Re: dotaz
Napsal: 29 pro 2010 19:44
========== Files Created - No Company Name ==========
[2010.12.27 23:42:37 | 000,000,483 | ---- | C] () -- C:\Documents and Settings\Peter\Dokumenty\Zástupce - ComboFix.exe.lnk
[2010.12.25 16:56:01 | 000,001,307 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\MyBookWorld (172.16.0.5).lnk
[2010.12.24 13:59:28 | 000,054,141 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Vianoce.jpg
[2010.12.24 13:46:35 | 000,043,048 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\20835.jpg
[2010.12.22 10:41:51 | 000,517,854 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\quadriga.pdf
[2010.12.21 20:08:08 | 009,897,736 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\f1e4a985aa36225d4f52e0010cde3013[1].mp4
[2010.12.16 10:06:48 | 002,432,680 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\TSSL.pdf
[2010.12.13 21:11:39 | 000,001,200 | ---- | C] () -- C:\WINDOWS\System32\rzeksfsp.dat
[2010.12.11 19:04:22 | 000,000,668 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Hard Disk Low Level Format Tool.lnk
[2010.12.02 13:02:02 | 000,008,827 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\SPAM_____ Re_ cauko.zip
[2010.11.29 22:11:53 | 001,633,167 | ---- | C] () -- C:\Documents and Settings\Peter\Dokumenty\sľuk.mp4
[2010.11.29 21:52:45 | 067,076,118 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\SLUK__Najkrajsie_slovenske_ludove_piesne.zip
[2010.11.27 10:35:42 | 000,947,755 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\OTP.pdf
[2010.11.26 10:25:19 | 002,495,105 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\LGACSELE.ppt
[2010.11.26 10:25:19 | 001,536,000 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\LG AC SELECTOR MULTI F DX.xls
[2010.11.24 22:23:49 | 000,001,082 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\b.bmp
[2010.11.22 21:15:49 | 001,354,457 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\dm2.pdf
[2010.11.22 21:14:04 | 000,694,407 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\dm1.pdf
[2010.11.18 23:56:21 | 001,447,924 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\majka1.pdf
[2010.11.18 23:56:21 | 001,390,236 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\majka0.pdf
[2010.11.18 23:56:21 | 001,194,049 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\majka3.pdf
[2010.11.18 23:56:21 | 001,101,952 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\majka2.pdf
[2010.11.13 02:41:27 | 015,167,442 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\mecar.exe
[2010.11.08 14:27:02 | 000,709,277 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\21102010374.jpg
[2010.11.03 01:13:47 | 011,593,131 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\4779-705013.pdf
[2010.11.03 00:47:07 | 000,000,650 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\RegCleaner.lnk
[2010.11.02 22:05:28 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2010.11.02 22:05:28 | 000,005,672 | ---- | C] () -- C:\WINDOWS\System32\quartz.vxd
[2010.11.02 22:04:44 | 000,000,021 | ---- | C] () -- C:\WINDOWS\CS_setup.ini
[2010.11.02 21:15:40 | 000,237,568 | R--- | C] () -- C:\WINDOWS\System32\qtmlClient.dll
[2010.11.02 21:15:40 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\BFXSrcFilter.ax
[2010.11.02 21:15:40 | 000,002,145 | ---- | C] () -- C:\WINDOWS\Graffiti5.2Pin.ini
[2010.11.02 21:10:46 | 000,000,902 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Pinnacle Studio 12.lnk
[2010.11.02 21:04:53 | 000,000,349 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\PCLECHAL.INI
[2010.10.26 00:26:16 | 000,000,685 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\NSS.lnk
[2010.10.26 00:14:44 | 000,001,768 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Nokia PC Suite.lnk
[2010.10.25 23:47:43 | 000,001,860 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Nokia Software Updater.lnk
[2010.10.25 23:46:06 | 036,732,728 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\NokiaSoftwareUpdaterSetup_SK.exe
[2010.10.24 00:54:13 | 000,000,039 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Default.PLS
[2010.10.19 12:46:14 | 000,861,966 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Neurlg.pdf
[2010.10.19 12:44:04 | 000,716,844 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\CT.pdf
[2010.10.10 15:46:34 | 000,593,894 | ---- | C] () -- C:\Documents and Settings\Peter\Dokumenty\VZT_PRIZEMIE_020910-Model.pdf
[2010.10.05 21:42:33 | 000,000,831 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Sygic Assistant.lnk
[2010.10.04 18:21:37 | 008,808,947 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\VZT_PRIZEMIE_020910-Model1.psd
[2010.10.01 09:27:25 | 001,448,347 | ---- | C] () -- C:\Documents and Settings\Peter\Dokumenty\Tatramat290910.pdf
[2010.09.27 12:07:53 | 000,001,920 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Google Earth.lnk
[2010.09.24 19:48:58 | 000,000,675 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\DVD Shrink 3.2.lnk
[2010.09.18 18:22:44 | 000,000,443 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\MyBookWorld (172.16.0.8).lnk
[2010.09.17 18:06:03 | 000,000,846 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\WD Discovery.lnk
[2010.09.06 22:16:11 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
[2010.09.06 22:16:06 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_user_01_09_00.Wdf
[2010.07.29 22:51:57 | 013,150,378 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\IMG_6717.tif
[2010.07.28 00:01:13 | 000,000,789 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.07.27 23:19:32 | 003,998,686 | R--- | C] () -- C:\ComboFix.exe
[2010.07.25 15:32:13 | 001,869,090 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\interaudit_TO.pdf
[2010.07.23 12:51:31 | 000,053,760 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\ZoDLogis.doc
[2010.07.15 10:34:41 | 000,094,797 | ---- | C] () -- C:\Documents and Settings\Peter\Dokumenty\Logis15071.pdf
[2010.07.04 19:50:15 | 004,403,479 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Rapget.RS_Public_v1.0.9.0_cz.exe
[2009.12.27 19:41:08 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009.03.14 17:23:04 | 000,004,533 | ---- | C] () -- C:\WINDOWS\comsoft3.ini
[2009.01.10 23:54:19 | 000,000,137 | ---- | C] () -- C:\WINDOWS\canopus.ini
[2009.01.10 23:32:21 | 000,001,536 | ---- | C] () -- C:\WINDOWS\System32\pavedius.dll
[2009.01.10 23:32:21 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\pavplal.dll
[2008.11.23 15:47:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2008.11.08 21:32:27 | 000,003,399 | ---- | C] () -- C:\WINDOWS\SETUPACT.INI
[2008.11.03 20:21:04 | 000,000,108 | ---- | C] () -- C:\WINDOWS\WFT-E2Utility.INI
[2008.09.27 21:34:58 | 000,000,598 | ---- | C] () -- C:\WINDOWS\TRNCOM.INI
[2008.08.05 19:13:34 | 000,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2008.05.03 19:14:05 | 000,000,235 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2008.04.06 17:56:01 | 000,000,737 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.04.06 17:53:53 | 000,000,855 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2008.03.25 21:45:17 | 000,003,732 | ---- | C] () -- C:\WINDOWS\wtran32.INI
[2008.03.21 22:02:26 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
[2008.03.21 22:02:26 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2008.03.21 22:02:26 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2008.03.21 22:02:26 | 000,000,205 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2008.03.21 22:02:26 | 000,000,073 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
[2008.03.21 21:38:13 | 000,000,541 | ---- | C] () -- C:\WINDOWS\webtran4.INI
[2008.03.21 21:24:20 | 000,000,088 | ---- | C] () -- C:\WINDOWS\STXKBD32.INI
[2008.03.15 21:04:46 | 000,038,442 | ---- | C] () -- C:\Documents and Settings\Peter\Data aplikací\Microsoft Access.ADR
[2008.03.15 21:02:48 | 000,038,460 | ---- | C] () -- C:\Documents and Settings\Peter\Data aplikací\Hodnoty oddělené tabulátorem (Windows).ADR
[2008.03.10 00:48:40 | 000,000,015 | ---- | C] () -- C:\WINDOWS\jafcd.ini
[2008.02.08 18:13:44 | 000,319,488 | ---- | C] () -- C:\WINDOWS\System32\LS3Renderer.dll
[2008.01.27 17:36:42 | 000,000,186 | ---- | C] () -- C:\WINDOWS\KPCMS.INI
[2008.01.27 17:36:05 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2007.12.15 19:50:00 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007.12.02 14:23:20 | 000,000,101 | ---- | C] () -- C:\WINDOWS\PSXLPR.INI
[2007.12.02 14:23:19 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\Bot.dll
[2007.11.13 22:48:57 | 000,004,733 | ---- | C] () -- C:\WINDOWS\wdict32.INI
[2007.09.21 15:23:58 | 000,413,696 | ---- | C] () -- C:\WINDOWS\System32\RTClientSDK71.dll
[2007.09.21 15:23:58 | 000,001,147 | ---- | C] () -- C:\WINDOWS\System32\IPCamera.ini
[2007.08.22 23:27:29 | 000,000,277 | ---- | C] () -- C:\WINDOWS\hpqcopy.INI
[2007.07.24 20:59:14 | 000,000,229 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007.06.29 15:07:35 | 000,000,799 | ---- | C] () -- C:\WINDOWS\electrolux.ini
[2007.06.03 19:32:13 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Peter\Data aplikací\$_hpcst$.hpc
[2007.06.03 17:26:36 | 000,000,376 | ---- | C] () -- C:\WINDOWS\settings.ini
[2007.06.03 16:49:21 | 000,000,744 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.05.19 21:41:49 | 000,231,936 | ---- | C] () -- C:\Documents and Settings\Peter\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.05.18 16:43:58 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2007.05.18 16:43:58 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2007.04.29 09:36:34 | 000,000,139 | ---- | C] () -- C:\WINDOWS\msicpl.ini
[2007.04.28 15:55:58 | 000,004,265 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007.04.28 14:28:40 | 000,003,485 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2007.04.28 14:28:37 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007.04.28 14:25:29 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\memtest.dll
[2007.04.28 14:25:28 | 000,037,880 | R--- | C] () -- C:\WINDOWS\System32\drivers\vgauti.sys
[2007.04.28 14:25:28 | 000,037,880 | R--- | C] () -- C:\WINDOWS\System32\drivers\msicpl.sys
[2007.04.28 14:25:14 | 000,004,385 | ---- | C] () -- C:\WINDOWS\System32\drivers\Stdsys.SYS
[2007.01.26 03:04:12 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\mase32.dll
[2007.01.26 03:04:12 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\ma32.dll
[2006.10.22 12:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.10.22 12:22:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.10.22 12:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.10.22 12:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.10.22 12:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.10.22 12:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.22 12:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005.10.14 11:56:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 11:56:50 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 11:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 11:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 11:56:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\MMSwitch.dll
[2005.04.22 15:17:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\AVSClientSDK45.dll
[2003.09.30 11:47:38 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2003.09.30 11:47:38 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2003.09.30 11:47:38 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2003.09.30 11:47:38 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2003.04.16 14:00:00 | 000,002,048 | ---- | C] () -- C:\WINDOWS\System32\syscvchk.dll
[2003.04.09 15:38:04 | 000,005,664 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2010.02.17 23:04:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Avigilon
[2009.05.13 18:47:21 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2009.05.13 19:59:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonIJScan
[2007.11.27 18:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Downloaded Installations
[2010.01.02 15:46:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\espionServerData
[2008.01.10 16:46:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Grisoft
[2010.10.26 00:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Installations
[2007.10.03 18:22:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\muvee Technologies
[2010.10.25 23:47:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Nokia
[2010.10.25 21:46:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NokiaInstallerCache
[2007.11.27 18:37:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2010.11.02 21:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle
[2010.11.02 21:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle Studio Plus
[2010.11.02 21:12:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle Studio Ultimate
[2010.02.01 19:13:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2010.11.02 21:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Studio 12
[2008.01.06 23:26:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2009.02.21 17:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ulead Systems
[2008.02.05 19:18:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\PC Suite
[2008.02.05 19:18:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\Složka odesílání Share-to-Web
[2010.02.17 23:39:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Avigilon
[2008.11.08 22:09:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Babylon
[2008.10.08 22:51:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Canon
[2009.01.10 23:47:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Canopus
[2009.10.27 00:50:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\GARMIN
[2009.07.18 17:49:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Graphisoft
[2007.04.29 10:17:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\InterTrust
[2009.11.24 23:57:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\MRP
[2007.10.04 01:12:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\muvee Technologies
[2010.10.26 00:41:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Nokia
[2008.09.15 19:43:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Opera
[2010.12.27 18:22:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\PC Suite
[2010.11.02 21:16:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\proDAD
[2010.02.01 19:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Publish Providers
[2009.03.18 09:39:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\select
[2007.06.24 11:27:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Složka odesílání Share-to-Web
[2007.11.05 12:44:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Software602
[2010.02.01 19:42:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Sony
[2008.11.28 22:59:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Thinstall
[2009.01.02 00:38:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Ulead Systems
[2010.09.24 20:37:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\WD
[2009.03.29 18:17:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\peter1\Data aplikací\PC Suite
[2010.12.27 23:44:56 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{CCA8FD82-364E-43D1-9724-9942B392C758}.job
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"H/PC Connection Agent" = "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" -- [2006.11.13 16:50:20 | 001,289,000 | ---- | M] (Microsoft Corporation)
"Creative Live! Cam Manager" = C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe -- [2007.05.02 10:30:20 | 000,151,552 | ---- | M] (Creative Technology Ltd.)
"PC Suite Tray" = "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray -- [2010.05.14 10:32:30 | 001,479,680 | ---- | M] (Nokia)
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 08:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]
"" =
< c:\windows\*.* /U >
[10 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
[2010.12.27 23:35:10 | 003,998,686 | R--- | M] () -- C:\ComboFix.exe
[2007.11.20 23:34:08 | 005,168,831 | ---- | M] () -- C:\smac20_setup.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.11.16 19:54:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Adobe
[2007.09.16 17:33:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Ahead
[2008.06.16 22:22:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Apple Computer
[2010.11.03 00:18:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\ArcSoft
[2010.02.17 23:39:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Avigilon
[2008.11.08 22:09:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Babylon
[2008.10.08 22:51:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Canon
[2009.01.10 23:47:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Canopus
[2008.10.14 22:42:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Creative
[2010.04.07 22:40:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Download Manager
[2009.10.01 20:33:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\FastStone
[2009.10.27 00:50:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\GARMIN
[2007.07.08 23:42:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Google
[2009.07.18 17:49:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Graphisoft
[2007.05.22 09:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Help
[2007.04.28 14:15:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Identities
[2008.03.23 14:40:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\InstallShield
[2010.02.26 19:14:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Intelli-studio
[2007.04.29 10:17:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\InterTrust
[2008.02.14 00:53:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Lavasoft
[2007.04.29 09:40:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Macromedia
[2010.07.28 00:01:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Malwarebytes
[2009.10.20 22:47:34 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Peter\Data aplikací\Microsoft
[2009.03.04 21:01:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Mozilla
[2009.11.24 23:57:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\MRP
[2007.10.04 01:12:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\muvee Technologies
[2009.04.22 20:40:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Nero
[2010.09.18 17:50:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\NeroDigital(TM)
[2010.10.26 00:41:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Nokia
[2008.09.15 19:43:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Opera
[2010.12.27 18:22:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\PC Suite
[2010.11.02 21:16:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\proDAD
[2010.02.01 19:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Publish Providers
[2009.03.18 09:39:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\select
[2007.06.24 11:27:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Složka odesílání Share-to-Web
[2007.11.05 12:44:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Software602
[2010.02.01 19:42:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Sony
[2009.06.18 13:17:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Sun
[2008.02.12 23:21:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Symantec
[2008.11.28 22:59:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Thinstall
[2009.01.02 00:38:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Ulead Systems
[2010.09.24 20:37:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\WD
[2009.09.05 14:21:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\WinRAR
[2008.10.09 16:43:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\ZoomBrowser EX
< %APPDATA%\*.exe /s >
[2008.11.23 17:05:04 | 017,732,895 | ---- | M] (Arcsoft ) -- C:\Documents and Settings\Peter\Data aplikací\ArcSoft\Video Impression\2. 0\VI2_Update_2.0.0.22_2.0.0.78_E.exe
[2008.03.28 00:14:16 | 000,003,638 | R--- | M] () -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{33359986-DD66-44E1-A709-D1FA943B014F}\_0A3C0C09C850366E910CA7.exe
[2008.03.28 00:14:16 | 000,003,638 | R--- | M] () -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{33359986-DD66-44E1-A709-D1FA943B014F}\_4337C2151BC3851DD530CB.exe
[2008.03.28 00:14:16 | 000,003,638 | R--- | M] () -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{33359986-DD66-44E1-A709-D1FA943B014F}\_6FEFF9B68218417F98F549.exe
[2010.11.02 21:12:45 | 000,029,926 | R--- | M] () -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{5EB90C06-964F-4195-B83E-BD7E55C88415}\ARPPRODUCTICON.exe
[2010.11.02 21:10:54 | 000,040,960 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_AMCap.exe
[2010.11.02 21:10:54 | 000,049,152 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_Check3D.exe
[2010.11.02 21:10:55 | 000,069,632 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_ContentTransfer.exe
[2010.11.02 21:10:55 | 000,434,176 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_GuidedTour.exe
[2010.11.02 21:10:55 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_Help_HH.exe
[2010.11.02 21:10:55 | 000,065,536 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_ReadMe.exe
[2010.11.02 21:10:54 | 000,069,632 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\Studio.exe
< MD5 for: AGP440.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:AGP440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\AGP440.SYS
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\AGP440.SYS
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\ReinstallBackups\0034\DriverFiles\i386\AGP440.SYS
[2003.04.16 14:00:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:atapi.sys
[2003.04.16 14:00:00 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0026\DriverFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0031\DriverFiles\i386\atapi.sys
[1996.09.17 01:00:00 | 000,014,208 | ---- | M] (Microsoft Corporation) MD5=A5C43F72AA6FCC9080504FCD39465DA4 -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Atapi.sys
< MD5 for: CDROM.SYS >
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2003.04.16 14:00:00 | 000,047,488 | ---- | M] (Microsoft Corporation) MD5=6506E033AD04CFEC9EE56DBEFD1083DD -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2003.04.16 14:00:00 | 000,053,248 | ---- | M] (Microsoft Corporation) MD5=031E7FF41B13B658CAE7D6C98086F76A -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[1996.09.17 01:00:00 | 000,045,776 | ---- | M] (Microsoft Corporation) MD5=DA8297BCC3E0D8F7A42DAA2240AA14DB -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Eventlog.dll
[2003.04.16 14:00:00 | 000,049,152 | ---- | M] (Microsoft Corporation) MD5=E8508E7F865490D8AE71D00C8DF4D227 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2003.04.16 14:00:00 | 001,004,544 | ---- | M] (Microsoft Corporation) MD5=11D80755545CFB5EB9659EE88440EAE2 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007.06.13 15:11:59 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=9B32416BD5988C97B6397CE0B02CAF97 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
< MD5 for: HAL.DLL >
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:hal.dll
[1996.09.17 01:00:00 | 000,049,296 | ---- | M] (Microsoft Corporation) MD5=0C67548274C591CDF7313340CD6ECF9F -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Hal.dll
[2003.04.16 14:00:00 | 000,129,920 | ---- | M] (Microsoft Corporation) MD5=308709E92843DFF3A5CDCA069F6F5C61 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
[2008.04.14 00:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.14 00:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\hal.dll
< MD5 for: CHANGER.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:Changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\changer.sys
< MD5 for: IASTOR.SYS >
[2007.03.21 21:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Install\Počítače\DUSAN_PC\7.5.0.1017\32bit\iastor.sys
[2007.03.21 21:59:30 | 000,381,720 | ---- | M] (Intel Corporation) MD5=9D7ED4275702E2FC409F2CC563245740 -- C:\Install\Počítače\DUSAN_PC\7.5.0.1017\64bit\IaStor.sys
< MD5 for: ISAPNP.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:isapnp.sys
[2003.04.16 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\dllcache\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\ReinstallBackups\0025\DriverFiles\i386\isapnp.sys
< MD5 for: LSASS.EXE >
[1996.09.17 01:00:00 | 000,006,960 | ---- | M] (Microsoft Corporation) MD5=0A2A65B3165965BB1B7AAA360B03A10A -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Lsass.exe
[2003.04.16 14:00:00 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=32F7074BAC9A5F899CCA9C046C9FA6EB -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2003.04.16 14:00:00 | 000,167,552 | ---- | M] (Microsoft Corporation) MD5=3B350E5A2A5E951453F3993275A4523A -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
[1996.09.17 01:00:00 | 000,089,616 | ---- | M] (Microsoft Corporation) MD5=3EE20762D9FE31A0BD219991B61969CA -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Ndis.sys
< MD5 for: NETLOGON.DLL >
[1996.09.17 01:00:00 | 000,150,064 | ---- | M] (Microsoft Corporation) MD5=A9EE1BBA71C41613F5833F7375D38232 -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
[2003.04.16 14:00:00 | 000,399,360 | ---- | M] (Microsoft Corporation) MD5=CF03E300B5CEEFFEFBE6F67532BD0EF1 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
[2003.04.16 14:00:00 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B2666CAB5E8C8A741D63F18D551A47FB -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2003.04.16 14:00:00 | 000,045,568 | ---- | M] (Microsoft Corporation) MD5=7763D73255AD4046FA999D42EAF22C26 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
[1996.09.17 01:00:00 | 000,037,328 | ---- | M] (Microsoft Corporation) MD5=B473F5311FC0056FDBAE613E2226B42F -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Smss.exe
< MD5 for: SVCHOST.EXE >
[2003.04.16 14:00:00 | 000,012,800 | ---- | M] (Microsoft Corporation) MD5=329945887A0C684C38A4845330BC9100 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2006.04.20 13:51:50 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=1DBF125862891817F374F407626967F4 -- C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
[2003.04.16 14:00:00 | 000,332,928 | ---- | M] (Microsoft Corporation) MD5=244A2F9816BC9B593957281EF577D976 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2007.10.30 18:53:32 | 000,360,832 | ---- | M] (Microsoft Corporation) MD5=64798ECFA43D78C7178375FCDD16D8C8 -- C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[1996.09.17 01:00:00 | 000,123,264 | ---- | M] (Microsoft Corporation) MD5=B0925178A046228F1356D7151F9DA2BC -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Tcpip.sys
[2006.04.20 14:18:35 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[1996.09.17 01:00:00 | 000,015,984 | ---- | M] (Microsoft Corporation) MD5=39E9464F9D0536FB01C1CFFE43CD5EEA -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2003.04.16 14:00:00 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=B26871B5CE92F9D95AE6E62119799EB9 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: VAXSCSI.SYS >
[2009.02.21 17:21:26 | 000,223,128 | ---- | M] (Alcohol Soft Co., Ltd.) MD5=92CEBC2BC7BE2C8D49391B365569F306 -- C:\WINDOWS\system32\drivers\vaxscsi.sys
< MD5 for: VIAMRAID.SYS >
[2007.03.19 16:18:12 | 000,104,064 | ---- | M] (VIA Technologies inc,.ltd) MD5=85E9421C8A99D1291B43B9B59A669AC3 -- C:\WINDOWS\system32\drivers\viamraid.sys
< MD5 for: WINLOGON.EXE >
[1996.09.17 01:00:00 | 000,169,504 | ---- | M] (Microsoft Corporation) MD5=6AE8F0E6FB65E51DFACA46F9E90879D5 -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
[2003.04.16 14:00:00 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=FF8857D1AF59071F172C0FAD0FD33E87 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
< MD5 for: WS2_32.DLL >
[2003.04.16 14:00:00 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=748494B94A871A828C64D1D5C738D2B7 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008.04.14 08:51:50 | 001,384,479 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\msvbvm60.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2008.09.14 22:08:47 | 000,524,288 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2008.09.14 19:57:31 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2008.09.14 22:08:47 | 031,195,136 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2008.09.14 22:08:47 | 008,912,896 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[2008.04.14 08:51:50 | 001,384,479 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\msvbvm60.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< %systemroot%\system32\drivers\*.sys /3 >
[2010.11.29 17:42:06 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys
[2010.11.29 17:42:18 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010.11.02 17:17:02 | 000,040,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ndproxy.sys
[2010.08.26 15:39:50 | 000,357,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\srv.sys
< %systemroot%\system32\*.* /3 >
[2010.11.06 02:25:02 | 000,124,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\advpack.dll
[2010.11.02 22:05:35 | 000,016,832 | ---- | M] () -- C:\WINDOWS\system32\amcompat.tlb
[2010.10.28 15:09:00 | 000,290,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\system32\atmfd.dll
[2010.08.23 18:12:35 | 000,617,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comctl32.dll
[2010.11.06 02:25:02 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\corpol.dll
[2010.11.06 02:25:02 | 000,347,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dxtmsft.dll
[2010.11.06 02:25:02 | 000,214,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dxtrans.dll
[2010.11.06 02:25:03 | 000,133,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\extmgr.dll
[2010.12.17 04:22:32 | 002,399,048 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2010.11.03 14:25:53 | 000,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\html.iec
[2010.11.06 02:25:03 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\icardie.dll
[2010.11.03 14:24:55 | 000,070,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ie4uinit.exe
[2010.11.06 02:25:03 | 000,153,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieakeng.dll
[2010.11.06 02:25:03 | 000,230,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieaksie.dll
[2010.10.18 13:06:11 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieakui.dll
[2010.11.06 02:25:03 | 000,380,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieapfltr.dll
[2010.11.06 02:25:03 | 000,384,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\iedkcs32.dll
[2010.11.06 02:25:03 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieencode.dll
[2010.11.06 02:25:03 | 006,075,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieframe.dll
[2010.11.06 02:25:03 | 000,192,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\iepeers.dll
[2010.11.06 02:25:03 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\iernonce.dll
[2010.11.06 02:25:03 | 000,268,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\iertutil.dll
[2010.11.03 14:24:56 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieudinit.exe
[2010.11.06 02:25:03 | 001,830,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\inetcpl.cpl
[2010.11.18 20:15:47 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\isign32.dll
[2010.11.06 02:25:03 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\jsproxy.dll
[2010.09.18 08:53:37 | 000,954,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc40.dll
[2010.09.18 08:53:37 | 000,953,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc40u.dll
[2010.09.18 08:53:37 | 000,974,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc42.dll
[2010.09.18 12:23:38 | 000,974,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc42u.dll
[2010.12.17 04:01:26 | 037,366,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MRT.exe
[2010.11.06 02:25:03 | 000,468,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msfeeds.dll
[2010.11.06 02:25:03 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msfeedsbs.dll
[2010.11.06 02:25:04 | 003,604,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mshtml.dll
[2010.11.06 02:25:04 | 000,478,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mshtmled.dll
[2010.11.06 02:25:04 | 000,193,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msrating.dll
[2010.11.06 02:25:04 | 000,671,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mstime.dll
[2010.11.02 22:05:35 | 000,023,392 | ---- | M] () -- C:\WINDOWS\system32\nscompat.tlb
[2010.11.06 02:25:04 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\occache.dll
[2010.12.11 15:34:11 | 000,104,306 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2010.12.11 15:34:11 | 000,093,370 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2010.12.11 15:34:11 | 000,498,154 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2010.12.11 15:34:11 | 000,501,488 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2010.12.11 15:34:11 | 001,213,216 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2010.11.06 02:25:04 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\pngfilt.dll
[2010.07.27 23:30:36 | 000,000,202 | ---- | M] () -- C:\WINDOWS\system32\PSLOG
[2010.08.16 10:45:05 | 000,590,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rpcrt4.dll
[2010.12.15 18:28:20 | 000,001,200 | ---- | M] () -- C:\WINDOWS\system32\rzeksfsp.dat
[2010.07.27 08:30:31 | 008,466,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shell32.dll
[2010.08.17 15:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spoolsv.exe
[2010.08.27 07:54:10 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\srvsvc.dll
[2010.08.27 10:03:42 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\t2embed.dll
[2010.11.03 15:12:40 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\tzchange.exe
[2010.12.17 04:05:25 | 000,842,762 | ---- | M] () -- C:\WINDOWS\system32\TZLog.log
[2010.11.06 02:25:04 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\url.dll
[2010.11.06 02:25:04 | 001,168,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\urlmon.dll
[2010.11.02 22:05:26 | 000,002,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\w95inf16.dll
[2010.11.02 22:05:26 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\w95inf32.dll
[2010.11.06 02:25:04 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\webcheck.dll
[2010.10.26 15:58:35 | 001,853,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[2010.11.06 02:25:04 | 000,832,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wininet.dll
[2010.08.25 23:36:02 | 010,841,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wmp.dll
[2010.07.27 23:30:56 | 000,012,598 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2010.08.27 03:43:50 | 000,005,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\xpsp4res.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< >
< >
========== Files - Unicode (All) ==========
[2010.10.25 21:55:14 | 000,000,000 | ---D | M](C:\Documents and Settings\Peter\Data aplikac?) -- C:\Documents and Settings\Peter\Data aplikac�
[2010.10.25 21:55:14 | 000,000,000 | ---D | C](C:\Documents and Settings\Peter\Data aplikac?) -- C:\Documents and Settings\Peter\Data aplikac�
========== Alternate Data Streams ==========
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:ECE4A64B
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
< End of report >
[2010.12.27 23:42:37 | 000,000,483 | ---- | C] () -- C:\Documents and Settings\Peter\Dokumenty\Zástupce - ComboFix.exe.lnk
[2010.12.25 16:56:01 | 000,001,307 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\MyBookWorld (172.16.0.5).lnk
[2010.12.24 13:59:28 | 000,054,141 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Vianoce.jpg
[2010.12.24 13:46:35 | 000,043,048 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\20835.jpg
[2010.12.22 10:41:51 | 000,517,854 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\quadriga.pdf
[2010.12.21 20:08:08 | 009,897,736 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\f1e4a985aa36225d4f52e0010cde3013[1].mp4
[2010.12.16 10:06:48 | 002,432,680 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\TSSL.pdf
[2010.12.13 21:11:39 | 000,001,200 | ---- | C] () -- C:\WINDOWS\System32\rzeksfsp.dat
[2010.12.11 19:04:22 | 000,000,668 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Hard Disk Low Level Format Tool.lnk
[2010.12.02 13:02:02 | 000,008,827 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\SPAM_____ Re_ cauko.zip
[2010.11.29 22:11:53 | 001,633,167 | ---- | C] () -- C:\Documents and Settings\Peter\Dokumenty\sľuk.mp4
[2010.11.29 21:52:45 | 067,076,118 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\SLUK__Najkrajsie_slovenske_ludove_piesne.zip
[2010.11.27 10:35:42 | 000,947,755 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\OTP.pdf
[2010.11.26 10:25:19 | 002,495,105 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\LGACSELE.ppt
[2010.11.26 10:25:19 | 001,536,000 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\LG AC SELECTOR MULTI F DX.xls
[2010.11.24 22:23:49 | 000,001,082 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\b.bmp
[2010.11.22 21:15:49 | 001,354,457 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\dm2.pdf
[2010.11.22 21:14:04 | 000,694,407 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\dm1.pdf
[2010.11.18 23:56:21 | 001,447,924 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\majka1.pdf
[2010.11.18 23:56:21 | 001,390,236 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\majka0.pdf
[2010.11.18 23:56:21 | 001,194,049 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\majka3.pdf
[2010.11.18 23:56:21 | 001,101,952 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\majka2.pdf
[2010.11.13 02:41:27 | 015,167,442 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\mecar.exe
[2010.11.08 14:27:02 | 000,709,277 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\21102010374.jpg
[2010.11.03 01:13:47 | 011,593,131 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\4779-705013.pdf
[2010.11.03 00:47:07 | 000,000,650 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\RegCleaner.lnk
[2010.11.02 22:05:28 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2010.11.02 22:05:28 | 000,005,672 | ---- | C] () -- C:\WINDOWS\System32\quartz.vxd
[2010.11.02 22:04:44 | 000,000,021 | ---- | C] () -- C:\WINDOWS\CS_setup.ini
[2010.11.02 21:15:40 | 000,237,568 | R--- | C] () -- C:\WINDOWS\System32\qtmlClient.dll
[2010.11.02 21:15:40 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\BFXSrcFilter.ax
[2010.11.02 21:15:40 | 000,002,145 | ---- | C] () -- C:\WINDOWS\Graffiti5.2Pin.ini
[2010.11.02 21:10:46 | 000,000,902 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Pinnacle Studio 12.lnk
[2010.11.02 21:04:53 | 000,000,349 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\PCLECHAL.INI
[2010.10.26 00:26:16 | 000,000,685 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\NSS.lnk
[2010.10.26 00:14:44 | 000,001,768 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Nokia PC Suite.lnk
[2010.10.25 23:47:43 | 000,001,860 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Nokia Software Updater.lnk
[2010.10.25 23:46:06 | 036,732,728 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\NokiaSoftwareUpdaterSetup_SK.exe
[2010.10.24 00:54:13 | 000,000,039 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Default.PLS
[2010.10.19 12:46:14 | 000,861,966 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Neurlg.pdf
[2010.10.19 12:44:04 | 000,716,844 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\CT.pdf
[2010.10.10 15:46:34 | 000,593,894 | ---- | C] () -- C:\Documents and Settings\Peter\Dokumenty\VZT_PRIZEMIE_020910-Model.pdf
[2010.10.05 21:42:33 | 000,000,831 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Sygic Assistant.lnk
[2010.10.04 18:21:37 | 008,808,947 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\VZT_PRIZEMIE_020910-Model1.psd
[2010.10.01 09:27:25 | 001,448,347 | ---- | C] () -- C:\Documents and Settings\Peter\Dokumenty\Tatramat290910.pdf
[2010.09.27 12:07:53 | 000,001,920 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Google Earth.lnk
[2010.09.24 19:48:58 | 000,000,675 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\DVD Shrink 3.2.lnk
[2010.09.18 18:22:44 | 000,000,443 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\MyBookWorld (172.16.0.8).lnk
[2010.09.17 18:06:03 | 000,000,846 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\WD Discovery.lnk
[2010.09.06 22:16:11 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_User_PCCSWpdDriver_01_09_00.Wdf
[2010.09.06 22:16:06 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_user_01_09_00.Wdf
[2010.07.29 22:51:57 | 013,150,378 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\IMG_6717.tif
[2010.07.28 00:01:13 | 000,000,789 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.07.27 23:19:32 | 003,998,686 | R--- | C] () -- C:\ComboFix.exe
[2010.07.25 15:32:13 | 001,869,090 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\interaudit_TO.pdf
[2010.07.23 12:51:31 | 000,053,760 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\ZoDLogis.doc
[2010.07.15 10:34:41 | 000,094,797 | ---- | C] () -- C:\Documents and Settings\Peter\Dokumenty\Logis15071.pdf
[2010.07.04 19:50:15 | 004,403,479 | ---- | C] () -- C:\Documents and Settings\Peter\Plocha\Rapget.RS_Public_v1.0.9.0_cz.exe
[2009.12.27 19:41:08 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009.03.14 17:23:04 | 000,004,533 | ---- | C] () -- C:\WINDOWS\comsoft3.ini
[2009.01.10 23:54:19 | 000,000,137 | ---- | C] () -- C:\WINDOWS\canopus.ini
[2009.01.10 23:32:21 | 000,001,536 | ---- | C] () -- C:\WINDOWS\System32\pavedius.dll
[2009.01.10 23:32:21 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\pavplal.dll
[2008.11.23 15:47:13 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2008.11.08 21:32:27 | 000,003,399 | ---- | C] () -- C:\WINDOWS\SETUPACT.INI
[2008.11.03 20:21:04 | 000,000,108 | ---- | C] () -- C:\WINDOWS\WFT-E2Utility.INI
[2008.09.27 21:34:58 | 000,000,598 | ---- | C] () -- C:\WINDOWS\TRNCOM.INI
[2008.08.05 19:13:34 | 000,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2008.05.03 19:14:05 | 000,000,235 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2008.04.06 17:56:01 | 000,000,737 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.04.06 17:53:53 | 000,000,855 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2008.03.25 21:45:17 | 000,003,732 | ---- | C] () -- C:\WINDOWS\wtran32.INI
[2008.03.21 22:02:26 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
[2008.03.21 22:02:26 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2008.03.21 22:02:26 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2008.03.21 22:02:26 | 000,000,205 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2008.03.21 22:02:26 | 000,000,073 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
[2008.03.21 21:38:13 | 000,000,541 | ---- | C] () -- C:\WINDOWS\webtran4.INI
[2008.03.21 21:24:20 | 000,000,088 | ---- | C] () -- C:\WINDOWS\STXKBD32.INI
[2008.03.15 21:04:46 | 000,038,442 | ---- | C] () -- C:\Documents and Settings\Peter\Data aplikací\Microsoft Access.ADR
[2008.03.15 21:02:48 | 000,038,460 | ---- | C] () -- C:\Documents and Settings\Peter\Data aplikací\Hodnoty oddělené tabulátorem (Windows).ADR
[2008.03.10 00:48:40 | 000,000,015 | ---- | C] () -- C:\WINDOWS\jafcd.ini
[2008.02.08 18:13:44 | 000,319,488 | ---- | C] () -- C:\WINDOWS\System32\LS3Renderer.dll
[2008.01.27 17:36:42 | 000,000,186 | ---- | C] () -- C:\WINDOWS\KPCMS.INI
[2008.01.27 17:36:05 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2007.12.15 19:50:00 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007.12.02 14:23:20 | 000,000,101 | ---- | C] () -- C:\WINDOWS\PSXLPR.INI
[2007.12.02 14:23:19 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\Bot.dll
[2007.11.13 22:48:57 | 000,004,733 | ---- | C] () -- C:\WINDOWS\wdict32.INI
[2007.09.21 15:23:58 | 000,413,696 | ---- | C] () -- C:\WINDOWS\System32\RTClientSDK71.dll
[2007.09.21 15:23:58 | 000,001,147 | ---- | C] () -- C:\WINDOWS\System32\IPCamera.ini
[2007.08.22 23:27:29 | 000,000,277 | ---- | C] () -- C:\WINDOWS\hpqcopy.INI
[2007.07.24 20:59:14 | 000,000,229 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007.06.29 15:07:35 | 000,000,799 | ---- | C] () -- C:\WINDOWS\electrolux.ini
[2007.06.03 19:32:13 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Peter\Data aplikací\$_hpcst$.hpc
[2007.06.03 17:26:36 | 000,000,376 | ---- | C] () -- C:\WINDOWS\settings.ini
[2007.06.03 16:49:21 | 000,000,744 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.05.19 21:41:49 | 000,231,936 | ---- | C] () -- C:\Documents and Settings\Peter\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.05.18 16:43:58 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2007.05.18 16:43:58 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2007.04.29 09:36:34 | 000,000,139 | ---- | C] () -- C:\WINDOWS\msicpl.ini
[2007.04.28 15:55:58 | 000,004,265 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007.04.28 14:28:40 | 000,003,485 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2007.04.28 14:28:37 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007.04.28 14:25:29 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\memtest.dll
[2007.04.28 14:25:28 | 000,037,880 | R--- | C] () -- C:\WINDOWS\System32\drivers\vgauti.sys
[2007.04.28 14:25:28 | 000,037,880 | R--- | C] () -- C:\WINDOWS\System32\drivers\msicpl.sys
[2007.04.28 14:25:14 | 000,004,385 | ---- | C] () -- C:\WINDOWS\System32\drivers\Stdsys.SYS
[2007.01.26 03:04:12 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\mase32.dll
[2007.01.26 03:04:12 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\ma32.dll
[2006.10.22 12:22:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006.10.22 12:22:00 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006.10.22 12:22:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006.10.22 12:22:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006.10.22 12:22:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006.10.22 12:22:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.22 12:22:00 | 000,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2005.10.14 11:56:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 11:56:50 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 11:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 11:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 11:56:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\MMSwitch.dll
[2005.04.22 15:17:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\AVSClientSDK45.dll
[2003.09.30 11:47:38 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2003.09.30 11:47:38 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2003.09.30 11:47:38 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2003.09.30 11:47:38 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2003.04.16 14:00:00 | 000,002,048 | ---- | C] () -- C:\WINDOWS\System32\syscvchk.dll
[2003.04.09 15:38:04 | 000,005,664 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2010.02.17 23:04:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Avigilon
[2009.05.13 18:47:21 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2009.05.13 19:59:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonIJScan
[2007.11.27 18:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Downloaded Installations
[2010.01.02 15:46:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\espionServerData
[2008.01.10 16:46:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Grisoft
[2010.10.26 00:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Installations
[2007.10.03 18:22:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\muvee Technologies
[2010.10.25 23:47:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Nokia
[2010.10.25 21:46:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NokiaInstallerCache
[2007.11.27 18:37:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2010.11.02 21:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle
[2010.11.02 21:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle Studio Plus
[2010.11.02 21:12:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle Studio Ultimate
[2010.02.01 19:13:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2010.11.02 21:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Studio 12
[2008.01.06 23:26:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2009.02.21 17:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ulead Systems
[2008.02.05 19:18:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\PC Suite
[2008.02.05 19:18:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\Složka odesílání Share-to-Web
[2010.02.17 23:39:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Avigilon
[2008.11.08 22:09:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Babylon
[2008.10.08 22:51:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Canon
[2009.01.10 23:47:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Canopus
[2009.10.27 00:50:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\GARMIN
[2009.07.18 17:49:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Graphisoft
[2007.04.29 10:17:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\InterTrust
[2009.11.24 23:57:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\MRP
[2007.10.04 01:12:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\muvee Technologies
[2010.10.26 00:41:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Nokia
[2008.09.15 19:43:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Opera
[2010.12.27 18:22:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\PC Suite
[2010.11.02 21:16:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\proDAD
[2010.02.01 19:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Publish Providers
[2009.03.18 09:39:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\select
[2007.06.24 11:27:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Složka odesílání Share-to-Web
[2007.11.05 12:44:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Software602
[2010.02.01 19:42:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Sony
[2008.11.28 22:59:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Thinstall
[2009.01.02 00:38:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Ulead Systems
[2010.09.24 20:37:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\WD
[2009.03.29 18:17:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\peter1\Data aplikací\PC Suite
[2010.12.27 23:44:56 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{CCA8FD82-364E-43D1-9724-9942B392C758}.job
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"H/PC Connection Agent" = "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" -- [2006.11.13 16:50:20 | 001,289,000 | ---- | M] (Microsoft Corporation)
"Creative Live! Cam Manager" = C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe -- [2007.05.02 10:30:20 | 000,151,552 | ---- | M] (Creative Technology Ltd.)
"PC Suite Tray" = "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray -- [2010.05.14 10:32:30 | 001,479,680 | ---- | M] (Nokia)
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 08:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]
"" =
< c:\windows\*.* /U >
[10 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
[2010.12.27 23:35:10 | 003,998,686 | R--- | M] () -- C:\ComboFix.exe
[2007.11.20 23:34:08 | 005,168,831 | ---- | M] () -- C:\smac20_setup.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.11.16 19:54:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Adobe
[2007.09.16 17:33:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Ahead
[2008.06.16 22:22:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Apple Computer
[2010.11.03 00:18:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\ArcSoft
[2010.02.17 23:39:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Avigilon
[2008.11.08 22:09:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Babylon
[2008.10.08 22:51:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Canon
[2009.01.10 23:47:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Canopus
[2008.10.14 22:42:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Creative
[2010.04.07 22:40:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Download Manager
[2009.10.01 20:33:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\FastStone
[2009.10.27 00:50:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\GARMIN
[2007.07.08 23:42:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Google
[2009.07.18 17:49:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Graphisoft
[2007.05.22 09:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Help
[2007.04.28 14:15:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Identities
[2008.03.23 14:40:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\InstallShield
[2010.02.26 19:14:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Intelli-studio
[2007.04.29 10:17:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\InterTrust
[2008.02.14 00:53:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Lavasoft
[2007.04.29 09:40:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Macromedia
[2010.07.28 00:01:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Malwarebytes
[2009.10.20 22:47:34 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Peter\Data aplikací\Microsoft
[2009.03.04 21:01:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Mozilla
[2009.11.24 23:57:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\MRP
[2007.10.04 01:12:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\muvee Technologies
[2009.04.22 20:40:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Nero
[2010.09.18 17:50:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\NeroDigital(TM)
[2010.10.26 00:41:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Nokia
[2008.09.15 19:43:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Opera
[2010.12.27 18:22:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\PC Suite
[2010.11.02 21:16:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\proDAD
[2010.02.01 19:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Publish Providers
[2009.03.18 09:39:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\select
[2007.06.24 11:27:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Složka odesílání Share-to-Web
[2007.11.05 12:44:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Software602
[2010.02.01 19:42:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Sony
[2009.06.18 13:17:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Sun
[2008.02.12 23:21:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Symantec
[2008.11.28 22:59:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Thinstall
[2009.01.02 00:38:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\Ulead Systems
[2010.09.24 20:37:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\WD
[2009.09.05 14:21:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\WinRAR
[2008.10.09 16:43:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peter\Data aplikací\ZoomBrowser EX
< %APPDATA%\*.exe /s >
[2008.11.23 17:05:04 | 017,732,895 | ---- | M] (Arcsoft ) -- C:\Documents and Settings\Peter\Data aplikací\ArcSoft\Video Impression\2. 0\VI2_Update_2.0.0.22_2.0.0.78_E.exe
[2008.03.28 00:14:16 | 000,003,638 | R--- | M] () -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{33359986-DD66-44E1-A709-D1FA943B014F}\_0A3C0C09C850366E910CA7.exe
[2008.03.28 00:14:16 | 000,003,638 | R--- | M] () -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{33359986-DD66-44E1-A709-D1FA943B014F}\_4337C2151BC3851DD530CB.exe
[2008.03.28 00:14:16 | 000,003,638 | R--- | M] () -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{33359986-DD66-44E1-A709-D1FA943B014F}\_6FEFF9B68218417F98F549.exe
[2010.11.02 21:12:45 | 000,029,926 | R--- | M] () -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{5EB90C06-964F-4195-B83E-BD7E55C88415}\ARPPRODUCTICON.exe
[2010.11.02 21:10:54 | 000,040,960 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_AMCap.exe
[2010.11.02 21:10:54 | 000,049,152 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_Check3D.exe
[2010.11.02 21:10:55 | 000,069,632 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_ContentTransfer.exe
[2010.11.02 21:10:55 | 000,434,176 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_GuidedTour.exe
[2010.11.02 21:10:55 | 000,045,056 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_Help_HH.exe
[2010.11.02 21:10:55 | 000,065,536 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\SC_ReadMe.exe
[2010.11.02 21:10:54 | 000,069,632 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Peter\Data aplikací\Microsoft\Installer\{D041EB9E-890A-4098-8F94-51DA194AC72A}\Studio.exe
< MD5 for: AGP440.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:AGP440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\AGP440.SYS
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\AGP440.SYS
[2008.04.14 00:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\ReinstallBackups\0034\DriverFiles\i386\AGP440.SYS
[2003.04.16 14:00:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:atapi.sys
[2003.04.16 14:00:00 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0026\DriverFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0031\DriverFiles\i386\atapi.sys
[1996.09.17 01:00:00 | 000,014,208 | ---- | M] (Microsoft Corporation) MD5=A5C43F72AA6FCC9080504FCD39465DA4 -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Atapi.sys
< MD5 for: CDROM.SYS >
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2003.04.16 14:00:00 | 000,047,488 | ---- | M] (Microsoft Corporation) MD5=6506E033AD04CFEC9EE56DBEFD1083DD -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2003.04.16 14:00:00 | 000,053,248 | ---- | M] (Microsoft Corporation) MD5=031E7FF41B13B658CAE7D6C98086F76A -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[1996.09.17 01:00:00 | 000,045,776 | ---- | M] (Microsoft Corporation) MD5=DA8297BCC3E0D8F7A42DAA2240AA14DB -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Eventlog.dll
[2003.04.16 14:00:00 | 000,049,152 | ---- | M] (Microsoft Corporation) MD5=E8508E7F865490D8AE71D00C8DF4D227 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2003.04.16 14:00:00 | 001,004,544 | ---- | M] (Microsoft Corporation) MD5=11D80755545CFB5EB9659EE88440EAE2 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007.06.13 15:11:59 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=9B32416BD5988C97B6397CE0B02CAF97 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
< MD5 for: HAL.DLL >
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:hal.dll
[1996.09.17 01:00:00 | 000,049,296 | ---- | M] (Microsoft Corporation) MD5=0C67548274C591CDF7313340CD6ECF9F -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Hal.dll
[2003.04.16 14:00:00 | 000,129,920 | ---- | M] (Microsoft Corporation) MD5=308709E92843DFF3A5CDCA069F6F5C61 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
[2008.04.14 00:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.14 00:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\hal.dll
< MD5 for: CHANGER.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:Changer.sys
[2008.04.14 00:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\changer.sys
< MD5 for: IASTOR.SYS >
[2007.03.21 21:58:56 | 000,304,920 | ---- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 -- C:\Install\Počítače\DUSAN_PC\7.5.0.1017\32bit\iastor.sys
[2007.03.21 21:59:30 | 000,381,720 | ---- | M] (Intel Corporation) MD5=9D7ED4275702E2FC409F2CC563245740 -- C:\Install\Počítače\DUSAN_PC\7.5.0.1017\64bit\IaStor.sys
< MD5 for: ISAPNP.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2008.07.29 00:33:23 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\sp3.cab:isapnp.sys
[2003.04.16 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\dllcache\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\ReinstallBackups\0025\DriverFiles\i386\isapnp.sys
< MD5 for: LSASS.EXE >
[1996.09.17 01:00:00 | 000,006,960 | ---- | M] (Microsoft Corporation) MD5=0A2A65B3165965BB1B7AAA360B03A10A -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Lsass.exe
[2003.04.16 14:00:00 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=32F7074BAC9A5F899CCA9C046C9FA6EB -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2003.04.16 14:00:00 | 000,167,552 | ---- | M] (Microsoft Corporation) MD5=3B350E5A2A5E951453F3993275A4523A -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
[1996.09.17 01:00:00 | 000,089,616 | ---- | M] (Microsoft Corporation) MD5=3EE20762D9FE31A0BD219991B61969CA -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Ndis.sys
< MD5 for: NETLOGON.DLL >
[1996.09.17 01:00:00 | 000,150,064 | ---- | M] (Microsoft Corporation) MD5=A9EE1BBA71C41613F5833F7375D38232 -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
[2003.04.16 14:00:00 | 000,399,360 | ---- | M] (Microsoft Corporation) MD5=CF03E300B5CEEFFEFBE6F67532BD0EF1 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
[2003.04.16 14:00:00 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B2666CAB5E8C8A741D63F18D551A47FB -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2003.04.16 14:00:00 | 000,045,568 | ---- | M] (Microsoft Corporation) MD5=7763D73255AD4046FA999D42EAF22C26 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
[1996.09.17 01:00:00 | 000,037,328 | ---- | M] (Microsoft Corporation) MD5=B473F5311FC0056FDBAE613E2226B42F -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Smss.exe
< MD5 for: SVCHOST.EXE >
[2003.04.16 14:00:00 | 000,012,800 | ---- | M] (Microsoft Corporation) MD5=329945887A0C684C38A4845330BC9100 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2006.04.20 13:51:50 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=1DBF125862891817F374F407626967F4 -- C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
[2003.04.16 14:00:00 | 000,332,928 | ---- | M] (Microsoft Corporation) MD5=244A2F9816BC9B593957281EF577D976 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2007.10.30 18:53:32 | 000,360,832 | ---- | M] (Microsoft Corporation) MD5=64798ECFA43D78C7178375FCDD16D8C8 -- C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[1996.09.17 01:00:00 | 000,123,264 | ---- | M] (Microsoft Corporation) MD5=B0925178A046228F1356D7151F9DA2BC -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Tcpip.sys
[2006.04.20 14:18:35 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[1996.09.17 01:00:00 | 000,015,984 | ---- | M] (Microsoft Corporation) MD5=39E9464F9D0536FB01C1CFFE43CD5EEA -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2003.04.16 14:00:00 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=B26871B5CE92F9D95AE6E62119799EB9 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: VAXSCSI.SYS >
[2009.02.21 17:21:26 | 000,223,128 | ---- | M] (Alcohol Soft Co., Ltd.) MD5=92CEBC2BC7BE2C8D49391B365569F306 -- C:\WINDOWS\system32\drivers\vaxscsi.sys
< MD5 for: VIAMRAID.SYS >
[2007.03.19 16:18:12 | 000,104,064 | ---- | M] (VIA Technologies inc,.ltd) MD5=85E9421C8A99D1291B43B9B59A669AC3 -- C:\WINDOWS\system32\drivers\viamraid.sys
< MD5 for: WINLOGON.EXE >
[1996.09.17 01:00:00 | 000,169,504 | ---- | M] (Microsoft Corporation) MD5=6AE8F0E6FB65E51DFACA46F9E90879D5 -- C:\Install\ACAD1\MECHSOFT PROFI 6.14\SP5NT351\Winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
[2003.04.16 14:00:00 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=FF8857D1AF59071F172C0FAD0FD33E87 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
< MD5 for: WS2_32.DLL >
[2003.04.16 14:00:00 | 000,075,264 | ---- | M] (Microsoft Corporation) MD5=748494B94A871A828C64D1D5C738D2B7 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008.04.14 08:51:50 | 001,384,479 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\msvbvm60.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2008.09.14 22:08:47 | 000,524,288 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2008.09.14 19:57:31 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2008.09.14 22:08:47 | 031,195,136 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2008.09.14 22:08:47 | 008,912,896 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[2008.04.14 08:51:50 | 001,384,479 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\msvbvm60.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< %systemroot%\system32\drivers\*.sys /3 >
[2010.11.29 17:42:06 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys
[2010.11.29 17:42:18 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010.11.02 17:17:02 | 000,040,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ndproxy.sys
[2010.08.26 15:39:50 | 000,357,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\srv.sys
< %systemroot%\system32\*.* /3 >
[2010.11.06 02:25:02 | 000,124,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\advpack.dll
[2010.11.02 22:05:35 | 000,016,832 | ---- | M] () -- C:\WINDOWS\system32\amcompat.tlb
[2010.10.28 15:09:00 | 000,290,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\system32\atmfd.dll
[2010.08.23 18:12:35 | 000,617,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comctl32.dll
[2010.11.06 02:25:02 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\corpol.dll
[2010.11.06 02:25:02 | 000,347,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dxtmsft.dll
[2010.11.06 02:25:02 | 000,214,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dxtrans.dll
[2010.11.06 02:25:03 | 000,133,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\extmgr.dll
[2010.12.17 04:22:32 | 002,399,048 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2010.11.03 14:25:53 | 000,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\html.iec
[2010.11.06 02:25:03 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\icardie.dll
[2010.11.03 14:24:55 | 000,070,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ie4uinit.exe
[2010.11.06 02:25:03 | 000,153,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieakeng.dll
[2010.11.06 02:25:03 | 000,230,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieaksie.dll
[2010.10.18 13:06:11 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieakui.dll
[2010.11.06 02:25:03 | 000,380,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieapfltr.dll
[2010.11.06 02:25:03 | 000,384,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\iedkcs32.dll
[2010.11.06 02:25:03 | 000,078,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieencode.dll
[2010.11.06 02:25:03 | 006,075,904 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieframe.dll
[2010.11.06 02:25:03 | 000,192,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\iepeers.dll
[2010.11.06 02:25:03 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\iernonce.dll
[2010.11.06 02:25:03 | 000,268,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\iertutil.dll
[2010.11.03 14:24:56 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ieudinit.exe
[2010.11.06 02:25:03 | 001,830,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\inetcpl.cpl
[2010.11.18 20:15:47 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\isign32.dll
[2010.11.06 02:25:03 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\jsproxy.dll
[2010.09.18 08:53:37 | 000,954,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc40.dll
[2010.09.18 08:53:37 | 000,953,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc40u.dll
[2010.09.18 08:53:37 | 000,974,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc42.dll
[2010.09.18 12:23:38 | 000,974,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mfc42u.dll
[2010.12.17 04:01:26 | 037,366,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MRT.exe
[2010.11.06 02:25:03 | 000,468,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msfeeds.dll
[2010.11.06 02:25:03 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msfeedsbs.dll
[2010.11.06 02:25:04 | 003,604,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mshtml.dll
[2010.11.06 02:25:04 | 000,478,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mshtmled.dll
[2010.11.06 02:25:04 | 000,193,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msrating.dll
[2010.11.06 02:25:04 | 000,671,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mstime.dll
[2010.11.02 22:05:35 | 000,023,392 | ---- | M] () -- C:\WINDOWS\system32\nscompat.tlb
[2010.11.06 02:25:04 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\occache.dll
[2010.12.11 15:34:11 | 000,104,306 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2010.12.11 15:34:11 | 000,093,370 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2010.12.11 15:34:11 | 000,498,154 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2010.12.11 15:34:11 | 000,501,488 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2010.12.11 15:34:11 | 001,213,216 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2010.11.06 02:25:04 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\pngfilt.dll
[2010.07.27 23:30:36 | 000,000,202 | ---- | M] () -- C:\WINDOWS\system32\PSLOG
[2010.08.16 10:45:05 | 000,590,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rpcrt4.dll
[2010.12.15 18:28:20 | 000,001,200 | ---- | M] () -- C:\WINDOWS\system32\rzeksfsp.dat
[2010.07.27 08:30:31 | 008,466,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shell32.dll
[2010.08.17 15:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spoolsv.exe
[2010.08.27 07:54:10 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\srvsvc.dll
[2010.08.27 10:03:42 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\t2embed.dll
[2010.11.03 15:12:40 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\tzchange.exe
[2010.12.17 04:05:25 | 000,842,762 | ---- | M] () -- C:\WINDOWS\system32\TZLog.log
[2010.11.06 02:25:04 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\url.dll
[2010.11.06 02:25:04 | 001,168,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\urlmon.dll
[2010.11.02 22:05:26 | 000,002,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\w95inf16.dll
[2010.11.02 22:05:26 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\w95inf32.dll
[2010.11.06 02:25:04 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\webcheck.dll
[2010.10.26 15:58:35 | 001,853,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[2010.11.06 02:25:04 | 000,832,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wininet.dll
[2010.08.25 23:36:02 | 010,841,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wmp.dll
[2010.07.27 23:30:56 | 000,012,598 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2010.08.27 03:43:50 | 000,005,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\xpsp4res.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< >
< >
========== Files - Unicode (All) ==========
[2010.10.25 21:55:14 | 000,000,000 | ---D | M](C:\Documents and Settings\Peter\Data aplikac?) -- C:\Documents and Settings\Peter\Data aplikac�
[2010.10.25 21:55:14 | 000,000,000 | ---D | C](C:\Documents and Settings\Peter\Data aplikac?) -- C:\Documents and Settings\Peter\Data aplikac�
========== Alternate Data Streams ==========
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:ECE4A64B
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
< End of report >