Log zo SecurityCheck:
Results of screen317's Security Check version 0.99.1
Windows XP Service Pack 2
Out of date service pack!!
``````````````````````````````
Antivirus/Firewall Check:
Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Disabled!
ESET NOD32 Antivirus
Antivirus up to date!
``````````````````````````````
Anti-malware/Other Utilities Check:
Ad-Aware
SpywareBlaster 4.2
Spybot - Search & Destroy
SUPERAntiSpyware Free Edition
Rootkit Unhooker LE 3.8 SR 1
HijackThis 2.0.2
CCleaner
Java(TM) SE Runtime Environment 6 Update 1
Adobe Flash Player 10
Adobe Reader 8 - Czech
Out of date Adobe Reader installed!
``````````````````````````````
Process Check:
objlist.exe by Laurent
Ad-Aware AAWService.exe
Ad-Aware AAWTray.exe is disabled!
``````````````````````````````
DNS Vulnerability Check:
GREAT! (Not vulnerable to DNS cache poisoning)
`````````End of Log```````````
Tu je OTL.txt
OTL logfile created on: 4.3.2010 14:43:06 - Run 1
OTL by OldTimer - Version 3.1.33.0 Folder = C:\Documents and Settings\Ocko\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d.M.yyyy
511,00 Mb Total Physical Memory | 164,00 Mb Available Physical Memory | 32,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48,83 Gb Total Space | 10,47 Gb Free Space | 21,43% Space Free | Partition Type: NTFS
Drive D: | 78,13 Gb Total Space | 2,64 Gb Free Space | 3,38% Space Free | Partition Type: NTFS
Drive E: | 62,96 Gb Total Space | 13,55 Gb Free Space | 21,52% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JKIRKA
Current User Name: Ocko
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.03.04 14:05:15 | 000,552,960 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ocko\Desktop\OTL.exe
PRC - [2009.06.01 21:20:12 | 000,222,968 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2009.05.14 14:47:54 | 000,731,840 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2009.05.14 14:47:08 | 002,029,640 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2009.03.31 09:39:36 | 000,233,472 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2008.07.07 08:15:18 | 000,611,664 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2004.12.01 08:54:22 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2004.08.04 13:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004.06.16 06:55:20 | 000,233,472 | R--- | M] (Conexant Systems, Inc.) -- C:\Program Files\Microcom\ADSL DeskPorte USB\CnxDslTb.exe
========== Modules (SafeList) ==========
MOD - [2010.03.04 14:05:15 | 000,552,960 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ocko\Desktop\OTL.exe
MOD - [2004.08.04 13:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2009.06.02 10:10:08 | 000,637,952 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (servicelayer)
SRV - [2009.06.01 21:20:12 | 000,222,968 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (icq service)
SRV - [2009.05.14 14:54:22 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (ehttpsrv)
SRV - [2009.05.14 14:47:54 | 000,731,840 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2009.03.31 09:39:36 | 000,233,472 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2008.07.07 08:15:18 | 000,611,664 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice)
SRV - [2004.03.18 16:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - [2010.01.24 08:40:18 | 000,051,072 | ---- | M] (Identcode Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\Drivers\ANGELNT.SYS -- (Angelnt)
DRV - [2009.05.14 14:49:32 | 000,094,360 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2009.05.14 14:47:14 | 000,107,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009.05.14 14:41:10 | 000,114,472 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2009.03.31 09:39:36 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009.02.09 08:37:46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.04.02 19:07:31 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2008.04.01 23:37:14 | 000,223,128 | ---- | M] (DT Soft Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\dtscsi.sys -- (dtscsi)
DRV - [2008.02.29 15:03:48 | 000,008,944 | ---- | M] () [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2008.02.29 15:03:46 | 000,051,440 | ---- | M] () [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2008.02.26 06:51:43 | 002,863,616 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2007.04.04 12:43:38 | 000,098,952 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s716unic.sys -- (s716unic) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM)
DRV - [2007.04.04 12:43:36 | 000,098,568 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s716obex.sys -- (s716obex)
DRV - [2007.04.04 12:43:36 | 000,023,176 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s716nd5.sys -- (s716nd5) Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS)
DRV - [2007.04.04 12:43:34 | 000,108,552 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s716mdm.sys -- (s716mdm)
DRV - [2007.04.04 12:43:34 | 000,100,360 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s716mgmt.sys -- (s716mgmt) Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM)
DRV - [2007.04.04 12:43:32 | 000,015,112 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s716mdfl.sys -- (s716mdfl)
DRV - [2007.04.04 12:43:20 | 000,083,208 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s716bus.sys -- (s716bus) Sony Ericsson Device 716 driver (WDM)
DRV - [2007.04.03 13:57:48 | 000,108,680 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s116mdm.sys -- (s116mdm)
DRV - [2007.04.03 13:57:48 | 000,015,112 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s116mdfl.sys -- (s116mdfl)
DRV - [2007.04.03 13:57:42 | 000,083,336 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s116bus.sys -- (s116bus) Sony Ericsson Device 116 driver (WDM)
DRV - [2006.03.13 18:35:28 | 000,079,488 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750obex.sys -- (k750obex)
DRV - [2006.03.13 18:35:26 | 000,081,728 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750mgmt.sys -- (k750mgmt)
DRV - [2006.03.13 18:35:20 | 000,089,872 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750mdm.sys -- (k750mdm)
DRV - [2006.03.13 18:35:18 | 000,006,576 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750mdfl.sys -- (k750mdfl)
DRV - [2006.03.13 18:35:12 | 000,055,216 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\k750bus.sys -- (k750bus) Sony Ericsson 750 driver (WDM)
DRV - [2006.02.16 15:51:08 | 000,004,096 | R--- | M] (SuperAdBlocker, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\sasenum.sys -- (SASENUM)
DRV - [2004.12.07 09:15:54 | 000,087,936 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvatabus.sys -- (nvatabus)
DRV - [2004.12.01 13:40:08 | 002,300,928 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004.11.24 10:42:48 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2004.11.24 10:42:46 | 000,033,408 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvenetfd.sys -- (NVENETFD)
DRV - [2004.11.16 10:54:06 | 000,038,336 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\MSI\Core Center\rushtop.sys -- (RushTopDevice)
DRV - [2004.10.21 04:39:44 | 000,035,840 | R--- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2004.08.03 23:00:14 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\Changer.sys -- (Changer)
DRV - [2004.08.03 22:59:34 | 000,034,688 | ---- | M] (Toshiba Corp.) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\lbrtfdc.sys -- (lbrtfdc)
DRV - [2004.06.16 06:51:56 | 000,614,272 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CnxEtU.sys -- (CnxEtU)
DRV - [2004.06.16 06:51:56 | 000,060,416 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CnxTgNP.sys -- (CnxTgNP)
DRV - [2004.06.16 06:51:50 | 000,131,072 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CnxEtP.sys -- (CnxEtP)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.zoznam.sk/
IE - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\S-1-5-21-1935655697-1563985344-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http:/
www.zoznam.sk"
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5
FF - prefs.js..keyword.URL: "
http://search.icq.com/search/afe_result ... id=afex&q="
FF - HKLM\software\mozilla\Firefox\Extensions\\
bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009.11.04 20:14:10 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.02.27 11:27:10 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.02.19 06:54:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\
eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009.07.15 06:46:10 | 000,000,000 | ---D | M]
[2008.07.28 14:14:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Extensions
[2009.10.29 17:21:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\extensions
[2009.02.04 21:14:39 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\bsplayer-search.xml
[2010.02.28 20:22:10 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-1.xml
[2009.02.04 21:39:13 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-10.xml
[2009.03.07 17:20:34 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-11.xml
[2009.03.28 22:07:18 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-12.xml
[2009.04.23 13:08:17 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-13.xml
[2009.04.29 07:10:00 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-14.xml
[2009.06.13 19:05:03 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-15.xml
[2009.07.06 07:04:19 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-16.xml
[2009.07.23 08:12:15 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-17.xml
[2009.08.09 20:06:50 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-18.xml
[2009.08.10 08:58:00 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-19.xml
[2008.07.28 14:14:31 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-2.xml
[2009.10.29 13:44:01 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-20.xml
[2009.11.07 11:19:18 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-21.xml
[2009.12.01 20:13:16 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-22.xml
[2010.01.08 20:04:35 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-23.xml
[2010.02.19 06:55:16 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-24.xml
[2008.07.29 15:05:53 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-3.xml
[2008.09.26 21:03:49 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-4.xml
[2008.09.28 06:51:19 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-5.xml
[2008.11.15 13:55:29 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-6.xml
[2008.11.22 15:12:09 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-7.xml
[2008.11.22 21:40:17 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-8.xml
[2008.12.18 06:51:33 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin-9.xml
[2008.03.31 08:52:00 | 000,000,168 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin.gif
[2008.03.31 08:52:00 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin.src
[2009.07.13 16:12:02 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\Mozilla\Firefox\Profiles\jfna20ew.default\searchplugins\icqplugin.xml
[2010.03.02 17:19:35 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.07.19 19:05:28 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2008.12.22 12:43:42 | 000,279,888 | ---- | M] (Musicnotes, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npmusicn.dll
[2008.09.10 13:49:14 | 005,817,064 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\ScorchPDFWrapper.dll
[2009.07.23 08:11:51 | 000,001,583 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\atlas-sk.xml
[2009.07.23 08:11:51 | 000,001,380 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\azet-sk.xml
[2009.07.23 08:11:51 | 000,001,479 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\dunaj-sk.xml
[2009.07.23 08:11:51 | 000,001,473 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slovnik-sk.xml
[2009.07.23 08:11:51 | 000,001,104 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sk.xml
[2009.07.23 08:11:51 | 000,000,830 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\zoznam-sk.xml
O1 HOSTS File: ([2010.03.02 18:05:27 | 000,000,736 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (Podpora odkazu pro Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\..\Toolbar\WebBrowser: (no name) - {2C688203-7EB3-4327-9995-1CB417BA23F9} - No CLSID value found.
O4 - HKLM..\Run: [CnxDslTaskBar] File not found
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\Ocko\Start Menu\Programs\Startup\winesm32.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1935655697-1563985344-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKU\S-1-5-21-1935655697-1563985344-725345543-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: ICQ6 - {e59eb121-f339-4851-a3ba-fe49c35617c2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {e59eb121-f339-4851-a3ba-fe49c35617c2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4}
http://asp02.photoprintit.de/microsite/ ... oader4.cab (IPSUploader4 Control)
O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233}
https://asp.photoprintit.de/microsite/5 ... oader4.cab (IPSUploader4 Control)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/pub/sh ... wflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: D:\Dokumenty\JURKO\Dokumenty\Obrázky\Moje\autá\medved SLK.bmp
O24 - Desktop BackupWallPaper: D:\Dokumenty\JURKO\Dokumenty\Obrázky\Moje\autá\medved SLK.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.04.01 22:15:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008.04.01 22:14:59 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55453963436163072)
========== Files/Folders - Created Within 30 Days ==========
[2010.03.04 14:06:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ocko\Desktop\logy na anti
[2010.03.04 14:04:23 | 000,552,960 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ocko\Desktop\OTL.exe
[2010.03.03 16:30:06 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Ocko\Recent
[2010.03.02 17:55:26 | 000,060,416 | R--- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\CnxTgNP.sys
[2010.03.02 17:55:08 | 001,671,168 | R--- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\cnxci.dll
[2010.03.02 17:55:07 | 000,614,272 | R--- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\CnxEtU.sys
[2010.03.02 17:55:07 | 000,131,072 | R--- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\CnxEtP.sys
[2010.02.28 15:19:18 | 000,000,000 | ---D | C] -- C:\Program Files\Resource Kit
[2010.02.27 23:14:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ocko\Application Data\Comodo
[2010.02.27 23:09:11 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2010.02.27 22:24:19 | 000,000,000 | ---D | C] -- C:\Program Files\RootkitUnhooker
[2010.02.27 12:10:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Samsung_USB_Drivers
[2010.02.27 12:09:48 | 000,233,472 | ---- | C] (Teruten) -- C:\WINDOWS\System32\FsUsbExService.Exe
[2010.02.27 12:09:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ocko\My Documents\My NPS Files
[2010.02.27 12:09:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ocko\Application Data\Samsung
[2010.02.27 12:08:37 | 000,000,000 | ---D | C] -- C:\Program Files\MarkAny
[2010.02.27 12:07:07 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
[2010.02.26 16:49:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2010.02.26 16:16:09 | 001,028,608 | ---- | C] (J.C. Kessels) -- C:\WINDOWS\System32\MyDefragScreenSaver v4.2.8.exe
[2010.02.26 16:16:09 | 000,432,640 | ---- | C] (J.C. Kessels) -- C:\WINDOWS\System32\MyDefragScreenSaver v4.2.8.scr
[2010.02.26 16:16:07 | 000,000,000 | ---D | C] -- C:\Program Files\MyDefrag v4.2.8
[2010.02.26 14:00:30 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.02.26 13:57:56 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.02.26 13:54:12 | 000,000,000 | --SD | C] -- C:\ComboFix
[2010.02.26 13:34:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010.02.26 11:39:34 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.02.25 12:04:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ocko\Application Data\Malwarebytes
[2010.02.25 12:04:24 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.02.25 12:04:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010.02.25 12:04:20 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.02.25 12:04:18 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.02.25 11:04:20 | 000,000,000 | ---D | C] -- C:\_OTM
[2010.02.24 19:18:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ocko\Desktop\zaloha alfa 24.2.2010 19.20
[2010.02.21 22:47:29 | 000,034,688 | ---- | C] (Toshiba Corp.) -- C:\WINDOWS\System32\drivers\lbrtfdc.sys
[2010.02.21 22:47:29 | 000,034,688 | ---- | C] (Toshiba Corp.) -- C:\WINDOWS\System32\dllcache\lbrtfdc.sys
[2010.02.21 22:47:07 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\i2omgmt.sys
[2010.02.21 22:46:52 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\Changer.sys
[2010.02.21 22:46:52 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\changer.sys
[2010.02.20 12:08:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ocko\Desktop\KRIMINALITA - more zdravia
[2010.02.14 21:21:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ocko\Desktop\umk
[2010.02.10 19:39:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ocko\My Documents\Nový priečinok (4)
[2010.02.09 21:18:36 | 000,404,480 | ---- | C] (Lambda Core) -- C:\Documents and Settings\Ocko\Desktop\DocReader.exe
[2010.02.04 21:51:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ocko\Desktop\Foto lad
[2009.08.17 06:17:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2008.05.07 13:08:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008.04.01 22:19:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008.04.01 22:18:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008.04.01 22:15:18 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008.04.01 22:15:18 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
========== Files - Modified Within 30 Days ==========
[2010.03.04 14:53:21 | 000,792,064 | ---- | M] () -- C:\WINDOWS\System32\drivers\ahvoncix.sys
[2010.03.04 14:30:13 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.03.04 14:29:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.03.04 14:29:16 | 019,922,944 | ---- | M] () -- C:\Documents and Settings\Ocko\NTUSER.DAT
[2010.03.04 14:29:12 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Ocko\ntuser.ini
[2010.03.04 14:12:15 | 000,114,309 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\problem 4.JPG
[2010.03.04 14:05:15 | 000,552,960 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ocko\Desktop\OTL.exe
[2010.03.03 21:36:23 | 000,083,605 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\problem3.JPG
[2010.03.03 21:27:51 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010.03.03 21:18:42 | 000,016,515 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\problem.JPG
[2010.03.03 21:12:56 | 000,083,004 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\problem 2.JPG
[2010.03.03 16:58:02 | 000,000,704 | ---- | M] () -- C:\WINDOWS\eporadca_0905.ini
[2010.03.03 07:57:05 | 000,000,078 | ---- | M] () -- C:\WINDOWS\System32\asr_vxfmp
[2010.03.03 07:46:53 | 000,000,078 | ---- | M] () -- C:\WINDOWS\System32\asr_uorrg
[2010.03.03 07:43:25 | 000,000,004 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\avdrn.dat
[2010.03.02 19:17:43 | 000,000,782 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.03.02 19:17:43 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.03.02 19:17:43 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.03.02 18:05:27 | 000,000,736 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.03.02 17:55:33 | 000,001,448 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microcom ADSL DeskPorte USB.lnk
[2010.03.02 07:48:19 | 000,000,078 | ---- | M] () -- C:\WINDOWS\System32\asr_lspxs
[2010.03.02 07:47:43 | 000,000,078 | ---- | M] () -- C:\WINDOWS\System32\asr_ssver
[2010.03.01 23:34:11 | 000,034,816 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\antigona.doc
[2010.03.01 23:02:37 | 000,041,984 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\shakespeare.doc
[2010.03.01 23:00:32 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\docreader.ini
[2010.03.01 22:19:03 | 000,004,845 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\william_shakespeare__15993.rtf
[2010.03.01 21:56:41 | 000,039,424 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\Čitateľský denník.doc
[2010.03.01 16:13:47 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Ocko\Desktop\~$vý objekt - Dokument programu Microsoft Word (2).doc
[2010.02.28 23:13:35 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.02.28 20:47:44 | 000,000,798 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
[2010.02.28 20:06:49 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Ocko\My Documents\PDVD_MediaDisc.PlayList
[2010.02.28 16:56:52 | 000,079,360 | ---- | M] () -- C:\Documents and Settings\Ocko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.02.28 16:09:31 | 000,002,389 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\602XML Filler.lnk
[2010.02.27 23:45:40 | 000,000,130 | ---- | M] () -- C:\WINDOWS\cfplogvw.INI
[2010.02.27 23:34:58 | 013,949,469 | ---- | M] () -- C:\Documents and Settings\Ocko\My Documents\Hiromi Uehara - The Tom and Jerry Show_0
[2010.02.27 19:10:13 | 000,031,232 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\Nový objekt - Dokument programu Microsoft Word (2).doc
[2010.02.27 12:09:25 | 000,002,528 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\$_hpcst$.hpc
[2010.02.27 12:08:40 | 000,001,887 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Samsung New PC Studio.lnk
[2010.02.26 13:07:17 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.02.25 10:57:33 | 002,949,174 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\viry.bmp
[2010.02.25 09:58:54 | 000,026,112 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\HODNOTY.doc
[2010.02.25 04:30:31 | 000,379,546 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20100225-043207.backup
[2010.02.24 14:08:31 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.02.21 22:45:47 | 000,000,012 | ---- | M] () -- C:\Documents and Settings\Ocko\Application Data\cqfyto.dat
[2010.02.20 12:05:38 | 001,665,294 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\KRIMINALITA - more zdravia.rar
[2010.02.19 08:38:24 | 000,043,008 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\Kremnica-Krahule_-_text opravene.doc
[2010.02.15 16:32:44 | 000,280,385 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\pocasicko.rar
[2010.02.15 16:27:28 | 000,284,193 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\pocasicko.jpg
[2010.02.14 22:35:27 | 000,030,720 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\Pohronsko-_kremnický_okruh-text opravene.doc
[2010.02.14 21:54:48 | 000,136,704 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\Nový objekt - Dokument programu Microsoft Word.doc
[2010.02.14 21:24:03 | 000,055,972 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\Afrodita4_550.jpg
[2010.02.14 21:18:05 | 000,007,351 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\clanok_foto.jpg
[2010.02.14 21:17:38 | 000,019,862 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\4102-amon.jpg
[2010.02.14 19:47:48 | 002,162,102 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\Pohronsko-kremnicky.bmp
[2010.02.14 19:43:48 | 002,144,174 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\kremnica- krahule.bmp
[2010.02.14 16:00:54 | 000,210,162 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\image12421.jpg
[2010.02.14 14:12:34 | 000,029,696 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\pohronsko kremnicky okruh.doc
[2010.02.13 12:23:44 | 001,028,608 | ---- | M] (J.C. Kessels) -- C:\WINDOWS\System32\MyDefragScreenSaver v4.2.8.exe
[2010.02.09 21:49:55 | 000,048,128 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\Test - Xl0000000(1) (5).xls
[2010.02.09 21:18:49 | 000,110,474 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\William Shakespeare - Hamlet.doc.pdb
[2010.02.09 21:18:47 | 000,404,480 | ---- | M] (Lambda Core) -- C:\Documents and Settings\Ocko\Desktop\DocReader.exe
[2010.02.09 21:05:10 | 000,034,501 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\William_Shakespeare_-_Hamlet.rar
[2010.02.09 17:36:05 | 000,057,856 | ---- | M] () -- C:\Documents and Settings\Ocko\Desktop\Sj- čitatelsky WILLIAM SHAKESPEARE.doc
[2010.02.05 12:00:46 | 000,432,640 | ---- | M] (J.C. Kessels) -- C:\WINDOWS\System32\MyDefragScreenSaver v4.2.8.scr
========== Files Created - No Company Name ==========
[2010.03.04 14:12:15 | 000,114,309 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\problem 4.JPG
[2010.03.03 21:03:20 | 000,083,004 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\problem 2.JPG
[2010.03.03 20:59:00 | 000,083,605 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\problem3.JPG
[2010.03.03 20:47:23 | 000,016,515 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\problem.JPG
[2010.03.03 07:57:05 | 000,000,078 | ---- | C] () -- C:\WINDOWS\System32\asr_vxfmp
[2010.03.03 07:46:53 | 000,000,078 | ---- | C] () -- C:\WINDOWS\System32\asr_uorrg
[2010.03.03 07:44:35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\ahvoncix.sys
[2010.03.03 07:43:33 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\NetworkService\Application Data\rbuwzv.dat
[2010.03.03 07:43:25 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Ocko\Application Data\avdrn.dat
[2010.03.02 17:55:33 | 000,001,448 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microcom ADSL DeskPorte USB.lnk
[2010.03.02 07:48:19 | 000,000,078 | ---- | C] () -- C:\WINDOWS\System32\asr_lspxs
[2010.03.02 07:47:43 | 000,000,078 | ---- | C] () -- C:\WINDOWS\System32\asr_ssver
[2010.03.01 23:02:54 | 000,034,816 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\antigona.doc
[2010.03.01 22:19:01 | 000,004,845 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\william_shakespeare__15993.rtf
[2010.03.01 22:13:51 | 000,041,984 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\shakespeare.doc
[2010.03.01 16:51:24 | 000,039,424 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Čitateľský denník.doc
[2010.03.01 16:13:47 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Ocko\Desktop\~$vý objekt - Dokument programu Microsoft Word (2).doc
[2010.02.27 23:40:49 | 000,000,130 | ---- | C] () -- C:\WINDOWS\cfplogvw.INI
[2010.02.27 23:34:49 | 013,949,469 | ---- | C] () -- C:\Documents and Settings\Ocko\My Documents\Hiromi Uehara - The Tom and Jerry Show_0
[2010.02.27 18:24:21 | 000,031,232 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Nový objekt - Dokument programu Microsoft Word (2).doc
[2010.02.27 12:09:49 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010.02.27 12:09:48 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010.02.27 12:09:25 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Ocko\Application Data\$_hpcst$.hpc
[2010.02.27 12:08:40 | 000,001,887 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Samsung New PC Studio.lnk
[2010.02.26 11:39:39 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.02.26 11:39:37 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010.02.25 10:57:33 | 002,949,174 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\viry.bmp
[2010.02.21 22:45:46 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\Ocko\Application Data\cqfyto.dat
[2010.02.20 12:05:35 | 001,665,294 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\KRIMINALITA - more zdravia.rar
[2010.02.20 11:36:10 | 000,026,112 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\HODNOTY.doc
[2010.02.18 21:19:13 | 000,002,404 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Nero StartSmart.lnk
[2010.02.15 18:19:40 | 000,284,193 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\pocasicko.jpg
[2010.02.15 16:32:43 | 000,280,385 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\pocasicko.rar
[2010.02.14 22:23:37 | 000,030,720 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Pohronsko-_kremnický_okruh-text opravene.doc
[2010.02.14 22:22:58 | 000,043,008 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Kremnica-Krahule_-_text opravene.doc
[2010.02.14 21:24:03 | 000,055,972 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Afrodita4_550.jpg
[2010.02.14 21:18:05 | 000,007,351 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\clanok_foto.jpg
[2010.02.14 21:17:38 | 000,019,862 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\4102-amon.jpg
[2010.02.14 19:53:13 | 000,035,871 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Pohronsko - Kremnický okruh výškový profil.JPG
[2010.02.14 19:51:32 | 002,365,042 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Krahule- Kremnica Profil.bmp
[2010.02.14 19:45:30 | 002,162,102 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Pohronsko-kremnicky.bmp
[2010.02.14 19:43:02 | 002,144,174 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\kremnica- krahule.bmp
[2010.02.14 19:24:56 | 001,101,312 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Krahule - Kremnica.doc
[2010.02.14 16:00:53 | 000,210,162 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\image12421.jpg
[2010.02.14 15:50:30 | 000,136,704 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Nový objekt - Dokument programu Microsoft Word.doc
[2010.02.14 14:14:07 | 000,029,696 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\pohronsko kremnicky okruh.doc
[2010.02.09 21:49:55 | 000,048,128 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Test - Xl0000000(1) (5).xls
[2010.02.09 21:32:56 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\docreader.ini
[2010.02.09 21:18:48 | 000,110,474 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\William Shakespeare - Hamlet.doc.pdb
[2010.02.09 21:05:08 | 000,034,501 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\William_Shakespeare_-_Hamlet.rar
[2010.02.09 17:36:03 | 000,057,856 | ---- | C] () -- C:\Documents and Settings\Ocko\Desktop\Sj- čitatelsky WILLIAM SHAKESPEARE.doc
[2009.12.03 20:50:06 | 000,000,034 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009.09.20 12:53:30 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009.05.06 21:39:21 | 000,000,704 | ---- | C] () -- C:\WINDOWS\eporadca_0905.ini
[2008.06.30 07:26:45 | 000,001,747 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2008.05.30 18:29:05 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
[2008.05.30 18:29:05 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2008.05.30 18:29:05 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2008.05.30 18:29:05 | 000,000,205 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2008.04.06 21:17:54 | 000,079,360 | ---- | C] () -- C:\Documents and Settings\Ocko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.04.04 09:38:12 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.04.02 18:23:33 | 000,000,405 | ---- | C] () -- C:\WINDOWS\System32\ANGELDOS.SYS
[2008.04.02 18:14:18 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Ocko\Local Settings\Application Data\fusioncache.dat
[2008.04.02 16:37:43 | 000,008,196 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008.04.02 14:08:38 | 000,000,325 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2008.04.01 22:53:32 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008.04.01 22:34:33 | 000,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll
[2008.04.01 22:31:36 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2007.10.25 17:26:10 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2005.12.31 15:19:08 | 001,097,728 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.12.31 15:13:14 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2005.11.30 12:49:56 | 000,161,792 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2005.10.14 10:56:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 10:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 10:56:50 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 10:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 10:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2004.08.04 13:00:00 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004.08.04 13:00:00 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2003.04.07 10:38:32 | 000,005,746 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002.11.06 11:16:26 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\angel32.dll
[2001.01.12 10:49:38 | 000,021,504 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
========== LOP Check ==========
[2008.04.01 23:26:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2009.07.14 21:32:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2008.11.10 21:05:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GARMIN
[2009.07.19 19:05:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2009.11.27 08:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2008.11.22 21:44:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008.12.22 12:44:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Musicnotes
[2009.11.04 20:22:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2008.06.20 20:32:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2008.10.31 19:57:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Teleca
[2010.02.27 23:32:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009.07.04 07:54:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Juraj\Application Data\ESET
[2009.03.16 14:03:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Juraj\Application Data\Teleca
[2008.04.01 23:27:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\ACD Systems
[2008.04.02 19:02:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Acoustica
[2010.02.26 16:55:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Any Video Converter
[2010.02.26 16:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Any Video Converter Professional
[2009.08.26 18:59:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Blender Foundation
[2009.02.04 21:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\BSplayer
[2008.04.02 19:04:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\BSplayer Pro
[2009.12.13 19:47:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Design Science
[2009.06.01 14:49:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\ESET
[2008.11.30 12:15:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\GARMIN
[2008.07.02 15:32:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\ICQ
[2010.02.10 23:35:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\LimeWire
[2010.02.04 21:44:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Nokia
[2008.11.26 21:37:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Opera
[2009.11.04 20:22:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\PC Suite
[2010.02.27 12:09:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Samsung
[2008.10.31 20:13:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Teleca
[2009.08.24 17:28:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\Thinstall
[2010.02.27 23:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\uTorrent
[2008.12.14 20:35:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ocko\Application Data\zweitgeist
[2008.04.05 14:12:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Application Data\ACD Systems
[2009.07.03 13:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Application Data\ESET
[2008.11.06 23:29:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Veronika\Application Data\Teleca
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2009.01.02 14:42:56 | 057,182,054 | ---- | M] () -- C:\ALFAOstra(14.53).exe
[2009.03.10 18:48:24 | 060,158,330 | ---- | M] () -- C:\ALFAOstra(15,11) .exe
[2009.01.02 14:32:39 | 058,871,293 | ---- | M] () -- C:\ALFAOstra(15.00).exe
[2009.03.26 20:40:29 | 060,158,330 | ---- | M] () -- C:\ALFAStart.exe
[2008.06.02 09:27:14 | 010,538,520 | ---- | M] (Doctor Web, Ltd.) -- C:\launch.exe
[2008.11.10 21:01:24 | 059,659,552 | ---- | M] () -- C:\MapSource_6141.exe
[2009.11.04 20:09:59 | 033,911,376 | ---- | M] () -- C:\Nokia_PC_Suite_7_1_30_9_slk_web.exe
< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
[2004.08.04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2004.08.04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll
[2004.08.04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\dllcache\eventlog.dll
< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2004.08.04 13:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2004.08.04 13:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll
[2004.08.04 13:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\dllcache\scecli.dll
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2004.08.04 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2004.08.04 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll
[2004.08.04 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
< %SYSTEMDRIVE%\sceclt.dll /s /md5 >
< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >
< %SYSTEMDRIVE%\logevent.dll /s /md5 >
< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2004.08.04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2004.08.04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >
< %SYSTEMDRIVE%\viasraid.sys /s /md5 >
< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >
[2004.12.07 17:15:54 | 000,087,936 | ---- | M] (NVIDIA Corporation) MD5=E4F1F95A6BBBFBBFF9A713C6063AA2CB -- C:\WINDOWS\OemDir\nvatabus.sys
[2004.12.07 09:15:54 | 000,087,936 | ---- | M] (NVIDIA Corporation) MD5=E4F1F95A6BBBFBBFF9A713C6063AA2CB -- C:\WINDOWS\system32\drivers\nvatabus.sys
[2004.12.07 17:15:54 | 000,087,936 | ---- | M] (NVIDIA Corporation) MD5=E4F1F95A6BBBFBBFF9A713C6063AA2CB -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\nvatabus.sys
[2004.12.07 09:15:54 | 000,087,936 | R--- | M] (NVIDIA Corporation) MD5=E4F1F95A6BBBFBBFF9A713C6063AA2CB -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\nvatabus.sys
[2004.12.07 09:15:54 | 000,087,936 | R--- | M] (NVIDIA Corporation) MD5=E4F1F95A6BBBFBBFF9A713C6063AA2CB -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\nvatabus.sys
< %SYSTEMDRIVE%\viamraid.sys /s /md5 >
< %SYSTEMDRIVE%\nvata.sys /s /md5 >
< %SYSTEMROOT%\*. /mp /s >
< %SYSTEMROOT%\system32\*.dll /lockedfiles >
[2008.02.26 04:12:07 | 000,372,736 | ---- | M] (Advanced Micro Devices, Inc.)
Unable to obtain MD5 -- C:\WINDOWS\system32\ATIDEMGX.dll
< %SYSTEMROOT%\Tasks\*.job /lockedfiles >
========== Alternate Data Streams ==========
@Alternate Data Stream - 498 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8CE646EE
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:661DFA1C
< End of report >