Log Extras.txt se neudělal. Nejprve jsem testoval v nouzovém režimu a potom v normálním, Extras se neobjevil. Log vytvořený v nouzovém režimu se liší, raději dám oba.
Nejprve OTL.txt z normálního spuštění: (test v normálním režimu byl spuštěn až po testu v režimu nouze)
OTL logfile created on: 11.12.2011 14:50:52 - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = F:\Testovací prog
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
767,53 Mb Total Physical Memory | 301,45 Mb Available Physical Memory | 39,28% Memory free
1,71 Gb Paging File | 1,20 Gb Available in Paging File | 70,29% Paging File free
Paging file location(s): D:\pagefile.sys 1024 2304 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 1,74 Gb Free Space | 8,90% Space Free | Partition Type: NTFS
Drive D: | 11,95 Gb Total Space | 2,49 Gb Free Space | 20,84% Space Free | Partition Type: FAT32
Drive F: | 963,70 Mb Total Space | 232,36 Mb Free Space | 24,11% Space Free | Partition Type: FAT
Computer Name: DOLNI | User Name: Dolní | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Processes (SafeList) ==========
PRC - [2011.12.11 13:43:52 | 000,584,192 | ---- | M] (OldTimer Tools) -- F:\Testovací prog\OTL.exe
PRC - [2011.11.23 21:31:27 | 000,803,328 | ---- | M] (bProtector) -- C:\Documents and Settings\All Users\Data aplikací\bProtector\bProtect.exe
PRC - [2011.11.23 21:21:16 | 000,273,912 | ---- | M] () -- C:\Program Files\InstallBrainService\InstallBrainService.exe
PRC - [2011.10.28 18:13:21 | 000,246,600 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
PRC - [2011.10.28 18:13:17 | 000,218,440 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2011.10.24 20:29:16 | 002,415,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2011.10.20 12:58:40 | 002,497,352 | ---- | M] (COMODO) -- C:\Program Files\Comodo\COMODO Internet Security\cfp.exe
PRC - [2011.10.18 06:14:54 | 001,229,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011.10.12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011.10.10 06:23:34 | 000,973,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2011.10.07 18:47:13 | 001,883,328 | ---- | M] (COMODO) -- C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
PRC - [2011.09.08 19:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011.08.15 05:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011.08.02 05:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011.02.08 18:21:52 | 001,114,040 | ---- | M] (MusicLab, LLC) -- C:\Program Files\BearShare Applications\MediaBar\Datamngr\datamngrUI.exe
PRC - [2010.03.04 21:38:00 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
PRC - [2009.12.13 14:37:00 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009.09.08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2008.04.14 05:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2003.05.05 07:57:30 | 000,143,360 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
PRC - [2002.09.20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
========== Modules (No Company Name) ==========
MOD - [2011.11.23 21:31:27 | 000,748,544 | ---- | M] () -- C:\WINDOWS\system32\protector.dll
MOD - [2011.11.23 21:21:16 | 000,273,912 | ---- | M] () -- C:\Program Files\InstallBrainService\InstallBrainService.exe
MOD - [2011.10.28 18:13:21 | 000,246,600 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
MOD - [2011.10.28 18:13:17 | 000,218,440 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2010.03.04 21:38:00 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe
MOD - [2008.10.11 21:18:46 | 000,319,488 | ---- | M] () -- C:\Program Files\WinRAR\rarlng.dll
MOD - [2008.09.16 19:18:06 | 000,132,608 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [Auto | Stopped] -- -- (helpsvc)
SRV - [2011.11.23 21:31:27 | 000,803,328 | ---- | M] (bProtector) [Auto | Running] -- C:\Documents and Settings\All Users\Data aplikací\bProtector\bProtect.exe -- (bProtector)
SRV - [2011.11.23 21:21:16 | 000,273,912 | ---- | M] () [Auto | Running] -- C:\Program Files\InstallBrainService\InstallBrainService.exe -- (InstallBrainService)
SRV - [2011.10.28 18:13:21 | 000,246,600 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe -- (vToolbarUpdater)
SRV - [2011.10.12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011.10.07 18:47:13 | 001,883,328 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011.08.02 05:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2010.03.04 21:38:00 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
SRV - [2009.09.08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2002.09.20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))
========== Driver Services (SafeList) ==========
DRV - [2011.10.07 18:48:02 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2011.10.07 18:48:01 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2011.10.07 18:48:00 | 000,492,768 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2011.10.07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011.10.04 06:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011.09.13 05:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011.08.08 05:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011.07.11 00:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011.07.11 00:14:28 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011.07.11 00:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011.07.11 00:14:26 | 000,134,608 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2009.11.12 12:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2008.04.14 06:10:02 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008.04.13 21:05:40 | 000,032,768 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisnic.sys -- (SISNIC)
DRV - [2003.10.28 15:06:16 | 000,014,352 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PvXBAR.sys -- (PVXBAR)
DRV - [2003.10.28 15:05:26 | 000,071,151 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Pv848.sys -- (Pv848)
DRV - [2003.10.28 15:04:18 | 000,032,930 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PvTUNER.sys -- (PVTUNER)
DRV - [2003.07.18 02:58:20 | 000,036,992 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\SISAGPX.sys -- (sisagp)
DRV - [2002.07.17 07:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\aspi32.BAK -- (Aspi32)
DRV - [2001.08.17 21:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page =
http://www.goonsearch.com/?source=IBR-IB-PDP-INS-HP
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page =
http://www.goonsearch.com/?source=IBR-IB-PDP-INS-HP
IE - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://search.qip.ru
IE - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://search.qip.ru
IE - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://toolbar.inbox.com/search/dispatc ... &%language
IE - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://search.qip.ru
IE - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/
IE - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://search.qip.ru/ie
IE - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\..\URLSearchHook: {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
IE - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\..\URLSearchHook: {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No CLSID value found
IE - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG2012\Firefox\ [2011.11.05 20:53:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011.11.22 13:42:05 | 000,000,000 | ---D | M]
========== Chrome ==========
O1 HOSTS File: ([2011.11.01 20:53:41 | 000,437,882 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O1 - Hosts: 127.0.0.1
www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1
www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1
www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1
www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1
www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1
www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1
www.100888290cs.com
O1 - Hosts: 127.0.0.1
www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1
www.10sek.com
O1 - Hosts: 127.0.0.1
www.1-2005-search.com
O1 - Hosts: 15062 more lines...
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (UrlHelper Class) - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\IEBHO.dll (MusicLab, LLC)
O2 - BHO: (WindowShopper) - {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Program Files\SuperFish\Superfish.dll (Superfish)
O2 - BHO: (QIPBHO Class) - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (File2LinkIB) - {c23b756a-bd9f-4ca6-aded-17ab8ccf3e8b} - C:\Program Files\file2linkib\file2linkibX.dll ()
O2 - BHO: (MediaBar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\bsdtxmltbpi.dll ()
O2 - BHO: (PandoraTV Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (File2LinkIB) - {c23b756a-bd9f-4ca6-aded-17ab8ccf3e8b} - C:\Program Files\file2linkib\file2linkibX.dll ()
O3 - HKLM\..\Toolbar: (MediaBar) - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\ToolBar\bsdtxmltbpi.dll ()
O3 - HKLM\..\Toolbar: (PandoraTV Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found.
O3 - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\BearShare Applications\MediaBar\Datamngr\datamngrUI.exe (MusicLab, LLC)
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKU\.DEFAULT..\Run: [jusched] %APPDATA%\jusched.exe File not found
O4 - HKU\S-1-5-18..\Run: [jusched] %APPDATA%\jusched.exe File not found
O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe File not found
O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe File not found
O4 - Startup: C:\Documents and Settings\Cernopolak\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.3.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 1
O7 - HKU\S-1-5-21-1078081533-492894223-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O9 - Extra Button: WindowShopper - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Program Files\SuperFish\Superfish.dll (Superfish)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8862CCCC-5EBE-4341-A372-BCF758AA33EE}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Dolní\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dolní\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.05.24 20:05:44 | 000,000,141 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008.02.02 15:14:36 | 000,000,170 | -HS- | M] () - C:\AUTOEXEC.DOS -- [ NTFS ]
O32 - AutoRun File - [2008.02.02 16:08:08 | 000,000,170 | ---- | M] () - C:\AUTOEXEC.NU4 -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: helpsvc - File not found
NetSvcs: SSHNAS - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 60 Days ==========
[2011.12.10 20:25:52 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011.12.10 19:15:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Microsoft Office
[2011.12.10 19:11:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Synchronization Services
[2011.12.10 19:10:11 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2011.12.10 19:10:11 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2011.12.10 19:10:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Microsoft
[2011.12.10 19:03:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2011.12.10 19:03:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
[2011.12.10 19:02:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dolní\Local Settings\Data aplikací\Microsoft Help
[2011.12.10 18:57:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
[2011.12.10 18:55:28 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2011.12.10 18:46:21 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011.12.07 22:40:18 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[2011.12.07 22:25:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dolní\Data aplikací\OpenOffice.org
[2011.12.07 22:17:26 | 000,000,000 | ---D | C] -- C:\Program Files\OpenOffice.org 3
[2011.12.07 22:15:06 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011.12.07 22:15:06 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011.12.07 22:15:06 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011.12.02 16:30:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Fighters
[2011.11.30 22:09:23 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011.11.30 22:09:23 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011.11.30 22:09:23 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011.11.29 20:59:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011.11.29 19:42:07 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011.11.29 19:38:45 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011.11.29 19:26:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011.11.29 19:26:16 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.11.29 19:24:55 | 004,334,705 | R--- | C] (Swearware) -- C:\Documents and Settings\Dolní\Plocha\ComboFix.exe
[2011.11.26 23:34:52 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Dolní\Recent
[2011.11.26 19:16:07 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.11.26 19:16:02 | 000,000,000 | ---D | C] -- C:\rsit
[2011.11.23 21:43:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dolní\Nabídka Start\Programy\Microsoft Bootvis
[2011.11.23 21:43:44 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Bootvis
[2011.11.23 21:32:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dolní\Data aplikací\PerformerSoft
[2011.11.23 21:32:15 | 000,017,456 | ---- | C] (PerformerSoft LLC) -- C:\WINDOWS\System32\roboot.exe
[2011.11.23 21:31:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Extensions
[2011.11.23 21:31:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\bProtector
[2011.11.23 21:30:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dolní\Nabídka Start\Programy\SpecialSavings
[2011.11.23 21:30:28 | 000,000,000 | ---D | C] -- C:\Program Files\SuperFish
[2011.11.23 21:30:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dolní\Data aplikací\file2linkib
[2011.11.23 21:29:56 | 000,000,000 | ---D | C] -- C:\Program Files\file2linkib
[2011.11.23 21:29:26 | 000,000,000 | ---D | C] -- C:\Program Files\InstallBrainService
[2011.11.20 19:52:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dolní\Plocha\Testování
[2011.11.18 18:27:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\ZoomBrowser
[2011.11.18 18:27:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Canon Utilities
[2011.11.11 17:53:53 | 000,033,984 | ---- | C] (COMODO) -- C:\WINDOWS\System32\cmdcsr.dll
[2011.11.05 20:20:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\COMODO
[2011.11.05 20:04:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
[2011.11.01 22:05:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dolní\Data aplikací\Comodo
[2011.11.01 20:28:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Comodo
[2011.11.01 20:24:54 | 000,000,000 | ---D | C] -- C:\Program Files\Comodo
[2011.10.30 21:04:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dolní\Data aplikací\AVG
[2011.10.28 18:47:27 | 000,000,000 | -H-D | C] -- C:\$AVG
[2011.10.28 18:16:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dolní\Data aplikací\AVG2012
[2011.10.28 18:13:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\AVG 2012
[2011.10.28 18:13:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dolní\Data aplikací\AVG Secure Search
[2011.10.28 18:13:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search
[2011.10.28 18:13:17 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search
[2011.10.28 18:13:13 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2011.10.28 18:10:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\AVG2012
[2011.10.28 18:10:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2011.10.28 18:04:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 60 Days ==========
[2011.12.11 14:53:49 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011.12.11 14:47:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.12.11 14:47:20 | 804,884,480 | -HS- | M] () -- C:\hiberfil.sys
[2011.12.11 12:51:18 | 111,839,177 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011.12.10 20:57:50 | 000,220,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.12.10 20:24:39 | 004,334,705 | R--- | M] (Swearware) -- C:\Documents and Settings\Dolní\Plocha\ComboFix.exe
[2011.12.07 21:32:14 | 000,000,390 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2011.12.07 11:59:43 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.12.04 19:11:50 | 000,000,893 | ---- | M] () -- C:\Documents and Settings\Dolní\Plocha\EVEREST Ultimate Edition.lnk
[2011.12.04 18:09:44 | 000,004,692 | ---- | M] () -- C:\WINDOWS\WTRAN32.INI
[2011.12.04 18:09:44 | 000,000,000 | ---- | M] () -- C:\WINDOWS\XXLGSC
[2011.12.02 18:50:32 | 000,026,143 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011.12.02 16:53:26 | 104,379,152 | ---- | M] () -- C:\Documents and Settings\Dolní\Plocha\setup_11.0.0.1245.x01_2011_12_02_18_18.exe
[2011.11.29 23:07:58 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011.11.29 23:04:28 | 000,432,928 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.11.29 23:04:28 | 000,429,454 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2011.11.29 23:04:28 | 000,078,466 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2011.11.29 23:04:28 | 000,067,884 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.11.29 19:42:12 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011.11.27 22:31:49 | 000,000,410 | ---- | M] () -- C:\Documents and Settings\Dolní\Plocha\Zástupce - TestCPU.lnk
[2011.11.23 21:32:28 | 000,001,661 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\repository.xml
[2011.11.23 21:31:27 | 000,748,544 | ---- | M] () -- C:\WINDOWS\System32\protector.dll
[2011.11.22 13:42:06 | 000,000,720 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\AVG 2012.lnk
[2011.11.18 18:56:28 | 000,114,933 | -H-- | M] () -- C:\ZbThumbnail.info
[2011.11.18 18:27:33 | 000,000,929 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\ZoomBrowser EX.lnk
[2011.11.18 18:00:08 | 000,000,410 | ---- | M] () -- C:\WINDOWS\ULead32.ini
[2011.11.11 17:46:24 | 001,775,842 | ---- | M] () -- C:\Documents and Settings\Dolní\Plocha\Geologické epochy.psd
[2011.11.07 20:18:27 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2011.11.05 20:20:18 | 000,001,653 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\COMODO Firewall.lnk
[2011.11.02 15:16:08 | 000,017,456 | ---- | M] (PerformerSoft LLC) -- C:\WINDOWS\System32\roboot.exe
[2011.11.01 20:53:41 | 000,437,882 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.12.11 14:47:20 | 804,884,480 | -HS- | C] () -- C:\hiberfil.sys
[2011.12.11 12:51:18 | 111,839,177 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011.12.10 19:25:49 | 000,744,786 | ---- | C] () -- C:\Documents and Settings\Dolní\Plocha\Aktivátor.exe
[2011.12.07 22:47:45 | 000,001,946 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Microsoft PowerPoint Viewer .lnk
[2011.12.04 19:11:50 | 000,000,893 | ---- | C] () -- C:\Documents and Settings\Dolní\Plocha\EVEREST Ultimate Edition.lnk
[2011.12.02 18:50:32 | 000,026,143 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011.12.02 16:50:09 | 104,379,152 | ---- | C] () -- C:\Documents and Settings\Dolní\Plocha\setup_11.0.0.1245.x01_2011_12_02_18_18.exe
[2011.11.30 22:09:24 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011.11.30 22:09:23 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011.11.30 22:09:23 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011.11.30 22:09:23 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011.11.29 22:41:05 | 000,001,393 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011.11.29 19:42:12 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011.11.29 19:42:07 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2011.11.29 19:38:45 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011.11.27 22:31:49 | 000,000,410 | ---- | C] () -- C:\Documents and Settings\Dolní\Plocha\Zástupce - TestCPU.lnk
[2011.11.27 18:43:40 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2011.11.23 21:32:27 | 000,001,661 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\repository.xml
[2011.11.23 21:31:27 | 000,748,544 | ---- | C] () -- C:\WINDOWS\System32\protector.dll
[2011.11.18 18:27:33 | 000,000,929 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\ZoomBrowser EX.lnk
[2011.11.05 20:20:18 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\COMODO Firewall.lnk
[2011.11.01 20:26:03 | 000,000,211 | ---- | C] () -- C:\boot.ini.comodofirewall
[2011.10.28 18:13:41 | 000,000,720 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\AVG 2012.lnk
[2011.07.19 19:34:29 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\pool.bin
[2011.01.02 20:10:55 | 000,473,384 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2010.10.01 11:18:28 | 000,000,067 | ---- | C] () -- C:\WINDOWS\DVDIdle.INI
[2010.06.27 20:19:10 | 000,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\.zreglib
[2010.04.01 12:48:57 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2010.01.22 22:07:15 | 000,000,057 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009.12.30 13:06:29 | 000,135,168 | ---- | C] () -- C:\WINDOWS\AmCap5a.exe
[2009.12.30 13:06:29 | 000,004,604 | ---- | C] () -- C:\WINDOWS\ALIAS.INI
[2009.12.30 13:06:29 | 000,003,977 | ---- | C] () -- C:\WINDOWS\PV_Tuner.ini
[2009.12.30 13:06:29 | 000,003,450 | ---- | C] () -- C:\WINDOWS\FINETUNE.INI
[2009.12.30 13:06:29 | 000,003,107 | ---- | C] () -- C:\WINDOWS\REMAP.INI
[2009.12.30 13:06:29 | 000,003,073 | ---- | C] () -- C:\WINDOWS\frequency.ini
[2009.12.30 13:06:29 | 000,001,571 | ---- | C] () -- C:\WINDOWS\HOL.INI
[2009.12.30 13:06:29 | 000,001,115 | ---- | C] () -- C:\WINDOWS\AUS.INI
[2009.12.30 13:06:29 | 000,000,895 | ---- | C] () -- C:\WINDOWS\TAIWAN.INI
[2009.12.30 13:06:29 | 000,000,881 | ---- | C] () -- C:\WINDOWS\US.INI
[2009.12.30 13:06:29 | 000,000,875 | ---- | C] () -- C:\WINDOWS\ROMANIA-MSDN.INI
[2009.12.30 13:06:29 | 000,000,868 | ---- | C] () -- C:\WINDOWS\FRANCE.INI
[2009.12.30 13:06:29 | 000,000,817 | ---- | C] () -- C:\WINDOWS\OIRT.INI
[2009.12.30 13:06:29 | 000,000,751 | ---- | C] () -- C:\WINDOWS\IC.INI
[2009.12.30 13:06:29 | 000,000,711 | ---- | C] () -- C:\WINDOWS\FOT.INI
[2009.12.30 13:06:29 | 000,000,651 | ---- | C] () -- C:\WINDOWS\ANGOLA.INI
[2009.12.30 13:06:29 | 000,000,648 | ---- | C] () -- C:\WINDOWS\UK.INI
[2009.12.30 13:06:29 | 000,000,648 | ---- | C] () -- C:\WINDOWS\CCIR.INI
[2009.12.30 13:06:29 | 000,000,641 | ---- | C] () -- C:\WINDOWS\CHINA.INI
[2009.12.30 13:06:29 | 000,000,625 | ---- | C] () -- C:\WINDOWS\SA.INI
[2009.12.30 13:06:29 | 000,000,618 | ---- | C] () -- C:\WINDOWS\IR.INI
[2009.12.30 13:06:29 | 000,000,616 | ---- | C] () -- C:\WINDOWS\MO.INI
[2009.12.30 13:06:29 | 000,000,615 | ---- | C] () -- C:\WINDOWS\NZ.INI
[2009.12.30 13:06:29 | 000,000,615 | ---- | C] () -- C:\WINDOWS\NE.INI
[2009.12.30 13:06:29 | 000,000,607 | ---- | C] () -- C:\WINDOWS\IN.INI
[2009.12.30 13:06:29 | 000,000,602 | ---- | C] () -- C:\WINDOWS\ROMANIA.INI
[2009.12.30 13:06:29 | 000,000,587 | ---- | C] () -- C:\WINDOWS\JAPAN.INI
[2009.12.30 13:06:29 | 000,000,567 | ---- | C] () -- C:\WINDOWS\IT.INI
[2009.12.30 13:06:29 | 000,000,555 | ---- | C] () -- C:\WINDOWS\ISR.INI
[2009.12.30 13:06:29 | 000,000,481 | ---- | C] () -- C:\WINDOWS\RUSSIA.INI
[2009.12.13 14:43:18 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009.06.06 21:38:04 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009.06.02 19:19:18 | 000,001,123 | ---- | C] () -- C:\WINDOWS\mgreg.ini
[2009.06.02 19:19:04 | 000,000,030 | ---- | C] () -- C:\WINDOWS\mgwin.ini
[2009.05.31 12:40:38 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009.05.30 15:49:59 | 000,003,021 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2009.05.30 15:49:53 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009.05.30 14:46:36 | 000,004,692 | ---- | C] () -- C:\WINDOWS\WTRAN32.INI
[2009.05.30 12:18:08 | 000,000,410 | ---- | C] () -- C:\WINDOWS\ULead32.ini
[2009.05.30 10:41:08 | 000,010,240 | ---- | C] () -- C:\Documents and Settings\Dolní\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.05.30 10:22:24 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009.05.30 10:09:51 | 000,022,916 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009.05.30 10:02:36 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009.05.30 10:01:11 | 000,220,040 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008.08.19 16:39:57 | 000,000,016 | ---- | C] () -- C:\Program Files\Common Files\dht342126
[2008.04.14 06:16:08 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008.02.02 13:52:23 | 000,011,253 | -H-- | C] () -- C:\Program Files\folder.htt
[2006.12.31 04:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004.12.31 18:35:42 | 000,000,237 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2001.10.25 15:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001.10.25 15:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001.10.25 15:00:00 | 000,432,928 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001.10.25 15:00:00 | 000,429,454 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2001.10.25 15:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001.10.25 15:00:00 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2001.10.25 15:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001.10.25 15:00:00 | 000,078,466 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2001.10.25 15:00:00 | 000,067,884 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001.10.25 15:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001.10.25 15:00:00 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2001.10.25 15:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001.10.25 15:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.10.25 15:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2009.11.10 23:19:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\22718222
[2011.04.05 16:23:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\34186
[2010.04.14 00:02:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\53110717
[2011.11.05 19:42:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVG2012
[2011.11.23 21:31:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\bProtector
[2010.04.01 12:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Canneverbe Limited
[2011.10.28 18:13:13 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2011.12.02 16:30:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Fighters
[2011.09.01 19:54:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Kristanix Games
[2011.12.11 13:01:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2011.06.12 16:13:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PhotoStitch
[2011.07.19 19:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Research In Motion
[2011.11.11 17:28:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2011.01.23 17:58:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\aAvgApi
[2011.11.06 10:52:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\AVG Secure Search
[2011.10.28 21:28:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\AVG2012
[2011.07.03 16:29:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\bsbandmltbpi
[2011.09.04 19:06:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\Canneverbe Limited
[2011.11.23 22:17:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\file2linkib
[2011.10.13 20:26:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\Inbox Toolbar
[2011.01.09 15:30:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\Jpeg Resampler
[2011.11.06 10:52:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\mediabarbs
[2011.12.08 22:17:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\OpenOffice.org
[2011.05.22 12:56:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\Opera
[2011.07.25 13:11:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\Research In Motion
[2011.02.06 16:51:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Cernopolak\Data aplikací\Zoner
[2010.04.05 11:03:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\aAvgApi
[2011.10.30 21:11:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\AVG
[2011.10.28 18:13:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\AVG Secure Search
[2011.10.28 18:16:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\AVG2012
[2011.05.07 11:07:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\bsbandmltbpi
[2010.04.01 12:49:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Canneverbe Limited
[2011.11.23 21:30:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\file2linkib
[2011.06.25 16:00:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\mediabarbs
[2011.10.03 19:42:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\NeuroProgrammer3
[2011.12.07 22:25:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\OpenOffice.org
[2009.05.30 10:48:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Opera
[2011.11.23 21:45:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\PerformerSoft
[2009.05.30 12:11:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\ProfiCAD
[2009.06.28 16:10:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\QIP
[2011.09.02 23:26:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Research In Motion
[2011.09.01 19:50:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Rovio
[2009.07.12 19:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Zoner
[2011.10.30 22:05:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\AVG2012
[2011.07.28 13:55:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Data aplikací\Opera
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 05:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
"MSMSGS" = "C:\Program Files\Messenger\msmsgs.exe" /background -- [2008.04.14 07:52:38 | 001,695,232 | ---- | M] (Microsoft Corporation)
< >
< MD5 for: AGP440.SYS >
[2008.04.14 06:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008.04.14 06:10:02 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2008.04.14 06:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 05:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe
[2008.04.14 05:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2008.04.14 05:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\dllcache\autochk.exe
< MD5 for: CDROM.SYS >
[2008.04.14 06:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.13 21:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2008.04.14 05:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 05:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: CSRSS.EXE >
[2008.04.14 05:52:18 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\system32\csrss.exe
[2008.04.14 05:52:18 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\system32\dllcache\csrss.exe
< MD5 for: EVENTLOG.DLL >
[2008.04.14 05:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.14 05:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 05:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 05:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: FASTFAT.SYS >
[2008.04.13 21:44:30 | 000,143,744 | ---- | M] (Microsoft Corporation) MD5=38D332A6D56AF32635675F132548343E -- C:\WINDOWS\system32\dllcache\fastfat.sys
[2008.04.13 21:44:30 | 000,143,744 | ---- | M] (Microsoft Corporation) MD5=38D332A6D56AF32635675F132548343E -- C:\WINDOWS\system32\drivers\fastfat.sys
< MD5 for: HAL.DLL >
[2008.04.14 06:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.13 21:01:30 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2008.04.14 06:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
< MD5 for: IASTOR.SYS >
[2008.06.23 11:12:16 | 000,277,784 | ---- | M] (Intel Corporation) MD5=FD7F9D74C2B35DBDA400804A3F5ED5D8 -- C:\WINDOWS\NLDRV\001\iastor.sys
< MD5 for: ISAPNP.SYS >
[2008.04.14 06:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 04:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2008.04.14 05:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 05:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.13 21:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys
[2008.04.13 21:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.04.14 05:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008.04.14 05:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NTFS.SYS >
[2008.04.13 21:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\dllcache\ntfs.sys
[2008.04.13 21:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\drivers\ntfs.sys
[2004.08.03 23:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\cmdcons\NTFS.SYS
< MD5 for: SCECLI.DLL >
[2008.04.14 05:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 05:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SERVICES.EXE >
[2009.02.09 11:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009.02.09 11:25:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 11:25:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\services.exe
< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 05:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 05:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SPOOLSV.EXE >
[2010.08.17 14:19:36 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 -- C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\dllcache\spoolsv.exe
[2010.08.17 14:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\spoolsv.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 05:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.14 05:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.06.20 11:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 11:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 11:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 05:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 05:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2008.04.14 05:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 05:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.14 05:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2008.04.14 05:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< >
< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >
[2008.07.06 12:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008.07.06 12:06:10 | 000,147,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\x64\filterpipelineprintproc.dll
< %systemroot%\system32\drivers\*.sys /5 >
< %systemroot%\system32\drivers\*.sys /X >
[2002.07.17 07:53:02 | 000,016,877 | ---- | M] (Adaptec) -- C:\WINDOWS\system32\drivers\aspi32.BAK
[2001.10.25 15:00:00 | 003,440,660 | ---- | M] () -- C:\WINDOWS\system32\drivers\gm.dls
[2001.10.25 15:00:00 | 000,000,646 | ---- | M] () -- C:\WINDOWS\system32\drivers\gmreadme.txt
[2011.07.19 19:16:36 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2011.07.19 19:16:38 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\Msft_Kernel_RimUsb_01009.Wdf
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\system32\*.* /5 >
[2011.12.10 20:57:50 | 000,220,040 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2011.12.07 11:59:43 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\config\*.sav >
[2010.02.04 17:27:16 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.02.04 17:17:18 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2010.02.04 17:27:16 | 019,136,512 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.02.04 17:27:18 | 004,718,592 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\*.* /U /s >
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[22 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[12 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\Installer\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}\*.tmp files -> C:\WINDOWS\Installer\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[4 C:\WINDOWS\temp\*.tmp files -> C:\WINDOWS\temp\*.tmp -> ]
< %systemroot%\*. /mp /s >
< %ALLUSERSPROFILE%\Data Aplikací\*.* >
[2010.06.27 20:19:12 | 000,000,041 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\.zreglib
[2010.02.04 17:29:22 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\desktop.ini
[2011.11.23 21:32:28 | 000,001,661 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\repository.xml
< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
[2011.11.23 21:31:27 | 000,803,328 | ---- | M] (bProtector) -- C:\Documents and Settings\All Users\Data Aplikací\bProtector\bProtect.exe
[2011.06.30 09:37:06 | 000,198,984 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\ComodoCleanup.exe
[5 C:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\*.tmp files -> C:\Documents and Settings\All Users\Data Aplikací\Comodo\Installer\*.tmp -> ]
< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >
< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >
< %APPDATA%\*. >
[2010.04.05 11:03:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\aAvgApi
[2009.05.30 10:44:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Adobe
[2009.05.30 10:44:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\AdobeUM
[2011.10.30 21:11:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\AVG
[2011.10.28 18:13:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\AVG Secure Search
[2011.10.28 18:16:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\AVG2012
[2010.02.04 18:32:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\AVG8
[2011.05.07 11:07:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\bsbandmltbpi
[2010.04.01 12:49:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Canneverbe Limited
[2011.01.02 18:03:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\CANON INC
[2011.11.01 22:05:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Comodo
[2011.11.23 21:30:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\file2linkib
[2011.05.07 11:05:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Google
[2010.01.29 13:27:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Help
[2009.05.30 10:27:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Identities
[2009.05.30 11:28:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Macromedia
[2011.06.25 16:00:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\mediabarbs
[2011.10.28 17:52:49 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft
[2011.10.03 19:42:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\NeuroProgrammer3
[2010.07.24 19:17:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Norton Utilities 14
[2011.12.07 22:25:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\OpenOffice.org
[2009.05.30 10:48:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Opera
[2011.11.23 21:45:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\PerformerSoft
[2009.05.30 12:11:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\ProfiCAD
[2009.06.28 16:10:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\QIP
[2009.12.13 14:36:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Real
[2011.09.02 23:26:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Research In Motion
[2011.09.01 19:50:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Rovio
[2009.08.13 12:26:18 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Dolní\Data aplikací\SecuROM
[2011.08.09 22:22:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Skype
[2010.01.23 11:42:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\SkypeMate
[2011.08.08 20:46:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\skypePM
[2011.08.17 20:26:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Sun
[2009.06.20 13:09:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\WinRAR
[2009.07.12 19:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\Zoner
[2010.12.07 16:13:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dolní\Data aplikací\ZoomBrowser EX
< %APPDATA%\*.* >
[2011.09.02 23:27:18 | 000,000,954 | ---- | M] () -- C:\Documents and Settings\Dolní\Data aplikací\BBMS_EXCEPTION.txt
[2009.05.30 10:02:02 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Dolní\Data aplikací\desktop.ini
[2011.12.07 21:39:28 | 000,016,688 | ---- | M] () -- C:\Documents and Settings\Dolní\Data aplikací\GDIPFONTCACHEV1.DAT
< %APPDATA%\*.exe /s >
[2011.11.23 21:43:49 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_18be6784.exe
[2011.11.23 21:43:49 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_294823.exe
[2011.11.23 21:43:49 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_2cd672ae.exe
[2011.11.23 21:43:49 | 000,001,078 | R--- | M] () -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{0F9196C6-58B4-445B-B56E-B1200FECC151}\_4ae13d6c.exe
[2011.07.19 20:20:39 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}\ARPPRODUCTICON.exe
[2011.07.19 19:15:56 | 000,413,696 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{3E79F719-BE4A-4579-9FFF-559EF7A81AB4}\ARPPRODUCTICON.exe
[2011.07.19 19:15:56 | 000,069,632 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{3E79F719-BE4A-4579-9FFF-559EF7A81AB4}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
[2011.08.18 21:00:24 | 000,099,678 | R--- | M] () -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{E2B4FE1C-2CFA-47EE-A88C-A14D0FF1F0B0}\_FA1973C448F0CDEF5FD499.exe
[2011.07.19 19:32:50 | 000,069,632 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{F11E0BBC-5CB9-4D64-A942-6B64043BED97}\DesktopMgr.exe
[2011.07.19 19:32:50 | 000,069,632 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{F11E0BBC-5CB9-4D64-A942-6B64043BED97}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
[2011.07.19 19:32:51 | 000,069,632 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{F11E0BBC-5CB9-4D64-A942-6B64043BED97}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
[2011.07.19 19:32:51 | 000,069,632 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{F11E0BBC-5CB9-4D64-A942-6B64043BED97}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
[2011.07.19 19:32:51 | 000,069,632 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{F11E0BBC-5CB9-4D64-A942-6B64043BED97}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
[2011.07.19 19:32:51 | 000,069,632 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{F11E0BBC-5CB9-4D64-A942-6B64043BED97}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
[2011.07.19 19:32:51 | 000,069,632 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{F11E0BBC-5CB9-4D64-A942-6B64043BED97}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
[2011.07.19 19:32:51 | 000,069,632 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{F11E0BBC-5CB9-4D64-A942-6B64043BED97}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
[2011.07.19 19:32:50 | 000,049,152 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{F11E0BBC-5CB9-4D64-A942-6B64043BED97}\RedirectorEXE1_770DFD1204C24F4DA163D64FACCB5CBD.exe
[2011.07.19 19:32:51 | 000,049,152 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{F11E0BBC-5CB9-4D64-A942-6B64043BED97}\RedirectorEXE2_770DFD1204C24F4DA163D64FACCB5CBD.exe
[2011.07.19 19:32:50 | 000,049,152 | R--- | M] (Acresso Software Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Microsoft\Installer\{F11E0BBC-5CB9-4D64-A942-6B64043BED97}\RedirectorEXE_770DFD1204C24F4DA163D64FACCB5CBD.exe
[2010.05.27 20:58:48 | 000,439,816 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Real\Update\setup3.10\setup.exe
[2011.11.20 19:46:46 | 000,315,512 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Real\Update\UpgradeHelper\RealPlayer\9.00\rnupgagent.exe
[2011.12.04 19:08:21 | 000,315,512 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Dolní\Data aplikací\Real\Update\UpgradeHelper\RealPlayer\9.01\rnupgagent.exe
< %SYSTEMDRIVE%\*.exe >
< >
< >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >
"AUPowerManagement" = 0
"IncludeRecommendedUpdates" = 0
"AutoInstallMinorUpdates" = 0
"DetectionFrequencyEnabled" = 0
"NoAUAsDefaultShutdownOption" = 0
"NoAUShutdownOption" = 1
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-29 22:08:28
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS /s >
"StateIndex" = 0
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart\0\0
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
< >
< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2011.12.11 14:53:49 | 000,000,512 | ---- | M] () MD5=21954C6A813125BBE683D3259A510EAC -- C:\PhysicalMBR.bin
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Dolní\Plocha\Geologické epochy.psd:SummaryInformation
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D287FACF
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:157E1AD3
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4
< End of report >