Re: Prosím o kontolu logu
Napsal: 16 pro 2012 09:22
[2012/12/15 22:34:19 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012/12/15 22:27:00 | 000,000,950 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/15 22:02:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/15 21:27:01 | 000,000,946 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/15 19:26:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ondra\Desktop\OTL.exe
[2012/12/15 17:51:53 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/12/15 16:27:56 | 000,037,232 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/15 16:27:56 | 000,037,232 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/15 16:19:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/12/15 16:19:42 | 3180,220,416 | -HS- | M] () -- C:\hiberfil.sys
[2012/12/15 16:12:06 | 000,545,819 | ---- | M] () -- C:\Users\Ondra\Desktop\adwcleaner.exe
[2012/12/15 16:11:49 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/12/15 14:58:49 | 000,001,152 | ---- | M] () -- C:\Users\Ondra\Desktop\XviD4PSP 5.0.lnk
[2012/12/15 14:30:12 | 000,003,011 | ---- | M] () -- C:\Users\Ondra\Desktop\HDTV2DVD.lnk
[2012/12/15 14:23:07 | 000,003,584 | ---- | M] () -- C:\Users\Ondra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/15 14:22:55 | 000,000,093 | ---- | M] () -- C:\Users\Ondra\AppData\Local\fusioncache.dat
[2012/12/15 14:20:10 | 000,001,331 | ---- | M] () -- C:\Users\Ondra\Desktop\Wondershare HD Video Converter.lnk
[2012/12/15 14:16:16 | 002,186,538 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/12/15 14:16:16 | 000,640,430 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2012/12/15 14:16:16 | 000,625,220 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/12/15 14:16:16 | 000,563,522 | ---- | M] () -- C:\Windows\SysNative\perfh008.dat
[2012/12/15 14:16:16 | 000,127,052 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2012/12/15 14:16:16 | 000,110,600 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/12/15 14:16:16 | 000,095,338 | ---- | M] () -- C:\Windows\SysNative\perfc008.dat
[2012/12/15 12:05:03 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\Ondra\Desktop\dds.exe
[2012/12/15 10:16:16 | 000,935,175 | ---- | M] () -- C:\Users\Ondra\Desktop\RSITx64.exe
[2012/12/14 23:35:54 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012/12/14 23:12:21 | 000,054,156 | -H-- | M] () -- C:\Windows\QTFont.qfn
[2012/12/14 23:12:21 | 000,001,409 | ---- | M] () -- C:\Windows\QTFont.for
[2012/12/14 09:05:31 | 000,414,240 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/13 20:56:17 | 000,001,066 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/12/13 19:19:06 | 000,000,009 | ---- | M] () -- C:\END
[2012/12/13 14:33:06 | 000,001,320 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2012/12/11 23:02:19 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/12/11 23:02:19 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/12/04 19:12:40 | 000,001,609 | ---- | M] () -- C:\Users\Ondra\Desktop\DivX Movies.lnk
[2012/12/04 19:12:39 | 000,001,152 | ---- | M] () -- C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2012/12/04 16:38:54 | 000,011,478 | ---- | M] () -- C:\Users\Ondra\Desktop\výpověd.odt
[2012/12/04 09:08:50 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForOndra.job
[2012/12/03 15:36:36 | 000,129,216 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012/12/03 15:36:35 | 000,099,912 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2012/12/02 17:21:36 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\Free Video Converter.lnk
[2012/12/02 17:21:05 | 000,001,102 | ---- | M] () -- C:\Users\Public\Desktop\Free DVD Converter.lnk
[2012/12/02 17:15:48 | 000,001,137 | ---- | M] () -- C:\Users\Public\Desktop\Free HD Video Converter.lnk
[2012/11/30 17:08:57 | 000,002,140 | ---- | M] () -- C:\Users\Public\Desktop\Splash PRO EX.lnk
[2012/11/29 21:13:35 | 002,110,044 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/28 16:38:19 | 000,002,185 | ---- | M] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
[2012/11/25 19:00:00 | 000,112,640 | ---- | M] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012/11/23 09:04:59 | 000,011,426 | ---- | M] () -- C:\Users\Ondra\Desktop\žádost o byt.odt
[2012/11/22 17:17:41 | 000,000,988 | ---- | M] () -- C:\Users\Ondra\Desktop\DVDx 4.0.lnk
[2012/11/22 16:30:25 | 000,002,111 | ---- | M] () -- C:\Users\Public\Desktop\Splash Lite.lnk
[2012/11/22 16:29:41 | 000,002,093 | ---- | M] () -- C:\Users\Public\Desktop\Splash PRO.lnk
[2012/11/20 20:00:36 | 000,002,750 | ---- | M] () -- C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk
[2012/11/20 20:00:36 | 000,002,256 | ---- | M] () -- C:\Users\Public\Desktop\Online aktualizace Nero.lnk
[2012/11/16 20:17:15 | 000,027,800 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/12/15 19:31:55 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012/12/15 17:51:53 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/12/15 16:12:57 | 000,545,819 | ---- | C] () -- C:\Users\Ondra\Desktop\adwcleaner.exe
[2012/12/15 14:58:49 | 000,001,152 | ---- | C] () -- C:\Users\Ondra\Desktop\XviD4PSP 5.0.lnk
[2012/12/15 14:30:12 | 000,003,011 | ---- | C] () -- C:\Users\Ondra\Desktop\HDTV2DVD.lnk
[2012/12/15 14:22:55 | 000,000,093 | ---- | C] () -- C:\Users\Ondra\AppData\Local\fusioncache.dat
[2012/12/15 14:20:10 | 000,001,331 | ---- | C] () -- C:\Users\Ondra\Desktop\Wondershare HD Video Converter.lnk
[2012/12/15 10:16:16 | 000,935,175 | ---- | C] () -- C:\Users\Ondra\Desktop\RSITx64.exe
[2012/12/14 23:35:54 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012/12/14 23:12:15 | 000,054,156 | -H-- | C] () -- C:\Windows\QTFont.qfn
[2012/12/14 23:12:15 | 000,001,409 | ---- | C] () -- C:\Windows\QTFont.for
[2012/12/14 09:05:11 | 000,414,240 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/13 22:55:39 | 000,675,840 | ---- | C] () -- C:\Windows\SysWow64\ac3filter.ax
[2012/12/13 22:55:39 | 000,496,640 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax
[2012/12/13 20:56:17 | 000,001,066 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/12/06 21:17:59 | 000,000,950 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/06 21:17:59 | 000,000,946 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/04 19:12:39 | 000,001,152 | ---- | C] () -- C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2012/12/04 15:17:09 | 000,011,478 | ---- | C] () -- C:\Users\Ondra\Desktop\výpověd.odt
[2012/12/03 11:30:15 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2012/12/03 11:30:15 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2012/12/03 11:30:15 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2012/12/03 11:30:07 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012/12/02 17:21:36 | 000,001,116 | ---- | C] () -- C:\Users\Public\Desktop\Free Video Converter.lnk
[2012/12/02 17:21:05 | 000,001,102 | ---- | C] () -- C:\Users\Public\Desktop\Free DVD Converter.lnk
[2012/12/02 17:15:48 | 000,001,137 | ---- | C] () -- C:\Users\Public\Desktop\Free HD Video Converter.lnk
[2012/12/02 17:15:47 | 000,070,656 | ---- | C] () -- C:\Windows\SysWow64\RLAPEDec.ax
[2012/12/02 15:57:53 | 000,001,320 | ---- | C] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2012/11/30 17:08:57 | 000,002,140 | ---- | C] () -- C:\Users\Public\Desktop\Splash PRO EX.lnk
[2012/11/28 16:38:19 | 000,002,185 | ---- | C] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
[2012/11/22 17:17:41 | 000,000,988 | ---- | C] () -- C:\Users\Ondra\Desktop\DVDx 4.0.lnk
[2012/11/22 16:30:25 | 000,002,111 | ---- | C] () -- C:\Users\Public\Desktop\Splash Lite.lnk
[2012/11/22 16:29:41 | 000,002,093 | ---- | C] () -- C:\Users\Public\Desktop\Splash PRO.lnk
[2012/11/20 20:00:36 | 000,002,750 | ---- | C] () -- C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk
[2012/11/20 20:00:36 | 000,002,256 | ---- | C] () -- C:\Users\Public\Desktop\Online aktualizace Nero.lnk
[2012/11/20 18:45:35 | 000,001,305 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[2012/11/20 18:45:21 | 000,001,374 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
[2012/11/20 18:41:30 | 000,002,180 | ---- | C] () -- C:\Users\Ondra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
[2012/11/20 18:29:01 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2012/11/19 23:39:59 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/19 23:26:14 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/14 13:54:55 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012/11/11 17:27:00 | 000,380,928 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll
[2012/11/11 12:50:54 | 000,000,012 | ---- | C] () -- C:\Windows\Ulead32.ini
[2012/11/01 18:01:26 | 000,049,152 | ---- | C] () -- C:\Windows\SysWow64\AVerIO.dll
[2012/11/01 18:01:26 | 000,003,456 | ---- | C] () -- C:\Windows\SysWow64\AVerIO.sys
[2012/11/01 18:01:25 | 000,614,400 | ---- | C] () -- C:\Windows\SysWow64\sptlib21.dll
[2012/11/01 18:01:25 | 000,421,888 | ---- | C] () -- C:\Windows\SysWow64\sptlib02.dll
[2012/11/01 18:01:25 | 000,311,296 | ---- | C] () -- C:\Windows\SysWow64\sptlib01.dll
[2012/11/01 18:01:25 | 000,307,200 | ---- | C] () -- C:\Windows\SysWow64\sptlib22.dll
[2012/11/01 18:01:25 | 000,307,200 | ---- | C] () -- C:\Windows\SysWow64\sptlib03.dll
[2012/11/01 18:01:25 | 000,294,912 | ---- | C] () -- C:\Windows\SysWow64\sptlib11.dll
[2012/11/01 18:01:25 | 000,135,168 | ---- | C] () -- C:\Windows\SysWow64\sptlib12.dll
[2012/10/29 22:49:33 | 000,003,584 | ---- | C] () -- C:\Users\Ondra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/21 17:04:48 | 002,186,538 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/08/28 09:04:34 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012/08/28 09:04:34 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012/08/28 09:04:34 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012/08/28 09:04:34 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012/08/28 09:04:32 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012/01/19 18:41:38 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/01/19 18:31:46 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat
[2012/01/19 18:27:21 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011/07/21 18:08:37 | 000,000,068 | ---- | C] () -- C:\Windows\SysWow64\ezdigsgn.dat
[2011/06/10 03:17:36 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011/05/13 16:33:18 | 000,007,736 | ---- | C] () -- C:\Windows\hpDSTRES.DLL
[2011/04/15 20:05:50 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011/04/15 20:05:50 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011/04/15 20:05:48 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011/04/15 19:59:48 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011/04/15 19:33:40 | 013,359,616 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/01/13 07:03:20 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/09/21 21:36:27 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Acoustica
[2012/12/02 17:22:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\ahd_free_dvd_converter
[2012/12/02 17:22:02 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\ahd_free_video_converter
[2012/11/11 17:27:40 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Audacity
[2012/12/01 19:56:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\avidemux
[2012/11/14 15:43:04 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\BSplayer
[2012/11/14 14:03:20 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\BSplayer Pro
[2012/12/13 19:02:36 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Cuttermaran
[2012/12/14 23:10:04 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\DVDVideoSoft
[2012/12/13 19:25:56 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\FileOpen
[2012/09/21 17:29:48 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\FreeAudioPack
[2012/12/02 17:16:13 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\free_hd_video_converter
[2012/09/21 20:47:09 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\GetRightToGo
[2012/09/21 20:06:20 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\GHISLER
[2012/09/21 20:17:32 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\LEAPS
[2012/09/22 09:45:10 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\LibreOffice
[2012/11/30 17:09:09 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Mirillis
[2012/12/13 19:25:56 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Nitro
[2012/12/13 20:26:55 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Pegasys Inc
[2012/11/11 13:11:23 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Posta
[2012/10/16 17:59:17 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Samsung
[2012/12/10 19:29:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Seznam.cz
[2012/10/07 17:21:49 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\SoftGrid Client
[2012/12/13 21:01:47 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\SpiritON TV Software
[2012/09/21 16:15:41 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Synaptics
[2012/09/21 22:09:39 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\TP
[2012/12/13 14:33:35 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\TuneUp Software
[2012/11/11 13:08:03 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Ulead Systems
[2012/09/25 19:08:35 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\WildTangent
[2012/09/22 09:13:49 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Windows Live Writer
[2012/12/13 22:15:53 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\XMedia Recode
[2012/11/05 09:33:39 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Zoner
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009/07/14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009/07/14 06:08:49 | 000,032,600 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/09/21 17:14:42 | 000,000,332 | ---- | C] () -- C:\Windows\Tasks\HPCeeScheduleForOndra.job
[2012/09/30 08:50:14 | 000,000,914 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012/12/06 21:17:59 | 000,000,946 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012/12/06 21:17:59 | 000,000,950 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
< >
< MD5 for: ATAPI.SYS >
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010/11/21 04:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010/11/21 04:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2010/11/21 04:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010/11/21 04:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2011/07/22 04:33:14 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/07/22 04:33:14 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/07/22 04:33:14 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/07/22 04:33:14 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/21 04:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/07/22 04:33:14 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/07/22 04:33:14 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/21 04:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: HAL.DLL >
[2010/11/21 04:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010/11/21 04:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: SCECLI.DLL >
[2010/11/21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010/11/21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010/11/21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SVCHOST.EXE >
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2012/10/03 18:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\SysNative\drivers\tcpip.sys
[2012/10/03 18:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_110e0fbd7d2e4b88\tcpip.sys
[2010/11/21 04:24:08 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2012/08/22 19:06:13 | 001,901,936 | ---- | M] (Microsoft Corporation) MD5=7880A26B7D3B96FDA8EFD9F985036B1D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22097_none_117a13de9661c145\tcpip.sys
[2012/03/30 11:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
[2012/03/30 12:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
[2011/07/22 04:33:25 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=CB6A53EF141CC3DA32DA54F7E75D301B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21687_none_118505f696597a9d\tcpip.sys
[2012/10/03 18:44:29 | 001,902,472 | ---- | M] (Microsoft Corporation) MD5=D5707FC2300AA5B04B7BFE86D40C0133 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_11c2c45a962baed0\tcpip.sys
[2011/07/22 04:33:25 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=DC08410DB2D0CC542DACAC7A90E6CB7A -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17582_none_10f667b97d405c20\tcpip.sys
[2012/08/22 19:12:50 | 001,913,200 | ---- | M] (Microsoft Corporation) MD5=F782CAD3CEDBB3F9FFE3BF2775D92DDC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17939_none_113380f37d117668\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010/11/21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
< >
< %systemroot%*.* /U /s >
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[4 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[7 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[1 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2012/09/21 21:36:27 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Acoustica
[2012/10/19 09:30:59 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Adobe
[2012/12/02 17:22:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\ahd_free_dvd_converter
[2012/12/02 17:22:02 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\ahd_free_video_converter
[2012/11/20 20:02:45 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Ahead
[2012/09/21 16:16:53 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\ATI
[2012/11/11 17:27:40 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Audacity
[2012/12/01 19:56:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\avidemux
[2012/12/14 23:38:06 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Avira
[2012/11/14 15:43:04 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\BSplayer
[2012/11/14 14:03:20 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\BSplayer Pro
[2012/12/13 19:02:36 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Cuttermaran
[2012/09/23 20:43:10 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\CyberLink
[2012/10/04 15:11:30 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\DivX
[2012/12/13 21:43:41 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\dvdcss
[2012/12/14 23:10:04 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\DVDVideoSoft
[2012/12/13 19:25:56 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\FileOpen
[2012/09/21 17:29:48 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\FreeAudioPack
[2012/12/02 17:16:13 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\free_hd_video_converter
[2012/09/21 20:47:09 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\GetRightToGo
[2012/09/21 20:06:20 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\GHISLER
[2012/11/22 18:20:39 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Hewlett-Packard
[2012/12/14 09:12:51 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\hpqLog
[2012/09/21 16:15:07 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Identities
[2012/09/21 16:16:04 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Intel Corporation
[2012/09/21 20:17:32 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\LEAPS
[2012/09/22 09:45:10 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\LibreOffice
[2012/09/21 17:06:28 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Macromedia
[2012/12/15 17:51:55 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Malwarebytes
[2012/01/19 18:23:06 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Media Center Programs
[2012/12/15 16:40:37 | 000,000,000 | --SD | M] -- C:\Users\Ondra\AppData\Roaming\Microsoft
[2012/11/30 17:09:09 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Mirillis
[2012/10/28 18:56:27 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Nero
[2012/12/13 19:25:56 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Nitro
[2012/12/13 20:26:55 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Pegasys Inc
[2012/11/11 13:11:23 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Posta
[2012/10/16 17:59:17 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Samsung
[2012/12/10 19:29:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Seznam.cz
[2012/12/14 08:32:52 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Skype
[2012/10/07 17:21:49 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\SoftGrid Client
[2012/12/13 21:01:47 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\SpiritON TV Software
[2012/09/21 16:15:16 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Symantec
[2012/09/21 16:15:41 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Synaptics
[2012/09/21 22:09:39 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\TP
[2012/12/13 14:33:35 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\TuneUp Software
[2012/11/11 13:08:03 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Ulead Systems
[2012/12/15 14:32:34 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\vlc
[2012/09/25 19:08:35 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\WildTangent
[2012/09/22 09:13:49 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Windows Live Writer
[2012/12/13 22:15:53 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\XMedia Recode
[2012/11/05 09:33:39 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Zoner
< %APPDATA%\*.exe /s >
[2012/11/05 13:20:42 | 000,060,888 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AdminDelegator.exe
[2012/11/05 13:20:42 | 000,088,024 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentInstaller.exe
[2012/11/05 13:20:42 | 000,077,264 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentUpdate.exe
[2012/11/05 13:20:43 | 000,843,208 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\KiesPDLR.exe
[2012/08/31 08:52:12 | 000,964,024 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\Kies.exe
[2012/08/28 09:06:22 | 000,291,840 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\KiesAgent.exe
[2012/08/31 08:52:14 | 000,278,968 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\KiesDriverInstaller.exe
[2012/08/31 08:52:14 | 003,524,536 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\KiesTrayAgent.exe
[2012/08/28 09:05:28 | 000,182,784 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\ConnectionManager.exe
[2012/08/28 09:05:28 | 000,322,048 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\DeviceDataService.exe
[2012/08/28 09:05:32 | 000,717,312 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\DeviceManager.exe
[2012/08/31 08:52:18 | 000,067,512 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\Kies_Tutorial.exe
[2012/08/28 09:05:28 | 000,057,344 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\RegisterCOM.exe
[2012/08/28 09:05:14 | 000,106,960 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\AgentInstaller.exe
[2012/08/28 09:05:14 | 000,101,328 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\AgentUpdate.exe
[2012/08/31 08:52:22 | 000,021,432 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\KiesPDLR.exe
[2012/08/31 08:52:24 | 003,765,256 | ---- | M] (Freeware) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\MediaModules\MyFreeCodecPack.exe
[2012/08/28 09:05:02 | 000,262,144 | ---- | M] (ENJsoft corp.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\TransModules\SelfMV.exe
[2012/08/28 09:05:02 | 000,090,112 | ---- | M] (ENJsoft corp.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\TransModules\SelfMV2.exe
[2012/08/31 08:52:26 | 000,593,848 | ---- | M] (ml) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\Updater\Kies.Update.exe
[2012/08/28 09:04:28 | 024,177,352 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
[2012/10/11 01:33:52 | 000,966,072 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Kies.exe
[2012/10/11 01:33:52 | 000,297,912 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesAgent.exe
[2012/10/09 01:17:54 | 000,580,096 | ---- | M] (Samsung Electronics) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesAirMessage.exe
[2012/10/11 01:33:56 | 000,277,432 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesDriverInstaller.exe
[2012/10/11 01:33:54 | 000,309,688 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesTrayAgent.exe
[2012/09/27 07:19:08 | 000,171,008 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\ConnectionManager.exe
[2012/09/27 07:21:52 | 000,325,120 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\DeviceDataService.exe
[2012/10/10 06:06:28 | 000,689,152 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\DeviceManager.exe
[2012/10/11 01:33:56 | 000,067,512 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\Kies_Tutorial.exe
[2012/10/11 01:34:04 | 000,063,416 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\RegisterCOM.exe
[2012/10/11 01:22:52 | 000,060,888 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AdminDelegator.exe
[2012/10/11 01:22:52 | 000,088,024 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AgentInstaller.exe
[2012/10/11 01:22:50 | 000,077,264 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AgentUpdate.exe
[2012/10/11 01:33:58 | 000,842,680 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\KiesPDLR.exe
[2012/10/11 01:34:00 | 003,767,312 | ---- | M] (Freeware) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\MediaModules\MyFreeCodecPack.exe
[2012/09/26 12:57:20 | 000,266,240 | ---- | M] (ENJsoft corp.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\TransModules\SelfMV.exe
[2012/09/26 12:57:20 | 000,102,400 | ---- | M] (ENJsoft corp.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\TransModules\SelfMV2.exe
[2012/10/11 01:34:02 | 000,596,920 | ---- | M] (ml) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Updater\Kies.Update.exe
[2012/09/26 12:57:10 | 014,754,760 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
[2012/08/31 08:52:26 | 000,593,848 | ---- | M] (ml) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
[2012/10/11 01:34:02 | 000,596,920 | ---- | M] (ml) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
[2012/09/25 19:08:38 | 001,007,648 | ---- | M] (WildTangent) -- C:\Users\Ondra\AppData\Roaming\WildTangent\WildTangent Games\App\DPConfig\InstallTouchpoints-wildgames.exe
[2012/09/25 19:08:36 | 000,000,179 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\WildTangent\WildTangent Games\App\DPConfig\InstallTouchpoints-wildgames.exe_filedata
[2012/09/25 19:08:37 | 000,000,172 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\WildTangent\WildTangent Games\App\DPConfig\InstallTouchpoints-hp.exe_filedata
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job >
[2012/12/15 23:02:06 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012/12/15 21:27:01 | 000,000,946 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012/12/15 22:27:00 | 000,000,950 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012/12/04 09:08:50 | 000,000,332 | ---- | M] () -- C:\Windows\Tasks\HPCeeScheduleForOndra.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2012/12/15 16:22:51 | 000,000,018 | ---- | M] () -- C:\Windows\system32\log.txt
[2012/12/15 14:16:16 | 002,186,538 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI
< %SYSTEMDRIVE%\*.exe >
< >
[2012/12/15 22:27:00 | 000,000,950 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/15 22:02:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/15 21:27:01 | 000,000,946 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/15 19:26:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ondra\Desktop\OTL.exe
[2012/12/15 17:51:53 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/12/15 16:27:56 | 000,037,232 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/15 16:27:56 | 000,037,232 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/15 16:19:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/12/15 16:19:42 | 3180,220,416 | -HS- | M] () -- C:\hiberfil.sys
[2012/12/15 16:12:06 | 000,545,819 | ---- | M] () -- C:\Users\Ondra\Desktop\adwcleaner.exe
[2012/12/15 16:11:49 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/12/15 14:58:49 | 000,001,152 | ---- | M] () -- C:\Users\Ondra\Desktop\XviD4PSP 5.0.lnk
[2012/12/15 14:30:12 | 000,003,011 | ---- | M] () -- C:\Users\Ondra\Desktop\HDTV2DVD.lnk
[2012/12/15 14:23:07 | 000,003,584 | ---- | M] () -- C:\Users\Ondra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/15 14:22:55 | 000,000,093 | ---- | M] () -- C:\Users\Ondra\AppData\Local\fusioncache.dat
[2012/12/15 14:20:10 | 000,001,331 | ---- | M] () -- C:\Users\Ondra\Desktop\Wondershare HD Video Converter.lnk
[2012/12/15 14:16:16 | 002,186,538 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/12/15 14:16:16 | 000,640,430 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2012/12/15 14:16:16 | 000,625,220 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/12/15 14:16:16 | 000,563,522 | ---- | M] () -- C:\Windows\SysNative\perfh008.dat
[2012/12/15 14:16:16 | 000,127,052 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2012/12/15 14:16:16 | 000,110,600 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/12/15 14:16:16 | 000,095,338 | ---- | M] () -- C:\Windows\SysNative\perfc008.dat
[2012/12/15 12:05:03 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\Ondra\Desktop\dds.exe
[2012/12/15 10:16:16 | 000,935,175 | ---- | M] () -- C:\Users\Ondra\Desktop\RSITx64.exe
[2012/12/14 23:35:54 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012/12/14 23:12:21 | 000,054,156 | -H-- | M] () -- C:\Windows\QTFont.qfn
[2012/12/14 23:12:21 | 000,001,409 | ---- | M] () -- C:\Windows\QTFont.for
[2012/12/14 09:05:31 | 000,414,240 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/13 20:56:17 | 000,001,066 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/12/13 19:19:06 | 000,000,009 | ---- | M] () -- C:\END
[2012/12/13 14:33:06 | 000,001,320 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2012/12/11 23:02:19 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/12/11 23:02:19 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/12/04 19:12:40 | 000,001,609 | ---- | M] () -- C:\Users\Ondra\Desktop\DivX Movies.lnk
[2012/12/04 19:12:39 | 000,001,152 | ---- | M] () -- C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2012/12/04 16:38:54 | 000,011,478 | ---- | M] () -- C:\Users\Ondra\Desktop\výpověd.odt
[2012/12/04 09:08:50 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForOndra.job
[2012/12/03 15:36:36 | 000,129,216 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2012/12/03 15:36:35 | 000,099,912 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2012/12/02 17:21:36 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\Free Video Converter.lnk
[2012/12/02 17:21:05 | 000,001,102 | ---- | M] () -- C:\Users\Public\Desktop\Free DVD Converter.lnk
[2012/12/02 17:15:48 | 000,001,137 | ---- | M] () -- C:\Users\Public\Desktop\Free HD Video Converter.lnk
[2012/11/30 17:08:57 | 000,002,140 | ---- | M] () -- C:\Users\Public\Desktop\Splash PRO EX.lnk
[2012/11/29 21:13:35 | 002,110,044 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/28 16:38:19 | 000,002,185 | ---- | M] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
[2012/11/25 19:00:00 | 000,112,640 | ---- | M] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012/11/23 09:04:59 | 000,011,426 | ---- | M] () -- C:\Users\Ondra\Desktop\žádost o byt.odt
[2012/11/22 17:17:41 | 000,000,988 | ---- | M] () -- C:\Users\Ondra\Desktop\DVDx 4.0.lnk
[2012/11/22 16:30:25 | 000,002,111 | ---- | M] () -- C:\Users\Public\Desktop\Splash Lite.lnk
[2012/11/22 16:29:41 | 000,002,093 | ---- | M] () -- C:\Users\Public\Desktop\Splash PRO.lnk
[2012/11/20 20:00:36 | 000,002,750 | ---- | M] () -- C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk
[2012/11/20 20:00:36 | 000,002,256 | ---- | M] () -- C:\Users\Public\Desktop\Online aktualizace Nero.lnk
[2012/11/16 20:17:15 | 000,027,800 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/12/15 19:31:55 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012/12/15 17:51:53 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/12/15 16:12:57 | 000,545,819 | ---- | C] () -- C:\Users\Ondra\Desktop\adwcleaner.exe
[2012/12/15 14:58:49 | 000,001,152 | ---- | C] () -- C:\Users\Ondra\Desktop\XviD4PSP 5.0.lnk
[2012/12/15 14:30:12 | 000,003,011 | ---- | C] () -- C:\Users\Ondra\Desktop\HDTV2DVD.lnk
[2012/12/15 14:22:55 | 000,000,093 | ---- | C] () -- C:\Users\Ondra\AppData\Local\fusioncache.dat
[2012/12/15 14:20:10 | 000,001,331 | ---- | C] () -- C:\Users\Ondra\Desktop\Wondershare HD Video Converter.lnk
[2012/12/15 10:16:16 | 000,935,175 | ---- | C] () -- C:\Users\Ondra\Desktop\RSITx64.exe
[2012/12/14 23:35:54 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2012/12/14 23:12:15 | 000,054,156 | -H-- | C] () -- C:\Windows\QTFont.qfn
[2012/12/14 23:12:15 | 000,001,409 | ---- | C] () -- C:\Windows\QTFont.for
[2012/12/14 09:05:11 | 000,414,240 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/13 22:55:39 | 000,675,840 | ---- | C] () -- C:\Windows\SysWow64\ac3filter.ax
[2012/12/13 22:55:39 | 000,496,640 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax
[2012/12/13 20:56:17 | 000,001,066 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/12/06 21:17:59 | 000,000,950 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/06 21:17:59 | 000,000,946 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/04 19:12:39 | 000,001,152 | ---- | C] () -- C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2012/12/04 15:17:09 | 000,011,478 | ---- | C] () -- C:\Users\Ondra\Desktop\výpověd.odt
[2012/12/03 11:30:15 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2012/12/03 11:30:15 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2012/12/03 11:30:15 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2012/12/03 11:30:07 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012/12/02 17:21:36 | 000,001,116 | ---- | C] () -- C:\Users\Public\Desktop\Free Video Converter.lnk
[2012/12/02 17:21:05 | 000,001,102 | ---- | C] () -- C:\Users\Public\Desktop\Free DVD Converter.lnk
[2012/12/02 17:15:48 | 000,001,137 | ---- | C] () -- C:\Users\Public\Desktop\Free HD Video Converter.lnk
[2012/12/02 17:15:47 | 000,070,656 | ---- | C] () -- C:\Windows\SysWow64\RLAPEDec.ax
[2012/12/02 15:57:53 | 000,001,320 | ---- | C] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2012/11/30 17:08:57 | 000,002,140 | ---- | C] () -- C:\Users\Public\Desktop\Splash PRO EX.lnk
[2012/11/28 16:38:19 | 000,002,185 | ---- | C] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
[2012/11/22 17:17:41 | 000,000,988 | ---- | C] () -- C:\Users\Ondra\Desktop\DVDx 4.0.lnk
[2012/11/22 16:30:25 | 000,002,111 | ---- | C] () -- C:\Users\Public\Desktop\Splash Lite.lnk
[2012/11/22 16:29:41 | 000,002,093 | ---- | C] () -- C:\Users\Public\Desktop\Splash PRO.lnk
[2012/11/20 20:00:36 | 000,002,750 | ---- | C] () -- C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk
[2012/11/20 20:00:36 | 000,002,256 | ---- | C] () -- C:\Users\Public\Desktop\Online aktualizace Nero.lnk
[2012/11/20 18:45:35 | 000,001,305 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[2012/11/20 18:45:21 | 000,001,374 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
[2012/11/20 18:41:30 | 000,002,180 | ---- | C] () -- C:\Users\Ondra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
[2012/11/20 18:29:01 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2012/11/19 23:39:59 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/19 23:26:14 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/14 13:54:55 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012/11/11 17:27:00 | 000,380,928 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll
[2012/11/11 12:50:54 | 000,000,012 | ---- | C] () -- C:\Windows\Ulead32.ini
[2012/11/01 18:01:26 | 000,049,152 | ---- | C] () -- C:\Windows\SysWow64\AVerIO.dll
[2012/11/01 18:01:26 | 000,003,456 | ---- | C] () -- C:\Windows\SysWow64\AVerIO.sys
[2012/11/01 18:01:25 | 000,614,400 | ---- | C] () -- C:\Windows\SysWow64\sptlib21.dll
[2012/11/01 18:01:25 | 000,421,888 | ---- | C] () -- C:\Windows\SysWow64\sptlib02.dll
[2012/11/01 18:01:25 | 000,311,296 | ---- | C] () -- C:\Windows\SysWow64\sptlib01.dll
[2012/11/01 18:01:25 | 000,307,200 | ---- | C] () -- C:\Windows\SysWow64\sptlib22.dll
[2012/11/01 18:01:25 | 000,307,200 | ---- | C] () -- C:\Windows\SysWow64\sptlib03.dll
[2012/11/01 18:01:25 | 000,294,912 | ---- | C] () -- C:\Windows\SysWow64\sptlib11.dll
[2012/11/01 18:01:25 | 000,135,168 | ---- | C] () -- C:\Windows\SysWow64\sptlib12.dll
[2012/10/29 22:49:33 | 000,003,584 | ---- | C] () -- C:\Users\Ondra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/21 17:04:48 | 002,186,538 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/08/28 09:04:34 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012/08/28 09:04:34 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012/08/28 09:04:34 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012/08/28 09:04:34 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012/08/28 09:04:32 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012/01/19 18:41:38 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/01/19 18:31:46 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat
[2012/01/19 18:27:21 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011/07/21 18:08:37 | 000,000,068 | ---- | C] () -- C:\Windows\SysWow64\ezdigsgn.dat
[2011/06/10 03:17:36 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011/05/13 16:33:18 | 000,007,736 | ---- | C] () -- C:\Windows\hpDSTRES.DLL
[2011/04/15 20:05:50 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011/04/15 20:05:50 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2011/04/15 20:05:48 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011/04/15 19:59:48 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011/04/15 19:33:40 | 013,359,616 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/01/13 07:03:20 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/09/21 21:36:27 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Acoustica
[2012/12/02 17:22:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\ahd_free_dvd_converter
[2012/12/02 17:22:02 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\ahd_free_video_converter
[2012/11/11 17:27:40 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Audacity
[2012/12/01 19:56:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\avidemux
[2012/11/14 15:43:04 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\BSplayer
[2012/11/14 14:03:20 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\BSplayer Pro
[2012/12/13 19:02:36 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Cuttermaran
[2012/12/14 23:10:04 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\DVDVideoSoft
[2012/12/13 19:25:56 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\FileOpen
[2012/09/21 17:29:48 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\FreeAudioPack
[2012/12/02 17:16:13 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\free_hd_video_converter
[2012/09/21 20:47:09 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\GetRightToGo
[2012/09/21 20:06:20 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\GHISLER
[2012/09/21 20:17:32 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\LEAPS
[2012/09/22 09:45:10 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\LibreOffice
[2012/11/30 17:09:09 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Mirillis
[2012/12/13 19:25:56 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Nitro
[2012/12/13 20:26:55 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Pegasys Inc
[2012/11/11 13:11:23 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Posta
[2012/10/16 17:59:17 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Samsung
[2012/12/10 19:29:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Seznam.cz
[2012/10/07 17:21:49 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\SoftGrid Client
[2012/12/13 21:01:47 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\SpiritON TV Software
[2012/09/21 16:15:41 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Synaptics
[2012/09/21 22:09:39 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\TP
[2012/12/13 14:33:35 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\TuneUp Software
[2012/11/11 13:08:03 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Ulead Systems
[2012/09/25 19:08:35 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\WildTangent
[2012/09/22 09:13:49 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Windows Live Writer
[2012/12/13 22:15:53 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\XMedia Recode
[2012/11/05 09:33:39 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Zoner
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009/07/14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009/07/14 06:08:49 | 000,032,600 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/09/21 17:14:42 | 000,000,332 | ---- | C] () -- C:\Windows\Tasks\HPCeeScheduleForOndra.job
[2012/09/30 08:50:14 | 000,000,914 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012/12/06 21:17:59 | 000,000,946 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012/12/06 21:17:59 | 000,000,950 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
< >
< MD5 for: ATAPI.SYS >
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010/11/21 04:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010/11/21 04:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2010/11/21 04:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010/11/21 04:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2011/07/22 04:33:14 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/07/22 04:33:14 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/07/22 04:33:14 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/07/22 04:33:14 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/21 04:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/07/22 04:33:14 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/07/22 04:33:14 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/21 04:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: HAL.DLL >
[2010/11/21 04:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010/11/21 04:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: SCECLI.DLL >
[2010/11/21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010/11/21 04:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010/11/21 04:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SVCHOST.EXE >
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/09/29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009/07/14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2012/10/03 18:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\SysNative\drivers\tcpip.sys
[2012/10/03 18:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_110e0fbd7d2e4b88\tcpip.sys
[2010/11/21 04:24:08 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2012/08/22 19:06:13 | 001,901,936 | ---- | M] (Microsoft Corporation) MD5=7880A26B7D3B96FDA8EFD9F985036B1D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22097_none_117a13de9661c145\tcpip.sys
[2012/03/30 11:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
[2012/03/30 12:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
[2011/07/22 04:33:25 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=CB6A53EF141CC3DA32DA54F7E75D301B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21687_none_118505f696597a9d\tcpip.sys
[2012/10/03 18:44:29 | 001,902,472 | ---- | M] (Microsoft Corporation) MD5=D5707FC2300AA5B04B7BFE86D40C0133 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_11c2c45a962baed0\tcpip.sys
[2011/07/22 04:33:25 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=DC08410DB2D0CC542DACAC7A90E6CB7A -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17582_none_10f667b97d405c20\tcpip.sys
[2012/08/22 19:12:50 | 001,913,200 | ---- | M] (Microsoft Corporation) MD5=F782CAD3CEDBB3F9FFE3BF2775D92DDC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17939_none_113380f37d117668\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010/11/21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
< >
< %systemroot%*.* /U /s >
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[4 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[7 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[1 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2012/09/21 21:36:27 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Acoustica
[2012/10/19 09:30:59 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Adobe
[2012/12/02 17:22:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\ahd_free_dvd_converter
[2012/12/02 17:22:02 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\ahd_free_video_converter
[2012/11/20 20:02:45 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Ahead
[2012/09/21 16:16:53 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\ATI
[2012/11/11 17:27:40 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Audacity
[2012/12/01 19:56:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\avidemux
[2012/12/14 23:38:06 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Avira
[2012/11/14 15:43:04 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\BSplayer
[2012/11/14 14:03:20 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\BSplayer Pro
[2012/12/13 19:02:36 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Cuttermaran
[2012/09/23 20:43:10 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\CyberLink
[2012/10/04 15:11:30 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\DivX
[2012/12/13 21:43:41 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\dvdcss
[2012/12/14 23:10:04 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\DVDVideoSoft
[2012/12/13 19:25:56 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\FileOpen
[2012/09/21 17:29:48 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\FreeAudioPack
[2012/12/02 17:16:13 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\free_hd_video_converter
[2012/09/21 20:47:09 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\GetRightToGo
[2012/09/21 20:06:20 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\GHISLER
[2012/11/22 18:20:39 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Hewlett-Packard
[2012/12/14 09:12:51 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\hpqLog
[2012/09/21 16:15:07 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Identities
[2012/09/21 16:16:04 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Intel Corporation
[2012/09/21 20:17:32 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\LEAPS
[2012/09/22 09:45:10 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\LibreOffice
[2012/09/21 17:06:28 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Macromedia
[2012/12/15 17:51:55 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Malwarebytes
[2012/01/19 18:23:06 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Media Center Programs
[2012/12/15 16:40:37 | 000,000,000 | --SD | M] -- C:\Users\Ondra\AppData\Roaming\Microsoft
[2012/11/30 17:09:09 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Mirillis
[2012/10/28 18:56:27 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Nero
[2012/12/13 19:25:56 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Nitro
[2012/12/13 20:26:55 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Pegasys Inc
[2012/11/11 13:11:23 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Posta
[2012/10/16 17:59:17 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Samsung
[2012/12/10 19:29:01 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Seznam.cz
[2012/12/14 08:32:52 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Skype
[2012/10/07 17:21:49 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\SoftGrid Client
[2012/12/13 21:01:47 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\SpiritON TV Software
[2012/09/21 16:15:16 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Symantec
[2012/09/21 16:15:41 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Synaptics
[2012/09/21 22:09:39 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\TP
[2012/12/13 14:33:35 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\TuneUp Software
[2012/11/11 13:08:03 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Ulead Systems
[2012/12/15 14:32:34 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\vlc
[2012/09/25 19:08:35 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\WildTangent
[2012/09/22 09:13:49 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Windows Live Writer
[2012/12/13 22:15:53 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\XMedia Recode
[2012/11/05 09:33:39 | 000,000,000 | ---D | M] -- C:\Users\Ondra\AppData\Roaming\Zoner
< %APPDATA%\*.exe /s >
[2012/11/05 13:20:42 | 000,060,888 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AdminDelegator.exe
[2012/11/05 13:20:42 | 000,088,024 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentInstaller.exe
[2012/11/05 13:20:42 | 000,077,264 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentUpdate.exe
[2012/11/05 13:20:43 | 000,843,208 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\KiesPDLR.exe
[2012/08/31 08:52:12 | 000,964,024 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\Kies.exe
[2012/08/28 09:06:22 | 000,291,840 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\KiesAgent.exe
[2012/08/31 08:52:14 | 000,278,968 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\KiesDriverInstaller.exe
[2012/08/31 08:52:14 | 003,524,536 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\KiesTrayAgent.exe
[2012/08/28 09:05:28 | 000,182,784 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\ConnectionManager.exe
[2012/08/28 09:05:28 | 000,322,048 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\DeviceDataService.exe
[2012/08/28 09:05:32 | 000,717,312 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\DeviceManager.exe
[2012/08/31 08:52:18 | 000,067,512 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\Kies_Tutorial.exe
[2012/08/28 09:05:28 | 000,057,344 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\DeviceModules\RegisterCOM.exe
[2012/08/28 09:05:14 | 000,106,960 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\AgentInstaller.exe
[2012/08/28 09:05:14 | 000,101,328 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\AgentUpdate.exe
[2012/08/31 08:52:22 | 000,021,432 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\FirmwareUpdate\KiesPDLR.exe
[2012/08/31 08:52:24 | 003,765,256 | ---- | M] (Freeware) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\MediaModules\MyFreeCodecPack.exe
[2012/08/28 09:05:02 | 000,262,144 | ---- | M] (ENJsoft corp.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\TransModules\SelfMV.exe
[2012/08/28 09:05:02 | 000,090,112 | ---- | M] (ENJsoft corp.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\External\TransModules\SelfMV2.exe
[2012/08/31 08:52:26 | 000,593,848 | ---- | M] (ml) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\Updater\Kies.Update.exe
[2012/08/28 09:04:28 | 024,177,352 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Backup\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
[2012/10/11 01:33:52 | 000,966,072 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Kies.exe
[2012/10/11 01:33:52 | 000,297,912 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesAgent.exe
[2012/10/09 01:17:54 | 000,580,096 | ---- | M] (Samsung Electronics) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesAirMessage.exe
[2012/10/11 01:33:56 | 000,277,432 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesDriverInstaller.exe
[2012/10/11 01:33:54 | 000,309,688 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\KiesTrayAgent.exe
[2012/09/27 07:19:08 | 000,171,008 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\ConnectionManager.exe
[2012/09/27 07:21:52 | 000,325,120 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\DeviceDataService.exe
[2012/10/10 06:06:28 | 000,689,152 | ---- | M] (Mobileleader Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\DeviceManager.exe
[2012/10/11 01:33:56 | 000,067,512 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\Kies_Tutorial.exe
[2012/10/11 01:34:04 | 000,063,416 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\DeviceModules\RegisterCOM.exe
[2012/10/11 01:22:52 | 000,060,888 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AdminDelegator.exe
[2012/10/11 01:22:52 | 000,088,024 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AgentInstaller.exe
[2012/10/11 01:22:50 | 000,077,264 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\AgentUpdate.exe
[2012/10/11 01:33:58 | 000,842,680 | ---- | M] (Samsung) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\FirmwareUpdate\KiesPDLR.exe
[2012/10/11 01:34:00 | 003,767,312 | ---- | M] (Freeware) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\MediaModules\MyFreeCodecPack.exe
[2012/09/26 12:57:20 | 000,266,240 | ---- | M] (ENJsoft corp.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\TransModules\SelfMV.exe
[2012/09/26 12:57:20 | 000,102,400 | ---- | M] (ENJsoft corp.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\External\TransModules\SelfMV2.exe
[2012/10/11 01:34:02 | 000,596,920 | ---- | M] (ml) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\Updater\Kies.Update.exe
[2012/09/26 12:57:10 | 014,754,760 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Sub\USB Driver\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
[2012/08/31 08:52:26 | 000,593,848 | ---- | M] (ml) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
[2012/10/11 01:34:02 | 000,596,920 | ---- | M] (ml) -- C:\Users\Ondra\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
[2012/09/25 19:08:38 | 001,007,648 | ---- | M] (WildTangent) -- C:\Users\Ondra\AppData\Roaming\WildTangent\WildTangent Games\App\DPConfig\InstallTouchpoints-wildgames.exe
[2012/09/25 19:08:36 | 000,000,179 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\WildTangent\WildTangent Games\App\DPConfig\InstallTouchpoints-wildgames.exe_filedata
[2012/09/25 19:08:37 | 000,000,172 | ---- | M] () -- C:\Users\Ondra\AppData\Roaming\WildTangent\WildTangent Games\App\DPConfig\InstallTouchpoints-hp.exe_filedata
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job >
[2012/12/15 23:02:06 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012/12/15 21:27:01 | 000,000,946 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012/12/15 22:27:00 | 000,000,950 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012/12/04 09:08:50 | 000,000,332 | ---- | M] () -- C:\Windows\Tasks\HPCeeScheduleForOndra.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2012/12/15 16:22:51 | 000,000,018 | ---- | M] () -- C:\Windows\system32\log.txt
[2012/12/15 14:16:16 | 002,186,538 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI
< %SYSTEMDRIVE%\*.exe >
< >