Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomalé PC, pravděpodobně malware

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Matt.Mikolaj

Pomalé PC, pravděpodobně malware

#1 Příspěvek od Matt.Mikolaj »

Dobrý den,

PC je strašně zpomalené. Vysakují na mě různá pop-up okna. Celkově PC bere až moc paměti. Děkuji za prohlédnutí LOGu.




Logfile of random's system information tool 1.09 (written by random/random)
Run by Master at 2012-08-29 15:13:56
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 9 GB (26%) free of 35 GB
Total RAM: 1015 MB (42% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:14:04, on 29.8.2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Master\Dokumenty\Downloads\RSIT (1).exe
C:\Program Files\trend micro\Master.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Dropbox.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: M-Audio Series II MIDI Installer (MA_CMIDI_InstallerService) - Unknown owner - C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Airytec Switch Off - Task Scheduler (SwOffScheduler) - Airytec - C:\Program Files\Airytec\Switch Off\swoff.exe
O23 - Service: Airytec Switch Off - Web Interface (SwOffWeb) - Airytec - C:\Program Files\Airytec\Switch Off\swoff.exe
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

--
End of file - 9081 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-507921405-413027322-725345543-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-507921405-413027322-725345543-1003UA.job
C:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]
"JMB36X IDE Setup"=C:\WINDOWS\JM\JMInsIDE.exe [2006-10-30 36864]
"36X Raid Configurer"=C:\WINDOWS\system32\JMRaidSetup.exe [2006-11-16 1953792]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-05-11 8429568]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-05-11 81920]
"ASUSGamerOSD"=C:\Program Files\ASUS\GamerOSD\GamerOSD.exe [2007-06-01 380928]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2007-08-07 200704]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-02-20 59240]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2012-03-27 421736]
"LWS"=C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [2011-11-11 205336]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2012-04-18 421888]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-09-29 2054360]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"Google Update"=C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2012-06-06 116648]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]

C:\Documents and Settings\Master\Nabídka Start\Programy\Po spuštění
Dropbox.lnk - C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Trillian\trillian.exe"="C:\Program Files\Trillian\trillian.exe:*:Enabled:Trillian"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\eJamming\eJammingAUDiiO\eJammingAUDiiO.exe"="C:\Program Files\eJamming\eJammingAUDiiO\eJammingAUDiiO.exe:*:Enabled:eJammingAUDiiO"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Logitech\Vid HD\Vid.exe"="C:\Program Files\Logitech\Vid HD\Vid.exe:*:Enabled:Logitech Vid HD"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe"="C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exe"="C:\Program Files\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exe:*:Enabled:Adobe After Effects CS4"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=lvcodec2.dll
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.XVID"=xvidvfw.dll
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux3"=wdmaud.drv
"MSVideo"=vfwwdm32.dll
"wave5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux4"=wdmaud.drv
"wave6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux5"=wdmaud.drv
"wave7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux6"=wdmaud.drv
"wave8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux7"=wdmaud.drv
"aux8"=wdmaud.drv
"aux9"=wdmaud.drv
"Midi"=wdmaud.drv
"Midi1"=ma_cmidn.dll
"midi2"=ma_cmidn.dll
"midi3"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-08-29 15:07:21 ----D---- C:\Program Files\trend micro
2012-08-29 15:07:19 ----D---- C:\rsit
2012-08-29 15:06:22 ----A---- C:\WINDOWS\eSellerateEngine.dll
2012-08-29 15:05:37 ----D---- C:\Program Files\Common Files\DeskShare Shared
2012-08-29 15:05:33 ----D---- C:\Program Files\Deskshare
2012-08-29 14:57:53 ----D---- C:\Documents and Settings\Master\Data aplikací\systweak
2012-08-29 00:12:35 ----D---- C:\Program Files\Synthesia
2012-08-28 23:33:59 ----D---- C:\Documents and Settings\Master\Data aplikací\Synthesia
2012-08-26 22:54:41 ----D---- C:\Documents and Settings\Master\Data aplikací\Airytec
2012-08-26 22:54:27 ----D---- C:\Program Files\Airytec
2012-08-23 14:12:18 ----A---- C:\WINDOWS\jidgjinf.ini
2012-08-23 14:11:18 ----A---- C:\WINDOWS\jidgjikl.ini
2012-08-23 14:09:37 ----A---- C:\WINDOWS\jidgjicm.ini
2012-08-23 14:09:29 ----A---- C:\WINDOWS\jidgjipm.ini
2012-08-23 14:09:29 ----A---- C:\WINDOWS\jidgjibl.ini
2012-08-23 14:09:10 ----A---- C:\WINDOWS\jidgjiip.ini
2012-08-23 14:09:10 ----A---- C:\WINDOWS\jidgjihk.ini
2012-08-23 14:09:10 ----A---- C:\WINDOWS\jidgjiei.ini
2012-08-23 14:09:10 ----A---- C:\WINDOWS\jidgjiaf.ini
2012-08-22 21:23:03 ----D---- C:\Documents and Settings\Master\Data aplikací\Waves
2012-08-22 21:23:02 ----D---- C:\Documents and Settings\Master\Data aplikací\Waves Preferences
2012-08-21 16:05:33 ----A---- C:\CountCyclesWMVDecLog.txt
2012-08-20 20:25:00 ----D---- C:\Program Files\TabIt
2012-08-09 16:34:24 ----D---- C:\Documents and Settings\Master\Data aplikací\BSplayer Pro
2012-08-09 16:34:24 ----D---- C:\Documents and Settings\Master\Data aplikací\BSplayer
2012-08-09 16:34:23 ----D---- C:\Program Files\Webteh
2012-08-02 14:46:23 ----D---- C:\Documents and Settings\Master\Data aplikací\JAM Software
2012-08-02 14:46:21 ----D---- C:\Program Files\JAM Software

======List of files/folders modified in the last 1 month======

2012-08-29 15:14:03 ----D---- C:\WINDOWS\Prefetch
2012-08-29 15:13:57 ----D---- C:\WINDOWS\Temp
2012-08-29 15:11:26 ----D---- C:\Documents and Settings\Master\Data aplikací\uTorrent
2012-08-29 15:07:21 ----RD---- C:\Program Files
2012-08-29 15:06:22 ----D---- C:\WINDOWS
2012-08-29 15:05:37 ----D---- C:\Program Files\Common Files
2012-08-29 14:55:50 ----D---- C:\WINDOWS\system32
2012-08-29 11:46:29 ----D---- C:\Documents and Settings\Master\Data aplikací\Dropbox
2012-08-29 00:35:07 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-08-29 00:34:43 ----D---- C:\Program Files\Trillian
2012-08-28 23:54:36 ----A---- C:\WINDOWS\NeroDigital.ini
2012-08-27 15:40:15 ----D---- C:\Documents and Settings\Master\Data aplikací\vlc
2012-08-27 13:31:03 ----A---- C:\WINDOWS\system32\msvcsv60.dll
2012-08-23 14:25:33 ----D---- C:\Program Files\Waves
2012-08-22 21:57:49 ----D---- C:\WINDOWS\system32\CatRoot2
2012-08-22 21:17:27 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2012-08-20 14:10:32 ----D---- C:\Documents and Settings\Master\Data aplikací\Skype
2012-08-20 14:09:24 ----D---- C:\Documents and Settings\Master\Data aplikací\skypePM
2012-08-17 21:37:13 ----SHD---- C:\WINDOWS\Installer
2012-08-17 21:37:04 ----HD---- C:\WINDOWS\inf
2012-08-17 21:37:04 ----D---- C:\WINDOWS\system32\drivers
2012-08-09 15:18:11 ----D---- C:\WINDOWS\Minidump
2012-08-08 11:58:02 ----D---- C:\Documents and Settings\Master\Data aplikací\Adobe
2012-08-04 09:22:39 ----D---- C:\WINDOWS\Config
2012-08-03 23:50:26 ----SHD---- C:\System Volume Information
2012-08-03 23:50:26 ----D---- C:\WINDOWS\system32\Restore
2012-08-03 15:11:10 ----D---- C:\WINDOWS\system32\wbem
2012-08-03 15:11:10 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-07-31 12:41:15 ----D---- C:\Program Files\Adobe
2012-07-31 12:40:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2012-07-31 12:40:25 ----D---- C:\Program Files\Common Files\Adobe
2012-07-30 16:38:47 ----D---- C:\Program Files\QuickTime

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JGOGO;JMicron Hot-Plug Driver; C:\WINDOWS\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; C:\WINDOWS\system32\DRIVERS\jraid.sys [2006-12-06 44416]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-06-28 691696]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2007-05-31 11136]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-09-29 108792]
R1 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-09-29 96408]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2007-08-07 33052]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-09-29 116008]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
R3 asusgsb;ASUS Virtual Video Capture Device Driver; C:\WINDOWS\system32\drivers\asusgsb.sys [2007-05-31 12416]
R3 CompFilter;UVCCompositeFilter; C:\WINDOWS\system32\DRIVERS\lvbusflt.sys [2012-01-18 22176]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-10-27 138240]
R3 LVRS;Logitech RightSound Filter Driver; C:\WINDOWS\system32\DRIVERS\lvrs.sys [2012-01-18 312096]
R3 LVUVC;Logitech HD Pro Webcam C910(UVC); C:\WINDOWS\system32\DRIVERS\lvuvc.sys [2012-01-18 4332960]
R3 MA_CMIDI;M-Audio USB Driver; C:\WINDOWS\system32\drivers\ma_cmidi.sys [2006-08-16 21888]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-05-11 6738432]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-08-14 83200]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys [2007-05-31 10752]
S3 a1sd209w;a1sd209w; C:\WINDOWS\system32\drivers\a1sd209w.sys []
S3 BEHRINGER_2902;usb-audio.de driver for BEHRINGER USB AUDIO; C:\WINDOWS\System32\Drivers\BUSB2902.sys [2009-10-30 384576]
S3 BUSB_AUDIO_WDM;BEHRINGER USB WDM AUDIO; C:\WINDOWS\system32\drivers\busbwdm.sys [2009-10-30 39488]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2012-02-15 43520]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-03 78464]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-02-27 55144]
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2007-05-31 258560]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-09-29 735960]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-05-11 163908]
R2 UMVPFSrv;UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2012-03-27 821608]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S2 MA_CMIDI_InstallerService;M-Audio Series II MIDI Installer; C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe []
S2 SwOffScheduler;Airytec Switch Off - Task Scheduler; C:\Program Files\Airytec\Switch Off\swoff.exe [2011-05-28 135168]
S2 SwOffWeb;Airytec Switch Off - Web Interface; C:\Program Files\Airytec\Switch Off\swoff.exe [2011-05-28 135168]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-09-29 20680]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-06-06 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pomalé PC, pravděpodobně malware

#2 Příspěvek od vyosek »

Zdravim a pekny podvecer preji :)

:arrow: Mate nejaky problem s intalaci ServicePack 3 ?

:arrow: Poprosim i o druhy log z RSIT s nazvem info.txt

:arrow: Predpokladam, ze na ten NOD32 mate zakoupenou licenci :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Matt.Mikolaj

Re: Pomalé PC, pravděpodobně malware

#3 Příspěvek od Matt.Mikolaj »

Na Nod-32 mi vypršela TRIAL(zkušební) licence.


info.txt logfile of random's system information tool 1.09 2012-08-29 15:14:07

======Uninstall list======

Leawo Video Converter version 5.2.0.0-->"C:\Program Files\Leawo\Video Converter\unins000.exe"
-->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent-->"C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe After Effects CS4 Presets-->MsiExec.exe /I{44E240EC-2224-4078-A88B-2CEE0D3016EF}
Adobe After Effects CS4 Third Party Content-->C:\Program Files\Common Files\Adobe\Installers\5aab5a491a3a52ae624fd639f6aaa95\Setup.exe --uninstall=1
Adobe After Effects CS4 Third Party Content-->MsiExec.exe /I{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}
Adobe After Effects CS4-->C:\Program Files\Common Files\Adobe\Installers\3dcb365ab9e01871fb8c6f27b0ea079\Setup.exe --uninstall=1
Adobe After Effects CS4-->MsiExec.exe /I{45EC816C-0771-4C14-AE6D-72D1B578F4C8}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}
Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Anchor Service CS4-->MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8}
Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge CS4-->MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2BAC22E093E0}
Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}
Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color EU Extra Settings-->MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings-->MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Color Video Profiles AE CS4-->MsiExec.exe /I{B15381DD-FF97-4FCD-A881-ED4DB0975500}
Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}
Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe Device Central CS4-->MsiExec.exe /I{67F0E67A-8E93-4C2C-B29D-47C48262738A}
Adobe Dynamiclink Support-->MsiExec.exe /I{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}
Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe ExtendScript Toolkit CS4-->MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}
Adobe Extension Manager CS4-->MsiExec.exe /I{054EFA56-2AC1-48F4-A883-0AB89874B972}
Adobe Fonts All-->MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe Media Encoder CS4 Additional Exporter-->MsiExec.exe /I{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}
Adobe Media Encoder CS4-->MsiExec.exe /I{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}
Adobe Media Player-->msiexec /qb /x {39F6E2B4-CFE8-C30A-66E8-489651F0F34C}
Adobe Media Player-->MsiExec.exe /I{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}
Adobe MotionPicture Color Files CS4-->MsiExec.exe /I{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}
Adobe Output Module-->MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A}
Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}
Adobe Photoshop CS3-->C:\Program Files\Common Files\Adobe\Installers\2ac78060bc5856b0c1cf873bb919b58\Setup.exe
Adobe Photoshop CS3-->MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Adobe Setup-->MsiExec.exe /I{411F3ABA-2AB5-4799-AA19-6ADF0A8F7424}
Adobe Setup-->MsiExec.exe /I{8EB8E60B-315D-44EB-A896-10D88602EE46}
Adobe Setup-->MsiExec.exe /I{D1BB4446-AE9C-4256-9A7F-4D46604D2462}
Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Update Manager CS4-->MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755}
Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
Adobe XMP Panels CS4-->MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
AdobeColorCommonSetRGB-->MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
Airytec Switch Off-->"C:\Program Files\Airytec\Switch Off\uninstall.exe"
Aktualizace systému Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB925720)-->"C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player (KB978695)-->"C:\WINDOWS\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player (KB979402)-->"C:\WINDOWS\$NtUninstallKB979402_WM9L$\spuninst\spuninst.exe"
Aktualizace zabezpečení produktu Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB2229593)-->"C:\WINDOWS\$NtUninstallKB2229593$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Aktualizace zabezpečení systému Windows XP (KB944338-v2)-->"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB958470)-->"C:\WINDOWS\$NtUninstallKB958470$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB971032)-->"C:\WINDOWS\$NtUninstallKB971032$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB975561)-->"C:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB975562)-->"C:\WINDOWS\$NtUninstallKB975562$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB977816)-->"C:\WINDOWS\$NtUninstallKB977816$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB978338)-->"C:\WINDOWS\$NtUninstallKB978338$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB978542)-->"C:\WINDOWS\$NtUninstallKB978542$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB978601)-->"C:\WINDOWS\$NtUninstallKB978601$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB979309)-->"C:\WINDOWS\$NtUninstallKB979309$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB979482)-->"C:\WINDOWS\$NtUninstallKB979482$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB979559)-->"C:\WINDOWS\$NtUninstallKB979559$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB979683)-->"C:\WINDOWS\$NtUninstallKB979683$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB980195)-->"C:\WINDOWS\$NtUninstallKB980195$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB980218)-->"C:\WINDOWS\$NtUninstallKB980218$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB980232)-->"C:\WINDOWS\$NtUninstallKB980232$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB981350)-->"C:\WINDOWS\$NtUninstallKB981350$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB982381)-->"C:\WINDOWS\$NtUninstallKB982381$\spuninst\spuninst.exe"
AmpliTube 3-->C:\Program Files\InstallShield Installation Information\{5DD152A8-BFB3-439E-90CD-5C00C2116E23}\setup.exe -runfromtemp -l0x0009 uninstall -removeonly
Apple Application Support-->MsiExec.exe /I{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}
Apple Mobile Device Support-->MsiExec.exe /I{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}
Apple Software Update-->MsiExec.exe /I{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}
ASUS Gamer OSD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}\setup.exe" -l0x9 -removeonly
AVI to 3GP 1.3-->"C:\Program Files\AVI to 3GP\unins000.exe"
BEHRINGER USB AUDIO DRIVER-->C:\WINDOWS\usb-audio.deBehringer2902\Setup.exe /l1
Bonjour-->MsiExec.exe /X{79155F2B-9895-49D7-8612-D92580E0DE5B}
BS.Player FREE-->"C:\Program Files\Webteh\BSPlayer\uninstall.exe"
CameraHelperMsi-->MsiExec.exe /I{15634701-BACE-4449-8B25-1567DA8C9FD3}
Deamon Tools Lite-->"C:\Program Files\Deamon Tools Lite\uninstall.exe" "/U:C:\Program Files\Deamon Tools Lite\Uninstall\uninstall.xml"
eJammingAUDiiO-->MsiExec.exe /I{68544F92-4A85-48F2-9997-40E02EFB2305}
erLT-->MsiExec.exe /I{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}
Guitar Pro 5.2-->"C:\Program Files\Guitar Pro 5\unins000.exe"
High Definition Audio Driver Package - KB888111-->C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe
iTunes-->MsiExec.exe /I{23B8A91D-680B-462B-87AD-3D70F7341731}
JMB36X Raid Configurer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}\setup.exe" -l0x9 -removeonly
Lennar Digital Sylenth VSTi v1.2.1-->C:\PROGRA~1\COMMON~1\STEINB~1\VST2\Sylenth1\UNINST~1\UNWISE.EXE C:\PROGRA~1\COMMON~1\STEINB~1\VST2\Sylenth1\UNINST~1\INSTALL.LOG
Logitech Vid HD-->C:\Program Files\Logitech\Vid HD\uninst.exe
Logitech Webcam Software-->"C:\Program Files\Common Files\LogiShrd\Installer\{D40EB009-0499-459c-A8AF-C9C110766215}\setup.exe" /lang=ENU /guid="{D40EB009-0499-459c-A8AF-C9C110766215}"
LWS Facebook-->MsiExec.exe /I{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}
LWS Gallery-->MsiExec.exe /I{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}
LWS Help_main-->MsiExec.exe /I{1651216E-E7AD-4250-92A1-FB8ED61391C9}
LWS Launcher-->MsiExec.exe /I{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}
LWS Motion Detection-->MsiExec.exe /I{71E66D3F-A009-44AB-8784-75E2819BA4BA}
LWS Pictures And Video-->MsiExec.exe /I{08610298-29AE-445B-B37D-EFBE05802967}
LWS Twitter-->MsiExec.exe /I{174A3B31-4C43-43DD-866F-73C9DB887B48}
LWS Video Mask Maker-->MsiExec.exe /I{EED027B7-0DB6-404B-8F45-6DFEE34A0441}
LWS VideoEffects-->MsiExec.exe /I{138A4072-9E64-46BD-B5F9-DB2BB395391F}
LWS Webcam Software-->MsiExec.exe /I{8937D274-C281-42E4-8CDB-A0B2DF979189}
LWS WLM Plugin-->MsiExec.exe /I{9DAEA76B-E50F-4272-A595-0124E826553D}
LWS YouTube Plugin-->MsiExec.exe /I{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}
M-Audio Oxygen DirectLink for Cubase 5 1.0.0 (x86)-->MsiExec.exe /X{D6F43337-4502-4FF2-8865-E6F7D6F776AF}
M-Audio Series II MIDI-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{379BD39E-F13E-458F-96D8-56BD7F2CC516}\setup.exe" -l0x9 -removeonly
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft .NET Framework 3.0-->C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
Microsoft .NET Framework 3.0-->MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2007-->MsiExec.exe /X{90120000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2007-->MsiExec.exe /X{90120000-0044-0405-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2007-->MsiExec.exe /X{90120000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MSXML 6 Service Pack 2 (KB973686)-->MsiExec.exe /I{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}
My Screen Recorder Pro 2.3-->"C:\Program Files\Deskshare\My Screen Recorder Pro\unins000.exe"
Nero 7 Ultra Edition-->MsiExec.exe /X{CF097717-F174-4144-954A-FBC4BF301029}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
Oprava Hotfix systému Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Oprava Hotfix systému Windows XP (KB981793)-->"C:\WINDOWS\$NtUninstallKB981793$\spuninst\spuninst.exe"
PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Photoshop Camera Raw-->MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8}
Pixel Bender Toolkit-->MsiExec.exe /I{43509E18-076E-40FE-AF38-CA5ED400A5A9}
PowerISO-->"C:\Program Files\PowerISO\uninstall.exe"
QuickTime-->MsiExec.exe /I{0E64B098-8018-4256-BA23-C316A43AD9B0}
Red Giant Psunami-->C:\WINDOWS\unvise32.exe C:\Program Files\Adobe\Common\Plug-ins\CS4\MediaCore\RGPsunamiAE.log
Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}
Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Sony Vegas Pro 8.0-->MsiExec.exe /X{B7E2A724-2774-4AC2-9F0A-B58C7319B6E6}
SoundMAX-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe" -l0x9 -removeonly
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Steinberg Cubase 5-->MsiExec.exe /I{4A19D6AC-ADE0-4A07-80FF-9C9812C45557}
Steinberg Drum Loop Expansion 01-->MsiExec.exe /I{490BF87E-1F75-4453-BF55-9F540543A3CA}
Steinberg Groove Agent ONE Content-->MsiExec.exe /I{BD86F1AC-B594-46E4-85DC-1258AC9E2232}
Steinberg HALionOne Additional Content Set 01-->MsiExec.exe /I{F3AFD063-8BAD-485E-B641-E7F5A2C5AE71}
Steinberg HALionOne Expression Set-->MsiExec.exe /I{E22AD5D3-EB60-4A8F-835C-6C10E369DCE2}
Steinberg HALionOne GM Drum Set-->MsiExec.exe /I{AC997F93-0757-4ED4-A701-F40C2D654D09}
Steinberg HALionOne GM Set-->MsiExec.exe /I{F057965A-D974-4C64-ADB1-4381CD4B8956}
Steinberg HALionOne Pro Set-->MsiExec.exe /I{D82CDA0D-C182-42C8-8FF2-5649C98D6003}
Steinberg HALionOne Studio Drum Set-->MsiExec.exe /I{865D9ED1-EAC2-436D-AFA7-0B750EB5AAAB}
Steinberg HALionOne Studio Set-->MsiExec.exe /I{D23CBFDA-C46B-4920-BA70-FC7878A3F05A}
Steinberg HALionOne-->MsiExec.exe /I{E70E7159-93B1-470D-9FBD-D8E9EF34B538}
Steinberg LoopMash Content-->MsiExec.exe /I{4D454CF8-12FD-464D-B57B-B46FE27B78BB}
Steinberg REVerence Content 01-->MsiExec.exe /I{532B917B-8235-4FA5-BE36-643A8BB053A5}
Steinberg The Grand VSTi DXi v2.1.0-->"C:\Program Files\Steinberg\The Grand 2\Uninstall\unins000.exe"
StreamDown 6.8.0.0-->"C:\Program Files\StreamDown\unins000.exe"
Suite Shared Configuration CS4-->MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434}
Superior Drummer Installer-->MsiExec.exe /I{009AC76E-1A66-4682-82B7-417E77F3C648}
Synthesia (remove only)-->"C:\Program Files\Synthesia\uninstall.exe"
TabIt version 2.03 (Trial)-->"C:\Program Files\TabIt\unins000.exe"
Trapcode Particular 32 bit-->"C:\Program Files\InstallShield Installation Information\{D1345EF1-9655-47C0-BB35-6DC2BD0A2826}\setup.exe" -runfromtemp -l0x0409 -removeonly
Trapcode Particular 32 bit-->MsiExec.exe /I{D1345EF1-9655-47C0-BB35-6DC2BD0A2826}
TreeSize Free V2.3.3-->"C:\Program Files\JAM Software\TreeSize Free\unins000.exe"
Trillian-->C:\Program Files\Trillian\Trillian.exe /uninstall
TubeOhm Pure-PoneV1_6-->"C:\Program Files\vstplugins\P-PoneV1_6\unins000.exe"
VLC media player 2.0.1-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Vypínač na dobrou noc verze 2.0-->"C:\Program Files\Vypínač na dobrou noc\unins000.exe"
Wave Arts Power Suite-->C:\PROGRA~1\WAVEAR~1\UNWISE.EXE C:\PROGRA~1\WAVEAR~1\INSTALL.LOG
Waves API Collection-->E:\PROGRA~1\Waves\API\Logs\WAVESA~1\UNWISE.EXE E:\PROGRA~1\Waves\API\Logs\WAVESA~1\INSTALL.LOG
Waves Diamond Bundle v5.2-->E:\PROGRA~1\Waves\DIAMON~1\DIAMON~1\UNWISE.EXE E:\PROGRA~1\Waves\DIAMON~1\DIAMON~1\INSTALL.LOG
Waves GTR 3-->E:\PROGRA~1\Waves\Logs\WAVESG~1\UNWISE.EXE E:\PROGRA~1\Waves\Logs\WAVESG~1\INSTALL.LOG
Waves IRx v5.2-->E:\PROGRA~1\Waves\IR\UNINST~1\UNWISE.EXE E:\PROGRA~1\Waves\IR\UNINST~1\INSTALL.LOG
Waves L3 v5.2-->E:\PROGRA~1\Waves\L3\UNINST~1\UNWISE.EXE E:\PROGRA~1\Waves\L3\UNINST~1\INSTALL.LOG
Waves Mercury Bundle-->E:\PROGRA~1\Waves\MERCUR~1\Logs\WAVESM~1\UNWISE.EXE E:\PROGRA~1\Waves\MERCUR~1\Logs\WAVESM~1\INSTALL.LOG
Waves SSL Collection v1.2-->C:\PROGRA~1\Waves\AIRLOG~1\WAVESS~1.2\UNWISE.EXE C:\PROGRA~1\Waves\AIRLOG~1\WAVESS~1.2\INSTALL.LOG
Waves Vocal Bundle v1.1-->E:\PROGRA~1\Waves\Vocal\AIRLOG~1\WAVESV~1\UNWISE.EXE E:\PROGRA~1\Waves\Vocal\AIRLOG~1\WAVESV~1\INSTALL.LOG
Waves Znoise v1.0-->E:\PROGRA~1\Waves\Z-Noise\AIRLOG~1\ZNOISE~1\UNWISE.EXE E:\PROGRA~1\Waves\Z-Noise\AIRLOG~1\ZNOISE~1\INSTALL.LOG
Webcam and Screen Recorder-->"C:\Program Files\Webcam and Screen Recorder\uninstall.exe" "/U:C:\Program Files\Webcam and Screen Recorder\Uninstall\uninstall.xml"
Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
XviD MPEG-4 Video Codec-->C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_XviD 132 C:\WINDOWS\INF\xvid.inf

======Hosts File======

127.0.0.1 activate.adobe.com

======Security center information======

AV: ESET NOD32 Antivirus 4.0

======System event log======

Computer Name: MIKO
Event Code: 7035
Message: Řídící příkaz Spuštěno byl službě Kompatibilita pro rychlé přepínání uživatelů úspěšně odeslán.

Record Number: 5
Source Name: Service Control Manager
Time Written: 20120816141610.000000+120
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: MIKO
Event Code: 7036
Message: Stav služby Terminálová služba byl změněn na: Spuštěno

Record Number: 4
Source Name: Service Control Manager
Time Written: 20120816141610.000000+120
Event Type: Informace
User:

Computer Name: MIKO
Event Code: 7000
Message: Služba M-Audio Series II MIDI Installer neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.


Record Number: 3
Source Name: Service Control Manager
Time Written: 20120816141604.000000+120
Event Type: Chyba
User:

Computer Name: MIKO
Event Code: 6005
Message: Služba Event Log byla spuštěna.

Record Number: 2
Source Name: EventLog
Time Written: 20120816141552.000000+120
Event Type: Informace
User:

Computer Name: MIKO
Event Code: 6009
Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Multiprocessor Free.

Record Number: 1
Source Name: EventLog
Time Written: 20120816141552.000000+120
Event Type: Informace
User:

=====Application event log=====

Computer Name: MIKO
Event Code: 1000
Message: Čítače výkonu pro službu MSDTC (MSDTC) byly úspěšně načteny.
Data záznamu obsahují nové indexové hodnoty přiřazené
této službě.

Record Number: 5
Source Name: LoadPerf
Time Written: 20120606154750.000000+120
Event Type: Informace
User:

Computer Name: MIKO
Event Code: 1000
Message: Čítače výkonu pro službu TermService (Terminálová služba) byly úspěšně načteny.
Data záznamu obsahují nové indexové hodnoty přiřazené
této službě.

Record Number: 4
Source Name: LoadPerf
Time Written: 20120606154747.000000+120
Event Type: Informace
User:

Computer Name: MIKO
Event Code: 1000
Message: Čítače výkonu pro službu RemoteAccess (Směrování a vzdálený přístup) byly úspěšně načteny.
Data záznamu obsahují nové indexové hodnoty přiřazené
této službě.

Record Number: 3
Source Name: LoadPerf
Time Written: 20120606154649.000000+120
Event Type: Informace
User:

Computer Name: MIKO
Event Code: 1000
Message: Čítače výkonu pro službu PSched (PSched) byly úspěšně načteny.
Data záznamu obsahují nové indexové hodnoty přiřazené
této službě.

Record Number: 2
Source Name: LoadPerf
Time Written: 20120606154626.000000+120
Event Type: Informace
User:

Computer Name: MIKO
Event Code: 1000
Message: Čítače výkonu pro službu RSVP (QoS RSVP) byly úspěšně načteny.
Data záznamu obsahují nové indexové hodnoty přiřazené
této službě.

Record Number: 1
Source Name: LoadPerf
Time Written: 20120606154625.000000+120
Event Type: Informace
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"asl.log"=Destination=file
"CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pomalé PC, pravděpodobně malware

#4 Příspěvek od vyosek »

:arrow: Neaktualizovany antivir je jako zamknuty dum ale s otevrenymi okny

:arrow: Nehlede na to, ze dle licencnich podminek jej po skonceni tria licence nesmite pouzivat

:arrow: Takze jej odinstalujte a dejte free reseni (nejlepe Avast Free http://www.avast.com/cs-cz/free-antivirus-download )

:arrow: Pak poprosim o novy log z RSIT

:arrow: A co je s tim ServicePackem 3?
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Matt.Mikolaj

Re: Pomalé PC, pravděpodobně malware

#5 Příspěvek od Matt.Mikolaj »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Master at 2012-08-30 10:53:27
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 6 GB (17%) free of 35 GB
Total RAM: 1015 MB (42% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:53:55, on 30.8.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Documents and Settings\Master\Dokumenty\Downloads\RSIT.exe
C:\Program Files\AVAST Software\Avast\setup\avast.setup
C:\Program Files\trend micro\Master.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Dropbox.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: M-Audio Series II MIDI Installer (MA_CMIDI_InstallerService) - Unknown owner - C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Airytec Switch Off - Task Scheduler (SwOffScheduler) - Airytec - C:\Program Files\Airytec\Switch Off\swoff.exe
O23 - Service: Airytec Switch Off - Web Interface (SwOffWeb) - Airytec - C:\Program Files\Airytec\Switch Off\swoff.exe
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe

--
End of file - 8397 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-507921405-413027322-725345543-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-507921405-413027322-725345543-1003UA.job
C:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2006-07-13 729088]
"JMB36X IDE Setup"=C:\WINDOWS\JM\JMInsIDE.exe [2006-10-30 36864]
"36X Raid Configurer"=C:\WINDOWS\system32\JMRaidSetup.exe [2006-11-16 1953792]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-05-11 8429568]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-05-11 81920]
"ASUSGamerOSD"=C:\Program Files\ASUS\GamerOSD\GamerOSD.exe [2007-06-01 380928]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2007-08-07 200704]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-02-20 59240]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2012-03-27 421736]
"LWS"=C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [2011-11-11 205336]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2012-04-18 421888]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-08-21 4282728]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2012-06-06 116648]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]

C:\Documents and Settings\Master\Nabídka Start\Programy\Po spuštění
Dropbox.lnk - C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Trillian\trillian.exe"="C:\Program Files\Trillian\trillian.exe:*:Enabled:Trillian"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\eJamming\eJammingAUDiiO\eJammingAUDiiO.exe"="C:\Program Files\eJamming\eJammingAUDiiO\eJammingAUDiiO.exe:*:Enabled:eJammingAUDiiO"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Logitech\Vid HD\Vid.exe"="C:\Program Files\Logitech\Vid HD\Vid.exe:*:Enabled:Logitech Vid HD"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe"="C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exe"="C:\Program Files\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exe:*:Enabled:Adobe After Effects CS4"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=lvcodec2.dll
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"vidc.XVID"=xvidvfw.dll
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux3"=wdmaud.drv
"MSVideo"=vfwwdm32.dll
"wave5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux4"=wdmaud.drv
"wave6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux5"=wdmaud.drv
"wave7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux6"=wdmaud.drv
"wave8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux7"=wdmaud.drv
"aux8"=wdmaud.drv
"aux9"=wdmaud.drv
"Midi"=wdmaud.drv
"Midi1"=ma_cmidn.dll
"midi2"=ma_cmidn.dll
"midi3"=wdmaud.drv
"vidc.tscc"=tsccvid.dll

======List of files/folders created in the last 1 month======

2012-08-30 10:52:08 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2012-08-30 10:52:08 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2012-08-30 10:52:06 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2012-08-30 10:52:06 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2012-08-30 10:52:06 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2012-08-30 10:52:05 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2012-08-30 10:52:05 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2012-08-30 10:52:04 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2012-08-30 10:51:41 ----A---- C:\WINDOWS\avastSS.scr
2012-08-30 10:51:39 ----A---- C:\WINDOWS\system32\aswBoot.exe
2012-08-30 10:50:52 ----D---- C:\Program Files\AVAST Software
2012-08-30 10:50:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2012-08-30 10:14:22 ----D---- C:\WINDOWS\Prefetch
2012-08-30 00:08:45 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2012-08-30 00:08:16 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2012-08-30 00:07:50 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2012-08-30 00:07:15 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2012-08-30 00:06:43 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2012-08-30 00:06:18 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2012-08-30 00:05:45 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2012-08-30 00:05:23 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2012-08-30 00:04:52 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2012-08-30 00:04:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2012-08-30 00:04:01 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2012-08-30 00:03:40 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2012-08-30 00:03:10 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2012-08-30 00:02:45 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2012-08-30 00:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2012-08-30 00:01:42 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2012-08-30 00:00:07 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2012-08-29 23:58:43 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2012-08-29 23:57:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2012-08-29 23:55:52 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2012-08-29 23:54:18 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2012-08-29 23:52:32 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2012-08-29 23:50:49 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2012-08-29 23:50:17 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2012-08-29 23:49:46 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2012-08-29 23:49:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2012-08-29 23:48:48 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2012-08-29 23:48:17 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2012-08-29 23:47:52 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2012-08-29 23:47:18 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2012-08-29 23:46:54 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2012-08-29 23:46:29 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2012-08-29 23:46:01 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2012-08-29 23:45:30 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2012-08-29 23:45:05 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2012-08-29 23:44:40 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2012-08-29 23:44:16 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2012-08-29 23:43:52 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2012-08-29 23:43:25 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2012-08-29 23:42:59 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2012-08-29 23:42:34 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2012-08-29 23:42:09 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2012-08-29 23:41:43 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2012-08-29 23:40:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2012-08-29 23:40:34 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2012-08-29 23:40:08 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2012-08-29 23:39:44 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2012-08-29 23:39:20 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2012-08-29 23:38:47 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2012-08-29 23:38:22 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2012-08-29 23:37:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2012-08-29 23:37:31 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2012-08-29 23:37:07 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2012-08-29 23:36:43 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2012-08-29 23:36:12 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2012-08-29 23:35:00 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2012-08-29 23:33:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2012-08-29 23:33:03 ----D---- C:\WINDOWS\LastGood.Tmp
2012-08-29 23:30:28 ----A---- C:\WINDOWS\setuplog.txt
2012-08-29 23:29:36 ----N---- C:\WINDOWS\system32\smtpapi.dll
2012-08-29 23:29:36 ----N---- C:\WINDOWS\system32\rwnh.dll
2012-08-29 23:29:36 ----N---- C:\WINDOWS\system32\drivers\irbus.sys
2012-08-29 23:29:36 ----N---- C:\WINDOWS\system32\comsdupd.exe
2012-08-29 23:29:34 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2012-08-29 23:29:34 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2012-08-29 23:29:34 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2012-08-29 23:29:34 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2012-08-29 23:29:34 ----N---- C:\WINDOWS\system32\aaclient.dll
2012-08-29 23:29:33 ----N---- C:\WINDOWS\system32\credssp.dll
2012-08-29 23:29:33 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2012-08-29 23:29:33 ----N---- C:\WINDOWS\system32\azroles.dll
2012-08-29 23:29:33 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2012-08-29 23:29:33 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2012-08-29 23:29:33 ----N---- C:\WINDOWS\system32\ati3duag.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\eapsvc.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\eapqec.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\eappprxy.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\eapphost.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\eappgnui.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\eappcfg.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\eapolqec.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\dot3ui.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\dot3svc.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\dot3msm.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\dot3api.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\dimsroam.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2012-08-29 23:29:32 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2012-08-29 23:29:31 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2012-08-29 23:29:30 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2012-08-29 23:29:30 ----N---- C:\WINDOWS\system32\kmsvc.dll
2012-08-29 23:29:30 ----N---- C:\WINDOWS\system32\kbdpash.dll
2012-08-29 23:29:30 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2012-08-29 23:29:30 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2012-08-29 23:29:30 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2012-08-29 23:29:29 ----N---- C:\WINDOWS\system32\mssha.dll
2012-08-29 23:29:29 ----N---- C:\WINDOWS\system32\mmcperf.exe
2012-08-29 23:29:29 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2012-08-29 23:29:29 ----N---- C:\WINDOWS\system32\mmcex.dll
2012-08-29 23:29:29 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2012-08-29 23:29:29 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\slcoinst.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\setupn.exe
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\s3gnb.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\rasqec.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\qutil.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\qcliprov.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\qagentrt.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\qagent.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\onex.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\napstat.exe
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\napmontr.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\napipsec.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2012-08-29 23:29:28 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2012-08-29 23:29:27 ----N---- C:\WINDOWS\system32\slserv.exe
2012-08-29 23:29:27 ----N---- C:\WINDOWS\system32\slrundll.exe
2012-08-29 23:29:27 ----N---- C:\WINDOWS\system32\slgen.dll
2012-08-29 23:29:27 ----N---- C:\WINDOWS\system32\slextspk.dll
2012-08-29 23:29:26 ----N---- C:\WINDOWS\system32\verclsid.exe
2012-08-29 23:29:26 ----N---- C:\WINDOWS\system32\tspkg.dll
2012-08-29 23:29:26 ----N---- C:\WINDOWS\system32\tsgqec.dll
2012-08-29 23:29:24 ----N---- C:\WINDOWS\system32\wlanapi.dll
2012-08-29 23:29:22 ----N---- C:\WINDOWS\system32\xmllite.dll
2012-08-29 23:29:22 ----N---- C:\WINDOWS\slrundll.exe
2012-08-29 23:29:22 ----D---- C:\WINDOWS\system32\cs-cz
2012-08-29 23:29:21 ----D---- C:\WINDOWS\system32\cs
2012-08-29 23:29:21 ----D---- C:\WINDOWS\system32\bits
2012-08-29 23:29:21 ----D---- C:\WINDOWS\l2schemas
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\atinxsxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\atinxbxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\atintuxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\atinttxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\atinsnxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\atinrvxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\atinraxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\atinpdxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\atinmdxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\atinbtxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati2mtag.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati1snxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati1raxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\ati1btxx.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\amdagp.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\alim1541.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\agpcpq.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\agp440.sys
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\adv11nt5.dll
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\adv09nt5.dll
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\adv08nt5.dll
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\adv07nt5.dll
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\adv05nt5.dll
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\adv02nt5.dll
2012-08-29 23:25:57 ----N---- C:\WINDOWS\system32\drivers\adv01nt5.dll
2012-08-29 23:25:57 ----D---- C:\WINDOWS\network diagnostic
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\hidir.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\hidbth.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\gagp30kx.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\bthusb.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\bthprint.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\bthpan.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\bthmodem.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\bthenum.sys
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\atv10nt5.dll
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\atv06nt5.dll
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\atv04nt5.dll
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\atv02nt5.dll
2012-08-29 23:25:56 ----N---- C:\WINDOWS\system32\drivers\atv01nt5.dll
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\wacompen.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\viaagp.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\vchnt5.dll
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\usb8023x.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\uagp35.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\smbali.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\slwdmsup.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\slnthal.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\slntamr.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\slnt7554.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\sisagp.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\siint5.dll
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\s3gnbm.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\rndismpx.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\rfcomm.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\recagent.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\mutohpen.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\mtxparhm.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\mtlstrm.sys
2012-08-29 23:25:55 ----N---- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2012-08-29 23:25:54 ----N---- C:\WINDOWS\system32\drivers\watv10nt.sys
2012-08-29 23:25:54 ----N---- C:\WINDOWS\system32\drivers\watv06nt.sys
2012-08-29 23:25:54 ----N---- C:\WINDOWS\system32\drivers\wadv11nt.sys
2012-08-29 23:25:54 ----N---- C:\WINDOWS\system32\drivers\wadv09nt.sys
2012-08-29 23:25:54 ----N---- C:\WINDOWS\system32\drivers\wadv08nt.sys
2012-08-29 23:25:54 ----N---- C:\WINDOWS\system32\drivers\wadv07nt.sys
2012-08-29 23:24:49 ----A---- C:\WINDOWS\002929_.tmp
2012-08-29 23:22:17 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2012-08-29 17:27:03 ----A---- C:\WINDOWS\system32\tsccvid.dll
2012-08-29 17:27:02 ----D---- C:\WINDOWS\system32\QuickTime
2012-08-29 17:26:16 ----D---- C:\Program Files\Common Files\TechSmith Shared
2012-08-29 17:25:52 ----D---- C:\Program Files\TechSmith
2012-08-29 17:25:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\TechSmith
2012-08-29 15:07:21 ----D---- C:\Program Files\trend micro
2012-08-29 15:07:19 ----D---- C:\rsit
2012-08-29 15:06:22 ----A---- C:\WINDOWS\eSellerateEngine.dll
2012-08-29 15:05:33 ----D---- C:\Program Files\Deskshare
2012-08-29 14:57:53 ----D---- C:\Documents and Settings\Master\Data aplikací\systweak
2012-08-29 00:12:35 ----D---- C:\Program Files\Synthesia
2012-08-28 23:33:59 ----D---- C:\Documents and Settings\Master\Data aplikací\Synthesia
2012-08-26 22:54:41 ----D---- C:\Documents and Settings\Master\Data aplikací\Airytec
2012-08-26 22:54:27 ----D---- C:\Program Files\Airytec
2012-08-23 14:12:18 ----A---- C:\WINDOWS\jidgjinf.ini
2012-08-23 14:11:18 ----A---- C:\WINDOWS\jidgjikl.ini
2012-08-23 14:09:37 ----A---- C:\WINDOWS\jidgjicm.ini
2012-08-23 14:09:29 ----A---- C:\WINDOWS\jidgjipm.ini
2012-08-23 14:09:29 ----A---- C:\WINDOWS\jidgjibl.ini
2012-08-23 14:09:10 ----A---- C:\WINDOWS\jidgjiip.ini
2012-08-23 14:09:10 ----A---- C:\WINDOWS\jidgjihk.ini
2012-08-23 14:09:10 ----A---- C:\WINDOWS\jidgjiei.ini
2012-08-23 14:09:10 ----A---- C:\WINDOWS\jidgjiaf.ini
2012-08-22 21:23:03 ----D---- C:\Documents and Settings\Master\Data aplikací\Waves
2012-08-22 21:23:02 ----D---- C:\Documents and Settings\Master\Data aplikací\Waves Preferences
2012-08-21 16:05:33 ----A---- C:\CountCyclesWMVDecLog.txt
2012-08-20 20:25:00 ----D---- C:\Program Files\TabIt
2012-08-09 16:34:24 ----D---- C:\Documents and Settings\Master\Data aplikací\BSplayer Pro
2012-08-09 16:34:24 ----D---- C:\Documents and Settings\Master\Data aplikací\BSplayer
2012-08-09 16:34:23 ----D---- C:\Program Files\Webteh
2012-08-02 14:46:23 ----D---- C:\Documents and Settings\Master\Data aplikací\JAM Software
2012-08-02 14:46:21 ----D---- C:\Program Files\JAM Software

======List of files/folders modified in the last 1 month======

2012-08-30 10:53:57 ----D---- C:\WINDOWS\Temp
2012-08-30 10:52:08 ----D---- C:\WINDOWS\system32\drivers
2012-08-30 10:52:05 ----SD---- C:\WINDOWS\Tasks
2012-08-30 10:51:58 ----SHD---- C:\WINDOWS\Installer
2012-08-30 10:51:57 ----D---- C:\WINDOWS\WinSxS
2012-08-30 10:51:42 ----D---- C:\WINDOWS
2012-08-30 10:51:39 ----D---- C:\WINDOWS\system32
2012-08-30 10:50:52 ----RD---- C:\Program Files
2012-08-30 10:26:41 ----D---- C:\Documents and Settings\Master\Data aplikací\Dropbox
2012-08-30 10:25:56 ----A---- C:\WINDOWS\OEWABLog.txt
2012-08-30 10:15:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-08-30 10:14:40 ----D---- C:\WINDOWS\system32\CatRoot2
2012-08-30 10:13:58 ----D---- C:\WINDOWS\system32\Setup
2012-08-30 10:13:58 ----D---- C:\WINDOWS\AppPatch
2012-08-30 10:13:57 ----D---- C:\WINDOWS\system32\wbem
2012-08-30 10:13:55 ----RSD---- C:\WINDOWS\Fonts
2012-08-30 00:26:43 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-08-30 00:26:19 ----D---- C:\Program Files\Trillian
2012-08-30 00:09:11 ----HD---- C:\WINDOWS\inf
2012-08-30 00:09:01 ----D---- C:\WINDOWS\system32\CatRoot
2012-08-30 00:09:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-08-30 00:04:40 ----D---- C:\Program Files\Outlook Express
2012-08-30 00:02:00 ----D---- C:\Program Files\Movie Maker
2012-08-30 00:01:38 ----D---- C:\Documents and Settings\Master\Data aplikací\uTorrent
2012-08-29 23:38:56 ----D---- C:\WINDOWS\security
2012-08-29 23:36:30 ----D---- C:\Program Files\Messenger
2012-08-29 23:29:44 ----D---- C:\Program Files\Windows Media Player
2012-08-29 23:29:43 ----D---- C:\WINDOWS\Help
2012-08-29 23:29:37 ----D---- C:\WINDOWS\ehome
2012-08-29 23:29:35 ----D---- C:\WINDOWS\system32\inetsrv
2012-08-29 23:29:35 ----D---- C:\WINDOWS\ime
2012-08-29 23:29:22 ----D---- C:\WINDOWS\system32\usmt
2012-08-29 23:29:22 ----D---- C:\Program Files\Internet Explorer
2012-08-29 23:29:21 ----D---- C:\WINDOWS\PeerNet
2012-08-29 23:28:03 ----D---- C:\WINDOWS\system32\Restore
2012-08-29 23:28:03 ----D---- C:\WINDOWS\system32\npp
2012-08-29 23:28:02 ----D---- C:\WINDOWS\srchasst
2012-08-29 23:28:02 ----D---- C:\WINDOWS\msagent
2012-08-29 23:28:01 ----D---- C:\WINDOWS\system32\Com
2012-08-29 23:28:01 ----D---- C:\Program Files\NetMeeting
2012-08-29 23:27:57 ----D---- C:\Program Files\Windows NT
2012-08-29 23:27:52 ----D---- C:\Program Files\Common Files\System
2012-08-29 23:27:27 ----D---- C:\WINDOWS\system32\oobe
2012-08-29 23:27:26 ----D---- C:\WINDOWS\system
2012-08-29 21:16:17 ----D---- C:\Documents and Settings\Master\Data aplikací\vlc
2012-08-29 19:36:51 ----A---- C:\WINDOWS\NeroDigital.ini
2012-08-29 18:51:36 ----D---- C:\WINDOWS\Minidump
2012-08-29 17:26:16 ----D---- C:\Program Files\Common Files
2012-08-27 13:31:03 ----A---- C:\WINDOWS\system32\msvcsv60.dll
2012-08-23 14:25:33 ----D---- C:\Program Files\Waves
2012-08-22 21:17:27 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2012-08-20 14:10:32 ----D---- C:\Documents and Settings\Master\Data aplikací\Skype
2012-08-20 14:09:24 ----D---- C:\Documents and Settings\Master\Data aplikací\skypePM
2012-08-08 11:58:02 ----D---- C:\Documents and Settings\Master\Data aplikací\Adobe
2012-08-04 09:22:39 ----D---- C:\WINDOWS\Config
2012-08-03 23:50:26 ----SHD---- C:\System Volume Information
2012-07-31 12:41:15 ----D---- C:\Program Files\Adobe
2012-07-31 12:40:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2012-07-31 12:40:25 ----D---- C:\Program Files\Common Files\Adobe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JGOGO;JMicron Hot-Plug Driver; C:\WINDOWS\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; C:\WINDOWS\system32\DRIVERS\jraid.sys [2006-12-06 44416]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2012-06-28 691696]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2012-08-21 25256]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2007-05-31 11136]
R1 AswRdr;aswRdr; C:\WINDOWS\system32\drivers\AswRdr.sys [2012-08-21 35928]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2012-08-21 355632]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2012-08-21 54232]
R1 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2007-08-07 33052]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-08-21 21256]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2012-08-21 97608]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 asusgsb;ASUS Virtual Video Capture Device Driver; C:\WINDOWS\system32\drivers\asusgsb.sys [2007-05-31 12416]
R3 CompFilter;UVCCompositeFilter; C:\WINDOWS\system32\DRIVERS\lvbusflt.sys [2012-01-18 22176]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 LVRS;Logitech RightSound Filter Driver; C:\WINDOWS\system32\DRIVERS\lvrs.sys [2012-01-18 312096]
R3 LVUVC;Logitech HD Pro Webcam C910(UVC); C:\WINDOWS\system32\DRIVERS\lvuvc.sys [2012-01-18 4332960]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-05-11 6738432]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-08-14 83200]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys [2007-05-31 10752]
S1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2012-08-21 729752]
S3 acg3euy7;acg3euy7; C:\WINDOWS\system32\drivers\acg3euy7.sys []
S3 BEHRINGER_2902;usb-audio.de driver for BEHRINGER USB AUDIO; C:\WINDOWS\System32\Drivers\BUSB2902.sys [2009-10-30 384576]
S3 BUSB_AUDIO_WDM;BEHRINGER USB WDM AUDIO; C:\WINDOWS\system32\drivers\busbwdm.sys [2009-10-30 39488]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 MA_CMIDI;M-Audio USB Driver; C:\WINDOWS\system32\drivers\ma_cmidi.sys [2006-08-16 21888]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2012-02-15 43520]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-02-27 55144]
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2007-05-31 258560]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-08-21 44808]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-05-11 163908]
R2 UMVPFSrv;UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-01-18 450848]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2012-03-27 821608]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S2 MA_CMIDI_InstallerService;M-Audio Series II MIDI Installer; C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe []
S2 SwOffScheduler;Airytec Switch Off - Task Scheduler; C:\Program Files\Airytec\Switch Off\swoff.exe [2011-05-28 135168]
S2 SwOffWeb;Airytec Switch Off - Web Interface; C:\Program Files\Airytec\Switch Off\swoff.exe [2011-05-28 135168]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-06-06 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pomalé PC, pravděpodobně malware

#6 Příspěvek od vyosek »

:arrow: Stahnete OTL (viz muj podpis) a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
    
    netsvcs
    drivers32
    savembr:0
    
    /md5start
    adp3132.sys
    AGP440.sys
    ahcix86.sys
    ahcix86s.sys
    atapi.sys
    autochk.exe
    cdrom.sys
    cngaudit.dll
    cryptsvc.dll
    eNetHook.dll
    eventlog.dll
    explorer.exe
    hal.dll
    Changer.sys
    iaStor.sys
    iastorv.sys
    IdeChnDr.sys
    isapnp.sys
    JakNDis.sys
    KR10N.sys
    logevent.dll
    lsass.exe
    mv61xx.sys
    ndis.sys
    netlogon.dll
    ntelogon.dll
    nvata.sys
    nvatabus.sys
    nvgts.sys
    nvraid.sys
    nvrd32.sys
    nvstor.sys
    nvstor32.sys
    scecli.dll
    sceclt.dll
    smss.exe
    svchost.exe
    symmpi.sys
    tcpip.sys
    userinit.exe
    vaxscsi.sys
    viamraid.sys
    viasraid.sys
    ViPrt.sys
    winlogon.exe
    ws2_32.dll
    /md5stop
    
    %systemroot%*.* /U /s
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    %SYSTEMDRIVE%\*.exe
    
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    
    %SystemDrive%\PhysicalMBR.bin /md5 
    
    *crack* /s
    *keygen* /s
    *loader* /s
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Matt.Mikolaj

Re: Pomalé PC, pravděpodobně malware

#7 Příspěvek od Matt.Mikolaj »

OTL logfile created on: 30.8.2012 21:23:15 - Run 1
OTL by OldTimer - Version 3.2.59.1 Folder = C:\Documents and Settings\Master\Dokumenty\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1015,11 Mb Total Physical Memory | 416,66 Mb Available Physical Memory | 41,05% Memory free
2,38 Gb Paging File | 1,59 Gb Available in Paging File | 66,50% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34,18 Gb Total Space | 5,78 Gb Free Space | 16,91% Space Free | Partition Type: NTFS
Drive D: | 198,70 Gb Total Space | 8,56 Gb Free Space | 4,31% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 198,52 Gb Free Space | 85,25% Space Free | Partition Type: NTFS

Computer Name: MIKO | User Name: Master | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2012.08.30 21:21:46 | 000,598,528 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Master\Dokumenty\Downloads\OTL.exe
PRC - [2012.08.21 11:12:26 | 004,282,728 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012.08.21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.08.18 00:28:57 | 001,229,848 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
PRC - [2012.07.02 00:00:00 | 002,380,752 | ---- | M] (Cerulean Studios) -- C:\Program Files\Trillian\trillian.exe
PRC - [2012.06.14 04:08:56 | 027,595,032 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe
PRC - [2012.01.18 08:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
PRC - [2011.11.11 14:08:06 | 000,205,336 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2009.10.30 13:57:08 | 000,369,200 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.08.07 02:05:46 | 000,200,704 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2007.06.27 19:04:00 | 001,213,736 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007.06.27 19:03:40 | 000,152,872 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2007.06.01 09:37:20 | 000,380,928 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
PRC - [2007.05.31 14:29:44 | 000,258,560 | ---- | M] (ASUSTeK COMPUTER INC.) -- C:\WINDOWS\ATKKBService.exe


========== Modules (No Company Name) ==========

MOD - [2012.08.30 11:38:21 | 001,805,312 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12083000\algo.dll
MOD - [2012.08.18 00:28:55 | 000,442,392 | ---- | M] () -- C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\21.0.1180.83\ppgooglenaclpluginchrome.dll
MOD - [2012.08.18 00:28:54 | 012,236,824 | ---- | M] () -- C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll
MOD - [2012.08.18 00:28:52 | 003,997,720 | ---- | M] () -- C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\21.0.1180.83\pdf.dll
MOD - [2012.08.18 00:27:23 | 000,144,424 | ---- | M] () -- C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\21.0.1180.83\avutil-51.dll
MOD - [2012.08.18 00:27:22 | 000,266,792 | ---- | M] () -- C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\21.0.1180.83\avformat-54.dll
MOD - [2012.08.18 00:27:21 | 002,480,680 | ---- | M] () -- C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\21.0.1180.83\avcodec-54.dll
MOD - [2012.07.02 00:00:00 | 000,187,392 | ---- | M] () -- C:\Program Files\Trillian\libpng15.dll
MOD - [2012.07.02 00:00:00 | 000,065,536 | ---- | M] () -- C:\Program Files\Trillian\libungif.dll
MOD - [2012.07.02 00:00:00 | 000,059,904 | ---- | M] () -- C:\Program Files\Trillian\zlib1.dll
MOD - [2012.07.02 00:00:00 | 000,011,264 | ---- | M] () -- c:\Program Files\Trillian\languages\en\buddy.dll
MOD - [2012.07.02 00:00:00 | 000,007,168 | ---- | M] () -- c:\Program Files\Trillian\languages\en\talk.dll
MOD - [2012.07.02 00:00:00 | 000,006,656 | ---- | M] () -- c:\Program Files\Trillian\languages\en\trillian.dll
MOD - [2012.07.02 00:00:00 | 000,006,656 | ---- | M] () -- c:\Program Files\Trillian\languages\en\events.dll
MOD - [2012.07.02 00:00:00 | 000,003,584 | ---- | M] () -- c:\Program Files\Trillian\languages\en\toolkit.dll
MOD - [2012.02.20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012.02.20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011.11.11 14:08:18 | 007,956,504 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2011.11.11 14:08:18 | 000,342,552 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2011.11.11 14:08:18 | 000,128,536 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2011.11.11 14:08:18 | 000,029,208 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2011.11.11 14:08:06 | 002,145,304 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2008.07.10 16:27:42 | 000,132,608 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2008.04.14 08:51:48 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2007.05.31 14:29:48 | 000,761,856 | ---- | M] () -- C:\Program Files\ASUS\GamerOSD\ImageTransform.dll
MOD - [2007.05.31 14:29:42 | 000,643,142 | ---- | M] () -- C:\WINDOWS\aticlocklib.dll
MOD - [2007.05.11 00:03:00 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll
MOD - [2001.10.25 16:00:00 | 000,015,360 | ---- | M] () -- C:\WINDOWS\system32\tsd32.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe -- (MA_CMIDI_InstallerService)
SRV - [2012.08.21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.06.06 16:58:48 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012.01.18 08:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2011.05.28 22:24:28 | 000,135,168 | ---- | M] (Airytec) [Auto | Stopped] -- C:\Program Files\Airytec\Switch Off\swoff.exe -- (SwOffWeb)
SRV - [2011.05.28 22:24:28 | 000,135,168 | ---- | M] (Airytec) [Auto | Stopped] -- C:\Program Files\Airytec\Switch Off\swoff.exe -- (SwOffScheduler)
SRV - [2007.05.31 14:29:44 | 000,258,560 | ---- | M] (ASUSTeK COMPUTER INC.) [Auto | Running] -- C:\WINDOWS\ATKKBService.exe -- (ATKKeyboardService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (acg3euy7)
DRV - [2012.08.21 11:13:15 | 000,729,752 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012.08.21 11:13:15 | 000,355,632 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012.08.21 11:13:15 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012.08.21 11:13:14 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012.08.21 11:13:14 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012.08.21 11:13:13 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012.08.21 11:13:13 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.06.28 13:54:51 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2012.01.18 08:44:52 | 004,332,960 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC)
DRV - [2012.01.18 08:44:28 | 000,312,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS)
DRV - [2012.01.18 08:44:14 | 000,022,176 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvbusflt.sys -- (CompFilter)
DRV - [2009.10.30 13:39:44 | 000,384,576 | ---- | M] (BEHRINGER) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BUSB2902.sys -- (BEHRINGER_2902)
DRV - [2009.10.30 13:39:44 | 000,039,488 | ---- | M] (BEHRINGER) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\busbwdm.sys -- (BUSB_AUDIO_WDM)
DRV - [2007.08.07 02:15:07 | 000,033,052 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007.05.31 14:29:50 | 000,012,416 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\asusgsb.sys -- (asusgsb)
DRV - [2007.05.31 14:29:48 | 000,010,752 | ---- | M] (ASUSTeK COMPUTER INC.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Video3D32.sys -- (Video3D)
DRV - [2007.05.31 14:29:44 | 000,012,288 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\EIO.sys -- (EIO)
DRV - [2007.05.31 14:29:44 | 000,011,136 | ---- | M] (ASUSTeK COMPUTER INC.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\atkkbnt.sys -- (asuskbnt)
DRV - [2006.12.06 13:41:16 | 000,044,416 | R--- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\jraid.sys -- (JRAID)
DRV - [2006.08.16 10:23:46 | 000,021,888 | ---- | M] (M-Audio) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ma_cmidi.sys -- (MA_CMIDI)
DRV - [2006.08.14 15:09:48 | 000,083,200 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2006.03.17 11:18:58 | 000,392,960 | R--- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2006.02.07 13:52:58 | 000,006,912 | R--- | M] (JMicron ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\JGOGO.sys -- (JGOGO)
DRV - [2004.08.13 04:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-507921405-413027322-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-507921405-413027322-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird


========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Master\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Master\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\21.0.1180.83\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Master\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\21.0.1180.83\gcswf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Master\Local Settings\Data aplikac\u00ED\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: YouTube = C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: avast! WebRep = C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_0\
CHR - Extension: Fast save = C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lgpnbpalkblakfknihidolpapoimggbg\1.1_0\
CHR - Extension: Plugin Extension Manager = C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lillnffdgldhennjjnefmcefopbdfhlj\1.5_0\
CHR - Extension: Fast save = C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\mlfbcjcjhibnmigmjjkaoipcmmgidfgd\1.1_0\
CHR - Extension: Fast save = C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pheelfngeeimijkondfbmomahlellkog\1.1_0\
CHR - Extension: Gmail = C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012.06.06 17:24:51 | 000,000,770 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [36X Raid Configurer] C:\WINDOWS\System32\JMRaidSetup.exe (JMicron Technology Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe ()
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKU\S-1-5-21-507921405-413027322-725345543-1003..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\S-1-5-21-507921405-413027322-725345543-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - Startup: C:\Documents and Settings\Master\Nabídka Start\Programy\Po spuštění\Dropbox.lnk = C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-507921405-413027322-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C572E4A-E271-48AC-A823-44DAEA9F400A}: DhcpNameServer = 192.168.1.1 192.168.10.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Master\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Master\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012.06.06 15:50:18 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: Midi1 - C:\WINDOWS\System32\MA_CMIDN.DLL (M-Audio)
Drivers32: midi2 - C:\WINDOWS\System32\MA_CMIDN.DLL (M-Audio)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2012.08.30 10:52:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\avast! Free Antivirus
[2012.08.30 10:52:08 | 000,355,632 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012.08.30 10:52:08 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012.08.30 10:52:06 | 000,729,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012.08.30 10:52:06 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012.08.30 10:52:06 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012.08.30 10:52:05 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012.08.30 10:52:05 | 000,089,624 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012.08.30 10:52:04 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012.08.30 10:51:41 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012.08.30 10:51:39 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012.08.30 10:50:52 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012.08.30 10:50:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2012.08.30 10:14:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2012.08.29 23:29:45 | 001,372,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6.dll
[2012.08.29 23:29:45 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6r.dll
[2012.08.29 23:29:41 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msaud32.acm
[2012.08.29 23:29:41 | 000,290,816 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\WINDOWS\System32\dllcache\l3codeca.acm
[2012.08.29 23:29:41 | 000,086,016 | ---- | C] (Sipro Lab Telecom Inc.) -- C:\WINDOWS\System32\dllcache\sl_anet.acm
[2012.08.29 23:29:37 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dpcdll.dll
[2012.08.29 23:29:36 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\irbus.sys
[2012.08.29 23:29:36 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\smtpapi.dll
[2012.08.29 23:29:36 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rwnh.dll
[2012.08.29 23:29:36 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsdupd.exe
[2012.08.29 23:29:34 | 000,870,784 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ati3d1ag.dll
[2012.08.29 23:29:34 | 000,377,984 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2dvaa.dll
[2012.08.29 23:29:34 | 000,229,376 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2cqag.dll
[2012.08.29 23:29:34 | 000,201,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ati2dvag.dll
[2012.08.29 23:29:34 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aaclient.dll
[2012.08.29 23:29:33 | 001,888,992 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ati3duag.dll
[2012.08.29 23:29:33 | 000,516,768 | ---- | C] (ATI Technologies Inc. ) -- C:\WINDOWS\System32\ativvaxx.dll
[2012.08.29 23:29:33 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\azroles.dll
[2012.08.29 23:29:33 | 000,032,768 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativtmxx.dll
[2012.08.29 23:29:33 | 000,023,040 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativmvxx.ax
[2012.08.29 23:29:33 | 000,009,728 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\ativdaxx.ax
[2012.08.29 23:29:33 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx4.dll
[2012.08.29 23:29:32 | 000,651,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3ui.dll
[2012.08.29 23:29:32 | 000,184,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapp3hst.dll
[2012.08.29 23:29:32 | 000,179,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapphost.dll
[2012.08.29 23:29:32 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eappgnui.dll
[2012.08.29 23:29:32 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eapqec.dll
[2012.08.29 23:29:32 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3cfg.dll
[2012.08.29 23:29:32 | 000,056,320 | ---- | C] (Společnost Microsoft) -- C:\WINDOWS\System32\dot3msm.dll
[2012.08.29 23:29:32 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dhcpqec.dll
[2012.08.29 23:29:32 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dot3gpclnt.dll
[2012.08.29 23:29:32 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dimsroam.dll
[2012.08.29 23:29:31 | 000,032,285 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\hsfcisp2.dll
[2012.08.29 23:29:30 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\l2gpstore.dll
[2012.08.29 23:29:30 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpash.dll
[2012.08.29 23:29:30 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdnepr.dll
[2012.08.29 23:29:30 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdiultn.dll
[2012.08.29 23:29:30 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdbhc.dll
[2012.08.29 23:29:29 | 000,397,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcex.dll
[2012.08.29 23:29:29 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\microsoft.managementconsole.dll
[2012.08.29 23:29:29 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mssha.dll
[2012.08.29 23:29:29 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcfxcommon.dll
[2012.08.29 23:29:29 | 000,086,016 | ---- | C] (Conexant) -- C:\WINDOWS\System32\mdmxsdk.dll
[2012.08.29 23:29:29 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmcperf.exe
[2012.08.29 23:29:28 | 001,737,856 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\mtxparhd.dll
[2012.08.29 23:29:28 | 000,397,056 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\s3gnb.dll
[2012.08.29 23:29:28 | 000,290,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rhttpaa.dll
[2012.08.29 23:29:28 | 000,197,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napmontr.dll
[2012.08.29 23:29:28 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napstat.exe
[2012.08.29 23:29:28 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qagent.dll
[2012.08.29 23:29:28 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msshavmsg.dll
[2012.08.29 23:29:28 | 000,073,832 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slcoinst.dll
[2012.08.29 23:29:28 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qcliprov.dll
[2012.08.29 23:29:28 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\setupn.exe
[2012.08.29 23:29:28 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\napipsec.dll
[2012.08.29 23:29:27 | 000,286,792 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slextspk.dll
[2012.08.29 23:29:27 | 000,188,508 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slgen.dll
[2012.08.29 23:29:27 | 000,073,796 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slserv.exe
[2012.08.29 23:29:27 | 000,032,866 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\slrundll.exe
[2012.08.29 23:29:26 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsgqec.dll
[2012.08.29 23:29:26 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\verclsid.exe
[2012.08.29 23:29:24 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wlanapi.dll
[2012.08.29 23:29:22 | 000,032,866 | ---- | C] (Smart Link) -- C:\WINDOWS\slrundll.exe
[2012.08.29 23:29:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cs-cz
[2012.08.29 23:29:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2012.08.29 23:29:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cs
[2012.08.29 23:29:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2012.08.29 23:27:51 | 000,294,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dlimport.exe
[2012.08.29 23:25:57 | 000,701,440 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati2mtag.sys
[2012.08.29 23:25:57 | 000,326,912 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2012.08.29 23:25:57 | 000,104,960 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinrvxx.sys
[2012.08.29 23:25:57 | 000,073,216 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atintuxx.sys
[2012.08.29 23:25:57 | 000,063,663 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2012.08.29 23:25:57 | 000,063,488 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinxsxx.sys
[2012.08.29 23:25:57 | 000,057,856 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinbtxx.sys
[2012.08.29 23:25:57 | 000,056,623 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1btxx.sys
[2012.08.29 23:25:57 | 000,052,224 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinraxx.sys
[2012.08.29 23:25:57 | 000,036,463 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2012.08.29 23:25:57 | 000,034,735 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2012.08.29 23:25:57 | 000,031,744 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinxbxx.sys
[2012.08.29 23:25:57 | 000,030,671 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1raxx.sys
[2012.08.29 23:25:57 | 000,029,455 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2012.08.29 23:25:57 | 000,028,672 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinsnxx.sys
[2012.08.29 23:25:57 | 000,026,367 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1snxx.sys
[2012.08.29 23:25:57 | 000,021,343 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2012.08.29 23:25:57 | 000,014,336 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinpdxx.sys
[2012.08.29 23:25:57 | 000,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinttxx.sys
[2012.08.29 23:25:57 | 000,013,824 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\atinmdxx.sys
[2012.08.29 23:25:57 | 000,012,047 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2012.08.29 23:25:57 | 000,011,615 | ---- | C] (ATI Technologies Inc.) -- C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2012.08.29 23:25:57 | 000,004,255 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv01nt5.dll
[2012.08.29 23:25:57 | 000,003,967 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv02nt5.dll
[2012.08.29 23:25:57 | 000,003,775 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv11nt5.dll
[2012.08.29 23:25:57 | 000,003,711 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv09nt5.dll
[2012.08.29 23:25:57 | 000,003,647 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv07nt5.dll
[2012.08.29 23:25:57 | 000,003,615 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv05nt5.dll
[2012.08.29 23:25:57 | 000,003,135 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\adv08nt5.dll
[2012.08.29 23:25:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\network diagnostic
[2012.08.29 23:25:56 | 000,036,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthprint.sys
[2012.08.29 23:25:56 | 000,025,471 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\atv04nt5.dll
[2012.08.29 23:25:56 | 000,021,183 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\atv01nt5.dll
[2012.08.29 23:25:56 | 000,017,279 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\atv10nt5.dll
[2012.08.29 23:25:56 | 000,015,423 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2012.08.29 23:25:56 | 000,014,143 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\atv06nt5.dll
[2012.08.29 23:25:56 | 000,011,359 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\atv02nt5.dll
[2012.08.29 23:25:55 | 001,309,184 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\mtlstrm.sys
[2012.08.29 23:25:55 | 000,452,736 | ---- | C] (Matrox Graphics Inc.) -- C:\WINDOWS\System32\drivers\mtxparhm.sys
[2012.08.29 23:25:55 | 000,404,990 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slntamr.sys
[2012.08.29 23:25:55 | 000,180,360 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2012.08.29 23:25:55 | 000,166,912 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\drivers\s3gnbm.sys
[2012.08.29 23:25:55 | 000,129,535 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slnt7554.sys
[2012.08.29 23:25:55 | 000,126,686 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2012.08.29 23:25:55 | 000,095,424 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slnthal.sys
[2012.08.29 23:25:55 | 000,030,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rndismpx.sys
[2012.08.29 23:25:55 | 000,013,776 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\recagent.sys
[2012.08.29 23:25:55 | 000,013,240 | ---- | C] (Smart Link) -- C:\WINDOWS\System32\drivers\slwdmsup.sys
[2012.08.29 23:25:55 | 000,012,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mutohpen.sys
[2012.08.29 23:25:55 | 000,011,325 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\vchnt5.dll
[2012.08.29 23:25:55 | 000,005,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\smbali.sys
[2012.08.29 23:25:55 | 000,003,901 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\siint5.dll
[2012.08.29 23:25:54 | 000,025,471 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\watv10nt.sys
[2012.08.29 23:25:54 | 000,022,271 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\watv06nt.sys
[2012.08.29 23:25:54 | 000,011,935 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\wadv11nt.sys
[2012.08.29 23:25:54 | 000,011,871 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\wadv09nt.sys
[2012.08.29 23:25:54 | 000,011,807 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\wadv07nt.sys
[2012.08.29 23:25:54 | 000,011,295 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\wadv08nt.sys
[2012.08.29 23:22:17 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2012.08.29 21:33:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Dokumenty\Native Instruments Kontakt 4 vsti rtas v4.0.2.PC-AiR[h33t][Theslayerz]
[2012.08.29 18:44:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Local Settings\Data aplikací\TechSmith
[2012.08.29 17:28:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Dokumenty\Camtasia Studio
[2012.08.29 17:27:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\QuickTime
[2012.08.29 17:26:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Camtasia Studio 7
[2012.08.29 17:26:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\TechSmith Shared
[2012.08.29 17:25:52 | 000,000,000 | ---D | C] -- C:\Program Files\TechSmith
[2012.08.29 17:25:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\TechSmith
[2012.08.29 16:53:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Dokumenty\Camtasia Studio 7 + Keygen
[2012.08.29 15:07:21 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.08.29 15:07:19 | 000,000,000 | ---D | C] -- C:\rsit
[2012.08.29 15:06:22 | 000,356,352 | ---- | C] (eSellerate Inc.) -- C:\WINDOWS\eSellerateEngine.dll
[2012.08.29 15:05:33 | 000,000,000 | ---D | C] -- C:\Program Files\Deskshare
[2012.08.29 14:57:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Data aplikací\systweak
[2012.08.29 14:55:50 | 000,152,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\COMDLG32.OCX
[2012.08.29 14:45:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Nabídka Start\Programy\Webcam and Screen Recorder
[2012.08.29 14:15:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Dokumenty\Aerosmith 23 CD Discography Properly Tagged [VBR320] by vtwin88cube
[2012.08.29 00:12:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Synthesia
[2012.08.29 00:12:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Dokumenty\Synthesia Music
[2012.08.29 00:12:35 | 000,000,000 | ---D | C] -- C:\Program Files\Synthesia
[2012.08.29 00:03:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Dokumenty\Synthesia.v0.8.3.incl.Patch.&.Key
[2012.08.28 23:33:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Data aplikací\Synthesia
[2012.08.27 20:08:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Dokumenty\Safe House {2012} DVDRIP. Jaybob
[2012.08.26 22:54:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Data aplikací\Airytec
[2012.08.26 22:54:27 | 000,000,000 | ---D | C] -- C:\Program Files\Airytec
[2012.08.26 22:53:44 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Master\Nabídka Start\Programy\Nástroje pro správu
[2012.08.26 22:53:44 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Master\Dokumenty\Filmy
[2012.08.26 18:10:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Dokumenty\Audiffex
[2012.08.26 18:09:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Nabídka Start\Programy\Audiffex
[2012.08.26 15:10:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Dokumenty\Softube Plugins Bundles VST.RTAS-AiR[h33t][Theslayerz]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2012.08.30 21:27:05 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.08.30 21:27:02 | 000,001,030 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-507921405-413027322-725345543-1003UA.job
[2012.08.30 18:01:58 | 000,049,664 | ---- | M] () -- C:\Documents and Settings\Master\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.08.30 14:40:29 | 000,000,016 | ---- | M] () -- C:\WINDOWS\System32\w3data.vss
[2012.08.30 14:40:29 | 000,000,016 | ---- | M] () -- C:\WINDOWS\System32\msvcsv60.dll
[2012.08.30 14:40:29 | 000,000,016 | ---- | M] () -- C:\WINDOWS\msocreg32.dat
[2012.08.30 14:35:17 | 000,010,536 | ---- | M] () -- C:\Documents and Settings\Master\Plocha\Aerosmith - I don't wanna miss a thing.mid
[2012.08.30 14:35:11 | 000,012,923 | ---- | M] () -- C:\Documents and Settings\Master\Plocha\I dont wanna miss a thing.gp5
[2012.08.30 14:25:36 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012.08.30 10:52:09 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2012.08.30 10:52:06 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012.08.30 10:52:05 | 000,002,552 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012.08.30 10:25:52 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2012.08.30 10:25:50 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2012.08.30 10:25:47 | 002,334,544 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.08.30 10:25:41 | 000,002,262 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.08.30 10:15:51 | 000,430,632 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012.08.30 10:15:51 | 000,427,610 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2012.08.30 10:15:51 | 000,077,886 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2012.08.30 10:15:51 | 000,067,356 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012.08.30 10:14:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.08.29 23:25:43 | 000,250,576 | RHS- | M] () -- C:\ntldr
[2012.08.29 19:23:42 | 000,196,608 | ---- | M] () -- C:\WINDOWS\System32\drivers\nStandard.bin
[2012.08.29 18:47:14 | 003,275,806 | ---- | M] () -- C:\Documents and Settings\Master\Plocha\capture-1.avi
[2012.08.29 18:38:21 | 005,106,206 | ---- | M] () -- C:\Documents and Settings\Master\Plocha\Aerosmith - I dont' wanna miss a thing(rythm piano sheet).PDF
[2012.08.29 18:27:43 | 001,702,503 | ---- | M] () -- C:\Documents and Settings\Master\Plocha\I DONW WANNA MISS A THING 3s.jpg
[2012.08.29 18:04:41 | 000,088,396 | ---- | M] () -- C:\Documents and Settings\Master\Plocha\asdf.jpg
[2012.08.29 17:55:41 | 000,359,579 | ---- | M] () -- C:\Documents and Settings\Master\Plocha\idwmt.xml
[2012.08.29 17:51:02 | 000,074,565 | ---- | M] () -- C:\Documents and Settings\Master\Plocha\idwmat score.jpg
[2012.08.29 17:26:54 | 000,000,893 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Camtasia Studio 7.lnk
[2012.08.29 15:06:22 | 000,356,352 | ---- | M] (eSellerate Inc.) -- C:\WINDOWS\eSellerateEngine.dll
[2012.08.29 15:05:11 | 009,872,707 | ---- | M] () -- C:\Documents and Settings\Master\Dokumenty\My_Screen_Recorder_Pro_2.3_+_Crack.rar
[2012.08.29 00:33:50 | 000,013,275 | ---- | M] () -- C:\Documents and Settings\Master\Plocha\Kopie - I dont wanna miss a thing.gp5
[2012.08.29 00:27:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-507921405-413027322-725345543-1003Core.job
[2012.08.28 23:55:27 | 011,838,703 | ---- | M] () -- C:\Documents and Settings\Master\Dokumenty\Synthesia v0.8.2 - Portable Registered.rar
[2012.08.28 23:54:50 | 001,544,996 | ---- | M] () -- C:\Documents and Settings\Master\Dokumenty\Synthesia 0.8.1 (r1288) crack by Voltc.rar
[2012.08.27 13:25:34 | 011,878,444 | ---- | M] () -- C:\Documents and Settings\Master\Plocha\break.wav
[2012.08.27 13:25:11 | 008,908,854 | ---- | M] () -- C:\Documents and Settings\Master\Dokumenty\Audio_T1_1.aif
[2012.08.26 22:54:29 | 000,000,799 | ---- | M] () -- C:\Documents and Settings\Master\Plocha\Airytec Switch Off.lnk
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

Matt.Mikolaj

Re: Pomalé PC, pravděpodobně malware

#8 Příspěvek od Matt.Mikolaj »

========== Files Created - No Company Name ==========

[2012.08.30 21:27:05 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.08.30 10:52:09 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2012.08.30 10:52:05 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012.08.29 23:29:43 | 000,674,168 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.chm
[2012.08.29 23:29:43 | 000,354,468 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud1.wav
[2012.08.29 23:29:43 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud7.wav
[2012.08.29 23:29:43 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud6.wav
[2012.08.29 23:29:43 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud9.wav
[2012.08.29 23:29:43 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud8.wav
[2012.08.29 23:29:43 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud3.wav
[2012.08.29 23:29:43 | 000,086,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud5.wav
[2012.08.29 23:29:43 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud4.wav
[2012.08.29 23:29:43 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud2.wav
[2012.08.29 23:29:43 | 000,069,570 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.adm
[2012.08.29 23:29:43 | 000,028,164 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplay.chm
[2012.08.29 23:29:43 | 000,010,457 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.hta
[2012.08.29 23:29:43 | 000,001,771 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.css
[2012.08.29 23:29:43 | 000,001,746 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpocm.inf
[2012.08.29 23:29:43 | 000,000,420 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmploc.js
[2012.08.29 23:29:42 | 000,300,969 | ---- | C] () -- C:\WINDOWS\System32\dllcache\viz.wmv
[2012.08.29 23:29:42 | 000,058,456 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmp.inf
[2012.08.29 23:29:42 | 000,034,548 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmdm.inf
[2012.08.29 23:29:42 | 000,017,489 | ---- | C] () -- C:\WINDOWS\System32\dllcache\videobg.gif
[2012.08.29 23:29:42 | 000,013,540 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmfsdk.inf
[2012.08.29 23:29:42 | 000,008,677 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm7.gif
[2012.08.29 23:29:42 | 000,007,892 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm9.gif
[2012.08.29 23:29:42 | 000,007,636 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm2.gif
[2012.08.29 23:29:42 | 000,007,369 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm4.gif
[2012.08.29 23:29:42 | 000,006,241 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm3.gif
[2012.08.29 23:29:42 | 000,006,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm6.gif
[2012.08.29 23:29:42 | 000,005,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm1.gif
[2012.08.29 23:29:42 | 000,005,290 | ---- | C] () -- C:\WINDOWS\System32\dllcache\vidsamp.gif
[2012.08.29 23:29:42 | 000,004,193 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm8.gif
[2012.08.29 23:29:42 | 000,002,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm5.gif
[2012.08.29 23:29:41 | 000,572,557 | ---- | C] () -- C:\WINDOWS\System32\dllcache\rtuner.wmv
[2012.08.29 23:29:41 | 000,457,607 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mdlib.wmv
[2012.08.29 23:29:41 | 000,375,519 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nuskin.wmv
[2012.08.29 23:29:41 | 000,086,446 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plyr_err.chm
[2012.08.29 23:29:41 | 000,066,170 | ---- | C] () -- C:\WINDOWS\System32\dllcache\revert.wmz
[2012.08.29 23:29:41 | 000,036,870 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.inf
[2012.08.29 23:29:41 | 000,023,829 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tourbg.gif
[2012.08.29 23:29:41 | 000,022,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npds.zip
[2012.08.29 23:29:41 | 000,005,971 | ---- | C] () -- C:\WINDOWS\System32\dllcache\events.js
[2012.08.29 23:29:41 | 000,003,187 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tour.js
[2012.08.29 23:29:41 | 000,002,778 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogoh.gif
[2012.08.29 23:29:41 | 000,002,545 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogo.gif
[2012.08.29 23:29:41 | 000,002,469 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplay.gif
[2012.08.29 23:29:41 | 000,002,450 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpause.gif
[2012.08.29 23:29:41 | 000,002,375 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplayh.gif
[2012.08.29 23:29:41 | 000,002,371 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpauseh.gif
[2012.08.29 23:29:41 | 000,001,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\skins.inf
[2012.08.29 23:29:41 | 000,001,483 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst6.wpl
[2012.08.29 23:29:41 | 000,001,480 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst5.wpl
[2012.08.29 23:29:41 | 000,001,479 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst3.wpl
[2012.08.29 23:29:41 | 000,001,465 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst12.wpl
[2012.08.29 23:29:41 | 000,001,462 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst4.wpl
[2012.08.29 23:29:41 | 000,001,398 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taon.gif
[2012.08.29 23:29:41 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taonh.gif
[2012.08.29 23:29:41 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoff.gif
[2012.08.29 23:29:41 | 000,001,367 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoffh.gif
[2012.08.29 23:29:41 | 000,001,263 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst1.wpl
[2012.08.29 23:29:41 | 000,001,148 | ---- | C] () -- C:\WINDOWS\System32\dllcache\snd.htm
[2012.08.29 23:29:41 | 000,001,059 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst2.wpl
[2012.08.29 23:29:41 | 000,001,042 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst7.wpl
[2012.08.29 23:29:41 | 000,001,034 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst8.wpl
[2012.08.29 23:29:41 | 000,000,809 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst11.wpl
[2012.08.29 23:29:41 | 000,000,806 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst10.wpl
[2012.08.29 23:29:41 | 000,000,783 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst13.wpl
[2012.08.29 23:29:41 | 000,000,777 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst9.wpl
[2012.08.29 23:29:41 | 000,000,774 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst14.wpl
[2012.08.29 23:29:41 | 000,000,722 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst15.wpl
[2012.08.29 23:29:41 | 000,000,403 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npdrmv2.zip
[2012.08.29 23:29:40 | 000,381,425 | ---- | C] () -- C:\WINDOWS\System32\dllcache\copycd.wmv
[2012.08.29 23:29:40 | 000,184,130 | ---- | C] () -- C:\WINDOWS\System32\dllcache\compact.wmz
[2012.08.29 23:29:40 | 000,009,585 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.css
[2012.08.29 23:29:40 | 000,008,298 | ---- | C] () -- C:\WINDOWS\System32\dllcache\contents.htm
[2012.08.29 23:29:40 | 000,006,878 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.js
[2012.08.29 23:29:40 | 000,000,999 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bktrh.gif
[2012.08.29 23:29:40 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnth.gif
[2012.08.29 23:29:40 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnt.gif
[2012.08.29 23:29:40 | 000,000,772 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cntd.gif
[2012.08.29 23:29:40 | 000,000,760 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapph.gif
[2012.08.29 23:29:40 | 000,000,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapp.gif
[2012.08.29 23:25:56 | 000,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2012.08.29 23:25:56 | 000,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod
[2012.08.29 23:25:55 | 000,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
[2012.08.29 18:47:35 | 003,275,806 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\capture-1.avi
[2012.08.29 18:38:18 | 005,106,206 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\Aerosmith - I dont' wanna miss a thing(rythm piano sheet).PDF
[2012.08.29 18:35:37 | 001,111,552 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\jpegtopdf.exe
[2012.08.29 18:27:37 | 001,702,503 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\I DONW WANNA MISS A THING 3s.jpg
[2012.08.29 18:04:41 | 000,088,396 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\asdf.jpg
[2012.08.29 17:55:40 | 000,359,579 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\idwmt.xml
[2012.08.29 17:51:02 | 000,074,565 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\idwmat score.jpg
[2012.08.29 17:26:53 | 000,000,893 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Camtasia Studio 7.lnk
[2012.08.29 17:23:03 | 000,010,536 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\Aerosmith - I don't wanna miss a thing.mid
[2012.08.29 15:00:32 | 009,872,707 | ---- | C] () -- C:\Documents and Settings\Master\Dokumenty\My_Screen_Recorder_Pro_2.3_+_Crack.rar
[2012.08.29 13:02:06 | 000,013,275 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\Kopie - I dont wanna miss a thing.gp5
[2012.08.28 23:54:07 | 001,544,996 | ---- | C] () -- C:\Documents and Settings\Master\Dokumenty\Synthesia 0.8.1 (r1288) crack by Voltc.rar
[2012.08.28 23:53:56 | 011,838,703 | ---- | C] () -- C:\Documents and Settings\Master\Dokumenty\Synthesia v0.8.2 - Portable Registered.rar
[2012.08.28 19:23:37 | 000,012,923 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\I dont wanna miss a thing.gp5
[2012.08.27 13:25:24 | 011,878,444 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\break.wav
[2012.08.27 13:25:11 | 008,908,854 | ---- | C] () -- C:\Documents and Settings\Master\Dokumenty\Audio_T1_1.aif
[2012.08.26 22:54:28 | 000,000,799 | ---- | C] () -- C:\Documents and Settings\Master\Plocha\Airytec Switch Off.lnk
[2012.08.23 14:12:18 | 000,000,005 | ---- | C] () -- C:\WINDOWS\jidgjinf.ini
[2012.08.23 14:11:18 | 000,000,005 | ---- | C] () -- C:\WINDOWS\jidgjikl.ini
[2012.08.23 14:09:37 | 000,000,005 | ---- | C] () -- C:\WINDOWS\jidgjicm.ini
[2012.08.23 14:09:29 | 000,000,005 | ---- | C] () -- C:\WINDOWS\jidgjipm.ini
[2012.08.23 14:09:29 | 000,000,005 | ---- | C] () -- C:\WINDOWS\jidgjibl.ini
[2012.08.23 14:09:10 | 000,000,005 | ---- | C] () -- C:\WINDOWS\jidgjiip.ini
[2012.08.23 14:09:10 | 000,000,005 | ---- | C] () -- C:\WINDOWS\jidgjihk.ini
[2012.08.23 14:09:10 | 000,000,005 | ---- | C] () -- C:\WINDOWS\jidgjiei.ini
[2012.08.23 14:09:10 | 000,000,005 | ---- | C] () -- C:\WINDOWS\jidgjiaf.ini
[2012.06.29 13:50:44 | 000,002,240 | ---- | C] () -- C:\WINDOWS\LENDIG.sys
[2012.06.19 11:55:28 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2012.06.15 19:10:20 | 000,000,100 | ---- | C] () -- C:\Documents and Settings\Master\default.pls
[2012.06.13 01:22:02 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2012.06.11 15:31:41 | 000,049,664 | ---- | C] () -- C:\Documents and Settings\Master\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.06.10 17:14:53 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2012.06.08 14:39:30 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\msvcsv60.dll
[2012.06.08 14:39:30 | 000,000,016 | ---- | C] () -- C:\WINDOWS\msocreg32.dat
[2012.06.06 18:27:49 | 000,104,584 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2012.06.06 17:42:20 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012.06.06 17:39:47 | 002,334,544 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.06.06 16:09:19 | 000,643,142 | ---- | C] () -- C:\WINDOWS\aticlocklib.dll
[2012.06.06 16:09:19 | 000,110,592 | ---- | C] () -- C:\WINDOWS\R5ClkLib.dll
[2012.06.06 16:09:19 | 000,020,480 | ---- | C] () -- C:\WINDOWS\HyperDrive.exe
[2012.06.06 16:09:18 | 000,196,653 | ---- | C] () -- C:\WINDOWS\System32\drivers\aVivid.bin
[2012.06.06 16:09:18 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\drivers\nVivid.bin
[2012.06.06 16:09:18 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\drivers\nStandard.bin
[2012.06.06 16:09:18 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\drivers\nAsmedia.bin
[2012.06.06 16:09:18 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\drivers\nAdvanced.bin
[2012.06.06 16:09:18 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\drivers\aAdvanced.bin
[2012.06.06 16:09:18 | 000,196,582 | ---- | C] () -- C:\WINDOWS\System32\drivers\aStandard.bin
[2012.06.06 16:09:18 | 000,196,582 | ---- | C] () -- C:\WINDOWS\System32\drivers\aAsmedia.bin
[2012.06.06 16:09:18 | 000,000,018 | ---- | C] () -- C:\WINDOWS\System32\atkid.ini
[2012.06.06 16:09:17 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2012.06.06 16:09:17 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2012.06.06 16:09:17 | 000,046,592 | ---- | C] () -- C:\WINDOWS\System32\asfrench.dll
[2012.06.06 16:09:17 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\asrussian.dll
[2012.06.06 16:09:17 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\asgerman.dll
[2012.06.06 16:09:17 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\aseng.dll
[2012.06.06 16:09:17 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\askorean.dll
[2012.06.06 16:09:17 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\asjapan.dll
[2012.06.06 16:09:17 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\ASCHT.dll
[2012.06.06 16:09:17 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\aschs.dll
[2012.06.06 15:55:17 | 000,015,795 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2012.06.06 15:55:09 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2012.06.06 15:55:08 | 000,015,481 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2012.06.06 15:54:59 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2012.06.06 15:52:01 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012.06.06 15:48:06 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012.01.18 08:44:00 | 010,920,984 | ---- | C] () -- C:\WINDOWS\System32\LogiDPP.dll
[2012.01.18 08:44:00 | 000,336,408 | ---- | C] () -- C:\WINDOWS\System32\DevManagerCore.dll
[2012.01.18 08:44:00 | 000,104,472 | ---- | C] () -- C:\WINDOWS\System32\LogiDPPApp.exe
[2011.11.17 03:40:38 | 000,028,418 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2011.08.12 12:20:14 | 000,015,896 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll

========== LOP Check ==========

[2012.07.21 11:02:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ableton
[2012.08.30 10:50:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2012.06.28 13:54:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2012.06.06 17:29:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2012.06.23 23:09:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Leawo
[2012.07.21 12:16:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\M-Audio
[2012.06.06 18:30:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2012.06.10 12:55:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Steinberg
[2012.08.29 17:26:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TechSmith
[2012.08.22 21:17:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2012.06.10 13:03:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\VST3 Presets
[2012.06.29 13:22:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Wave Arts
[2012.06.09 17:34:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012.07.21 11:02:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Ableton
[2012.08.26 22:54:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Airytec
[2012.08.09 16:43:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\BSplayer
[2012.08.09 16:34:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\BSplayer Pro
[2012.06.28 14:24:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\DAEMON Tools Lite
[2012.08.30 10:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Dropbox
[2012.06.09 16:00:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\eJamming
[2012.08.02 14:46:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\JAM Software
[2012.06.11 13:22:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Leadertech
[2012.06.23 23:09:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Leawo
[2012.06.06 18:40:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Publish Providers
[2012.06.13 18:29:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Sony
[2012.06.06 17:28:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Sony Setup
[2012.07.22 11:17:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Steinberg
[2012.08.30 14:32:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Synthesia
[2012.08.29 14:57:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\systweak
[2012.06.08 21:34:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Thinstall
[2012.06.23 23:09:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\tiger-k
[2012.06.21 22:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Trillian
[2012.08.30 12:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\uTorrent
[2012.08.22 21:23:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Waves
[2012.06.29 13:23:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Waves Audio
[2012.08.22 21:23:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Waves Preferences
[2012.08.30 10:52:06 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
[2012.08.30 10:25:50 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job

========== Purity Check ==========



========== Custom Scans ==========

< >

< >

< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\system32\DRIVERS\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\autochk.exe
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe

< MD5 for: CDROM.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2004.08.03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: HAL.DLL >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.14 00:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.14 00:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\hal.dll
[2004.08.03 22:59:14 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll

< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\changer.sys

< MD5 for: ISAPNP.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2001.10.24 11:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2001.10.25 16:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\drivers\system32\DRIVERS\isapnp.sys
[2001.10.25 16:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys

< MD5 for: LSASS.EXE >
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

< MD5 for: NETLOGON.DLL >
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe

< MD5 for: SVCHOST.EXE >
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll

< >

< %systemroot%*.* /U /s >
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\053a8d720f751c64c56fbe8b6600daef\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\053a8d720f751c64c56fbe8b6600daef\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\11aafafbb87ec74d28458e82d4e698ae\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\11aafafbb87ec74d28458e82d4e698ae\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\1d8dd98abe0ed0d26bc073a83ddc074b\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\1d8dd98abe0ed0d26bc073a83ddc074b\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\24957a983e1ed82751d0e04e4d999dc7\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\24957a983e1ed82751d0e04e4d999dc7\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\2669788b2ed683212782ea820636565b\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\2669788b2ed683212782ea820636565b\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\29ef1050760378dde1308339cd54188f\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\29ef1050760378dde1308339cd54188f\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\343ee728fc29446bf7afc2cdaef1b332\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\343ee728fc29446bf7afc2cdaef1b332\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\34448bd8142379149cb8cef0f5a0f690\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\34448bd8142379149cb8cef0f5a0f690\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\34be356f9a111a17675dc288437e09e3\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\34be356f9a111a17675dc288437e09e3\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\40ff1c2576d72a940c4903dd67d9e7f4\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\40ff1c2576d72a940c4903dd67d9e7f4\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\4f117ea82f047151f372fc40eae8b663\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\4f117ea82f047151f372fc40eae8b663\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\513c4590bd1894ef6eabf763bf3a7503\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\513c4590bd1894ef6eabf763bf3a7503\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\54438091347d420ae27601eb9fcb4587\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\54438091347d420ae27601eb9fcb4587\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\701bbc439e2ff47a457d9740440ec948\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\701bbc439e2ff47a457d9740440ec948\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\7a93be16865afe5068a00f32d0ad1246\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\7a93be16865afe5068a00f32d0ad1246\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\7ea0907c12389f8327ba547c9e394348\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\7ea0907c12389f8327ba547c9e394348\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\7fce958b0ca0fd79d0e07ec7f1d00afc\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\7fce958b0ca0fd79d0e07ec7f1d00afc\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\83fea40c19f48d8678633ac5af441e54\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\83fea40c19f48d8678633ac5af441e54\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\92082761f51194cdf64ab9e514c4b224\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\92082761f51194cdf64ab9e514c4b224\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\96596298c814e2d472eb776751230590\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\96596298c814e2d472eb776751230590\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\9e0a3a14ec0d4e4d61a1ad2b435c7de0\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\9e0a3a14ec0d4e4d61a1ad2b435c7de0\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\b5d199e63d3a54cb10dea086bab42b9b\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\b5d199e63d3a54cb10dea086bab42b9b\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\b95839b4d5e2c0bda9ff4803479a62ae\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\b95839b4d5e2c0bda9ff4803479a62ae\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\ba698011e4f92f4f5a7de348c0eb7e8f\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\ba698011e4f92f4f5a7de348c0eb7e8f\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\cc3db833e3f609b71eae88255a252a15\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\cc3db833e3f609b71eae88255a252a15\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\e5a6ce1f8ea60105c71471c731c05538\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\e5a6ce1f8ea60105c71471c731c05538\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\f130e00444d27b807b3e818375c146d6\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\f130e00444d27b807b3e818375c146d6\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\f140665df4e18766cc361fea1d99e7c3\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\f140665df4e18766cc361fea1d99e7c3\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\f8f14336809d26202246a8947e41aa50\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\f8f14336809d26202246a8947e41aa50\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2012.07.21 11:02:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Ableton
[2012.08.08 11:58:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Adobe
[2012.06.15 18:47:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Ahead
[2012.08.26 22:54:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Airytec
[2012.07.08 15:19:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Apple Computer
[2012.08.09 16:43:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\BSplayer
[2012.08.09 16:34:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\BSplayer Pro
[2012.06.28 14:24:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\DAEMON Tools Lite
[2012.08.30 10:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Dropbox
[2012.06.19 20:27:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\dvdcss
[2012.06.09 16:00:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\eJamming
[2012.06.06 15:53:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Identities
[2012.06.08 14:36:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\InstallShield
[2012.08.02 14:46:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\JAM Software
[2012.06.11 13:22:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Leadertech
[2012.06.23 23:09:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Leawo
[2012.06.06 16:21:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Macromedia
[2012.06.27 13:53:21 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Master\Data aplikací\Microsoft
[2012.06.06 18:40:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Publish Providers
[2012.08.20 14:10:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Skype
[2012.08.20 14:09:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\skypePM
[2012.06.13 18:29:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Sony
[2012.06.06 17:28:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Sony Setup
[2012.07.22 11:17:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Steinberg
[2012.08.30 14:32:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Synthesia
[2012.08.29 14:57:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\systweak
[2012.06.08 21:34:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Thinstall
[2012.06.23 23:09:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\tiger-k
[2012.06.21 22:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Trillian
[2012.08.30 12:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\uTorrent
[2012.08.30 16:00:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\vlc
[2012.08.22 21:23:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Waves
[2012.06.29 13:23:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Waves Audio
[2012.08.22 21:23:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\Waves Preferences
[2012.06.06 16:24:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Data aplikací\WinRAR

< %APPDATA%\*.exe /s >
[2009.08.11 21:21:26 | 000,087,552 | ---- | M] () -- C:\Documents and Settings\Master\Data aplikací\BSplayer\AC3 Filter\ac3config.exe
[2009.08.11 21:21:30 | 000,090,112 | ---- | M] () -- C:\Documents and Settings\Master\Data aplikací\BSplayer\AC3 Filter\spdif_test.exe
[2010.03.22 14:52:04 | 000,697,690 | ---- | M] () -- C:\Documents and Settings\Master\Data aplikací\BSplayer\AC3 Filter\unins000.exe
[2010.08.14 10:42:54 | 000,113,152 | ---- | M] () -- C:\Documents and Settings\Master\Data aplikací\BSplayer\Haali media splitter\dsmux.exe
[2010.08.14 10:45:10 | 000,358,400 | ---- | M] () -- C:\Documents and Settings\Master\Data aplikací\BSplayer\Haali media splitter\gdsmux.exe
[2010.08.14 10:42:06 | 000,137,728 | ---- | M] () -- C:\Documents and Settings\Master\Data aplikací\BSplayer\Haali media splitter\mkv2vfr.exe
[2010.09.30 15:30:22 | 000,042,305 | ---- | M] () -- C:\Documents and Settings\Master\Data aplikací\BSplayer\Haali media splitter\uninstall.exe
[2012.06.14 04:08:56 | 027,595,032 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe
[2012.06.14 04:09:00 | 000,874,440 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\DropboxUpdateHelper.exe
[2012.06.14 04:09:06 | 000,181,776 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Uninstall.exe
[2012.06.30 17:49:08 | 000,045,056 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Master\Data aplikací\Microsoft\Installer\{009AC76E-1A66-4682-82B7-417E77F3C648}\ARPPRODUCTICON.exe
[2012.06.11 13:22:08 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Master\Data aplikací\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2012.06.06 18:20:46 | 052,770,576 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Master\Data aplikací\Sony Setup\64993CD0-67D1-4244-A2BC-FD73F4DA5B62\dotnetfx3.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2012.06.28 13:54:51 | 000,691,696 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2012.06.06 17:38:16 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2012.06.06 17:38:16 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2012.06.06 17:38:15 | 000,487,424 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2012.08.30 10:52:05 | 000,002,552 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT
[2012.08.30 10:25:47 | 002,334,544 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2012.08.29 23:18:03 | 000,009,367 | ---- | M] () -- C:\WINDOWS\system32\lvcoinst.log
[2012.08.30 14:40:29 | 000,000,016 | ---- | M] () -- C:\WINDOWS\system32\msvcsv60.dll
[2012.08.30 10:15:51 | 000,077,886 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2012.08.30 10:15:51 | 000,067,356 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2012.08.30 10:15:51 | 000,427,610 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2012.08.30 10:15:51 | 000,430,632 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2012.08.30 10:15:51 | 001,017,012 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2012.08.30 10:14:36 | 000,000,247 | ---- | M] () -- C:\WINDOWS\system32\spupdwxp.log
[2012.08.30 14:40:29 | 000,000,016 | ---- | M] () -- C:\WINDOWS\system32\w3data.vss
[2012.08.30 10:25:41 | 000,002,262 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 08:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
"Google Update" = "C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c -- [2012.06.06 16:14:36 | 000,116,648 | ---- | M] (Google Inc.)
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" -- [2007.06.27 19:03:40 | 000,152,872 | ---- | M] (Nero AG)
"DAEMON Tools Lite" = "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun -- [2009.10.30 13:57:08 | 000,369,200 | ---- | M] (DT Soft Ltd)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]
"" =

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.08.30 21:27:05 | 000,000,512 | ---- | M] () MD5=006B7ECFD48D5F615B7DB60A1A65DC94 -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2012.08.22 21:48:28 | 000,000,762 | ---- | M] () -- \Documents and Settings\All Users\Nabídka Start\Programy\Waves\Documents\X-Crackle Help.lnk
[2012.06.09 13:56:51 | 000,017,459 | ---- | M] () -- \Documents and Settings\Master\Data aplikací\uTorrent\Ableton Live 8.2.2 (CRACKED) [theLEAK].torrent
[2012.07.18 15:50:02 | 000,002,562 | ---- | M] () -- \Documents and Settings\Master\Data aplikací\uTorrent\CocSoft.Stream.Down.v6.8.0.Cracked-CzW.torrent
[2012.08.29 14:59:29 | 000,003,258 | ---- | M] () -- \Documents and Settings\Master\Data aplikací\uTorrent\My_Screen_Recorder_Pro_2.3_+_Crack.rar.torrent
[2012.08.28 23:53:57 | 000,001,365 | ---- | M] () -- \Documents and Settings\Master\Data aplikací\uTorrent\Synthesia 0.8.1 (r1288) crack by Voltc.rar.torrent
[2012.08.29 15:05:11 | 009,872,707 | ---- | M] () -- \Documents and Settings\Master\Dokumenty\My_Screen_Recorder_Pro_2.3_+_Crack.rar
[2012.08.28 23:54:50 | 001,544,996 | ---- | M] () -- \Documents and Settings\Master\Dokumenty\Synthesia 0.8.1 (r1288) crack by Voltc.rar
[2012.08.29 14:59:29 | 000,003,258 | ---- | M] () -- \Documents and Settings\Master\Dokumenty\Downloads\[isoHunt] My_Screen_Recorder_Pro_2.3_ _Crack.rar.torrent
[2012.08.28 23:53:57 | 000,001,365 | ---- | M] () -- \Documents and Settings\Master\Dokumenty\Downloads\[isoHunt] Synthesia_0.8.1_r1288_crack_by_Voltc.6569592.TPB.torrent
[2012.08.22 21:42:19 | 000,000,762 | ---- | M] () -- \Documents and Settings\Master\Nabídka Start\Programy\Waves\Documents\X-Crackle help.lnk
[2012.08.29 15:05:15 | 000,000,887 | ---- | M] () -- \Documents and Settings\Master\Recent\My_Screen_Recorder_Pro_2.3_+_Crack.lnk
[2012.08.28 23:58:24 | 000,000,682 | ---- | M] () -- \Documents and Settings\Master\Recent\Synthesia 0.8.1 (r1288) crack by Voltc.lnk
[2012.08.28 23:56:07 | 000,001,112 | ---- | M] () -- \Documents and Settings\Master\Recent\Synthesia 0.8.2 (r1507) crack by Voltc.lnk
[2008.08.07 11:28:04 | 001,159,409 | ---- | M] () -- \Program Files\Adobe\Adobe After Effects CS4\Support Files\Presets\Image - Special Effects\Cracked Tiles.ffx
[2004.06.28 17:08:30 | 001,486,848 | ---- | M] () -- \Program Files\Waves\Plug-Ins\XCrackle.dll
[2005.04.28 17:22:20 | 000,067,537 | ---- | M] () -- \Program Files\Waves\Plug-Ins\Documents\XCrackle.pdf
[2012.06.30 12:24:05 | 000,000,030 | ---- | M] () -- \Program Files\Waves\Plug-Ins\Plug-In Settings\X-Crackle Settings.xps

< *keygen* /s >
[2012.06.08 12:32:30 | 000,015,546 | ---- | M] () -- \Documents and Settings\Master\Data aplikací\uTorrent\AmpliTube 3+keygen.rar.torrent
[2012.08.29 16:52:48 | 000,013,740 | ---- | M] () -- \Documents and Settings\Master\Data aplikací\uTorrent\Camtasia Studio 7 + Keygen.torrent
[2012.06.07 22:54:23 | 000,017,744 | ---- | M] () -- \Documents and Settings\Master\Data aplikací\uTorrent\IK.Multimedia.AmpliTube.v3.0.VST.RTAS.Incl.KeyGen-DYNAMiCS - [ www.torrentday.com ].torrent
[2012.06.06 18:55:38 | 000,001,089 | ---- | M] () -- \Documents and Settings\Master\Data aplikací\uTorrent\Power ISO v3.8 + keygen [h33t] [Original].torrent
[2012.06.23 08:12:46 | 000,000,192 | ---- | M] () -- \Documents and Settings\Master\Data aplikací\uTorrent\Windows XP Pro Keygen.torrent
[2012.06.08 12:59:47 | 200,650,967 | ---- | M] () -- \Documents and Settings\Master\Dokumenty\AmpliTube 3+keygen.rar
[2012.08.29 16:57:59 | 000,465,920 | ---- | M] () -- \Documents and Settings\Master\Dokumenty\Camtasia Studio 7 + Keygen\Camtasia_Studio_7_Keygen.exe
[2012.08.29 16:52:48 | 000,013,740 | ---- | M] () -- \Documents and Settings\Master\Dokumenty\Downloads\[isoHunt] Camtasia_Studio_7___Keygen.5493137.TPB.torrent
[2012.06.23 08:13:17 | 000,000,808 | ---- | M] () -- \Documents and Settings\Master\Recent\Windows XP Pro Keygen.lnk

< *loader* /s >
[2008.09.03 02:14:34 | 000,217,088 | ---- | M] () -- \Program Files\Adobe\Adobe After Effects CS4\Support Files\MXF_SDK_MetaMetadata_BinaryLoader_r.4.1.1.223.dll
[2007.03.14 19:21:36 | 004,937,904 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\Photodownloader.exe
[2007.03.14 17:07:28 | 000,011,161 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\bitmaps\main_window\C_LoadError.png
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\da_dk\Photodownloader.ini
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\de_de\Photodownloader.ini
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\en_us\Photodownloader.ini
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\es_es\Photodownloader.ini
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\fi_fi\Photodownloader.ini
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\fr_fr\Photodownloader.ini
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\it_it\Photodownloader.ini
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\ja_jp\Photodownloader.ini
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\ko_kr\Photodownloader.ini
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\nl_nl\Photodownloader.ini
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\no_no\Photodownloader.ini
[2007.03.14 17:07:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\pt_br\Photodownloader.ini
[2007.03.14 17:07:30 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\sv_se\Photodownloader.ini
[2007.03.14 17:07:30 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\zh_cn\Photodownloader.ini
[2007.03.14 17:07:30 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS3\apd\shared_assets\locales\zh_tw\Photodownloader.ini
[2008.08.28 19:34:20 | 004,965,736 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\Photodownloader.exe
[2008.08.28 16:42:12 | 000,011,161 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\bitmaps\main_window\C_LoadError.png
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\da_dk\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\de_de\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\en_us\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\es_es\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\fi_fi\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\fr_fr\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\it_it\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\ja_jp\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\ko_kr\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\nl_nl\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\no_no\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\pt_br\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\sv_se\Photodownloader.ini
[2008.08.28 16:42:14 | 000,000,308 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\zh_cn\Photodownloader.ini
[2008.08.28 16:42:16 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS4\apd\shared_assets\locales\zh_tw\Photodownloader.ini
[2008.08.26 01:32:24 | 000,217,088 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS4\MXF_SDK_MetaMetadata_BinaryLoader_r.4.1.1.223.dll
[2007.03.14 17:10:18 | 000,088,333 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\ar_AE\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:20 | 000,025,188 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\cs_CZ\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:26 | 000,032,022 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\da_DK\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:28 | 000,032,216 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\de_DE\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:30 | 000,027,655 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\el_GR\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:36 | 000,030,891 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\en_US\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:38 | 000,032,399 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\es_ES\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:42 | 000,032,333 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\fi_FI\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:42 | 000,032,393 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\fr_FR\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:46 | 000,022,871 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\he_IL\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:48 | 000,025,272 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\hu_HU\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:50 | 000,032,109 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\it_IT\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:50 | 000,032,441 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\ja_JP\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:52 | 000,032,499 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\ko_KR\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:54 | 000,032,074 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\nb_NO\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:56 | 000,032,110 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\nl_NL\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:10:58 | 000,024,996 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\pl_PL\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:11:00 | 000,031,772 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\pt_BR\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:11:02 | 000,024,463 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\ro_RO\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:11:04 | 000,025,054 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\ru_RU\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:11:06 | 000,032,171 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\sv_SE\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:11:06 | 000,024,411 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\tr_TR\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:11:08 | 000,025,525 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\uk_UA\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:11:10 | 000,032,741 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\zh_CN\Bridge\2.0\images\br_photo_downloader.png
[2007.03.14 17:11:10 | 000,032,833 | ---- | M] () -- \Program Files\Common Files\Adobe\Help\zh_TW\Bridge\2.0\images\br_photo_downloader.png
[2007.03.08 16:35:32 | 000,004,239 | ---- | M] () -- \Program Files\Common Files\Adobe\Startup Scripts CS3\Adobe Version Cue\VersionCueSDKLoader.jsx
[2007.06.27 19:03:00 | 000,177,448 | ---- | M] () -- \Program Files\Common Files\Ahead\Lib\NeGuideStoreLoader.dll
[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.dll
[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.tlb
[2010.03.04 12:25:54 | 000,002,223 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp7_azul_preloader.swf
[2010.03.04 12:25:54 | 000,001,841 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp7_black_outline_preloader.swf
[2010.03.04 12:25:54 | 000,001,810 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp7_black_preloader.swf
[2010.03.04 12:25:54 | 000,002,173 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp7_blue_preloader.swf
[2010.03.04 12:25:54 | 000,028,899 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp7_branded_large_preloader.swf
[2010.03.04 12:25:54 | 000,017,183 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp7_branded_small_preloader.swf
[2010.03.04 12:25:54 | 000,002,140 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp7_gray_grad_preloader.swf
[2010.03.04 12:25:54 | 000,001,845 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp7_white_preloader.swf
[2010.03.04 12:25:54 | 000,002,278 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp8_azul_preloader.swf
[2010.03.04 12:25:54 | 000,001,899 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp8_black_outline_preloader.swf
[2010.03.04 12:25:54 | 000,001,863 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp8_black_preloader.swf
[2010.03.04 12:25:54 | 000,002,227 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp8_blue_preloader.swf
[2010.03.04 12:25:54 | 000,028,967 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp8_branded_large_preloader.swf
[2010.03.04 12:25:54 | 000,017,248 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp8_branded_small_preloader.swf
[2010.03.04 12:25:54 | 000,002,204 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp8_gray_grad_preloader.swf
[2010.03.04 12:25:54 | 000,001,899 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\fp8_white_preloader.swf
[2010.03.04 12:25:54 | 000,236,529 | ---- | M] () -- \Program Files\TechSmith\Camtasia Studio 7\Media\Studio\Swf\Preloaders\preloaders_src.zip
[2008.06.20 19:13:32 | 000,044,032 | ---- | M] () -- \Program Files\WinRAR\RarExtLoader.exe
[2004.08.17 15:49:06 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll
[2012.06.27 13:50:13 | 000,082,784 | ---- | M] () -- \WINDOWS\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll
[2008.04.14 00:01:48 | 000,230,912 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe
[2008.04.14 00:01:50 | 000,278,528 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd
[2008.04.14 05:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\dmloader.dll
[2008.04.13 20:31:47 | 000,230,912 | ---- | M] () -- \WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\osloader.exe
[2008.04.13 20:31:48 | 000,278,528 | ---- | M] () -- \WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\osloader.ntd
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]

========== Alternate Data Streams ==========

@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:888AFB86
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:6F4E31ED

< End of report >

Matt.Mikolaj

Re: Pomalé PC, pravděpodobně malware

#9 Příspěvek od Matt.Mikolaj »

OTL Extras logfile created on: 30.8.2012 21:23:15 - Run 1
OTL by OldTimer - Version 3.2.59.1 Folder = C:\Documents and Settings\Master\Dokumenty\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1015,11 Mb Total Physical Memory | 416,66 Mb Available Physical Memory | 41,05% Memory free
2,38 Gb Paging File | 1,59 Gb Available in Paging File | 66,50% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34,18 Gb Total Space | 5,78 Gb Free Space | 16,91% Space Free | Partition Type: NTFS
Drive D: | 198,70 Gb Total Space | 8,56 Gb Free Space | 4,31% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 198,52 Gb Free Space | 85,25% Space Free | Partition Type: NTFS

Computer Name: MIKO | User Name: Master | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-507921405-413027322-725345543-1003\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- C:\Documents and Settings\Master\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (Google Inc.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Trillian\trillian.exe" = C:\Program Files\Trillian\trillian.exe:*:Enabled:Trillian -- (Cerulean Studios)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"C:\Program Files\eJamming\eJammingAUDiiO\eJammingAUDiiO.exe" = C:\Program Files\eJamming\eJammingAUDiiO\eJammingAUDiiO.exe:*:Enabled:eJammingAUDiiO -- (eJammingInc)
"C:\Program Files\Logitech\Vid HD\Vid.exe" = C:\Program Files\Logitech\Vid HD\Vid.exe:*:Enabled:Logitech Vid HD -- (Logitech Inc.)
"C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Master\Data aplikací\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.)
"C:\Program Files\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exe" = C:\Program Files\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exe:*:Enabled:Adobe After Effects CS4 -- (Adobe Systems Incorporated)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{009AC76E-1A66-4682-82B7-417E77F3C648}" = Superior Drummer Installer
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Gamer OSD
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{379BD39E-F13E-458F-96D8-56BD7F2CC516}" = M-Audio Series II MIDI
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMB36X Raid Configurer
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{411F3ABA-2AB5-4799-AA19-6ADF0A8F7424}" = Adobe Setup
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{490BF87E-1F75-4453-BF55-9F540543A3CA}" = Steinberg Drum Loop Expansion 01
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4A19D6AC-ADE0-4A07-80FF-9C9812C45557}" = Steinberg Cubase 5
"{4D454CF8-12FD-464D-B57B-B46FE27B78BB}" = Steinberg LoopMash Content
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{532B917B-8235-4FA5-BE36-643A8BB053A5}" = Steinberg REVerence Content 01
"{53FA9A9F-3C19-4D43-AD6B-DEF365D469BA}" = Camtasia Studio 7
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5DD152A8-BFB3-439E-90CD-5C00C2116E23}" = AmpliTube 3
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68544F92-4A85-48F2-9997-40E02EFB2305}" = eJammingAUDiiO
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78F2282B-9AC8-49AA-B34F-6FD68E8E4362}_is1" = StreamDown 6.8.0.0
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{865D9ED1-EAC2-436D-AFA7-0B750EB5AAAB}" = Steinberg HALionOne Studio Drum Set
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8EB8E60B-315D-44EB-A896-10D88602EE46}" = Adobe Setup
"{90120000-0010-0405-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Czech) 12
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AC997F93-0757-4ED4-A701-F40C2D654D09}" = Steinberg HALionOne GM Drum Set
"{AE4E8D53-2D05-4EB4-A1E7-FF48B8E76DDE}_is1" = AVI to 3GP 1.3
"{AFAF626C-D2E6-455C-9A5A-ACDF049A6168}" = ASUS nVidia Driver
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7E2A724-2774-4AC2-9F0A-B58C7319B6E6}" = Sony Vegas Pro 8.0
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD86F1AC-B594-46E4-85DC-1258AC9E2232}" = Steinberg Groove Agent ONE Content
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CF097717-F174-4144-954A-FBC4BF301029}" = Nero 7 Ultra Edition
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1345EF1-9655-47C0-BB35-6DC2BD0A2826}" = Trapcode Particular 32 bit
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D23CBFDA-C46B-4920-BA70-FC7878A3F05A}" = Steinberg HALionOne Studio Set
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D6F43337-4502-4FF2-8865-E6F7D6F776AF}" = M-Audio Oxygen DirectLink for Cubase 5 1.0.0 (x86)
"{D82CDA0D-C182-42C8-8FF2-5649C98D6003}" = Steinberg HALionOne Pro Set
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E22AD5D3-EB60-4A8F-835C-6C10E369DCE2}" = Steinberg HALionOne Expression Set
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E70E7159-93B1-470D-9FBD-D8E9EF34B538}" = Steinberg HALionOne
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{F057965A-D974-4C64-ADB1-4381CD4B8956}" = Steinberg HALionOne GM Set
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F3AFD063-8BAD-485E-B641-E7F5A2C5AE71}" = Steinberg HALionOne Additional Content Set 01
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"Adobe_3dcb365ab9e01871fb8c6f27b0ea079" = Adobe After Effects CS4
"Adobe_5aab5a491a3a52ae624fd639f6aaa95" = Adobe After Effects CS4 Third Party Content
"Airytec Switch Off" = Airytec Switch Off
"avast" = avast! Free Antivirus
"BSPlayerf" = BS.Player FREE
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Deamon Tools Lite4" = Deamon Tools Lite
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Guitar Pro 5_is1" = Guitar Pro 5.2
"InstallShield_{D1345EF1-9655-47C0-BB35-6DC2BD0A2826}" = Trapcode Particular 32 bit
"Lennar Digital Sylenth VSTi v1.2.1" = Lennar Digital Sylenth VSTi v1.2.1
"Logitech Vid" = Logitech Vid HD
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"NVIDIA Drivers" = NVIDIA Drivers
"PowerISO" = PowerISO
"Red Giant Psunami" = Red Giant Psunami
"Steinberg The Grand VSTi DXi_is1" = Steinberg The Grand VSTi DXi v2.1.0
"Synthesia" = Synthesia (remove only)
"TabIt for Windows_is1" = TabIt version 2.03 (Trial)
"TreeSize Free_is1" = TreeSize Free V2.3.3
"Trillian" = Trillian
"TUBEOHM Pure-Pone V1.6_is1" = TubeOhm Pure-PoneV1_6
"USB_AUDIO_DEusb-audio.deBehringer2902" = BEHRINGER USB AUDIO DRIVER
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.1
"Vypínač na dobrou noc_is1" = Vypínač na dobrou noc verze 2.0
"Wave Arts Power Suite" = Wave Arts Power Suite
"Waves API Collection" = Waves API Collection
"Waves Diamond Bundle v5.2" = Waves Diamond Bundle v5.2
"Waves GTR 3" = Waves GTR 3
"Waves IRx v5.2" = Waves IRx v5.2
"Waves L3 v5.2" = Waves L3 v5.2
"Waves Mercury Bundle" = Waves Mercury Bundle
"Waves SSL Collection v1.2" = Waves SSL Collection v1.2
"Waves Vocal Bundle v1.1" = Waves Vocal Bundle v1.1
"Waves Znoise v1.0" = Waves Znoise v1.0
"Webcam and Screen Recorder4" = Webcam and Screen Recorder
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"xvid" = XviD MPEG-4 Video Codec

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-507921405-413027322-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 26.7.2012 9:43:56 | Computer Name = MIKO | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 26.7.2012 13:39:02 | Computer Name = MIKO | Source = Application Error | ID = 1000
Description = Chybující aplikace UMVPFSrv.exe, verze 13.31.1044.0, chybující modul
UMVPFSrv.exe, verze 13.31.1044.0, adresa chyby 0x00005753.

Error - 4.8.2012 2:45:06 | Computer Name = MIKO | Source = Application Error | ID = 1000
Description = Chybující aplikace egui.exe, verze 4.0.468.0, chybující modul eguiupdate.dll,
verze 4.0.468.0, adresa chyby 0x00008692.

Error - 11.8.2012 5:52:06 | Computer Name = MIKO | Source = Application Error | ID = 1000
Description = Chybující aplikace egui.exe, verze 4.0.468.0, chybující modul eguiupdate.dll,
verze 4.0.468.0, adresa chyby 0x00008692.

Error - 14.8.2012 11:43:10 | Computer Name = MIKO | Source = Application Error | ID = 1000
Description = Chybující aplikace applemobilebackup.exe, verze 17.1008.10.20, chybující
modul corefoundation.dll, verze 1.630.16.0, adresa chyby 0x0006a26a.

Error - 17.8.2012 15:28:33 | Computer Name = MIKO | Source = crypt32 | ID = 131080
Description = Načtení automatické aktualizace pořadového čísla kořenového seznamu
jiného výrobce z: <http://www.download.windowsupdate.com/m ... ootseq.txt>
se nezdařilo. Chyba: Daná operace se vrátila, protože vypršel časový limit.

Error - 17.8.2012 15:28:38 | Computer Name = MIKO | Source = MsiInstaller | ID = 10005
Description = Product: ESET NOD32 Antivirus -- Error 5001. The computer has not
been restarted after a program uninstallation. Please restart the computer and run
the installer again.

Error - 17.8.2012 15:36:43 | Computer Name = MIKO | Source = crypt32 | ID = 131080
Description = Načtení automatické aktualizace pořadového čísla kořenového seznamu
jiného výrobce z: <http://www.download.windowsupdate.com/m ... ootseq.txt>
se nezdařilo. Chyba: Daná operace se vrátila, protože vypršel časový limit.

Error - 17.8.2012 15:36:45 | Computer Name = MIKO | Source = crypt32 | ID = 131080
Description = Načtení automatické aktualizace pořadového čísla kořenového seznamu
jiného výrobce z: <http://www.download.windowsupdate.com/m ... ootseq.txt>
se nezdařilo. Chyba: Zvolený server nemůže provést požadovanou operaci.

Error - 17.8.2012 15:37:03 | Computer Name = MIKO | Source = crypt32 | ID = 131083
Description = Extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou
aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>
se nezdařilo. Chyba: Neplatné údaje.

[ System Events ]
Error - 24.8.2012 1:39:15 | Computer Name = MIKO | Source = Service Control Manager | ID = 7000
Description = Služba M-Audio Series II MIDI Installer neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 25.8.2012 3:28:49 | Computer Name = MIKO | Source = Service Control Manager | ID = 7000
Description = Služba M-Audio Series II MIDI Installer neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 25.8.2012 21:28:28 | Computer Name = MIKO | Source = Service Control Manager | ID = 7000
Description = Služba M-Audio Series II MIDI Installer neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 26.8.2012 4:25:40 | Computer Name = MIKO | Source = Service Control Manager | ID = 7000
Description = Služba M-Audio Series II MIDI Installer neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 27.8.2012 3:02:00 | Computer Name = MIKO | Source = Service Control Manager | ID = 7000
Description = Služba M-Audio Series II MIDI Installer neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 28.8.2012 5:05:47 | Computer Name = MIKO | Source = Service Control Manager | ID = 7000
Description = Služba M-Audio Series II MIDI Installer neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 28.8.2012 5:14:37 | Computer Name = MIKO | Source = Service Control Manager | ID = 7000
Description = Služba M-Audio Series II MIDI Installer neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 29.8.2012 5:46:20 | Computer Name = MIKO | Source = Service Control Manager | ID = 7000
Description = Služba M-Audio Series II MIDI Installer neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 29.8.2012 12:51:53 | Computer Name = MIKO | Source = Service Control Manager | ID = 7000
Description = Služba M-Audio Series II MIDI Installer neuspěla při spuštění v důsledku
následující chyby: %%2

Error - 30.8.2012 4:14:43 | Computer Name = MIKO | Source = Service Control Manager | ID = 7000
Description = Služba M-Audio Series II MIDI Installer neuspěla při spuštění v důsledku
následující chyby: %%2


< End of report >

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pomalé PC, pravděpodobně malware

#10 Příspěvek od vyosek »

Takze to tu mame nekolikanasobne poruseni pravidel fora
  • nelegalni operacni system
  • nelegalni antivir - ten jste se pak tedy racil nahradit
  • nelegalni produkty adobe
I presto nelegalni OS je duvodem pro odmitnuti pomoci na zaklade platnych pravidel fora

:closed:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pomalé PC, pravděpodobně malware

#11 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno