Re: Prosim o kontrolu logu
Napsal: 13 zář 2010 16:22
2 cast logu:
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 08:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
< c:\windows\*.* /U >
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
[2009.03.31 17:47:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Agnitum
[2010.04.09 17:33:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.03.31 13:39:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Adobe
[2006.11.04 19:59:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\AdobeUM
[2007.12.04 17:50:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Ahead
[2006.11.09 17:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Apple Computer
[2007.11.20 16:36:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\AVG7
[2007.09.20 18:27:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\BearShare
[2010.04.29 18:08:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Canneverbe Limited
[2008.07.31 11:32:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\DAEMON Tools
[2009.01.31 13:37:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Deckadance
[2010.06.28 19:37:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\DivX
[2007.05.11 20:09:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\dvdcss
[2007.12.12 20:46:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ESET
[2006.12.26 18:21:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ESTSoft
[2009.10.26 18:46:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Faktury Plus
[2007.09.26 15:16:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\FreeCommander
[2007.11.01 20:16:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Google
[2008.04.05 13:50:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Hamachi
[2007.01.17 20:46:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Help
[2010.01.23 19:33:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\HLSW
[2010.09.05 13:49:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ICQ
[2008.04.10 19:20:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ICQ Toolbar
[2007.09.19 15:30:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ICQLite
[2006.11.04 15:35:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Identities
[2009.12.24 20:18:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\InstallShield
[2009.12.21 15:05:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Juce VST Host
[2006.11.28 17:58:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Leadertech
[2007.10.03 00:13:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\LimeWire
[2006.12.12 15:50:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Macromedia
[2009.02.08 20:25:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Malwarebytes
[2010.09.10 12:26:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Media Player Classic
[2010.09.09 10:32:51 | 000,000,000 | --SD | M] -- C:\Documents and Settings\student\Data aplikací\Microsoft
[2007.11.09 20:40:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Microsoft Games
[2007.09.24 15:36:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Mozilla
[2008.02.27 23:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\MRP
[2008.04.16 14:09:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\MxBoost
[2010.03.31 15:46:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Nero
[2006.11.11 21:54:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\NeroVision
[2010.07.08 16:16:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\OpenOffice.org2
[2009.06.03 19:31:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Opera
[2007.01.11 21:25:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\REAPER
[2006.11.06 16:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\SecuROM
[2006.11.05 22:03:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Sierra
[2007.11.20 15:09:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Simple Star
[2010.09.05 13:57:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Skype
[2010.09.05 12:54:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\skypePM
[2010.01.23 14:57:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Sony
[2010.01.23 14:50:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Sony Setup
[2008.01.15 15:44:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Sun
[2008.01.16 15:54:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Tank Combat
[2009.06.10 18:14:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\teamspeak2
[2006.11.26 20:48:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\temp
[2008.03.26 16:38:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\TuneUp Software
[2007.08.08 17:39:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\TVSM
[2008.07.31 13:18:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Uniblue
[2010.03.27 16:02:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\URSoft
[2009.06.10 18:38:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Ventrilo
[2007.04.24 15:28:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\vlc
[2009.01.10 17:25:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Vso
[2009.05.19 16:19:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\WinRAR
[2009.07.16 11:09:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\wsInspector
[2010.09.05 13:47:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Xfire
[2007.09.04 15:03:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ZOO Digital Publishing
< %APPDATA%\*.exe /s >
[2009.12.06 16:39:55 | 000,111,928 | ---- | M] () -- C:\Documents and Settings\student\Data aplikací\PnkBstrB.exe
[2008.02.29 21:19:16 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{35725FBC-A136-4A46-9F29-091759D9BB93}\ARPPRODUCTICON.exe
[2010.09.08 15:52:23 | 000,388,096 | R--- | M] (Trend Micro Inc.) -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
[2009.12.11 14:23:07 | 000,010,752 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon8255BBAC1.exe
[2009.12.11 14:23:07 | 000,006,144 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon83F12F734.exe
[2009.12.11 14:23:07 | 000,015,360 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon83F12F738.exe
[2010.04.09 17:29:48 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{89661B04-C646-4412-B6D3-5E19F02F1F37}\ARPPRODUCTICON.exe
[2007.08.06 19:36:42 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{B75EF7C9-E289-4EEF-8676-B46349F210C2}\ARPPRODUCTICON.exe
[2007.08.06 19:36:42 | 000,053,248 | R--- | M] (InstallShield Software Corp.) -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{B75EF7C9-E289-4EEF-8676-B46349F210C2}\NewShortcut11_B75EF7C9E2894EEF8676B46349F210C2.exe
[2007.08.06 19:36:42 | 000,053,248 | R--- | M] (InstallShield Software Corp.) -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{B75EF7C9-E289-4EEF-8676-B46349F210C2}\NewShortcut1_B75EF7C9E2894EEF8676B46349F210C2.exe
[2008.02.29 21:19:31 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{BEF726DD-4037-4214-8C6A-E625C02D2870}\ARPPRODUCTICON.exe
[2009.12.11 15:12:49 | 000,015,360 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E910.exe
[2009.12.11 15:12:49 | 000,011,264 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E96.exe
[2008.02.29 21:19:09 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{EA516024-D84D-41F1-814F-83175A6188F2}\ARPPRODUCTICON.exe
[2008.11.30 16:40:49 | 001,357,312 | ---- | M] (MRP Company, s.r.o.) -- C:\Documents and Settings\student\Data aplikací\MRP\NetAgent\SK\Upgrade.exe
[2010.01.23 14:52:17 | 032,494,896 | ---- | M] (Apple Inc.) -- C:\Documents and Settings\student\Data aplikací\Sony Setup\9234765D-29DF-48d0-93FB-284B7B6009B9\QuickTimeInstaller.exe
< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
< MD5 for: CDROM.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007.06.13 15:11:59 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=9B32416BD5988C97B6397CE0B02CAF97 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
< MD5 for: HAL.DLL >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.14 00:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.14 00:01:30 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL
< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\system32\dllcache\changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\system32\drivers\Changer.sys
< MD5 for: ISAPNP.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NVATA.SYS >
[2005.08.18 11:52:06 | 000,093,568 | R--- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\WINDOWS\system32\drivers\nvata.sys
< MD5 for: SCECLI.DLL >
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2006.04.20 14:18:35 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2006.11.04 18:02:10 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006.11.04 16:55:09 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2006.11.04 18:02:10 | 010,223,616 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006.11.04 18:02:10 | 002,359,296 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2010.09.13 14:45:46 | 000,272,431 | ---- | M] () -- C:\WINDOWS\system32\NvApps.xml
[2010.09.13 14:45:56 | 000,002,228 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
========== Alternate Data Streams ==========
@Alternate Data Stream - 40 bytes -> C:\Documents and Settings\student\Data aplikací:NT
@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:B3D74A13
@Alternate Data Stream - 157 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:1CE11B51
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:05EE1EEF
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:C4252FE0
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:202EF4B1
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:8FB6501C
< End of report >
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 08:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
< c:\windows\*.* /U >
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
[2009.03.31 17:47:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Agnitum
[2010.04.09 17:33:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.03.31 13:39:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Adobe
[2006.11.04 19:59:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\AdobeUM
[2007.12.04 17:50:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Ahead
[2006.11.09 17:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Apple Computer
[2007.11.20 16:36:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\AVG7
[2007.09.20 18:27:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\BearShare
[2010.04.29 18:08:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Canneverbe Limited
[2008.07.31 11:32:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\DAEMON Tools
[2009.01.31 13:37:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Deckadance
[2010.06.28 19:37:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\DivX
[2007.05.11 20:09:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\dvdcss
[2007.12.12 20:46:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ESET
[2006.12.26 18:21:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ESTSoft
[2009.10.26 18:46:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Faktury Plus
[2007.09.26 15:16:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\FreeCommander
[2007.11.01 20:16:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Google
[2008.04.05 13:50:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Hamachi
[2007.01.17 20:46:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Help
[2010.01.23 19:33:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\HLSW
[2010.09.05 13:49:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ICQ
[2008.04.10 19:20:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ICQ Toolbar
[2007.09.19 15:30:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ICQLite
[2006.11.04 15:35:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Identities
[2009.12.24 20:18:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\InstallShield
[2009.12.21 15:05:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Juce VST Host
[2006.11.28 17:58:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Leadertech
[2007.10.03 00:13:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\LimeWire
[2006.12.12 15:50:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Macromedia
[2009.02.08 20:25:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Malwarebytes
[2010.09.10 12:26:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Media Player Classic
[2010.09.09 10:32:51 | 000,000,000 | --SD | M] -- C:\Documents and Settings\student\Data aplikací\Microsoft
[2007.11.09 20:40:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Microsoft Games
[2007.09.24 15:36:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Mozilla
[2008.02.27 23:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\MRP
[2008.04.16 14:09:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\MxBoost
[2010.03.31 15:46:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Nero
[2006.11.11 21:54:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\NeroVision
[2010.07.08 16:16:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\OpenOffice.org2
[2009.06.03 19:31:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Opera
[2007.01.11 21:25:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\REAPER
[2006.11.06 16:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\SecuROM
[2006.11.05 22:03:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Sierra
[2007.11.20 15:09:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Simple Star
[2010.09.05 13:57:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Skype
[2010.09.05 12:54:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\skypePM
[2010.01.23 14:57:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Sony
[2010.01.23 14:50:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Sony Setup
[2008.01.15 15:44:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Sun
[2008.01.16 15:54:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Tank Combat
[2009.06.10 18:14:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\teamspeak2
[2006.11.26 20:48:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\temp
[2008.03.26 16:38:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\TuneUp Software
[2007.08.08 17:39:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\TVSM
[2008.07.31 13:18:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Uniblue
[2010.03.27 16:02:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\URSoft
[2009.06.10 18:38:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Ventrilo
[2007.04.24 15:28:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\vlc
[2009.01.10 17:25:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Vso
[2009.05.19 16:19:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\WinRAR
[2009.07.16 11:09:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\wsInspector
[2010.09.05 13:47:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\Xfire
[2007.09.04 15:03:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\student\Data aplikací\ZOO Digital Publishing
< %APPDATA%\*.exe /s >
[2009.12.06 16:39:55 | 000,111,928 | ---- | M] () -- C:\Documents and Settings\student\Data aplikací\PnkBstrB.exe
[2008.02.29 21:19:16 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{35725FBC-A136-4A46-9F29-091759D9BB93}\ARPPRODUCTICON.exe
[2010.09.08 15:52:23 | 000,388,096 | R--- | M] (Trend Micro Inc.) -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
[2009.12.11 14:23:07 | 000,010,752 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon8255BBAC1.exe
[2009.12.11 14:23:07 | 000,006,144 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon83F12F734.exe
[2009.12.11 14:23:07 | 000,015,360 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{83F12F73-D52E-40C0-93B1-463C311C4E17}\Icon83F12F738.exe
[2010.04.09 17:29:48 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{89661B04-C646-4412-B6D3-5E19F02F1F37}\ARPPRODUCTICON.exe
[2007.08.06 19:36:42 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{B75EF7C9-E289-4EEF-8676-B46349F210C2}\ARPPRODUCTICON.exe
[2007.08.06 19:36:42 | 000,053,248 | R--- | M] (InstallShield Software Corp.) -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{B75EF7C9-E289-4EEF-8676-B46349F210C2}\NewShortcut11_B75EF7C9E2894EEF8676B46349F210C2.exe
[2007.08.06 19:36:42 | 000,053,248 | R--- | M] (InstallShield Software Corp.) -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{B75EF7C9-E289-4EEF-8676-B46349F210C2}\NewShortcut1_B75EF7C9E2894EEF8676B46349F210C2.exe
[2008.02.29 21:19:31 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{BEF726DD-4037-4214-8C6A-E625C02D2870}\ARPPRODUCTICON.exe
[2009.12.11 15:12:49 | 000,015,360 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E910.exe
[2009.12.11 15:12:49 | 000,011,264 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E96.exe
[2008.02.29 21:19:09 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\student\Data aplikací\Microsoft\Installer\{EA516024-D84D-41F1-814F-83175A6188F2}\ARPPRODUCTICON.exe
[2008.11.30 16:40:49 | 001,357,312 | ---- | M] (MRP Company, s.r.o.) -- C:\Documents and Settings\student\Data aplikací\MRP\NetAgent\SK\Upgrade.exe
[2010.01.23 14:52:17 | 032,494,896 | ---- | M] (Apple Inc.) -- C:\Documents and Settings\student\Data aplikací\Sony Setup\9234765D-29DF-48d0-93FB-284B7B6009B9\QuickTimeInstaller.exe
< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
< MD5 for: CDROM.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007.06.13 15:11:59 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=9B32416BD5988C97B6397CE0B02CAF97 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
< MD5 for: HAL.DLL >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.14 00:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.14 00:01:30 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL
< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\system32\dllcache\changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\system32\drivers\Changer.sys
< MD5 for: ISAPNP.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NVATA.SYS >
[2005.08.18 11:52:06 | 000,093,568 | R--- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\WINDOWS\system32\drivers\nvata.sys
< MD5 for: SCECLI.DLL >
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2006.04.20 14:18:35 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2006.11.04 18:02:10 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006.11.04 16:55:09 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2006.11.04 18:02:10 | 010,223,616 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006.11.04 18:02:10 | 002,359,296 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2010.09.13 14:45:46 | 000,272,431 | ---- | M] () -- C:\WINDOWS\system32\NvApps.xml
[2010.09.13 14:45:56 | 000,002,228 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
========== Alternate Data Streams ==========
@Alternate Data Stream - 40 bytes -> C:\Documents and Settings\student\Data aplikací:NT
@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:B3D74A13
@Alternate Data Stream - 157 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:1CE11B51
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:05EE1EEF
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:C4252FE0
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:202EF4B1
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:8FB6501C
< End of report >