Re: Prosím o kontrolu logu
Napsal: 17 úno 2013 22:35
< >
< %systemroot%*.* /U /s >
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[18 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\WINDOWS\Globalization\*.tmp files -> C:\WINDOWS\Globalization\*.tmp -> ]
[45 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[11 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
[1 C:\WINDOWS\Temp\_avast_\*.tmp files -> C:\WINDOWS\Temp\_avast_\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
[2012.09.15 11:15:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.08.11 18:13:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Acronis
[2012.03.07 09:20:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Adobe
[2011.06.24 12:41:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Ahead
[2012.12.26 15:06:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Apple Computer
[2012.01.02 21:13:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\AskToolbar
[2012.10.07 18:33:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Audacity
[2011.11.20 16:13:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\AVG
[2010.08.16 15:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Canneverbe Limited
[2010.08.11 16:44:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\CyberLink
[2011.02.25 13:03:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\DAEMON Tools Pro
[2012.10.03 19:51:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\DDMSettings
[2011.08.28 21:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\DivX
[2012.12.27 15:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Dropbox
[2012.12.03 11:38:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\EPSON
[2011.01.30 16:21:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\ESET
[2010.07.30 13:07:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\GHISLER
[2011.06.11 10:12:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Google
[2012.08.27 12:57:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\ICQ
[2010.07.29 17:30:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Identities
[2012.03.06 09:02:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\inkscape
[2010.07.30 08:16:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\InstallShield
[2010.07.30 13:13:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Intel
[2011.11.26 19:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\IObit
[2010.08.11 01:39:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Macromedia
[2013.02.16 16:05:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Malwarebytes
[2012.03.07 08:27:48 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft
[2013.02.12 22:36:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Mozilla
[2012.03.22 09:20:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Myx
[2012.01.01 18:58:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Nero
[2013.01.07 12:30:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Nokia
[2011.11.12 22:49:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Nokia Suite
[2012.04.14 07:04:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Ochuz
[2011.11.12 19:38:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\PC Suite
[2011.08.30 07:21:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Publish Providers
[2011.11.12 11:36:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\QIP
[2012.01.21 10:53:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Real
[2011.08.29 07:01:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Registry Mechanic
[2011.07.31 19:57:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Sibelius Software
[2012.09.10 15:20:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Skype
[2011.07.07 07:08:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\skypePM
[2012.08.08 20:28:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Sony
[2011.07.29 17:38:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Sony Corporation
[2011.08.30 07:42:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Sony Creative Software Inc
[2011.01.26 11:05:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Sun
[2011.07.30 08:31:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Thunderbird
[2010.07.30 08:10:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\TMP
[2011.11.12 14:11:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\TOSHIBA
[2012.09.15 11:07:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\TuneUp Software
[2011.08.31 17:46:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Ulead Systems
[2011.11.12 14:31:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Uniblue
[2010.07.30 08:09:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\WinBatch
[2012.01.21 14:30:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Windows Desktop Search
[2012.01.21 14:54:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Windows Search
[2010.07.30 08:41:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\WinRAR
[2012.04.02 10:11:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Xilisoft
< %APPDATA%\*.exe /s >
[2011.09.01 08:04:43 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2011.09.01 08:06:14 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
[2011.12.31 19:55:58 | 000,053,248 | R--- | M] (Flexera Software, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{889D48DA-457F-4C8B-9095-6458F2793B12}\ARPPRODUCTICON.exe
[2011.12.31 19:55:58 | 000,049,152 | R--- | M] (Flexera Software, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{889D48DA-457F-4C8B-9095-6458F2793B12}\NewShortcut2_1C7B7089989A424FB39D41A32581C775.exe
[2011.12.31 19:55:58 | 000,073,728 | R--- | M] (Flexera Software, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{889D48DA-457F-4C8B-9095-6458F2793B12}\NewShortcut46_74B9CE5DF1F4447F982DCA29A461B529.exe
[2011.12.31 19:55:58 | 000,073,728 | R--- | M] (Flexera Software, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{889D48DA-457F-4C8B-9095-6458F2793B12}\NewShortcut47_74B9CE5DF1F4447F982DCA29A461B529.exe
[2011.12.31 19:55:58 | 000,049,152 | R--- | M] (Flexera Software, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{889D48DA-457F-4C8B-9095-6458F2793B12}\Uninstall_QA_OTI_H_FE5D756F71E147C4972AD6775344B40B.exe
[2010.12.09 22:32:28 | 000,506,024 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Real\Update\setup3.13\setup.exe
[2011.01.28 08:55:48 | 000,510,120 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Real\Update\setup3.14\setup.exe
[2011.12.11 02:13:10 | 000,315,512 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Real\Update\temp\~Upg0\rnupgagent.exe
[2012.01.20 21:36:49 | 000,315,512 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Real\Update\UpgradeHelper\RealPlayer\9.01\rnupgagent.exe
[2008.01.10 10:51:00 | 017,857,392 | ---- | M] (Marvell ) -- C:\Documents and Settings\Ferko\Data aplikací\TMP\setup.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job >
[2013.02.17 22:00:00 | 000,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012.12.25 02:00:00 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\AdobeAAMUpdater-1.0-FERKO-NTB-Ferko.job
[2013.02.11 12:12:03 | 000,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2013.02.17 20:25:01 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
[2013.02.17 13:07:00 | 000,001,084 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1003Core.job
[2013.02.17 22:07:03 | 000,001,106 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1003UA.job
[2013.02.17 20:42:00 | 000,000,918 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2013.02.17 21:42:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2013.02.17 12:32:00 | 000,000,958 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1003Core.job
[2013.02.17 20:32:00 | 000,001,010 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1003UA.job
[2013.02.12 20:28:42 | 000,000,986 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1005Core.job
[2013.02.17 22:00:04 | 000,001,038 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1005UA.job
[2013.02.17 22:26:00 | 000,000,234 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2011.02.25 13:10:32 | 000,717,296 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2010.07.29 19:11:18 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2010.07.29 19:11:18 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2010.07.29 19:11:18 | 000,487,424 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2013.02.15 08:25:05 | 000,002,552 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT
[2013.02.15 09:14:17 | 003,616,272 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2013.02.17 17:14:28 | 000,106,518 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2013.02.17 17:14:28 | 000,085,238 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2013.02.17 17:14:28 | 000,510,704 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2013.02.17 17:14:28 | 000,494,144 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2013.02.17 17:14:28 | 001,172,076 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2013.02.17 17:03:40 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 04:22:17 | 000,015,360 | ---- | M] (Microsoft Corporation)
"Akamai NetSession Interface" = "C:\Documents and Settings\Ferko\Local Settings\Data aplikací\Akamai\netsession_win.exe" -- [2012.10.09 09:53:36 | 004,441,920 | ---- | M] (Akamai Technologies, Inc.)
"PC Suite Tray" = "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray -- [2011.06.16 15:21:06 | 001,500,160 | ---- | M] (Nokia)
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2012.12.21 09:25:35 | 000,643,120 | ---- | M] (Microsoft Corporation) MD5=C3DDC05C898F19D35A4A2B5F707CA916 -- C:\Program Files\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.02.17 22:04:26 | 000,000,512 | ---- | M] () MD5=37B26BD8A035430A472CE41B013C7D1F -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2010.03.01 16:38:35 | 005,403,571 | ---- | M] () -- \Organova hudba\0123 NOVE ORGAN\Popular Organ Music ( David Briggs )\06 - David Briggs - 06 Miniature-Overture from The Nutcracker Suite - P. I. Tchaikovsky.mp3
[2010.03.01 16:38:48 | 009,969,289 | ---- | M] () -- \Organova hudba\0123 NOVE ORGAN\Popular Organ Music ( David Briggs )\07 - David Briggs - 07 Waltz of the Flower from The Nutcracker Suite - P. I. Tchaikovsky.mp3
< *keygen* /s >
< *loader* /s >
[2008.03.18 06:31:00 | 000,009,216 | R--- | M] () -- \Program Files\Adobe\Acrobat 9.0\PDFMaker\AutoCAD\OD\AecDummyLoader_2.05_8.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 161 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:1493A0EF
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:C8B8CEBD
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
< End of report >
< %systemroot%*.* /U /s >
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[18 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\WINDOWS\Globalization\*.tmp files -> C:\WINDOWS\Globalization\*.tmp -> ]
[45 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[11 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
[1 C:\WINDOWS\Temp\_avast_\*.tmp files -> C:\WINDOWS\Temp\_avast_\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
[2012.09.15 11:15:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.08.11 18:13:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Acronis
[2012.03.07 09:20:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Adobe
[2011.06.24 12:41:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Ahead
[2012.12.26 15:06:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Apple Computer
[2012.01.02 21:13:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\AskToolbar
[2012.10.07 18:33:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Audacity
[2011.11.20 16:13:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\AVG
[2010.08.16 15:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Canneverbe Limited
[2010.08.11 16:44:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\CyberLink
[2011.02.25 13:03:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\DAEMON Tools Pro
[2012.10.03 19:51:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\DDMSettings
[2011.08.28 21:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\DivX
[2012.12.27 15:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Dropbox
[2012.12.03 11:38:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\EPSON
[2011.01.30 16:21:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\ESET
[2010.07.30 13:07:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\GHISLER
[2011.06.11 10:12:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Google
[2012.08.27 12:57:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\ICQ
[2010.07.29 17:30:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Identities
[2012.03.06 09:02:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\inkscape
[2010.07.30 08:16:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\InstallShield
[2010.07.30 13:13:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Intel
[2011.11.26 19:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\IObit
[2010.08.11 01:39:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Macromedia
[2013.02.16 16:05:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Malwarebytes
[2012.03.07 08:27:48 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft
[2013.02.12 22:36:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Mozilla
[2012.03.22 09:20:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Myx
[2012.01.01 18:58:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Nero
[2013.01.07 12:30:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Nokia
[2011.11.12 22:49:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Nokia Suite
[2012.04.14 07:04:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Ochuz
[2011.11.12 19:38:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\PC Suite
[2011.08.30 07:21:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Publish Providers
[2011.11.12 11:36:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\QIP
[2012.01.21 10:53:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Real
[2011.08.29 07:01:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Registry Mechanic
[2011.07.31 19:57:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Sibelius Software
[2012.09.10 15:20:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Skype
[2011.07.07 07:08:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\skypePM
[2012.08.08 20:28:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Sony
[2011.07.29 17:38:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Sony Corporation
[2011.08.30 07:42:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Sony Creative Software Inc
[2011.01.26 11:05:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Sun
[2011.07.30 08:31:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Thunderbird
[2010.07.30 08:10:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\TMP
[2011.11.12 14:11:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\TOSHIBA
[2012.09.15 11:07:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\TuneUp Software
[2011.08.31 17:46:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Ulead Systems
[2011.11.12 14:31:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Uniblue
[2010.07.30 08:09:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\WinBatch
[2012.01.21 14:30:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Windows Desktop Search
[2012.01.21 14:54:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Windows Search
[2010.07.30 08:41:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\WinRAR
[2012.04.02 10:11:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Ferko\Data aplikací\Xilisoft
< %APPDATA%\*.exe /s >
[2011.09.01 08:04:43 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2011.09.01 08:06:14 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
[2011.12.31 19:55:58 | 000,053,248 | R--- | M] (Flexera Software, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{889D48DA-457F-4C8B-9095-6458F2793B12}\ARPPRODUCTICON.exe
[2011.12.31 19:55:58 | 000,049,152 | R--- | M] (Flexera Software, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{889D48DA-457F-4C8B-9095-6458F2793B12}\NewShortcut2_1C7B7089989A424FB39D41A32581C775.exe
[2011.12.31 19:55:58 | 000,073,728 | R--- | M] (Flexera Software, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{889D48DA-457F-4C8B-9095-6458F2793B12}\NewShortcut46_74B9CE5DF1F4447F982DCA29A461B529.exe
[2011.12.31 19:55:58 | 000,073,728 | R--- | M] (Flexera Software, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{889D48DA-457F-4C8B-9095-6458F2793B12}\NewShortcut47_74B9CE5DF1F4447F982DCA29A461B529.exe
[2011.12.31 19:55:58 | 000,049,152 | R--- | M] (Flexera Software, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Microsoft\Installer\{889D48DA-457F-4C8B-9095-6458F2793B12}\Uninstall_QA_OTI_H_FE5D756F71E147C4972AD6775344B40B.exe
[2010.12.09 22:32:28 | 000,506,024 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Real\Update\setup3.13\setup.exe
[2011.01.28 08:55:48 | 000,510,120 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Real\Update\setup3.14\setup.exe
[2011.12.11 02:13:10 | 000,315,512 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Real\Update\temp\~Upg0\rnupgagent.exe
[2012.01.20 21:36:49 | 000,315,512 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Ferko\Data aplikací\Real\Update\UpgradeHelper\RealPlayer\9.01\rnupgagent.exe
[2008.01.10 10:51:00 | 017,857,392 | ---- | M] (Marvell ) -- C:\Documents and Settings\Ferko\Data aplikací\TMP\setup.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job >
[2013.02.17 22:00:00 | 000,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012.12.25 02:00:00 | 000,000,342 | ---- | M] () -- C:\WINDOWS\Tasks\AdobeAAMUpdater-1.0-FERKO-NTB-Ferko.job
[2013.02.11 12:12:03 | 000,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2013.02.17 20:25:01 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
[2013.02.17 13:07:00 | 000,001,084 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1003Core.job
[2013.02.17 22:07:03 | 000,001,106 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1003UA.job
[2013.02.17 20:42:00 | 000,000,918 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2013.02.17 21:42:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2013.02.17 12:32:00 | 000,000,958 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1003Core.job
[2013.02.17 20:32:00 | 000,001,010 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1003UA.job
[2013.02.12 20:28:42 | 000,000,986 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1005Core.job
[2013.02.17 22:00:04 | 000,001,038 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-1957994488-682003330-1005UA.job
[2013.02.17 22:26:00 | 000,000,234 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2011.02.25 13:10:32 | 000,717,296 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2010.07.29 19:11:18 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2010.07.29 19:11:18 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2010.07.29 19:11:18 | 000,487,424 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2013.02.15 08:25:05 | 000,002,552 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT
[2013.02.15 09:14:17 | 003,616,272 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2013.02.17 17:14:28 | 000,106,518 | ---- | M] () -- C:\WINDOWS\system32\perfc005.dat
[2013.02.17 17:14:28 | 000,085,238 | ---- | M] () -- C:\WINDOWS\system32\perfc009.dat
[2013.02.17 17:14:28 | 000,510,704 | ---- | M] () -- C:\WINDOWS\system32\perfh005.dat
[2013.02.17 17:14:28 | 000,494,144 | ---- | M] () -- C:\WINDOWS\system32\perfh009.dat
[2013.02.17 17:14:28 | 001,172,076 | ---- | M] () -- C:\WINDOWS\system32\PerfStringBackup.INI
[2013.02.17 17:03:40 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 04:22:17 | 000,015,360 | ---- | M] (Microsoft Corporation)
"Akamai NetSession Interface" = "C:\Documents and Settings\Ferko\Local Settings\Data aplikací\Akamai\netsession_win.exe" -- [2012.10.09 09:53:36 | 004,441,920 | ---- | M] (Akamai Technologies, Inc.)
"PC Suite Tray" = "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray -- [2011.06.16 15:21:06 | 001,500,160 | ---- | M] (Nokia)
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2012.12.21 09:25:35 | 000,643,120 | ---- | M] (Microsoft Corporation) MD5=C3DDC05C898F19D35A4A2B5F707CA916 -- C:\Program Files\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.02.17 22:04:26 | 000,000,512 | ---- | M] () MD5=37B26BD8A035430A472CE41B013C7D1F -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2010.03.01 16:38:35 | 005,403,571 | ---- | M] () -- \Organova hudba\0123 NOVE ORGAN\Popular Organ Music ( David Briggs )\06 - David Briggs - 06 Miniature-Overture from The Nutcracker Suite - P. I. Tchaikovsky.mp3
[2010.03.01 16:38:48 | 009,969,289 | ---- | M] () -- \Organova hudba\0123 NOVE ORGAN\Popular Organ Music ( David Briggs )\07 - David Briggs - 07 Waltz of the Flower from The Nutcracker Suite - P. I. Tchaikovsky.mp3
< *keygen* /s >
< *loader* /s >
[2008.03.18 06:31:00 | 000,009,216 | R--- | M] () -- \Program Files\Adobe\Acrobat 9.0\PDFMaker\AutoCAD\OD\AecDummyLoader_2.05_8.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 161 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:1493A0EF
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0B4227B4
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:C8B8CEBD
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
< End of report >