a ten druhej:
OTL logfile created on: 22.8.2011 21:44:11 - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = H:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,37 Gb Total Physical Memory | 1,07 Gb Available Physical Memory | 31,88% Memory free
5,16 Gb Paging File | 3,08 Gb Available in Paging File | 59,75% Paging File free
Paging file location(s): G:\pagefile.sys 2020 2034 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,54 Gb Total Space | 2,17 Gb Free Space | 11,11% Space Free | Partition Type: NTFS
Drive D: | 54,98 Gb Total Space | 3,23 Gb Free Space | 5,87% Space Free | Partition Type: NTFS
Drive G: | 2,00 Gb Total Space | 0,03 Gb Free Space | 1,56% Space Free | Partition Type: NTFS
Drive H: | 1002,05 Mb Total Space | 991,24 Mb Free Space | 98,92% Space Free | Partition Type: FAT32
Computer Name: STANDA | User Name: Standysman | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.08.22 21:40:04 | 000,580,096 | ---- | M] (OldTimer Tools) -- H:\OTL.exe
PRC - [2008.04.14 09:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2010.04.11 19:48:06 | 000,327,680 | ---- | M] () -- C:\Program Files\WinRAR\rarlng.dll
MOD - [2010.03.15 12:28:24 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ==========
SRV - [2011.07.15 03:14:44 | 000,741,624 | ---- | M] (Tunngle.net GmbH) [Auto | Stopped] -- C:\Program Files\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2011.04.20 05:56:47 | 000,083,240 | ---- | M] () [Auto | Stopped] -- C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe -- (CLHNServiceForPowerDVD)
SRV - [2011.03.31 15:37:11 | 000,312,616 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe -- (CyberLink PowerDVD 11.0 Service)
SRV - [2011.03.31 15:37:06 | 000,070,952 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe -- (CyberLink PowerDVD 11.0 Monitor Service)
SRV - [2011.03.14 10:59:40 | 000,084,520 | ---- | M] (Software602 a.s.) [Auto | Stopped] -- C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe -- (602XML Updater)
SRV - [2011.03.11 17:21:26 | 000,365,336 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe -- (AVP)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
========== Driver Services (SafeList) ==========
DRV - [2011.05.19 15:27:16 | 002,649,216 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2011.05.14 23:40:28 | 000,229,208 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\VMM.sys -- (vmm)
DRV - [2011.04.20 05:56:48 | 000,071,664 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Stopped] -- C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys -- (ntk_PowerDVD)
DRV - [2011.04.12 11:16:53 | 000,077,296 | ---- | M] (CyberLink Corp.) [2011/05/28 23:57:38] [Kernel | Auto | Stopped] -- C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl -- ({329F96B6-DF1E-4328-BFDA-39EA953C1312})
DRV - [2011.03.11 17:59:25 | 000,218,688 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011.03.11 16:56:06 | 000,475,736 | ---- | M] (Kaspersky Lab) [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2011.02.03 17:31:42 | 000,104,376 | ---- | M] (e2eSoft) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VCam_WDM.sys -- (VCam_WDM)
DRV - [2010.12.18 13:03:56 | 000,021,696 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2010.06.09 18:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\kl2.sys -- (kl2)
DRV - [2010.06.09 18:43:50 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\kl1.sys -- (KL1)
DRV - [2010.05.07 13:06:26 | 000,032,856 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2010.02.11 14:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2009.11.02 21:27:24 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009.09.16 08:02:40 | 000,027,136 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tap0901t.sys -- (tap0901t) TAP-Win32 Adapter V9 (Tunngle)
DRV - [2009.06.18 08:23:46 | 000,065,944 | ---- | M] (SuperSpeed LLC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\SscRdBus.sys -- (SscRdBus) Virtual bus device (SuperSpeed LLC)
DRV - [2009.03.18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2007.11.16 15:58:22 | 000,037,504 | ---- | M] (SuperSpeed LLC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\SscRdCls.sys -- (SscRdCls) RAM Disk (SuperSpeed LLC)
DRV - [2007.01.29 06:20:34 | 000,059,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VMNetSrv.sys -- (VPCNetS2)
DRV - [2006.08.28 14:40:48 | 001,160,320 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2005.09.23 22:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2005.08.05 12:33:56 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2003.01.20 09:37:40 | 000,094,032 | R--- | M] (VM) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbVM31b.sys -- (ZSMC301b)
DRV - [2001.10.24 12:46:48 | 000,097,120 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2001.08.17 21:11:26 | 000,054,271 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bcm42xx5.sys -- (BCM42XX) Broadcom iLine10(tm)
DRV - [1996.04.03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-796845957-343818398-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-796845957-343818398-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems:
KavAntiBanner@Kaspersky.ru:11.0.2.556
FF - prefs.js..extensions.enabledItems:
linkfilter@kaspersky.ru:11.0.2.556
FF - prefs.js..extensions.enabledItems:
engine@conduit.com:3.3.3.2
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:3.3.3.2
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@software602.cz/602XML Filler: C:\Program Files\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Standysman\Local Settings\Data aplikací\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Standysman\Local Settings\Data aplikací\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\dipito.com/DipitoPS: C:\Program Files\Dipito\npdipitops.dll (Libor Sobotik)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\
virtualKeyboard@kaspersky.ru: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\
virtualKeyboard@kaspersky.ru [2011.06.11 23:39:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\
KavAntiBanner@Kaspersky.ru: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\
KavAntiBanner@kaspersky.ru [2011.06.11 23:39:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\
linkfilter@kaspersky.ru: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\
linkfilter@kaspersky.ru [2011.06.11 23:39:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.06.28 22:33:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.07.27 15:09:38 | 000,000,000 | ---D | M]
[2011.03.14 18:41:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Standysman\Data aplikací\Mozilla\Extensions
[2011.07.01 22:08:52 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Standysman\Data aplikací\Mozilla\Firefox\Profiles\4sr6mibw.default\extensions
[2011.05.06 11:01:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Standysman\Data aplikací\Mozilla\Firefox\Profiles\4sr6mibw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.07.01 22:08:52 | 000,000,000 | ---D | M] (Vuze Remote Community Toolbar) -- C:\Documents and Settings\Standysman\Data aplikací\Mozilla\Firefox\Profiles\4sr6mibw.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2011.03.28 15:49:21 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Standysman\Data aplikací\Mozilla\Firefox\Profiles\4sr6mibw.default\extensions\
engine@conduit.com
[2011.06.11 23:39:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.03.15 10:39:21 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\Program Files\Mozilla Firefox\extensions\
KavAntiBanner@kaspersky.ru_bak
[2011.03.15 10:39:16 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\
linkfilter@kaspersky.ru_bak
File not found (No name found) --
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\STANDYSMAN\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\4SR6MIBW.DEFAULT\EXTENSIONS\{BA14329E-9550-4989-B3F2-9732E92D17CC}
[2011.03.14 18:18:05 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011.06.28 22:33:49 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.05.13 10:49:10 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2011.05.13 10:49:10 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2011.03.03 19:52:54 | 000,001,687 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2011.05.13 10:49:10 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011.05.13 10:49:10 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.05.13 10:49:10 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2011.08.22 19:42:56 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [HPUsageTracking] c:\Program Files\HP\HP UT\bin\hppusg.exe ( )
O4 - HKLM..\Run: [Print2PDF Print Monitor] C:\Program Files\Software602\Print2PDF\Print2PDF.exe (Software602)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-796845957-343818398-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Expression\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O15 - HKU\S-1-5-21-796845957-343818398-682003330-1003\..Trusted Domains: dhlive.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-796845957-343818398-682003330-1003\..Trusted Domains: dhlive.net ([]http in Trusted sites)
O15 - HKU\S-1-5-21-796845957-343818398-682003330-1003\..Trusted Domains: homecams.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-796845957-343818398-682003330-1003\..Trusted Domains: inoveo.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-796845957-343818398-682003330-1003\..Trusted Domains: inoveo.com ([]https in Trusted sites)
O16 - DPF: {703C152F-46F5-4C39-8DE5-D113F9BD4031}
http://model.dhlive.net/_component/fmew ... .1.0.7.CAB (FMEWebEncoder Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O31 - SafeBoot: UseAlternatShell - 1
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.09.17 13:54:03 | 000,204,038 | ---- | M] () - C:\auto.jpg -- [ NTFS ]
O32 - AutoRun File - [2011.03.11 15:36:47 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2011.08.22 17:11:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Standysman\Data aplikací\Malwarebytes
[2011.08.22 17:10:33 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.08.22 17:10:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
[2011.08.22 17:10:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.08.22 17:10:17 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.08.22 17:10:17 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.08.22 16:32:46 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.08.22 16:32:45 | 000,000,000 | ---D | C] -- C:\rsit
[2011.08.11 10:40:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Standysman\Local Settings\Data aplikací\PCHealth
[2011.08.10 13:31:05 | 000,139,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011.08.10 13:30:49 | 000,010,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011.08.07 23:02:43 | 000,000,000 | ---D | C] -- C:\Program Files\SuperSpeed
[2011.08.07 23:02:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\SuperSpeed
[2011.08.04 15:32:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Standysman\Data aplikací\Software602
[2011.08.04 15:27:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Standysman\Data aplikací\pdf995
[2011.08.04 15:20:50 | 000,249,856 | ---- | C] (TODO: <Company name>) -- C:\WINDOWS\System32\pdfmona.dll
[2011.08.04 15:20:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\pdf995
[2011.08.04 15:20:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Software995
[2011.08.04 15:20:48 | 000,000,000 | ---D | C] -- C:\Program Files\pdf995
[2011.07.27 15:16:12 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Standysman\Dokumenty\My Web Sites
[2011.07.27 15:10:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Microsoft Expression
[2011.07.27 15:09:28 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2011.07.27 15:09:00 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2011.07.27 15:07:04 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Expression
========== Files - Modified Within 30 Days ==========
[2011.08.22 19:53:11 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.08.22 19:52:46 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.08.22 17:10:33 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.08.22 16:37:05 | 000,000,360 | RHS- | M] () -- C:\boot.ini
[2011.08.22 13:11:08 | 000,000,968 | -HS- | M] () -- C:\WINDOWS\KLIF.spi
[2011.08.22 11:02:46 | 000,035,593 | ---- | M] () -- C:\fakturatelefon.pdf
[2011.08.22 10:33:32 | 000,884,266 | ---- | M] () -- C:\smlouva0001.pdf
[2011.08.18 14:01:33 | 000,141,106 | ---- | M] () -- C:\Informace o parcele.pdf
[2011.08.18 13:00:33 | 000,026,624 | ---- | M] () -- C:\Documents and Settings\Standysman\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.08.15 17:57:35 | 001,201,067 | ---- | M] () -- C:\skenovat0034.pdf
[2011.08.15 11:34:21 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011.08.14 23:27:00 | 000,035,545 | ---- | M] () -- C:\Documents and Settings\Standysman\Dokumenty\Faktura_1100165081.pdf
[2011.08.11 12:55:50 | 000,343,681 | ---- | M] () -- C:\Invoice 205536.pdf
[2011.08.11 11:58:07 | 000,049,290 | ---- | M] () -- C:\Faktura_110100007.pdf
[2011.08.11 10:34:33 | 000,445,510 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.08.11 10:34:33 | 000,443,474 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2011.08.11 10:34:33 | 000,085,130 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2011.08.11 10:34:33 | 000,073,386 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.08.11 09:50:15 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011.08.07 23:17:31 | 013,320,192 | -H-- | M] () -- C:\SsRd0001.cif
[2011.08.07 23:02:43 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\RamDisk Plus.lnk
[2011.08.07 19:37:27 | 000,467,024 | ---- | M] () -- C:\formularcp.pdf
[2011.08.04 15:31:20 | 000,065,135 | ---- | M] () -- C:\Documents and Settings\Standysman\Dokumenty\Create PDF.pdf
[2011.08.04 15:31:18 | 000,000,059 | ---- | M] () -- C:\WINDOWS\wpd99.drv
[2011.08.04 15:29:52 | 000,249,856 | ---- | M] (TODO: <Company name>) -- C:\WINDOWS\System32\pdfmona.dll
[2011.08.04 15:29:52 | 000,051,716 | ---- | M] () -- C:\WINDOWS\System32\pdf995mon.dll
[2011.08.04 15:27:16 | 000,000,028 | ---- | M] () -- C:\WINDOWS\pdf995.ini
[2011.08.01 19:16:27 | 000,049,586 | ---- | M] () -- C:\Documents and Settings\Standysman\Dokumenty\Smlouva_zpr_8_Stará.rtf
[2011.07.31 20:46:43 | 000,056,355 | ---- | M] () -- C:\Faktura_110100006.pdf
[2011.07.29 14:57:46 | 000,000,132 | ---- | M] () -- C:\Documents and Settings\Standysman\Data aplikací\Adobe Formát PNG CS5 – předvolby
[2011.07.28 10:04:27 | 003,694,664 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.07.25 17:08:54 | 005,969,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
========== Files Created - No Company Name ==========
[2011.08.22 17:10:33 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.08.22 13:05:40 | 000,000,968 | -HS- | C] () -- C:\WINDOWS\KLIF.spi
[2011.08.22 11:02:46 | 000,035,593 | ---- | C] () -- C:\fakturatelefon.pdf
[2011.08.22 10:33:11 | 000,884,266 | ---- | C] () -- C:\smlouva0001.pdf
[2011.08.18 14:01:32 | 000,141,106 | ---- | C] () -- C:\Informace o parcele.pdf
[2011.08.15 17:56:55 | 001,201,067 | ---- | C] () -- C:\skenovat0034.pdf
[2011.08.14 23:27:00 | 000,035,545 | ---- | C] () -- C:\Documents and Settings\Standysman\Dokumenty\Faktura_1100165081.pdf
[2011.08.11 12:55:49 | 000,343,681 | ---- | C] () -- C:\Invoice 205536.pdf
[2011.08.11 11:58:06 | 000,049,290 | ---- | C] () -- C:\Faktura_110100007.pdf
[2011.08.07 23:17:28 | 013,320,192 | -H-- | C] () -- C:\SsRd0001.cif
[2011.08.07 23:02:43 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\RamDisk Plus.lnk
[2011.08.07 19:37:22 | 000,467,024 | ---- | C] () -- C:\formularcp.pdf
[2011.08.04 15:31:18 | 000,065,135 | ---- | C] () -- C:\Documents and Settings\Standysman\Dokumenty\Create PDF.pdf
[2011.08.04 15:27:16 | 000,000,028 | ---- | C] () -- C:\WINDOWS\pdf995.ini
[2011.08.04 15:20:50 | 000,051,716 | ---- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2011.08.04 15:20:50 | 000,000,059 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2011.08.01 19:16:27 | 000,049,586 | ---- | C] () -- C:\Documents and Settings\Standysman\Dokumenty\Smlouva_zpr_8_Stará.rtf
[2011.07.31 20:46:43 | 000,056,355 | ---- | C] () -- C:\Faktura_110100006.pdf
[2011.07.29 14:57:46 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Standysman\Data aplikací\Adobe Formát PNG CS5 – předvolby
[2011.07.21 23:01:09 | 000,000,045 | ---- | C] () -- C:\WINDOWS\Twacker.ini
[2011.07.21 23:01:02 | 000,000,046 | ---- | C] () -- C:\WINDOWS\lifeview.ini
[2011.05.27 15:10:30 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.04.18 18:08:02 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Standysman\Data aplikací\$_hpcst$.hpc
[2011.04.11 02:40:06 | 000,304,712 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2011.04.09 22:15:04 | 000,002,047 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2011.04.09 22:15:02 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2011.03.18 21:07:38 | 000,000,978 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2011.03.15 13:02:13 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\Standysman\Local Settings\Data aplikací\fusioncache.dat
[2011.03.15 12:53:40 | 000,000,139 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2011.03.15 12:52:59 | 000,000,719 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2011.03.15 12:50:51 | 000,120,160 | ---- | C] () -- C:\WINDOWS\hppins06.dat
[2011.03.15 12:50:51 | 000,001,300 | ---- | C] () -- C:\WINDOWS\hppmdl06.dat
[2011.03.14 18:40:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011.03.13 14:39:40 | 000,000,056 | ---- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2011.03.11 16:57:24 | 000,115,369 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
[2011.03.11 16:57:24 | 000,097,859 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
[2011.03.11 16:54:33 | 000,026,624 | ---- | C] () -- C:\Documents and Settings\Standysman\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.03.11 16:11:35 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011.03.11 16:10:19 | 003,694,664 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.03.11 15:55:22 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2011.03.11 15:39:08 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011.03.11 15:33:42 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009.09.09 20:01:40 | 000,027,675 | ---- | C] () -- C:\WINDOWS\System32\drivers\klopp.dat
[2006.04.03 18:22:18 | 000,000,668 | ---- | C] () -- C:\WINDOWS\System32\hppapr05.dat
[2005.10.14 12:56:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 12:56:50 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 12:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 11:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 11:56:50 | 000,778,240 | ---- | C] () -- C:\WINDOWS\System32\DivXsm.exe
[2005.10.14 11:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005.10.14 11:56:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 11:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 11:56:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2005.10.14 11:56:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\MMSwitch.dll
[2005.10.14 11:56:48 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\MMAVILNG.exe
[2004.08.17 15:58:58 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004.08.02 14:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001.10.25 16:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001.10.25 16:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001.10.25 16:00:00 | 000,445,510 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001.10.25 16:00:00 | 000,443,474 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2001.10.25 16:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001.10.25 16:00:00 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2001.10.25 16:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001.10.25 16:00:00 | 000,085,130 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2001.10.25 16:00:00 | 000,073,386 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001.10.25 16:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001.10.25 16:00:00 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2001.10.25 16:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001.10.25 16:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.10.25 16:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001.07.07 04:00:00 | 000,003,165 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI
[1996.04.03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2011.03.11 17:32:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2011.05.28 23:55:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\install_clap
[2011.08.04 15:31:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\pdf995
[2011.05.29 00:08:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PDVD
[2011.04.10 21:42:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle
[2011.03.28 18:15:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle Studio Ultimate Collection
[2011.04.05 15:16:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\regid.1986-12.com.adobe
[2011.06.25 17:55:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2011.03.24 13:11:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\STORMWARE
[2011.05.28 23:55:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2011.07.21 17:22:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Tunngle
[2011.03.11 18:06:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\{3155EF3F-3778-4C4C-B0F3-3E48423B8965}
[2011.05.01 16:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\602Installer
[2011.05.01 16:19:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\602XML
[2011.06.06 14:51:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Azureus
[2011.06.12 20:23:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer
[2011.06.12 20:01:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer Pro
[2011.03.11 18:09:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\DAEMON Tools Lite
[2011.04.07 11:40:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Dipito
[2011.03.11 19:23:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\IrfanView
[2011.08.04 15:27:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\pdf995
[2011.06.25 17:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Publish Providers
[2011.03.28 15:56:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Raptr
[2011.08.04 15:32:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Software602
[2011.06.27 18:11:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Sony
[2011.07.02 20:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Sony Creative Software
[2011.03.28 00:51:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\STORMWARE
[2011.08.05 00:01:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Tunngle
[2011.08.22 13:07:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\uTorrent
[2011.03.14 18:18:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\VitySoft
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 09:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
"H/PC Connection Agent" = "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" -- [2006.11.13 16:50:20 | 001,289,000 | ---- | M] (Microsoft Corporation)
"Skype" = "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized -- [2011.06.15 15:02:58 | 015,141,768 | R--- | M] (Skype Technologies S.A.)
< c:\windows\*.* /U >
< %SYSTEMDRIVE%\*.exe >
[2008.04.08 12:46:45 | 000,055,808 | ---- | M] (Microsoft Corporation) -- C:\devcon.exe
[2007.02.06 11:07:10 | 000,521,128 | ---- | M] (Microsoft Corporation) -- C:\DPINST.exe
[2008.05.02 11:11:10 | 000,364,721 | ---- | M] () -- C:\DPsFnshr.exe
[2008.05.02 11:11:14 | 000,282,725 | ---- | M] () -- C:\DSPdsblr.exe
[2008.04.08 12:46:45 | 000,020,992 | ---- | M] () -- C:\makePNF.exe
[2008.04.08 12:46:45 | 000,137,728 | ---- | M] () -- C:\mute.exe
[2008.05.02 11:11:17 | 000,235,131 | ---- | M] () -- C:\pmtimer.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2011.05.01 16:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\602Installer
[2011.05.01 16:19:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\602XML
[2011.04.06 16:09:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Adobe
[2011.05.27 20:00:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Apple Computer
[2011.06.06 14:51:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Azureus
[2011.06.12 20:23:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer
[2011.06.12 20:01:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer Pro
[2011.05.29 00:05:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\CyberLink
[2011.03.11 18:09:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\DAEMON Tools Lite
[2011.04.07 11:40:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Dipito
[2011.03.23 01:08:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Google
[2011.03.18 00:49:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\GRETECH
[2011.03.15 13:10:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\HP
[2011.04.13 18:43:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\HpUpdate
[2011.03.11 15:41:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Identities
[2011.03.11 15:54:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\InstallShield
[2011.03.11 19:23:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\IrfanView
[2011.03.11 18:02:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Macromedia
[2011.08.22 17:11:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Malwarebytes
[2011.07.29 15:20:20 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Standysman\Data aplikací\Microsoft
[2011.03.14 18:41:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Mozilla
[2011.05.10 16:04:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\NCH Software
[2011.08.04 15:27:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\pdf995
[2011.06.25 17:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Publish Providers
[2011.03.28 15:56:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Raptr
[2011.08.22 13:13:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Skype
[2011.07.09 20:12:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\skypePM
[2011.08.04 15:32:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Software602
[2011.06.27 18:11:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Sony
[2011.07.02 20:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Sony Creative Software
[2011.03.28 00:51:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\STORMWARE
[2011.03.14 18:17:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Sun
[2011.08.05 00:01:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\Tunngle
[2011.08.22 13:07:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\uTorrent
[2011.03.14 18:18:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\VitySoft
[2011.03.11 19:03:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Standysman\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
[2011.03.28 15:50:17 | 000,310,208 | ---- | M] (Georgia Institute of Technology) -- C:\Documents and Settings\Standysman\Data aplikací\Azureus\plugins\mlab\ShaperProbeC.exe
[2009.08.11 21:21:26 | 000,087,552 | ---- | M] () -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer\AC3 Filter\ac3config.exe
[2009.08.11 21:21:30 | 000,090,112 | ---- | M] () -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer\AC3 Filter\spdif_test.exe
[2010.03.22 14:52:04 | 000,697,690 | ---- | M] () -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer\AC3 Filter\unins000.exe
[2010.02.23 17:01:52 | 001,185,871 | ---- | M] () -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer\FFDShow\unins000.exe
[2010.08.14 10:42:54 | 000,113,152 | ---- | M] () -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer\Haali media splitter\dsmux.exe
[2010.08.14 10:45:10 | 000,358,400 | ---- | M] () -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer\Haali media splitter\gdsmux.exe
[2010.08.14 10:42:06 | 000,137,728 | ---- | M] () -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer\Haali media splitter\mkv2vfr.exe
[2010.09.30 15:30:22 | 000,042,305 | ---- | M] () -- C:\Documents and Settings\Standysman\Data aplikací\BSplayer\Haali media splitter\uninstall.exe
[2011.04.23 16:53:45 | 000,057,344 | R--- | M] (Macrovision Corporation) -- C:\Documents and Settings\Standysman\Data aplikací\Microsoft\Installer\{7F362F06-A9A3-440F-8B19-6A01A72723C4}\ARPPRODUCTICON.exe
< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\agp440.sys
[2008.04.14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 09:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\autochk.exe
[2008.04.14 09:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe
< MD5 for: CDROM.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.14 01:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cdrom.sys
[2008.04.14 01:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2004.08.03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 09:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cryptsvc.dll
[2008.04.14 09:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 09:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\eventlog.dll
[2008.04.14 09:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 09:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 09:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: HAL.DLL >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.14 01:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.14 01:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\hal.dll
[2004.08.03 22:59:14 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.14 01:11:00 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\changer.sys
< MD5 for: ISAPNP.SYS >
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 10:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2001.10.25 16:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2008.04.14 08:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\isapnp.sys
[2008.04.14 08:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 09:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\lsass.exe
[2008.04.14 09:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.14 01:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ndis.sys
[2008.04.14 01:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
< MD5 for: NETLOGON.DLL >
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 20:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 09:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\netlogon.dll
[2008.04.14 09:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 09:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\scecli.dll
[2008.04.14 09:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2008.04.14 09:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\smss.exe
[2008.04.14 09:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 09:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\svchost.exe
[2008.04.14 09:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2008.04.14 01:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.14 01:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 09:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\userinit.exe
[2008.04.14 09:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 09:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\winlogon.exe
[2008.04.14 09:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 09:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ws2_32.dll
[2008.04.14 09:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\system32\*k.dll >
[2009.03.08 05:32:48 | 000,128,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\advpack.dll
[2001.10.25 16:00:00 | 000,073,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\csseqchk.dll
[2008.04.14 09:51:40 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\d3d8thk.dll
[2001.10.25 16:00:00 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dpnwsock.dll
[2001.10.25 16:00:00 | 000,042,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dpwsock.dll
[2008.04.14 09:51:44 | 000,072,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\hlink.dll
[2008.04.14 09:51:44 | 000,065,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\icwphbk.dll
[2001.10.25 16:00:00 | 000,005,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\kbduk.dll
[2001.10.25 16:00:00 | 000,089,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\langwrbk.dll
[2008.04.14 09:51:46 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\lpk.dll
[2001.10.25 16:00:00 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mag_hook.dll
[2008.04.14 09:51:46 | 000,086,016 | ---- | M] (Conexant) -- C:\WINDOWS\system32\mdmxsdk.dll
[2008.04.14 09:51:50 | 000,275,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mstask.dll
[2008.06.20 18:04:19 | 000,247,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mswsock.dll
[2001.10.25 16:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\narrhook.dll
[2008.04.14 09:51:54 | 000,026,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\perfdisk.dll
[2008.04.14 09:51:56 | 000,286,792 | ---- | M] (Smart Link) -- C:\WINDOWS\system32\slextspk.dll
[2001.10.25 16:00:00 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svcpack.dll
[2001.10.25 16:00:00 | 000,018,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\vga64k.dll
[2009.03.08 05:34:48 | 000,236,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\webcheck.dll
[2001.10.25 16:00:00 | 000,002,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winsock.dll
[2009.01.30 21:34:08 | 000,535,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wmdrmsdk.dll
< %systemroot%\System32\config\*.sav >
[2011.03.11 16:09:18 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2011.03.11 16:09:18 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2011.03.11 16:09:18 | 000,479,232 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2011.08.22 19:53:11 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< *crack* /s >
< *keygen* /s >
< End of report >