OTL logfile created on: 26.3.2013 17:55:49 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Hanka\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
991,23 Mb Total Physical Memory | 625,05 Mb Available Physical Memory | 63,06% Memory free
2,33 Gb Paging File | 1,98 Gb Available in Paging File | 84,79% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 25,00 Gb Total Space | 14,78 Gb Free Space | 59,11% Space Free | Partition Type: NTFS
Drive D: | 49,53 Gb Total Space | 42,75 Gb Free Space | 86,31% Space Free | Partition Type: NTFS
Computer Name: BERKOVI | User Name: Hanka | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.03.26 17:54:19 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Hanka\Plocha\OTL.exe
PRC - [2013.03.24 19:25:49 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2013.03.24 19:25:29 | 000,079,584 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2013.03.24 19:25:26 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2013.03.24 19:25:25 | 000,385,248 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2013.03.23 21:05:15 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011.01.14 13:35:56 | 000,196,912 | ---- | M] (Nitro PDF Software) -- C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe
PRC - [2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.08.09 08:27:52 | 000,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2004.11.15 17:20:20 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
========== Modules (No Company Name) ==========
MOD - [2013.03.24 19:25:52 | 000,397,704 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2013.03.23 21:05:16 | 001,014,744 | ---- | M] () -- C:\Program Files\Mozilla Firefox\js3250.dll
MOD - [2012.08.14 20:31:24 | 009,465,032 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
MOD - [2009.04.07 04:32:10 | 000,022,723 | ---- | M] () -- C:\WINDOWS\system32\cl31cl3.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2013.03.24 19:25:49 | 000,086,752 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2013.03.24 19:25:26 | 000,110,816 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.01.14 13:35:56 | 000,196,912 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe -- (NitroReaderDriverReadSpool)
SRV - [2007.08.09 08:27:52 | 000,073,728 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\VcommMgr.sys -- (VcommMgr)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\VComm.sys -- (VComm)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | Boot | Stopped] -- System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vbtenum.sys -- (BTHidEnum)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\btcusb.sys -- (Btcsrusb)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btnetdrv.sys -- (BT)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\blueletaudio.sys -- (BlueletAudio)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (amxayeyl)
DRV - [2013.03.24 19:26:01 | 000,134,336 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2013.03.24 19:26:01 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2013.03.24 19:26:01 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2013.03.24 19:26:00 | 000,083,944 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012.06.27 09:37:56 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2012.06.27 09:37:56 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2012.06.27 09:37:56 | 000,114,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadserd.sys -- (ssadserd)
DRV - [2012.06.27 09:37:56 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadadb.sys -- (androidusb)
DRV - [2012.06.27 09:37:56 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2011.12.23 20:58:18 | 000,020,032 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - [2010.12.05 19:42:29 | 000,072,488 | ---- | M] (AVG) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\qtsmon.sys -- (qtsmon)
DRV - [2010.08.09 13:15:05 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2009.06.12 16:21:40 | 000,500,096 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt61.sys -- (RT61)
DRV - [2008.04.13 21:05:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)
DRV - [2006.11.10 14:03:48 | 000,266,752 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)
DRV - [2006.11.10 02:28:22 | 000,016,896 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)
DRV - [2004.11.17 18:05:38 | 002,297,664 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/
IE - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\..\SearchScopes\{52f54a4f-f372-4aa1-9e79-51086d3eed27}: "URL" =
http://www.zbozi.cz/?q={searchTerms}&r= ... rceid=IE_5
IE - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\..\SearchScopes\{93f786a7-1813-4731-951b-c17cccdfb57d}: "URL" =
http://www.firmy.cz/phr/{searchTerms}?sourceid=IE_5
IE - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\..\SearchScopes\{a0bb6a16-347f-4664-94b2-7505ad405835}: "URL" =
http://search.seznam.cz/?q={searchTerms}&sourceid=IE_5
IE - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\..\SearchScopes\{acec889c-f772-48f6-a6f8-63a71694838f}: "URL" =
http://www.mapy.cz/?query={searchTerms}&sourceid=IE_5
IE - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "
http://seznam.cz"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}:6.0.27
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.23 21:05:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013.03.23 21:05:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2013.03.13 14:45:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010.08.12 08:19:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Hanka\Data aplikací\Mozilla\Extensions
[2010.08.12 07:35:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Hanka\Data aplikací\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013.03.23 21:01:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Hanka\Data aplikací\Mozilla\Firefox\Profiles\m57i6dvm.default\extensions
[2013.03.25 22:30:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.09.23 09:15:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2013.03.23 21:05:23 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2013.03.23 21:05:23 | 000,001,687 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2013.03.23 21:05:23 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2013.03.23 21:05:23 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2013.03.23 21:05:23 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2013.03.25 17:49:02 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Lištička) - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\listicka.dll ()
O3 - HKLM\..\Toolbar: (Nástroje Lištičky) - {1EA00BE1-6E54-4E2A-8099-680300BF23E1} - C:\Program Files\Seznam.cz\toolbar\toolbar.dll ()
O3 - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\..\Toolbar\WebBrowser: (Nástroje Lištičky) - {34AB3C4C-DA1A-4067-96F4-31452C7CFE65} - C:\Program Files\Seznam.cz\listicka.dll ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 16895
O9 - Extra Button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra 'Tools' menuitem : Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra Button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra 'Tools' menuitem : Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Program Files\Seznam.cz\listicka.dll ()
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)
O15 - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\..Trusted Domains: ote-cr.cz ([portal] https in Důvěryhodné servery)
O15 - HKU\S-1-5-21-1004336348-725345543-1177238915-1004\..Trusted Domains: ote-cr.cz ([www] https in Důvěryhodné servery)
O16 - DPF: {A996E48C-D3DC-4244-89F7-AFA33EC60679}
https://portal.ote-cr.cz/otemarket/reso ... apicom.cab (Settings Class)
O16 - DPF: {EC71A2BE-E211-41F9-BCAF-4EFF13426DFE}
https://shop.rossmanncz.orwonet.de/shop ... upload.cab (RossmCZActiveFormX Element)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{57653143-89D9-4C3C-9C99-2EDB296161B8}: NameServer = 82.150.180.253,213.180.44.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6AC07F96-79D9-4FD9-BF50-96F669DB9462}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Hanka\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Hanka\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - VfWWDM32.dll File not found
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2013.03.26 17:54:18 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Hanka\Plocha\OTL.exe
[2013.03.25 21:47:45 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Hanka\Recent
[2013.03.25 00:45:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\Acronis
[2013.03.25 00:18:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Acronis
[2013.03.25 00:16:11 | 000,000,000 | ---D | C] -- C:\Program Files\Acronis
[2013.03.24 22:21:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\rajce
[2013.03.24 22:21:23 | 000,000,000 | ---D | C] -- C:\Program Files\rajce
[2013.03.24 21:55:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\aTube Catcher
[2013.03.24 21:55:07 | 000,000,000 | ---D | C] -- C:\Program Files\DsNET Corp
[2013.03.24 19:34:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Hanka\Data aplikací\Avira
[2013.03.24 19:28:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Avira
[2013.03.24 19:27:15 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2013.03.24 19:27:05 | 000,134,336 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2013.03.24 19:27:05 | 000,083,944 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2013.03.24 19:27:05 | 000,036,552 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\System32\drivers\avkmgr.sys
[2013.03.24 19:27:04 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2013.03.24 19:27:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Avira
[2013.03.24 13:32:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Hanka\Data aplikací\Malwarebytes
[2013.03.24 13:31:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2013.03.23 23:39:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Hanka\Data aplikací\Auslogics
[2013.03.23 23:36:58 | 000,000,000 | ---D | C] -- C:\Program Files\Auslogics
[2013.03.23 22:37:44 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2013.03.23 21:28:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Opera
[2013.03.23 21:28:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Data aplikací\Opera
[2013.03.23 21:02:16 | 000,000,000 | ---D | C] -- D:\Dokumentíky\Stažené soubory
[2013.03.21 21:59:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Hanka\Plocha\UČTO
[2013.03.17 08:30:27 | 000,000,000 | ---D | C] -- D:\Dokumentíky\Nová složka
[2013.03.17 08:30:09 | 000,000,000 | ---D | C] -- D:\Dokumentíky\Prominutí žádosti
[2013.03.13 14:45:38 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2013.03.06 11:56:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Hanka\Local Settings\Data aplikací\Sun
[2013.03.05 09:32:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013.03.05 09:31:22 | 000,143,872 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2013.03.05 09:31:21 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2013.03.05 09:31:09 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2013.03.05 09:31:09 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2013.03.05 09:31:09 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013.03.05 09:30:02 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013.03.04 15:15:49 | 000,000,000 | ---D | C] -- C:\UCTO2013
========== Files - Modified Within 30 Days ==========
[2013.03.26 17:59:58 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013.03.26 17:54:19 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Hanka\Plocha\OTL.exe
[2013.03.26 17:50:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.03.25 22:47:11 | 000,002,563 | ---- | M] () -- C:\Documents and Settings\Hanka\Plocha\Microsoft Office Word 2007.lnk
[2013.03.25 18:59:38 | 000,291,680 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013.03.25 17:49:02 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2013.03.25 00:45:49 | 000,000,155 | ---- | M] () -- C:\WINDOWS\System32\autopart.opt
[2013.03.24 22:21:30 | 000,000,638 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\rajče.lnk
[2013.03.24 21:55:51 | 000,000,839 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\aTube Catcher.lnk
[2013.03.24 19:26:01 | 000,134,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2013.03.24 19:26:01 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\System32\drivers\avkmgr.sys
[2013.03.24 19:26:01 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2013.03.24 19:26:00 | 000,083,944 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2013.03.24 19:03:52 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.03.24 18:37:14 | 000,000,826 | ---- | M] () -- C:\Documents and Settings\Hanka\.recently-used.xbel
[2013.03.23 19:50:24 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2013.03.23 16:59:59 | 000,027,648 | ---- | M] () -- C:\Documents and Settings\Hanka\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.03.14 20:58:09 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013.03.12 21:31:55 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013.03.12 21:31:54 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013.03.05 09:30:35 | 000,094,112 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013.03.05 09:30:27 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2013.03.05 09:30:27 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2013.03.05 09:30:26 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2013.03.05 09:30:26 | 000,143,872 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2013.03.05 09:30:25 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npdeployJava1.dll
[2013.03.05 09:30:24 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2013.03.04 15:16:28 | 000,001,581 | ---- | M] () -- C:\Documents and Settings\Hanka\Plocha\ÚČTO 2013.LNK
[2013.03.04 15:11:35 | 030,382,080 | ---- | M] () -- D:\Dokumentíky\u13_cd.exe
[2013.03.03 14:53:43 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2013.02.28 14:30:42 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Adobe Reader 9.lnk
[2013.02.25 17:36:50 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
========== Files Created - No Company Name ==========
[2013.03.26 17:59:58 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2013.03.25 00:45:49 | 000,000,155 | ---- | C] () -- C:\WINDOWS\System32\autopart.opt
[2013.03.24 22:21:30 | 000,000,638 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\rajče.lnk
[2013.03.24 21:55:51 | 000,000,839 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\aTube Catcher.lnk
[2013.03.24 18:37:14 | 000,000,826 | ---- | C] () -- C:\Documents and Settings\Hanka\.recently-used.xbel
[2013.03.04 15:16:28 | 000,001,581 | ---- | C] () -- C:\Documents and Settings\Hanka\Plocha\ÚČTO 2013.LNK
[2013.03.04 15:10:29 | 030,382,080 | ---- | C] () -- D:\Dokumentíky\u13_cd.exe
[2013.03.03 14:53:43 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Opera.lnk
[2013.03.03 14:53:42 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2012.08.08 12:25:09 | 001,188,443 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2012.08.08 12:25:09 | 000,005,427 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2012.06.14 21:37:30 | 000,037,256 | ---- | C] () -- C:\Documents and Settings\Hanka\Fotečky.jpg
[2012.02.07 23:23:13 | 001,776,036 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1004336348-725345543-1177238915-1004-0.dat
[2012.02.07 23:23:04 | 000,317,834 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
[2011.12.23 20:58:28 | 000,030,568 | ---- | C] () -- C:\WINDOWS\MusiccityDownload.exe
[2011.12.23 20:58:24 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2011.12.23 20:58:24 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011.12.23 20:58:24 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011.12.23 20:58:24 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2011.11.21 22:49:01 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2011.09.07 16:01:55 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.11.17 15:12:56 | 000,000,084 | ---- | C] () -- C:\Documents and Settings\Hanka\.gtk-bookmarks
[2010.08.18 20:20:03 | 000,027,648 | ---- | C] () -- C:\Documents and Settings\Hanka\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 07:51:56 | 001,499,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.09.24 14:43:03 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 07:52:06 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013.03.25 00:18:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Acronis
[2013.01.05 10:33:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
[2010.08.09 13:13:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ashampoo
[2010.12.05 19:42:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVGQTS
[2013.01.05 10:32:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AWEM
[2013.03.24 18:48:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Bluetooth
[2010.08.09 13:14:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2012.01.05 22:29:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\GameHouse
[2013.03.24 13:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2011.02.03 22:06:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Nitro PDF
[2011.09.19 16:12:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\page
[2012.02.07 21:49:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Samsung
[2013.03.24 21:19:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2011.11.14 15:22:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\W3i
[2012.12.13 15:01:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\WildTangent
[2011.11.14 15:31:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A}
[2013.01.05 10:34:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Alawar Entertainment
[2011.09.19 18:38:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Ashampoo
[2013.03.24 21:52:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Auslogics
[2010.08.09 13:36:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\DAEMON Tools Lite
[2012.11.23 16:45:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\gtk-2.0
[2012.01.20 10:02:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Happy Chef
[2013.03.23 16:44:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\ICQ
[2013.03.24 21:31:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Image Zone Express
[2013.01.02 21:27:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Nitro PDF
[2010.08.12 08:03:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\OpenOffice.org
[2011.11.18 09:49:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Opera
[2012.12.25 23:07:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Samsung
[2012.04.08 09:01:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Temp
[2010.08.12 07:35:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Thunderbird
[2011.11.14 15:23:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Uniblue
[2012.12.13 15:01:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\WildTangent
[2013.03.23 21:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Opera
========== Purity Check ==========
========== Custom Scans ==========
< >
[2010.08.09 12:21:19 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2010.08.09 12:26:34 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
< >
< MD5 for: AGP440.SYS >
[2009.09.24 14:51:30 | 017,813,130 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2009.09.24 14:51:30 | 017,813,130 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 07:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2008.04.14 07:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\dllcache\autochk.exe
< MD5 for: CDROM.SYS >
[2009.09.24 14:51:30 | 017,813,130 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.13 23:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2008.04.14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 07:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2009.09.24 14:51:30 | 017,813,130 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.13 23:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2009.09.24 14:51:30 | 017,813,130 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
< MD5 for: ISAPNP.SYS >
[2009.09.24 14:51:30 | 017,813,130 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 06:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2008.04.14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 07:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys
[2008.04.13 23:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2008.04.14 07:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 07:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.14 07:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2009.09.24 14:41:41 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2009.09.24 14:41:41 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\system32\drivers\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 07:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2008.04.14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 07:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2008.04.14 07:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[1 C:\WINDOWS\SoftwareDistribution\Download\07c90dcbdedfe16c2b58e68ce910936a\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\07c90dcbdedfe16c2b58e68ce910936a\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\0bfe47e58d65a90f0263f041ec115a72\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\0bfe47e58d65a90f0263f041ec115a72\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\0efb45fe14af60fce7fe141ae9ac7cc6\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\0efb45fe14af60fce7fe141ae9ac7cc6\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\0fedacd112dd13ad60761d9dc1180f1d\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\0fedacd112dd13ad60761d9dc1180f1d\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\1c3802531a1bdc5c0b934fb898785ca0\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\1c3802531a1bdc5c0b934fb898785ca0\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\41b2219405346d6421a1b21083eb6dd7\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\41b2219405346d6421a1b21083eb6dd7\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\43c07bfbb59d299ee8343d57713c3c0b\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\43c07bfbb59d299ee8343d57713c3c0b\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\4a6ebf52efbec44d28d5c0135c216a55\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\4a6ebf52efbec44d28d5c0135c216a55\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\508483484f3a183df6329500a0689df5\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\508483484f3a183df6329500a0689df5\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\5098dd9035927e206645a10b773e39d3\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\5098dd9035927e206645a10b773e39d3\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\509ce25d45fe208ee57ad15aa1012d9c\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\509ce25d45fe208ee57ad15aa1012d9c\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\5b1bf3c709a0479f95a0d490dc626aff\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\5b1bf3c709a0479f95a0d490dc626aff\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\6eb64538d1eb8e0e92baa96fc62ba854\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\6eb64538d1eb8e0e92baa96fc62ba854\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\8573f895b9caebec15a2846b147c4acc\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\8573f895b9caebec15a2846b147c4acc\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\94cb1155beed812ad7f0048d578b46e3\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\94cb1155beed812ad7f0048d578b46e3\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\987eadf0fc9ebf772c42ab3ca2bcfc3d\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\987eadf0fc9ebf772c42ab3ca2bcfc3d\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\a9de1b2071cad5998138befbe3b835b7\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\a9de1b2071cad5998138befbe3b835b7\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\af5e05ccd2c15416e9facffaeb01ca3b\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\af5e05ccd2c15416e9facffaeb01ca3b\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\b3ba0f7542150a0ff634f02bb11873ed\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\b3ba0f7542150a0ff634f02bb11873ed\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\b41185fd9ddb4a55a576f995b3e93215\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\b41185fd9ddb4a55a576f995b3e93215\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\be21e799c4114ec3b7e78e2497c5dec7\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\be21e799c4114ec3b7e78e2497c5dec7\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\d2e1f16f5be8fded7ed4631ce3e9160d\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\d2e1f16f5be8fded7ed4631ce3e9160d\download\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\ee98c73f0904cb50e0d59ccbd186551f\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\ee98c73f0904cb50e0d59ccbd186551f\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\ef042df797d3a27a3a89d1ad98b64d89\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\ef042df797d3a27a3a89d1ad98b64d89\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\fd674b0793556498419dc6d88ead9cda\download\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\fd674b0793556498419dc6d88ead9cda\download\*.tmp -> ]
[1 C:\WINDOWS\twain_32\*.tmp files -> C:\WINDOWS\twain_32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2012.06.14 21:31:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Adobe
[2013.01.05 10:34:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Alawar Entertainment
[2011.09.19 18:38:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Ashampoo
[2013.03.24 21:52:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Auslogics
[2013.03.24 19:34:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Avira
[2012.09.12 17:15:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\CyberLink
[2010.08.09 13:36:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\DAEMON Tools Lite
[2010.08.09 13:07:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\FastStone
[2012.11.23 16:45:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\gtk-2.0
[2012.01.20 10:02:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Happy Chef
[2010.08.24 17:01:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\HP
[2013.03.23 16:44:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\ICQ
[2010.08.09 12:27:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Identities
[2013.03.24 21:31:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Image Zone Express
[2010.08.11 22:46:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Macromedia
[2013.03.24 13:32:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Malwarebytes
[2013.02.23 15:57:03 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Hanka\Data aplikací\Microsoft
[2010.08.12 08:19:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Mozilla
[2010.08.19 13:32:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Nero
[2013.01.02 21:27:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Nitro PDF
[2010.08.12 08:03:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\OpenOffice.org
[2011.11.18 09:49:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Opera
[2012.12.25 23:07:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Samsung
[2013.03.23 18:21:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Skype
[2013.03.23 17:17:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\skypePM
[2011.09.23 09:13:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Sun
[2012.04.08 09:01:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Temp
[2010.08.12 07:35:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Thunderbird
[2011.11.14 15:23:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Uniblue
[2012.12.13 15:01:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\WildTangent
[2013.03.14 18:14:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\Winamp
[2010.08.30 14:10:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanka\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
[2012.03.15 17:53:33 | 000,106,408 | ---- | M] () -- C:\Documents and Settings\Hanka\Data aplikací\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentInstaller.exe
[2012.03.15 17:53:34 | 000,101,288 | ---- | M] () -- C:\Documents and Settings\Hanka\Data aplikací\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentUpdate.exe
[2012.03.15 17:53:35 | 000,021,416 | ---- | M] () -- C:\Documents and Settings\Hanka\Data aplikací\Samsung\Kies\FirmwareUpdateTemp\AGENT\KiesPDLR.exe
[2012.08.31 01:52:26 | 000,593,848 | ---- | M] (ml) -- C:\Documents and Settings\Hanka\Data aplikací\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
[2013.01.10 10:02:20 | 000,601,968 | ---- | M] (ml) -- C:\Documents and Settings\Hanka\Data aplikací\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.08.09 13:15:05 | 000,691,696 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2010.08.09 14:11:35 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2010.08.09 14:11:35 | 001,069,056 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2010.08.09 14:11:35 | 000,483,328 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
[2013.03.24 19:26:00 | 000,083,944 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\system32\drivers\avgntflt.sys
[2013.03.24 19:26:01 | 000,134,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\system32\drivers\avipbb.sys
[2013.03.24 19:26:01 | 000,036,552 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\WINDOWS\system32\drivers\avkmgr.sys
[2013.03.24 19:26:01 | 000,028,520 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\ssmdrv.sys
< %systemroot%\system32\*.* /3 >
[2013.03.25 00:45:49 | 000,000,155 | ---- | M] () -- C:\WINDOWS\system32\autopart.opt
[2013.03.25 18:59:38 | 000,291,680 | ---- | M] () -- C:\WINDOWS\system32\FNTCACHE.DAT
[2013.03.24 19:03:52 | 000,013,646 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 07:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< >
< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.03.26 17:59:58 | 000,000,512 | ---- | M] () MD5=BA9709D2F4CC35E38CE9FE7B77D5766E -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2010.10.04 22:50:56 | 000,062,238 | ---- | M] () -- \Program Files\GIMP-2.0\share\gimp\2.0\patterns\cracked.pat
< *keygen* /s >
< *loader* /s >
[2009.07.20 10:52:26 | 000,000,232 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Nero\OnlineServices\NOSWebConfig\MySpace\uploadError.xml
[2013.03.24 19:25:29 | 000,052,960 | ---- | M] () -- \Program Files\Avira\AntiVir Desktop\avwebloader.dll
[2013.03.24 19:25:29 | 000,232,816 | ---- | M] () -- \Program Files\Avira\AntiVir Desktop\avwebloader.exe
[2013.03.24 19:25:30 | 001,714,400 | ---- | M] () -- \Program Files\Avira\AntiVir Desktop\avwebloadergui.dll
[3 \Program Files\Avira\AntiVir Desktop\*.tmp files -> \Program Files\Avira\AntiVir Desktop\*.tmp -> ]
[2006.10.26 12:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.dll
[2006.10.26 12:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.tlb
[2010.02.07 22:40:00 | 000,000,543 | ---- | M] () -- \Program Files\GIMP-2.0\etc\gtk-2.0\gdk-pixbuf.loaders
[2009.12.15 18:58:18 | 000,017,056 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-ani.dll
[2009.12.15 18:58:20 | 000,018,592 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-bmp.dll
[2009.12.15 18:58:24 | 000,026,272 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-gif.dll
[2009.12.15 18:58:26 | 000,012,960 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-icns.dll
[2009.12.15 18:58:28 | 000,017,568 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-ico.dll
[2009.12.15 18:58:56 | 000,019,616 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-jpeg.dll
[2009.12.15 18:59:04 | 000,015,008 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-pcx.dll
[2009.12.15 18:59:06 | 000,019,104 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-png.dll
[2009.12.15 18:59:10 | 000,017,056 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-pnm.dll
[2009.12.15 18:59:14 | 000,012,448 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-ras.dll
[2009.12.15 18:59:16 | 000,016,544 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-tga.dll
[2009.12.15 18:59:20 | 000,016,544 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-tiff.dll
[2009.12.15 18:59:22 | 000,011,936 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-wbmp.dll
[2009.12.15 18:59:24 | 000,013,984 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-xbm.dll
[2009.12.15 18:59:28 | 000,028,320 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\libpixbufloader-xpm.dll
[2009.05.01 20:42:00 | 000,009,880 | ---- | M] () -- \Program Files\GIMP-2.0\lib\gtk-2.0\2.10.0\loaders\svg_loader.dll
[2011.04.04 11:32:47 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.4\imApp\theme\IMAGES\XtraPreloader\loader.jpg
[2011.04.04 11:32:48 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.4\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png
[2011.04.04 11:32:47 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.4\imApp\theme\MUICoreLib\xtraLoader.swf
[2011.04.11 12:00:20 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.4\Xtraz\icq\content\icq_profile\preloader.html
[2011.04.04 11:33:05 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.4\Xtraz\icq\content\profile_forms\preloader.html
[2011.04.04 11:33:05 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.4\Xtraz\icq\content\profile_lightboxs\preloader.html
[2011.10.11 08:34:40 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\IMAGES\XtraPreloader\loader.jpg
[2011.10.11 08:34:41 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png
[2011.10.11 08:34:40 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\MUICoreLib\xtraLoader.swf
[2011.10.11 20:37:28 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.6\Xtraz\icq\content\profile_lightboxs\preloader.html
[2010.06.07 20:11:08 | 000,006,262 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.py
[2010.08.12 08:02:14 | 000,021,504 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.dll
[2010.06.07 20:19:10 | 000,000,171 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.ini
[2010.08.12 08:02:23 | 000,029,184 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\bin\javaloader.uno.dll
[2010.06.09 15:21:40 | 000,003,874 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\java\unoloader.jar
[2012.08.31 01:48:34 | 000,069,120 | ---- | M] () -- \Program Files\Samsung\Kies\Common\Kies.Common.DeviceServiceLib.FirmwareUpdate.Downloader.dll
[2012.08.31 01:52:20 | 000,183,736 | ---- | M] () -- \Program Files\Samsung\Kies\External\FirmwareUpdate\BinaryLoaderMgr.exe
[2012.02.07 22:56:51 | 000,153,512 | ---- | M] () -- \Program Files\Samsung\Kies\External\FirmwareUpdate\GT-S5830\BinaryLoaderMgr.exe
[2012.02.07 22:56:51 | 000,270,248 | ---- | M] () -- \Program Files\Samsung\Kies\External\FirmwareUpdate\GT-S5830\FirmwareUpdate.Downloader.dll
[2012.08.31 01:48:34 | 000,069,120 | ---- | M] () -- \Program Files\Samsung\Kies\Plugins\DeviceHost\Kies.Common.DeviceServiceLib.FirmwareUpdate.Downloader.dll
[2010.02.10 17:10:14 | 000,045,056 | ---- | M] () -- \Program Files\WinRAR\RarExtLoader.exe
[2012.09.22 07:21:24 | 000,189,440 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\daa83fc7417177004595ee4a94e467ec\Kies.Common.DeviceServiceLib.FirmwareUpdate.Downloader.ni.dll
[2008.04.14 07:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[2008.04.14 07:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dllcache\dmloader.dll
< *minodlogin* /s >
< *tnod* /s >
< *AutoKMS* /s >
< *activator* /s >
< *serial* /s >
[2012.01.11 21:10:50 | 000,000,581 | ---- | M] () -- \Documents and Settings\Hanka\Local Settings\Data aplikací\Opera\Opera\icons\http%3A%2F%2Fwww.serialzone.cz%2Ffavicon.png
[2012.03.29 05:01:00 | 000,413,696 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.1.10329.0\System.Runtime.Serialization.dll
[2012.08.21 19:59:39 | 001,186,816 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.1.10329.0\System.Runtime.Serialization.ni.dll
[2012.02.07 21:52:41 | 000,310,272 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\d0ff3383438d688a0118d0fa19ed1dc4\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2012.02.07 21:52:28 | 002,625,024 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\e9f8a45b1063d6c6a62718c88a5623d1\System.Runtime.Serialization.ni.dll
[2010.10.07 09:03:33 | 000,013,972 | ---- | M] () -- \WINDOWS\inf\SocketSerialBT.PNF
[2012.03.01 15:58:33 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2012.03.01 15:58:10 | 001,026,936 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2010.03.18 13:16:28 | 001,026,936 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 13:16:28 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2004.08.18 13:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dpserial.dll
[2004.08.18 13:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\serialui.dll
[2004.08.18 13:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dllcache\dpserial.dll
[2004.08.18 13:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\dllcache\serialui.dll
[2008.04.14 06:51:10 | 000,064,256 | ---- | M] () -- \WINDOWS\system32\drivers\serial.sys
< *w7lxe* /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:587EB586
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
< End of report >