Re: haveď v notebooku
Napsal: 12 led 2012 21:39
od Crosby.WX
nech sa páči...
OTL logfile created on: 12. 1. 2012 21:25:53 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Michal\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d. M. yyyy
447,20 Mb Total Physical Memory | 124,15 Mb Available Physical Memory | 27,76% Memory free
1,03 Gb Paging File | 0,66 Gb Available in Paging File | 63,71% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,53 Gb Total Space | 53,25 Gb Free Space | 71,45% Space Free | Partition Type: NTFS
Computer Name: ALLA | User Name: Michal | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2012.01.12 21:23:00 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Michal\My Documents\Downloads\OTL.exe
PRC - [2011.11.16 00:41:32 | 008,391,152 | ---- | M] (TeamSpeak Systems GmbH) -- C:\Program Files\TeamSpeak 3 Client\ts3client_win32.exe
PRC - [2011.10.20 20:45:48 | 001,036,344 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2008.04.13 19:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.07.05 16:53:44 | 001,040,384 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe
PRC - [2007.05.03 17:42:56 | 000,376,921 | ---- | M] (Atheros Communications, Inc.) -- C:\Program Files\Atheros\ACU.exe
PRC - [2007.05.03 17:42:38 | 000,364,629 | ---- | M] (Atheros) -- C:\WINDOWS\system32\acs.exe
========== Modules (No Company Name) ==========
MOD - [2011.11.16 00:41:32 | 000,229,360 | ---- | M] () -- C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win32.dll
MOD - [2011.11.16 00:41:28 | 007,859,200 | ---- | M] () -- C:\Program Files\TeamSpeak 3 Client\QtGui4.dll
MOD - [2011.11.16 00:41:28 | 002,210,816 | ---- | M] () -- C:\Program Files\TeamSpeak 3 Client\QtCore4.dll
MOD - [2011.11.16 00:41:28 | 000,814,080 | ---- | M] () -- C:\Program Files\TeamSpeak 3 Client\QtNetwork4.dll
MOD - [2011.11.16 00:41:28 | 000,421,360 | ---- | M] () -- C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll
MOD - [2011.11.16 00:41:28 | 000,195,584 | ---- | M] () -- C:\Program Files\TeamSpeak 3 Client\imageformats\qjpeg4.dll
MOD - [2011.11.16 00:41:28 | 000,158,704 | ---- | M] () -- C:\Program Files\TeamSpeak 3 Client\plugins\appscanner_plugin.dll
MOD - [2011.11.16 00:41:28 | 000,025,600 | ---- | M] () -- C:\Program Files\TeamSpeak 3 Client\imageformats\qgif4.dll
MOD - [2011.10.20 20:45:46 | 000,420,920 | ---- | M] () -- C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\15.0.874.102\ppgooglenaclpluginchrome.dll
MOD - [2011.10.20 20:45:45 | 003,702,840 | ---- | M] () -- C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\15.0.874.102\pdf.dll
MOD - [2011.10.20 20:44:09 | 000,122,952 | ---- | M] () -- C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\15.0.874.102\avutil-51.dll
MOD - [2011.10.20 20:44:08 | 000,222,280 | ---- | M] () -- C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\15.0.874.102\avformat-53.dll
MOD - [2011.10.20 20:44:07 | 001,745,992 | ---- | M] () -- C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\15.0.874.102\avcodec-53.dll
MOD - [2011.10.20 17:45:13 | 008,587,936 | ---- | M] () -- C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\15.0.874.102\gcswf32.dll
MOD - [2011.06.16 00:14:48 | 000,331,776 | ---- | M] () -- C:\Program Files\WinRAR\rarlng.dll
MOD - [2011.05.28 22:04:58 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2010.01.09 20:18:18 | 004,254,560 | ---- | M] () -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2007.07.05 16:53:44 | 001,040,384 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe
MOD - [2007.03.02 11:44:34 | 000,073,728 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2012.01.09 23:28:14 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011.06.25 22:45:56 | 000,256,000 | R--- | M] () [Auto | Stopped] -- C:\Beruska.com\pev.3XE -- (PEVSystemStart)
SRV - [2010.01.21 17:51:12 | 030,963,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2007.05.03 17:42:38 | 000,364,629 | ---- | M] (Atheros) [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)
SRV - [2003.04.18 19:06:26 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\srvany.exe -- (KMService)
========== Driver Services (SafeList) ==========
DRV - [2012.01.12 17:57:11 | 000,000,536 | -HS- | M] () [File_System | Unknown | Running] -- C:\WINDOWS\0696139drv.spi -- (0696139drv)
DRV - [2012.01.12 16:38:51 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\34845690.sys -- (34845690)
DRV - [2008.04.13 14:05:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2007.08.24 11:46:48 | 000,005,760 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)
DRV - [2007.07.04 22:55:40 | 002,304,000 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2007.05.02 19:00:58 | 000,546,976 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2007.03.28 19:52:18 | 000,057,024 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wsimd.sys -- (WSIMD)
DRV - [2006.12.14 16:44:06 | 000,085,120 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2006.11.03 09:32:00 | 004,394,496 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005.07.14 12:14:34 | 000,027,904 | ---- | M] (REDC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\risdptsk.sys -- (risdptsk)
DRV - [2005.07.12 19:00:30 | 000,051,328 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1644491937-1935655697-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1644491937-1935655697-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\15.0.874.102\gcswf32.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\15.0.874.102\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\15.0.874.102\pdf.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
O1 HOSTS File: ([2012.01.11 17:50:30 | 000,000,726 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [ACU] C:\Program Files\Atheros\ACU.exe (Atheros Communications, Inc.)
O4 - HKLM..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1644491937-1935655697-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1644491937-1935655697-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Od&oslať do programu OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{55D5C386-D030-43D0-A347-01FBA96655DF}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O21 - SSODL: Windows Task Services - C:\Documents and Settings\Michal\Application Data\33.exe - No CLSID value found.
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012.01.03 09:24:35 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{1d22c106-3775-11e1-8eff-0015af57abac}\Shell - "" = AutoRun
O33 - MountPoints2\{1d22c106-3775-11e1-8eff-0015af57abac}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1d22c106-3775-11e1-8eff-0015af57abac}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\1b37f31f.exe
O33 - MountPoints2\{1d22c106-3775-11e1-8eff-0015af57abac}\Shell\explore\command - "" = E:\RECYCLER\1b37f31f.exe
O33 - MountPoints2\{1d22c106-3775-11e1-8eff-0015af57abac}\Shell\open\command - "" = E:\RECYCLER\1b37f31f.exe
O33 - MountPoints2\{4f4b96b0-3677-11e1-8efc-0015af57abac}\Shell - "" = AutoRun
O33 - MountPoints2\{4f4b96b0-3677-11e1-8efc-0015af57abac}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4f4b96b0-3677-11e1-8efc-0015af57abac}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
CREATERESTOREPOINT
Error creating restore point.
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2012.01.12 18:36:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michal\My Documents\VIDEO_TS
[2012.01.12 17:32:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012.01.12 17:32:20 | 000,133,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\34845690.sys
[2012.01.12 17:28:22 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Michal\Recent
[2012.01.12 15:33:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2012.01.12 14:22:42 | 000,000,000 | --SD | C] -- C:\Beruska.com
[2012.01.12 14:21:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2012.01.11 22:46:13 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012.01.11 22:44:42 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012.01.11 22:44:42 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012.01.11 22:44:42 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012.01.11 22:44:42 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012.01.11 22:44:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012.01.11 22:44:32 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.01.11 22:44:30 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Michal\Start Menu\Programs\Administrative Tools
[2012.01.11 22:31:39 | 004,377,322 | R--- | C] (Swearware) -- C:\Documents and Settings\Michal\Desktop\Beruska.com.exe
[2012.01.11 18:06:27 | 001,972,528 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Michal\Desktop\tdsskiller.exe
[2012.01.10 20:41:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michal\Start Menu\Programs\WinRAR
[2012.01.10 20:41:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
[2012.01.09 23:43:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2012.01.09 23:43:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michal\Local Settings\Application Data\Adobe
[2012.01.09 23:37:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2012.01.09 23:36:56 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012.01.09 23:28:52 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2012.01.09 23:28:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
[2012.01.09 23:27:09 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2012.01.09 23:02:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SharePoint
[2012.01.09 23:02:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
[2012.01.09 23:02:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2012.01.09 23:02:13 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2012.01.09 23:00:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework
[2012.01.09 23:00:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Microsoft
[2012.01.09 22:59:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2012.01.09 22:58:08 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
[2012.01.09 22:57:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2012.01.09 22:57:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michal\Local Settings\Application Data\Microsoft Help
[2012.01.09 22:57:00 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012.01.09 22:56:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2012.01.09 22:56:41 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2012.01.09 12:43:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michal\Desktop\Songy
[2012.01.09 12:10:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michal\Application Data\AVG
[2012.01.09 12:09:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012.01.09 12:09:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup 2011
[2012.01.09 12:09:07 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2012.01.09 11:53:19 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.01.09 11:53:16 | 000,000,000 | ---D | C] -- C:\rsit
[2012.01.09 11:29:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michal\Application Data\Malwarebytes
[2012.01.09 11:28:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.01.09 11:28:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012.01.09 11:28:31 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012.01.09 11:28:31 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.01.06 13:56:05 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Michal\My Documents\My Movies
[2012.01.06 01:13:18 | 000,000,000 | ---D | C] -- C:\Program Files\Elaborate Bytes
[2012.01.06 01:13:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Elaborate Bytes
[2012.01.06 01:08:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2012.01.06 01:08:03 | 000,000,000 | ---D | C] -- C:\Program Files\DVD Shrink
[2012.01.06 01:08:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DVD Shrink
[2012.01.06 00:47:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michal\Application Data\WinRAR
[2012.01.06 00:46:52 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 7 Days ==========
[2012.01.12 21:27:29 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.01.12 21:20:32 | 000,156,371 | ---- | M] () -- C:\Documents and Settings\Michal\My Documents\mucinko hotovo copy.jpg
[2012.01.12 21:20:20 | 004,605,679 | ---- | M] () -- C:\Documents and Settings\Michal\My Documents\mucinko hotovo.psd
[2012.01.12 21:04:37 | 001,320,979 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\beautiful-tree-wallpapers_28076_2560x1600.jpg
[2012.01.12 20:59:57 | 000,170,375 | ---- | M] () -- C:\Documents and Settings\Michal\My Documents\mucinko render.psd
[2012.01.12 20:59:33 | 000,054,503 | ---- | M] () -- C:\Documents and Settings\Michal\My Documents\mucinko render.png
[2012.01.12 20:47:32 | 000,193,502 | ---- | M] () -- C:\Documents and Settings\Michal\My Documents\mucinko copy.png
[2012.01.12 20:39:29 | 001,757,094 | ---- | M] () -- C:\Documents and Settings\Michal\My Documents\mucinko.psd
[2012.01.12 19:53:17 | 000,071,671 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\310816_211036362285068_100001361168147_512496_5434136_n.jpg
[2012.01.12 19:50:28 | 000,034,467 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\bean3.jpg
[2012.01.12 19:29:01 | 000,052,574 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\Bane_The_Dark_Knight_Rises.jpg
[2012.01.12 17:57:11 | 000,000,536 | -HS- | M] () -- C:\WINDOWS\0696139drv.spi
[2012.01.12 17:31:53 | 000,000,426 | ---- | M] () -- C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Start On Michal Logon.job
[2012.01.12 17:30:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.01.12 17:26:44 | 000,051,186 | ---- | M] () -- C:\Documents and Settings\Michal\Application Data\room_v3.dat
[2012.01.12 16:38:51 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\34845690.sys
[2012.01.12 16:21:22 | 000,000,064 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\keyset.dat
[2012.01.12 15:02:12 | 113,005,472 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\setup_11.0.0.1245.x01_2012_01_12_16_38.exe
[2012.01.11 22:46:18 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012.01.11 22:32:06 | 004,377,322 | R--- | M] (Swearware) -- C:\Documents and Settings\Michal\Desktop\Beruska.com.exe
[2012.01.11 18:06:32 | 001,972,528 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Michal\Desktop\tdsskiller.exe
[2012.01.11 17:50:38 | 000,111,872 | ---- | M] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2012.01.11 17:44:15 | 000,782,336 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\RogueKiller.exe
[2012.01.11 17:43:58 | 000,458,240 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\CKScanner.exe
[2012.01.11 16:27:24 | 000,000,085 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2012.01.11 15:14:42 | 000,000,670 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\DVD Shrink 3.2.lnk
[2012.01.11 14:19:01 | 000,005,120 | ---- | M] () -- C:\Documents and Settings\Michal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.10 23:16:04 | 000,043,388 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\untitled.JPG
[2012.01.10 00:11:30 | 001,565,328 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.01.09 23:42:23 | 000,000,848 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\Photoshop.lnk
[2012.01.09 23:40:10 | 000,034,308 | ---- | M] () -- C:\WINDOWS\System32\BASSMOD.dll
[2012.01.09 12:09:12 | 000,000,830 | ---- | M] () -- C:\Documents and Settings\Michal\Desktop\AVG PC Tuneup 2011.lnk
[2012.01.09 11:28:35 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.06 15:28:38 | 000,000,754 | ---- | M] () -- C:\WINDOWS\WORDPAD.INI
[2012.01.06 01:13:22 | 000,000,852 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CloneDVD2.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.01.12 21:27:29 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.01.12 21:20:27 | 000,156,371 | ---- | C] () -- C:\Documents and Settings\Michal\My Documents\mucinko hotovo copy.jpg
[2012.01.12 21:20:18 | 004,605,679 | ---- | C] () -- C:\Documents and Settings\Michal\My Documents\mucinko hotovo.psd
[2012.01.12 21:04:43 | 001,320,979 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\beautiful-tree-wallpapers_28076_2560x1600.jpg
[2012.01.12 20:59:56 | 000,170,375 | ---- | C] () -- C:\Documents and Settings\Michal\My Documents\mucinko render.psd
[2012.01.12 20:59:29 | 000,054,503 | ---- | C] () -- C:\Documents and Settings\Michal\My Documents\mucinko render.png
[2012.01.12 20:47:20 | 000,193,502 | ---- | C] () -- C:\Documents and Settings\Michal\My Documents\mucinko copy.png
[2012.01.12 20:39:22 | 001,757,094 | ---- | C] () -- C:\Documents and Settings\Michal\My Documents\mucinko.psd
[2012.01.12 19:53:19 | 000,071,671 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\310816_211036362285068_100001361168147_512496_5434136_n.jpg
[2012.01.12 19:50:35 | 000,034,467 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\bean3.jpg
[2012.01.12 19:31:26 | 000,052,574 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\Bane_The_Dark_Knight_Rises.jpg
[2012.01.12 17:57:09 | 000,000,536 | -HS- | C] () -- C:\WINDOWS\0696139drv.spi
[2012.01.12 14:53:25 | 113,005,472 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\setup_11.0.0.1245.x01_2012_01_12_16_38.exe
[2012.01.11 22:46:18 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2012.01.11 22:46:16 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012.01.11 22:44:42 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012.01.11 22:44:42 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012.01.11 22:44:42 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012.01.11 22:44:42 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012.01.11 22:44:42 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012.01.11 17:49:29 | 000,111,872 | ---- | C] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2012.01.11 17:44:14 | 000,782,336 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\RogueKiller.exe
[2012.01.11 17:43:57 | 000,458,240 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\CKScanner.exe
[2012.01.10 23:16:03 | 000,043,388 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\untitled.JPG
[2012.01.09 23:42:23 | 000,000,848 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\Photoshop.lnk
[2012.01.09 23:40:10 | 000,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2012.01.09 23:39:04 | 000,000,856 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Photoshop CS3.lnk
[2012.01.09 23:36:03 | 000,000,942 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Stock Photos CS3.lnk
[2012.01.09 23:33:42 | 000,001,100 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe ExtendScript Toolkit 2.lnk
[2012.01.09 23:33:02 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Device Central CS3.lnk
[2012.01.09 23:29:52 | 000,000,818 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Bridge CS3.lnk
[2012.01.09 23:05:41 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\srvany.exe
[2012.01.09 21:23:38 | 000,610,547 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\norway-fishing-holiday-1920x1080.jpg
[2012.01.09 12:09:18 | 000,000,426 | ---- | C] () -- C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Start On Michal Logon.job
[2012.01.09 12:09:12 | 000,000,830 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\AVG PC Tuneup 2011.lnk
[2012.01.09 11:28:35 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012.01.06 15:28:38 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2012.01.06 01:13:57 | 000,000,085 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2012.01.06 01:13:22 | 000,000,852 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CloneDVD2.lnk
[2012.01.06 01:08:04 | 000,000,670 | ---- | C] () -- C:\Documents and Settings\Michal\Desktop\DVD Shrink 3.2.lnk
[2012.01.04 23:49:29 | 000,012,906 | ---- | C] () -- C:\Documents and Settings\Michal\Application Data\113.exe
[2012.01.04 23:49:27 | 000,012,906 | ---- | C] () -- C:\Documents and Settings\Michal\Application Data\111.exe
[2012.01.04 23:49:24 | 000,012,887 | ---- | C] () -- C:\Documents and Settings\Michal\Application Data\10F.exe
[2012.01.04 14:55:10 | 000,012,906 | ---- | C] () -- C:\Documents and Settings\Michal\Application Data\7.exe
[2012.01.03 22:50:54 | 000,051,186 | ---- | C] () -- C:\Documents and Settings\Michal\Application Data\room_v3.dat
[2012.01.03 18:26:43 | 000,078,816 | ---- | C] () -- C:\WINDOWS\War3Unin.dat
[2012.01.03 17:54:21 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\Michal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.01.03 09:42:08 | 000,037,232 | ---- | C] () -- C:\WINDOWS\ASScrProlog.exe
[2012.01.03 09:42:06 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2012.01.03 09:27:30 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012.01.03 09:20:30 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012.01.03 01:06:34 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012.01.03 01:04:57 | 001,565,328 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012.01.03 00:44:24 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008.04.13 19:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2007.08.24 11:46:48 | 000,005,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\ATKACPI.sys
[2007.07.04 22:28:08 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2007.07.04 22:28:08 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2007.07.04 22:28:08 | 000,972,072 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2007.06.05 13:40:44 | 000,149,278 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006.12.30 21:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001.08.18 03:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001.08.18 03:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001.08.18 03:00:00 | 000,455,710 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001.08.18 03:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001.08.18 03:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001.08.18 03:00:00 | 000,075,684 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001.08.18 03:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001.08.18 03:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001.08.18 03:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001.08.18 03:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2012.01.12 14:45:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger
[2012.01.12 17:31:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012.01.09 22:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\AVG
[2012.01.12 15:49:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\GarenaPlus
[2012.01.12 18:39:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\TS3Client
[2012.01.12 17:31:53 | 000,000,426 | ---- | M] () -- C:\WINDOWS\Tasks\AVG PC Tuneup 2011 Integrator Start On Michal Logon.job
========== Purity Check ==========
========== Custom Scans ==========
< >
< >
< MD5 for: AGP440.SYS >
[2008.04.13 19:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2008.04.13 19:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.13 16:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.13 19:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\cmdcons\autochk.exe
[2008.04.13 19:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\autochk.exe
[2008.04.13 19:42:14 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=23043C91A0F9DFB4B9E9F87B680863B4 -- C:\WINDOWS\system32\dllcache\autochk.exe
< MD5 for: CDROM.SYS >
[2008.04.13 19:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.13 14:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2008.04.13 19:41:52 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=3D4E199942E29207970E04315D02AD3B -- C:\WINDOWS\system32\cryptsvc.dll
[2008.04.13 19:41:52 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=3D4E199942E29207970E04315D02AD3B -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.13 19:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.13 19:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.13 19:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008.04.13 19:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2008.04.13 19:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.13 14:01:30 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2008.04.13 19:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
< MD5 for: IASTOR.SYS >
[2008.12.14 08:42:56 | 000,308,248 | ---- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F -- C:\WINDOWS\NLDRV\004\iastor.sys
< MD5 for: ISAPNP.SYS >
[2008.04.13 19:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.13 14:06:42 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=05A299EC56E52649B1CF2FC52D20F2D7 -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2008.04.13 19:42:26 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.13 19:42:26 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=BF2466B3E18E970D8A976FB95FC1CA85 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.13 14:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys
[2008.04.13 14:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.04.13 19:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008.04.13 19:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NVATABUS.SYS >
[2008.12.14 08:42:53 | 000,079,360 | ---- | M] (NVIDIA Corporation) MD5=46DEED4C6C5FA765F9A2C723BE60348D -- C:\WINDOWS\NLDRV\003\nvatabus.sys
[2008.12.14 08:42:50 | 000,105,344 | ---- | M] (NVIDIA Corporation) MD5=DC1F9954B5EDDD147AF7E5C420BE7B93 -- C:\WINDOWS\NLDRV\002\nvatabus.sys
< MD5 for: NVGTS.SYS >
[2008.12.14 08:43:08 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=37954CD1D0AFC11BECD149F7C3EC88C2 -- C:\WINDOWS\NLDRV\005\nvgts.sys
[2008.12.14 08:43:19 | 000,132,096 | ---- | M] (NVIDIA Corporation) MD5=A117466B0ACB13288DEEE4F2E936E67F -- C:\WINDOWS\NLDRV\007\nvgts.sys
[2008.12.14 08:43:13 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E -- C:\WINDOWS\NLDRV\006\nvgts.sys
< MD5 for: NVRAID.SYS >
[2008.12.14 08:42:51 | 000,089,216 | ---- | M] (NVIDIA Corporation) MD5=9DCD6FDD6A84C4C466BAA88AB7FCE163 -- C:\WINDOWS\NLDRV\002\nvraid.sys
[2008.12.14 08:42:53 | 000,068,224 | ---- | M] (NVIDIA Corporation) MD5=A5C77D944410FADEE380FB20B432760D -- C:\WINDOWS\NLDRV\003\nvraid.sys
< MD5 for: NVRD32.SYS >
[2008.12.14 08:43:11 | 000,133,152 | ---- | M] (NVIDIA Corporation) MD5=BEF704AA9E17D176A46DDF77C6A52194 -- C:\WINDOWS\NLDRV\005\nvrd32.sys
< MD5 for: SCECLI.DLL >
[2008.04.13 19:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.13 19:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2008.04.13 19:42:38 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\system32\dllcache\smss.exe
[2008.04.13 19:42:38 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=5F816C1F539266D2D4C78694239DA0B5 -- C:\WINDOWS\system32\smss.exe
[2004.08.04 00:56:58 | 000,152,576 | ---- | M] (Microsoft Corporation) MD5=DA5CF1C368B33D75602FD6B3A7F5E0C6 -- C:\cmdcons\SYSTEM32\SMSS.EXE
< MD5 for: SVCHOST.EXE >
[2008.04.13 19:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.13 19:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2011.12.24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.04.13 14:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.04.13 14:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.13 19:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.13 19:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: VIAMRAID.SYS >
[2008.12.14 08:42:49 | 000,114,944 | ---- | M] (VIA Technologies inc,.ltd) MD5=1B7B0954AF54E716F697C511D68C150E -- C:\WINDOWS\NLDRV\001\viamraid.sys
< MD5 for: WINLOGON.EXE >
[2011.12.24 17:50:20 | 000,182,856 | ---- | M] () MD5=B382935AB01B27D0E14F267DBF288896 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.04.13 19:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.13 19:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.13 19:42:12 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2008.04.13 19:42:12 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
[2012.01.09 23:37:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2012.01.03 09:43:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Atheros
[2012.01.11 15:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2012.01.09 23:43:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2012.01.12 14:45:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GarenaMessenger
[2012.01.09 11:28:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012.01.09 23:00:56 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2012.01.09 23:04:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2012.01.12 17:31:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2012.01.12 20:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\Adobe
[2012.01.09 22:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\AVG
[2012.01.12 15:49:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\GarenaPlus
[2012.01.03 09:33:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\Identities
[2012.01.03 09:39:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\InstallShield
[2012.01.03 09:42:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\Macromedia
[2012.01.09 11:29:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\Malwarebytes
[2012.01.10 21:24:52 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Michal\Application Data\Microsoft
[2012.01.12 18:39:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\TS3Client
[2012.01.03 20:45:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\U3
[2012.01.04 14:17:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\vlc
[2012.01.06 00:48:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michal\Application Data\WinRAR
< %APPDATA%\*.exe /s >
[2012.01.04 23:49:24 | 000,012,887 | ---- | M] () -- C:\Documents and Settings\Michal\Application Data\10F.exe
[2012.01.04 23:49:27 | 000,012,906 | ---- | M] () -- C:\Documents and Settings\Michal\Application Data\111.exe
[2012.01.04 23:49:29 | 000,012,906 | ---- | M] () -- C:\Documents and Settings\Michal\Application Data\113.exe
[2012.01.04 14:55:10 | 000,012,906 | ---- | M] () -- C:\Documents and Settings\Michal\Application Data\7.exe
[2012.01.03 00:51:36 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{0AD37499-3D5D-12F0-EBEA-46EE9AD02DBF}\ARPPRODUCTICON.exe
[2012.01.03 00:51:57 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{174D7CC5-1117-29D3-8422-2E54ADF7DB5D}\ARPPRODUCTICON.exe
[2012.01.03 00:52:43 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{23894154-0961-CD0A-BAC0-67E6E96165C3}\ARPPRODUCTICON.exe
[2012.01.03 00:52:30 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{24DFAAD6-E1ED-F588-2AD5-2EA4FE9113AE}\ARPPRODUCTICON.exe
[2012.01.03 00:52:26 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{26886987-D038-7438-8DF2-ED3B1888E052}\ARPPRODUCTICON.exe
[2012.01.03 00:51:40 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{2C6D0ACD-DD2B-BFE5-A005-53AFD4AA3175}\ARPPRODUCTICON.exe
[2012.01.03 00:51:46 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{2D50DC1F-FCEC-D970-1DFB-E73CF2404451}\ARPPRODUCTICON.exe
[2012.01.03 00:52:42 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{306682DE-BB8E-CD56-9F6B-DE209469418A}\ARPPRODUCTICON.exe
[2012.01.03 00:52:39 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{310477AD-884B-736D-B2C8-7BE9433B243D}\ARPPRODUCTICON.exe
[2012.01.03 00:52:19 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{31814F2E-FA58-AFE8-DC97-3BD97F7191C2}\ARPPRODUCTICON.exe
[2012.01.03 00:52:18 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{354F7470-D8E3-95D0-3488-B9E32D5E9636}\ARPPRODUCTICON.exe
[2012.01.03 00:51:48 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{380FAC97-C47F-C5A9-2A51-DFF8DE144B37}\ARPPRODUCTICON.exe
[2012.01.03 00:52:35 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{407A5080-4B1C-A43D-9EED-A3B5EDBCF593}\ARPPRODUCTICON.exe
[2012.01.03 00:52:05 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{46FE06BF-2A08-9D00-ABFD-7F967817E275}\ARPPRODUCTICON.exe
[2012.01.03 00:51:18 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{4B50D80D-A482-DECD-B584-EB054EBA878A}\ARPPRODUCTICON.exe
[2012.01.03 00:51:54 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{5ABA84ED-D61B-257F-809F-A8C883865854}\ARPPRODUCTICON.exe
[2012.01.03 00:51:42 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{5B464CAC-76BD-BDBB-8066-318D05D171DF}\ARPPRODUCTICON.exe
[2012.01.03 00:51:59 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{5C7332EA-BFB9-24A0-BDD9-254F4B113E41}\ARPPRODUCTICON.exe
[2012.01.03 00:52:10 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{66B5F542-952C-F50D-BFF3-BCA582B65860}\ARPPRODUCTICON.exe
[2012.01.03 00:52:28 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{67213BA8-70C6-458D-9B64-4B93FB35E84B}\ARPPRODUCTICON.exe
[2012.01.03 00:52:33 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{6AA66ACB-E93C-C7CD-F303-D473AEC8A43E}\ARPPRODUCTICON.exe
[2012.01.03 00:51:50 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{6D5DC54D-B06E-32A8-A5D9-4978D7A75FA1}\ARPPRODUCTICON.exe
[2012.01.03 00:52:22 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{782BC438-2C73-77F4-F5B6-7ADC87F611BB}\ARPPRODUCTICON.exe
[2012.01.03 00:52:32 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{7BBA76B4-CC34-0AAB-6D48-BE0181E20832}\ARPPRODUCTICON.exe
[2012.01.03 00:52:03 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{7F311276-1CD6-1661-8BAE-DD9016FE9B8D}\ARPPRODUCTICON.exe
[2012.01.03 00:51:38 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{84C89CF4-F64E-6820-375C-24963DDF99C9}\ARPPRODUCTICON.exe
[2012.01.03 00:52:29 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{8C0D145D-EB41-E1DB-6250-0146B02CBA3A}\ARPPRODUCTICON.exe
[2012.01.03 00:52:25 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{8F5D6849-1A7E-B0B2-F1DE-C0FF21F9E78C}\ARPPRODUCTICON.exe
[2012.01.03 00:52:01 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{944DA8EF-FD4E-1FD9-D88A-B22D78913BE6}\ARPPRODUCTICON.exe
[2012.01.03 00:51:44 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{97F5E039-D2F5-18C0-F0C9-6981F73514CC}\ARPPRODUCTICON.exe
[2012.01.03 00:52:21 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{A35D49A6-F3CF-87AA-6FF1-777D8A06BAB1}\ARPPRODUCTICON.exe
[2012.01.03 00:52:14 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{B2CEACB9-7690-30B5-D80A-B138DB4F0E37}\ARPPRODUCTICON.exe
[2012.01.03 00:52:37 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{D26970AA-C66F-142F-7C66-A73FC3546F57}\ARPPRODUCTICON.exe
[2012.01.03 00:52:07 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{D88DB576-0989-879A-38B1-7ED6224B2F52}\ARPPRODUCTICON.exe
[2012.01.03 00:52:17 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{D8B87EBC-12C2-D4FC-F085-A062D4906216}\ARPPRODUCTICON.exe
[2012.01.03 00:52:24 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{E2A05D36-56EF-84FC-E7D7-090D6E5F09BC}\ARPPRODUCTICON.exe
[2012.01.03 00:51:52 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{E4DA4D2C-F57F-782E-752E-9286E5713297}\ARPPRODUCTICON.exe
[2012.01.03 00:52:36 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{E4E118EF-5286-915B-7DBD-D931AB9AF200}\ARPPRODUCTICON.exe
[2012.01.03 00:52:45 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{E5B85BE7-55B5-0A14-7634-FEF92BCB87FB}\ARPPRODUCTICON.exe
[2012.01.03 00:52:12 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{F384BD83-C317-94DA-A4AB-3E75E43F4F8C}\ARPPRODUCTICON.exe
[2012.01.03 00:52:40 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{F622BE4A-363F-F2B6-1F98-54E5E99B1750}\ARPPRODUCTICON.exe
[2012.01.03 00:52:15 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Michal\Application Data\Microsoft\Installer\{F6D39840-BB27-A191-BDF2-1841CA805D24}\ARPPRODUCTICON.exe
[2007.10.23 09:27:20 | 000,110,592 | ---- | M] () -- C:\Documents and Settings\Michal\Application Data\U3\temp\cleanup.exe
[2008.05.02 10:41:48 | 003,493,888 | -H-- | M] (SanDisk Corporation) -- C:\Documents and Settings\Michal\Application Data\U3\temp\Launchpad Removal.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2012.01.03 01:03:56 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2012.01.03 01:03:56 | 001,089,536 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2012.01.03 01:03:55 | 000,921,600 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
[2012.01.12 16:38:51 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) -- C:\WINDOWS\system32\drivers\34845690.sys
[2012.01.11 17:50:38 | 000,111,872 | ---- | M] () -- C:\WINDOWS\system32\drivers\TrueSight.sys
< %systemroot%\system32\*.* /3 >
[2012.01.09 23:40:10 | 000,034,308 | ---- | M] () -- C:\WINDOWS\system32\BASSMOD.dll
[2012.01.10 00:11:30 | 001,565,328 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]
"" =
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.01.12 21:27:29 | 000,000,512 | ---- | M] () MD5=421298B565E27DB289CF478C9A72786E -- C:\PhysicalMBR.bin
========== Alternate Data Streams ==========
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >
OTL Extras logfile created on: 12. 1. 2012 21:25:53 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Michal\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d. M. yyyy
447,20 Mb Total Physical Memory | 124,15 Mb Available Physical Memory | 27,76% Memory free
1,03 Gb Paging File | 0,66 Gb Available in Paging File | 63,71% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,53 Gb Total Space | 53,25 Gb Free Space | 71,45% Space Free | Partition Type: NTFS
Computer Name: ALLA | User Name: Michal | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_USERS\S-1-5-21-1644491937-1935655697-1417001333-1003\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Garena Plus\Room\garena_room.exe" = C:\Program Files\Garena Plus\Room\garena_room.exe:*:Enabled:Garena -- (Garena Online PTE LTD)
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003C932A-0064-B581-3935-284D2CE76A89}" = Catalyst Control Center Core Implementation
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0AD37499-3D5D-12F0-EBEA-46EE9AD02DBF}" = Catalyst Control Center Localization German
"{174D7CC5-1117-29D3-8422-2E54ADF7DB5D}" = Catalyst Control Center Localization Norwegian
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1E0E1039-E45D-7EA2-E377-E00C2857E0C2}" = ccc-core-static
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21A1D4A5-3D9B-9434-4F97-40367BDF4E47}" = Catalyst Control Center Graphics Full New
"{23894154-0961-CD0A-BAC0-67E6E96165C3}" = CCC Help Chinese Standard
"{24DFAAD6-E1ED-F588-2AD5-2EA4FE9113AE}" = CCC Help Korean
"{26886987-D038-7438-8DF2-ED3B1888E052}" = CCC Help Hungarian
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2C6D0ACD-DD2B-BFE5-A005-53AFD4AA3175}" = Catalyst Control Center Localization Spanish
"{2D50DC1F-FCEC-D970-1DFB-E73CF2404451}" = Catalyst Control Center Localization Hungarian
"{306682DE-BB8E-CD56-9F6B-DE209469418A}" = CCC Help Turkish
"{310477AD-884B-736D-B2C8-7BE9433B243D}" = CCC Help Swedish
"{31814F2E-FA58-AFE8-DC97-3BD97F7191C2}" = CCC Help Greek
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{354F7470-D8E3-95D0-3488-B9E32D5E9636}" = CCC Help German
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{380FAC97-C47F-C5A9-2A51-DFF8DE144B37}" = Catalyst Control Center Localization Italian
"{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}" = ATK Hotkey
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{407A5080-4B1C-A43D-9EED-A3B5EDBCF593}" = CCC Help Polish
"{4462AD13-F2AA-4CBD-9F95-293C38EED870}" = Power4 Gear
"{46FE06BF-2A08-9D00-ABFD-7F967817E275}" = Catalyst Control Center Localization Swedish
"{4B50D80D-A482-DECD-B584-EB054EBA878A}" = ccc-core-preinstall
"{4B8ACECB-D518-99AA-B1F3-E79F905A83EE}" = Catalyst Control Center Localization Czech
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5ABA84ED-D61B-257F-809F-A8C883865854}" = Catalyst Control Center Localization Dutch
"{5B464CAC-76BD-BDBB-8066-318D05D171DF}" = Catalyst Control Center Localization Finnish
"{5C7332EA-BFB9-24A0-BDD9-254F4B113E41}" = Catalyst Control Center Localization Polish
"{6426C1E8-ADD6-F91F-C152-2ABB7AB25F9F}" = Catalyst Control Center Graphics Full Existing
"{66B5F542-952C-F50D-BFF3-BCA582B65860}" = Catalyst Control Center Localization Turkish
"{67213BA8-70C6-458D-9B64-4B93FB35E84B}" = CCC Help Italian
"{6AA66ACB-E93C-C7CD-F303-D473AEC8A43E}" = CCC Help Norwegian
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6D5DC54D-B06E-32A8-A5D9-4978D7A75FA1}" = Catalyst Control Center Localization Japanese
"{6DC712D0-A8AE-70EE-215D-ECE5DB29782C}" = Skins
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{782BC438-2C73-77F4-F5B6-7ADC87F611BB}" = CCC Help Spanish
"{791A19F4-E4E5-F4B0-7687-F5D1C4FF799A}" = Catalyst Control Center Graphics Light
"{7BBA76B4-CC34-0AAB-6D48-BE0181E20832}" = CCC Help Dutch
"{7F311276-1CD6-1661-8BAE-DD9016FE9B8D}" = Catalyst Control Center Localization Russian
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{83F73CB1-7705-49D1-9852-84D839CA2A45}" = Wireless Console 2
"{84C89CF4-F64E-6820-375C-24963DDF99C9}" = Catalyst Control Center Localization Greek
"{8C0D145D-EB41-E1DB-6250-0146B02CBA3A}" = CCC Help Japanese
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8F5D6849-1A7E-B0B2-F1DE-C0FF21F9E78C}" = CCC Help French
"{90140000-0010-041B-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Slovak) 14
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-041B-0000-0000000FF1CE}" = Microsoft Office Access MUI (Slovak) 2010
"{90140000-0016-041B-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Slovak) 2010
"{90140000-0018-041B-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Slovak) 2010
"{90140000-0019-041B-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Slovak) 2010
"{90140000-001A-041B-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Slovak) 2010
"{90140000-001B-041B-0000-0000000FF1CE}" = Microsoft Office Word MUI (Slovak) 2010
"{90140000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2010
"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040E-0000-0000000FF1CE}" = Microsoft Office Proof (Hungarian) 2010
"{90140000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2010
"{90140000-002C-041B-0000-0000000FF1CE}" = Microsoft Office Proofing (Slovak) 2010
"{90140000-0044-041B-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Slovak) 2010
"{90140000-006E-041B-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Slovak) 2010
"{90140000-00A1-041B-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Slovak) 2010
"{90140000-00BA-041B-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Slovak) 2010
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{944DA8EF-FD4E-1FD9-D88A-B22D78913BE6}" = Catalyst Control Center Localization Portuguese
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{97F5E039-D2F5-18C0-F0C9-6981F73514CC}" = Catalyst Control Center Localization French
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9D48531D-2135-49FC-BC29-ACCDA5396A76}" = ASUS MultiFrame
"{9E684286-287F-AE06-6909-31A0944A9B4F}" = Catalyst Control Center Localization Danish
"{A0CE9CC5-B17D-3FD5-20B9-A2509B475A20}" = ccc-utility
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A35D49A6-F3CF-87AA-6FF1-777D8A06BAB1}" = CCC Help English
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{B2CEACB9-7690-30B5-D80A-B138DB4F0E37}" = Catalyst Control Center Localization Chinese Traditional
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{C0FC1C14-4824-4A73-87A6-9E888C9C3102}" = ASUS Splendid Video Enhancement Technology
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D26970AA-C66F-142F-7C66-A73FC3546F57}" = CCC Help Russian
"{D88DB576-0989-879A-38B1-7ED6224B2F52}" = Catalyst Control Center Localization Thai
"{D8B87EBC-12C2-D4FC-F085-A062D4906216}" = CCC Help Danish
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E2A05D36-56EF-84FC-E7D7-090D6E5F09BC}" = CCC Help Finnish
"{E4DA4D2C-F57F-782E-752E-9286E5713297}" = Catalyst Control Center Localization Korean
"{E4E118EF-5286-915B-7DBD-D931AB9AF200}" = CCC Help Portuguese
"{E5B85BE7-55B5-0A14-7634-FEF92BCB87FB}" = CCC Help Chinese Traditional
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F384BD83-C317-94DA-A4AB-3E75E43F4F8C}" = Catalyst Control Center Localization Chinese Standard
"{F622BE4A-363F-F2B6-1F98-54E5E99B1750}" = CCC Help Thai
"{F6D39840-BB27-A191-BDF2-1841CA805D24}" = CCC Help Czech
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"All ATI Software" = ATI - Software Uninstall Utility
"Asus_Camera_ScreenSaver" = Asus_Camera_ScreenSaver
"ATI Display Driver" = ATI Display Driver
"CCleaner" = CCleaner
"CloneDVD2" = CloneDVD2
"DVD Shrink_is1" = DVD Shrink 3.2
"im" = Garena Plus
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verze 1.60.0.1800
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"VLC media player" = VLC media player 1.1.11
"WinRAR archiver" = WinRAR 4.01 (32-bit)
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1644491937-1935655697-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Warcraft III" = Warcraft III: All Products
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 12. 1. 2012 19:41:01 | Computer Name = ALLA | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12. 1. 2012 21:21:05 | Computer Name = ALLA | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12. 1. 2012 21:21:06 | Computer Name = ALLA | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12. 1. 2012 21:30:59 | Computer Name = ALLA | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12. 1. 2012 21:30:59 | Computer Name = ALLA | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12. 1. 2012 21:37:34 | Computer Name = ALLA | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12. 1. 2012 21:37:34 | Computer Name = ALLA | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12. 1. 2012 23:12:36 | Computer Name = ALLA | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12. 1. 2012 23:31:38 | Computer Name = ALLA | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 13. 1. 2012 0:43:46 | Computer Name = ALLA | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
[ System Events ]
Error - 12. 1. 2012 22:38:21 | Computer Name = ALLA | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.
Error - 12. 1. 2012 22:38:25 | Computer Name = ALLA | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.
Error - 12. 1. 2012 22:38:29 | Computer Name = ALLA | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.
Error - 12. 1. 2012 22:38:33 | Computer Name = ALLA | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.
Error - 12. 1. 2012 22:38:37 | Computer Name = ALLA | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.
Error - 12. 1. 2012 22:38:42 | Computer Name = ALLA | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.
Error - 12. 1. 2012 22:38:46 | Computer Name = ALLA | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.
Error - 12. 1. 2012 22:38:50 | Computer Name = ALLA | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.
Error - 12. 1. 2012 22:38:58 | Computer Name = ALLA | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.
Error - 12. 1. 2012 22:38:58 | Computer Name = ALLA | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.
< End of report >