 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
[2007.10.23 08:56:51 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
[2007.10.23 08:56:51 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2007.07.12 17:14:30 | 000,319,488 | ---- | C] () -- C:\Windows\System32\MafiaSetup.exe
[2007.06.05 13:20:32 | 000,177,704 | ---- | C] () -- C:\Windows\System32\PSIService.exe
[2007.06.02 10:46:32 | 000,153,840 | ---- | C] () -- C:\Windows\System32\ARThumb.dll
[2007.05.14 21:25:07 | 000,000,026 | ---- | C] () -- C:\Windows\System32\satsukidecodersettings.ini
[2007.05.12 17:09:59 | 001,537,536 | ---- | C] () -- C:\Windows\System32\erdmpg-hi.dll
[2007.05.12 17:09:59 | 000,584,192 | ---- | C] () -- C:\Windows\System32\AdaptX30.dll
[2007.05.12 17:09:59 | 000,360,448 | ---- | C] () -- C:\Windows\System32\erdmpg-lo.dll
[2007.05.12 17:09:59 | 000,147,456 | ---- | C] () -- C:\Windows\System32\AVICreator.dll
[2007.05.12 17:09:59 | 000,135,168 | ---- | C] () -- C:\Windows\System32\MPEGCreator.dll
[2007.05.12 17:09:59 | 000,046,080 | ---- | C] () -- C:\Windows\System32\ac3encode.dll
[2007.05.12 17:09:59 | 000,043,008 | ---- | C] () -- C:\Windows\System32\KillUserBp.dll
[2007.05.12 17:09:58 | 000,270,336 | ---- | C] () -- C:\Windows\System32\WMVCreator.dll
[2007.05.12 16:04:37 | 000,000,220 | -HS- | C] () -- C:\Windows\dwin.sys
[2007.05.12 15:56:14 | 000,233,472 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2007.05.12 15:56:14 | 000,053,248 | ---- | C] () -- C:\Windows\System32\dcfft2.dll
[2007.05.12 15:56:14 | 000,021,504 | ---- | C] () -- C:\Windows\System32\wnaspi32.dll
[2007.05.11 08:57:21 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\ezpinst.exe
[2007.05.11 08:57:21 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\pcouffin.cat
[2007.05.11 08:57:21 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\pcouffin.inf
[2007.04.19 16:51:11 | 000,001,324 | ---- | C] () -- C:\Windows\System32\d3d9caps.dat
[2007.04.17 14:34:40 | 000,135,716 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2007.04.17 06:57:03 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2007.04.04 13:47:41 | 000,028,672 | ---- | C] () -- C:\Windows\System32\Alpha.dll
[2007.04.04 11:34:24 | 000,000,280 | ---- | C] () -- C:\Windows\mgutil_reg.ini
[2007.04.04 11:33:32 | 000,000,044 | ---- | C] () -- C:\Windows\mgutil_win.ini
[2007.03.31 22:54:26 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2007.03.13 09:25:31 | 000,000,112 | ---- | C] () -- C:\Windows\ActiveSkin.INI
[2007.03.13 09:25:11 | 000,017,268 | ---- | C] () -- C:\Windows\CDPlayer.ini
[2007.02.22 23:40:21 | 000,001,747 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\QTSBandwidthCache
[2007.02.11 00:05:55 | 000,000,157 | ---- | C] () -- C:\Windows\ADStahovac.INI
[2007.02.10 22:18:44 | 000,131,072 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2007.01.11 21:10:14 | 000,084,204 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2007.01.11 20:58:03 | 000,241,664 | ---- | C] () -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.01.11 08:59:25 | 000,000,332 | ---- | C] () -- C:\Windows\wcx_ftp.ini
[2007.01.11 00:07:34 | 000,001,477 | ---- | C] () -- C:\Windows\level.ini
[2007.01.11 00:07:34 | 000,001,158 | ---- | C] () -- C:\Windows\tmp2Level.ini
[2007.01.09 22:24:26 | 000,000,390 | ---- | C] () -- C:\Windows\ODBC.INI
[2007.01.09 00:50:08 | 000,000,124 | ---- | C] () -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\fusioncache.dat
[2007.01.08 23:03:23 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2007.01.08 21:05:59 | 000,000,192 | ---- | C] () -- C:\Windows\winamp.ini
[2007.01.08 20:53:23 | 000,004,714 | ---- | C] () -- C:\Windows\wincmd.ini
[2007.01.08 19:57:49 | 000,198,144 | ---- | C] () -- C:\Windows\System32\_psisdecd.dll
[2007.01.08 19:55:23 | 000,114,688 | ---- | C] () -- C:\Windows\PowerOption.exe
[2007.01.08 19:55:23 | 000,000,294 | ---- | C] () -- C:\Windows\PowerOption.ini
[2006.11.02 16:10:16 | 000,080,912 | ---- | C] () -- C:\Windows\System32\sherlock2.exe
[2006.08.18 08:27:18 | 000,002,048 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.08.18 08:27:10 | 000,000,061 | ---- | C] () -- C:\Windows\smscfg.ini
[2006.08.17 20:09:02 | 000,032,768 | ---- | C] () -- C:\Windows\System32\MWLPS.dll
[2006.08.17 20:08:54 | 000,000,050 | ---- | C] () -- C:\Windows\commercial.ini
[2006.08.17 20:07:44 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll
[2006.08.17 20:07:00 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIMPEG2.dll
[2006.08.17 20:07:00 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIMP3.dll
[2006.08.17 20:07:00 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIFCD3.dll
[2006.08.17 20:07:00 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTICDMK7.dll
[2006.08.17 20:05:04 | 000,575,040 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.08.17 20:05:04 | 000,570,302 | ---- | C] () -- C:\Windows\System32\perfh005.dat
[2006.08.17 20:05:04 | 000,132,326 | ---- | C] () -- C:\Windows\System32\perfc005.dat
[2006.08.17 20:05:04 | 000,117,220 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.08.17 20:01:52 | 003,783,864 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.08.17 19:52:22 | 000,004,249 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2006.08.17 19:51:32 | 000,021,812 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat
[2006.07.11 23:19:00 | 000,581,632 | ---- | C] () -- C:\Windows\System32\nvhwvid.dll
[2006.07.11 23:19:00 | 000,286,720 | ---- | C] () -- C:\Windows\System32\nvnt4cpl.dll
[2006.05.29 15:05:58 | 000,303,104 | ---- | C] () -- C:\Windows\CreateLnk.exe
[2006.04.23 16:15:36 | 000,000,095 | ---- | C] () -- C:\Windows\ALaunch.ini
[2006.03.29 07:43:38 | 000,042,496 | ---- | C] () -- C:\Windows\System32\ALZZip.BIN
[2006.03.29 07:43:36 | 000,062,464 | ---- | C] () -- C:\Windows\System32\ALZALZ.BIN
[2005.11.16 21:11:52 | 000,024,576 | RH-- | C] () -- C:\Windows\System32\Kill1211.exe
[2005.10.31 03:17:38 | 000,135,168 | ---- | C] () -- C:\Windows\System32\RtlCPAPI.dll
[2005.10.14 10:56:50 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2005.10.14 10:56:50 | 000,921,600 | ---- | C] () -- C:\Windows\System32\VorbisEnc.dll
[2005.10.14 10:56:50 | 000,761,856 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2005.10.14 10:56:50 | 000,344,064 | ---- | C] () -- C:\Windows\System32\xvid.dll
[2005.10.14 10:56:50 | 000,237,568 | ---- | C] () -- C:\Windows\System32\OggDS.dll
[2005.10.14 10:56:50 | 000,188,416 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2005.10.14 10:56:50 | 000,155,136 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2005.10.14 10:56:50 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ogg.dll
[2005.10.14 10:56:48 | 000,077,824 | ---- | C] () -- C:\Windows\System32\MMSwitch.dll
[2005.10.14 10:56:48 | 000,040,960 | ---- | C] () -- C:\Windows\System32\MMAVILNG.exe
[2005.07.15 01:48:00 | 000,040,960 | ---- | C] () -- C:\Windows\System32\ChCfg.exe
[2005.07.12 13:44:42 | 000,015,872 | ---- | C] () -- C:\Windows\System32\InsDrvZD64.DLL
[2004.08.18 21:00:00 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2004.08.18 21:00:00 | 000,272,128 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2004.08.18 21:00:00 | 000,269,162 | ---- | C] () -- C:\Windows\System32\perfi005.dat
[2004.08.18 21:00:00 | 000,218,003 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2004.08.18 21:00:00 | 000,046,258 | ---- | C] () -- C:\Windows\System32\mib.bin
[2004.08.18 21:00:00 | 000,032,072 | ---- | C] () -- C:\Windows\System32\perfd005.dat
[2004.08.18 21:00:00 | 000,028,626 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2004.08.18 21:00:00 | 000,004,569 | ---- | C] () -- C:\Windows\System32\secupd.dat
[2004.08.18 21:00:00 | 000,001,804 | ---- | C] () -- C:\Windows\System32\dcache.bin
[2004.08.18 21:00:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\noise.dat
[2004.03.23 15:38:00 | 000,028,672 | ---- | C] () -- C:\Windows\System32\InsDrvZD.dll
[2003.08.07 08:51:32 | 000,024,576 | -H-- | C] () -- C:\Windows\System32\reboot.exe
[2003.08.06 18:32:24 | 000,024,576 | -H-- | C] () -- C:\Windows\System32\KCMDNIns.exe
[2003.03.14 11:24:00 | 000,024,576 | ---- | C] () -- C:\Windows\System32\ZyDelReg.exe
[2002.05.23 16:34:46 | 000,032,768 | ---- | C] () -- C:\Windows\AMOVE.EXE
[2001.12.26 14:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001.09.03 21:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001.08.25 18:04:08 | 013,107,200 | ---- | C] () -- C:\Windows\System32\oembios.bin
[2001.08.25 18:02:42 | 000,004,524 | ---- | C] () -- C:\Windows\System32\oembios.dat
[2001.07.30 14:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001.07.23 20:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll
[2001.07.06 15:30:00 | 000,003,165 | ---- | C] () -- C:\Windows\System32\HPTCPMON.INI

========== LOP Check ==========

[2011.08.04 17:34:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\!SASCORE
[2011.05.16 22:20:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ACD Systems
[2008.10.25 18:28:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Activision
[2008.08.31 09:04:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alternate
[2011.11.25 22:31:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2011.06.05 19:21:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Big Fish Games
[2010.03.27 00:11:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\BioWare
[2007.09.20 12:01:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\BIZSCR
[2011.10.27 08:31:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\business-inkjet
[2010.12.12 20:15:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\BVRP Software
[2011.05.20 16:01:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Canneverbe Limited
[2011.11.30 20:10:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\CPA_VA
[2007.09.14 10:20:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DFX
[2010.10.04 06:34:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\EnterNHelp
[2007.11.05 11:45:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2011.10.04 12:52:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\f-secure
[2011.09.28 12:08:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\fssg
[2009.05.31 13:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2010.09.11 10:23:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\iolo
[2011.06.25 07:55:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\LANGMaster
[2010.09.13 22:41:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Last.fm
[2011.11.20 22:20:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Media Get LLC
[2011.05.02 11:50:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Nik Software
[2010.10.04 07:33:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Nikon
[2009.10.10 01:23:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NokiaMusic
[2010.05.11 17:10:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Drivers HeadQuarters Inc
[2009.10.10 01:43:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2011.11.23 15:27:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PCSettings
[2007.04.01 17:54:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pegtop
[2010.01.16 21:37:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle
[2010.01.16 21:37:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle Studio
[2011.07.18 16:01:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PMB Files
[2010.05.19 00:10:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\regid.1986-12.com.adobe
[2010.12.12 00:45:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Samsung
[2010.06.19 19:14:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Screen Saver
[2008.12.13 15:35:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2010.06.19 19:15:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Speech Enhancer
[2011.11.02 22:37:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SUPERSetup
[2011.06.19 20:59:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2011.06.22 21:01:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TrackMania
[2011.06.22 19:14:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TrackMania United
[2011.10.27 08:31:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Tuner
[2009.05.31 13:53:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2008.01.05 11:28:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ubisoft
[2009.09.12 14:22:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ulead Systems
[2010.10.04 06:34:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ultima_T15
[2011.10.27 08:33:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Vocals
[2008.07.11 06:02:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\vsosdk
[2011.09.02 16:11:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011.11.23 17:56:23 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{55A29068-F2CE-456C-9148-C869879E2357}
[2011.04.01 07:36:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\.kde
[2011.05.16 22:20:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ACD Systems
[2011.03.21 10:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Ambient Design
[2011.06.08 13:41:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\AnvSoft
[2010.12.11 22:49:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\avidemux
[2007.12.03 11:52:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\BitSpirit
[2009.07.20 12:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\BlackBean
[2011.06.08 14:10:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Broad Intelligence
[2009.12.27 02:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\BSplayer
[2009.12.26 15:29:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\BSplayer Pro
[2010.06.17 21:20:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Canneverbe Limited
[2010.06.06 22:22:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010.08.30 08:23:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ct24crawl
[2010.05.11 12:19:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\DAEMON Tools
[2007.03.12 06:21:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\DMCache
[2011.11.23 12:33:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\EurekaLog
[2010.12.11 21:16:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\FCSB000000001
[2011.07.15 20:46:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Feedreader
[2011.02.13 11:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Flickroom.7A385545159204287F941528E627F38AD4ECB7C0.1
[2010.06.01 16:32:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\GetRightToGo
[2010.03.15 11:49:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\gtk-2.0
[2011.08.27 18:41:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\HDRsoft
[2011.02.15 10:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ICQ
[2008.01.29 17:01:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\iolo
[2010.06.06 16:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\IrfanView
[2008.06.21 14:53:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Jasc
[2010.09.09 08:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\KDE
[2011.06.25 07:55:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\LANGMaster
[2008.03.01 08:23:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Leadertech
[2008.05.11 11:33:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\mojosoft
[2011.05.02 18:42:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Nik Software
[2011.08.27 13:04:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Nikon
[2011.05.24 20:15:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Notepad++
[2011.06.08 13:35:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\OpenCandy
[2011.02.21 18:32:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Panasonic
[2009.10.10 01:39:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\PC Suite
[2010.11.06 18:46:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\pdfforge
[2007.04.01 17:54:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Pegtop
[2010.10.25 21:38:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\PhotoScape
[2011.09.28 16:19:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Plane9
[2011.09.25 22:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\PriceGong
[2011.11.21 21:07:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\QuickScan
[2007.01.21 09:40:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Ringjacker
[2010.12.12 00:43:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Samsung
[2010.11.06 18:09:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Search Settings
[2009.10.10 01:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Sony
[2007.07.04 06:30:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\TuneUp Software
[2008.10.26 15:18:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Ulead Systems
[2011.11.23 03:05:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Uniblue
[2011.11.27 23:30:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\uTorrent
[2009.12.30 15:04:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ViGlance
[2009.12.30 15:04:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ViSplore
[2009.12.30 15:05:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ViStart
[2010.05.21 09:46:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\VitySoft
[2010.03.25 12:41:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Vso
[2008.11.12 12:29:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Zoner

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"RocketDock" = "C:\Program Files\RocketDock\RocketDock.exe" -- [2007.09.02 12:58:52 | 000,495,616 | ---- | M] ()
"SpybotSD TeaTimer" = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe -- [2009.03.05 15:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.)
"H/PC Connection Agent" = "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" -- [2006.11.13 16:50:20 | 001,289,000 | ---- | M] (Microsoft Corporation)
"Pando Media Booster" = C:\Program Files\Pando Networks\Media Booster\PMB.exe -- [2011.07.18 16:00:10 | 003,077,528 | ---- | M] ()
"KiesPDLR" = C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe -- [2011.06.24 07:54:46 | 000,020,880 | ---- | M] ()
"ctfmon.exe" = C:\Windows\system32\ctfmon.exe -- [2008.04.14 07:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)

< >


< MD5 for: AGP440.SYS >
[2004.08.18 21:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\i386\sp3.cab:AGP440.sys
[2004.08.18 21:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004.08.18 21:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\i386\sp3.cab:atapi.sys
[2004.08.18 21:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.18 21:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 07:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe
[2008.04.14 07:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 07:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2004.08.18 21:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe

< MD5 for: CDROM.SYS >
[2004.08.18 21:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\i386\sp2.cab:cdrom.sys
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\i386\sp3.cab:cdrom.sys
[2004.08.18 21:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.13 23:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 23:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2009.12.22 19:39:20 | 000,062,592 | ---- | M] (Microsoft Corporation) MD5=7B53584D94E9D8716B2DE91D5F1CB42D -- C:\WINDOWS\system32\dllcache\cdrom.sys
[2004.08.18 21:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2004.08.18 21:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008.04.14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll

< MD5 for: CSRSS.EXE >
[2004.08.18 21:00:00 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=490E6E57E54FAF5F23F658EA188405A1 -- C:\WINDOWS\$NtServicePackUninstall$\csrss.exe
[2008.04.14 07:52:18 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\ServicePackFiles\i386\csrss.exe
[2008.04.14 07:52:18 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\system32\csrss.exe

< MD5 for: EVENTLOG.DLL >
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2004.08.18 21:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007.06.13 14:11:59 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=9B32416BD5988C97B6397CE0B02CAF97 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2008.04.14 07:52:24 | 001,541,120 | ---- | M] (Microsoft Corporation) MD5=D63C59BB0CA2F83B62D003FD52863090 -- C:\WINDOWS\explorer.exe
[2007.06.13 14:23:39 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=ED7B460B142A32097B8A8F6ECC941815 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: FASTFAT.SYS >
[2004.08.18 21:00:00 | 000,143,360 | ---- | M] (Microsoft Corporation) MD5=3117F595E9615E04F05A54FC15A03B20 -- C:\WINDOWS\$NtServicePackUninstall$\fastfat.sys
[2008.04.13 23:44:30 | 000,143,744 | ---- | M] (Microsoft Corporation) MD5=38D332A6D56AF32635675F132548343E -- C:\WINDOWS\ServicePackFiles\i386\fastfat.sys
[2008.04.13 23:44:30 | 000,143,744 | ---- | M] (Microsoft Corporation) MD5=38D332A6D56AF32635675F132548343E -- C:\WINDOWS\system32\drivers\fastfat.sys

< MD5 for: HAL.DLL >
[2004.08.18 21:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\i386\sp2.cab:hal.dll
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\i386\sp3.cab:hal.dll
[2004.08.18 21:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.13 23:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.13 23:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2005.09.29 00:35:26 | 000,134,272 | ---- | M] (Microsoft Corporation) MD5=A3961B9456DE472D2F152C9DE950FFA5 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll

< MD5 for: CHANGER.SYS >
[2004.08.18 21:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\i386\sp2.cab:Changer.sys
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\i386\sp3.cab:Changer.sys
[2004.08.18 21:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.13 23:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys

< MD5 for: ISAPNP.SYS >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\i386\sp3.cab:isapnp.sys
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2004.08.18 21:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2008.04.14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys

< MD5 for: LSASS.EXE >
[2004.08.18 21:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2008.04.14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008.04.13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2004.08.18 21:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

< MD5 for: NETLOGON.DLL >
[2004.08.18 21:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: NTFS.SYS >
[2007.02.09 12:23:36 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=05AB81909514BFD69CBB1F2C147CF6B9 -- C:\WINDOWS\$hf_mig$\KB930916\SP2QFE\ntfs.sys
[2007.02.09 12:10:35 | 000,574,464 | ---- | M] (Microsoft Corporation) MD5=19A811EF5F1ED5C926A028CE107FF1AF -- C:\WINDOWS\$NtServicePackUninstall$\ntfs.sys
[2008.04.13 23:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\ERDNT\cache\ntfs.sys
[2008.04.13 23:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\ServicePackFiles\i386\ntfs.sys
[2008.04.13 23:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\drivers\ntfs.sys
[2004.08.03 23:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\cmdcons\NTFS.SYS

< MD5 for: NVATA.SYS >
[2006.06.28 16:38:56 | 000,105,088 | ---- | M] (NVIDIA Corporation) MD5=9ECCD189A9554C30A0D18A429778C7BA -- C:\WINDOWS\system32\drivers\nvata.sys
[2006.06.28 16:38:56 | 000,105,088 | ---- | M] (NVIDIA Corporation) MD5=9ECCD189A9554C30A0D18A429778C7BA -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\nvata.sys

< MD5 for: NVATABUS.SYS >
[2006.06.28 18:38:56 | 000,105,088 | ---- | M] (NVIDIA Corporation) MD5=9ECCD189A9554C30A0D18A429778C7BA -- C:\i386\$OEM$\$$\OEMDIR\nvatabus.sys
[2006.06.28 18:38:56 | 000,105,088 | ---- | M] (NVIDIA Corporation) MD5=9ECCD189A9554C30A0D18A429778C7BA -- C:\i386\$OEM$\TEXTMODE\nvatabus.sys
[2006.06.28 18:38:56 | 000,105,088 | ---- | M] (NVIDIA Corporation) MD5=9ECCD189A9554C30A0D18A429778C7BA -- C:\WINDOWS\OemDir\nvatabus.sys
[2006.06.28 18:38:56 | 000,105,088 | ---- | M] (NVIDIA Corporation) MD5=9ECCD189A9554C30A0D18A429778C7BA -- C:\WINDOWS\system32\drivers\nvatabus.sys

< MD5 for: NVRAID.SYS >
[2006.06.28 18:39:02 | 000,089,344 | ---- | M] (NVIDIA Corporation) MD5=FEC5BF206886B880B429216C63528AA2 -- C:\i386\$OEM$\$$\OEMDIR\nvraid.sys
[2006.06.28 18:39:02 | 000,089,344 | ---- | M] (NVIDIA Corporation) MD5=FEC5BF206886B880B429216C63528AA2 -- C:\i386\$OEM$\TEXTMODE\nvraid.sys
[2006.06.28 18:39:02 | 000,089,344 | ---- | M] (NVIDIA Corporation) MD5=FEC5BF206886B880B429216C63528AA2 -- C:\WINDOWS\OemDir\nvraid.sys
[2006.06.28 18:39:02 | 000,089,344 | ---- | M] (NVIDIA Corporation) MD5=FEC5BF206886B880B429216C63528AA2 -- C:\WINDOWS\system32\drivers\nvraid.sys

< MD5 for: SCECLI.DLL >
[2004.08.18 21:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2009.02.09 12:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2004.08.18 21:00:00 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=6E401E61F952FBBF708AFBECEFAFAE81 -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\ERDNT\cache\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\services.exe
[2008.04.14 07:52:46 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\ServicePackFiles\i386\services.exe

< MD5 for: SMSS.EXE >
[2004.08.18 21:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 07:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 07:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
[2004.08.18 21:00:00 | 000,481,792 | ---- | M] (Microsoft Corporation) MD5=CB56F803D2CAF6B3F32E82D2F73F4B3A -- C:\i386\SYSTEM32\SMSS.EXE

< MD5 for: SPOOLSV.EXE >
[2010.08.17 14:19:36 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 -- C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\ERDNT\cache\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\dllcache\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\spoolsv.exe
[2005.06.11 01:17:14 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=AD3D9D191AEA7B5445FE1D82FFBB4788 -- C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[2008.04.14 07:52:50 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=CB1090BCA0E7B40D0B5B4E4D66531809 -- C:\WINDOWS\$NtUninstallKB2347290$\spoolsv.exe
[2008.04.14 07:52:50 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=CB1090BCA0E7B40D0B5B4E4D66531809 -- C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
[2005.06.11 00:53:32 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=DA81EC57ACD4CDC3D4C51CF3D409AF9F -- C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe

< MD5 for: SVCHOST.EXE >
[2008.04.14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008.04.14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004.08.18 21:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: TCPIP.SYS >
[2006.01.13 18:07:08 | 000,360,448 | ---- | M] (Microsoft Corporation) MD5=5562CC0A47B2AEF06D3417B733F3C195 -- C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[2007.10.30 17:53:32 | 000,360,832 | ---- | M] (Microsoft Corporation) MD5=64798ECFA43D78C7178375FCDD16D8C8 -- C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[2007.10.30 18:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.04.13 23:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2006.04.20 13:18:35 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008.04.14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004.08.18 21:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004.08.18 21:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2004.08.18 21:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008.04.14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll

W.Mia
Návštěvník
Návštěvník
Příspěvky: 42
Registrován: 24 Lis 2011 08:29

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#33 Příspěvek od W.Mia »

OTL.Txt 3/3

< >

< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >
[2008.07.06 13:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007.04.09 12:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006.10.26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008.07.06 13:06:10 | 000,147,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\x64\filterpipelineprintproc.dll

< %systemroot%\system32\drivers\*.sys /5 >

< %systemroot%\system32\drivers\*.sys /X >
[2002.12.18 17:44:06 | 000,000,002 | ---- | M] () -- C:\Windows\system32\drivers\ACER_Pixie_XPH.MRK
[2008.04.14 07:51:38 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\adv01nt5.dll
[2008.04.14 07:51:38 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\adv02nt5.dll
[2008.04.14 07:51:38 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\adv05nt5.dll
[2008.04.14 07:51:38 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\adv07nt5.dll
[2008.04.14 07:51:38 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\adv08nt5.dll
[2008.04.14 07:51:38 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\adv09nt5.dll
[2008.04.14 07:51:38 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\adv11nt5.dll
[2005.10.14 16:10:12 | 001,114,674 | R--- | M] () -- C:\Windows\system32\drivers\ativcaxx.cpa
[2005.10.14 16:10:12 | 000,000,929 | R--- | M] () -- C:\Windows\system32\drivers\ativcaxx.vp
[2005.10.14 16:10:12 | 000,058,560 | R--- | M] () -- C:\Windows\system32\drivers\ativckxx.vp
[2006.12.29 19:21:08 | 000,064,352 | ---- | M] () -- C:\Windows\system32\drivers\ativmc20.cod
[2006.02.08 04:15:12 | 000,026,944 | R--- | M] () -- C:\Windows\system32\drivers\ativvpxx.vp
[2008.04.14 07:51:38 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\atv01nt5.dll
[2008.04.14 07:51:38 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\atv02nt5.dll
[2008.04.14 07:51:38 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\atv04nt5.dll
[2008.04.14 07:51:38 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\atv06nt5.dll
[2008.04.14 07:51:38 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\atv10nt5.dll
[2008.04.14 07:51:40 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\ch7xxnt5.dll
[2007.04.02 20:36:04 | 000,129,045 | ---- | M] () -- C:\Windows\system32\drivers\cxthsfs2.cty
[1999.11.02 10:01:32 | 000,006,173 | ---- | M] () -- C:\Windows\system32\drivers\Entech.vxd
[2004.08.18 21:00:00 | 003,440,660 | ---- | M] () -- C:\Windows\system32\drivers\gm.dls
[2004.08.18 21:00:00 | 000,000,646 | ---- | M] () -- C:\Windows\system32\drivers\gmreadme.txt
[2009.10.10 01:42:48 | 000,000,000 | -H-- | M] () -- C:\Windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2009.10.10 01:42:51 | 000,000,000 | -H-- | M] () -- C:\Windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
[2006.12.29 19:02:50 | 000,067,866 | ---- | M] () -- C:\Windows\system32\drivers\netwlan5.img
[2011.12.01 21:15:17 | 001,474,832 | ---- | M] () -- C:\Windows\system32\drivers\sfi.dat
[2008.04.14 07:51:56 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\siint5.dll
[2008.04.14 07:52:06 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\Windows\system32\drivers\vchnt5.dll

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2008.03.10 13:16:54 | 000,715,248 | ---- | M] () Unable to obtain MD5 -- C:\Windows\system32\drivers\sptd.sys

< %systemroot%\system32\*.* /5 >
[2011.11.30 02:46:22 | 003,783,864 | ---- | M] () -- C:\Windows\system32\FNTCACHE.DAT

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\config\*.sav >
[2006.08.17 21:48:14 | 000,094,208 | ---- | M] () -- C:\Windows\system32\config\default.sav
[2006.08.17 21:48:14 | 000,638,976 | ---- | M] () -- C:\Windows\system32\config\software.sav
[2006.08.17 21:48:14 | 000,475,136 | ---- | M] () -- C:\Windows\system32\config\system.sav

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\*.* /U /s >
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[18 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\Windows\Globalization\*.tmp files -> C:\Windows\Globalization\*.tmp -> ]
[13 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]

< %systemroot%\*. /mp /s >

< %ALLUSERSPROFILE%\Data Aplikací\*.* >
[2009.12.26 01:16:36 | 000,000,088 | RHS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\25136B1607.sys
[2010.10.03 18:02:21 | 000,000,012 | RH-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Alerts
[2010.10.03 18:02:19 | 000,000,012 | RH-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Ambient
[2006.08.17 21:49:52 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\desktop.ini
[2010.03.28 23:08:04 | 000,009,017 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\hpzinstall.log
[2011.10.27 08:29:52 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Hybrid Basic
[2011.11.23 02:40:26 | 000,004,107 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\ihfeumzb.qzk
[2009.01.24 02:05:20 | 000,001,024 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\imgpdf2.dll
[2010.06.19 19:14:35 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Installer Plugin
[2010.06.19 19:15:53 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Internet Plug-Ins
[2011.10.27 08:31:20 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Jingles
[2011.10.27 08:33:04 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Kernel Extension
[2011.10.27 08:31:21 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Keyboard Layouts
[2009.12.26 01:16:38 | 000,003,140 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\KGyGaAvL.sys
[2010.10.25 18:05:46 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\PKP_DLbx.DAT
[2010.10.03 18:02:22 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\PKP_DLck.DAT
[2011.11.06 14:12:43 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\PKP_DLdu.DAT
[2011.11.20 17:28:54 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\PKP_DLdw.DAT
[2011.10.27 08:33:04 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\PKP_DLes.DAT
[2011.11.10 08:33:07 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\PKP_DLet.DAT
[2011.10.27 08:31:21 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\PKP_DLev.DAT
[2008.01.20 22:58:03 | 000,001,747 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\QTSBandwidthCache
[2010.10.03 18:02:21 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Rule Actions
[2010.10.03 18:02:19 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Sample Delay
[2011.11.19 11:42:34 | 011,276,288 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\sandra.mda
[4 C:\Documents and Settings\All Users\Data Aplikací\*.tmp files -> C:\Documents and Settings\All Users\Data Aplikací\*.tmp -> ]

< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
[2009.02.04 13:56:14 | 000,075,112 | ---- | M] (GEAR Software, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\DifXInstall32.exe
[2010.03.01 22:44:10 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\java-rmi.exe
[2010.03.01 22:44:10 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\java.exe
[2010.03.01 22:44:10 | 000,059,168 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\javacpl.exe
[2010.03.01 22:44:10 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\javaw.exe
[2010.03.01 22:44:10 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\javaws.exe
[2010.03.01 22:44:12 | 000,079,648 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\jbroker.exe
[2010.03.01 22:44:12 | 000,023,328 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\jp2launcher.exe
[2010.03.01 22:44:12 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\jqs.exe
[2010.03.01 22:44:12 | 000,055,072 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\jqsnotify.exe
[2010.03.01 22:44:12 | 000,386,872 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\jucheck.exe
[2010.03.01 22:44:12 | 000,055,072 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\jureg.exe
[2010.03.01 22:44:14 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\jusched.exe
[2010.03.01 22:44:14 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\keytool.exe
[2010.03.01 22:44:14 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\kinit.exe
[2010.03.01 22:44:14 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\klist.exe
[2010.03.01 22:44:14 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\ktab.exe
[2010.03.01 22:44:14 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\orbd.exe
[2010.03.01 22:44:14 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\pack200.exe
[2010.03.01 22:44:14 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\policytool.exe
[2010.03.01 22:44:14 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\rmid.exe
[2010.03.01 22:44:14 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\rmiregistry.exe
[2010.03.01 22:44:14 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\servertool.exe
[2010.03.01 22:44:14 | 000,030,496 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\ssvagent.exe
[2010.03.01 22:44:14 | 000,033,568 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\tnameserv.exe
[2010.03.01 22:44:14 | 000,132,896 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Adobe\CS5\jre\bin\unpack200.exe
[2011.11.18 20:17:18 | 000,073,584 | ---- | M] (Apple Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Apple Computer\Installer Cache\iTunes 10.5.1.42\SetupAdmin.exe
[2011.11.27 10:15:56 | 007,245,888 | ---- | M] (COMODO) -- C:\Documents and Settings\All Users\Data Aplikací\Comodo Downloader\geekbuddy.exe
[2011.10.07 18:46:50 | 000,198,984 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\ComodoCleanup.exe
[5 C:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\*.tmp files -> C:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\*.tmp -> ]
[2010.12.11 16:46:05 | 000,056,969 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\ASPEncoder\Uninstaller.exe
[2010.12.11 16:46:10 | 000,057,591 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\ControlPanel\Uninstaller.exe
[2010.12.11 16:46:19 | 000,054,128 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Converter\Uninstaller.exe
[2010.12.11 16:46:20 | 000,054,153 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DFXPlugin\Uninstaller.exe
[2010.12.11 16:46:22 | 000,056,458 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DivXDecoderShortcut\Uninstaller.exe
[2010.12.11 16:47:04 | 000,064,957 | ---- | M] (DivX, LLC) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DivXPlusShortcuts\Uninstaller.exe
[2010.12.11 16:46:22 | 000,054,174 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSAACDecoder\Uninstaller.exe
[2010.12.11 16:46:23 | 000,057,532 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSASPDecoder\Uninstaller.exe
[2010.12.11 16:46:25 | 000,054,166 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSAVCDecoder\Uninstaller.exe
[2010.12.11 16:46:26 | 000,057,054 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSDesktopComponents\Uninstaller.exe
[2010.12.11 16:46:10 | 000,054,101 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\MPEG2Plugin\Uninstaller.exe
[2010.12.11 16:45:58 | 000,052,963 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\MSVC80CRTRedist\Uninstaller.exe
[2010.12.11 16:46:00 | 000,062,952 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\OVSHelper\Uninstaller.exe
[2010.12.11 16:47:03 | 000,057,736 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Player\Uninstaller.exe
[2010.12.11 16:46:08 | 000,054,073 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Qt4.5\Uninstaller.exe
[2010.12.11 16:43:20 | 000,903,520 | ---- | M] (DivX, LLC) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Setup\DivXSetup.exe
[2010.12.11 16:46:17 | 000,054,644 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\TranscodeEngine\Uninstaller.exe
[2010.12.11 16:46:30 | 000,084,038 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\TransferWizard\Uninstaller.exe
[2010.12.11 16:47:03 | 000,061,792 | ---- | M] (DivX, LLC) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Update\Uninstaller.exe
[2010.09.13 22:41:15 | 000,683,801 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Last.fm\Client\UninstWA\unins000.exe
[2010.06.07 19:23:07 | 000,086,016 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\NOS\Adobe_Downloads\arh.exe
[2011.10.08 05:50:00 | 000,195,904 | ---- | M] (NVIDIA Corporation) -- C:\Documents and Settings\All Users\Data Aplikací\NVIDIA\Updatus\WLMerger.exe
[2010.11.17 17:06:16 | 000,036,864 | ---- | M] ( ) -- C:\Documents and Settings\All Users\Data Aplikací\TEMP\{889C6F39-241F-4119-8026-1B2F4A124839}\PostBuild.exe
[2011.02.18 18:55:22 | 000,036,864 | ---- | M] ( ) -- C:\Documents and Settings\All Users\Data Aplikací\TEMP\{89A43E80-AC6C-4DA8-9800-F4B30ED577C0}\PostBuild.exe
[2009.12.30 18:51:07 | 000,053,319 | ---- | M] ( ) -- C:\Documents and Settings\All Users\Data Aplikací\TEMP\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe

< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >

< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >

< %APPDATA%\*. >
[2011.04.01 07:36:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\.kde
[2011.05.16 22:20:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ACD Systems
[2011.11.28 23:44:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Adobe
[2007.02.11 19:08:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\AdobeUM
[2011.11.20 17:18:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Ahead
[2011.03.21 10:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Ambient Design
[2011.06.08 13:41:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\AnvSoft
[2011.11.14 16:44:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Apple Computer
[2010.12.11 22:49:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\avidemux
[2007.12.03 11:52:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\BitSpirit
[2009.07.20 12:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\BlackBean
[2011.06.08 14:10:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Broad Intelligence
[2009.12.27 02:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\BSplayer
[2009.12.26 15:29:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\BSplayer Pro
[2010.06.17 21:20:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Canneverbe Limited
[2010.06.06 22:22:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.12.25 22:43:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Corel
[2010.08.30 08:23:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ct24crawl
[2011.02.19 16:12:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\CyberLink
[2010.05.11 12:19:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\DAEMON Tools
[2011.02.15 11:17:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Digsby
[2010.12.11 22:57:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\DivX
[2007.03.12 06:21:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\DMCache
[2009.07.08 11:23:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Download Manager
[2010.05.12 06:04:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ESTsoft
[2011.11.23 12:33:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\EurekaLog
[2010.12.11 21:16:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\FCSB000000001
[2011.07.15 20:46:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Feedreader
[2011.02.13 11:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Flickroom.7A385545159204287F941528E627F38AD4ECB7C0.1
[2010.06.01 16:32:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\GetRightToGo
[2011.03.02 09:07:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Google
[2010.03.15 11:49:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\gtk-2.0
[2011.08.27 18:41:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\HDRsoft
[2007.02.11 00:33:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Help
[2007.01.13 00:59:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\HP
[2011.02.15 10:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ICQ
[2006.12.13 23:20:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Identities
[2007.06.19 23:11:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\InstallShield
[2011.10.30 20:59:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Intelli-studio
[2008.01.29 17:01:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\iolo
[2010.06.06 16:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\IrfanView
[2008.06.21 14:53:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Jasc
[2010.09.09 08:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\KDE
[2011.06.25 07:55:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\LANGMaster
[2008.03.01 08:23:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Leadertech
[2008.04.03 10:24:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Macromedia
[2011.11.21 21:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Malwarebytes
[2011.11.21 21:16:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Media Player Classic
[2010.12.11 16:11:16 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Mike\Data aplikací\Microsoft
[2008.05.11 11:33:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\mojosoft
[2011.11.19 00:28:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Mozilla
[2011.05.02 18:42:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Nik Software
[2011.08.27 13:04:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Nikon
[2011.05.24 20:15:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Notepad++
[2011.11.20 11:43:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\NVIDIA
[2011.06.08 13:35:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\OpenCandy
[2011.02.21 18:32:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Panasonic
[2009.10.10 01:39:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\PC Suite
[2010.11.06 18:46:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\pdfforge
[2007.04.01 17:54:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Pegtop
[2010.10.25 21:38:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\PhotoScape
[2011.09.28 16:19:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Plane9
[2011.09.25 22:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\PriceGong
[2011.11.21 21:07:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\QuickScan
[2011.06.18 17:29:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Real
[2007.01.21 09:40:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Ringjacker
[2010.12.12 00:43:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Samsung
[2010.11.06 18:09:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Search Settings
[2008.01.19 20:50:19 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Mike\Data aplikací\SecuROM
[2009.10.10 01:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Sony
[2007.08.12 00:32:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Sun
[2011.04.12 19:12:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\SUPERAntiSpyware.com
[2007.07.04 06:30:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\TuneUp Software
[2008.10.26 15:18:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Ulead Systems
[2011.11.23 03:05:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Uniblue
[2011.11.27 23:30:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\uTorrent
[2009.12.30 15:04:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ViGlance
[2009.12.30 15:04:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ViSplore
[2009.12.30 15:05:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\ViStart
[2010.05.21 09:46:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\VitySoft
[2010.03.25 12:41:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Vso
[2011.11.21 21:16:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Winamp
[2007.08.14 16:27:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\WinRAR
[2008.11.12 12:29:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Data aplikací\Zoner

< %APPDATA%\*.* >
[2010.12.11 16:00:59 | 000,002,528 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\$_hpcst$.hpc
[2011.05.26 14:28:25 | 000,000,132 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Adobe Formát GIF CS5 – předvolby
[2010.10.09 11:44:38 | 000,057,344 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\chrtmp
[2006.08.17 21:49:52 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Mike\Data aplikací\desktop.ini
[2007.05.11 19:02:35 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\ezpinst.exe
[2010.06.19 19:14:35 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Image Units
[2010.06.19 19:15:53 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Importer
[2010.03.25 12:41:45 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\inst.exe
[2011.10.27 08:31:20 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Internet Services
[2011.10.27 08:33:04 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Iterate Items
[2011.10.27 08:31:21 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Jazz
[2010.03.25 12:41:45 | 000,007,887 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\pcouffin.cat
[2010.03.25 12:41:45 | 000,001,144 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\pcouffin.inf
[2010.03.25 12:41:46 | 000,000,033 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\pcouffin.log
[2010.03.25 12:41:45 | 000,047,360 | ---- | M] (VSO Software) -- C:\Documents and Settings\Mike\Data aplikací\pcouffin.sys
[2011.05.15 08:22:30 | 000,138,056 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\PnkBstrK.sys
[2010.10.03 18:02:21 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Reverb
[2010.10.03 18:02:19 | 000,000,268 | RH-- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Robot

< %APPDATA%\*.exe /s >
[2007.05.11 19:02:35 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\ezpinst.exe
[2010.03.25 12:41:45 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\inst.exe
[2011.03.23 21:37:57 | 017,983,128 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Intelli-studio\iUpdate.exe
[2011.09.02 06:28:55 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Documents and Settings\Mike\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2011.11.28 23:39:06 | 000,117,427 | ---- | M] (Adobe Systems, Inc.) -- C:\Documents and Settings\Mike\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\digitaleditions\digitaleditions.exe
[2010.06.06 22:19:06 | 000,003,584 | R--- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
[2010.10.30 19:12:09 | 000,335,872 | R--- | M] (InstallShield Software Corp.) -- C:\Documents and Settings\Mike\Data aplikací\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe
[2011.10.27 08:34:24 | 000,057,344 | R--- | M] (InstallShield Software Corp.) -- C:\Documents and Settings\Mike\Data aplikací\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
[2008.10.25 18:50:58 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Microsoft\Installer\{89661B04-C646-4412-B6D3-5E19F02F1F37}\ARPPRODUCTICON.exe
[2011.07.12 10:36:15 | 000,016,430 | R--- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Microsoft\Installer\{90A5371B-D960-4F28-B7FC-F1748518642E}\_6FEFF9B68218417F98F549.exe
[2010.10.30 19:10:13 | 000,049,152 | R--- | M] (InstallShield Software Corp.) -- C:\Documents and Settings\Mike\Data aplikací\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
[2011.06.08 13:35:43 | 000,416,160 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\OpenCandy\OpenCandy_082B0483A70844869A95E7B80F4C8B56\LatestDLMgr.exe
[2010.12.17 23:07:06 | 000,043,440 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\OpenCandy\OpenCandy_082B0483A70844869A95E7B80F4C8B56\SpeedstarterCZ.exe
[2010.12.17 18:48:22 | 001,720,472 | ---- | M] (Speedchecker Limited ) -- C:\Documents and Settings\Mike\Data aplikací\OpenCandy\OpenCandy_082B0483A70844869A95E7B80F4C8B56\ZrychleniPocitace.exe
[2011.06.08 13:35:48 | 001,842,096 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\OpenCandy\OpenCandy_082B0483A70844869A95E7B80F4C8B56\ZrychleniPocitace_p2v1.exe
[2010.03.25 00:29:14 | 000,439,816 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Mike\Data aplikací\Real\Update\setup3.10\setup.exe
[2010.03.12 22:43:45 | 008,405,312 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Real\Update\setup3.10\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
[2010.03.12 22:43:27 | 010,309,448 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Real\Update\setup3.10\chr\ChromeInstaller.exe
[2010.03.12 22:43:29 | 000,149,000 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Mike\Data aplikací\Real\Update\setup3.10\chr_helper\LaunchHelper.exe
[2010.03.28 00:56:01 | 020,841,968 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Mike\Data aplikací\Real\Update\setup3.10\rp\RealPlayerSPGold.exe
[2010.03.12 22:43:05 | 000,079,368 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Mike\Data aplikací\Real\Update\setup3.10\RUP\vista.exe
[2010.12.11 23:06:46 | 000,506,024 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Mike\Data aplikací\Real\Update\setup3.13\setup.exe
[2011.01.25 20:45:10 | 000,510,120 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Mike\Data aplikací\Real\Update\setup3.14\setup.exe
[2011.11.25 21:57:03 | 000,315,512 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Mike\Data aplikací\Real\Update\UpgradeHelper\RealPlayer\9.01\rnupgagent.exe
[2011.11.26 00:58:49 | 026,927,552 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Mike\Data aplikací\Real\Update\UpgradeHelper\RealPlayer\9.01\stub_data\RealPlayer.exe
[2011.11.26 00:57:14 | 000,713,472 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Mike\Data aplikací\Real\Update\UpgradeHelper\RealPlayer\9.01\stub_exe\RealPlayer.exe
[2011.07.12 08:27:50 | 003,154,792 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\NDP40-KB2461678-x86.exe
[2011.03.17 15:07:14 | 000,896,912 | ---- | M] (Samsung) -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\Kies.exe
[2011.03.17 15:04:38 | 000,271,360 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\KiesDriverInstaller.exe
[2011.03.17 15:04:00 | 000,034,816 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\KiesMobileDeviceService.exe
[2011.01.29 23:11:36 | 003,372,856 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\KiesTrayAgent.exe
[2011.03.08 06:41:52 | 000,146,832 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\ConnectionManager.exe
[2011.03.08 06:41:52 | 000,287,120 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceDataService.exe
[2011.03.08 06:41:54 | 000,651,152 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\DeviceManager.exe
[2011.03.08 06:41:52 | 000,107,008 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\HSPConnection.exe
[2011.03.08 06:41:50 | 000,061,440 | ---- | M] (Samsung) -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\External\DeviceModules\Kies_Tutorial.exe
[2011.03.17 15:07:18 | 000,131,984 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2011.04.02 04:42:57 | 000,013,824 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\External\FirmwareUpdate\KiesPDLR.exe
[2011.03.17 15:07:20 | 004,661,464 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\External\MediaModules\MyFreeCodecPack.exe
[2011.03.10 02:29:48 | 020,638,056 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\backup\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
[2011.06.24 07:54:50 | 000,358,800 | ---- | M] (ml) -- C:\Documents and Settings\Mike\Data aplikací\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe

< %SYSTEMDRIVE%\*.exe >

< >

< >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-30 07:25:02

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS /s >
"StateIndex" = 1
"tt" = 1

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0\0

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
PENDINGFILERENAMEOPERATIONS REG_MULTI_SZ \??\C:\Program Files\COMODO\COMODO GeekBuddy\Cpa_VA_ErrorLog.txt\0\0\0

< >

< type c:\boot.ini >> test.txt /c >
[Boot Loader]
timeout=2
Default=multi(0)disk(0)rdisk(0)partition(2)\Windows
[Operating Systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\Windows="3RD TRY THIS wahlen Sie diesen Third" /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\Windows="1ST TRY THIS seleccione esto primero" /fastdetect
multi(0)disk(0)rdisk(1)partition(1)\Windows="2ND TRY THIS essayez ceci en deuzieme" /fastdetect
multi(0)disk(0)rdisk(1)partition(2)\Windows="4TH TRY THIS selezioni questo fourth" /fastdetect
multi(0)disk(0)rdisk(0)partition(3)\Windows="5TH TRY THIS selecione este fifth" /fastdetect
multi(0)disk(0)rdisk(1)partition(3)\Windows="6TH TRY THIS seleccione este sexto" /fastdetect
multi(0)disk(0)rdisk(0)partition(4)\Windows="7TH TRY THIS essayez ceci en septieme" /fastdetect
multi(0)disk(0)rdisk(1)partition(4)\Windows="8TH TRY THIS wahlen Sie dieses achte" /fastdetect
C:\="9TH TRY THIS selezioni questo nono"
D:\="10TH TRY THIS selecione este decimo"

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2011.12.02 19:45:17 | 000,000,512 | ---- | M] () MD5=3EA5D476C4D6F9345E253EA35CED9686 -- C:\PhysicalMBR.bin

========== Alternate Data Streams ==========

@Alternate Data Stream - 6144 bytes -> C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0A8E2C33
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:5D17C178
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:CB0AACC9
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DAC76E02

< End of report >

W.Mia
Návštěvník
Návštěvník
Příspěvky: 42
Registrován: 24 Lis 2011 08:29

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#34 Příspěvek od W.Mia »

Extras.Txt

OTL Extras logfile created on: 2.12.2011 19:41:04 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Mike\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,75 Gb Total Physical Memory | 1,73 Gb Available Physical Memory | 62,75% Memory free
8,10 Gb Paging File | 7,02 Gb Available in Paging File | 86,70% Paging File free
Paging file location(s): C:\pagefile.sys 0 0D:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 113,76 Gb Total Space | 41,27 Gb Free Space | 36,28% Space Free | Partition Type: NTFS
Drive D: | 114,22 Gb Total Space | 32,45 Gb Free Space | 28,41% Space Free | Partition Type: FAT32

Computer Name: ACER-64B9BF4930 | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-1509661768-2596670817-2537616161-1006\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
jsfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"ANTIVIRUSDISABLENOTIFY" = 0
"FIREWALLDISABLENOTIFY" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"58890:TCP" = 58890:TCP:*:Enabled:Pando Media Booster
"58890:UDP" = 58890:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"18285:TCP" = 18285:TCP:*:Enabled:BitComet 18285 TCP
"18285:UDP" = 18285:UDP:*:Enabled:BitComet 18285 UDP
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"58890:TCP" = 58890:TCP:*:Enabled:Pando Media Booster
"58890:UDP" = 58890:UDP:*:Enabled:Pando Media Booster

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerCinema\PowerCinema.exe" = C:\Program Files\CyberLink\PowerCinema\PowerCinema.exe:*:Enabled:CyberLink PowerCinema -- (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerCinema\PCMService.exe" = C:\Program Files\CyberLink\PowerCinema\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program -- (CyberLink Corp.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\WINDOWS\system32\dpnsvr.exe" = C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server -- (Microsoft Corporation)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe" = C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome -- (Google Inc.)
"C:\Program Files\Samsung\Intelli-studio\iStudio.exe" = C:\Program Files\Samsung\Intelli-studio\iStudio.exe:*:Enabled:Samsung Intelli-studio -- ()
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- (Google)
"C:\Program Files\TmUnitedForever\TmForever.exe" = C:\Program Files\TmUnitedForever\TmForever.exe:*:Enabled:TmForever -- ()
"C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- (Google)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite (Eval) 2012\RpcAgentSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite (Eval) 2012\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service -- (SiSoftware)
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe -- (NVIDIA Corporation)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"C:\Program Files\Steam\steamapps\common\might and magic clash of heroes\ClashOfHeroes.exe" = C:\Program Files\Steam\steamapps\common\might and magic clash of heroes\ClashOfHeroes.exe:*:Enabled:Might and Magic: Clash of Heroes -- ()
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite (Eval) 2012\WNt500x86\RpcSandraSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite (Eval) 2012\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service -- (SiSoftware)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A04F205-BD23-857A-C524-C9AB43F19C53}" = LR 3 čeština
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0AA0475E-1CC0-47F0-A1E0-28F2DBDB00D1}_is1" = FreePDF Creator
"{0C973594-7DDF-4BD0-84ED-3517F7622037}" = PC Connectivity Solution
"{0CB98AC0-D691-4B21-AD3D-95982517021D}" = Acer WLAN 11g USB Dongle
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{13CB54D3-A7C9-4B23-89A4-6331368AFD30}" = ArtRage 2
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}" = Free NaturalReader
"{221125DC-6A40-4900-B844-591F5E1195B0}" = Microsoft Visual Web Developer 2005 Express Edition - ENU
"{235674B0-A35F-4811-8A8F-E8F42A919EA3}" = PhotoPresets with One-Click WOW!
"{237CD223-1B9D-47E8-A76C-E478B83CCEA2}" = File Uploader
"{239BB983-8A2D-4974-B780-2ADAE32752D5}" = Windows Live installer
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 29
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{2E56A14B-A38A-3AD6-B06D-4A0DCC0F2F2C}" = Google Talk Plugin
"{3127F76D-5335-4AC7-BD1E-2F5247A23C24}" = iTunes
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{38C65D12-79E3-49C0-B211-DE3BE0A7AB39}" = commercial
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{43F81BD1-10E1-4CCE-BCAF-E3100F039D6B}" = ArtRage Studio Pro
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EAB2511-0135-48CA-A47B-CE1E6836793A}" = COMODO Internet Security
"{4F0C7CCF-5666-474B-B02E-AC514A95EC93}" = NVIDIA GAME System Software 2.8.1
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}" = Nikon Movie Editor
"{5E65E94D-69F2-4850-9E93-6459C53A0F50}" = Microsoft .NET Framework 1.1 Czech Language Pack
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65CDEC30-4BF4-48FB-8059-9FC480E4E94F}" = Acer eMode Management
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}" = Microsoft SQL Server Native Client
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{79E37F9C-9330-42BA-9F49-4237A2F1C1C1}" = ImageShack Toolbar for Internet Explorer
"{7B4B0AA9-F97E-49C4-AE6F-D40580B65A22}" = onOne PerfectPresets
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7D71FCA2-DB4A-497D-AF6F-B0D88DA92F88}" = FEAR SP Demo
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{839916F4-D8B5-4407-BE6D-6D4EB9D96AF4}" = LIVE gaming on Windows Runtime Version 1.0.6027
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{89661B04-C646-4412-B6D3-5E19F02F1F37}" = EAX4 Unified Redist
"{89A43E80-AC6C-4DA8-9800-F4B30ED577C0}" = Olympus ib
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BCD7AE7-F713-4D50-BAB9-7839B9386870}" = ImageShack Uploader 2.2.0
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{909F8EBC-EC7F-48FF-0085-475D818F0F31}" = Need for Speed Underground 2
"{90A5371B-D960-4F28-B7FC-F1748518642E}" = PocketShield
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-003F-0405-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95140000-00AF-0405-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A7ED222-A1D0-B692-2AF0-7716C79C1DD9}" = Flickroom
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A2DE62D8-EF1B-36CB-B461-B1E221ED8608}" = Microsoft .NET Framework 4 Extended CSY Language Pack
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A68C62E8-B243-4777-89BB-12173DFA1D45}" = OLYMPUS Digital Camera Updater
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A89768CF-CD21-44FD-A723-16D5A8557415}" = NEF Codec
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B014EE44-9197-4513-9613-71E6EB1B514E}" = Nikon Message Center 2
"{B0DC2DA9-2AF9-422A-88E0-1B84E0F65DB5}" = Speed-Link SL-6535 USB Pad
"{B1BFDF6B-3C03-46fe-B5D7-BABB0063D8E0}" = pdfforge Toolbar v4.1
"{B2F25F71-D920-4288-A548-54CD253DEF14}" = SILKYPIX Developer Studio 3.0 SE
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Ovládací panel NVIDIA 285.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Ovladače grafiky 285.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.95
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizace NVIDIA 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{BC30E5E7-047D-4232-A7E8-F2CB7CC7B2E0}_is1" = Emsisoft Anti-Malware
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2296}_is1" = SiSoftware Sandra Lite (Eval) 2012
"{C46640C0-93FE-4CD7-8B5E-EB0E92C4C2C9}" = Adobe Photoshop Lightroom 3.4.1
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF097717-F174-4144-954A-FBC4BF301029}" = Nero 7 Premium
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D09E1835-02C7-43F2-99DA-0AE1F39D386D}" = Samsung RAW Converter 3
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D1E7142C-6BC3-49EB-A71A-E5D7ADAC7599}" = Nikon File Uploader 2
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D755C7A3-C03E-4460-8C00-AC6E55505FB5}" = LightScribe 1.4.74.1
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E64C137C-D0B7-467A-B47F-460AAB30F0A3}" = ViewNX 2
"{E7084B89-69E0-46B3-A118-8F99D06988CD}" = Microsoft SQL Server VSS Writer
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{F007CBCE-D714-4C0B-8CE9-9B0D78116468}" = ViewNX
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3FA1705966809259F916AF817C59B4F389F4572C" = Balíček ovladače systému Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Actual Booster" = Actual Booster 3.1
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ALZip_is1" = ALZip
"Any Video Converter_is1" = Any Video Converter 3.2.3
"CCleaner" = CCleaner
"CeRegEditor_is1" = CeRegEditor 0.0.5.1
"Color Efex Pro 3.0 Complete" = Color Efex Pro 3.0 Complete
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"COMODO GeekBuddy" = COMODO GeekBuddy
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"Digital Editions" = Adobe Digital Editions
"Digsby" = Digsby
"Dynamic-Photo HDR 4_is1" = Dynamic-Photo HDR 4.7
"E77704EF5E71F4F18CADFBFA68595AFE036D5D97" = Balíček ovladače systému Windows - OLYMPUS IMAGING CORP. Camera Communication Driver Package (09/09/2009 1.0.0.0)
"EAX Unified" = EAX Unified
"Fairies ." = Fairies .
"FeedReader_is1" = FeedReader
"ffdshow_is1" = ffdshow v1.1.3562 [2010-09-07]
"Flickroom.7A385545159204287F941528E627F38AD4ECB7C0.1" = Flickroom
"fring" = fring
"GamePlayLabs Plugin" = GamePlayLabs Plugin
"HDR Efex Pro" = HDR Efex Pro
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{0CB98AC0-D691-4B21-AD3D-95982517021D}" = Acer WLAN 11g USB Dongle
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{89A43E80-AC6C-4DA8-9800-F4B30ED577C0}" = Olympus ib
"InstallShield_{B2F25F71-D920-4288-A548-54CD253DEF14}" = SILKYPIX Developer Studio 3.0 SE
"InstallShield_{D09E1835-02C7-43F2-99DA-0AE1F39D386D}" = Samsung RAW Converter 3
"Intelli-studio" = SAMSUNG Intelli-studio
"IrfanView" = IrfanView (remove only)
"LastFM_is1" = Last.fm 1.5.4.27091
"LR3Cestina" = LR 3 čeština
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Media Key" = Media Key
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft .NET Framework 4 Extended CSY Language Pack" = Microsoft .NET Framework 4 Extended CSY Language Pack
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual Web Developer 2005 Express Edition - ENU" = Microsoft Visual Web Developer 2005 Express Edition - ENU
"Mozilla Firefox 8.0 (x86 cs)" = Mozilla Firefox 8.0 (x86 cs)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Notepad++" = Notepad++
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"OpenVPN" = OpenVPN 2.1rc7 Masaryk University
"PhotomatixPro3x32_is1" = Photomatix Pro version 3.2.6
"PhotoScape" = PhotoScape
"Picasa 3" = Picasa 3
"Plane9" = Plane9 v1.7
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 12.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.92
"RocketDock_is1" = RocketDock 1.3.5
"SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set
"SerifDrawPlus40" = Serif DrawPlus 4.0
"Silver Efex Pro 2" = Silver Efex Pro 2
"Steam App 61700" = Might and Magic: Clash of Heroes
"SystemRequirementsLab" = System Requirements Lab
"The KMPlayer" = The KMPlayer (remove only)
"The Matrix Trilogy" = The Matrix Trilogy Screensaver 0.45
"TmUnited_is1" = TrackMania United DVD Patch 2006-12-15
"TmUnitedForever_is1" = TmUnitedForever Update 2010-03-15
"Totalcmd" = Total Commander (Remove or Repair)
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"vis_milk.dllWinamp" = MilkDrop for Winamp 2x (remove only)
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01005" = Microsoft User-Mode Driver Framework Feature Pack 1.5
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1509661768-2596670817-2537616161-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"MyFreeCodec" = MyFreeCodec
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 26.11.2011 16:18:23 | Computer Name = ACER-64B9BF4930 | Source = Application Error | ID = 1000
Description = Chybující aplikace nvcplui.exe, verze 1.2.1.17, chybující modul xpsp2res.dll,
verze 5.1.2600.5512, adresa chyby 0x0013b7a7.

Error - 28.11.2011 7:11:44 | Computer Name = ACER-64B9BF4930 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 28.11.2011 7:11:44 | Computer Name = ACER-64B9BF4930 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 42951172

Error - 28.11.2011 7:11:44 | Computer Name = ACER-64B9BF4930 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 42951172

Error - 1.12.2011 12:33:49 | Computer Name = ACER-64B9BF4930 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 1.12.2011 12:33:49 | Computer Name = ACER-64B9BF4930 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 61342328

Error - 1.12.2011 12:33:49 | Computer Name = ACER-64B9BF4930 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 61342328

Error - 2.12.2011 13:38:57 | Computer Name = ACER-64B9BF4930 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2.12.2011 13:38:57 | Computer Name = ACER-64B9BF4930 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 14163406

Error - 2.12.2011 13:38:57 | Computer Name = ACER-64B9BF4930 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 14163406

[ OSession Events ]
Error - 10.4.2007 3:03:01 | Computer Name = ACER-64B9BF4930 | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

Error - 18.4.2007 9:51:18 | Computer Name = ACER-64B9BF4930 | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

[ System Events ]
Error - 1.12.2011 16:28:45 | Computer Name = ACER-64B9BF4930 | Source = Service Control Manager | ID = 7000
Description = Služba NTPort Library Driver neuspěla při spuštění v důsledku následující
chyby: %%2

Error - 1.12.2011 16:28:51 | Computer Name = ACER-64B9BF4930 | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: SMR210

Error - 1.12.2011 16:29:05 | Computer Name = ACER-64B9BF4930 | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1058 při pokusu o spuštění služby upnphost
s argumenty za účelem spuštění serveru: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 1.12.2011 16:29:07 | Computer Name = ACER-64B9BF4930 | Source = System Error | ID = 1003
Description = Kód chyby 00000019, parametr1 00000020, parametr2 884f1348, parametr3
884f1760, parametr4 1a830001.

Error - 1.12.2011 16:29:14 | Computer Name = ACER-64B9BF4930 | Source = RemoteAccess | ID = 20106
Description = Rozhraní {A009B4C3-26CA-4B8A-A189-755A4B57966D} se Správcem směrovačů
pro protokol IP nelze přidat. Došlo k následující chybě: Funkci nelze dokončit.

Error - 1.12.2011 16:29:15 | Computer Name = ACER-64B9BF4930 | Source = RemoteAccess | ID = 20106
Description = Rozhraní {88F6F24A-AA08-42A3-9BD8-CB496F5DDE24} se Správcem směrovačů
pro protokol IP nelze přidat. Došlo k následující chybě: Funkci nelze dokončit.

Error - 1.12.2011 17:08:27 | Computer Name = ACER-64B9BF4930 | Source = RemoteAccess | ID = 20106
Description = Rozhraní {A009B4C3-26CA-4B8A-A189-755A4B57966D} se Správcem směrovačů
pro protokol IP nelze přidat. Došlo k následující chybě: Funkci nelze dokončit.

Error - 2.12.2011 3:46:28 | Computer Name = ACER-64B9BF4930 | Source = RemoteAccess | ID = 20106
Description = Rozhraní {A009B4C3-26CA-4B8A-A189-755A4B57966D} se Správcem směrovačů
pro protokol IP nelze přidat. Došlo k následující chybě: Funkci nelze dokončit.

Error - 2.12.2011 3:46:28 | Computer Name = ACER-64B9BF4930 | Source = Service Control Manager | ID = 7011
Description = Vypršel časový limit (30000 milisekund) čekání na odezvu transakce
služby RemoteAccess.

Error - 2.12.2011 13:38:50 | Computer Name = ACER-64B9BF4930 | Source = RemoteAccess | ID = 20106
Description = Rozhraní {A009B4C3-26CA-4B8A-A189-755A4B57966D} se Správcem směrovačů
pro protokol IP nelze přidat. Došlo k následující chybě: Funkci nelze dokončit.

[ TuneUp Events ]
Error - 18.9.2009 23:27:35 | Computer Name = ACER-64B9BF4930 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 18.9.2009 23:27:35 | Computer Name = ACER-64B9BF4930 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 18.9.2009 23:31:42 | Computer Name = ACER-64B9BF4930 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 18.9.2009 23:31:42 | Computer Name = ACER-64B9BF4930 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 18.9.2009 23:52:06 | Computer Name = ACER-64B9BF4930 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 18.9.2009 23:53:16 | Computer Name = ACER-64B9BF4930 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 18.9.2009 23:53:16 | Computer Name = ACER-64B9BF4930 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 20.9.2009 9:34:21 | Computer Name = ACER-64B9BF4930 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 24.12.2009 21:36:17 | Computer Name = ACER-64B9BF4930 | Source = TuneUp Program Statistics | ID = 131840
Description =

Error - 10.1.2010 11:04:48 | Computer Name = ACER-64B9BF4930 | Source = TuneUp Program Statistics | ID = 131840
Description =


< End of report >

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#35 Příspěvek od motji »

:arrow: Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
@Alternate Data Stream - 6144 bytes -> C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0A8E2C33
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:5D17C178
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:CB0AACC9
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DAC76E02

:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
 C:\Documents and Settings\All Users\Data Aplikací\25136B1607.sys

:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]
[Reboot]

-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde :)



:arrow: otestujte na www.virustotal.com
C:\PhysicalMBR.bin

:arrow: Tuto složku znáte?
C:\Documents and Settings\Mike\Data aplikací\.kde
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

W.Mia
Návštěvník
Návštěvník
Příspěvky: 42
Registrován: 24 Lis 2011 08:29

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#36 Příspěvek od W.Mia »

motji napsal::arrow: Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
@Alternate Data Stream - 6144 bytes -> C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0A8E2C33
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:5D17C178
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:CB0AACC9
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DAC76E02

:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
 C:\Documents and Settings\All Users\Data Aplikací\25136B1607.sys

:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]
[Reboot]

-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde :)
Provedeno. Log je zde:

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
ADS C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:0A8E2C33 deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:5D17C178 deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:CB0AACC9 deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:DAC76E02 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\1C4551A64743409391E41477CD655043.TMP folder moved successfully.
C:\WINDOWS\5DB65884C9634454AABA4CA3089281FA.TMP folder moved successfully.
C:\WINDOWS\msdownld.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP10A6.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP118.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP119.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP162.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1A4.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3DC.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP402.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP497.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP4CB.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP504.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP527.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP6A3.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP787.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7B2.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7E6.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP8CD.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP956.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPFBC.tmp folder moved successfully.
C:\WINDOWS\Globalization\tl-PH-Nokia.tmp0 moved successfully.
C:\WINDOWS\Installer\MSI3D9.tmp moved successfully.
C:\WINDOWS\Installer\MSI417.tmp moved successfully.
C:\WINDOWS\Installer\MSI418.tmp moved successfully.
C:\WINDOWS\Installer\MSI419.tmp moved successfully.
C:\WINDOWS\Installer\MSI5CF.tmp moved successfully.
C:\WINDOWS\Installer\MSI76.tmp moved successfully.
C:\WINDOWS\Installer\MSI79.tmp moved successfully.
C:\WINDOWS\Installer\MSI7A.tmp moved successfully.
C:\WINDOWS\Installer\MSI7B.tmp moved successfully.
C:\WINDOWS\Installer\MSI7C.tmp moved successfully.
C:\WINDOWS\Installer\MSI7D.tmp moved successfully.
C:\WINDOWS\Installer\MSI7E.tmp moved successfully.
C:\WINDOWS\Installer\MSI7F.tmp moved successfully.
C:\Documents and Settings\All Users\Data Aplikací\25136B1607.sys moved successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 56999 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 56543 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Mike
->Temp folder emptied: 628869 bytes
->Temporary Internet Files folder emptied: 294747344 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 164560143 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 184316 bytes

User: NetworkService
->Temp folder emptied: 115576 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56543 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 18432 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 11229387 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 450,00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService

User: Mike
->Flash cache emptied: 0 bytes

User: NetworkService

User: UpdatusUser
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 12032011_090222

Files\Folders moved on Reboot...
C:\Documents and Settings\Mike\Local Settings\Temp\WCESLog.log moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_978.dat moved successfully.

Registry entries deleted on Reboot...
:arrow: otestujte na http://www.virustotal.com
C:\PhysicalMBR.bin
PhysicalMBR.bin
Result: 0/ 43 (0.0%)

http://www.virustotal.com/file-scan/rep ... 1322899468
:arrow: Tuto složku znáte?
C:\Documents and Settings\Mike\Data aplikací\.kde
Přemýšleli jsme nad tím a nevíme, kde se ta složka vzala. Vytvořena byla 9. 9. 2010, což si vůbec nevzpomínáme, že bychom tehdy řešili třeba nějaký problém.

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#37 Příspěvek od motji »

A můžete do té složky mrknout?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

W.Mia
Návštěvník
Návštěvník
Příspěvky: 42
Registrován: 24 Lis 2011 08:29

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#38 Příspěvek od W.Mia »

motji napsal:A můžete do té složky mrknout?
Má 20MB. Jsou v ní tři složky:

C:\Documents and Settings\Mike\Data aplikací\.kde\tmp-ACER-64B9BF-4930
...ta je prázdná. Jinak to "ACER-64B9BF-4930" je úplný název počítače.

C:\Documents and Settings\Mike\Data aplikací\.kde\share
...tam jsou podsložky apps a config.
V C:\Documents and Settings\Mike\Data aplikací\.kde\share\apps jsou další složky, většinou prázdné (nepomuk, khelpcenter, ...)
Akorát v jedné jsem našla log C:\Documents and Settings\Mike\Data aplikací\.kde\share\apps\kconf_update\log\update.log:

Kód: Vybrat vše

2010-09-09T09:35:28 Checking update-file 'c:/program files/kde/share/apps/kconf_update/devicepreference.upd' for new updates
2010-09-09T09:35:28 devicepreference.upd: Found new update 'DevicesMovedToPlatformPlugin'
2010-09-09T09:35:28 devicepreference.upd: !! Script 'phonon_devicepreference_update' not found in line 2 : 'Script=phonon_devicepreference_update'
2010-09-09T09:35:28 devicepreference.upd: Found new update 'DevicesUIDsChanged'
2010-09-09T09:35:28 devicepreference.upd: !! Script 'phonon_deviceuids_update' not found in line 5 : 'Script=phonon_deviceuids_update'
2010-09-09T09:35:28 Checking update-file 'c:/program files/kde/share/apps/kconf_update/kcookiescfg.upd' for new updates
2010-09-09T09:35:28 kcookiescfg.upd: Found new update 'kde2.2/b1'
2010-09-09T09:35:28 kcookiescfg.upd: File 'kcookiejarrc' does not exist or empty, skipping
2010-09-09T09:35:28 kcookiescfg.upd: Found new update 'kde3.1/cvs'
2010-09-09T09:35:28 kcookiescfg.upd: File 'kcookiejarrc' does not exist or empty, skipping
2010-09-09T09:35:28 Checking update-file 'c:/program files/kde/share/apps/kconf_update/kded.upd' for new updates
2010-09-09T09:35:28 kded.upd: Found new update 'kde3.0'
2010-09-09T09:35:28 kded.upd: File 'kdedrc' does not exist or empty, skipping
2010-09-09T09:35:28 Checking update-file 'c:/program files/kde/share/apps/kconf_update/kioslave.upd' for new updates
2010-09-09T09:35:28 kioslave.upd: Found new update 'kde2.2/r1'
2010-09-09T09:35:28 kioslave.upd: File 'kioslaverc' does not exist or empty, skipping
2010-09-09T09:35:28 kioslave.upd: Skipping update 'kde2.2/r1'
2010-09-09T09:35:28 kioslave.upd: File 'kioslaverc' does not exist or empty, skipping
2010-09-09T09:35:28 kioslave.upd: Found new update 'kde2.2/r2'
2010-09-09T09:35:28 kioslave.upd: File 'kioslaverc' does not exist or empty, skipping
2010-09-09T09:35:28 kioslave.upd: Found new update 'kde2.2/r3'
2010-09-09T09:35:28 kioslave.upd: File 'kioslaverc' does not exist or empty, skipping
2010-09-09T09:35:28 Checking update-file 'c:/program files/kde/share/apps/kconf_update/kio_help.upd' for new updates
2010-09-09T09:35:28 kio_help.upd: Found new update 'kde3_2'
2010-09-09T09:35:28 kio_help.upd: !! Script 'move_kio_help_cache.sh' not found in line 3 : 'Script=move_kio_help_cache.sh,sh'
2010-09-09T09:35:28 Checking update-file 'c:/program files/kde/share/apps/kconf_update/kpat_update_cardwidth.upd' for new updates
2010-09-09T09:35:28 kpat_update_cardwidth.upd: Found new update 'kpat_cardwidth_update.kde41'
2010-09-09T09:35:28 kpat_update_cardwidth.upd: File 'kpatrc' does not exist or empty, skipping
2010-09-09T09:35:28 Checking update-file 'c:/program files/kde/share/apps/kconf_update/ksslcertificatemanager.upd' for new updates
2010-09-09T09:35:28 ksslcertificatemanager.upd: Found new update 'kde4.2'
2010-09-09T09:35:28 ksslcertificatemanager.upd: Running script 'ksslcertificatemanager.upd.sh'
2010-09-09T09:35:28 ksslcertificatemanager.upd: !! An error occurred while running 'sh c:/program files/kde/share/apps/kconf_update/ksslcertificatemanager.upd.sh'
2010-09-09T09:35:28 Checking update-file 'c:/program files/kde/share/apps/kconf_update/kuriikwsfilter.upd' for new updates
2010-09-09T09:35:28 kuriikwsfilter.upd: Found new update 'post-kde3.1/cvs'
2010-09-09T09:35:28 kuriikwsfilter.upd: File 'kuriikwsfilterrc' does not exist or empty, skipping
2010-09-09T09:35:28 Checking update-file 'c:/program files/kde/share/apps/kconf_update/mailtransports.upd' for new updates
2010-09-09T09:35:28 mailtransports.upd: Found new update 'initial-kmail-migration'
2010-09-09T09:35:28 mailtransports.upd: File 'kmailrc' does not exist or empty, skipping
2010-09-09T09:35:28 mailtransports.upd: Found new update 'initial-knode-migration'
2010-09-09T09:35:28 mailtransports.upd: File 'knoderc' does not exist or empty, skipping
2010-09-09T09:35:28 Checking update-file 'c:/program files/kde/share/apps/kconf_update/plasma_popupapplet_fix_groups.upd' for new updates
2010-09-09T09:35:28 plasma_popupapplet_fix_groups.upd: Found new update 'PlasmaPopupAppletFixGroups1'
2010-09-09T09:35:28 plasma_popupapplet_fix_groups.upd: File 'plasma-appletsrc' does not exist or empty, skipping
2010-09-09T09:35:28 plasma_popupapplet_fix_groups.upd: Found new update 'PlasmaPopupAppletFixGroups2'
2010-09-09T09:35:28 plasma_popupapplet_fix_groups.upd: File 'plasmarc' does not exist or empty, skipping
2010-09-09T09:35:28 plasma_popupapplet_fix_groups.upd: Found new update 'PlasmaPopupAppletFixGroups3'
2010-09-09T09:35:28 plasma_popupapplet_fix_groups.upd: File 'plasmoidviewer-appletsrc' does not exist or empty, skipping
V C:\Documents and Settings\Mike\Data aplikací\.kde\share\config pak je toto:
Obrázek

C:\Documents and Settings\Mike\Data aplikací\.kde\cache-ACER-64B9BF-4930
...tam jsou dvě podsložky a dva soubory:
C:\Documents and Settings\Mike\Data aplikací\.kde\cache-ACER-64B9BF-4930\help, která je prázdná.
C:\Documents and Settings\Mike\Data aplikací\.kde\cache-ACER-64B9BF-4930\kp, kde jsou tři soubory kde-icon-cache.updated, kde-icon-cache.index, kde-icon-cache.date
C:\Documents and Settings\Mike\Data aplikací\.kde\cache-ACER-64B9BF-4930\ksycoca4
C:\Documents and Settings\Mike\Data aplikací\.kde\cache-ACER-64B9BF-4930\ksycoca4stamp

Ale nic z toho mi vůbec nic neříká, kde se vzalo a jak to mohlo vzniknout a k čemu to je. Jestli potřebujete vědět něco konkrétního, napište.

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#39 Příspěvek od motji »

Tu složku necháme být. Zkusíme znovu nahradit ty soubory, nějak se mi nelíbí :?: .

:arrow: Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

:files
C:\Windows\regedit.exe | C:\Windows\ServicePackFiles\i386\regedit.exe /replace
C:\Windows\explorer.exe | C:\Windows\ServicePackFiles\i386\explorer.exe  /replace

:commands
[Reboot]

-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

W.Mia
Návštěvník
Návštěvník
Příspěvky: 42
Registrován: 24 Lis 2011 08:29

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#40 Příspěvek od W.Mia »

Po restartu žádný log nevyskočil :( Nenašla jsem nic na ploše (tam je ten starý z 2. 12. 2011) a našla jsem akorát na rootu:

C:\_OTL\MovedFiles\12042011_170306.log (vytvořeno 4. 12. 2011, 17:03)

========== OTL ==========
Process explorer.exe killed successfully!
========== FILES ==========
File C:\Windows\regedit.exe successfully replaced with C:\Windows\ServicePackFiles\i386\regedit.exe
File C:\Windows\explorer.exe successfully replaced with C:\Windows\ServicePackFiles\i386\explorer.exe
========== COMMANDS ==========

OTL by OldTimer - Version 3.2.31.0 log created on 12042011_170306

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#41 Příspěvek od motji »

Udělejte nový OTL, ale jen sken :!:
Do bílého pole vložte

Kód: Vybrat vše

/md5start
explorer.exe
regedit.exe
/md5stop
- zaškrtněte okénko Pro všechny uživatele.
- Klikněte na tlačítko Prohledat
-po dokončení skenu se objeví log OTL.Txt , vložte je zde
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

W.Mia
Návštěvník
Návštěvník
Příspěvky: 42
Registrován: 24 Lis 2011 08:29

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#42 Příspěvek od W.Mia »

Provedeno, první část logu je zde:

OTL logfile created on: 4.12.2011 19:56:39 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Mike\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,75 Gb Total Physical Memory | 2,13 Gb Available Physical Memory | 77,42% Memory free
8,10 Gb Paging File | 7,40 Gb Available in Paging File | 91,36% Paging File free
Paging file location(s): C:\pagefile.sys 0 0D:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 113,76 Gb Total Space | 41,52 Gb Free Space | 36,50% Space Free | Partition Type: NTFS
Drive D: | 114,22 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: FAT32

Computer Name: ACER-64B9BF4930 | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011.12.02 18:57:11 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mike\Plocha\OTL.exe
PRC - [2011.11.23 11:27:04 | 001,052,472 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
PRC - [2011.11.16 12:09:18 | 002,996,784 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe
PRC - [2011.10.20 12:58:42 | 002,497,352 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2011.10.08 05:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011.10.07 18:47:14 | 001,883,328 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2011.06.24 07:54:46 | 000,020,880 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2011.06.18 17:29:21 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\real\realplayer\Update\realsched.exe
PRC - [2011.03.11 15:17:30 | 000,093,360 | ---- | M] (OLYMPUS IMAGING CORP.) -- C:\Program Files\OLYMPUS\ib\olycamdetect.exe
PRC - [2011.02.21 22:17:32 | 000,066,560 | ---- | M] (Nalpeiron Ltd.) -- C:\WINDOWS\system32\nlssrv32.exe
PRC - [2010.12.08 20:17:46 | 001,226,608 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.10.25 10:03:52 | 000,217,088 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2010.01.15 15:51:04 | 000,025,600 | ---- | M] (pdfconverter.com) -- C:\Program Files\pdfconverter.com\FreePDF Creator\itFPCPrnDisp.exe
PRC - [2009.05.29 15:58:46 | 000,479,232 | ---- | M] (Nikon Corporation) -- C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
PRC - [2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.09.02 12:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.exe
PRC - [2007.06.05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
PRC - [2006.08.11 16:14:28 | 000,110,592 | ---- | M] (Acer Inc.) -- C:\Program Files\Acer\Acer eMode Management\AspireService.exe
PRC - [2006.07.26 21:43:16 | 000,114,784 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
PRC - [2006.07.26 21:43:14 | 000,266,338 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
PRC - [2006.07.26 21:42:56 | 000,143,360 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerCinema\PCMService.exe
PRC - [2006.07.26 21:42:46 | 001,073,152 | ---- | M] (Cyberlink) -- C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
PRC - [2005.11.16 19:25:14 | 000,745,472 | ---- | M] (X-Micro Technology Corp.) -- C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
PRC - [2004.09.29 12:14:36 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe


========== Modules (No Company Name) ==========

MOD - [2011.12.03 09:08:25 | 000,055,816 | ---- | M] () -- C:\Documents and Settings\Mike\Local Settings\temp\b01d42a6-0948-4bd0-8dea-54d68f50a791\CliSecureRT.dll
MOD - [2011.10.12 12:27:04 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\4013a4d303761138606a952901b0f590\System.Management.ni.dll
MOD - [2011.10.12 12:23:22 | 000,770,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\59418ce1082157fbf6dbbbe85fa8d78e\System.Runtime.Remoting.ni.dll
MOD - [2011.10.12 12:22:17 | 001,781,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\0e06eb1acf979d6dfd95c9ebcf5550bb\System.Xaml.ni.dll
MOD - [2011.10.12 12:04:45 | 000,284,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\5ad95fffd68c6c29ead74009f3d89ec0\PresentationFramework.Classic.ni.dll
MOD - [2011.10.12 12:04:11 | 017,673,728 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\1418a81b6da08d4735b83a60f7525c8b\PresentationFramework.ni.dll
MOD - [2011.10.12 12:03:32 | 013,137,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\52e237bd9dcf62782e477d3caf451210\System.Windows.Forms.ni.dll
MOD - [2011.10.12 12:03:07 | 001,652,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\9f3d6ed58636f00b008eb84c2fecfffe\System.Drawing.ni.dll
MOD - [2011.10.12 12:02:50 | 011,106,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\fb7a70d4f5b2df437d456ec82d658fea\PresentationCore.ni.dll
MOD - [2011.10.12 12:02:28 | 003,798,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\81046d70594f88758b8b9b698d510fa8\WindowsBase.ni.dll
MOD - [2011.10.12 12:01:51 | 007,053,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\d3dab9ff9af3acc625d79329fc143357\System.Core.ni.dll
MOD - [2011.10.12 12:01:33 | 009,085,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\e3914597ed0a6c9bc82824f874ca21be\System.ni.dll
MOD - [2011.10.12 12:01:12 | 014,409,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\e5de681ee33ae6535462d070428f4f1b\mscorlib.ni.dll
MOD - [2011.10.07 18:46:30 | 000,068,424 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav
MOD - [2011.06.24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011.06.24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.06.24 07:54:46 | 000,020,880 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
MOD - [2011.02.09 01:56:38 | 000,296,448 | ---- | M] () -- C:\Program Files\Notepad++\NppShell_04.dll
MOD - [2010.12.08 20:18:26 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2010.12.08 20:17:46 | 001,226,608 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2008.04.14 07:51:48 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2007.09.02 12:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.exe
MOD - [2007.09.02 12:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.dll
MOD - [2007.06.05 13:20:32 | 000,177,704 | ---- | M] () -- C:\WINDOWS\system32\PSIService.exe
MOD - [2006.07.27 18:51:18 | 000,057,451 | ---- | M] () -- C:\Program Files\ICQLite\ICQLiteShell.dll
MOD - [2006.07.26 21:43:24 | 000,065,634 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSchMgr.dll
MOD - [2006.07.26 21:43:24 | 000,024,576 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSchedps.dll
MOD - [2006.07.26 21:43:22 | 000,225,384 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapEngine.dll
MOD - [2006.07.26 21:43:22 | 000,032,768 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvcps.dll
MOD - [2006.07.26 21:43:16 | 000,114,784 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
MOD - [2006.07.26 21:43:14 | 000,266,338 | ---- | M] () -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
MOD - [2005.11.01 16:36:28 | 000,045,056 | ---- | M] () -- C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.dll
MOD - [2005.09.21 20:39:52 | 000,212,992 | ---- | M] () -- C:\Program Files\Acer WLAN 11g USB Dongle\dot1x_dll.dll
MOD - [2004.03.05 14:00:58 | 000,155,648 | ---- | M] () -- C:\Program Files\Acer WLAN 11g USB Dongle\ssleay32.dll
MOD - [2004.03.05 14:00:26 | 000,827,392 | ---- | M] () -- C:\Program Files\Acer WLAN 11g USB Dongle\libeay32.dll
MOD - [2001.10.28 17:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (SwitchBoard)
SRV - File not found [On_Demand | Stopped] -- -- (ServiceLayer)
SRV - File not found [Auto | Stopped] -- -- (PCSpeedUpService)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - File not found [Auto | Stopped] -- -- (Application Updater)
SRV - [2011.11.23 11:27:04 | 001,052,472 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe -- (CLPSLS)
SRV - [2011.11.16 12:09:18 | 002,996,784 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe -- (a2AntiMalware)
SRV - [2011.10.08 05:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011.10.07 18:47:14 | 001,883,328 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011.04.24 21:55:00 | 004,066,168 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2011.03.16 10:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.02.21 22:17:32 | 000,066,560 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\WINDOWS\system32\nlssrv32.exe -- (nlsX86cc)
SRV - [2010.10.25 10:03:52 | 000,217,088 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010.02.17 15:34:07 | 000,015,872 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\OpenVPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2008.11.06 12:37:22 | 000,093,848 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite (Eval) 2012\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2007.06.05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PSIService.exe -- (ProtexisLicensing)
SRV - [2006.11.03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2006.07.26 21:43:16 | 000,114,784 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe -- (CLSched) CyberLink Task Scheduler (CTS)
SRV - [2006.07.26 21:43:14 | 000,266,338 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe -- (CLCapSvc) CyberLink Background Capture Service (CBCS)
SRV - [2006.07.26 21:42:46 | 001,073,152 | ---- | M] (Cyberlink) [Auto | Running] -- C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe -- (CyberLink Media Library Service)
SRV - [2004.09.29 12:14:36 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - [2011.10.07 18:48:04 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\Windows\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2011.10.07 18:48:02 | 000,492,768 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2011.10.07 18:48:02 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2011.05.19 13:10:34 | 000,017,904 | ---- | M] (Emsi Software GmbH) [Kernel | System | Running] -- C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys -- (A2DDA)
DRV - [2011.01.29 17:00:20 | 000,020,032 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - [2010.10.25 10:03:52 | 000,036,640 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010.02.17 15:34:07 | 000,025,216 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tap0901.sys -- (tap0901)
DRV - [2009.08.07 22:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite (Eval) 2012\WNt500x86\sandra.sys -- (SANDRA)
DRV - [2009.07.07 11:34:13 | 000,278,984 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2009.02.24 17:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2008.10.09 14:42:42 | 000,017,408 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\KMWDFILTER.sys -- (KMWDFILTER)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.05.16 11:33:14 | 000,115,752 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016unic.sys -- (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM)
DRV - [2008.05.16 11:33:14 | 000,025,512 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016nd5.sys -- (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS)
DRV - [2008.05.16 11:33:14 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016mdfl.sys -- (s0016mdfl)
DRV - [2008.05.16 11:33:12 | 000,120,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016mdm.sys -- (s0016mdm)
DRV - [2008.05.16 11:33:12 | 000,114,216 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016mgmt.sys -- (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM)
DRV - [2008.05.16 11:33:12 | 000,110,632 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016obex.sys -- (s0016obex)
DRV - [2008.05.16 11:33:12 | 000,089,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016bus.sys -- (s0016bus) Sony Ericsson Device 0016 driver (WDM)
DRV - [2008.03.11 16:38:43 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2008.03.11 00:51:36 | 000,162,432 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ithsgt.sys -- (ithsgt)
DRV - [2008.03.11 00:51:36 | 000,012,032 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lilsgt.sys -- (lilsgt)
DRV - [2008.03.10 13:16:54 | 000,715,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2007.11.14 21:50:04 | 000,025,544 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2006.06.29 09:53:00 | 000,244,864 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2006.06.28 18:38:56 | 000,105,088 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\nvatabus.sys -- (nvatabus)
DRV - [2006.06.28 16:38:56 | 000,105,088 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2006.06.18 22:59:28 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006.06.05 21:09:26 | 004,284,928 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005.10.28 10:38:18 | 000,402,432 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZD1211BU.sys -- (ZD1211BU(ZyDAS)) ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS)
DRV - [2005.10.04 14:38:24 | 000,280,064 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZD1211U.sys -- (ZD1211U(ZyDAS)) ZyDAS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyDAS)
DRV - [2005.07.08 14:44:18 | 000,159,616 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vax347b.sys -- (vax347b)
DRV - [2005.02.23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2005.02.09 10:59:00 | 000,014,165 | ---- | M] (Pinnacle Systems GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Pclepci.sys -- (PCLEPCI)
DRV - [2005.01.01 10:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\npptNT2.sys -- (NPPTNT2)
DRV - [2004.10.25 12:40:58 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZDPSp50.sys -- (ZDPSp50)
DRV - [2004.09.29 21:36:29 | 000,015,360 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NetMotCM.sys -- (ndiscm)
DRV - [2004.04.30 09:33:00 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\vax347s.sys -- (vax347s)
DRV - [2003.12.29 18:27:04 | 000,008,576 | ---- | M] (Waytech Development, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\UsbFltr.sys -- (UsbFltr)
DRV - [2002.07.11 12:00:44 | 000,012,856 | ---- | M] (WayTech Development, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\kbfilter.sys -- (kbfilter)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local;<local>

IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com
IE - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledItems: {cbafdacb-a320-4294-9516-494f93d5d1b3}:1.0.6
FF - prefs.js..extensions.enabledItems: googletube@googletube.com:2.0.2
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: cs@dictionaries.addons.mozilla.org:1.0.2
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: exif_viewer@mozilla.doslash.org:1.60
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: buckts@buckts.com:0.18
FF - prefs.js..extensions.enabledItems: {261a7cc7-4cbe-4741-bd5f-1ebdd0c63f7b}:0.2.2
FF - prefs.js..extensions.enabledItems: en-GB@dictionaries.addons.mozilla.org:1.19.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://search.centrum.cz/index.php?tool ... m-1.0.0&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Centrum.cz Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "http://cs.www.mozilla.com/cs/"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\Mike\Data aplikací\Facebook\npfbplugin_1_0_1.dll File not found
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Mike\Data aplikací\Facebook\npfbplugin_1_0_3.dll File not found
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Mike\Data aplikací\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Mike\Data aplikací\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Update\1.2.183.39\npGoogleOneClick8.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.06.18 17:29:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.18 20:38:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.11.18 20:38:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2010.05.11 15:55:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Extensions
[2011.11.25 22:34:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions
[2011.11.25 22:34:22 | 000,000,000 | ---D | M] (Flagfox) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011.11.08 02:32:09 | 000,000,000 | ---D | M] (Digsby) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\{cbafdacb-a320-4294-9516-494f93d5d1b3}
[2011.03.02 23:32:46 | 000,000,000 | ---D | M] (ÄŚeskĂ© slovnĂ­ky pro kontrolu pravopisu) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\cs@dictionaries.addons.mozilla.org
[2011.02.28 12:07:09 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\en-GB@dictionaries.addons.mozilla.org
[2010.05.20 21:52:05 | 000,000,000 | ---D | M] (GoogleTube) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\googletube@googletube.com
[2011.05.06 21:47:19 | 000,000,000 | ---D | M] (Media Plugin) -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\extensions\plugin3@gameplaylabs.com
[2011.04.16 13:58:58 | 000,002,247 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\searchplugins\slovnk-encz.xml
[2010.10.01 08:00:48 | 000,001,330 | ---- | M] () -- C:\Documents and Settings\Mike\Data aplikací\Mozilla\Firefox\Profiles\bjzck3b9.default\searchplugins\wikipedia-en.xml
[2011.11.09 09:31:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.10.23 08:09:04 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\{1018E4D6-728F-4B20-AD56-37578A4DE76B}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\{CBAFDACB-A320-4294-9516-494F93D5D1B3}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\CS@DICTIONARIES.ADDONS.MOZILLA.ORG
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\EN-GB@DICTIONARIES.ADDONS.MOZILLA.ORG
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\EXIF_VIEWER@MOZILLA.DOSLASH.ORG.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MIKE\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\BJZCK3B9.DEFAULT\EXTENSIONS\PLUGIN3@GAMEPLAYLABS.COM
[2010.10.25 18:20:06 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011.11.09 09:30:43 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.10.03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2005.04.27 21:10:49 | 000,102,400 | ---- | M] (RealNetworks) -- C:\Program Files\mozilla firefox\plugins\npracplug.dll
[2010.12.09 11:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2011.09.29 02:30:58 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2011.09.29 02:30:58 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2011.09.29 02:30:58 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011.09.29 02:30:58 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.09.29 02:30:58 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Mike\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Data aplikac\u00ED\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Data aplikac\u00ED\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Mike\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Mike\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Mike\Data aplikac\u00ED\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Mike\Data aplikac\u00ED\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: RealArcade Mozilla Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\Mike\Data aplikac\u00ED\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Mike\Local Settings\Data aplikac\u00ED\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: DivX OVS Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.4_0\
CHR - Extension: Yontoo Layers = C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.1_0\
CHR - Extension: Evolved Online hry = C:\Documents and Settings\Mike\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nkdaebmimnhlmgpjoppmdeokffoahpan\3.0.3_0\

O1 HOSTS File: ([2011.12.03 09:02:34 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {055FD26D-3A88-4e15-963D-DC8493744B1D} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O2 - BHO: (no name) - {998A3C0C-8914-4D2A-AE36-BFA2E5AE6D5D} - No CLSID value found.
O2 - BHO: (no name) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - No CLSID value found.
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTo2.dll (Conduit Ltd.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" File not found
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe (Acer Inc.)
O4 - HKLM..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe (COMODO)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe (COMODO)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe File not found
O4 - HKLM..\Run: [Free PDF Print Dispatcher] C:\Program Files\pdfconverter.com\FreePDF Creator\itFPCPrnDisp.exe (pdfconverter.com)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\Windows\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files\Olympus\ib\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [MSPY2002] C:\Windows\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
O4 - HKLM..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [Olympus ib] C:\Program Files\Olympus\ib\olycamdetect.exe (OLYMPUS IMAGING CORP.)
O4 - HKLM..\Run: [PC-Checkup] "C:\Program Files\Speeditup Free\PCCheckUp\PCCheckUp.exe" -mini File not found
O4 - HKLM..\Run: [PCMService] C:\Program Files\CyberLink\PowerCinema\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\Windows\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\Windows\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SMail] "C:\Program Files\Seznam\Postak\Postak.exe" File not found
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe File not found
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe (X-Micro Technology Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-1509661768-2596670817-2537616161-1012\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/200 ... oader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDow ... ab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {3190CE28-0B6E-4133-A7D3-87D29CB92120} http://software.seznam.cz/listicka/toolbar.cab (ToolbarInetInstall Control)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/v ... .2.4.8.cab (DLM Control)
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab (ImageShack Toolbar)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/200 ... ader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} http://service.futuremark.com/gom/receiver/tc/FMSI.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{83720A68-9FD4-4E19-B389-7845301CA38B}: DhcpNameServer = 81.27.192.33 81.27.192.97 89.102.0.238
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D96309E3-C34D-47E5-A426-1F7ABBF87FF8}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D96309E3-C34D-47E5-A426-1F7ABBF87FF8}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - File not found
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {097F10A7-487F-4457-AB1F-827C59479A72} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011.12.04 16:34:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\Terezka
[2011.12.03 09:02:22 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.12.02 18:57:08 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mike\Plocha\OTL.exe
[2011.12.01 21:17:14 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011.11.30 03:03:51 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Mike\Recent
[2011.11.30 02:56:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Nabídka Start\Programy\CCleaner
[2011.11.30 02:56:34 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.11.30 02:55:58 | 001,187,896 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Mike\Plocha\ccleaner.exe
[2011.11.30 02:49:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\CPA_VA
[2011.11.30 02:41:52 | 000,155,536 | ---- | C] (Protection Technology (StarForce)) -- C:\Documents and Settings\Mike\Plocha\sfdrvrem.exe
[2011.11.29 20:50:49 | 063,338,168 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Mike\Plocha\PowerPointViewer.exe
[2011.11.28 23:40:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Dokumenty\My Digital Editions
[2011.11.27 10:25:32 | 000,000,000 | -H-D | C] -- C:\VritualRoot
[2011.11.27 10:24:21 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011.11.27 10:18:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\COMODO
[2011.11.27 10:16:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Comodo
[2011.11.27 10:16:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\COMODO
[2011.11.27 10:16:02 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2011.11.27 10:14:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
[2011.11.27 10:12:59 | 061,667,536 | ---- | C] (COMODO) -- C:\Documents and Settings\Mike\Plocha\cav_installer.exe
[2011.11.27 09:31:50 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011.11.26 21:08:04 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab
[2011.11.26 00:21:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\blabla
[2011.11.24 15:43:54 | 000,222,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2011.11.24 15:41:45 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Defender
[2011.11.24 15:20:50 | 000,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
[2011.11.24 15:10:54 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011.11.24 15:09:12 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011.11.24 15:09:12 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011.11.24 15:09:12 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011.11.24 15:09:12 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011.11.24 15:09:04 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011.11.24 15:09:01 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.11.24 15:04:08 | 004,324,789 | R--- | C] (Swearware) -- C:\Documents and Settings\Mike\Plocha\ComboFix.exe
[2011.11.24 14:22:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\RK_Quarantine
[2011.11.24 14:12:37 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2011.11.24 14:09:27 | 001,566,512 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Mike\Plocha\tdsskiller.exe
[2011.11.24 12:07:29 | 000,000,000 | -H-D | C] -- C:\Windows\ie8
[2011.11.24 10:46:06 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NIS
[2011.11.24 10:46:06 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NIS\1301000.01C
[2011.11.24 10:10:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\NPE
[2011.11.24 08:21:38 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.11.24 08:21:38 | 000,000,000 | ---D | C] -- C:\rsit
[2011.11.23 22:37:44 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NAV
[2011.11.23 22:37:44 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NAV\1301000.01C
[2011.11.23 15:27:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\PCSettings
[2011.11.23 14:41:07 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2011.11.23 12:33:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Data aplikací\EurekaLog
[2011.11.23 07:42:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\EmsisoftEmergencyKit
[2011.11.23 03:05:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Data aplikací\Uniblue
[2011.11.23 03:05:51 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2011.11.23 03:05:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\PackageAware
[2011.11.23 02:40:26 | 000,000,000 | ---D | C] -- C:\RRTVAULT
[2011.11.23 02:35:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Emsisoft Anti-Malware
[2011.11.23 02:35:35 | 000,000,000 | ---D | C] -- C:\Program Files\Emsisoft Anti-Malware
[2011.11.23 02:35:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Dokumenty\Anti-Malware
[2011.11.21 21:19:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Data aplikací\Malwarebytes
[2011.11.21 21:19:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.11.21 21:07:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Data aplikací\QuickScan
[2011.11.20 22:29:37 | 000,000,000 | ---D | C] -- C:\WeruFoto
[2011.11.20 22:19:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Media Get LLC
[2011.11.20 15:37:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam
[2011.11.20 15:37:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabdka Start
[2011.11.20 15:37:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Steam
[2011.11.20 15:37:01 | 000,000,000 | ---D | C] -- C:\Program Files\Steam
[2011.11.20 11:43:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Data aplikací\NVIDIA
[2011.11.20 11:07:25 | 000,602,432 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\easyupdatusapiu.dll
[2011.11.20 11:05:55 | 000,877,376 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvgenco32.dll
[2011.11.20 11:05:54 | 000,919,872 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco32.dll
[2011.11.20 11:01:20 | 089,643,496 | ---- | C] (NVIDIA Corporation) -- C:\Documents and Settings\Mike\Plocha\285.58-desktop-winxp-32bit-english-whql.exe
[2011.11.20 10:54:32 | 000,000,000 | ---D | C] -- C:\ATI
[2011.11.19 11:30:09 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll
[2011.11.19 11:30:09 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll
[2011.11.19 11:30:08 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll
[2011.11.19 11:30:07 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_43.dll
[2011.11.19 11:30:07 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll
[2011.11.19 11:30:06 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll
[2011.11.19 11:30:06 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll
[2011.11.19 11:30:05 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll
[2011.11.18 20:37:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\QuickTime
[2011.11.18 20:37:19 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011.11.18 20:30:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\iTunes
[2011.11.18 20:28:56 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.11.18 20:28:49 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011.11.18 09:40:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\FreeRapid-0.86u1
[2011.11.14 22:02:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\Výstava TOP 10
[2011.11.14 21:13:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\FOTO výstava
[2011.11.12 23:20:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\bbtcz-s05e09_v1
[2011.11.10 16:45:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\PACK
[2011.11.06 16:46:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mike\Plocha\bbtcz-s05e08_v1
[2010.09.27 16:24:50 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[2008.06.16 01:39:45 | 000,032,768 | ---- | C] ( ) -- C:\Windows\System32\Interop.ShockwaveFlashObjects.dll
[2008.02.10 21:52:34 | 000,159,616 | ---- | C] ( ) -- C:\Windows\System32\drivers\vax347b.sys
[2008.02.10 21:52:34 | 000,005,248 | ---- | C] ( ) -- C:\Windows\System32\drivers\vax347s.sys
[2007.05.11 08:57:21 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Mike\Data aplikací\pcouffin.sys
[2007.01.08 19:54:55 | 000,016,384 | ---- | C] ( ) -- C:\Windows\System32\ClearEvent.exe
[2007.01.08 19:53:15 | 000,049,152 | ---- | C] ( ) -- C:\Windows\System32\SysMonitor.exe
[4 C:\Documents and Settings\All Users\Data aplikací\*.tmp files -> C:\Documents and Settings\All Users\Data aplikací\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.12.04 19:56:33 | 000,000,284 | ---- | M] () -- C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-1509661768-2596670817-2537616161-1006.job
[2011.12.04 19:56:33 | 000,000,276 | ---- | M] () -- C:\Windows\tasks\RealUpgradeLogonTaskS-1-5-21-1509661768-2596670817-2537616161-1006.job
[2011.12.04 19:39:06 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011.12.04 17:05:22 | 000,000,442 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2011.12.04 17:04:01 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011.12.04 17:03:58 | 000,000,294 | ---- | M] () -- C:\Windows\tasks\RealUpgradeLogonTaskS-1-5-21-1509661768-2596670817-2537616161-500.job
[2011.12.04 17:03:47 | 000,002,048 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.12.04 17:03:42 | 2952,318,976 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.04 02:00:06 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\AdobeAAMUpdater-1.0-ACER-64B9BF4930-Mike.job
[2011.12.03 21:17:46 | 000,242,688 | ---- | M] () -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.12.03 19:01:50 | 000,244,368 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\config.jpg
[2011.12.03 10:04:26 | 000,286,052 | ---- | M] () -- C:\Windows\System32\nvdrsdb1.bin
[2011.12.03 10:04:26 | 000,000,001 | ---- | M] () -- C:\Windows\System32\nvdrssel.bin
[2011.12.03 10:04:22 | 000,286,052 | ---- | M] () -- C:\Windows\System32\nvdrsdb0.bin
[2011.12.03 09:02:34 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2011.12.02 19:45:17 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011.12.02 18:57:11 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mike\Plocha\OTL.exe
[2011.12.01 21:35:29 | 000,177,871 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\CF02.jpg
[2011.12.01 21:34:43 | 000,473,227 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\CF01.jpg
[2011.12.01 21:16:11 | 004,324,789 | R--- | M] (Swearware) -- C:\Documents and Settings\Mike\Plocha\ComboFix.exe
[2011.12.01 21:15:17 | 001,474,832 | ---- | M] () -- C:\Windows\System32\drivers\sfi.dat
[2011.11.30 03:02:49 | 104,118,768 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\setup_11.0.0.1245.x01_2011_11_30_04_06.exe
[2011.11.30 02:56:35 | 000,000,686 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\CCleaner.lnk
[2011.11.30 02:56:00 | 001,187,896 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Mike\Plocha\ccleaner.exe
[2011.11.30 02:46:22 | 003,783,864 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.11.29 21:10:49 | 063,338,168 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Mike\Plocha\PowerPointViewer.exe
[2011.11.29 20:29:09 | 000,177,602 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\scsi-raid.jpg
[2011.11.28 23:39:48 | 000,001,823 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Adobe Digital Editions.lnk
[2011.11.27 22:34:41 | 000,108,057 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Comodo-2011-11-27.jpg
[2011.11.27 10:16:17 | 000,001,653 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\COMODO Internet Security.lnk
[2011.11.27 10:13:03 | 061,667,536 | ---- | M] (COMODO) -- C:\Documents and Settings\Mike\Plocha\cav_installer.exe
[2011.11.27 09:51:18 | 000,001,158 | ---- | M] () -- C:\Windows\System32\wpa.dbl
[2011.11.25 22:31:19 | 000,002,504 | ---- | M] () -- C:\Windows\System32\CONFIG.NT
[2011.11.25 22:01:11 | 061,657,056 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\setup_av_free.exe
[2011.11.24 15:20:59 | 000,000,302 | ---- | M] () -- C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-1509661768-2596670817-2537616161-500.job
[2011.11.24 15:11:00 | 000,001,067 | RHS- | M] () -- C:\BOOT.INI
[2011.11.24 14:56:55 | 000,218,081 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\310950_292433550789279_183813598317942_966443_201572440_n.jpg
[2011.11.24 14:21:50 | 000,766,976 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\RogueKiller.exe
[2011.11.24 14:09:28 | 001,566,512 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Mike\Plocha\tdsskiller.exe
[2011.11.24 11:24:46 | 000,663,017 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1301000.01C\Cat.DB
[2011.11.23 22:44:57 | 000,663,017 | ---- | M] () -- C:\Windows\System32\drivers\NAV\1301000.01C\Cat.DB
[2011.11.23 12:28:09 | 000,279,097 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Emsisoft_resume.jpg
[2011.11.23 12:24:41 | 000,155,355 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Emsisoft_upozorneni.jpg
[2011.11.23 09:10:17 | 000,195,258 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\emisoft-malware.jpg
[2011.11.23 07:02:41 | 000,000,950 | ---- | M] () -- C:\Boot.bak
[2011.11.23 03:11:33 | 000,575,040 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.11.23 03:11:33 | 000,570,302 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2011.11.23 03:11:33 | 000,132,326 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2011.11.23 03:11:33 | 000,117,220 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.11.23 02:40:26 | 000,004,107 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\ihfeumzb.qzk
[2011.11.23 02:35:55 | 000,000,770 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Emsisoft Anti-Malware.lnk
[2011.11.21 17:23:38 | 000,000,215 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Might and Magic Clash of Heroes.url
[2011.11.21 17:05:24 | 000,001,324 | ---- | M] () -- C:\Windows\System32\d3d9caps.dat
[2011.11.21 09:53:23 | 029,431,948 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Applied_Multivariate_Statistics_for_the_Social_Sciences__Fifth_Edition.pdf
[2011.11.21 09:41:30 | 002,566,722 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advanced_Quantative_Data_Analysis__Understanding_Socialresearch_.pdf
[2011.11.20 17:28:54 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdw.DAT
[2011.11.20 15:37:04 | 000,000,668 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Steam.lnk
[2011.11.20 11:07:13 | 000,000,000 | ---- | M] () -- C:\Windows\System32\nvdrswr.lk
[2011.11.20 11:04:19 | 089,643,496 | ---- | M] (NVIDIA Corporation) -- C:\Documents and Settings\Mike\Plocha\285.58-desktop-winxp-32bit-english-whql.exe
[2011.11.20 10:56:27 | 000,276,951 | ---- | M] () -- C:\Windows\System32\NvApps.xml
[2011.11.19 11:42:34 | 011,276,288 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\sandra.mda
[2011.11.19 11:28:55 | 000,001,049 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\SiSoftware Sandra Lite (Eval) 2012.lnk
[2011.11.18 23:44:04 | 000,026,120 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\The.Big.Bang.Theory.S05E10.The.Flaming.Spittoon.Acquisitoin.720p.WEB-DL.DD5.1.H.264-CtrlHD.srt
[2011.11.18 23:41:46 | 000,026,116 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\The.Big.Bang.Theory.S05E10.HDTV.XviD-ASAP.srt
[2011.11.18 20:30:29 | 000,001,546 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\iTunes.lnk
[2011.11.18 16:58:03 | 000,000,284 | ---- | M] () -- C:\Windows\tasks\AppleSoftwareUpdate.job
[2011.11.17 17:21:31 | 001,306,913 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__The_Foundations_of_Statistics__A_Simulation_based_Approach.pdf
[2011.11.17 17:21:04 | 006,388,481 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advances_in_Social_Science_Research_Using_R.pdf
[2011.11.17 17:20:59 | 007,783,134 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advances_in_Social_Science_Research_Using_R__Lecture_Notes_in_Statistics___Lecture_Notes_in_Statistics___Proceedings_.pdf
[2011.11.17 17:20:04 | 005,447,860 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__A_First_Course_in_Bayesian_Statistical_Methods__Springer_Texts_in_Statistics_.pdf
[2011.11.17 17:19:38 | 002,337,366 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Semiparametric_Regression_for_the_Social_Sciences.pdf
[2011.11.17 17:19:19 | 004,359,769 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Introduction_to_Applied_Bayesian_Statistics_and_Estimation_for_Social_Scientists__Statistics_for_Social_and_Behavioral_Sciences_.pdf
[2011.11.15 23:01:38 | 000,151,120 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Mia&DAx.JPG
[2011.11.15 09:23:32 | 000,000,116 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2011.11.14 12:21:00 | 002,538,109 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\DSC_0313.JPG
[2011.11.14 11:57:12 | 025,871,016 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\SilverEfexPro2-l-ver2.002all.exe
[2011.11.13 23:28:14 | 000,204,340 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\cats.jpg
[2011.11.13 23:27:48 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\padFB.jpg
[2011.11.13 23:27:14 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\pádFB.jpg
[2011.11.11 23:48:11 | 000,648,331 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\DSC_0313_SilverEf_2.jpg
[2011.11.10 18:33:21 | 000,004,714 | ---- | M] () -- C:\Windows\wincmd.ini
[2011.11.10 08:33:07 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLet.DAT
[2011.11.07 22:53:17 | 000,108,544 | -H-- | M] () -- C:\Documents and Settings\Mike\Plocha\photothumb.db
[2011.11.06 14:12:43 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdu.DAT
[2011.11.06 13:55:41 | 000,000,734 | ---- | M] () -- C:\Documents and Settings\Mike\Plocha\Mozilla Firefox.lnk
[4 C:\Documents and Settings\All Users\Data aplikací\*.tmp files -> C:\Documents and Settings\All Users\Data aplikací\*.tmp -> ]

W.Mia
Návštěvník
Návštěvník
Příspěvky: 42
Registrován: 24 Lis 2011 08:29

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#43 Příspěvek od W.Mia »

Druhá část logu je tu:

========== Files Created - No Company Name ==========

[2011.12.03 19:01:50 | 000,244,368 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\config.jpg
[2011.12.02 19:45:17 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2011.12.01 21:35:29 | 000,177,871 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\CF02.jpg
[2011.12.01 21:34:42 | 000,473,227 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\CF01.jpg
[2011.11.30 02:57:09 | 104,118,768 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\setup_11.0.0.1245.x01_2011_11_30_04_06.exe
[2011.11.30 02:56:35 | 000,000,686 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\CCleaner.lnk
[2011.11.29 21:16:23 | 000,001,946 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Microsoft PowerPoint Viewer .lnk
[2011.11.29 20:29:09 | 000,177,602 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\scsi-raid.jpg
[2011.11.28 23:39:48 | 000,001,823 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Adobe Digital Editions.lnk
[2011.11.27 22:34:41 | 000,108,057 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\Comodo-2011-11-27.jpg
[2011.11.27 10:17:52 | 001,474,832 | ---- | C] () -- C:\Windows\System32\drivers\sfi.dat
[2011.11.27 10:16:17 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\COMODO Internet Security.lnk
[2011.11.27 09:32:35 | 2952,318,976 | -HS- | C] () -- C:\hiberfil.sys
[2011.11.25 21:58:50 | 061,657,056 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\setup_av_free.exe
[2011.11.24 15:41:45 | 000,000,981 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Windows Defender.lnk
[2011.11.24 15:11:00 | 000,000,950 | ---- | C] () -- C:\Boot.bak
[2011.11.24 15:10:58 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2011.11.24 15:09:12 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011.11.24 15:09:12 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011.11.24 15:09:12 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.11.24 15:09:12 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.11.24 15:09:12 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.11.24 14:56:54 | 000,218,081 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\310950_292433550789279_183813598317942_966443_201572440_n.jpg
[2011.11.24 14:21:49 | 000,766,976 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\RogueKiller.exe
[2011.11.24 12:13:21 | 000,000,302 | ---- | C] () -- C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-1509661768-2596670817-2537616161-500.job
[2011.11.24 12:13:21 | 000,000,294 | ---- | C] () -- C:\Windows\tasks\RealUpgradeLogonTaskS-1-5-21-1509661768-2596670817-2537616161-500.job
[2011.11.24 11:24:27 | 000,663,017 | ---- | C] () -- C:\Windows\System32\drivers\NIS\1301000.01C\Cat.DB
[2011.11.23 23:52:17 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\Mike\Nabídka Start\Programy\Outlook Express.lnk
[2011.11.23 22:44:44 | 000,663,017 | ---- | C] () -- C:\Windows\System32\drivers\NAV\1301000.01C\Cat.DB
[2011.11.23 12:28:09 | 000,279,097 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\Emsisoft_resume.jpg
[2011.11.23 12:24:41 | 000,155,355 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\Emsisoft_upozorneni.jpg
[2011.11.23 09:10:17 | 000,195,258 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\emisoft-malware.jpg
[2011.11.23 07:02:38 | 000,000,800 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer WLAN 11g USB Dongle.lnk
[2011.11.23 03:11:30 | 000,000,807 | ---- | C] () -- C:\Documents and Settings\Mike\Nabídka Start\Programy\Internet Explorer.lnk
[2011.11.23 02:40:26 | 000,004,107 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ihfeumzb.qzk
[2011.11.23 02:35:54 | 000,000,770 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Emsisoft Anti-Malware.lnk
[2011.11.21 17:23:36 | 000,000,215 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\Might and Magic Clash of Heroes.url
[2011.11.21 09:52:22 | 029,431,948 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Applied_Multivariate_Statistics_for_the_Social_Sciences__Fifth_Edition.pdf
[2011.11.21 09:41:27 | 002,566,722 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advanced_Quantative_Data_Analysis__Understanding_Socialresearch_.pdf
[2011.11.20 17:49:13 | 004,318,049 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0027_002.JPG
[2011.11.20 17:49:12 | 011,021,141 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0027_002.NEF
[2011.11.20 17:49:09 | 004,148,902 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0023_001.JPG
[2011.11.20 17:49:08 | 010,801,184 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0023_001.NEF
[2011.11.20 17:48:04 | 003,448,376 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0052.JPG
[2011.11.20 17:48:03 | 010,602,195 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0052.NEF
[2011.11.20 17:48:01 | 010,558,701 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0051.NEF
[2011.11.20 17:48:01 | 003,406,205 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0051.JPG
[2011.11.20 17:48:01 | 003,283,367 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0047.JPG
[2011.11.20 17:47:59 | 010,623,342 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0047.NEF
[2011.11.20 17:47:59 | 003,294,739 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0039.JPG
[2011.11.20 17:47:58 | 010,530,015 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0039.NEF
[2011.11.20 17:47:58 | 003,822,680 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0036.JPG
[2011.11.20 17:47:56 | 010,718,800 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0036.NEF
[2011.11.20 17:47:56 | 003,862,069 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0035.JPG
[2011.11.20 17:47:54 | 010,729,932 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0035.NEF
[2011.11.20 17:47:54 | 003,575,502 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0033.JPG
[2011.11.20 17:47:53 | 010,688,515 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0033.NEF
[2011.11.20 17:47:52 | 004,088,438 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0030.JPG
[2011.11.20 17:47:51 | 010,900,742 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0030.NEF
[2011.11.20 17:47:51 | 004,318,049 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0027.JPG
[2011.11.20 17:47:44 | 004,148,902 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0023.JPG
[2011.11.20 17:37:24 | 008,757,039 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0027.NEF
[2011.11.20 17:37:21 | 009,663,154 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0025.NEF
[2011.11.20 17:37:19 | 009,866,269 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0024.NEF
[2011.11.20 17:37:19 | 009,745,193 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0023.NEF
[2011.11.20 17:37:18 | 009,797,663 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0022.NEF
[2011.11.20 15:37:04 | 000,000,668 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Steam.lnk
[2011.11.20 11:07:13 | 000,286,052 | ---- | C] () -- C:\Windows\System32\nvdrsdb1.bin
[2011.11.20 11:07:13 | 000,286,052 | ---- | C] () -- C:\Windows\System32\nvdrsdb0.bin
[2011.11.20 11:07:13 | 000,000,001 | ---- | C] () -- C:\Windows\System32\nvdrssel.bin
[2011.11.20 11:07:13 | 000,000,000 | ---- | C] () -- C:\Windows\System32\nvdrswr.lk
[2011.11.20 11:05:55 | 000,003,250 | ---- | C] () -- C:\Windows\System32\nvinfo.pb
[2011.11.20 11:05:54 | 002,130,002 | ---- | C] () -- C:\Windows\System32\nvdata.data
[2011.11.19 21:01:37 | 000,026,120 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\The.Big.Bang.Theory.S05E10.The.Flaming.Spittoon.Acquisitoin.720p.WEB-DL.DD5.1.H.264-CtrlHD.srt
[2011.11.19 21:01:37 | 000,026,116 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\The.Big.Bang.Theory.S05E10.HDTV.XviD-ASAP.srt
[2011.11.19 11:28:55 | 000,001,049 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\SiSoftware Sandra Lite (Eval) 2012.lnk
[2011.11.18 20:30:29 | 000,001,546 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\iTunes.lnk
[2011.11.17 17:21:30 | 001,306,913 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__The_Foundations_of_Statistics__A_Simulation_based_Approach.pdf
[2011.11.17 17:21:03 | 006,388,481 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advances_in_Social_Science_Research_Using_R.pdf
[2011.11.17 17:20:59 | 007,783,134 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Advances_in_Social_Science_Research_Using_R__Lecture_Notes_in_Statistics___Lecture_Notes_in_Statistics___Proceedings_.pdf
[2011.11.17 17:19:59 | 005,447,860 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__A_First_Course_in_Bayesian_Statistical_Methods__Springer_Texts_in_Statistics_.pdf
[2011.11.17 17:19:37 | 002,337,366 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Semiparametric_Regression_for_the_Social_Sciences.pdf
[2011.11.17 17:19:17 | 004,359,769 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\ebooksclub.org__Introduction_to_Applied_Bayesian_Statistics_and_Estimation_for_Social_Scientists__Statistics_for_Social_and_Behavioral_Sciences_.pdf
[2011.11.15 23:01:38 | 000,151,120 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\Mia&DAx.JPG
[2011.11.14 11:53:32 | 025,871,016 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\SilverEfexPro2-l-ver2.002all.exe
[2011.11.13 23:28:14 | 000,204,340 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\cats.jpg
[2011.11.13 23:27:48 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\padFB.jpg
[2011.11.13 23:27:14 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\pádFB.jpg
[2011.11.11 23:46:47 | 000,648,331 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0313_SilverEf_2.jpg
[2011.11.11 23:21:46 | 002,538,109 | ---- | C] () -- C:\Documents and Settings\Mike\Plocha\DSC_0313.JPG
[2011.10.27 08:33:04 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Kernel Extension
[2011.10.27 08:33:04 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Iterate Items
[2011.10.27 08:31:21 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Keyboard Layouts
[2011.10.27 08:31:20 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Jingles
[2011.06.25 07:55:42 | 000,000,788 | RH-- | C] () -- C:\Windows\System32\ttri.dat
[2011.05.27 07:50:15 | 000,288,048 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2011.05.26 14:28:25 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Adobe Formát GIF CS5 – předvolby
[2011.05.25 11:59:56 | 001,896,234 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1509661768-2596670817-2537616161-1006-0.dat
[2011.05.21 23:58:53 | 000,478,898 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
[2011.05.15 08:22:30 | 000,138,264 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.05.15 08:22:30 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\PnkBstrK.sys
[2011.05.15 08:22:09 | 000,234,768 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.05.15 08:22:06 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011.05.02 10:46:03 | 000,004,096 | ---- | C] () -- C:\Windows\System32\HDREfexProFC64.dll
[2011.04.18 07:03:10 | 000,004,608 | ---- | C] () -- C:\Windows\System32\SilverEfexPro2FC64.dll
[2011.04.13 19:16:16 | 039,289,424 | -HS- | C] () -- C:\Windows\setupa.exe
[2011.03.29 23:17:10 | 000,316,928 | ---- | C] () -- C:\Windows\System32\HDREfexProFC32.dll
[2011.03.28 21:36:51 | 000,000,848 | ---- | C] () -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\SRDownloader.nast
[2011.03.11 10:27:20 | 000,000,754 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2011.02.21 22:17:34 | 000,003,584 | ---- | C] () -- C:\Windows\System32\SilverEfexPro2FC32.dll
[2011.01.29 17:00:24 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011.01.29 17:00:22 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011.01.29 17:00:22 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011.01.29 17:00:22 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011.01.29 17:00:22 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2010.12.12 00:45:16 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2010.12.12 00:45:16 | 000,036,640 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2010.12.11 22:38:36 | 000,139,264 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010.12.11 16:00:59 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\$_hpcst$.hpc
[2010.12.01 17:27:19 | 000,108,032 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010.11.06 18:08:31 | 000,116,224 | ---- | C] () -- C:\Windows\System32\pdfcmnnt.dll
[2010.10.04 06:39:45 | 000,000,000 | ---- | C] () -- C:\Windows\ViewNX2.INI
[2010.10.04 06:34:41 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Jazz
[2010.10.04 06:34:41 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Internet Services
[2010.10.04 06:34:41 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLev.DAT
[2010.10.04 06:34:41 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLet.DAT
[2010.10.04 06:34:41 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLes.DAT
[2010.10.03 18:02:21 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Rule Actions
[2010.10.03 18:02:21 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Reverb
[2010.10.03 18:02:21 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLck.DAT
[2010.10.03 18:02:21 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Alerts
[2010.10.03 18:02:19 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Sample Delay
[2010.10.03 18:02:19 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Ambient
[2010.10.03 14:28:15 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Hybrid Basic
[2010.10.03 14:09:15 | 000,057,344 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\chrtmp
[2010.10.03 13:42:45 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Robot
[2010.10.03 12:26:58 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLbx.DAT
[2010.06.19 19:30:20 | 000,000,000 | ---- | C] () -- C:\Windows\ViewNX.INI
[2010.06.19 19:15:53 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Internet Plug-Ins
[2010.06.19 19:15:53 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Importer
[2010.06.19 19:15:53 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdw.DAT
[2010.06.19 19:14:35 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\Installer Plugin
[2010.06.19 19:14:35 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Mike\Data aplikací\Image Units
[2010.06.19 19:14:35 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\PKP_DLdu.DAT
[2010.06.06 10:10:44 | 011,276,288 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\sandra.mda
[2010.05.11 15:55:26 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010.04.03 21:55:32 | 002,183,470 | ---- | C] () -- C:\Windows\System32\nvdata.bin
[2010.03.25 12:41:45 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\inst.exe
[2010.01.16 21:30:31 | 000,001,196 | ---- | C] () -- C:\Windows\VFO.INI
[2009.12.30 15:00:32 | 000,146,412 | ---- | C] () -- C:\Windows\System32\vilaunch.exe
[2009.12.30 14:56:58 | 000,111,104 | ---- | C] () -- C:\Windows\System32\Uharc.exe
[2009.12.30 14:56:58 | 000,069,632 | ---- | C] () -- C:\Windows\System32\moveex.exe
[2009.12.30 14:56:58 | 000,008,636 | ---- | C] () -- C:\Windows\System32\modifype.exe
[2009.12.25 22:42:41 | 000,003,140 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
[2009.07.07 10:27:33 | 000,000,324 | ---- | C] () -- C:\Windows\game.ini
[2009.05.04 19:53:53 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2009.02.13 15:54:46 | 000,008,192 | ---- | C] () -- C:\Windows\d3dx.dat
[2009.01.24 15:14:29 | 000,000,059 | ---- | C] () -- C:\Windows\pdf2image.INI
[2009.01.24 02:05:16 | 000,001,024 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\imgpdf2.dll
[2008.12.28 13:31:00 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat
[2008.12.06 19:07:24 | 000,000,000 | ---- | C] () -- C:\Windows\pcfriend.INI
[2008.11.12 13:48:37 | 000,000,168 | RHS- | C] () -- C:\Windows\System32\D404ACE5F9.sys
[2008.11.12 13:43:24 | 000,002,828 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2008.11.12 13:16:15 | 000,114,351 | ---- | C] () -- C:\Windows\hpqins13.dat
[2008.10.26 15:17:12 | 000,000,014 | ---- | C] () -- C:\Windows\dswplug.ini
[2008.10.20 21:36:52 | 000,000,186 | ---- | C] () -- C:\Windows\wininit.ini
[2008.10.20 16:30:22 | 000,069,632 | R--- | C] () -- C:\Windows\System32\xmltok.dll
[2008.10.20 16:30:22 | 000,036,864 | R--- | C] () -- C:\Windows\System32\xmlparse.dll
[2008.10.20 08:55:43 | 000,000,751 | ---- | C] () -- C:\Windows\Rtcwplat.INI
[2008.10.07 08:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008.10.07 08:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008.08.31 08:59:23 | 000,000,176 | ---- | C] () -- C:\Windows\Swish.INI
[2008.08.20 02:07:02 | 000,035,328 | ---- | C] () -- C:\Windows\System32\ztLib.dll
[2008.08.10 19:30:05 | 000,000,010 | ---- | C] () -- C:\Windows\THECRO~1.DAT
[2008.08.10 19:29:46 | 000,188,043 | ---- | C] () -- C:\Windows\The Crow Comic Screen Saver.exe
[2008.08.10 19:29:46 | 000,058,690 | ---- | C] () -- C:\Windows\BINS.EXE
[2008.08.10 19:29:46 | 000,000,817 | ---- | C] () -- C:\Windows\The Crow Comic Screen Saver.ini
[2008.08.10 17:51:33 | 000,076,288 | ---- | C] () -- C:\Windows\System32\OneWaySerial.dll
[2008.07.07 13:50:00 | 000,354,816 | ---- | C] () -- C:\Windows\System32\psisdecd.dll
[2008.06.16 01:39:45 | 000,028,672 | ---- | C] () -- C:\Windows\System32\AxInterop.ShockwaveFlashObjects.dll
[2008.03.29 15:32:23 | 000,000,040 | ---- | C] () -- C:\Windows\DCheck95.ini
[2008.03.11 16:38:43 | 000,278,984 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2008.03.11 16:38:43 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2008.03.11 00:51:36 | 000,162,432 | ---- | C] () -- C:\Windows\System32\drivers\ithsgt.sys
[2008.03.11 00:51:36 | 000,012,032 | ---- | C] () -- C:\Windows\System32\drivers\lilsgt.sys
[2008.01.29 17:04:59 | 000,074,703 | ---- | C] () -- C:\Windows\System32\mfc45.dll
[2008.01.05 22:48:45 | 000,003,972 | ---- | C] () -- C:\Windows\System32\drivers\PciBus.sys
[2007.12.23 17:53:01 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2007.12.22 11:05:34 | 000,000,107 | ---- | C] () -- C:\Windows\Sansa Media Converter.INI
[2007.12.09 13:05:25 | 000,000,525 | ---- | C] () -- C:\Windows\eReg.dat
[2007.10.23 08:56:52 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2007.10.23 08:56:51 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2007.10.23 08:56:51 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
[2007.10.23 08:56:51 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
[2007.10.23 08:56:51 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2007.10.23 08:56:51 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2007.10.23 08:56:51 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2007.10.23 08:56:51 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2007.10.23 08:56:51 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2007.10.23 08:56:51 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2007.10.23 08:56:51 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
[2007.10.23 08:56:51 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2007.10.23 08:56:51 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2007.10.23 08:56:51 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2007.10.23 08:56:51 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2007.10.23 08:56:51 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2007.10.23 08:56:51 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
[2007.10.23 08:56:51 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
[2007.10.23 08:56:51 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2007.07.12 17:14:30 | 000,319,488 | ---- | C] () -- C:\Windows\System32\MafiaSetup.exe
[2007.06.05 13:20:32 | 000,177,704 | ---- | C] () -- C:\Windows\System32\PSIService.exe
[2007.06.02 10:46:32 | 000,153,840 | ---- | C] () -- C:\Windows\System32\ARThumb.dll
[2007.05.14 21:25:07 | 000,000,026 | ---- | C] () -- C:\Windows\System32\satsukidecodersettings.ini
[2007.05.12 17:09:59 | 001,537,536 | ---- | C] () -- C:\Windows\System32\erdmpg-hi.dll
[2007.05.12 17:09:59 | 000,584,192 | ---- | C] () -- C:\Windows\System32\AdaptX30.dll
[2007.05.12 17:09:59 | 000,360,448 | ---- | C] () -- C:\Windows\System32\erdmpg-lo.dll
[2007.05.12 17:09:59 | 000,147,456 | ---- | C] () -- C:\Windows\System32\AVICreator.dll
[2007.05.12 17:09:59 | 000,135,168 | ---- | C] () -- C:\Windows\System32\MPEGCreator.dll
[2007.05.12 17:09:59 | 000,046,080 | ---- | C] () -- C:\Windows\System32\ac3encode.dll
[2007.05.12 17:09:59 | 000,043,008 | ---- | C] () -- C:\Windows\System32\KillUserBp.dll
[2007.05.12 17:09:58 | 000,270,336 | ---- | C] () -- C:\Windows\System32\WMVCreator.dll
[2007.05.12 16:04:37 | 000,000,220 | -HS- | C] () -- C:\Windows\dwin.sys
[2007.05.12 15:56:14 | 000,233,472 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2007.05.12 15:56:14 | 000,053,248 | ---- | C] () -- C:\Windows\System32\dcfft2.dll
[2007.05.12 15:56:14 | 000,021,504 | ---- | C] () -- C:\Windows\System32\wnaspi32.dll
[2007.05.11 08:57:21 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\ezpinst.exe
[2007.05.11 08:57:21 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\pcouffin.cat
[2007.05.11 08:57:21 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Mike\Data aplikací\pcouffin.inf
[2007.04.19 16:51:11 | 000,001,324 | ---- | C] () -- C:\Windows\System32\d3d9caps.dat
[2007.04.17 14:34:40 | 000,135,716 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2007.04.17 06:57:03 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2007.04.04 13:47:41 | 000,028,672 | ---- | C] () -- C:\Windows\System32\Alpha.dll
[2007.04.04 11:34:24 | 000,000,280 | ---- | C] () -- C:\Windows\mgutil_reg.ini
[2007.04.04 11:33:32 | 000,000,044 | ---- | C] () -- C:\Windows\mgutil_win.ini
[2007.03.31 22:54:26 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2007.03.13 09:25:31 | 000,000,112 | ---- | C] () -- C:\Windows\ActiveSkin.INI
[2007.03.13 09:25:11 | 000,017,268 | ---- | C] () -- C:\Windows\CDPlayer.ini
[2007.02.22 23:40:21 | 000,001,747 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\QTSBandwidthCache
[2007.02.11 00:05:55 | 000,000,157 | ---- | C] () -- C:\Windows\ADStahovac.INI
[2007.02.10 22:18:44 | 000,131,072 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2007.01.11 21:10:14 | 000,084,204 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2007.01.11 20:58:03 | 000,242,688 | ---- | C] () -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.01.11 08:59:25 | 000,000,332 | ---- | C] () -- C:\Windows\wcx_ftp.ini
[2007.01.11 00:07:34 | 000,001,477 | ---- | C] () -- C:\Windows\level.ini
[2007.01.11 00:07:34 | 000,001,158 | ---- | C] () -- C:\Windows\tmp2Level.ini
[2007.01.09 22:24:26 | 000,000,390 | ---- | C] () -- C:\Windows\ODBC.INI
[2007.01.09 00:50:08 | 000,000,124 | ---- | C] () -- C:\Documents and Settings\Mike\Local Settings\Data aplikací\fusioncache.dat
[2007.01.08 23:03:23 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2007.01.08 21:05:59 | 000,000,192 | ---- | C] () -- C:\Windows\winamp.ini
[2007.01.08 20:53:23 | 000,004,714 | ---- | C] () -- C:\Windows\wincmd.ini
[2007.01.08 19:57:49 | 000,198,144 | ---- | C] () -- C:\Windows\System32\_psisdecd.dll
[2007.01.08 19:55:23 | 000,114,688 | ---- | C] () -- C:\Windows\PowerOption.exe
[2007.01.08 19:55:23 | 000,000,294 | ---- | C] () -- C:\Windows\PowerOption.ini
[2006.11.02 16:10:16 | 000,080,912 | ---- | C] () -- C:\Windows\System32\sherlock2.exe
[2006.08.18 08:27:18 | 000,002,048 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.08.18 08:27:10 | 000,000,061 | ---- | C] () -- C:\Windows\smscfg.ini
[2006.08.17 20:09:02 | 000,032,768 | ---- | C] () -- C:\Windows\System32\MWLPS.dll
[2006.08.17 20:08:54 | 000,000,050 | ---- | C] () -- C:\Windows\commercial.ini
[2006.08.17 20:07:44 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll
[2006.08.17 20:07:00 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIMPEG2.dll
[2006.08.17 20:07:00 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIMP3.dll
[2006.08.17 20:07:00 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIFCD3.dll
[2006.08.17 20:07:00 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTICDMK7.dll
[2006.08.17 20:05:04 | 000,575,040 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.08.17 20:05:04 | 000,570,302 | ---- | C] () -- C:\Windows\System32\perfh005.dat
[2006.08.17 20:05:04 | 000,132,326 | ---- | C] () -- C:\Windows\System32\perfc005.dat
[2006.08.17 20:05:04 | 000,117,220 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.08.17 20:01:52 | 003,783,864 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.08.17 19:52:22 | 000,004,249 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2006.08.17 19:51:32 | 000,021,812 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat
[2006.07.11 23:19:00 | 000,581,632 | ---- | C] () -- C:\Windows\System32\nvhwvid.dll
[2006.07.11 23:19:00 | 000,286,720 | ---- | C] () -- C:\Windows\System32\nvnt4cpl.dll
[2006.05.29 15:05:58 | 000,303,104 | ---- | C] () -- C:\Windows\CreateLnk.exe
[2006.04.23 16:15:36 | 000,000,095 | ---- | C] () -- C:\Windows\ALaunch.ini
[2006.03.29 07:43:38 | 000,042,496 | ---- | C] () -- C:\Windows\System32\ALZZip.BIN
[2006.03.29 07:43:36 | 000,062,464 | ---- | C] () -- C:\Windows\System32\ALZALZ.BIN
[2005.11.16 21:11:52 | 000,024,576 | RH-- | C] () -- C:\Windows\System32\Kill1211.exe
[2005.10.31 03:17:38 | 000,135,168 | ---- | C] () -- C:\Windows\System32\RtlCPAPI.dll
[2005.10.14 10:56:50 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2005.10.14 10:56:50 | 000,921,600 | ---- | C] () -- C:\Windows\System32\VorbisEnc.dll
[2005.10.14 10:56:50 | 000,761,856 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2005.10.14 10:56:50 | 000,344,064 | ---- | C] () -- C:\Windows\System32\xvid.dll
[2005.10.14 10:56:50 | 000,237,568 | ---- | C] () -- C:\Windows\System32\OggDS.dll
[2005.10.14 10:56:50 | 000,188,416 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2005.10.14 10:56:50 | 000,155,136 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2005.10.14 10:56:50 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ogg.dll
[2005.10.14 10:56:48 | 000,077,824 | ---- | C] () -- C:\Windows\System32\MMSwitch.dll
[2005.10.14 10:56:48 | 000,040,960 | ---- | C] () -- C:\Windows\System32\MMAVILNG.exe
[2005.07.15 01:48:00 | 000,040,960 | ---- | C] () -- C:\Windows\System32\ChCfg.exe
[2005.07.12 13:44:42 | 000,015,872 | ---- | C] () -- C:\Windows\System32\InsDrvZD64.DLL
[2004.08.18 21:00:00 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2004.08.18 21:00:00 | 000,272,128 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2004.08.18 21:00:00 | 000,269,162 | ---- | C] () -- C:\Windows\System32\perfi005.dat
[2004.08.18 21:00:00 | 000,218,003 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2004.08.18 21:00:00 | 000,046,258 | ---- | C] () -- C:\Windows\System32\mib.bin
[2004.08.18 21:00:00 | 000,032,072 | ---- | C] () -- C:\Windows\System32\perfd005.dat
[2004.08.18 21:00:00 | 000,028,626 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2004.08.18 21:00:00 | 000,004,569 | ---- | C] () -- C:\Windows\System32\secupd.dat
[2004.08.18 21:00:00 | 000,001,804 | ---- | C] () -- C:\Windows\System32\dcache.bin
[2004.08.18 21:00:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\noise.dat
[2004.03.23 15:38:00 | 000,028,672 | ---- | C] () -- C:\Windows\System32\InsDrvZD.dll
[2003.08.07 08:51:32 | 000,024,576 | -H-- | C] () -- C:\Windows\System32\reboot.exe
[2003.08.06 18:32:24 | 000,024,576 | -H-- | C] () -- C:\Windows\System32\KCMDNIns.exe
[2003.03.14 11:24:00 | 000,024,576 | ---- | C] () -- C:\Windows\System32\ZyDelReg.exe
[2002.05.23 16:34:46 | 000,032,768 | ---- | C] () -- C:\Windows\AMOVE.EXE
[2001.12.26 14:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001.09.03 21:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001.08.25 18:04:08 | 013,107,200 | ---- | C] () -- C:\Windows\System32\oembios.bin
[2001.08.25 18:02:42 | 000,004,524 | ---- | C] () -- C:\Windows\System32\oembios.dat
[2001.07.30 14:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001.07.23 20:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll
[2001.07.06 15:30:00 | 000,003,165 | ---- | C] () -- C:\Windows\System32\HPTCPMON.INI

========== Custom Scans ==========



< MD5 for: EXPLORER.EXE >
[2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\system32\dllcache\explorer.exe
[2007.06.13 14:11:59 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=9B32416BD5988C97B6397CE0B02CAF97 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007.06.13 14:23:39 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=ED7B460B142A32097B8A8F6ECC941815 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: REGEDIT.EXE >
[2004.08.18 21:00:00 | 000,147,968 | ---- | M] (Microsoft Corporation) MD5=CB5A91928D94224E7E30EE277B45E8A3 -- C:\WINDOWS\$NtServicePackUninstall$\regedit.exe
[2008.04.14 07:52:44 | 000,147,968 | ---- | M] (Microsoft Corporation) MD5=FDEB1D02CAE38665CBF114F44E6B997E -- C:\WINDOWS\regedit.exe
[2008.04.14 07:52:44 | 000,147,968 | ---- | M] (Microsoft Corporation) MD5=FDEB1D02CAE38665CBF114F44E6B997E -- C:\WINDOWS\ServicePackFiles\i386\regedit.exe
[2008.04.14 07:52:44 | 000,147,968 | ---- | M] (Microsoft Corporation) MD5=FDEB1D02CAE38665CBF114F44E6B997E -- C:\WINDOWS\system32\dllcache\regedit.exe

< End of report >

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#44 Příspěvek od motji »

Ted už jsem spokojená :D , co počítač?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

W.Mia
Návštěvník
Návštěvník
Příspěvky: 42
Registrován: 24 Lis 2011 08:29

Re: Odolná havěť v systému s mnoha projevy - prosím o kontro

#45 Příspěvek od W.Mia »

Počítač je v pohodě. Žádné konkrétní problémy nepozorujeme a ani nic typu zpomalení chodu či tak něco.

Odpovědět