Re: Zavirované PC Rootkit.Kryptik.BB, Injector.BNJ a Otlard
Napsal: 05 kvě 2010 18:44
[2010.04.21 19:56:02 | 000,000,811 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
[2010.04.21 19:53:29 | 000,165,437 | ---- | C] () -- C:\WINDOWS\hpwins05.dat
[2010.04.21 19:52:44 | 000,016,050 | ---- | C] () -- C:\WINDOWS\hpwscr05.dat
[2010.04.21 19:52:44 | 000,004,785 | ---- | C] () -- C:\WINDOWS\hpwmdl05.dat
[2010.04.21 19:44:50 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.04.21 19:36:33 | 000,001,690 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\AutoCAD 2010 - česky.lnk
[2010.04.21 15:24:02 | 000,013,588 | ---- | C] () -- C:\WINDOWS\System32\wpa.bak
[2010.04.21 15:02:32 | 000,000,684 | ---- | C] () -- C:\Documents and Settings\rhorsak\Plocha\QIP infium.lnk
[2010.04.21 15:02:16 | 000,002,521 | ---- | C] () -- C:\Documents and Settings\rhorsak\Plocha\Microsoft Office Outlook 2007.lnk
[2010.04.21 14:53:44 | 000,004,444 | ---- | C] () -- C:\WINDOWS\System32\pid.PNF
[2010.04.21 14:53:37 | 001,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2010.04.21 14:53:37 | 000,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2010.04.21 14:53:37 | 000,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2010.04.21 14:53:37 | 000,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2010.04.21 14:53:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28603.nls
[2010.04.21 14:53:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28603.nls
[2010.04.21 14:53:26 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_857.nls
[2010.04.21 14:53:26 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_857.nls
[2010.04.21 14:53:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28599.nls
[2010.04.21 14:53:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28599.nls
[2010.04.21 14:53:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10081.nls
[2010.04.21 14:53:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10081.nls
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28595.nls
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28595.NLS
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10017.nls
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10017.nls
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10007.nls
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10007.nls
[2010.04.21 14:53:21 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_869.nls
[2010.04.21 14:53:21 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_869.nls
[2010.04.21 14:53:21 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_737.nls
[2010.04.21 14:53:21 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_737.nls
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_875.nls
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_875.nls
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28597.nls
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28597.NLS
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10006.nls
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10006.nls
[2010.04.21 14:53:20 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_866.nls
[2010.04.21 14:53:20 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_866.nls
[2010.04.21 14:53:20 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_855.nls
[2010.04.21 14:53:20 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_855.nls
[2010.04.21 14:53:20 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28594.nls
[2010.04.21 14:53:20 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28594.NLS
[2010.04.21 14:53:15 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20127.nls
[2010.04.21 14:53:15 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_20127.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10082.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10082.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10029.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10029.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10010.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10010.nls
[2010.04.21 14:53:08 | 000,001,592 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2010.04.21 14:52:54 | 000,144,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2010.04.21 14:52:54 | 000,105,628 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2010.04.21 14:52:54 | 000,034,747 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2010.04.21 14:52:54 | 000,010,027 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2010.04.21 14:52:54 | 000,008,599 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2010.04.21 14:52:54 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2010.04.21 14:52:53 | 002,033,597 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2010.04.21 14:52:53 | 001,246,067 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP3.CAT
[2010.04.21 14:52:53 | 000,809,394 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2010.04.21 14:52:53 | 000,631,112 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2010.04.21 14:52:53 | 000,399,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2010.04.21 14:52:53 | 000,037,509 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2010.04.21 14:52:53 | 000,033,765 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2010.04.21 14:52:53 | 000,016,825 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2010.04.21 14:52:53 | 000,013,497 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2010.04.21 14:52:53 | 000,012,363 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2010.04.21 14:52:53 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2010.04.21 14:52:20 | 000,275,760 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.04.21 14:51:27 | 000,000,223 | RHS- | C] () -- C:\boot.ini
[2010.04.21 14:51:24 | 000,000,266 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2010.04.21 14:13:27 | 000,002,273 | ---- | C] () -- C:\Documents and Settings\rhorsak\Plocha\Google Chrome.lnk
[2010.04.21 14:05:51 | 000,001,034 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1651790719-4201147004-1817147730-1138UA.job
[2010.04.21 14:05:50 | 000,000,982 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1651790719-4201147004-1817147730-1138Core.job
[2010.04.21 13:46:48 | 000,000,642 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\TC UP.lnk
[2010.04.21 13:37:18 | 000,000,470 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{2B4E2C57-8533-46BC-BE6D-BD765062400A}.job
[2010.04.21 13:36:15 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\fusioncache.dat
[2010.04.21 13:36:00 | 000,002,464 | ---- | C] () -- C:\WINDOWS\$_hpcst$.hpc
[2010.04.21 13:35:44 | 000,057,422 | ---- | C] () -- C:\WINDOWS\System32\mobileV.acm
[2010.04.21 13:35:43 | 000,002,510 | ---- | C] () -- C:\WINDOWS\Microsoft.MIF
[2010.04.21 13:35:15 | 000,053,248 | -H-- | C] () -- C:\Documents and Settings\rhorsak\ntuser.dat.LOG
[2010.04.21 13:35:15 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\rhorsak\ntuser.ini
[2010.04.21 13:35:14 | 007,864,320 | -H-- | C] () -- C:\Documents and Settings\rhorsak\NTUSER.DAT
[2010.04.21 13:35:14 | 000,007,281 | ---- | C] () -- C:\Documents and Settings\rhorsak\ASPNETSetup.log
[2010.04.21 13:35:07 | 000,009,438 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2010.04.21 13:25:13 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2010.04.21 13:25:06 | 000,006,126 | R--- | C] () -- C:\WINDOWS\System32\atifglpf.xml
[2010.04.21 13:25:05 | 000,129,112 | R--- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2010.04.21 13:25:03 | 001,114,674 | R--- | C] () -- C:\WINDOWS\System32\drivers\ativcaxx.cpa
[2010.04.21 13:25:03 | 000,058,560 | R--- | C] () -- C:\WINDOWS\System32\drivers\ativckxx.vp
[2010.04.21 13:25:03 | 000,029,008 | R--- | C] () -- C:\WINDOWS\System32\drivers\ativvpxx.vp
[2010.04.21 13:25:03 | 000,000,929 | R--- | C] () -- C:\WINDOWS\System32\drivers\ativcaxx.vp
[2010.04.21 13:23:30 | 000,023,040 | R--- | C] () -- C:\WINDOWS\System32\drivers\GVCplDrv.sys
[2010.04.21 13:18:40 | 000,000,480 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{6CD4EB02-F798-4B09-9389-69E4B92B2FA7}.job
[2010.04.21 13:11:55 | 000,003,632 | ---- | C] () -- C:\WINDOWS\System32\nvnrm.nvu
[2010.04.21 13:10:57 | 000,012,675 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2010.04.21 13:10:56 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2010.04.21 13:10:40 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010.04.21 13:08:38 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2010.04.21 13:07:44 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010.04.21 13:07:35 | 000,028,288 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xjis.nls
[2010.04.21 13:07:13 | 000,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prcp.nls
[2010.04.21 13:07:13 | 000,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prc.nls
[2010.04.21 13:07:12 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2010.04.21 13:06:59 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2010.04.21 13:06:59 | 000,047,066 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ksc.nls
[2010.04.21 13:06:54 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2010.04.21 13:06:53 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2010.04.21 13:06:51 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2010.04.21 13:06:47 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2010.04.21 13:06:44 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2010.04.21 13:06:41 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2010.04.21 13:06:34 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2010.04.21 13:06:32 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_864.nls
[2010.04.21 13:06:32 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_862.nls
[2010.04.21 13:06:32 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_858.nls
[2010.04.21 13:06:32 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_720.nls
[2010.04.21 13:06:32 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_870.nls
[2010.04.21 13:06:31 | 000,180,770 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20932.nls
[2010.04.21 13:06:31 | 000,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20949.nls
[2010.04.21 13:06:31 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20936.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_708.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28596.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21027.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21025.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20924.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20880.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20871.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20838.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20833.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20424.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20423.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20420.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20297.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20290.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20285.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20284.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20280.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20278.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20277.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20273.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20269.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20108.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20107.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20106.nls
[2010.04.21 13:06:29 | 000,189,986 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1361.nls
[2010.04.21 13:06:29 | 000,187,938 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20005.nls
[2010.04.21 13:06:29 | 000,186,402 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20001.nls
[2010.04.21 13:06:29 | 000,185,378 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20003.nls
[2010.04.21 13:06:29 | 000,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20004.nls
[2010.04.21 13:06:29 | 000,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20000.nls
[2010.04.21 13:06:29 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20002.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20105.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1149.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1148.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1147.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1146.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1145.nls
[2010.04.21 13:06:28 | 000,195,618 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10002.nls
[2010.04.21 13:06:28 | 000,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10003.nls
[2010.04.21 13:06:28 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10008.nls
[2010.04.21 13:06:28 | 000,162,850 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10001.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1144.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1143.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1142.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1141.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1140.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1047.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10021.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10005.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10004.nls
[2010.04.21 13:06:27 | 000,082,172 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bopomofo.nls
[2010.04.21 13:06:27 | 000,066,728 | ---- | C] () -- C:\WINDOWS\System32\dllcache\big5.nls
[2010.04.21 13:05:34 | 000,896,104 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2010.04.21 13:04:00 | 000,002,504 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2010.04.21 13:04:00 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2010.04.21 13:04:00 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2010.04.21 13:04:00 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2010.04.21 13:04:00 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2010.04.21 13:03:53 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2010.04.21 13:03:53 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2010.04.21 13:03:51 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2010.04.21 13:03:02 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\WindowsLogon.manifest
[2010.04.21 13:03:02 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\WindowsShell.Manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\nwc.cpl.manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
[2010.04.21 13:02:37 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
[2010.04.21 13:02:19 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2010.04.21 13:02:19 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2010.04.21 13:02:12 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2010.04.21 13:01:31 | 000,378,880 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msinfo.dll
[2010.04.21 13:00:54 | 000,001,779 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk
[2010.04.21 13:00:23 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010.04.21 12:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2010.04.21 12:59:40 | 000,021,464 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2010.04.21 12:59:40 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2010.04.21 12:59:40 | 000,015,552 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2010.04.21 12:59:40 | 000,014,910 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2010.04.21 12:59:40 | 000,004,640 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.h
[2010.04.21 12:59:40 | 000,003,100 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.h
[2010.04.21 12:59:40 | 000,002,590 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.h
[2010.04.21 12:58:42 | 000,000,789 | ---- | C] () -- C:\WINDOWS\System32\winrmprov.mof
[2010.04.21 12:58:41 | 000,201,184 | ---- | C] () -- C:\WINDOWS\System32\winrm.vbs
[2010.04.21 12:58:41 | 000,002,426 | ---- | C] () -- C:\WINDOWS\System32\WsmTxt.xsl
[2010.04.21 12:58:41 | 000,001,559 | ---- | C] () -- C:\WINDOWS\System32\WsmPty.xsl
[2010.04.21 12:58:41 | 000,000,035 | ---- | C] () -- C:\WINDOWS\System32\winrm.cmd
[2010.04.21 12:58:00 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2010.04.21 12:57:59 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prérijní vítr.bmp
[2010.04.21 12:57:59 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Omítka Santa Fe.bmp
[2010.04.21 12:57:59 | 000,026,680 | ---- | C] () -- C:\WINDOWS\Řeka Sumida.bmp
[2010.04.21 12:57:59 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Zelený kámen.bmp
[2010.04.21 12:57:59 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rododendron.bmp
[2010.04.21 12:57:59 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Na rybách.bmp
[2010.04.21 12:57:59 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Zrnko kávy.bmp
[2010.04.21 12:57:59 | 000,016,730 | ---- | C] () -- C:\WINDOWS\Textura peří.bmp
[2010.04.21 12:57:58 | 000,093,702 | ---- | C] () -- C:\WINDOWS\System32\subrange.uce
[2010.04.21 12:57:58 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Mýdlové bubliny.bmp
[2010.04.21 12:57:58 | 000,060,458 | ---- | C] () -- C:\WINDOWS\System32\ideograf.uce
[2010.04.21 12:57:58 | 000,016,740 | ---- | C] () -- C:\WINDOWS\System32\shiftjis.uce
[2010.04.21 12:57:58 | 000,012,876 | ---- | C] () -- C:\WINDOWS\System32\korean.uce
[2010.04.21 12:57:58 | 000,008,484 | ---- | C] () -- C:\WINDOWS\System32\kanji_2.uce
[2010.04.21 12:57:58 | 000,006,948 | ---- | C] () -- C:\WINDOWS\System32\kanji_1.uce
[2010.04.21 12:57:58 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Modrá krajka 16.bmp
[2010.04.21 12:57:57 | 000,024,006 | ---- | C] () -- C:\WINDOWS\System32\gb2312.uce
[2010.04.21 12:57:57 | 000,022,984 | ---- | C] () -- C:\WINDOWS\System32\bopomofo.uce
[2010.04.21 12:57:54 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2010.04.21 12:57:53 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2010.04.21 12:57:52 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2010.04.21 12:57:46 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
========== LOP Check ==========
[2010.04.23 06:36:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ACD Systems
[2010.04.22 10:04:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Acronis
[2010.04.27 08:31:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ashampoo
[2010.04.26 08:15:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Autodesk
[2010.04.22 08:41:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Canon
[2010.04.29 16:19:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DIALux
[2010.04.21 13:35:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.04.23 15:36:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\FileOpen
[2010.04.21 13:09:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim Horsák\Data aplikací\Windows Desktop Search
[2010.04.23 06:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\ACD Systems
[2010.04.22 10:42:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Acronis
[2010.04.22 09:47:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\AIMP
[2010.04.27 10:52:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Artisteer
[2010.04.27 08:32:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Ashampoo
[2010.04.26 08:15:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Autodesk
[2010.04.23 15:36:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\FileOpen
[2010.04.23 07:16:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\HateML
[2010.04.21 13:45:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\HEXelon
[2010.04.22 13:54:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\TeamViewer
[2010.05.04 08:14:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Thinstall
[2010.04.21 19:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Windows Desktop Search
[2010.05.05 12:31:12 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010.05.05 15:13:07 | 000,000,316 | -HS- | M] () -- C:\WINDOWS\Tasks\LKHLKOTX.job
[2010.05.05 13:39:50 | 000,000,470 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{2B4E2C57-8533-46BC-BE6D-BD765062400A}.job
[2010.05.05 19:24:02 | 000,000,480 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{6CD4EB02-F798-4B09-9389-69E4B92B2FA7}.job
[2010.05.05 19:25:00 | 000,000,290 | -H-- | M] () -- C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 13:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation)
"Google Update" = "C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c -- [2010.04.21 14:05:46 | 000,136,176 | ---- | M] (Google Inc.)
"Seznam Postak" = "C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Seznam.cz\postak.exe" -s -- [2010.03.01 14:15:28 | 000,451,224 | ---- | M] ()
< c:\windows\*.* /U >
[1 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.04.23 06:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\ACD Systems
[2010.04.22 10:42:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Acronis
[2010.04.28 08:17:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Adobe
[2010.04.23 15:37:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\AdobeUM
[2010.04.22 09:47:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\AIMP
[2010.04.27 10:52:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Artisteer
[2010.04.27 08:32:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Ashampoo
[2010.04.21 13:36:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\ATI
[2010.04.26 08:15:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Autodesk
[2010.04.27 09:01:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\dvdcss
[2010.04.23 15:36:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\FileOpen
[2010.04.23 07:16:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\HateML
[2010.04.21 13:45:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\HEXelon
[2010.04.22 07:39:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\HP
[2010.04.21 13:35:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Identities
[2010.04.21 13:51:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\InstallShield
[2010.04.21 14:13:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Macromedia
[2010.04.22 10:51:59 | 000,000,000 | --SD | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Microsoft
[2010.05.05 10:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Skype
[2010.04.22 09:13:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Sun
[2010.04.22 13:54:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\TeamViewer
[2010.05.04 08:14:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Thinstall
[2010.05.03 14:07:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\vlc
[2010.04.21 19:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Windows Desktop Search
[2010.04.22 08:05:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
< MD5 for: AGP440.SYS >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 13:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 13:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2008.04.14 13:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
< MD5 for: CDROM.SYS >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.05.02 10:49:40 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\system32\dllcache\cdrom.sys
[2010.01.14 16:59:53 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2008.04.14 13:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 13:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 13:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.14 13:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2010.01.14 17:00:04 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=8AB626E4E4B289646E11311E66FB0B88 -- C:\WINDOWS\explorer.exe
[2010.01.14 17:00:04 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=8AB626E4E4B289646E11311E66FB0B88 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2010.01.14 17:00:11 | 000,134,528 | ---- | M] (Microsoft Corporation) MD5=E33DE9C65B3625BDD00C1313179DA5A5 -- C:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.13 23:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\system32\dllcache\changer.sys
[2008.04.13 23:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\system32\drivers\changer.sys
< MD5 for: ISAPNP.SYS >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 13:00:00 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2008.04.14 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2010.01.14 17:01:13 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=B5B1080D35974C0E718D64280761BCD5 -- C:\WINDOWS\system32\dllcache\ndis.sys
[2010.01.14 17:01:13 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=B5B1080D35974C0E718D64280761BCD5 -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2010.01.14 17:01:14 | 000,407,552 | ---- | M] (Microsoft Corporation) MD5=6A5A974D868AE2F9AC96DC14F221A5EF -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2010.01.14 17:01:14 | 000,407,552 | ---- | M] (Microsoft Corporation) MD5=6A5A974D868AE2F9AC96DC14F221A5EF -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NVATA.SYS >
[2010.04.22 07:21:45 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\WINDOWS\system32\drivers\nvata.sys
< MD5 for: SCECLI.DLL >
[2008.04.14 13:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 13:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2008.04.14 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2010.01.14 17:01:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=67E38B4A549833E02D4D1617B5DBC318 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2010.01.14 17:01:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=67E38B4A549833E02D4D1617B5DBC318 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2010.01.14 17:01:53 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=367DE8E5F638C091F49273144274F629 -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2010.01.14 17:01:53 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=367DE8E5F638C091F49273144274F629 -- C:\WINDOWS\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 13:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 13:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010.01.14 17:02:09 | 000,509,440 | ---- | M] (Microsoft Corporation) MD5=4212BABCC4408B052193DABAD9A691AB -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2010.01.14 17:02:09 | 000,509,440 | ---- | M] (Microsoft Corporation) MD5=4212BABCC4408B052193DABAD9A691AB -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.14 13:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2008.04.14 13:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2010.05.05 09:06:14 | 000,115,200 | RHS- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\axaltocms.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
[2010.05.05 15:13:07 | 000,000,316 | -HS- | M] () Unable to obtain MD5 -- C:\WINDOWS\Tasks\LKHLKOTX.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]
< %systemroot%\System32\config\*.sav >
[2010.04.21 14:51:26 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.04.21 14:51:26 | 001,093,632 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.04.21 14:51:26 | 000,491,520 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[2010.05.05 09:06:14 | 000,115,200 | RHS- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\axaltocms.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< %systemroot%\system32\drivers\*.sys /3 >
[2010.05.05 11:26:19 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\system32\drivers\SBREDrv.sys
[2 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]
< %systemroot%\system32\*.* /3 >
[2010.05.05 09:06:14 | 000,115,200 | RHS- | M] () -- C:\WINDOWS\system32\axaltocms.dll
[2010.05.05 14:50:09 | 000,182,784 | ---- | M] () -- C:\WINDOWS\system32\regedit.exe
[2010.05.05 15:13:46 | 000,013,646 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< End of report >
[2010.04.21 19:53:29 | 000,165,437 | ---- | C] () -- C:\WINDOWS\hpwins05.dat
[2010.04.21 19:52:44 | 000,016,050 | ---- | C] () -- C:\WINDOWS\hpwscr05.dat
[2010.04.21 19:52:44 | 000,004,785 | ---- | C] () -- C:\WINDOWS\hpwmdl05.dat
[2010.04.21 19:44:50 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.04.21 19:36:33 | 000,001,690 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\AutoCAD 2010 - česky.lnk
[2010.04.21 15:24:02 | 000,013,588 | ---- | C] () -- C:\WINDOWS\System32\wpa.bak
[2010.04.21 15:02:32 | 000,000,684 | ---- | C] () -- C:\Documents and Settings\rhorsak\Plocha\QIP infium.lnk
[2010.04.21 15:02:16 | 000,002,521 | ---- | C] () -- C:\Documents and Settings\rhorsak\Plocha\Microsoft Office Outlook 2007.lnk
[2010.04.21 14:53:44 | 000,004,444 | ---- | C] () -- C:\WINDOWS\System32\pid.PNF
[2010.04.21 14:53:37 | 001,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2010.04.21 14:53:37 | 000,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2010.04.21 14:53:37 | 000,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2010.04.21 14:53:37 | 000,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2010.04.21 14:53:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28603.nls
[2010.04.21 14:53:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28603.nls
[2010.04.21 14:53:26 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_857.nls
[2010.04.21 14:53:26 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_857.nls
[2010.04.21 14:53:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28599.nls
[2010.04.21 14:53:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28599.nls
[2010.04.21 14:53:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10081.nls
[2010.04.21 14:53:26 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10081.nls
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28595.nls
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28595.NLS
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10017.nls
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10017.nls
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10007.nls
[2010.04.21 14:53:23 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10007.nls
[2010.04.21 14:53:21 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_869.nls
[2010.04.21 14:53:21 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_869.nls
[2010.04.21 14:53:21 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_737.nls
[2010.04.21 14:53:21 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_737.nls
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_875.nls
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_875.nls
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28597.nls
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28597.NLS
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10006.nls
[2010.04.21 14:53:21 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10006.nls
[2010.04.21 14:53:20 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_866.nls
[2010.04.21 14:53:20 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_866.nls
[2010.04.21 14:53:20 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_855.nls
[2010.04.21 14:53:20 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_855.nls
[2010.04.21 14:53:20 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28594.nls
[2010.04.21 14:53:20 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28594.NLS
[2010.04.21 14:53:15 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20127.nls
[2010.04.21 14:53:15 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_20127.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10082.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10082.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10029.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10029.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10010.nls
[2010.04.21 14:53:13 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10010.nls
[2010.04.21 14:53:08 | 000,001,592 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2010.04.21 14:52:54 | 000,144,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2010.04.21 14:52:54 | 000,105,628 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2010.04.21 14:52:54 | 000,034,747 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2010.04.21 14:52:54 | 000,010,027 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2010.04.21 14:52:54 | 000,008,599 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2010.04.21 14:52:54 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2010.04.21 14:52:53 | 002,033,597 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2010.04.21 14:52:53 | 001,246,067 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP3.CAT
[2010.04.21 14:52:53 | 000,809,394 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2010.04.21 14:52:53 | 000,631,112 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2010.04.21 14:52:53 | 000,399,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2010.04.21 14:52:53 | 000,037,509 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2010.04.21 14:52:53 | 000,033,765 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2010.04.21 14:52:53 | 000,016,825 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2010.04.21 14:52:53 | 000,013,497 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2010.04.21 14:52:53 | 000,012,363 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2010.04.21 14:52:53 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2010.04.21 14:52:20 | 000,275,760 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.04.21 14:51:27 | 000,000,223 | RHS- | C] () -- C:\boot.ini
[2010.04.21 14:51:24 | 000,000,266 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2010.04.21 14:13:27 | 000,002,273 | ---- | C] () -- C:\Documents and Settings\rhorsak\Plocha\Google Chrome.lnk
[2010.04.21 14:05:51 | 000,001,034 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1651790719-4201147004-1817147730-1138UA.job
[2010.04.21 14:05:50 | 000,000,982 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1651790719-4201147004-1817147730-1138Core.job
[2010.04.21 13:46:48 | 000,000,642 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\TC UP.lnk
[2010.04.21 13:37:18 | 000,000,470 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{2B4E2C57-8533-46BC-BE6D-BD765062400A}.job
[2010.04.21 13:36:15 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\fusioncache.dat
[2010.04.21 13:36:00 | 000,002,464 | ---- | C] () -- C:\WINDOWS\$_hpcst$.hpc
[2010.04.21 13:35:44 | 000,057,422 | ---- | C] () -- C:\WINDOWS\System32\mobileV.acm
[2010.04.21 13:35:43 | 000,002,510 | ---- | C] () -- C:\WINDOWS\Microsoft.MIF
[2010.04.21 13:35:15 | 000,053,248 | -H-- | C] () -- C:\Documents and Settings\rhorsak\ntuser.dat.LOG
[2010.04.21 13:35:15 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\rhorsak\ntuser.ini
[2010.04.21 13:35:14 | 007,864,320 | -H-- | C] () -- C:\Documents and Settings\rhorsak\NTUSER.DAT
[2010.04.21 13:35:14 | 000,007,281 | ---- | C] () -- C:\Documents and Settings\rhorsak\ASPNETSetup.log
[2010.04.21 13:35:07 | 000,009,438 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2010.04.21 13:25:13 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2010.04.21 13:25:06 | 000,006,126 | R--- | C] () -- C:\WINDOWS\System32\atifglpf.xml
[2010.04.21 13:25:05 | 000,129,112 | R--- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2010.04.21 13:25:03 | 001,114,674 | R--- | C] () -- C:\WINDOWS\System32\drivers\ativcaxx.cpa
[2010.04.21 13:25:03 | 000,058,560 | R--- | C] () -- C:\WINDOWS\System32\drivers\ativckxx.vp
[2010.04.21 13:25:03 | 000,029,008 | R--- | C] () -- C:\WINDOWS\System32\drivers\ativvpxx.vp
[2010.04.21 13:25:03 | 000,000,929 | R--- | C] () -- C:\WINDOWS\System32\drivers\ativcaxx.vp
[2010.04.21 13:23:30 | 000,023,040 | R--- | C] () -- C:\WINDOWS\System32\drivers\GVCplDrv.sys
[2010.04.21 13:18:40 | 000,000,480 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{6CD4EB02-F798-4B09-9389-69E4B92B2FA7}.job
[2010.04.21 13:11:55 | 000,003,632 | ---- | C] () -- C:\WINDOWS\System32\nvnrm.nvu
[2010.04.21 13:10:57 | 000,012,675 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2010.04.21 13:10:56 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2010.04.21 13:10:40 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010.04.21 13:08:38 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2010.04.21 13:07:44 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010.04.21 13:07:35 | 000,028,288 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xjis.nls
[2010.04.21 13:07:13 | 000,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prcp.nls
[2010.04.21 13:07:13 | 000,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prc.nls
[2010.04.21 13:07:12 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2010.04.21 13:06:59 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2010.04.21 13:06:59 | 000,047,066 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ksc.nls
[2010.04.21 13:06:54 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2010.04.21 13:06:53 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2010.04.21 13:06:51 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2010.04.21 13:06:47 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2010.04.21 13:06:44 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2010.04.21 13:06:41 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2010.04.21 13:06:34 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2010.04.21 13:06:32 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_864.nls
[2010.04.21 13:06:32 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_862.nls
[2010.04.21 13:06:32 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_858.nls
[2010.04.21 13:06:32 | 000,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_720.nls
[2010.04.21 13:06:32 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_870.nls
[2010.04.21 13:06:31 | 000,180,770 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20932.nls
[2010.04.21 13:06:31 | 000,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20949.nls
[2010.04.21 13:06:31 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20936.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_708.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28596.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21027.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_21025.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20924.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20880.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20871.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20838.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20833.nls
[2010.04.21 13:06:31 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20424.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20423.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20420.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20297.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20290.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20285.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20284.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20280.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20278.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20277.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20273.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20269.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20108.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20107.nls
[2010.04.21 13:06:30 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20106.nls
[2010.04.21 13:06:29 | 000,189,986 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1361.nls
[2010.04.21 13:06:29 | 000,187,938 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20005.nls
[2010.04.21 13:06:29 | 000,186,402 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20001.nls
[2010.04.21 13:06:29 | 000,185,378 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20003.nls
[2010.04.21 13:06:29 | 000,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20004.nls
[2010.04.21 13:06:29 | 000,180,258 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20000.nls
[2010.04.21 13:06:29 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20002.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_20105.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1149.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1148.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1147.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1146.nls
[2010.04.21 13:06:29 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1145.nls
[2010.04.21 13:06:28 | 000,195,618 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10002.nls
[2010.04.21 13:06:28 | 000,177,698 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10003.nls
[2010.04.21 13:06:28 | 000,173,602 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10008.nls
[2010.04.21 13:06:28 | 000,162,850 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10001.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1144.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1143.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1142.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1141.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1140.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_1047.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10021.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10005.nls
[2010.04.21 13:06:28 | 000,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10004.nls
[2010.04.21 13:06:27 | 000,082,172 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bopomofo.nls
[2010.04.21 13:06:27 | 000,066,728 | ---- | C] () -- C:\WINDOWS\System32\dllcache\big5.nls
[2010.04.21 13:05:34 | 000,896,104 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2010.04.21 13:04:00 | 000,002,504 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2010.04.21 13:04:00 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2010.04.21 13:04:00 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2010.04.21 13:04:00 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2010.04.21 13:04:00 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2010.04.21 13:03:53 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2010.04.21 13:03:53 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2010.04.21 13:03:51 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2010.04.21 13:03:02 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\WindowsLogon.manifest
[2010.04.21 13:03:02 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\WindowsShell.Manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\nwc.cpl.manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2010.04.21 13:03:00 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
[2010.04.21 13:02:37 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
[2010.04.21 13:02:19 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2010.04.21 13:02:19 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2010.04.21 13:02:12 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2010.04.21 13:01:31 | 000,378,880 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msinfo.dll
[2010.04.21 13:00:54 | 000,001,779 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk
[2010.04.21 13:00:23 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010.04.21 12:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2010.04.21 12:59:40 | 000,021,464 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2010.04.21 12:59:40 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2010.04.21 12:59:40 | 000,015,552 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2010.04.21 12:59:40 | 000,014,910 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2010.04.21 12:59:40 | 000,004,640 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.h
[2010.04.21 12:59:40 | 000,003,100 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.h
[2010.04.21 12:59:40 | 000,002,590 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.h
[2010.04.21 12:58:42 | 000,000,789 | ---- | C] () -- C:\WINDOWS\System32\winrmprov.mof
[2010.04.21 12:58:41 | 000,201,184 | ---- | C] () -- C:\WINDOWS\System32\winrm.vbs
[2010.04.21 12:58:41 | 000,002,426 | ---- | C] () -- C:\WINDOWS\System32\WsmTxt.xsl
[2010.04.21 12:58:41 | 000,001,559 | ---- | C] () -- C:\WINDOWS\System32\WsmPty.xsl
[2010.04.21 12:58:41 | 000,000,035 | ---- | C] () -- C:\WINDOWS\System32\winrm.cmd
[2010.04.21 12:58:00 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2010.04.21 12:57:59 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prérijní vítr.bmp
[2010.04.21 12:57:59 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Omítka Santa Fe.bmp
[2010.04.21 12:57:59 | 000,026,680 | ---- | C] () -- C:\WINDOWS\Řeka Sumida.bmp
[2010.04.21 12:57:59 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Zelený kámen.bmp
[2010.04.21 12:57:59 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rododendron.bmp
[2010.04.21 12:57:59 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Na rybách.bmp
[2010.04.21 12:57:59 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Zrnko kávy.bmp
[2010.04.21 12:57:59 | 000,016,730 | ---- | C] () -- C:\WINDOWS\Textura peří.bmp
[2010.04.21 12:57:58 | 000,093,702 | ---- | C] () -- C:\WINDOWS\System32\subrange.uce
[2010.04.21 12:57:58 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Mýdlové bubliny.bmp
[2010.04.21 12:57:58 | 000,060,458 | ---- | C] () -- C:\WINDOWS\System32\ideograf.uce
[2010.04.21 12:57:58 | 000,016,740 | ---- | C] () -- C:\WINDOWS\System32\shiftjis.uce
[2010.04.21 12:57:58 | 000,012,876 | ---- | C] () -- C:\WINDOWS\System32\korean.uce
[2010.04.21 12:57:58 | 000,008,484 | ---- | C] () -- C:\WINDOWS\System32\kanji_2.uce
[2010.04.21 12:57:58 | 000,006,948 | ---- | C] () -- C:\WINDOWS\System32\kanji_1.uce
[2010.04.21 12:57:58 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Modrá krajka 16.bmp
[2010.04.21 12:57:57 | 000,024,006 | ---- | C] () -- C:\WINDOWS\System32\gb2312.uce
[2010.04.21 12:57:57 | 000,022,984 | ---- | C] () -- C:\WINDOWS\System32\bopomofo.uce
[2010.04.21 12:57:54 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2010.04.21 12:57:53 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2010.04.21 12:57:52 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2010.04.21 12:57:46 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
========== LOP Check ==========
[2010.04.23 06:36:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ACD Systems
[2010.04.22 10:04:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Acronis
[2010.04.27 08:31:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ashampoo
[2010.04.26 08:15:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Autodesk
[2010.04.22 08:41:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Canon
[2010.04.29 16:19:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DIALux
[2010.04.21 13:35:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.04.23 15:36:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\FileOpen
[2010.04.21 13:09:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim Horsák\Data aplikací\Windows Desktop Search
[2010.04.23 06:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\ACD Systems
[2010.04.22 10:42:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Acronis
[2010.04.22 09:47:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\AIMP
[2010.04.27 10:52:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Artisteer
[2010.04.27 08:32:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Ashampoo
[2010.04.26 08:15:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Autodesk
[2010.04.23 15:36:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\FileOpen
[2010.04.23 07:16:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\HateML
[2010.04.21 13:45:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\HEXelon
[2010.04.22 13:54:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\TeamViewer
[2010.05.04 08:14:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Thinstall
[2010.04.21 19:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Windows Desktop Search
[2010.05.05 12:31:12 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010.05.05 15:13:07 | 000,000,316 | -HS- | M] () -- C:\WINDOWS\Tasks\LKHLKOTX.job
[2010.05.05 13:39:50 | 000,000,470 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{2B4E2C57-8533-46BC-BE6D-BD765062400A}.job
[2010.05.05 19:24:02 | 000,000,480 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{6CD4EB02-F798-4B09-9389-69E4B92B2FA7}.job
[2010.05.05 19:25:00 | 000,000,290 | -H-- | M] () -- C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 13:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation)
"Google Update" = "C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c -- [2010.04.21 14:05:46 | 000,136,176 | ---- | M] (Google Inc.)
"Seznam Postak" = "C:\Documents and Settings\rhorsak\Local Settings\Data aplikací\Seznam.cz\postak.exe" -s -- [2010.03.01 14:15:28 | 000,451,224 | ---- | M] ()
< c:\windows\*.* /U >
[1 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.04.23 06:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\ACD Systems
[2010.04.22 10:42:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Acronis
[2010.04.28 08:17:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Adobe
[2010.04.23 15:37:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\AdobeUM
[2010.04.22 09:47:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\AIMP
[2010.04.27 10:52:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Artisteer
[2010.04.27 08:32:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Ashampoo
[2010.04.21 13:36:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\ATI
[2010.04.26 08:15:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Autodesk
[2010.04.27 09:01:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\dvdcss
[2010.04.23 15:36:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\FileOpen
[2010.04.23 07:16:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\HateML
[2010.04.21 13:45:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\HEXelon
[2010.04.22 07:39:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\HP
[2010.04.21 13:35:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Identities
[2010.04.21 13:51:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\InstallShield
[2010.04.21 14:13:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Macromedia
[2010.04.22 10:51:59 | 000,000,000 | --SD | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Microsoft
[2010.05.05 10:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Skype
[2010.04.22 09:13:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Sun
[2010.04.22 13:54:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\TeamViewer
[2010.05.04 08:14:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Thinstall
[2010.05.03 14:07:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\vlc
[2010.04.21 19:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\Windows Desktop Search
[2010.04.22 08:05:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rhorsak\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
< MD5 for: AGP440.SYS >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 13:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 13:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2008.04.14 13:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
< MD5 for: CDROM.SYS >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.05.02 10:49:40 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\system32\dllcache\cdrom.sys
[2010.01.14 16:59:53 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=4B0A100EAF5C49EF3CCA8C641431EACC -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2008.04.14 13:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 13:00:00 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 13:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.14 13:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2010.01.14 17:00:04 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=8AB626E4E4B289646E11311E66FB0B88 -- C:\WINDOWS\explorer.exe
[2010.01.14 17:00:04 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=8AB626E4E4B289646E11311E66FB0B88 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2010.01.14 17:00:11 | 000,134,528 | ---- | M] (Microsoft Corporation) MD5=E33DE9C65B3625BDD00C1313179DA5A5 -- C:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.13 23:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\system32\dllcache\changer.sys
[2008.04.13 23:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\system32\drivers\changer.sys
< MD5 for: ISAPNP.SYS >
[2010.01.14 17:14:14 | 017,817,320 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 13:00:00 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2008.04.14 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2010.01.14 17:01:13 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=B5B1080D35974C0E718D64280761BCD5 -- C:\WINDOWS\system32\dllcache\ndis.sys
[2010.01.14 17:01:13 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=B5B1080D35974C0E718D64280761BCD5 -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2010.01.14 17:01:14 | 000,407,552 | ---- | M] (Microsoft Corporation) MD5=6A5A974D868AE2F9AC96DC14F221A5EF -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2010.01.14 17:01:14 | 000,407,552 | ---- | M] (Microsoft Corporation) MD5=6A5A974D868AE2F9AC96DC14F221A5EF -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NVATA.SYS >
[2010.04.22 07:21:45 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\WINDOWS\system32\drivers\nvata.sys
< MD5 for: SCECLI.DLL >
[2008.04.14 13:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 13:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2008.04.14 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2010.01.14 17:01:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=67E38B4A549833E02D4D1617B5DBC318 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2010.01.14 17:01:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=67E38B4A549833E02D4D1617B5DBC318 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2010.01.14 17:01:53 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=367DE8E5F638C091F49273144274F629 -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2010.01.14 17:01:53 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=367DE8E5F638C091F49273144274F629 -- C:\WINDOWS\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 13:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 13:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010.01.14 17:02:09 | 000,509,440 | ---- | M] (Microsoft Corporation) MD5=4212BABCC4408B052193DABAD9A691AB -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2010.01.14 17:02:09 | 000,509,440 | ---- | M] (Microsoft Corporation) MD5=4212BABCC4408B052193DABAD9A691AB -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.14 13:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2008.04.14 13:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2010.05.05 09:06:14 | 000,115,200 | RHS- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\axaltocms.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
[2010.05.05 15:13:07 | 000,000,316 | -HS- | M] () Unable to obtain MD5 -- C:\WINDOWS\Tasks\LKHLKOTX.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]
< %systemroot%\System32\config\*.sav >
[2010.04.21 14:51:26 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.04.21 14:51:26 | 001,093,632 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.04.21 14:51:26 | 000,491,520 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[2010.05.05 09:06:14 | 000,115,200 | RHS- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\axaltocms.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< %systemroot%\system32\drivers\*.sys /3 >
[2010.05.05 11:26:19 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\system32\drivers\SBREDrv.sys
[2 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]
< %systemroot%\system32\*.* /3 >
[2010.05.05 09:06:14 | 000,115,200 | RHS- | M] () -- C:\WINDOWS\system32\axaltocms.dll
[2010.05.05 14:50:09 | 000,182,784 | ---- | M] () -- C:\WINDOWS\system32\regedit.exe
[2010.05.05 15:13:46 | 000,013,646 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< End of report >