Re: policejní vír
Napsal: 01 črc 2013 22:26
OTL logfile created on: 1.7.2013 23:02:08 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\michal\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1,25 Gb Total Physical Memory | 0,50 Gb Available Physical Memory | 40,05% Memory free
1,85 Gb Paging File | 1,25 Gb Available in Paging File | 67,54% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 36,20 Gb Total Space | 16,36 Gb Free Space | 45,18% Space Free | Partition Type: FAT32
Drive D: | 36,35 Gb Total Space | 36,07 Gb Free Space | 99,22% Space Free | Partition Type: FAT32
Computer Name: ASER | User Name: michal | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2013.07.01 22:55:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\michal\Plocha\OTL.exe
PRC - [2013.05.09 10:58:36 | 006,583,664 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\Setup\avast.setup
PRC - [2013.05.09 10:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.12.25 17:54:40 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre1.7.0_07\bin\jqs.exe
PRC - [2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.04.25 15:36:26 | 000,835,584 | ---- | M] () -- C:\WINDOWS\vsnp325.exe
PRC - [2007.04.21 09:30:54 | 000,270,336 | ---- | M] () -- C:\WINDOWS\tsnp325.exe
PRC - [2007.02.12 14:50:40 | 000,020,480 | ---- | M] () -- C:\WINDOWS\FixCamera.exe
PRC - [2007.01.21 13:51:02 | 000,488,448 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Documents and Settings\michal\Local Settings\Temp\RtkBtMnt.EXE
PRC - [2006.11.17 05:42:52 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe
PRC - [2005.11.08 02:31:48 | 000,278,528 | ---- | M] (InterVideo Inc.) -- C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
PRC - [2005.07.25 12:00:56 | 000,876,032 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2005.03.28 13:52:08 | 000,360,448 | ---- | M] (acer Inc.) -- C:\Program Files\acer\eRecovery\Monitor.exe
PRC - [2005.01.31 08:05:50 | 000,253,952 | ---- | M] (Atheros Communications, Inc.) -- C:\Program Files\Atheros\ACU.exe
PRC - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
PRC - [2004.08.05 17:23:10 | 000,308,352 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
PRC - [2004.05.17 14:57:00 | 000,184,320 | ---- | M] (O&O Software GmbH) -- C:\WINDOWS\system32\oodag.exe
PRC - [2002.12.20 16:18:40 | 000,200,704 | ---- | M] (FUJI PHOTO FILM CO., LTD.) -- C:\Program Files\FinePixViewer\QuickDCF.exe
========== Modules (No Company Name) ==========
MOD - [2013.05.09 10:58:26 | 000,240,448 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\Setup\setiface.dll
MOD - [2013.05.09 10:49:30 | 002,085,376 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\13050900\algo.dll
MOD - [2007.04.25 15:36:26 | 000,835,584 | ---- | M] () -- C:\WINDOWS\vsnp325.exe
MOD - [2007.04.21 09:30:54 | 000,270,336 | ---- | M] () -- C:\WINDOWS\tsnp325.exe
MOD - [2007.02.12 14:50:40 | 000,020,480 | ---- | M] () -- C:\WINDOWS\FixCamera.exe
MOD - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
========== Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013.03.14 12:56:56 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.12.25 17:54:40 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre1.7.0_07\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012.12.23 15:18:20 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.03.20 13:08:30 | 000,008,704 | ---- | M] (Vodafone) [Auto | Stopped] -- C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe -- (VmbService)
SRV - [2005.07.25 12:00:56 | 000,876,032 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
SRV - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)
SRV - [2004.08.05 17:23:10 | 000,308,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- (SymWSC)
SRV - [2004.05.17 14:57:00 | 000,184,320 | ---- | M] (O&O Software GmbH) [Auto | Running] -- C:\WINDOWS\system32\oodag.exe -- (O&O Defrag)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Launch Manager\POWERKEY.sys -- (POWERKEY)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\PhTVTune.sys -- (PhTVTune)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\PCASp50.sys -- (PCASp50)
DRV - File not found [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\osanbm.sys -- (osanbm)
DRV - File not found [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\osaio.sys -- (osaio)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Cap7134.sys -- (Cap7134)
DRV - [2013.07.01 22:53:18 | 000,770,344 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2013.07.01 22:53:18 | 000,369,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2013.07.01 22:53:18 | 000,175,176 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2013.05.09 10:59:10 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2013.05.09 10:59:10 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2013.05.09 10:59:10 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2013.05.09 10:59:10 | 000,049,376 | ---- | M] () [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013.05.09 10:59:08 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.03.16 14:55:26 | 000,239,488 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2012.03.16 14:55:26 | 000,195,200 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2012.03.16 14:55:26 | 000,102,784 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2012.03.16 14:55:26 | 000,089,856 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - [2012.03.16 14:55:26 | 000,073,984 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2012.03.16 14:55:26 | 000,066,688 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_jucdcecm.sys -- (huawei_cdcecm)
DRV - [2012.03.16 14:55:26 | 000,026,624 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl)
DRV - [2012.03.16 14:55:26 | 000,011,136 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter)
DRV - [2007.04.26 11:03:12 | 010,343,168 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snp325.sys -- (SNP325)
DRV - [2007.01.14 16:28:36 | 000,034,760 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2006.12.29 14:48:06 | 004,026,112 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM)
DRV - [2006.07.20 20:40:00 | 000,332,800 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AG120.sys -- (AG120(ZyXEL)
DRV - [2005.07.25 11:53:30 | 000,008,704 | ---- | M] (Nero AG) [Recognizer | System | Unknown] -- C:\WINDOWS\System32\drivers\InCDrec.sys -- (InCDrec)
DRV - [2005.07.25 11:53:28 | 000,101,504 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005.07.25 11:53:04 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2005.07.25 11:53:00 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)
DRV - [2005.02.08 16:33:06 | 000,970,240 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005.01.13 14:46:16 | 000,069,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\acer\eRecovery\int15.sys -- (int15.sys)
DRV - [2005.01.10 15:47:14 | 000,449,888 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2004.12.21 03:32:12 | 000,369,024 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2004.12.15 15:18:30 | 000,200,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWATI.sys -- (HSFHWATI)
DRV - [2004.12.15 15:18:28 | 000,703,232 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2004.12.15 15:18:26 | 001,038,208 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2004.12.01 18:36:08 | 000,070,912 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)
DRV - [2004.09.14 02:40:56 | 000,146,304 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2004.08.03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)
DRV - [2004.03.02 16:37:50 | 000,125,184 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\imagesrv.sys -- (imagesrv)
DRV - [2004.03.02 16:37:48 | 000,005,504 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\imagedrv.sys -- (imagedrv)
DRV - [2003.12.05 18:46:36 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy.karneval.cz:3128
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://www.centrum.cz/"
FF - prefs.js..extensions.enabledAddons: centrumpomocnik%40centrum.cz:1.1
FF - prefs.js..extensions.enabledAddons: %7B800b5000-a755-47e1-992b-48a1c1357f07%7D:1.5.3
FF - prefs.js..extensions.enabledAddons: %7Bea614400-e918-4741-9a97-7a972ff7c30b%7D:2.5.15
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..network.proxy.ftp: "proxy.karneval.cz"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "proxy.karneval.cz"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "proxy.karneval.cz"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "proxy.karneval.cz"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "proxy.karneval.cz"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre1.7.0_07\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2088: C:\Program Files\K-Lite Codec Pack\real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1069: C:\Program Files\K-Lite Codec Pack\real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/Acrobat,version=5.1: C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.07.01 22:52:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.14 12:56:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2010.10.23 21:20:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Extensions
[2005.10.31 14:32:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\extensions
[2013.04.29 10:56:52 | 000,000,000 | ---D | M] (Seznam lištiÄŤka) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[2012.01.01 12:11:22 | 000,000,000 | ---D | M] (Centrum domĂ©novĂ˝ pomocnĂk) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\extensions\centrumpomocnik@centrum.cz
[2011.11.10 11:26:50 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-11.xml
[2012.01.01 12:11:28 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-12.xml
[2012.01.01 14:11:54 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-13.xml
[2012.01.20 20:50:28 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-14.xml
[2012.01.20 22:52:22 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-15.xml
[2012.04.24 22:49:30 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-16.xml
[2012.04.25 08:50:12 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-17.xml
[2012.08.02 21:59:54 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-18.xml
[2013.02.18 09:53:52 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-19.xml
[2013.02.18 09:57:42 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-20.xml
[2013.04.10 08:55:14 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-21.xml
[2013.03.14 12:56:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013.03.14 12:56:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\distribution\extensions
[2013.03.14 12:56:22 | 000,000,000 | ---D | M] (Seznam lištička) -- C:\Program Files\Mozilla Firefox\distribution\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\{EA614400-E918-4741-9A97-7A972FF7C30B}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\CENTRUMPOMOCNIK@CENTRUM.CZ
[2013.03.14 12:56:58 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013.03.14 12:56:52 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
[2013.03.14 12:56:52 | 000,000,867 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2013.03.14 12:56:52 | 000,001,580 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2013.03.14 12:56:52 | 000,000,851 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2013.03.14 12:56:52 | 000,002,421 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
O1 HOSTS File: ([2004.08.18 05:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.7.0_07\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.7.0_07\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [ACU] C:\Program Files\Atheros\ACU.exe (Atheros Communications, Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [eRecoveryService] C:\WINDOWS\system32\Check.exe (acer Inc.)
O4 - HKLM..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe ()
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [preload] C:\WINDOWS\RUNXMLPL.EXE (Wistron)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [snp325] C:\WINDOWS\vsnp325.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [tsnp325] C:\WINDOWS\tsnp325.exe ()
O4 - HKCU..\Run: [DefaultScope] File not found
O4 - HKLM..\RunOnce: [SymInstallStub] C:\WINDOWS\System32\Adobe\Shockwave 12\SymInstallStub.exe (Symantec Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe (FUJI PHOTO FILM CO., LTD.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O12 - Plugin for: .mov - C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll (Apple Computer, Inc.)
O12 - Plugin for: .spop - Reg Error: Value error. File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/wind ... 6275069656 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C331F4CA-1704-4B66-8B58-02813C76C8E7}: DhcpNameServer = 192.168.1.2
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{0a6b2edc-8197-11e2-9ff7-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{0a6b2edc-8197-11e2-9ff7-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{108d712c-4d0c-11e2-9fcf-000ae4e102c4}\Shell\AutoRun\command - "" = F:\Toshiba\Launcher\start.exe
O33 - MountPoints2\{1f374922-5a2d-11e2-9fde-000ae4e102c4}\Shell - "" = AutoRun
O33 - MountPoints2\{1f374922-5a2d-11e2-9fde-000ae4e102c4}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{1f374923-5a2d-11e2-9fde-000ae4e102c4}\Shell - "" = AutoRun
O33 - MountPoints2\{1f374923-5a2d-11e2-9fde-000ae4e102c4}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{431be504-7c16-11e2-9ff6-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{431be504-7c16-11e2-9ff6-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{45a9bf54-8bce-11e2-a001-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{45a9bf54-8bce-11e2-a001-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{4904b514-69eb-11e2-9fe4-001e101fcbdc}\Shell - "" = AutoRun
O33 - MountPoints2\{4904b514-69eb-11e2-9fe4-001e101fcbdc}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{7b6b6e54-8a3d-11e2-9fff-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{7b6b6e54-8a3d-11e2-9fff-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{a5022804-7109-11e2-9feb-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{a5022804-7109-11e2-9feb-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{b6354008-71df-11e2-9fec-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{b6354008-71df-11e2-9fec-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{bb5ea302-8a3b-11e2-9ffe-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{bb5ea302-8a3b-11e2-9ffe-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{c09951f2-69dc-11e2-9fe1-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{c09951f2-69dc-11e2-9fe1-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{e49b5bca-69d4-11e2-9fe0-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{e49b5bca-69d4-11e2-9fe0-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (OODBS)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Ligos Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.3iv2 - C:\WINDOWS\System32\3ivxVfWCodec.dll (3ivx.com)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: VIDC.IV40 - C:\WINDOWS\System32\Ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv41 - C:\WINDOWS\System32\Ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\Ir50_32.dll (Ligos Corporation)
Drivers32: VIDC.VP31 - C:\WINDOWS\System32\vp31vfw.dll (On2.com)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.wmv3 - C:\WINDOWS\System32\WMV9VCM.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2013.07.01 22:55:32 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\michal\Plocha\OTL.exe
[2013.07.01 22:53:11 | 000,029,816 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2013.07.01 22:53:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\avast! Free Antivirus
[2013.07.01 22:53:10 | 000,369,584 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2013.07.01 22:53:09 | 000,049,760 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2013.07.01 22:53:08 | 000,770,344 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2013.07.01 22:53:08 | 000,056,080 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2013.07.01 22:53:06 | 000,229,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2013.07.01 22:53:06 | 000,066,336 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys
[2013.07.01 22:52:06 | 000,041,664 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2013.07.01 22:51:27 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2013.07.01 22:50:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2013.07.01 22:11:46 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2013.07.01 22:11:45 | 000,000,000 | ---D | C] -- C:\rsit
[2013.07.01 21:19:29 | 000,000,000 | ---D | C] -- C:\FRST
[2013.07.01 21:18:49 | 001,371,463 | ---- | C] (Farbar) -- C:\Documents and Settings\michal\Plocha\FRST.exe
[2013.07.01 02:27:08 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.06.25 15:10:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2007.01.21 13:31:48 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\michal\Data aplikací\pcouffin.sys
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 7 Days ==========
[2013.07.01 23:06:48 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013.07.01 22:55:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\michal\Plocha\OTL.exe
[2013.07.01 22:53:18 | 000,770,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2013.07.01 22:53:18 | 000,369,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2013.07.01 22:53:18 | 000,175,176 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013.07.01 22:53:18 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum
[2013.07.01 22:53:18 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum
[2013.07.01 22:53:18 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum
[2013.07.01 22:53:12 | 000,001,597 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2013.07.01 22:53:08 | 000,002,504 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2013.07.01 22:53:08 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013.07.01 22:41:48 | 000,000,692 | ---- | M] () -- C:\WINDOWS\System32\eRLog.ini
[2013.07.01 22:41:46 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.07.01 22:40:20 | 000,000,096 | ---- | M] () -- C:\WINDOWS\ComponentList.xml
[2013.07.01 22:40:06 | 000,000,636 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Product InstallerIdle.job
[2013.07.01 22:40:06 | 000,000,628 | ---- | M] () -- C:\WINDOWS\tasks\Norton Product Installer.job
[2013.07.01 22:39:34 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.07.01 22:39:26 | 1340,313,600 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.01 22:39:22 | 000,363,750 | ---- | M] () -- C:\WINDOWS\System32\OODBS.lor
[2013.07.01 22:18:28 | 000,648,201 | ---- | M] () -- C:\Documents and Settings\michal\Plocha\adwcleaner.exe
[2013.07.01 22:10:48 | 000,781,383 | ---- | M] () -- C:\Documents and Settings\michal\Plocha\RSIT.exe
[2013.07.01 21:27:02 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013.07.01 21:18:20 | 000,000,714 | ---- | M] () -- C:\Documents and Settings\michal\wincmd.ini
[2013.06.28 21:54:14 | 001,371,463 | ---- | M] (Farbar) -- C:\Documents and Settings\michal\Plocha\FRST.exe
[2013.06.28 21:32:24 | 095,023,320 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\eej88.pad
[2013.06.25 15:25:18 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013.06.25 15:09:54 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\michal\Nabídka Start\Programy\Po spuštění\regmonstd.lnk
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.07.01 23:00:50 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2013.07.01 22:53:17 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum
[2013.07.01 22:53:17 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum
[2013.07.01 22:53:17 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum
[2013.07.01 22:53:11 | 000,001,597 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2013.07.01 22:53:08 | 000,175,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013.07.01 22:53:07 | 000,049,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2013.07.01 22:53:07 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013.07.01 22:19:09 | 000,648,201 | ---- | C] () -- C:\Documents and Settings\michal\Plocha\adwcleaner.exe
[2013.07.01 22:11:39 | 000,781,383 | ---- | C] () -- C:\Documents and Settings\michal\Plocha\RSIT.exe
[2013.07.01 21:17:23 | 000,000,692 | ---- | C] () -- C:\WINDOWS\System32\eRLog.ini
[2013.07.01 21:15:38 | 000,000,096 | ---- | C] () -- C:\WINDOWS\ComponentList.xml
[2013.06.25 15:19:02 | 000,000,628 | ---- | C] () -- C:\WINDOWS\tasks\Norton Product Installer.job
[2013.06.25 15:19:01 | 000,000,636 | -H-- | C] () -- C:\WINDOWS\tasks\Norton Product InstallerIdle.job
[2013.06.25 15:09:52 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\michal\Nabídka Start\Programy\Po spuštění\regmonstd.lnk
[2013.06.25 15:09:31 | 095,023,320 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\eej88.pad
[2013.02.03 15:29:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.04.20 20:55:40 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.03.16 14:55:44 | 000,286,678 | R--- | C] () -- C:\Documents and Settings\All Users\Data aplikací\DeviceManager.xml.rc4
[2007.01.21 13:31:48 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\ezpinst.exe
[2007.01.21 13:31:48 | 000,007,824 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\pcouffin.cat
[2007.01.21 13:31:48 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\pcouffin.inf
[2007.01.21 13:09:22 | 000,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\.zreglib
[2006.02.02 12:41:12 | 000,000,714 | ---- | C] () -- C:\Documents and Settings\michal\wincmd.ini
[2005.08.01 21:38:32 | 000,000,083 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\sversion.ini
[2005.07.19 03:01:41 | 000,078,848 | ---- | C] () -- C:\Documents and Settings\michal\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005.07.15 22:24:44 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\michal\Local Settings\Data aplikací\fusioncache.dat
[2005.04.11 18:47:34 | 000,001,648 | ---- | C] () -- C:\Program Files\Adobe Reader 6.0.lnk
========== ZeroAccess Check ==========
[2005.07.15 22:10:52 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 04:21:56 | 001,499,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 11:56:06 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 04:22:06 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2005.07.15 22:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Autodesk
[2005.11.20 13:13:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NtiDvdCopy
[2007.01.21 14:10:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ACD Systems
[2010.08.20 21:14:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg9
[2011.03.16 21:18:56 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2011.06.15 13:01:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2012.02.01 19:52:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2013.01.29 06:31:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Vodafone
[2013.07.01 22:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2005.07.15 22:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Autodesk
[2005.07.19 02:56:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\FUJIFILM
[2005.10.08 10:50:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ
[2006.06.03 15:39:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterTrust
[2006.11.26 19:50:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\PC Suite
[2007.01.21 13:31:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vso
[2007.01.21 15:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterVideo
[2007.01.31 19:49:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ACD Systems
[2007.04.24 22:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ Toolbar
[2013.01.29 06:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vodafone
[2013.02.17 15:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz
[2013.04.29 10:41:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\TuneUp Software
========== Purity Check ==========
========== Custom Scans ==========
< >
[1980.01.01 00:00:00 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2004.09.17 12:16:27 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2012.12.23 15:18:23 | 000,000,914 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2013.06.25 15:19:01 | 000,000,636 | -H-- | C] () -- C:\WINDOWS\Tasks\Norton Product InstallerIdle.job
[2013.06.25 15:19:02 | 000,000,628 | ---- | C] () -- C:\WINDOWS\Tasks\Norton Product Installer.job
[2013.07.01 22:53:07 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
< >
< MD5 for: ATAPI.SYS >
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2004.08.18 05:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\I386\AUTOCHK.EXE
[2004.08.18 05:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe
< MD5 for: CDROM.SYS >
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\I386\sp2.cab:cdrom.sys
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2004.08.18 05:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004.08.18 05:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: HAL.DLL >
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\I386\sp2.cab:hal.dll
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.13 19:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.13 19:31:28 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL
[2004.08.18 05:00:00 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
< MD5 for: SCECLI.DLL >
[2004.08.18 05:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SERVICES.EXE >
[2009.02.09 10:54:36 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=33081FED75032291EE0E008D5385E86F -- C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe
[2009.02.09 12:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009.02.09 11:11:38 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=4F9F7B567970B524F31D9970A23F7C24 -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2004.08.18 05:00:00 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=6E401E61F952FBBF708AFBECEFAFAE81 -- C:\WINDOWS\$NtUninstallKB956572_0$\services.exe
[2009.02.09 12:25:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009.02.09 12:25:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 12:25:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\services.exe
[2008.04.14 04:22:46 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008.04.14 04:22:46 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\ServicePackFiles\i386\services.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004.08.18 05:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: TCPIP.SYS >
[2006.04.20 13:51:50 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=1DBF125862891817F374F407626967F4 -- C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
[2008.06.20 11:45:14 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2006.01.13 18:07:08 | 000,360,448 | ---- | M] (Microsoft Corporation) MD5=5562CC0A47B2AEF06D3417B733F3C195 -- C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[2006.01.13 03:28:14 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=583E063FDC888CA30D05C2724B0D7EF4 -- C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
[2005.05.25 20:07:12 | 000,359,936 | ---- | M] (Microsoft Corporation) MD5=63FDFEA54EB53DE2D863EE454937CE1E -- C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[2008.06.20 11:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2005.05.25 20:04:02 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=88763A98A4C26C409741B4AA162720C9 -- C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.18 05:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2006.04.20 14:18:36 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004.08.18 05:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.18 05:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 04:22:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:22:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< >
< %systemroot%*.* /U /s >
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[22 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[1 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2004.09.17 12:16:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Identities
[2004.09.17 12:03:12 | 000,000,000 | --SD | M] -- C:\Documents and Settings\michal\Data aplikací\Microsoft
[2005.07.11 17:51:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Adobe
[2005.07.11 17:51:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\AdobeUM
[2005.07.11 17:53:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\CyberLink
[2005.07.15 04:19:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Help
[2005.07.15 21:46:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Symantec
[2005.07.15 22:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Autodesk
[2005.07.19 02:56:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\FUJIFILM
[2005.08.01 21:43:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Media Player Classic
[2005.09.13 14:12:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Macromedia
[2005.09.13 23:41:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Real
[2005.09.14 21:26:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Corel
[2005.09.20 20:30:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Sun
[2005.10.08 10:50:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ
[2005.10.30 18:00:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Mozilla
[2006.04.29 17:09:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Ahead
[2006.06.03 15:39:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterTrust
[2006.11.26 19:50:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\PC Suite
[2007.01.21 12:52:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Winamp
[2007.01.21 13:31:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vso
[2007.01.21 15:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterVideo
[2007.01.31 19:49:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ACD Systems
[2007.04.24 22:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ Toolbar
[2007.05.06 21:28:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Skype
[2007.07.06 10:40:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InstallShield
[2010.09.05 21:27:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\skypePM
[2013.01.29 06:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vodafone
[2013.02.17 15:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz
[2013.02.17 15:39:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\vlc
[2013.04.29 10:41:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\TuneUp Software
< %APPDATA%\*.exe /s >
[2007.01.21 13:31:50 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\ezpinst.exe
[2012.09.14 14:06:28 | 002,515,592 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz\sznsetup.exe
[2012.09.13 15:24:48 | 001,009,288 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz\szninstall.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job >
[2012.12.23 15:18:24 | 000,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2013.07.01 22:40:06 | 000,000,636 | -H-- | M] () -- C:\WINDOWS\Tasks\Norton Product InstallerIdle.job
[2013.07.01 22:40:06 | 000,000,628 | ---- | M] () -- C:\WINDOWS\Tasks\Norton Product Installer.job
[2013.07.01 22:53:08 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2004.09.17 12:02:34 | 000,471,040 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
[2004.09.17 12:02:34 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2004.09.17 12:02:34 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
[2013.07.01 22:53:18 | 000,175,176 | ---- | M] () -- C:\WINDOWS\system32\drivers\aswVmm.sys
[2013.07.01 22:53:18 | 000,770,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswSnx.sys
[2013.07.01 22:53:18 | 000,369,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswSP.sys
< %systemroot%\system32\*.* /3 >
[2013.07.01 22:41:46 | 000,001,158 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2013.07.01 22:41:48 | 000,000,692 | ---- | M] () -- C:\WINDOWS\system32\eRLog.ini
[2013.07.01 21:27:12 | 073,381,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MRT.exe
[2013.07.01 22:53:08 | 000,002,504 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT
[2013.07.01 22:39:22 | 000,363,750 | ---- | M] () -- C:\WINDOWS\system32\OODBS.lor
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 04:22:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
"DefaultScope" =
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2013.03.14 12:56:58 | 000,917,400 | ---- | M] (Mozilla Corporation) MD5=BF2F2717C13A4BD4FD73F2788534E86B -- C:\Program Files\Mozilla Firefox\firefox.exe
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2009.03.08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\Program Files\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.07.01 23:06:48 | 000,000,512 | ---- | M] () MD5=A411D0C8A13CFABEAC5C3BB0608F94F4 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[1999.06.02 06:41:58 | 000,003,504 | ---- | M] () -- \TOOLS\UEDIT\!crack.exe
< *keygen* /s >
< *loader* /s >
[2013.01.21 15:03:44 | 000,030,608 | ---- | M] () -- \Documents and Settings\michal\Data aplikací\Seznam.cz\install\cz.seznam.software.libfoxloader-3.0.0-win32.zip
[2013.07.01 22:48:40 | 000,003,705 | ---- | M] () -- \Documents and Settings\michal\Local Settings\Temporary Internet Files\Content.IE5\MV7MGVT2\lang_loader[2].gif
[2004.08.18 05:00:00 | 000,017,423 | ---- | M] () -- \I386\DMLOADER.DL_
[2004.08.18 05:00:00 | 000,115,153 | ---- | M] () -- \I386\OSLOADER.EX_
[2004.08.18 05:00:00 | 000,132,757 | ---- | M] () -- \I386\OSLOADER.NT_
[2002.09.25 21:05:38 | 000,113,664 | ---- | M] () -- \Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[2004.08.18 05:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll
[2005.07.27 20:01:00 | 000,000,894 | ---- | M] () -- \WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[2008.04.13 19:31:48 | 000,230,912 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe
[2008.04.14 04:21:40 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll
[2008.04.13 19:31:48 | 000,278,528 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd
[2008.04.14 04:21:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2013.04.26 11:45:20 | 000,012,532 | ---- | M] () -- \WINDOWS\system32\Adobe\Shockwave 12\shockwave_Projector_Loader.dcr
[2013.04.04 06:47:00 | 000,009,622 | ---- | M] () -- \WINDOWS\system32\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr
< End of report >
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\michal\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1,25 Gb Total Physical Memory | 0,50 Gb Available Physical Memory | 40,05% Memory free
1,85 Gb Paging File | 1,25 Gb Available in Paging File | 67,54% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 36,20 Gb Total Space | 16,36 Gb Free Space | 45,18% Space Free | Partition Type: FAT32
Drive D: | 36,35 Gb Total Space | 36,07 Gb Free Space | 99,22% Space Free | Partition Type: FAT32
Computer Name: ASER | User Name: michal | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2013.07.01 22:55:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\michal\Plocha\OTL.exe
PRC - [2013.05.09 10:58:36 | 006,583,664 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\Setup\avast.setup
PRC - [2013.05.09 10:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.12.25 17:54:40 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre1.7.0_07\bin\jqs.exe
PRC - [2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.04.25 15:36:26 | 000,835,584 | ---- | M] () -- C:\WINDOWS\vsnp325.exe
PRC - [2007.04.21 09:30:54 | 000,270,336 | ---- | M] () -- C:\WINDOWS\tsnp325.exe
PRC - [2007.02.12 14:50:40 | 000,020,480 | ---- | M] () -- C:\WINDOWS\FixCamera.exe
PRC - [2007.01.21 13:51:02 | 000,488,448 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Documents and Settings\michal\Local Settings\Temp\RtkBtMnt.EXE
PRC - [2006.11.17 05:42:52 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe
PRC - [2005.11.08 02:31:48 | 000,278,528 | ---- | M] (InterVideo Inc.) -- C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
PRC - [2005.07.25 12:00:56 | 000,876,032 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2005.03.28 13:52:08 | 000,360,448 | ---- | M] (acer Inc.) -- C:\Program Files\acer\eRecovery\Monitor.exe
PRC - [2005.01.31 08:05:50 | 000,253,952 | ---- | M] (Atheros Communications, Inc.) -- C:\Program Files\Atheros\ACU.exe
PRC - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
PRC - [2004.08.05 17:23:10 | 000,308,352 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
PRC - [2004.05.17 14:57:00 | 000,184,320 | ---- | M] (O&O Software GmbH) -- C:\WINDOWS\system32\oodag.exe
PRC - [2002.12.20 16:18:40 | 000,200,704 | ---- | M] (FUJI PHOTO FILM CO., LTD.) -- C:\Program Files\FinePixViewer\QuickDCF.exe
========== Modules (No Company Name) ==========
MOD - [2013.05.09 10:58:26 | 000,240,448 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\Setup\setiface.dll
MOD - [2013.05.09 10:49:30 | 002,085,376 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\13050900\algo.dll
MOD - [2007.04.25 15:36:26 | 000,835,584 | ---- | M] () -- C:\WINDOWS\vsnp325.exe
MOD - [2007.04.21 09:30:54 | 000,270,336 | ---- | M] () -- C:\WINDOWS\tsnp325.exe
MOD - [2007.02.12 14:50:40 | 000,020,480 | ---- | M] () -- C:\WINDOWS\FixCamera.exe
MOD - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
========== Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013.03.14 12:56:56 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.12.25 17:54:40 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre1.7.0_07\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012.12.23 15:18:20 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.03.20 13:08:30 | 000,008,704 | ---- | M] (Vodafone) [Auto | Stopped] -- C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe -- (VmbService)
SRV - [2005.07.25 12:00:56 | 000,876,032 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
SRV - [2004.12.27 17:12:16 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)
SRV - [2004.08.05 17:23:10 | 000,308,352 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- (SymWSC)
SRV - [2004.05.17 14:57:00 | 000,184,320 | ---- | M] (O&O Software GmbH) [Auto | Running] -- C:\WINDOWS\system32\oodag.exe -- (O&O Defrag)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Launch Manager\POWERKEY.sys -- (POWERKEY)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\PhTVTune.sys -- (PhTVTune)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\PCASp50.sys -- (PCASp50)
DRV - File not found [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\osanbm.sys -- (osanbm)
DRV - File not found [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\osaio.sys -- (osaio)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Cap7134.sys -- (Cap7134)
DRV - [2013.07.01 22:53:18 | 000,770,344 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2013.07.01 22:53:18 | 000,369,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2013.07.01 22:53:18 | 000,175,176 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2013.05.09 10:59:10 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2013.05.09 10:59:10 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2013.05.09 10:59:10 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2013.05.09 10:59:10 | 000,049,376 | ---- | M] () [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013.05.09 10:59:08 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.03.16 14:55:26 | 000,239,488 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2012.03.16 14:55:26 | 000,195,200 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2012.03.16 14:55:26 | 000,102,784 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2012.03.16 14:55:26 | 000,089,856 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - [2012.03.16 14:55:26 | 000,073,984 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2012.03.16 14:55:26 | 000,066,688 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_jucdcecm.sys -- (huawei_cdcecm)
DRV - [2012.03.16 14:55:26 | 000,026,624 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl)
DRV - [2012.03.16 14:55:26 | 000,011,136 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter)
DRV - [2007.04.26 11:03:12 | 010,343,168 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snp325.sys -- (SNP325)
DRV - [2007.01.14 16:28:36 | 000,034,760 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2006.12.29 14:48:06 | 004,026,112 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM)
DRV - [2006.07.20 20:40:00 | 000,332,800 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AG120.sys -- (AG120(ZyXEL)
DRV - [2005.07.25 11:53:30 | 000,008,704 | ---- | M] (Nero AG) [Recognizer | System | Unknown] -- C:\WINDOWS\System32\drivers\InCDrec.sys -- (InCDrec)
DRV - [2005.07.25 11:53:28 | 000,101,504 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005.07.25 11:53:04 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2005.07.25 11:53:00 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)
DRV - [2005.02.08 16:33:06 | 000,970,240 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005.01.13 14:46:16 | 000,069,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\acer\eRecovery\int15.sys -- (int15.sys)
DRV - [2005.01.10 15:47:14 | 000,449,888 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2004.12.21 03:32:12 | 000,369,024 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2004.12.15 15:18:30 | 000,200,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWATI.sys -- (HSFHWATI)
DRV - [2004.12.15 15:18:28 | 000,703,232 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2004.12.15 15:18:26 | 001,038,208 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2004.12.01 18:36:08 | 000,070,912 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)
DRV - [2004.09.14 02:40:56 | 000,146,304 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2004.08.03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)
DRV - [2004.03.02 16:37:50 | 000,125,184 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\imagesrv.sys -- (imagesrv)
DRV - [2004.03.02 16:37:48 | 000,005,504 | ---- | M] (Ahead Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\imagedrv.sys -- (imagedrv)
DRV - [2003.12.05 18:46:36 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy.karneval.cz:3128
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://www.centrum.cz/"
FF - prefs.js..extensions.enabledAddons: centrumpomocnik%40centrum.cz:1.1
FF - prefs.js..extensions.enabledAddons: %7B800b5000-a755-47e1-992b-48a1c1357f07%7D:1.5.3
FF - prefs.js..extensions.enabledAddons: %7Bea614400-e918-4741-9a97-7a972ff7c30b%7D:2.5.15
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..network.proxy.ftp: "proxy.karneval.cz"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "proxy.karneval.cz"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "proxy.karneval.cz"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "proxy.karneval.cz"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "proxy.karneval.cz"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre1.7.0_07\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2088: C:\Program Files\K-Lite Codec Pack\real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1069: C:\Program Files\K-Lite Codec Pack\real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/Acrobat,version=5.1: C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.07.01 22:52:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013.03.14 12:56:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2010.10.23 21:20:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Extensions
[2005.10.31 14:32:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\extensions
[2013.04.29 10:56:52 | 000,000,000 | ---D | M] (Seznam lištiÄŤka) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[2012.01.01 12:11:22 | 000,000,000 | ---D | M] (Centrum domĂ©novĂ˝ pomocnĂk) -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\extensions\centrumpomocnik@centrum.cz
[2011.11.10 11:26:50 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-11.xml
[2012.01.01 12:11:28 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-12.xml
[2012.01.01 14:11:54 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-13.xml
[2012.01.20 20:50:28 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-14.xml
[2012.01.20 22:52:22 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-15.xml
[2012.04.24 22:49:30 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-16.xml
[2012.04.25 08:50:12 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-17.xml
[2012.08.02 21:59:54 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-18.xml
[2013.02.18 09:53:52 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-19.xml
[2013.02.18 09:57:42 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-20.xml
[2013.04.10 08:55:14 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Mozilla\Firefox\Profiles\kj955ltm.default\searchplugins\icqplugin-21.xml
[2013.03.14 12:56:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013.03.14 12:56:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\distribution\extensions
[2013.03.14 12:56:22 | 000,000,000 | ---D | M] (Seznam lištička) -- C:\Program Files\Mozilla Firefox\distribution\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\{EA614400-E918-4741-9A97-7A972FF7C30B}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAL\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\KJ955LTM.DEFAULT\EXTENSIONS\CENTRUMPOMOCNIK@CENTRUM.CZ
[2013.03.14 12:56:58 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013.03.14 12:56:52 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
[2013.03.14 12:56:52 | 000,000,867 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2013.03.14 12:56:52 | 000,001,580 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2013.03.14 12:56:52 | 000,000,851 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2013.03.14 12:56:52 | 000,002,421 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
O1 HOSTS File: ([2004.08.18 05:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.7.0_07\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.7.0_07\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [ACU] C:\Program Files\Atheros\ACU.exe (Atheros Communications, Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [eRecoveryService] C:\WINDOWS\system32\Check.exe (acer Inc.)
O4 - HKLM..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe ()
O4 - HKLM..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe (Vodafone)
O4 - HKLM..\Run: [preload] C:\WINDOWS\RUNXMLPL.EXE (Wistron)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [snp325] C:\WINDOWS\vsnp325.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [tsnp325] C:\WINDOWS\tsnp325.exe ()
O4 - HKCU..\Run: [DefaultScope] File not found
O4 - HKLM..\RunOnce: [SymInstallStub] C:\WINDOWS\System32\Adobe\Shockwave 12\SymInstallStub.exe (Symantec Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe (FUJI PHOTO FILM CO., LTD.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O12 - Plugin for: .mov - C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll (Apple Computer, Inc.)
O12 - Plugin for: .spop - Reg Error: Value error. File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate.microsoft.com/wind ... 6275069656 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C331F4CA-1704-4B66-8B58-02813C76C8E7}: DhcpNameServer = 192.168.1.2
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{0a6b2edc-8197-11e2-9ff7-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{0a6b2edc-8197-11e2-9ff7-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{108d712c-4d0c-11e2-9fcf-000ae4e102c4}\Shell\AutoRun\command - "" = F:\Toshiba\Launcher\start.exe
O33 - MountPoints2\{1f374922-5a2d-11e2-9fde-000ae4e102c4}\Shell - "" = AutoRun
O33 - MountPoints2\{1f374922-5a2d-11e2-9fde-000ae4e102c4}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{1f374923-5a2d-11e2-9fde-000ae4e102c4}\Shell - "" = AutoRun
O33 - MountPoints2\{1f374923-5a2d-11e2-9fde-000ae4e102c4}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{431be504-7c16-11e2-9ff6-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{431be504-7c16-11e2-9ff6-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{45a9bf54-8bce-11e2-a001-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{45a9bf54-8bce-11e2-a001-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{4904b514-69eb-11e2-9fe4-001e101fcbdc}\Shell - "" = AutoRun
O33 - MountPoints2\{4904b514-69eb-11e2-9fe4-001e101fcbdc}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{7b6b6e54-8a3d-11e2-9fff-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{7b6b6e54-8a3d-11e2-9fff-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{a5022804-7109-11e2-9feb-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{a5022804-7109-11e2-9feb-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{b6354008-71df-11e2-9fec-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{b6354008-71df-11e2-9fec-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{bb5ea302-8a3b-11e2-9ffe-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{bb5ea302-8a3b-11e2-9ffe-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{c09951f2-69dc-11e2-9fe1-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{c09951f2-69dc-11e2-9fe1-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{e49b5bca-69d4-11e2-9fe0-000e9bbfc587}\Shell - "" = AutoRun
O33 - MountPoints2\{e49b5bca-69d4-11e2-9fe0-000e9bbfc587}\Shell\AutoRun\command - "" = F:\setup_vmb_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (OODBS)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Ligos Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.3iv2 - C:\WINDOWS\System32\3ivxVfWCodec.dll (3ivx.com)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\Ir32_32.dll ()
Drivers32: VIDC.IV40 - C:\WINDOWS\System32\Ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv41 - C:\WINDOWS\System32\Ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\Ir50_32.dll (Ligos Corporation)
Drivers32: VIDC.VP31 - C:\WINDOWS\System32\vp31vfw.dll (On2.com)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.wmv3 - C:\WINDOWS\System32\WMV9VCM.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2013.07.01 22:55:32 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\michal\Plocha\OTL.exe
[2013.07.01 22:53:11 | 000,029,816 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2013.07.01 22:53:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\avast! Free Antivirus
[2013.07.01 22:53:10 | 000,369,584 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2013.07.01 22:53:09 | 000,049,760 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2013.07.01 22:53:08 | 000,770,344 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2013.07.01 22:53:08 | 000,056,080 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2013.07.01 22:53:06 | 000,229,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2013.07.01 22:53:06 | 000,066,336 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys
[2013.07.01 22:52:06 | 000,041,664 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2013.07.01 22:51:27 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2013.07.01 22:50:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2013.07.01 22:11:46 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2013.07.01 22:11:45 | 000,000,000 | ---D | C] -- C:\rsit
[2013.07.01 21:19:29 | 000,000,000 | ---D | C] -- C:\FRST
[2013.07.01 21:18:49 | 001,371,463 | ---- | C] (Farbar) -- C:\Documents and Settings\michal\Plocha\FRST.exe
[2013.07.01 02:27:08 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.06.25 15:10:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2007.01.21 13:31:48 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\michal\Data aplikací\pcouffin.sys
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 7 Days ==========
[2013.07.01 23:06:48 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013.07.01 22:55:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\michal\Plocha\OTL.exe
[2013.07.01 22:53:18 | 000,770,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2013.07.01 22:53:18 | 000,369,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2013.07.01 22:53:18 | 000,175,176 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013.07.01 22:53:18 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum
[2013.07.01 22:53:18 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum
[2013.07.01 22:53:18 | 000,000,175 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum
[2013.07.01 22:53:12 | 000,001,597 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2013.07.01 22:53:08 | 000,002,504 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2013.07.01 22:53:08 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013.07.01 22:41:48 | 000,000,692 | ---- | M] () -- C:\WINDOWS\System32\eRLog.ini
[2013.07.01 22:41:46 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013.07.01 22:40:20 | 000,000,096 | ---- | M] () -- C:\WINDOWS\ComponentList.xml
[2013.07.01 22:40:06 | 000,000,636 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Product InstallerIdle.job
[2013.07.01 22:40:06 | 000,000,628 | ---- | M] () -- C:\WINDOWS\tasks\Norton Product Installer.job
[2013.07.01 22:39:34 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.07.01 22:39:26 | 1340,313,600 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.01 22:39:22 | 000,363,750 | ---- | M] () -- C:\WINDOWS\System32\OODBS.lor
[2013.07.01 22:18:28 | 000,648,201 | ---- | M] () -- C:\Documents and Settings\michal\Plocha\adwcleaner.exe
[2013.07.01 22:10:48 | 000,781,383 | ---- | M] () -- C:\Documents and Settings\michal\Plocha\RSIT.exe
[2013.07.01 21:27:02 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013.07.01 21:18:20 | 000,000,714 | ---- | M] () -- C:\Documents and Settings\michal\wincmd.ini
[2013.06.28 21:54:14 | 001,371,463 | ---- | M] (Farbar) -- C:\Documents and Settings\michal\Plocha\FRST.exe
[2013.06.28 21:32:24 | 095,023,320 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\eej88.pad
[2013.06.25 15:25:18 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013.06.25 15:09:54 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\michal\Nabídka Start\Programy\Po spuštění\regmonstd.lnk
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.07.01 23:00:50 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2013.07.01 22:53:17 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum
[2013.07.01 22:53:17 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum
[2013.07.01 22:53:17 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum
[2013.07.01 22:53:11 | 000,001,597 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2013.07.01 22:53:08 | 000,175,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013.07.01 22:53:07 | 000,049,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2013.07.01 22:53:07 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013.07.01 22:19:09 | 000,648,201 | ---- | C] () -- C:\Documents and Settings\michal\Plocha\adwcleaner.exe
[2013.07.01 22:11:39 | 000,781,383 | ---- | C] () -- C:\Documents and Settings\michal\Plocha\RSIT.exe
[2013.07.01 21:17:23 | 000,000,692 | ---- | C] () -- C:\WINDOWS\System32\eRLog.ini
[2013.07.01 21:15:38 | 000,000,096 | ---- | C] () -- C:\WINDOWS\ComponentList.xml
[2013.06.25 15:19:02 | 000,000,628 | ---- | C] () -- C:\WINDOWS\tasks\Norton Product Installer.job
[2013.06.25 15:19:01 | 000,000,636 | -H-- | C] () -- C:\WINDOWS\tasks\Norton Product InstallerIdle.job
[2013.06.25 15:09:52 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\michal\Nabídka Start\Programy\Po spuštění\regmonstd.lnk
[2013.06.25 15:09:31 | 095,023,320 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\eej88.pad
[2013.02.03 15:29:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.04.20 20:55:40 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012.03.16 14:55:44 | 000,286,678 | R--- | C] () -- C:\Documents and Settings\All Users\Data aplikací\DeviceManager.xml.rc4
[2007.01.21 13:31:48 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\ezpinst.exe
[2007.01.21 13:31:48 | 000,007,824 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\pcouffin.cat
[2007.01.21 13:31:48 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\pcouffin.inf
[2007.01.21 13:09:22 | 000,000,041 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\.zreglib
[2006.02.02 12:41:12 | 000,000,714 | ---- | C] () -- C:\Documents and Settings\michal\wincmd.ini
[2005.08.01 21:38:32 | 000,000,083 | ---- | C] () -- C:\Documents and Settings\michal\Data aplikací\sversion.ini
[2005.07.19 03:01:41 | 000,078,848 | ---- | C] () -- C:\Documents and Settings\michal\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005.07.15 22:24:44 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\michal\Local Settings\Data aplikací\fusioncache.dat
[2005.04.11 18:47:34 | 000,001,648 | ---- | C] () -- C:\Program Files\Adobe Reader 6.0.lnk
========== ZeroAccess Check ==========
[2005.07.15 22:10:52 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 04:21:56 | 001,499,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 11:56:06 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 04:22:06 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2005.07.15 22:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Autodesk
[2005.11.20 13:13:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NtiDvdCopy
[2007.01.21 14:10:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ACD Systems
[2010.08.20 21:14:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg9
[2011.03.16 21:18:56 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2011.06.15 13:01:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MFAData
[2012.02.01 19:52:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Temp
[2013.01.29 06:31:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Vodafone
[2013.07.01 22:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2005.07.15 22:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Autodesk
[2005.07.19 02:56:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\FUJIFILM
[2005.10.08 10:50:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ
[2006.06.03 15:39:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterTrust
[2006.11.26 19:50:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\PC Suite
[2007.01.21 13:31:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vso
[2007.01.21 15:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterVideo
[2007.01.31 19:49:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ACD Systems
[2007.04.24 22:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ Toolbar
[2013.01.29 06:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vodafone
[2013.02.17 15:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz
[2013.04.29 10:41:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\TuneUp Software
========== Purity Check ==========
========== Custom Scans ==========
< >
[1980.01.01 00:00:00 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2004.09.17 12:16:27 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2012.12.23 15:18:23 | 000,000,914 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2013.06.25 15:19:01 | 000,000,636 | -H-- | C] () -- C:\WINDOWS\Tasks\Norton Product InstallerIdle.job
[2013.06.25 15:19:02 | 000,000,628 | ---- | C] () -- C:\WINDOWS\Tasks\Norton Product Installer.job
[2013.07.01 22:53:07 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
< >
< MD5 for: ATAPI.SYS >
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 04:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2004.08.18 05:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\I386\AUTOCHK.EXE
[2004.08.18 05:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe
< MD5 for: CDROM.SYS >
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\I386\sp2.cab:cdrom.sys
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2004.08.18 05:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004.08.18 05:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: HAL.DLL >
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\I386\sp2.cab:hal.dll
[2004.08.18 05:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2013.02.03 13:40:20 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.13 19:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.13 19:31:28 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL
[2004.08.18 05:00:00 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
< MD5 for: SCECLI.DLL >
[2004.08.18 05:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SERVICES.EXE >
[2009.02.09 10:54:36 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=33081FED75032291EE0E008D5385E86F -- C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe
[2009.02.09 12:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009.02.09 11:11:38 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=4F9F7B567970B524F31D9970A23F7C24 -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2004.08.18 05:00:00 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=6E401E61F952FBBF708AFBECEFAFAE81 -- C:\WINDOWS\$NtUninstallKB956572_0$\services.exe
[2009.02.09 12:25:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009.02.09 12:25:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 12:25:58 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\services.exe
[2008.04.14 04:22:46 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008.04.14 04:22:46 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\ServicePackFiles\i386\services.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004.08.18 05:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: TCPIP.SYS >
[2006.04.20 13:51:50 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=1DBF125862891817F374F407626967F4 -- C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
[2008.06.20 11:45:14 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2006.01.13 18:07:08 | 000,360,448 | ---- | M] (Microsoft Corporation) MD5=5562CC0A47B2AEF06D3417B733F3C195 -- C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[2006.01.13 03:28:14 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=583E063FDC888CA30D05C2724B0D7EF4 -- C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
[2005.05.25 20:07:12 | 000,359,936 | ---- | M] (Microsoft Corporation) MD5=63FDFEA54EB53DE2D863EE454937CE1E -- C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[2008.06.20 11:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2005.05.25 20:04:02 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=88763A98A4C26C409741B4AA162720C9 -- C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.18 05:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2006.04.20 14:18:36 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004.08.18 05:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.18 05:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 04:22:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 04:22:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< >
< %systemroot%*.* /U /s >
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[22 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[1 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2004.09.17 12:16:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Identities
[2004.09.17 12:03:12 | 000,000,000 | --SD | M] -- C:\Documents and Settings\michal\Data aplikací\Microsoft
[2005.07.11 17:51:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Adobe
[2005.07.11 17:51:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\AdobeUM
[2005.07.11 17:53:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\CyberLink
[2005.07.15 04:19:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Help
[2005.07.15 21:46:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Symantec
[2005.07.15 22:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Autodesk
[2005.07.19 02:56:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\FUJIFILM
[2005.08.01 21:43:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Media Player Classic
[2005.09.13 14:12:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Macromedia
[2005.09.13 23:41:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Real
[2005.09.14 21:26:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Corel
[2005.09.20 20:30:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Sun
[2005.10.08 10:50:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ
[2005.10.30 18:00:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Mozilla
[2006.04.29 17:09:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Ahead
[2006.06.03 15:39:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterTrust
[2006.11.26 19:50:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\PC Suite
[2007.01.21 12:52:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Winamp
[2007.01.21 13:31:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vso
[2007.01.21 15:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InterVideo
[2007.01.31 19:49:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ACD Systems
[2007.04.24 22:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\ICQ Toolbar
[2007.05.06 21:28:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Skype
[2007.07.06 10:40:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\InstallShield
[2010.09.05 21:27:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\skypePM
[2013.01.29 06:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Vodafone
[2013.02.17 15:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz
[2013.02.17 15:39:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\vlc
[2013.04.29 10:41:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\michal\Data aplikací\TuneUp Software
< %APPDATA%\*.exe /s >
[2007.01.21 13:31:50 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\ezpinst.exe
[2012.09.14 14:06:28 | 002,515,592 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz\sznsetup.exe
[2012.09.13 15:24:48 | 001,009,288 | ---- | M] () -- C:\Documents and Settings\michal\Data aplikací\Seznam.cz\szninstall.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job >
[2012.12.23 15:18:24 | 000,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2013.07.01 22:40:06 | 000,000,636 | -H-- | M] () -- C:\WINDOWS\Tasks\Norton Product InstallerIdle.job
[2013.07.01 22:40:06 | 000,000,628 | ---- | M] () -- C:\WINDOWS\Tasks\Norton Product Installer.job
[2013.07.01 22:53:08 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2004.09.17 12:02:34 | 000,471,040 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
[2004.09.17 12:02:34 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2004.09.17 12:02:34 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
[2013.07.01 22:53:18 | 000,175,176 | ---- | M] () -- C:\WINDOWS\system32\drivers\aswVmm.sys
[2013.07.01 22:53:18 | 000,770,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswSnx.sys
[2013.07.01 22:53:18 | 000,369,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswSP.sys
< %systemroot%\system32\*.* /3 >
[2013.07.01 22:41:46 | 000,001,158 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2013.07.01 22:41:48 | 000,000,692 | ---- | M] () -- C:\WINDOWS\system32\eRLog.ini
[2013.07.01 21:27:12 | 073,381,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MRT.exe
[2013.07.01 22:53:08 | 000,002,504 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT
[2013.07.01 22:39:22 | 000,363,750 | ---- | M] () -- C:\WINDOWS\system32\OODBS.lor
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 04:22:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
"DefaultScope" =
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2013.03.14 12:56:58 | 000,917,400 | ---- | M] (Mozilla Corporation) MD5=BF2F2717C13A4BD4FD73F2788534E86B -- C:\Program Files\Mozilla Firefox\firefox.exe
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2009.03.08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\Program Files\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.07.01 23:06:48 | 000,000,512 | ---- | M] () MD5=A411D0C8A13CFABEAC5C3BB0608F94F4 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[1999.06.02 06:41:58 | 000,003,504 | ---- | M] () -- \TOOLS\UEDIT\!crack.exe
< *keygen* /s >
< *loader* /s >
[2013.01.21 15:03:44 | 000,030,608 | ---- | M] () -- \Documents and Settings\michal\Data aplikací\Seznam.cz\install\cz.seznam.software.libfoxloader-3.0.0-win32.zip
[2013.07.01 22:48:40 | 000,003,705 | ---- | M] () -- \Documents and Settings\michal\Local Settings\Temporary Internet Files\Content.IE5\MV7MGVT2\lang_loader[2].gif
[2004.08.18 05:00:00 | 000,017,423 | ---- | M] () -- \I386\DMLOADER.DL_
[2004.08.18 05:00:00 | 000,115,153 | ---- | M] () -- \I386\OSLOADER.EX_
[2004.08.18 05:00:00 | 000,132,757 | ---- | M] () -- \I386\OSLOADER.NT_
[2002.09.25 21:05:38 | 000,113,664 | ---- | M] () -- \Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[2004.08.18 05:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll
[2005.07.27 20:01:00 | 000,000,894 | ---- | M] () -- \WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[2008.04.13 19:31:48 | 000,230,912 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe
[2008.04.14 04:21:40 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll
[2008.04.13 19:31:48 | 000,278,528 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd
[2008.04.14 04:21:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2013.04.26 11:45:20 | 000,012,532 | ---- | M] () -- \WINDOWS\system32\Adobe\Shockwave 12\shockwave_Projector_Loader.dcr
[2013.04.04 06:47:00 | 000,009,622 | ---- | M] () -- \WINDOWS\system32\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr
< End of report >