OTL logfile created on: 3.6.2014 16:29:31 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\pocitac\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
959,36 Mb Total Physical Memory | 277,43 Mb Available Physical Memory | 28,92% Memory free
2,26 Gb Paging File | 1,40 Gb Available in Paging File | 61,83% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 50,78 Gb Total Space | 9,66 Gb Free Space | 19,03% Space Free | Partition Type: NTFS
Drive D: | 98,26 Gb Total Space | 46,88 Gb Free Space | 47,71% Space Free | Partition Type: NTFS
Computer Name: HOME | User Name: pocitac | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014.06.03 16:26:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\pocitac\Plocha\OTL.exe
PRC - [2014.05.14 01:40:56 | 000,860,488 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2014.04.25 11:56:13 | 004,582,720 | ---- | M] (TeamViewer GmbH) -- c:\Program Files\TeamViewer\Version9\TeamViewer_Desktop.exe
PRC - [2014.04.25 11:56:12 | 012,971,328 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version9\TeamViewer.exe
PRC - [2014.04.25 11:56:12 | 005,024,576 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
PRC - [2014.04.25 11:42:00 | 000,238,400 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version9\tv_w32.exe
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006.02.10 07:56:12 | 000,479,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
PRC - [2001.11.15 10:00:16 | 000,245,760 | ---- | M] (rc) -- D:\PO FORMATU SYSTEMU WINDOWS XP\Průhledné hodiny\tclock.exe
========== Modules (No Company Name) ==========
MOD - [2014.05.14 01:40:54 | 000,414,536 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\35.0.1916.114\ppgooglenaclpluginchrome.dll
MOD - [2014.05.14 01:40:50 | 004,217,672 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\35.0.1916.114\pdf.dll
MOD - [2014.05.14 01:40:43 | 001,732,424 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll
MOD - [2013.07.12 09:50:58 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_a2223024\mscorlib.dll
MOD - [2013.07.12 09:50:55 | 000,843,776 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_9f7d5fe5\system.drawing.dll
MOD - [2013.07.12 09:50:49 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_a1c74181\system.xml.dll
MOD - [2013.07.12 09:50:44 | 003,035,136 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_74904e54\system.windows.forms.dll
MOD - [2013.07.12 09:50:34 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_787016cb\system.dll
MOD - [2013.07.12 09:50:24 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2013.07.12 09:50:23 | 000,471,040 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2013.07.12 09:50:22 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2010.02.18 00:49:10 | 000,323,584 | ---- | M] () -- C:\Program Files\WinRAR\rarlng.dll
MOD - [2010.02.10 18:10:12 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2008.05.01 10:19:28 | 000,069,632 | ---- | M] () -- c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll
MOD - [2008.05.01 10:19:27 | 000,065,536 | ---- | M] () -- c:\windows\assembly\gac\hpqisrtb.resources\4.0.0.0_cs_a53cf5803f4c3827\hpqisrtb.resources.dll
MOD - [2008.05.01 10:19:21 | 001,163,264 | ---- | M] () -- c:\windows\assembly\gac\hpqedit\3.0.0.0__a53cf5803f4c3827\hpqedit.dll
MOD - [2008.05.01 10:19:21 | 000,790,528 | ---- | M] () -- c:\windows\assembly\gac\hpqbakup\3.0.0.0__a53cf5803f4c3827\hpqbakup.dll
MOD - [2008.05.01 10:19:21 | 000,376,832 | ---- | M] () -- c:\windows\assembly\gac\hpqedit.resources\3.0.0.0_cs_a53cf5803f4c3827\hpqedit.resources.dll
MOD - [2008.05.01 10:19:21 | 000,258,048 | ---- | M] () -- c:\windows\assembly\gac\hpqbakup.resources\3.0.0.0_cs_a53cf5803f4c3827\hpqbakup.resources.dll
MOD - [2008.05.01 10:19:19 | 000,163,840 | ---- | M] () -- c:\windows\assembly\gac\hpqvideo\3.0.0.0__a53cf5803f4c3827\hpqvideo.dll
MOD - [2008.05.01 10:19:18 | 000,430,080 | ---- | M] () -- c:\windows\assembly\gac\lead.wrapper\13.0.0.113__9cf889f53ea9b907\lead.wrapper.dll
MOD - [2008.05.01 10:19:18 | 000,090,112 | ---- | M] () -- c:\windows\assembly\gac\lead.drawing.imaging.imageprocessing\13.0.0.113__9cf889f53ea9b907\lead.drawing.imaging.imageprocessing.dll
MOD - [2008.05.01 10:19:18 | 000,086,016 | ---- | M] () -- c:\windows\assembly\gac\lead.drawing\13.0.0.113__9cf889f53ea9b907\lead.drawing.dll
MOD - [2008.05.01 10:19:18 | 000,081,920 | ---- | M] () -- c:\windows\assembly\gac\lead.drawing.imaging.codecs\13.0.0.113__9cf889f53ea9b907\lead.drawing.imaging.codecs.dll
MOD - [2008.05.01 10:19:18 | 000,077,824 | ---- | M] () -- c:\windows\assembly\gac\lead\13.0.0.113__9cf889f53ea9b907\lead.dll
MOD - [2008.05.01 10:19:18 | 000,069,632 | ---- | M] () -- c:\windows\assembly\gac\lead.windows.forms.drawingcontainer\13.0.0.113__9cf889f53ea9b907\lead.windows.forms.drawingcontainer.dll
MOD - [2008.05.01 10:19:18 | 000,065,536 | ---- | M] () -- c:\windows\assembly\gac\hpqmdmr\4.0.0.0__a53cf5803f4c3827\hpqmdmr.dll
MOD - [2008.05.01 10:19:18 | 000,057,344 | ---- | M] () -- c:\windows\assembly\gac\hpqprrsc\4.0.0.0__a53cf5803f4c3827\hpqprrsc.dll
MOD - [2008.05.01 10:19:18 | 000,053,248 | ---- | M] () -- c:\windows\assembly\gac\hpqovskn\3.0.0.0__a53cf5803f4c3827\hpqovskn.dll
MOD - [2008.05.01 10:19:18 | 000,040,960 | ---- | M] () -- c:\windows\assembly\gac\lead.windows.forms\13.0.0.113__9cf889f53ea9b907\lead.windows.forms.dll
MOD - [2008.05.01 10:19:18 | 000,016,384 | ---- | M] () -- c:\windows\assembly\gac\hpqprrsc.resources\4.0.0.0_cs_a53cf5803f4c3827\hpqprrsc.resources.dll
MOD - [2008.05.01 10:19:17 | 000,516,096 | ---- | M] () -- c:\windows\assembly\gac\hpqimvlt\3.0.0.0__a53cf5803f4c3827\hpqimvlt.dll
MOD - [2008.05.01 10:19:17 | 000,192,512 | ---- | M] () -- c:\windows\assembly\gac\hpqimgrc\4.0.0.0__a53cf5803f4c3827\hpqimgrc.dll
MOD - [2008.05.01 10:19:17 | 000,069,632 | ---- | M] () -- c:\windows\assembly\gac\hpqntrop\4.0.0.0__a53cf5803f4c3827\hpqntrop.dll
MOD - [2008.05.01 10:19:17 | 000,036,864 | ---- | M] () -- c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll
MOD - [2008.05.01 10:19:17 | 000,014,848 | ---- | M] () -- c:\windows\assembly\gac\interop.hpqvideo\4.0.0.0__a53cf5803f4c3827\interop.hpqvideo.dll
MOD - [2008.05.01 10:19:17 | 000,010,240 | ---- | M] () -- c:\windows\assembly\gac\interop.hpqimgr\4.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll
MOD - [2008.05.01 10:19:17 | 000,004,096 | ---- | M] () -- c:\windows\assembly\gac\interop.hprblog\3.0.0.0__a53cf5803f4c3827\interop.hprblog.dll
MOD - [2008.05.01 10:19:16 | 000,593,920 | ---- | M] () -- c:\windows\assembly\gac\hpqcc2\3.0.0.0__a53cf5803f4c3827\hpqcc2.dll
MOD - [2008.05.01 10:19:16 | 000,425,984 | ---- | M] () -- c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll
MOD - [2008.05.01 10:19:16 | 000,385,024 | ---- | M] () -- c:\windows\assembly\gac\hpqtray\4.0.0.0__a53cf5803f4c3827\hpqtray.dll
MOD - [2008.05.01 10:19:16 | 000,229,376 | ---- | M] () -- c:\windows\assembly\gac\hpqutils\4.0.0.0__a53cf5803f4c3827\hpqutils.dll
MOD - [2008.05.01 10:19:16 | 000,135,168 | ---- | M] () -- c:\windows\assembly\gac\hpqcc2.resources\3.0.0.0_cs_a53cf5803f4c3827\hpqcc2.resources.dll
MOD - [2008.05.01 10:19:16 | 000,126,976 | ---- | M] () -- c:\windows\assembly\gac\hpqtray.resources\4.0.0.0_cs_a53cf5803f4c3827\hpqtray.resources.dll
MOD - [2008.05.01 10:19:16 | 000,094,208 | ---- | M] () -- c:\windows\assembly\gac\hpqcprsc.resources\3.0.0.0_cs_a53cf5803f4c3827\hpqcprsc.resources.dll
MOD - [2008.05.01 10:19:16 | 000,077,824 | ---- | M] () -- c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll
MOD - [2008.05.01 10:19:16 | 000,069,632 | ---- | M] () -- c:\windows\assembly\gac\hpqglutl\4.0.0.0__a53cf5803f4c3827\hpqglutl.dll
MOD - [2008.05.01 10:19:16 | 000,061,440 | ---- | M] () -- c:\windows\assembly\gac\hpqimlib\3.0.0.0__a53cf5803f4c3827\hpqimlib.dll
MOD - [2008.05.01 10:19:16 | 000,036,864 | ---- | M] () -- c:\windows\assembly\gac\hpqfmrsc\4.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll
MOD - [2008.05.01 10:19:16 | 000,024,576 | ---- | M] () -- c:\windows\assembly\gac\hpqfmrsc.resources\4.0.0.0_cs_a53cf5803f4c3827\hpqfmrsc.resources.dll
MOD - [2008.05.01 10:19:16 | 000,024,576 | ---- | M] () -- c:\windows\assembly\gac\hpqasset\4.0.0.0__a53cf5803f4c3827\hpqasset.dll
MOD - [2008.05.01 10:19:16 | 000,020,480 | ---- | M] () -- c:\windows\assembly\gac\hpqiface\4.0.0.0__a53cf5803f4c3827\hpqiface.dll
MOD - [2008.05.01 10:18:57 | 000,229,376 | ---- | M] () -- c:\windows\assembly\gac\mscorlib.resources\1.0.5000.0_cs_b77a5c561934e089\mscorlib.resources.dll
MOD - [2008.05.01 10:18:57 | 000,081,920 | ---- | M] () -- c:\windows\assembly\gac\system.resources\1.0.5000.0_cs_b77a5c561934e089\system.resources.dll
MOD - [2008.04.14 05:21:47 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2007.11.18 21:21:21 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2007.07.16 17:06:53 | 000,007,680 | ---- | M] () -- c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll
MOD - [2006.06.27 12:53:08 | 000,017,704 | ---- | M] () -- C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll
MOD - [2005.10.20 10:36:08 | 000,077,824 | R--- | M] () -- C:\Program Files\HP\Digital Imaging\bin\crm\xmltok.dll
MOD - [2005.10.20 10:36:08 | 000,065,536 | R--- | M] () -- C:\Program Files\HP\Digital Imaging\bin\crm\xmlparse.dll
========== Services (SafeList) ==========
SRV - [2014.05.14 15:37:03 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014.05.10 15:30:09 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014.04.25 11:56:12 | 005,024,576 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
SRV - [2012.01.04 13:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2006.03.03 21:03:10 | 000,069,632 | ---- | M] (HP) [Auto | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\pocitac\LOCALS~1\Temp\mbr.sys -- (mbr)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- E:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2011.11.01 10:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011.11.01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011.11.01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011.11.01 10:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2008.08.26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2006.11.07 10:42:30 | 000,086,368 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w200obex.sys -- (w200obex)
DRV - [2006.11.07 10:42:28 | 000,088,560 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w200mgmt.sys -- (w200mgmt)
DRV - [2006.11.07 10:42:24 | 000,097,056 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w200mdm.sys -- (w200mdm)
DRV - [2006.11.07 10:42:22 | 000,009,328 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w200mdfl.sys -- (w200mdfl)
DRV - [2006.11.07 10:42:16 | 000,061,504 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w200bus.sys -- (w200bus)
DRV - [2006.09.06 10:04:12 | 004,377,600 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService)
DRV - [2006.08.18 11:10:24 | 000,061,504 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\K320bus.sys -- (K320bus)
DRV - [2006.08.18 11:10:22 | 000,097,056 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\K320mdm.sys -- (K320mdm)
DRV - [2006.08.18 11:10:22 | 000,009,328 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\K320mdfl.sys -- (K320mdfl)
DRV - [2006.08.18 11:10:20 | 000,088,560 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\K320mgmt.sys -- (K320mgmt)
DRV - [2006.08.18 11:10:18 | 000,086,368 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\K320obex.sys -- (K320obex)
DRV - [2006.08.14 08:51:28 | 000,105,344 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvata.sys -- (nvata)
DRV - [2006.07.11 15:38:30 | 000,020,480 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006.07.11 15:38:28 | 000,057,856 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005.03.09 08:53:00 | 000,036,352 | R--- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2004.08.22 16:31:48 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\d347prt.sys -- (d347prt)
DRV - [2004.08.22 16:31:10 | 000,155,136 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\d347bus.sys -- (d347bus)
DRV - [2004.08.09 13:33:26 | 000,114,016 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\prohlp02.sys -- (prohlp02)
DRV - [2004.08.09 13:29:28 | 000,053,920 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\prodrv06.sys -- (prodrv06)
DRV - [2004.07.19 16:49:54 | 000,007,040 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\prosync1.sys -- (prosync1)
DRV - [2003.12.01 17:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfhlp01.sys -- (sfhlp01)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchT ... urceid=ie7
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Bar =
http://www.google.com
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Prev Search Page =
http://www.google.com
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchT ... f8&oe=utf8
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes,DefaultScope = {0A0F1224-0E62-4622-8D15-B25B0769D083}
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{0A0F1224-0E62-4622-8D15-B25B0769D083}: "URL" =
http://www.google.com/search?q={searchT ... 1I7GGLL_en
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{0C68024A-F373-4481-A37D-5F032C4568EB}: "URL" =
http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{148257B2-D4E9-42B0-8256-F7484946FD21}: "URL" =
http://encyklopedie.seznam.cz/search?q= ... arch_16194
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{3838B315-F9A5-461F-9DE7-5FAA5AEBFF2A}: "URL" =
http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{3F84B0DC-194B-4679-BD27-28BB90ECAB32}: "URL" =
http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{47AC5287-B6DE-426B-940F-3AC40128BFC7}: "URL" =
http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{548C06F1-1398-482F-84AE-08A460026E6B}: "URL" =
http://www.novinky.cz/hledej?w={searchT ... arch_16194
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{6E026E0F-6B99-4A4C-ABD6-8791396A0F0A}: "URL" =
http://www.mapy.cz/?query={searchTerms} ... arch_16194
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{ADA46E29-79AB-428D-B746-8104FE478F30}: "URL" =
http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{BE44ACC0-0906-406E-8603-541EA2D97D37}: "URL" =
http://search.seznam.cz/?q={searchTerms ... arch_16194
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://www.seznam.cz/"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre1.6.0_24\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@kb-ext.cz/PKIComponent: C:\Documents and Settings\pocitac\Data aplikací\KB-ext\lib\x86\npPKIComponentNPAPI-kbext.dll (Komerční banka, a.s.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\pocitac\Local Settings\Data aplikací\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\
jqs@sun.com: C:\Program Files\Java\jre1.6.0_24\lib\deploy\jqs\ff [2012.01.04 23:41:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014.05.10 15:28:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014.05.14 15:21:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012.05.17 20:46:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2009.08.11 22:52:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\pocitac\Data aplikací\Mozilla\Extensions
[2014.05.02 15:40:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\pocitac\Data aplikací\Mozilla\Firefox\Profiles\ygqnynkr.default-1385666418012\extensions
[2014.05.10 15:28:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2014.05.10 15:28:03 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2014.05.10 15:28:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014.05.10 15:28:01 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2014.05.10 15:30:22 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012.01.04 23:41:31 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\35.0.1916.114\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java(TM) Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\35.0.1916.114\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\35.0.1916.114\gears.dll
CHR - plugin: MicrosoftĂ‚ĂÂĂ‚ÂĂ‚‚® DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: MicrosoftĂ‚ĂÂĂ‚ÂĂ‚‚® DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Seznam LiĂÂĂ‚Â…Ă‚Â¡tiĂÂĂ‚ÂĂ‚„Ă‚Âka - Email = C:\Documents and Settings\pocitac\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig\1.3.13_0\
CHR - Extension: Seznam LiĂÂĂ‚Â…Ă‚Â¡tiĂÂĂ‚ÂĂ‚„Ă‚Âka - SlovnĂÂĂ‚ÂĂ‚ÂÂĂ‚ÂÂÂk = C:\Documents and Settings\pocitac\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd\1.2.13_1\
CHR - Extension: AT_Porsche = C:\Documents and Settings\pocitac\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg\3_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\pocitac\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\7.2.15747.10003_0\
CHR - Extension: PenĂÂĂ‚ÂĂ‚„›ĂÂĂ‚Â…Ă‚Â¾enka Google = C:\Documents and Settings\pocitac\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Seznam LiĂ…¡tiĂ„ka - RychlĂ¡ volba = C:\Documents and Settings\pocitac\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak\1.6.5_0\
O1 HOSTS File: ([2014.06.02 18:14:04 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_24\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.6.0_24\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre1.6.0_24\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Printsrv] C:\WINDOWS\system32\Printing_Admin_Scripts\en-US\pubpr.vbs ()
O4 - HKU\S-1-5-21-329068152-1078081533-839522115-1003..\Run: [TransClock] D:\PO FORMATU SYSTEMU WINDOWS XP\Průhledné hodiny\tclock.exe (rc)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Rychlý začátek s aplikací HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_24\bin\npjpi160_24.dll (Sun Microsystems, Inc.)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe File not found
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe File not found
O9 - Extra 'Tools' menuitem : ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe File not found
O15 - HKLM\..Trusted Domains: mojebanka.cz ([*] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mojebanka.cz ([etrading] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mojebanka.cz ([www] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: ([]msn in My Computer)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: localhost ([]http in Internet)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: mojebanka.cz ([*] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: mojebanka.cz ([etrading] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: mojebanka.cz ([sign] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: mojebanka.cz ([www] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: mojeplatba.cz ([www] https in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/pub/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BEDD1CE1-A339-41D5-AE71-2DDADCA6CE0C}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ipp\0x00000001 - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18 - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () -
https://www.mojebanka.cz/js/cexi/zoom.js?2402
O24 - Desktop Components:1 (Aktuální domovská stránka) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.07.15 22:39:06 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Ligos Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll (Ligos Corporation)
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll (Ligos Corporation)
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Ligos Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (
www.helixcommunity.org)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2014.06.03 16:27:25 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\pocitac\Plocha\OTL.exe
[2014.06.02 18:18:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2014.06.01 20:45:31 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2014.06.01 20:37:33 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2014.06.01 20:37:33 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2014.06.01 20:37:33 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2014.06.01 20:37:32 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2014.06.01 20:37:09 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014.06.01 20:36:44 | 000,000,000 | R--D | C] -- D:\Oblíbené položky\Dokumenty\Hudba
[2014.06.01 20:36:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2014.05.31 21:52:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\RogueKiller
[2014.05.31 12:39:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\pocitac\Data aplikací\Malwarebytes
[2014.05.31 12:39:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2014.05.31 12:39:38 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2014.05.31 12:29:47 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\WINDOWS\System32\sqlite3.dll
[2014.05.31 12:28:21 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014.05.31 12:21:26 | 000,000,000 | ---D | C] -- C:\rsit
[2014.05.31 11:30:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\TeamViewer 9
[2014.05.31 11:29:54 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2014.05.31 11:16:16 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2014.05.31 11:00:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\pocitac\Data aplikací\TS3Client
[2014.05.31 11:00:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\TeamSpeak 3 Client
[2014.05.31 11:00:30 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client
[2014.05.31 10:51:23 | 000,000,000 | ---D | C] -- C:\Program Files\Lavalys
[2014.05.30 21:58:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\pocitac\Plocha\Práce Květen2014
[2014.05.24 09:48:21 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\pocitac\IECompatCache
[2014.05.10 15:27:59 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014.05.07 16:25:20 | 001,557,017 | ---- | C] (TeamExtreme) -- C:\Documents and Settings\pocitac\Plocha\Minecraft-1.7.2.exe
[2014.05.04 21:21:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\pocitac\Plocha\Práce Duben 2014
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[19 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2036.02.07 03:58:15 | 002,023,957 | R--- | M] (Finalhit Ltd) -- C:\WINDOWS\System32\DUCHOVE.scr
[2014.06.03 16:32:44 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2014.06.03 16:26:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\pocitac\Plocha\OTL.exe
[2014.06.03 16:19:57 | 000,781,909 | ---- | M] () -- C:\Documents and Settings\pocitac\Plocha\RSIT.exe
[2014.06.02 21:58:00 | 000,000,942 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014.06.02 21:35:00 | 000,000,914 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014.06.02 18:58:00 | 000,000,938 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014.06.02 18:14:32 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014.06.02 18:14:04 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2014.06.02 18:13:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014.06.02 17:54:37 | 000,001,912 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2014.06.02 15:52:54 | 000,000,738 | ---- | M] () -- C:\Documents and Settings\pocitac\Plocha\Zástupce - ComboFix.exe.lnk
[2014.06.02 15:49:28 | 000,001,693 | ---- | M] () -- D:\Plocha\Google Chrome.lnk
[2014.06.02 15:22:10 | 000,002,193 | ---- | M] () -- D:\Plocha\Skype.lnk
[2014.06.01 21:11:58 | 000,000,003 | ---- | M] () -- C:\Documents and Settings\pocitac\stut
[2014.06.01 20:45:40 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2014.06.01 12:12:38 | 000,026,624 | ---- | M] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2014.05.31 12:34:53 | 000,000,062 | ---- | M] () -- C:\Documents and Settings\pocitac\rgut
[2014.05.31 12:32:36 | 000,204,920 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2014.05.31 11:30:04 | 000,000,699 | ---- | M] () -- D:\Plocha\TeamViewer 9.lnk
[2014.05.31 11:00:43 | 000,000,713 | ---- | M] () -- D:\Plocha\TeamSpeak 3 Client.lnk
[2014.05.31 10:51:27 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\pocitac\Plocha\EVEREST Home Edition.lnk
[2014.05.24 12:34:30 | 000,005,544 | ---- | M] () -- D:\Oblíbené položky\Dokumenty\Těžba SV.Hubert1
[2014.05.22 14:55:34 | 001,557,017 | ---- | M] (TeamExtreme) -- C:\Documents and Settings\pocitac\Plocha\Minecraft-1.7.2.exe
[2014.05.14 15:37:00 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2014.05.14 15:37:00 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2014.05.14 15:13:21 | 000,001,300 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
[2014.05.14 15:01:22 | 000,001,755 | ---- | M] () -- C:\Documents and Settings\All Users\Data aplikací\QTSBandwidthCache
[2014.05.14 15:00:54 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[19 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.06.03 16:32:44 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2014.06.03 16:20:27 | 000,781,909 | ---- | C] () -- C:\Documents and Settings\pocitac\Plocha\RSIT.exe
[2014.06.02 15:52:53 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\pocitac\Plocha\Zástupce - ComboFix.exe.lnk
[2014.06.02 15:49:28 | 000,001,693 | ---- | C] () -- D:\Plocha\Google Chrome.lnk
[2014.06.01 20:45:40 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2014.06.01 20:45:37 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2014.06.01 20:37:33 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2014.06.01 20:37:33 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2014.06.01 20:37:33 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2014.06.01 20:37:33 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2014.06.01 20:37:33 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2014.05.31 21:52:12 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2014.05.31 11:30:04 | 000,000,699 | ---- | C] () -- D:\Plocha\TeamViewer 9.lnk
[2014.05.31 11:00:43 | 000,000,713 | ---- | C] () -- D:\Plocha\TeamSpeak 3 Client.lnk
[2014.05.31 10:51:27 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\pocitac\Plocha\EVEREST Home Edition.lnk
[2014.05.30 22:14:42 | 000,005,544 | ---- | C] () -- D:\Oblíbené položky\Dokumenty\Těžba SV.Hubert1
[2014.05.05 17:16:52 | 011,102,655 | ---- | C] ( ) -- C:\Documents and Settings\pocitac\Plocha\Minecraft-1.7.2(1).exe
[2014.05.04 17:05:46 | 000,000,003 | ---- | C] () -- C:\Documents and Settings\pocitac\stut
[2014.05.04 17:03:26 | 000,000,062 | ---- | C] () -- C:\Documents and Settings\pocitac\rgut
[2014.05.03 13:41:19 | 000,100,864 | --S- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2014.05.03 13:41:18 | 000,192,512 | --S- | C] () -- C:\WINDOWS\System32\libidn-11.dll
[2014.05.03 13:41:18 | 000,133,632 | --S- | C] () -- C:\WINDOWS\System32\librtmp.dll
[2014.05.03 13:41:17 | 000,538,126 | --S- | C] () -- C:\WINDOWS\System32\libcurl-4.dll
[2014.03.09 19:39:31 | 000,138,464 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2014.03.09 19:39:31 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\pocitac\Data aplikací\PnkBstrK.sys
[2014.03.09 19:39:13 | 000,111,928 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2014.03.09 19:39:09 | 000,682,280 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2014.03.09 19:39:09 | 000,066,872 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2014.02.27 21:51:16 | 000,001,300 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2014.02.13 10:55:31 | 000,127,504 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2013.05.24 15:19:39 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2013.05.14 17:35:22 | 001,072,544 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2013.05.14 17:35:22 | 001,072,544 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2013.05.14 17:35:22 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2013.02.08 05:03:08 | 002,816,504 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2013.01.25 18:08:42 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\QTSBandwidthCache
[2012.06.28 22:32:24 | 000,000,382 | ---- | C] () -- C:\Program Files\Zástupce - Program Files.lnk
[2011.10.10 22:08:03 | 002,053,902 | ---- | C] () -- C:\Documents and Settings\pocitac\Data aplikací\mdbu.bin
[2009.05.31 18:54:21 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\pocitac\Data aplikací\$_hpcst$.hpc
[2007.10.24 16:00:25 | 000,005,289 | ---- | C] () -- C:\Documents and Settings\pocitac\Data aplikací\froggy_scorebox
[2007.10.24 16:00:25 | 000,001,595 | ---- | C] () -- C:\Documents and Settings\pocitac\Data aplikací\pl_accounts.pl_acc
[2007.10.24 16:00:25 | 000,000,556 | ---- | C] () -- C:\Documents and Settings\pocitac\Data aplikací\Troll.options
[2007.07.29 12:50:33 | 000,090,624 | ---- | C] () -- C:\Documents and Settings\pocitac\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.07.16 17:08:47 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\pocitac\Local Settings\Data aplikací\fusioncache.dat
========== ZeroAccess Check ==========
[2007.07.16 17:07:06 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 05:21:55 | 001,499,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.02.09 12:56:05 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008.04.14 05:22:05 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2009.03.15 19:49:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Disney Interactive
[2013.05.12 13:19:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2012.08.09 15:30:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\HF Designer
[2014.05.31 12:30:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2008.10.03 14:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Meridian93
[2012.05.17 20:46:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Nokia
[2010.08.29 17:42:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NokiaInstallerCache
[2010.08.29 15:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NokiaMusic
[2010.08.29 17:52:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2012.01.14 17:27:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PhotoGenie
[2014.05.31 21:52:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\RogueKiller
[2014.06.01 20:32:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2014.03.03 17:53:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\tmp
[2012.09.18 16:36:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Vivendi Universal Games
[2014.06.03 16:05:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\.minecraft
[2013.03.16 08:26:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\.techniclauncher
[2007.10.25 15:39:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Alawar
[2008.09.19 19:33:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\ESET
[2009.03.21 14:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\FashionCrazeChech
[2013.09.22 10:52:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Friday's games
[2011.03.13 22:39:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\ICQ
[2008.05.29 09:07:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\ICQ Toolbar
[2008.05.14 18:37:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\ICQLite
[2007.07.23 18:00:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\InterVideo
[2013.10.27 11:36:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\KB-ext
[2007.07.26 15:15:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Leadertech
[2012.05.17 20:47:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Nokia
[2008.07.27 21:11:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Opera
[2012.05.17 21:18:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\PC Suite
[2014.05.31 17:38:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Seznam.cz
[2013.09.22 10:43:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\SprillBermudeChech
[2014.05.31 11:14:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\TS3Client
[2013.05.11 11:51:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Unity
[2012.12.27 00:19:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Wargaming.net
========== Purity Check ==========
========== Custom Scans ==========
< >
[2007.07.15 22:37:06 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2007.07.15 22:39:00 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2011.03.13 18:09:01 | 000,000,938 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2011.03.13 18:09:01 | 000,000,942 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2012.04.03 09:19:04 | 000,000,914 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2014.03.10 10:51:00 | 000,000,220 | ---- | C] () -- C:\WINDOWS\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
< >
< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\erdnt\cache\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004.08.03 23:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2002.09.20 18:17:54 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002.08.29 01:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\erdnt\cache\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe
[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe
< MD5 for: CDROM.SYS >
[2002.09.20 18:17:54 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:cdrom.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:cdrom.sys
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2004.08.03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\erdnt\cache\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\erdnt\cache\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\erdnt\cache\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2007.06.13 15:11:59 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=9B32416BD5988C97B6397CE0B02CAF97 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007.06.13 15:23:39 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=ED7B460B142A32097B8A8F6ECC941815 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: HAL.DLL >
[2002.09.20 18:17:54 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:hal.dll
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:hal.dll
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.13 20:31:28 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL
[2004.08.03 22:59:10 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:Changer.sys
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
[2004.08.03 23:00:14 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=DAF1A8193B6CAF0FB858CADCC5C4AF4A -- C:\WINDOWS\$NtServicePackUninstall$\changer.sys
< MD5 for: ISAPNP.SYS >
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2009.04.06 11:37:08 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2001.10.25 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\erdnt\cache\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\erdnt\cache\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
< MD5 for: NETLOGON.DLL >
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\erdnt\cache\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NVATA.SYS >
[2006.08.14 08:51:28 | 000,105,344 | R--- | M] (NVIDIA Corporation) MD5=947C4A0E7B25BCECC3B40F0F1070378B -- C:\WINDOWS\system32\drivers\nvata.sys
< MD5 for: SCECLI.DLL >
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\erdnt\cache\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\erdnt\cache\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.06.20 12:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2007.10.30 18:53:32 | 000,360,832 | ---- | M] (Microsoft Corporation) MD5=64798ECFA43D78C7178375FCDD16D8C8 -- C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[2008.06.20 12:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2007.10.30 19:20:55 | 000,360,064 | ---- | M] (Microsoft Corporation) MD5=90CAFF4B094573449A0872A0F919B178 -- C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\erdnt\cache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\erdnt\cache\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\erdnt\cache\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\erdnt\cache\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[29 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[3 C:\WINDOWS\Globalization\*.tmp files -> C:\WINDOWS\Globalization\*.tmp -> ]
[3 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\06620c7b1db9765396cb9665461ee743\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\06620c7b1db9765396cb9665461ee743\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\111513dc05eb541ecc5e6b3b1828572b\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\111513dc05eb541ecc5e6b3b1828572b\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\19dbc9ddb70fd9c4ebcebff519e945a6\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\19dbc9ddb70fd9c4ebcebff519e945a6\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\25c9064b7f6c54426934bec83d91c7fa\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\25c9064b7f6c54426934bec83d91c7fa\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\2e08f215e20e73d0029fbbcc34710bb8\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\2e08f215e20e73d0029fbbcc34710bb8\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\2e388494bddf17e38d98d1636abe38c5\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\2e388494bddf17e38d98d1636abe38c5\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\30ac3e25776f287599e730665baf9314\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\30ac3e25776f287599e730665baf9314\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\31cdb2744333b76b9c05de01d88e9723\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\31cdb2744333b76b9c05de01d88e9723\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\4714635eedfab2ea52e0ae109642cf08\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\4714635eedfab2ea52e0ae109642cf08\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\4a6ebf52efbec44d28d5c0135c216a55\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\4a6ebf52efbec44d28d5c0135c216a55\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\5bb95c58dabd9a23775b7de0f3523176\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\5bb95c58dabd9a23775b7de0f3523176\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\741de8ed746d624fbf64b4b2dfcc6b20\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\741de8ed746d624fbf64b4b2dfcc6b20\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\749a50d8acbc46b72e35cabcff87e207\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\749a50d8acbc46b72e35cabcff87e207\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\7c4ef551e9870b02a2c4f2ccdb0f1681\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\7c4ef551e9870b02a2c4f2ccdb0f1681\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\7f66daa47a40dc41b0d7fb589e125ac2\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\7f66daa47a40dc41b0d7fb589e125ac2\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\9500ee49543bc5a0500280fd21265403\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\9500ee49543bc5a0500280fd21265403\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\ad6d3a2b5d58e4a2aa3165693404efb8\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\ad6d3a2b5d58e4a2aa3165693404efb8\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\b4ccf90cba244e6dadbae18938ad1aee\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\b4ccf90cba244e6dadbae18938ad1aee\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\bf374b2d169e42120c7c1270e9577152\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\bf374b2d169e42120c7c1270e9577152\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\f0e463b1bba7747ae839cdace6593161\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\f0e463b1bba7747ae839cdace6593161\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\f2eb137e9f93ae1346cdad7b147c0149\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\f2eb137e9f93ae1346cdad7b147c0149\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\fd674b0793556498419dc6d88ead9cda\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\fd674b0793556498419dc6d88ead9cda\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\fe61c629c8f74ff0b36cb17d266219b9\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\fe61c629c8f74ff0b36cb17d266219b9\*.tmp -> ]
[19 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[1 C:\WINDOWS\twain_32\*.tmp files -> C:\WINDOWS\twain_32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2014.06.03 16:05:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\.minecraft
[2013.03.16 08:26:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\.techniclauncher
[2013.07.22 09:07:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Adobe
[2008.12.17 11:57:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\AdobeUM
[2007.10.21 21:21:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Ahead
[2007.10.25 15:39:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Alawar
[2007.10.10 17:55:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Apple Computer
[2012.06.09 19:58:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\dvdcss
[2008.09.19 19:33:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\ESET
[2009.03.21 14:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\FashionCrazeChech
[2013.09.22 10:52:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Friday's games
[2008.10.25 14:00:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Google
[2007.10.23 21:12:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Help
[2008.06.24 09:01:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\HP
[2011.03.13 22:39:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\ICQ
[2008.05.29 09:07:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\ICQ Toolbar
[2008.05.14 18:37:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\ICQLite
[2007.07.15 22:47:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Identities
[2009.03.15 19:49:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\InstallShield
[2007.07.23 18:00:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\InterVideo
[2013.10.27 11:36:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\KB-ext
[2007.07.26 15:15:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Leadertech
[2008.02.25 10:17:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Macromedia
[2014.05.31 12:39:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Malwarebytes
[2012.01.28 22:10:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Media Player Classic
[2014.02.01 15:25:56 | 000,000,000 | --SD | M] -- C:\Documents and Settings\pocitac\Data aplikací\Microsoft
[2009.08.11 22:52:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Mozilla
[2009.04.17 22:24:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\MSN6
[2012.05.17 20:47:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Nokia
[2013.11.23 22:19:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\NVIDIA
[2008.07.27 21:11:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Opera
[2012.05.17 21:18:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\PC Suite
[2010.03.07 16:05:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Real
[2008.04.23 16:01:29 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\pocitac\Data aplikací\SecuROM
[2014.05.31 17:38:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Seznam.cz
[2014.06.02 17:22:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Skype
[2012.01.26 16:08:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\skypePM
[2013.09.22 10:43:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\SprillBermudeChech
[2009.06.07 11:39:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Sun
[2014.05.31 11:14:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\TS3Client
[2013.05.11 11:51:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Unity
[2014.04.27 10:34:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\vlc
[2012.12.27 00:19:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Wargaming.net
[2013.07.28 14:06:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\Winamp
[2010.05.23 11:24:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
[2012.08.12 15:21:56 | 000,617,969 | ---- | M] () -- C:\Documents and Settings\pocitac\Data aplikací\.techniclauncher\tekkit_launcher_cracked.exe
[2013.03.09 17:34:14 | 000,733,685 | ---- | M] () -- C:\Documents and Settings\pocitac\Data aplikací\.techniclauncher\unins000.exe
[2013.10.27 11:36:24 | 001,175,960 | ---- | M] () -- C:\Documents and Settings\pocitac\Data aplikací\KB-ext\lib\unins000.exe
[2013.05.16 15:25:04 | 001,062,472 | ---- | M] () -- C:\Documents and Settings\pocitac\Data aplikací\Seznam.cz\szninstall.exe
[2013.05.16 15:26:24 | 002,589,256 | ---- | M] () -- C:\Documents and Settings\pocitac\Data aplikací\Seznam.cz\sznsetup.exe
[2013.04.16 13:52:34 | 000,055,808 | ---- | M] () -- C:\Documents and Settings\pocitac\Data aplikací\Seznam.cz\bin\ffkill.exe
[2013.04.29 12:53:34 | 000,045,560 | ---- | M] () -- C:\Documents and Settings\pocitac\Data aplikací\Seznam.cz\bin\listicka-x64.exe
[2013.04.12 10:13:24 | 000,457,208 | ---- | M] () -- C:\Documents and Settings\pocitac\Data aplikací\Seznam.cz\bin\szndesktop.exe
[2013.04.12 10:10:22 | 000,092,664 | ---- | M] () -- C:\Documents and Settings\pocitac\Data aplikací\Seznam.cz\bin\wszndesktop.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[19 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2007.07.16 00:21:31 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2007.07.16 00:21:31 | 000,630,784 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2007.07.16 00:21:31 | 000,430,080 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[19 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
[2014.06.01 12:12:38 | 000,026,624 | ---- | M] () -- C:\WINDOWS\system32\drivers\TrueSight.sys
< %systemroot%\system32\*.* /3 >
[2014.06.01 19:08:11 | 000,000,270 | ---- | M] () -- C:\WINDOWS\system32\AppLog.log
[2036.02.07 03:58:15 | 002,023,957 | R--- | M] (Finalhit Ltd) -- C:\WINDOWS\system32\DUCHOVE.scr
[2014.06.02 18:14:32 | 000,002,206 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[19 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"TransClock" = D:\PO FORMATU SYSTEMU WINDOWS XP\Průhledné hodiny\tclock.exe -- [2001.11.15 10:00:16 | 000,245,760 | ---- | M] (rc)
"H/PC Connection Agent" = "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" -- [2006.06.27 12:55:26 | 001,211,176 | ---- | M] (Microsoft Corporation)
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< >
< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2014.06.03 16:32:44 | 000,000,512 | ---- | M] () MD5=5E528666F2872D82629D65292CD96A5E -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2012.08.12 15:21:56 | 000,617,969 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\.techniclauncher\tekkit_launcher_cracked.exe
[2012.06.24 07:01:48 | 000,568,305 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\.techniclauncher\tekkit_launcher_cracked.jar
< *keygen* /s >
< *AntiWPA* /s >
< *loader* /s >
[2014.04.27 10:41:36 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\pocitac\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded\loader.gif.vir
[2014.04.27 10:41:36 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\pocitac\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square\loader.gif.vir
[2014.04.27 10:41:37 | 000,006,331 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\pocitac\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default\loader.gif.vir
[2014.04.27 10:41:37 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\pocitac\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\loader.gif.vir
[2014.04.27 10:41:37 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\pocitac\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_rounded\loader.gif.vir
[2014.04.27 10:41:38 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Documents and Settings\pocitac\Local Settings\Data aplikací\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_square\loader.gif.vir
[2014.04.27 10:41:36 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Program Files\Mobogenie\templates\web\images\prettyPhoto\dark_rounded\loader.gif.vir
[2014.04.27 10:41:36 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Program Files\Mobogenie\templates\web\images\prettyPhoto\dark_square\loader.gif.vir
[2014.04.27 10:41:37 | 000,006,331 | ---- | M] () -- \AdwCleaner\Quarantine\C\Program Files\Mobogenie\templates\web\images\prettyPhoto\default\loader.gif.vir
[2014.04.27 10:41:37 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Program Files\Mobogenie\templates\web\images\prettyPhoto\facebook\loader.gif.vir
[2014.04.27 10:41:37 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Program Files\Mobogenie\templates\web\images\prettyPhoto\light_rounded\loader.gif.vir
[2014.04.27 10:41:38 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Program Files\Mobogenie\templates\web\images\prettyPhoto\light_square\loader.gif.vir
[2012.02.29 08:49:32 | 000,072,638 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.gif
[2012.02.29 08:49:32 | 000,003,032 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.png
[2012.08.12 15:55:08 | 000,001,980 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\.techniclauncher\tekkit\mods\ComputerCraft\org\luaj\vm2\luajc\JavaLoader.class
[2012.08.12 15:59:16 | 000,004,966 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\.techniclauncher\voxelmodpack\ModLoader.txt
[2012.08.12 15:59:10 | 000,000,250 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\.techniclauncher\voxelmodpack\config\ModLoader.cfg
[2012.08.12 15:57:36 | 000,000,833 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\.techniclauncher\yogbox\config\ModLoader.cfg
[2012.08.12 15:57:30 | 000,000,047 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\.techniclauncher\yogbox\config\mod_ModLoaderMp.cfg
[2013.03.29 13:37:34 | 000,059,384 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\Seznam.cz\bin\30941libfoxloader.dll
[2013.04.15 13:32:10 | 000,060,416 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\Seznam.cz\bin\30945libfoxloader-x64.dll
[2014.02.10 20:17:42 | 000,000,165 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\Seznam.cz\conf\szndesktop.d\libfoxloader.conf
[2013.01.09 12:41:56 | 000,030,608 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\Seznam.cz\install\cz.seznam.software.libfoxloader-3.0.0-win32.zip
[2013.03.25 16:27:20 | 000,000,665 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\Seznam.cz\uninstall\cz_seznam_software_libfoxloader_3_1_2.install.bat
[2013.03.25 16:27:26 | 000,000,117 | ---- | M] () -- \Documents and Settings\pocitac\Data aplikací\Seznam.cz\uninstall\cz_seznam_software_libfoxloader_3_1_2.uninstall.bat
[2005.06.06 23:02:16 | 000,011,161 | ---- | M] () -- \Program Files\Adobe\Photoshop Album Starter Edition\3.0\Shared_Assets\combined_bitmaps\main_window\C_LoadError.png
[2001.01.16 06:55:36 | 000,053,248 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\COLOADER.DLL
[2001.01.16 04:22:34 | 000,002,560 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\COLOADER.TLB
[2011.09.01 12:13:30 | 000,112,128 | ---- | M] () -- \Program Files\Common Files\Nokia\Tss\ProductApiLoader\ta_productapiloader.dll
[2012.05.16 07:50:40 | 000,342,528 | ---- | M] () -- \Program Files\Fotolab\Fotolab Fotosvet\CWImageLoader0.dll
[2012.04.04 10:12:16 | 000,001,538 | ---- | M] () -- \Program Files\HF Designer\Loader.elf
[2014.01.29 11:26:58 | 000,924,736 | ---- | M] () -- \Program Files\HF Designer\Loader.exe
[2013.01.09 12:41:56 | 000,030,608 | ---- | M] () -- \Program Files\Seznam.cz\distribution\install\cz.seznam.software.libfoxloader-3.0.0-win32.zip
[2010.02.10 18:10:14 | 000,045,056 | ---- | M] () -- \Program Files\WinRAR\RarExtLoader.exe
[2004.08.17 15:49:06 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll
[2004.08.03 22:59:38 | 000,230,400 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\osloader.exe
[2004.08.03 22:59:38 | 000,278,016 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\osloader.ntd
[2008.04.14 05:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll
[2008.04.13 20:31:47 | 000,230,912 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe
[2008.04.13 20:31:48 | 000,278,528 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd
[2008.04.14 05:21:39 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[19 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2013.12.05 09:32:02 | 000,012,532 | ---- | M] () -- \WINDOWS\system32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2013.12.05 09:32:02 | 000,012,532 | ---- | M] () -- \WINDOWS\system32\Adobe\Shockwave 12\shockwave_Projector_Loader.dcr
< *minodlogin* /s >
< *tnod* /s >
< *AutoKMS* /s >
< *activator* /s >
< *serial* /s >
[2004.08.17 15:44:16 | 000,030,301 | ---- | M] () -- \cmdcons\SERIAL.SY_
[2012.05.12 18:11:03 | 000,032,768 | ---- | M] () -- \Documents and Settings\pocitac\Local Settings\Data aplikací\HF Designer\{A7E34C75-DBE6-413C-9E64-FED9AD8CB48B}\mdbu\Locations!IX_VolumeSerialNumber_Location.ind
[2012.05.12 18:11:04 | 000,008,192 | ---- | M] () -- \Documents and Settings\pocitac\Local Settings\Data aplikací\HF Designer\{A7E34C75-DBE6-413C-9E64-FED9AD8CB48B}\mdbu\Media!IX_VolumeSerialNumber.ind
[2011.03.10 00:43:26 | 000,413,696 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.0.60310.0\System.Runtime.Serialization.dll
[2012.06.29 16:45:42 | 001,186,816 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.0.60310.0\System.Runtime.Serialization.ni.dll
[2012.09.27 00:12:26 | 000,970,752 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2004.08.17 15:43:56 | 000,028,416 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\grserial.sys
[2004.08.17 15:44:16 | 000,064,640 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\serial.sys
[2008.05.01 10:18:57 | 000,011,776 | ---- | M] () -- \WINDOWS\assembly\GAC\System.Runtime.Serialization.Formatters.Soap.resources\1.0.5000.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2007.11.18 21:21:20 | 000,131,072 | ---- | M] () -- \WINDOWS\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2010.08.29 14:55:52 | 000,011,776 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\2.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014.02.13 09:41:01 | 000,131,072 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2010.08.29 14:56:01 | 000,090,112 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\system.runtime.serialization.resources\3.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.Resources.dll
[2013.05.14 18:05:08 | 000,970,752 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014.02.13 10:43:06 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\6c29ee2bedfe88dcd66993f1af135ad8\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.02.13 10:40:52 | 002,345,472 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\9860da66bf0219612908e7412b0a6e2e\System.Runtime.Serialization.ni.dll
[2013.08.15 10:56:23 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\a95e0af6fa5d2e8ffd5e0091f6513271\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2013.08.15 10:16:44 | 002,345,472 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\ba6670610621b25b1608e457ba0ef305\System.Runtime.Serialization.ni.dll
[2004.07.15 15:31:54 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
[2003.04.07 19:24:52 | 000,011,776 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v1.1.4322\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2008.07.25 11:17:00 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2008.09.10 17:46:28 | 000,011,776 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2012.09.27 00:12:26 | 000,970,752 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2008.04.14 04:17:25 | 000,028,416 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\grserial.sys
[2008.04.14 04:21:08 | 000,064,256 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\serial.sys
[2004.07.19 18:54:20 | 000,131,072 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\system.runtime.serialization.formatters.soap.dll
[2001.10.25 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dpserial.dll
[2001.10.25 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\serialui.dll
[19 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2001.10.25 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dllcache\dpserial.dll
[2001.10.25 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\dllcache\serialui.dll
[2008.04.14 04:21:08 | 000,064,256 | ---- | M] () -- \WINDOWS\system32\drivers\serial.sys
......................................