Stránka 2 z 2

Re: Nějaká infekce, prosím o kontrolu.

Napsal: 20 lis 2011 22:38
od rokony
OTL logfile created on: 20.11.2011 22:23:23 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = G:\Nové nástroje
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,97 Gb Total Physical Memory | 1,49 Gb Available Physical Memory | 75,61% Memory free
3,82 Gb Paging File | 3,26 Gb Available in Paging File | 85,35% Paging File free
Paging file location(s): E:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = E: | %SystemRoot% = E:\WINDOWS | %ProgramFiles% = E:\Program Files
Drive C: | 18,65 Gb Total Space | 3,34 Gb Free Space | 17,93% Space Free | Partition Type: NTFS
Drive E: | 149,04 Gb Total Space | 71,94 Gb Free Space | 48,27% Space Free | Partition Type: NTFS
Drive G: | 963,70 Mb Total Space | 101,83 Mb Free Space | 10,57% Space Free | Partition Type: FAT

Computer Name: PILA | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Processes (SafeList) ==========

PRC - [2011.11.20 22:18:24 | 000,584,192 | ---- | M] (OldTimer Tools) -- G:\Nové nástroje\OTL.exe
PRC - [2011.10.24 20:29:16 | 002,415,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2011.10.20 12:58:42 | 002,497,352 | ---- | M] (COMODO) -- E:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2011.10.18 06:14:54 | 001,229,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011.10.12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011.10.10 06:23:34 | 000,973,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2011.10.07 18:47:14 | 001,883,328 | ---- | M] (COMODO) -- E:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2011.09.08 19:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011.08.15 05:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011.08.02 05:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011.02.18 10:47:12 | 000,079,192 | ---- | M] (Research In Motion Limited) -- E:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
PRC - [2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\explorer.exe
PRC - [2007.01.03 19:38:44 | 000,207,680 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\GUI.exe
PRC - [2005.10.11 14:03:26 | 000,204,800 | ---- | M] (National Instruments, Inc.) -- E:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
PRC - [2005.10.11 14:00:24 | 000,053,248 | ---- | M] (National Instruments, Inc.) -- E:\WINDOWS\system32\lktsrv.exe
PRC - [2005.10.11 14:00:22 | 000,045,056 | ---- | M] (National Instruments, Inc.) -- E:\WINDOWS\system32\lkads.exe
PRC - [2005.10.10 13:08:32 | 000,049,152 | ---- | M] (National Instruments Corp.) -- E:\WINDOWS\system32\nisvcloc.exe
PRC - [2005.08.25 13:43:14 | 000,688,190 | ---- | M] (National Instruments, Inc.) -- E:\WINDOWS\system32\lkcitdl.exe


========== Modules (No Company Name) ==========

MOD - [2011.08.26 10:03:38 | 011,800,576 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\1fb5d8788c9a9a7f44e2d0fa19c62729\System.Web.ni.dll
MOD - [2011.08.26 10:02:44 | 000,971,264 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\48f8b951a598647dd309ca2031807a5d\System.Configuration.ni.dll
MOD - [2011.08.26 10:02:18 | 000,025,600 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d9228d58804dfd75fd92a4d12ffac8af\Accessibility.ni.dll
MOD - [2011.08.26 09:47:00 | 005,450,752 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\f354057a5b4fad4c399da28449ba0d92\System.Xml.ni.dll
MOD - [2011.08.26 09:46:56 | 012,430,848 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\29d16d2f164fe2263539789ecd0d9d4f\System.Windows.Forms.ni.dll
MOD - [2011.08.26 09:46:48 | 001,587,200 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\a59b17e6040e3f6286a2227dfdb17096\System.Drawing.ni.dll
MOD - [2011.08.26 09:45:55 | 007,950,848 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\f6a9a002526806f3a5b745cf5c407cae\System.ni.dll
MOD - [2011.08.26 09:45:50 | 011,490,816 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll
MOD - [2011.08.21 17:47:33 | 000,303,104 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2010.09.18 19:02:18 | 000,364,544 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3512.36804__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:18 | 000,204,800 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3512.36823__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:18 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3512.36818__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:18 | 000,011,776 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Runtime\2.0.3512.36907__90ba9c70f846762e\CLI.Caste.HydraVision.Runtime.dll
MOD - [2010.09.18 19:02:18 | 000,008,704 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Shared\2.0.3512.36906__90ba9c70f846762e\CLI.Caste.HydraVision.Shared.dll
MOD - [2010.09.18 19:02:18 | 000,007,680 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Wizard\2.0.3512.36910__90ba9c70f846762e\CLI.Caste.HydraVision.Wizard.dll
MOD - [2010.09.18 19:02:18 | 000,007,680 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.HydraVision.Dashboard\2.0.3512.36906__90ba9c70f846762e\CLI.Caste.HydraVision.Dashboard.dll
MOD - [2010.09.18 19:02:17 | 001,736,704 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3512.36822__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:17 | 000,692,224 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3512.36866__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:17 | 000,491,520 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3512.36894__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:17 | 000,364,544 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3512.36880__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:17 | 000,077,824 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3512.36875__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:17 | 000,065,536 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3512.36856__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:17 | 000,036,864 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3512.36847__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:17 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3512.36812__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:16 | 000,331,776 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3512.36861__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:16 | 000,094,208 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3512.36862__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:16 | 000,073,728 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3512.36812__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:16 | 000,061,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dashboard\2.0.3512.36823__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:16 | 000,061,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3512.36861__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:16 | 000,045,056 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3512.36895__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:16 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runtime\2.0.3512.36822__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:15 | 000,643,072 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Dashboard\2.0.3512.36905__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:15 | 000,077,824 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Runtime\2.0.3512.36905__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:14 | 000,798,720 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3512.36849__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:14 | 000,409,600 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3512.36869__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2010.09.18 19:02:14 | 000,196,608 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3512.36824__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:14 | 000,094,208 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3512.36854__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:14 | 000,090,112 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3512.36848__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:13 | 000,749,568 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3512.36876__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:13 | 000,573,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3512.36824__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:13 | 000,409,600 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3512.36813__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:13 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3512.36854__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:13 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3512.36828__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:12 | 000,630,784 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3512.36857__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:12 | 000,393,216 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3512.36848__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:12 | 000,360,448 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3512.36843__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:12 | 000,270,336 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2010.09.18 19:02:12 | 000,061,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3512.36847__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:12 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3512.36848__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:12 | 000,032,768 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3512.36855__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2010.09.18 19:02:11 | 000,032,768 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.3498.37515__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2010.09.18 19:02:11 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3498.37517__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2010.09.18 19:02:11 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3498.37534__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3498.37533__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.3498.37551__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3498.37558__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3498.37615__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3498.37612__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3498.37554__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3498.37610__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2010.09.18 19:02:11 | 000,007,168 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2010.09.18 19:02:10 | 000,135,168 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3498.37541__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,094,208 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.3498.37518__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2010.09.18 19:02:10 | 000,061,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Shared\2.0.3498.37614__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,053,248 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3498.37582__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,045,056 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2010.09.18 19:02:10 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3498.37603__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3498.37674__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2010.09.18 19:02:10 | 000,024,576 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3498.37536__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0703\2.0.2651.18802__90ba9c70f846762e\DEM.Graphics.I0703.dll
MOD - [2010.09.18 19:02:10 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3498.37540__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3498.37526__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shared\2.0.3498.37575__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.3498.37571__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3498.37544__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3498.37574__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2010.09.18 19:02:10 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3498.37547__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,651,264 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\ResourceManagement.Foundation.Implementation\2.0.3512.36919__90ba9c70f846762e\ResourceManagement.Foundation.Implementation.dll
MOD - [2010.09.18 19:02:09 | 000,065,536 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3498.37583__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,057,344 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3498.37579__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,053,248 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3498.37578__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,049,152 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3498.37577__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,045,056 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3512.36900__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2010.09.18 19:02:09 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3498.37582__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,032,768 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3498.37557__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3498.37575__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3498.37572__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,028,672 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3498.37552__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,024,576 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3498.37580__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3498.37555__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.3498.37553__90ba9c70f846762e\APM.Foundation.dll
MOD - [2010.09.18 19:02:09 | 000,016,384 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3498.37535__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2010.09.18 19:02:09 | 000,014,848 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll
MOD - [2010.09.18 19:02:09 | 000,013,312 | ---- | M] () -- E:\WINDOWS\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll
MOD - [2010.09.18 19:02:09 | 000,007,168 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3512.36801__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
MOD - [2010.09.18 19:02:08 | 000,552,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3512.36883__90ba9c70f846762e\CLI.Component.Systemtray.dll
MOD - [2010.09.18 19:02:08 | 000,405,504 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3512.36817__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2010.09.18 19:02:08 | 000,106,496 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3512.36889__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2010.09.18 19:02:08 | 000,065,536 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3512.36887__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2010.09.18 19:02:08 | 000,057,344 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3512.36803__90ba9c70f846762e\CLI.Component.SkinFactory.dll
MOD - [2010.09.18 19:02:08 | 000,057,344 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3512.36801__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2010.09.18 19:02:08 | 000,045,056 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3498.37546__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2010.09.18 19:02:08 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3498.37522__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2010.09.18 19:02:08 | 000,036,864 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3498.37528__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2010.09.18 19:02:08 | 000,024,576 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3498.37548__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2010.09.18 19:02:08 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3498.37531__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll
MOD - [2010.09.18 19:02:08 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3498.37547__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2010.09.18 19:02:07 | 001,212,416 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3512.36808__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2010.09.18 19:02:07 | 000,040,960 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3498.37538__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2010.09.18 19:02:07 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3498.37549__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2010.09.18 19:02:07 | 000,020,480 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3498.37585__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2010.09.18 19:02:06 | 000,061,440 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\APM.Server\2.0.3512.36800__90ba9c70f846762e\APM.Server.dll
MOD - [2010.09.18 19:02:06 | 000,045,056 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.3512.36801__90ba9c70f846762e\AEM.Server.dll
MOD - [2010.09.18 19:02:06 | 000,032,768 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2010.09.18 19:02:06 | 000,019,456 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3512.36889__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2010.07.07 22:52:44 | 000,555,624 | ---- | M] () -- E:\Program Files\NVIDIA Corporation\nView\nvShell.dll
MOD - [2009.08.28 15:08:26 | 000,016,384 | R--- | M] () -- E:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
MOD - [2008.10.11 21:18:46 | 000,319,488 | ---- | M] () -- E:\Program Files\WinRAR\rarlng.dll
MOD - [2008.09.16 19:18:06 | 000,132,608 | ---- | M] () -- E:\Program Files\WinRAR\RarExt.dll
MOD - [2007.09.05 13:39:02 | 000,073,728 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\work.dll
MOD - [2007.08.21 10:49:36 | 000,125,504 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\MarkFunDrv.dll
MOD - [2007.08.15 14:34:22 | 000,446,464 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\Normal.dll
MOD - [2007.08.08 13:42:06 | 000,180,224 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\GVTunner.dll
MOD - [2007.05.14 18:47:24 | 000,073,728 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\W83781D.DLL
MOD - [2007.01.05 12:23:20 | 000,151,552 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\etiv.dll
MOD - [2007.01.03 19:38:44 | 000,207,680 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\GUI.exe
MOD - [2006.10.04 14:25:42 | 000,651,334 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\aticlocklib.dll
MOD - [2003.11.19 08:18:52 | 000,028,672 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\mibdata.dll
MOD - [2003.02.14 13:11:46 | 000,102,400 | ---- | M] () -- E:\Program Files\GIGABYTE\ET5Pro\Sound.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (wuauserv)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011.11.18 14:22:06 | 000,428,928 | ---- | M] (Sysinternals - www.sysinternals.com) [On_Demand | Stopped] -- E:\Documents and Settings\Paul\Local Settings\temp\ZWGAPDV.exe -- (ZWGAPDV)
SRV - [2011.10.12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- E:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011.10.07 18:47:14 | 001,883,328 | ---- | M] (COMODO) [Auto | Running] -- E:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011.08.02 05:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- E:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2008.05.05 23:25:46 | 000,165,416 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- E:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe -- (GameConsoleService)
SRV - [2005.10.11 14:03:26 | 000,204,800 | ---- | M] (National Instruments, Inc.) [Auto | Running] -- E:\Program Files\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService)
SRV - [2005.10.11 14:00:24 | 000,053,248 | ---- | M] (National Instruments, Inc.) [Auto | Running] -- E:\WINDOWS\system32\lktsrv.exe -- (lkTimeSync)
SRV - [2005.10.11 14:00:22 | 000,045,056 | ---- | M] (National Instruments, Inc.) [Auto | Running] -- E:\WINDOWS\system32\lkads.exe -- (lkClassAds)
SRV - [2005.10.10 13:08:32 | 000,049,152 | ---- | M] (National Instruments Corp.) [Auto | Running] -- E:\WINDOWS\System32\nisvcloc.exe -- (niSvcLoc)
SRV - [2005.08.25 13:43:14 | 000,688,190 | ---- | M] (National Instruments, Inc.) [Auto | Running] -- E:\WINDOWS\system32\lkcitdl.exe -- (LkCitadelServer)


========== Driver Services (SafeList) ==========

DRV - [2011.11.20 22:05:55 | 000,024,944 | ---- | M] () [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\GVTDrv.sys -- (GVTDrv)
DRV - [2011.10.07 18:48:04 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- E:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2011.10.07 18:48:02 | 000,492,768 | ---- | M] (COMODO) [File_System | System | Running] -- E:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2011.10.07 18:48:02 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- E:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2011.10.07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- E:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011.10.04 06:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011.09.13 05:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- E:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011.08.08 05:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- E:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011.07.11 00:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- E:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011.07.11 00:14:28 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011.07.11 00:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- E:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011.07.11 00:14:26 | 000,134,608 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010.09.18 09:35:04 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- E:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2010.09.18 09:35:04 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- E:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2010.09.10 18:26:37 | 000,016,512 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2010.07.28 11:27:36 | 006,108,776 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009.11.18 00:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009.11.18 00:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009.08.14 05:27:00 | 004,485,632 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2007.08.21 10:49:28 | 000,017,912 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- E:\Program Files\GIGABYTE\ET5Pro\MARKFUN.W32 -- (MarkFun_NT)
DRV - [2006.11.24 13:47:50 | 000,040,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ET5Drv.sys -- (ET5Drv)
DRV - [2006.07.19 11:25:10 | 000,012,048 | R--- | M] (ATI Technologies Inc.) [Kernel | Disabled | Running] -- E:\Program Files\GIGABYTE\ET5Pro\atidgllk.sys -- (atidgllk)
DRV - [2005.06.10 09:01:00 | 000,007,140 | ---- | M] () [Kernel | Auto | Running] -- E:\WINDOWS\System32\drivers\cvintdrv.sys -- (cvintdrv)
DRV - [2004.10.24 08:11:00 | 000,028,800 | ---- | M] (Deon van der Westhuysen) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\PPortJoy.sys -- (PPortJoystick)
DRV - [2004.10.24 08:11:00 | 000,013,952 | ---- | M] (Deon van der Westhuysen) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\PPJoyBus.sys -- (PPJoyBus)
DRV - [2003.10.31 09:37:12 | 000,027,631 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\system32\drivers\bcbus.sys -- (bcbus)
DRV - [2003.10.31 07:51:22 | 000,031,639 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\bc_tfish.sys -- (BC_TFISH)
DRV - [2003.10.31 07:49:42 | 000,043,101 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\bc_rijn.sys -- (BC_RIJN)
DRV - [2003.10.31 07:46:16 | 000,014,013 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\bc_gost.sys -- (BC_Gost)
DRV - [2003.10.31 07:19:02 | 000,017,991 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\bc_des.sys -- (BC_DES)
DRV - [2003.10.31 07:17:00 | 000,012,747 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\bc_bfish.sys -- (BC_BFish)
DRV - [2003.04.18 10:41:50 | 000,008,448 | ---- | M] (Jetico, Inc.) [Kernel | System | Running] -- E:\WINDOWS\System32\drivers\fsh.sys -- (fsh)
DRV - [2002.09.11 07:09:48 | 000,083,456 | ---- | M] (Jetico, Inc.) [Kernel | Disabled | Stopped] -- E:\WINDOWS\System32\drivers\BCSwap.sys -- (BCSWAP)
DRV - [2002.09.11 07:08:52 | 000,003,328 | ---- | M] (Jetico, Inc.) [Kernel | On_Demand | Running] -- E:\WINDOWS\System32\drivers\moh.sys -- (moh)
DRV - [2002.09.11 07:01:16 | 000,006,272 | ---- | M] (Jetico, Inc.) [Kernel | On_Demand | Running] -- E:\WINDOWS\System32\drivers\mhk.sys -- (mhk)
DRV - [2001.01.08 10:53:24 | 000,015,576 | R--- | M] () [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\usbbc.sys -- (Wdm1)
DRV - [1998.04.02 10:36:14 | 000,025,824 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- E:\WINDOWS\System32\drivers\A4SII300.SYS -- (A4SII300)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2025429265-261478967-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKU\S-1-5-21-2025429265-261478967-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: E:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: e:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: E:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: E:\Program Files\AVG\AVG2012\Firefox4\ [2011.11.06 18:08:22 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2011.11.02 16:30:57 | 000,437,882 | R--- | M]) - E:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 15062 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKU\S-1-5-21-2025429265-261478967-682003330-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] E:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BCWipeTM Startup] E:\Program Files\Jetico\BestCrypt\BCWipeTM.exe (Jetico, Inc.)
O4 - HKLM..\Run: [COMODO Internet Security] E:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [EasyTuneVPro] E:\Program Files\GIGABYTE\ET5Pro\ETcall.exe ()
O4 - HKLM..\Run: [NvCplDaemon] E:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] E:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] E:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] E:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [StartCCC] E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - Startup: E:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.exe.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2025429265-261478967-682003330-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2025429265-261478967-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2025429265-261478967-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2025429265-261478967-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O12 - Plugin for: .spop - E:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/aut ... s-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F108EBA-DDA6-4975-9336-D963815B6357}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -E:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (E:\WINDOWS\system32\userinit.exe) -E:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - E:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: E:\WINDOWS\Web\Wallpaper\Nebe.bmp
O24 - Desktop BackupWallPaper: E:\WINDOWS\Web\Wallpaper\Nebe.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\Y\Shell - "" = AutoRun
O33 - MountPoints2\Y\Shell\AutoRun\command - "" = Y:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (E:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - File not found

Drivers32: msacm.iac2 - E:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - E:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - E:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - E:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - E:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - E:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - E:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - E:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - E:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
PhysicalDisk0 MBR saved to E:\PhysicalMBR.bin

Re: Nějaká infekce, prosím o kontrolu.

Napsal: 20 lis 2011 22:38
od rokony
========== Files/Folders - Created Within 60 Days ==========

[2011.11.18 14:16:03 | 000,000,000 | ---D | C] -- E:\Program Files\trend micro
[2011.11.18 14:16:01 | 000,000,000 | ---D | C] -- E:\rsit
[2011.11.18 13:56:30 | 000,000,000 | ---D | C] -- E:\Program Files\HijackThis
[2011.11.18 12:43:37 | 000,518,144 | ---- | C] (SteelWerX) -- E:\WINDOWS\SWREG.exe
[2011.11.18 12:43:37 | 000,406,528 | ---- | C] (SteelWerX) -- E:\WINDOWS\SWSC.exe
[2011.11.18 12:43:37 | 000,212,480 | ---- | C] (SteelWerX) -- E:\WINDOWS\SWXCACLS.exe
[2011.11.18 12:43:37 | 000,060,416 | ---- | C] (NirSoft) -- E:\WINDOWS\NIRCMD.exe
[2011.11.18 12:34:31 | 000,000,000 | R--D | C] -- E:\Documents and Settings\Paul\Nabídka Start\Programy\Nástroje pro správu
[2011.11.17 23:27:54 | 000,000,000 | ---D | C] -- E:\WINDOWS\temp
[2011.11.17 23:26:50 | 000,390,144 | ---- | C] (Microsoft Corporation) -- E:\WINDOWS\System32\CF11002.exe
[2011.11.17 23:26:24 | 000,396,288 | ---- | C] (Trend Micro Inc.) -- E:\hijackthis.exe
[2011.11.17 22:48:19 | 000,000,000 | ---D | C] -- E:\WINDOWS\ERDNT
[2011.11.17 22:48:18 | 000,390,144 | ---- | C] (Microsoft Corporation) -- E:\WINDOWS\System32\CF3455.exe
[2011.11.17 22:48:15 | 000,000,000 | ---D | C] -- E:\Qoobox
[2011.11.17 11:56:17 | 000,000,000 | ---D | C] -- E:\Záloha SD karty 2G
[2011.11.07 19:40:07 | 000,000,000 | ---D | C] -- E:\WINDOWS\pss
[2011.11.03 18:07:27 | 000,000,000 | ---D | C] -- E:\WINDOWS\Sun
[2011.11.03 17:08:22 | 000,000,000 | ---D | C] -- E:\Program Files\NORTON UTILITIES 14
[2011.11.02 00:07:42 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Dokumenty\COMODO
[2011.11.01 23:53:28 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Nabídka Start\Programy\COMODO
[2011.11.01 23:53:28 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Data aplikací\Comodo
[2011.11.01 23:53:24 | 000,000,000 | ---D | C] -- E:\Program Files\COMODO
[2011.11.01 23:53:23 | 001,700,352 | ---- | C] (Microsoft Corporation) -- E:\WINDOWS\System32\gdiplus.dll
[2011.11.01 23:52:30 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
[2011.11.01 23:39:41 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Nabídka Start\Programy\Spybot - Search & Destroy
[2011.11.01 23:39:36 | 000,000,000 | ---D | C] -- E:\Program Files\Spybot - Search & Destroy
[2011.11.01 23:39:36 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
[2011.10.30 19:25:55 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Data aplikací\AVG
[2011.10.29 20:36:35 | 000,000,000 | ---D | C] -- E:\WINDOWS\System32\NtmsData
[2011.10.29 17:42:24 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\Opera
[2011.10.29 17:42:24 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Data aplikací\Opera
[2011.10.29 17:42:15 | 000,000,000 | ---D | C] -- E:\Program Files\Opera
[2011.10.29 17:41:32 | 011,355,704 | ---- | C] (Opera Software ASA) -- E:\Opera_1152_int_Setup.exe
[2011.10.29 16:18:54 | 000,000,000 | ---D | C] -- E:\XP Dell
[2011.10.23 19:47:58 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\tific
[2011.10.23 19:47:58 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Data aplikací\Tific
[2011.10.18 19:29:28 | 000,000,000 | -H-D | C] -- E:\$AVG
[2011.10.18 19:13:10 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Data aplikací\AVG2012
[2011.10.18 19:11:19 | 000,000,000 | -H-D | C] -- E:\Documents and Settings\All Users\Data aplikací\Common Files
[2011.10.18 19:11:13 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Nabídka Start\Programy\AVG 2012
[2011.10.18 19:10:38 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Data aplikací\AVG2012
[2011.10.18 19:10:38 | 000,000,000 | ---D | C] -- E:\WINDOWS\System32\drivers\AVG
[2011.10.18 19:10:10 | 000,000,000 | ---D | C] -- E:\Program Files\AVG
[2011.10.18 19:09:49 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Data aplikací\MFAData
[2011.10.07 18:48:04 | 000,097,760 | ---- | C] (COMODO) -- E:\WINDOWS\System32\drivers\inspect.sys
[2011.10.07 18:48:02 | 000,492,768 | ---- | C] (COMODO) -- E:\WINDOWS\System32\drivers\cmdGuard.sys
[2011.10.07 18:48:02 | 000,031,704 | ---- | C] (COMODO) -- E:\WINDOWS\System32\drivers\cmdhlp.sys
[2011.10.07 18:48:00 | 000,018,056 | ---- | C] (COMODO) -- E:\WINDOWS\System32\drivers\cmderd.sys
[2011.10.07 18:47:12 | 000,300,200 | ---- | C] (COMODO) -- E:\WINDOWS\System32\guard32.dll
[2011.10.07 18:47:12 | 000,033,984 | ---- | C] (COMODO) -- E:\WINDOWS\System32\cmdcsr.dll
[2011.10.03 20:35:12 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\NP3
[2011.10.03 20:33:23 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Data aplikací\NeuroProgrammer3
[2011.10.03 20:33:23 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Dokumenty\Neuro-Programmer 3 Documents
[2011.10.03 20:33:20 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\Xenocode
[2011.10.03 20:33:17 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Nabídka Start\Programy\Neuro-Programmer 3
[2011.10.03 20:33:08 | 000,000,000 | ---D | C] -- E:\Program Files\Neuro-Programmer 3
[2011.01.22 20:24:57 | 000,047,360 | ---- | C] (VSO Software) -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.sys
[9 E:\WINDOWS\*.tmp files -> E:\WINDOWS\*.tmp -> ]
[1 E:\WINDOWS\System32\*.tmp files -> E:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 60 Days ==========

[2011.11.20 22:24:40 | 000,000,512 | ---- | M] () -- E:\PhysicalMBR.bin
[2011.11.20 22:18:24 | 000,584,192 | ---- | M] () -- E:\Documents and Settings\Paul\Plocha\OTL.exe
[2011.11.20 22:05:55 | 000,024,944 | ---- | M] () -- E:\WINDOWS\System32\drivers\GVTDrv.sys
[2011.11.20 22:05:54 | 000,000,004 | ---- | M] () -- E:\WINDOWS\System32\GVTunner.ref
[2011.11.20 22:04:50 | 000,002,048 | --S- | M] () -- E:\WINDOWS\bootstat.dat
[2011.11.19 23:50:42 | 000,000,000 | ---- | M] () -- E:\Documents and Settings\Paul\defogger_reenable
[2011.11.19 19:46:30 | 000,050,477 | ---- | M] () -- E:\Documents and Settings\Paul\Plocha\Defogger.exe
[2011.11.18 20:56:08 | 071,353,389 | ---- | M] () -- E:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011.11.18 16:26:00 | 000,003,302 | ---- | M] () -- E:\WINDOWS\WTRAN32.INI
[2011.11.18 16:26:00 | 000,000,000 | ---- | M] () -- E:\WINDOWS\XXLGSC
[2011.11.18 14:25:28 | 000,440,820 | ---- | M] () -- E:\WINDOWS\System32\perfh009.dat
[2011.11.18 14:25:28 | 000,437,336 | ---- | M] () -- E:\WINDOWS\System32\perfh005.dat
[2011.11.18 14:25:28 | 000,082,642 | ---- | M] () -- E:\WINDOWS\System32\perfc005.dat
[2011.11.18 14:25:28 | 000,071,138 | ---- | M] () -- E:\WINDOWS\System32\perfc009.dat
[2011.11.17 23:26:43 | 000,390,144 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\System32\CF11002.exe
[2011.11.17 22:48:13 | 000,390,144 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\System32\CF3455.exe
[2011.11.17 11:42:26 | 000,002,206 | ---- | M] () -- E:\WINDOWS\System32\wpa.dbl
[2011.11.06 18:08:22 | 000,000,714 | ---- | M] () -- E:\Documents and Settings\All Users\Plocha\AVG 2012.lnk
[2011.11.02 19:25:12 | 000,396,288 | ---- | M] (Trend Micro Inc.) -- E:\hijackthis.exe
[2011.11.02 16:30:57 | 000,437,882 | R--- | M] () -- E:\WINDOWS\System32\drivers\etc\hosts
[2011.11.01 23:53:48 | 000,001,653 | ---- | M] () -- E:\Documents and Settings\All Users\Plocha\COMODO Firewall.lnk
[2011.11.01 23:53:24 | 001,700,352 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\System32\gdiplus.dll
[2011.11.01 23:39:42 | 000,000,933 | ---- | M] () -- E:\Documents and Settings\Paul\Plocha\Spybot - Search & Destroy.lnk
[2011.10.29 18:45:48 | 000,000,671 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\vso_ts_preview.xml
[2011.10.29 17:50:50 | 000,024,061 | ---- | M] () -- E:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011.10.29 17:50:00 | 000,354,709 | ---- | M] () -- E:\Documents and Settings\Paul\Dokumenty\Vytvoření recovery consoly.mht
[2011.10.29 17:42:19 | 000,001,492 | ---- | M] () -- E:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.10.29 17:41:32 | 011,355,704 | ---- | M] (Opera Software ASA) -- E:\Opera_1152_int_Setup.exe
[2011.10.26 20:04:15 | 001,461,600 | ---- | M] () -- E:\Documents and Settings\Paul\Dokumenty\Návod k použití ComboFixu.mht
[2011.10.09 16:32:01 | 000,024,576 | ---- | M] () -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.10.07 18:48:04 | 000,097,760 | ---- | M] (COMODO) -- E:\WINDOWS\System32\drivers\inspect.sys
[2011.10.07 18:48:02 | 000,492,768 | ---- | M] (COMODO) -- E:\WINDOWS\System32\drivers\cmdGuard.sys
[2011.10.07 18:48:02 | 000,031,704 | ---- | M] (COMODO) -- E:\WINDOWS\System32\drivers\cmdhlp.sys
[2011.10.07 18:48:00 | 000,018,056 | ---- | M] (COMODO) -- E:\WINDOWS\System32\drivers\cmderd.sys
[2011.10.07 18:47:12 | 000,300,200 | ---- | M] (COMODO) -- E:\WINDOWS\System32\guard32.dll
[2011.10.07 18:47:12 | 000,033,984 | ---- | M] (COMODO) -- E:\WINDOWS\System32\cmdcsr.dll
[2011.10.07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\WINDOWS\System32\drivers\avgldx86.sys
[2011.10.04 06:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) -- E:\WINDOWS\System32\drivers\AVGIDSShim.sys
[2011.10.03 20:33:17 | 000,000,730 | ---- | M] () -- E:\Documents and Settings\All Users\Plocha\Neuro-Programmer 3.lnk
[2011.10.02 18:07:14 | 000,000,075 | ---- | M] () -- E:\WINDOWS\USBBC.ini
[9 E:\WINDOWS\*.tmp files -> E:\WINDOWS\*.tmp -> ]
[1 E:\WINDOWS\System32\*.tmp files -> E:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.11.20 22:24:40 | 000,000,512 | ---- | C] () -- E:\PhysicalMBR.bin
[2011.11.20 22:20:28 | 000,584,192 | ---- | C] () -- E:\Documents and Settings\Paul\Plocha\OTL.exe
[2011.11.19 23:50:42 | 000,000,000 | ---- | C] () -- E:\Documents and Settings\Paul\defogger_reenable
[2011.11.19 23:49:43 | 000,050,477 | ---- | C] () -- E:\Documents and Settings\Paul\Plocha\Defogger.exe
[2011.11.19 23:49:21 | 000,302,592 | ---- | C] () -- E:\Documents and Settings\Paul\Plocha\gmer.exe
[2011.11.18 20:56:08 | 071,353,389 | ---- | C] () -- E:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011.11.18 14:24:33 | 000,000,004 | ---- | C] () -- E:\WINDOWS\System32\GVTunner.ref
[2011.11.18 12:43:37 | 000,256,000 | ---- | C] () -- E:\WINDOWS\PEV.exe
[2011.11.18 12:43:37 | 000,098,816 | ---- | C] () -- E:\WINDOWS\sed.exe
[2011.11.18 12:43:37 | 000,080,412 | ---- | C] () -- E:\WINDOWS\grep.exe
[2011.11.18 12:43:37 | 000,068,096 | ---- | C] () -- E:\WINDOWS\zip.exe
[2011.11.01 23:53:48 | 000,001,653 | ---- | C] () -- E:\Documents and Settings\All Users\Plocha\COMODO Firewall.lnk
[2011.11.01 23:39:42 | 000,000,933 | ---- | C] () -- E:\Documents and Settings\Paul\Plocha\Spybot - Search & Destroy.lnk
[2011.10.29 17:50:50 | 000,024,061 | ---- | C] () -- E:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011.10.29 17:49:57 | 000,354,709 | ---- | C] () -- E:\Documents and Settings\Paul\Dokumenty\Vytvoření recovery consoly.mht
[2011.10.29 17:42:19 | 000,001,498 | ---- | C] () -- E:\Documents and Settings\All Users\Nabídka Start\Programy\Opera.lnk
[2011.10.29 17:42:19 | 000,001,492 | ---- | C] () -- E:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.10.26 20:04:12 | 001,461,600 | ---- | C] () -- E:\Documents and Settings\Paul\Dokumenty\Návod k použití ComboFixu.mht
[2011.10.18 19:11:13 | 000,000,714 | ---- | C] () -- E:\Documents and Settings\All Users\Plocha\AVG 2012.lnk
[2011.10.03 20:33:17 | 000,000,730 | ---- | C] () -- E:\Documents and Settings\All Users\Plocha\Neuro-Programmer 3.lnk
[2011.07.14 19:14:34 | 001,239,680 | ---- | C] () -- E:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2011.05.05 21:39:12 | 000,225,280 | ---- | C] () -- E:\WINDOWS\System32\net_rim_plazmic_flint_dialog.dll
[2011.03.18 23:39:58 | 000,000,217 | ---- | C] () -- E:\WINDOWS\MPPAGER.INI
[2011.03.16 18:12:32 | 000,000,871 | ---- | C] () -- E:\WINDOWS\QIII.INI
[2011.02.08 16:48:13 | 000,002,591 | ---- | C] () -- E:\WINDOWS\SE.INI
[2011.01.22 20:25:08 | 000,000,671 | ---- | C] () -- E:\Documents and Settings\Paul\Data aplikací\vso_ts_preview.xml
[2011.01.22 20:24:57 | 000,087,608 | ---- | C] () -- E:\Documents and Settings\Paul\Data aplikací\inst.exe
[2011.01.22 20:24:57 | 000,007,887 | ---- | C] () -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.cat
[2011.01.22 20:24:57 | 000,001,144 | ---- | C] () -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.inf
[2010.12.08 13:15:03 | 000,004,096 | ---- | C] () -- E:\WINDOWS\d3dx.dat
[2010.11.09 18:22:36 | 000,024,576 | ---- | C] () -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.09.23 08:34:37 | 000,000,124 | ---- | C] () -- E:\Documents and Settings\Paul\Local Settings\Data aplikací\fusioncache.dat
[2010.09.22 12:15:21 | 000,022,328 | ---- | C] () -- E:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010.09.22 12:15:21 | 000,022,328 | ---- | C] () -- E:\Documents and Settings\Paul\Data aplikací\PnkBstrK.sys
[2010.09.22 12:15:06 | 000,103,736 | ---- | C] () -- E:\WINDOWS\System32\PnkBstrB.exe
[2010.09.22 12:15:05 | 000,669,184 | ---- | C] () -- E:\WINDOWS\System32\pbsvc.exe
[2010.09.22 12:15:05 | 000,066,872 | ---- | C] () -- E:\WINDOWS\System32\PnkBstrA.exe
[2010.09.21 17:34:51 | 000,003,302 | ---- | C] () -- E:\WINDOWS\WTRAN32.INI
[2010.09.18 19:00:15 | 004,289,024 | ---- | C] () -- E:\Program Files\trial_setup.msi
[2010.09.18 19:00:15 | 000,040,448 | ---- | C] () -- E:\Program Files\trial_setup.exe
[2010.09.18 19:00:15 | 000,000,777 | ---- | C] () -- E:\Program Files\trial_setup.ini
[2010.09.18 09:35:04 | 000,281,760 | ---- | C] () -- E:\WINDOWS\System32\drivers\atksgt.sys
[2010.09.18 09:35:04 | 000,025,888 | ---- | C] () -- E:\WINDOWS\System32\drivers\lirsgt.sys
[2010.09.18 08:30:29 | 000,015,576 | R--- | C] () -- E:\WINDOWS\System32\drivers\usbbc.sys
[2010.09.18 08:30:29 | 000,003,953 | R--- | C] () -- E:\WINDOWS\System32\coinst.dll
[2010.09.18 08:22:15 | 000,000,075 | ---- | C] () -- E:\WINDOWS\USBBC.ini
[2010.09.18 08:22:15 | 000,000,000 | ---- | C] () -- E:\WINDOWS\MDI.INI
[2010.09.14 17:42:49 | 000,000,000 | ---- | C] () -- E:\WINDOWS\ativpsrm.bin
[2010.09.14 17:40:48 | 000,593,920 | ---- | C] () -- E:\WINDOWS\System32\ati2sgag.exe
[2010.09.11 20:10:48 | 000,024,944 | ---- | C] () -- E:\WINDOWS\System32\drivers\GVTDrv.sys
[2010.09.11 12:48:03 | 000,208,896 | ---- | C] () -- E:\WINDOWS\System32\igxpun.exe
[2010.09.11 12:32:21 | 000,232,968 | ---- | C] () -- E:\WINDOWS\System32\nvdrsdb0.bin
[2010.09.11 12:32:19 | 000,232,968 | ---- | C] () -- E:\WINDOWS\System32\nvdrsdb1.bin
[2010.09.11 12:32:19 | 000,000,001 | ---- | C] () -- E:\WINDOWS\System32\nvdrssel.bin
[2010.09.10 19:51:39 | 000,004,249 | ---- | C] () -- E:\WINDOWS\ODBCINST.INI
[2010.09.10 19:50:33 | 000,120,544 | ---- | C] () -- E:\WINDOWS\System32\FNTCACHE.DAT
[2010.09.10 19:41:47 | 000,004,990 | ---- | C] () -- E:\Documents and Settings\All Users\Data aplikací\mtbjfghn.xbe
[2010.09.10 19:09:12 | 000,182,275 | ---- | C] () -- E:\WINDOWS\System32\d3d10core.dll
[2010.09.10 19:09:11 | 000,376,832 | ---- | C] () -- E:\WINDOWS\System32\M2000Twn.dll
[2010.09.10 19:09:10 | 000,728,858 | ---- | C] () -- E:\Program Files\Common Files\unins000.exe
[2010.09.10 19:09:10 | 000,073,728 | ---- | C] () -- E:\WINDOWS\System32\CompressATI2.dll
[2010.09.10 19:09:10 | 000,002,884 | ---- | C] () -- E:\Program Files\Common Files\unins000.dat
[2010.09.10 19:04:50 | 002,195,030 | ---- | C] () -- E:\WINDOWS\System32\nvdata.bin
[2010.09.10 18:00:37 | 000,002,048 | --S- | C] () -- E:\WINDOWS\bootstat.dat
[2010.09.10 17:56:06 | 000,021,812 | ---- | C] () -- E:\WINDOWS\System32\emptyregdb.dat
[2009.08.14 02:42:20 | 000,887,724 | ---- | C] () -- E:\WINDOWS\System32\ativva6x.dat
[2009.08.14 02:42:20 | 000,000,003 | ---- | C] () -- E:\WINDOWS\System32\ativva5x.dat
[2009.07.14 16:09:12 | 000,197,654 | ---- | C] () -- E:\WINDOWS\System32\atiicdxx.dat
[2009.02.18 18:55:20 | 000,294,912 | ---- | C] () -- E:\WINDOWS\System32\ATIODE.exe
[2009.02.03 21:52:02 | 000,045,056 | ---- | C] () -- E:\WINDOWS\System32\ATIODCLI.exe
[2008.10.07 08:13:30 | 000,197,912 | ---- | C] () -- E:\WINDOWS\System32\physxcudart_20.dll
[2008.10.07 08:13:22 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSwedish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSpanish.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelPortugese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelKorean.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelJapanese.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelGerman.dll
[2008.10.07 08:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelFrench.dll
[2008.04.15 03:20:46 | 000,237,568 | ---- | C] () -- E:\WINDOWS\glut32.dll
[2008.04.14 08:16:08 | 000,001,804 | ---- | C] () -- E:\WINDOWS\System32\Dcache.bin
[2006.12.31 06:57:08 | 000,004,569 | ---- | C] () -- E:\WINDOWS\System32\secupd.dat
[2005.06.10 09:00:00 | 000,102,400 | ---- | C] () -- E:\WINDOWS\System32\cviUSI.dll
[2005.06.10 09:00:00 | 000,007,140 | ---- | C] () -- E:\WINDOWS\System32\drivers\cvintdrv.sys
[2004.12.31 18:35:42 | 000,000,237 | ---- | C] () -- E:\WINDOWS\System32\oeminfo.ini
[2002.10.03 14:42:27 | 000,000,034 | ---- | C] () -- E:\WINDOWS\Q3version.ini
[2001.10.25 17:00:00 | 013,107,200 | ---- | C] () -- E:\WINDOWS\System32\oembios.bin
[2001.10.25 17:00:00 | 000,673,088 | ---- | C] () -- E:\WINDOWS\System32\mlang.dat
[2001.10.25 17:00:00 | 000,440,820 | ---- | C] () -- E:\WINDOWS\System32\perfh009.dat
[2001.10.25 17:00:00 | 000,437,336 | ---- | C] () -- E:\WINDOWS\System32\perfh005.dat
[2001.10.25 17:00:00 | 000,272,128 | ---- | C] () -- E:\WINDOWS\System32\perfi009.dat
[2001.10.25 17:00:00 | 000,269,162 | ---- | C] () -- E:\WINDOWS\System32\perfi005.dat
[2001.10.25 17:00:00 | 000,218,003 | ---- | C] () -- E:\WINDOWS\System32\dssec.dat
[2001.10.25 17:00:00 | 000,082,642 | ---- | C] () -- E:\WINDOWS\System32\perfc005.dat
[2001.10.25 17:00:00 | 000,071,138 | ---- | C] () -- E:\WINDOWS\System32\perfc009.dat
[2001.10.25 17:00:00 | 000,046,258 | ---- | C] () -- E:\WINDOWS\System32\mib.bin
[2001.10.25 17:00:00 | 000,032,072 | ---- | C] () -- E:\WINDOWS\System32\perfd005.dat
[2001.10.25 17:00:00 | 000,028,626 | ---- | C] () -- E:\WINDOWS\System32\perfd009.dat
[2001.10.25 17:00:00 | 000,004,463 | ---- | C] () -- E:\WINDOWS\System32\oembios.dat
[2001.10.25 17:00:00 | 000,000,741 | ---- | C] () -- E:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011.10.18 19:27:00 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\AVG2012
[2011.10.18 19:11:19 | 000,000,000 | -H-D | M] -- E:\Documents and Settings\All Users\Data aplikací\Common Files
[2011.09.02 15:38:01 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\GameXzone
[2011.11.18 20:56:13 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\MFAData
[2011.07.14 17:48:27 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\Research In Motion
[2011.11.07 19:48:37 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.12.09 22:12:36 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Data aplikací\WildTangent
[2011.10.30 19:26:25 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\AVG
[2011.10.18 19:13:10 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\AVG2012
[2010.09.10 19:41:47 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Carambis
[2011.08.05 20:43:22 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Composer
[2011.07.20 19:30:07 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\ImgBurn
[2010.12.13 16:48:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\InterTrust
[2011.10.05 21:56:12 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\NeuroProgrammer3
[2011.10.29 17:42:24 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Opera
[2010.09.10 20:31:02 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Poser 7
[2011.08.05 20:36:08 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Research In Motion
[2011.09.01 21:18:56 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Rovio
[2011.10.23 19:47:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Tific
[2010.09.10 18:50:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Uniblue
[2011.10.29 18:43:05 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Vso
[2010.12.08 22:50:01 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\WildTangent

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = E:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 07:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)

< >


< MD5 for: AGP440.SYS >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys

< MD5 for: ATAPI.SYS >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- E:\WINDOWS\system32\dllcache\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- E:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- E:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- E:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 07:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- E:\WINDOWS\system32\autochk.exe
[2008.04.14 07:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- E:\WINDOWS\system32\dllcache\autochk.exe

< MD5 for: CDROM.SYS >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.13 23:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- E:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2008.04.14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- E:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- E:\WINDOWS\system32\dllcache\cryptsvc.dll

< MD5 for: CSRSS.EXE >
[2008.04.14 07:52:18 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- E:\WINDOWS\system32\csrss.exe
[2008.04.14 07:52:18 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- E:\WINDOWS\system32\dllcache\csrss.exe

< MD5 for: EVENTLOG.DLL >
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- E:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- E:\WINDOWS\system32\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- E:\WINDOWS\explorer.exe
[2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- E:\WINDOWS\system32\dllcache\explorer.exe
[2010.09.12 15:09:18 | 000,017,408 | ---- | M] () MD5=315E8398DFF13A6CA45A2B6C189E7284 -- E:\Documents and Settings\Paul\Plocha\Data\Native\STUBEXE\8.0.1135\@WINDIR@\explorer.exe

< MD5 for: FASTFAT.SYS >
[2008.04.13 23:44:30 | 000,143,744 | ---- | M] (Microsoft Corporation) MD5=38D332A6D56AF32635675F132548343E -- E:\WINDOWS\system32\dllcache\fastfat.sys
[2008.04.13 23:44:30 | 000,143,744 | ---- | M] (Microsoft Corporation) MD5=38D332A6D56AF32635675F132548343E -- E:\WINDOWS\system32\drivers\fastfat.sys

< MD5 for: HAL.DLL >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.13 23:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- E:\WINDOWS\system32\hal.dll

< MD5 for: CHANGER.SYS >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys

< MD5 for: IASTOR.SYS >
[2008.06.23 13:12:16 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- E:\WINDOWS\NLDRV\001\iastor.sys

< MD5 for: ISAPNP.SYS >
[2008.04.14 08:10:02 | 020,102,206 | ---- | M] () .cab file -- E:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- E:\WINDOWS\system32\dllcache\isapnp.sys
[2008.04.14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- E:\WINDOWS\system32\drivers\isapnp.sys
[2008.04.14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- E:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\isapnp.sys

< MD5 for: LSASS.EXE >
[2008.04.14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- E:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- E:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- E:\WINDOWS\system32\dllcache\ndis.sys
[2008.04.13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- E:\WINDOWS\system32\drivers\ndis.sys
[1994.09.04 07:07:02 | 000,107,812 | ---- | M] () MD5=EDE3814D47F3F103771DBC1590D6B177 -- E:\RŮZNÉ OVLADAČE\E2000-origDisketa\WINNT31\NDIS.SYS

< MD5 for: NETLOGON.DLL >
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- E:\WINDOWS\system32\dllcache\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- E:\WINDOWS\system32\netlogon.dll

< MD5 for: NTFS.SYS >
[2008.04.13 23:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- E:\WINDOWS\system32\dllcache\ntfs.sys
[2008.04.13 23:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- E:\WINDOWS\system32\drivers\ntfs.sys

< MD5 for: SCECLI.DLL >
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- E:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- E:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2009.02.09 12:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- E:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- E:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- E:\WINDOWS\system32\services.exe

< MD5 for: SMSS.EXE >
[2008.04.14 07:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- E:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 07:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- E:\WINDOWS\system32\smss.exe

< MD5 for: SPOOLSV.EXE >
[2010.08.17 14:19:36 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 -- E:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- E:\WINDOWS\system32\dllcache\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- E:\WINDOWS\system32\spoolsv.exe

< MD5 for: SVCHOST.EXE >
[2008.04.14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- E:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- E:\WINDOWS\system32\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- E:\Záloha SD karty 2G\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- E:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- E:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- E:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- E:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- E:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- E:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008.04.14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- E:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- E:\WINDOWS\system32\winlogon.exe

< MD5 for: WS2_32.DLL >
[2008.04.14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- E:\WINDOWS\system32\dllcache\ws2_32.dll
[2008.04.14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- E:\WINDOWS\system32\ws2_32.dll

< >

< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >

< %systemroot%\system32\drivers\*.sys /5 >
[2011.11.20 22:05:55 | 000,024,944 | ---- | M] () -- E:\WINDOWS\system32\drivers\GVTDrv.sys

< %systemroot%\system32\drivers\*.sys /X >
[2009.08.14 02:17:58 | 000,053,248 | ---- | M] (ATI Technologies Inc.) -- E:\WINDOWS\system32\drivers\ati2erec.dll
[2001.10.25 17:00:00 | 003,440,660 | ---- | M] () -- E:\WINDOWS\system32\drivers\gm.dls
[2001.10.25 17:00:00 | 000,000,646 | ---- | M] () -- E:\WINDOWS\system32\drivers\gmreadme.txt
[2011.07.14 17:50:45 | 000,000,000 | -H-- | M] () -- E:\WINDOWS\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011.07.14 17:50:47 | 000,000,000 | -H-- | M] () -- E:\WINDOWS\system32\drivers\Msft_Kernel_RimUsb_01009.Wdf

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\*.* /5 >
[2011.11.17 23:26:43 | 000,390,144 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\system32\CF11002.exe
[2011.11.17 22:48:13 | 000,390,144 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\system32\CF3455.exe
[2011.11.20 22:05:54 | 000,000,004 | ---- | M] () -- E:\WINDOWS\system32\GVTunner.ref
[2011.11.18 14:25:28 | 000,082,642 | ---- | M] () -- E:\WINDOWS\system32\perfc005.dat
[2011.11.18 14:25:28 | 000,071,138 | ---- | M] () -- E:\WINDOWS\system32\perfc009.dat
[2011.11.18 14:25:28 | 000,437,336 | ---- | M] () -- E:\WINDOWS\system32\perfh005.dat
[2011.11.18 14:25:28 | 000,440,820 | ---- | M] () -- E:\WINDOWS\system32\perfh009.dat
[2011.11.18 14:25:28 | 001,046,050 | ---- | M] () -- E:\WINDOWS\system32\PerfStringBackup.INI
[2011.11.17 11:42:26 | 000,002,206 | ---- | M] () -- E:\WINDOWS\system32\wpa.dbl
[1 E:\WINDOWS\system32\*.tmp files -> E:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\*.dll /lockedfiles >
[1 E:\WINDOWS\system32\*.tmp files -> E:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\config\*.sav >
[2010.09.10 19:49:51 | 000,094,208 | ---- | M] () -- E:\WINDOWS\system32\config\default.sav
[2010.09.10 19:49:51 | 001,093,632 | ---- | M] () -- E:\WINDOWS\system32\config\software.sav
[2010.09.10 19:49:51 | 000,507,904 | ---- | M] () -- E:\WINDOWS\system32\config\system.sav

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\*.* /U /s >
[9 E:\WINDOWS\*.tmp files -> E:\WINDOWS\*.tmp -> ]
[11 E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[8 E:\WINDOWS\Installer\*.tmp files -> E:\WINDOWS\Installer\*.tmp -> ]
[1 E:\WINDOWS\SoftwareDistribution\Download\43aa18ebd60ddd747e3a838509abcd92\download\*.tmp files -> E:\WINDOWS\SoftwareDistribution\Download\43aa18ebd60ddd747e3a838509abcd92\download\*.tmp -> ]
[1 E:\WINDOWS\SoftwareDistribution\Download\6d0c89a36b9ebeb9a8ad3924b5c9131f\download\*.tmp files -> E:\WINDOWS\SoftwareDistribution\Download\6d0c89a36b9ebeb9a8ad3924b5c9131f\download\*.tmp -> ]
[1 E:\WINDOWS\SoftwareDistribution\Download\83f89bf741551173774b5c6c29adff30\download\*.tmp files -> E:\WINDOWS\SoftwareDistribution\Download\83f89bf741551173774b5c6c29adff30\download\*.tmp -> ]
[1 E:\WINDOWS\SoftwareDistribution\Download\b4ccf90cba244e6dadbae18938ad1aee\*.tmp files -> E:\WINDOWS\SoftwareDistribution\Download\b4ccf90cba244e6dadbae18938ad1aee\*.tmp -> ]
[1 E:\WINDOWS\SoftwareDistribution\Download\f3146c7a92d8fac266514a452b7053fb\*.tmp files -> E:\WINDOWS\SoftwareDistribution\Download\f3146c7a92d8fac266514a452b7053fb\*.tmp -> ]
[1 E:\WINDOWS\system32\*.tmp files -> E:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\*. /mp /s >

< %ALLUSERSPROFILE%\Data Aplikací\*.* >
[2010.09.10 19:51:14 | 000,000,062 | -HS- | M] () -- E:\Documents and Settings\All Users\Data Aplikací\desktop.ini
[2010.09.10 19:41:47 | 000,004,990 | ---- | M] () -- E:\Documents and Settings\All Users\Data Aplikací\mtbjfghn.xbe

< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
[2011.10.26 16:32:07 | 005,595,488 | ---- | M] (AVG Technologies CZ, s.r.o.) -- E:\Documents and Settings\All Users\Data Aplikací\AVG2012\update\backup\avgmfapx.exe
[2011.11.01 23:53:19 | 007,245,888 | ---- | M] (COMODO) -- E:\Documents and Settings\All Users\Data Aplikací\Comodo Downloader\geekbuddy.exe
[2011.10.07 18:46:50 | 000,198,984 | ---- | M] () -- E:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\ComodoCleanup.exe
[5 E:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\*.tmp files -> E:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\*.tmp -> ]

< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >

< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >

< %APPDATA%\*. >
[2011.07.20 22:53:42 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Adobe
[2011.08.06 13:08:58 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\AdobeUM
[2010.09.18 19:02:20 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\ATI
[2011.10.30 19:26:25 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\AVG
[2011.10.18 19:13:10 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\AVG2012
[2010.09.10 19:41:47 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Carambis
[2011.08.05 20:43:22 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Composer
[2010.09.19 17:00:24 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Help
[2010.09.10 18:02:35 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Identities
[2011.07.20 19:30:07 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\ImgBurn
[2010.12.13 16:22:39 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\InstallShield
[2010.12.13 16:48:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\InterTrust
[2011.07.20 22:53:42 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Macromedia
[2011.07.14 18:02:28 | 000,000,000 | --SD | M] -- E:\Documents and Settings\Paul\Data aplikací\Microsoft
[2011.10.05 21:56:12 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\NeuroProgrammer3
[2011.10.29 17:42:24 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Opera
[2010.09.10 20:31:02 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Poser 7
[2011.08.05 20:36:08 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Research In Motion
[2011.09.01 21:18:56 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Rovio
[2011.08.01 17:41:51 | 000,000,000 | RH-D | M] -- E:\Documents and Settings\Paul\Data aplikací\SecuROM
[2011.04.25 16:44:08 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Sun
[2011.10.23 19:47:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Tific
[2010.09.10 18:50:59 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Uniblue
[2011.10.29 18:43:05 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\Vso
[2010.12.08 22:50:01 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\WildTangent
[2010.09.18 19:57:05 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Paul\Data aplikací\WinRAR

< %APPDATA%\*.* >
[2010.09.10 19:51:14 | 000,000,062 | -HS- | M] () -- E:\Documents and Settings\Paul\Data aplikací\desktop.ini
[2011.01.22 20:24:57 | 000,087,608 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\inst.exe
[2011.01.22 20:24:57 | 000,007,887 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.cat
[2011.01.22 20:24:57 | 000,001,144 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.inf
[2011.01.22 20:25:00 | 000,000,034 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.log
[2011.01.22 20:24:57 | 000,047,360 | ---- | M] (VSO Software) -- E:\Documents and Settings\Paul\Data aplikací\pcouffin.sys
[2010.09.22 12:15:21 | 000,022,328 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\PnkBstrK.sys
[2011.08.14 21:17:14 | 000,002,785 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Rim.Desktop.Exception.log
[2011.07.14 17:48:33 | 000,001,105 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Rim.Desktop.HttpServerSetup.log
[2011.08.14 21:17:14 | 000,001,848 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Rim.DesktopHelper.Exception.log
[2011.10.29 18:45:48 | 000,000,671 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\vso_ts_preview.xml

< %APPDATA%\*.exe /s >
[2011.01.22 20:24:57 | 000,087,608 | ---- | M] () -- E:\Documents and Settings\Paul\Data aplikací\inst.exe
[2011.07.14 18:02:28 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- E:\Documents and Settings\Paul\Data aplikací\Microsoft\Installer\{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}\ARPPRODUCTICON.exe
[2011.08.03 18:00:21 | 000,001,078 | R--- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Microsoft\Installer\{6F1AE16C-769D-4574-A813-F2ABB27FD6E1}\device.exe
[2011.08.03 18:00:21 | 000,000,766 | R--- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Microsoft\Installer\{6F1AE16C-769D-4574-A813-F2ABB27FD6E1}\ess.exe
[2011.08.03 18:00:21 | 000,001,078 | R--- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Microsoft\Installer\{6F1AE16C-769D-4574-A813-F2ABB27FD6E1}\mds.exe
[2011.08.03 18:00:21 | 000,001,078 | R--- | M] () -- E:\Documents and Settings\Paul\Data aplikací\Microsoft\Installer\{6F1AE16C-769D-4574-A813-F2ABB27FD6E1}\sdk.exe

< %SYSTEMDRIVE%\*.exe >
[2011.11.02 19:25:12 | 000,396,288 | ---- | M] (Trend Micro Inc.) -- E:\hijackthis.exe
[2011.10.29 17:41:32 | 011,355,704 | ---- | M] (Opera Software ASA) -- E:\Opera_1152_int_Setup.exe

< >

< >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-27 15:32:59

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS /s >
"StateIndex" = 0

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0E:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart\0\0

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER

< >

< type c:\boot.ini >> test.txt /c >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2011.11.20 22:24:40 | 000,000,512 | ---- | M] () MD5=7D06030DED6A6D4612137AE02DF8E565 -- E:\PhysicalMBR.bin

========== Alternate Data Streams ==========

@Alternate Data Stream - 147 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:D287FACF
@Alternate Data Stream - 139 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:157E1AD3
@Alternate Data Stream - 137 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4

< End of report >

Re: Nějaká infekce, prosím o kontrolu.

Napsal: 20 lis 2011 23:07
od motji
:arrow: Spustte OTL
-do bílého okna dole skopírujte tento skript:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
@Alternate Data Stream - 147 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:D287FACF
@Alternate Data Stream - 139 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:157E1AD3
@Alternate Data Stream - 137 bytes -> E:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4

:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
E:\WINDOWS\system32\CF11002.exe
E:\WINDOWS\system32\CF3455.exe

:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]
[clearallrestorepoints]
[Reboot]

-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde :)

Re: Nějaká infekce, prosím o kontrolu.

Napsal: 22 lis 2011 16:24
od rokony
Včera jsem byl v práci do večera, proto dávám log až dneska.

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
ADS E:\Documents and Settings\All Users\Data aplikací\TEMP:D287FACF deleted successfully.
ADS E:\Documents and Settings\All Users\Data aplikací\TEMP:157E1AD3 deleted successfully.
ADS E:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
E:\WINDOWS\system32\CF11002.exe moved successfully.
E:\WINDOWS\system32\CF3455.exe moved successfully.
========== COMMANDS ==========
E:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Paul
->Temp folder emptied: 1574275 bytes
->Temporary Internet Files folder emptied: 200899 bytes
->Java cache emptied: 18617 bytes
->Opera cache emptied: 27580327 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2941556 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 406057 bytes
RecycleBin emptied: 2157928 bytes

Total Files Cleaned = 33,00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: Paul
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb

Restore points cleared and new OTL Restore Point set!

OTL by OldTimer - Version 3.2.31.0 log created on 11222011_161630

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Re: Nějaká infekce, prosím o kontrolu.

Napsal: 22 lis 2011 21:39
od motji
Jak to vypadá s počítačem?

Re: Nějaká infekce, prosím o kontrolu.

Napsal: 23 lis 2011 21:11
od rokony
Zatím vše v pořádku, dneska se ten trojan neobjevil, tak je to snad už pryč.
Děkuji za Vaši pomoc!
Mohl bych zde dát ještě log s tátového počítače? Nebo mám založit raději jiné téma?
Velmi dlouho mu Xp startují, po přihlášení do systému se tak 3 minuty nedá pracovat.

Re: Nějaká infekce, prosím o kontrolu.

Napsal: 24 lis 2011 08:58
od motji
:arrow: Ještě znovu spustte OTL, klikněte na tlačítko vyčisti, uklidí po sobě :)


Založte topic s názvem pro Motji, ale mrknu na to asi až zítra :)