Re: Mel jsem Security Tool a asi i TrojanDownloader.Wigon.BS ...
Napsal: 16 bře 2010 08:30
OTL.TXT
OTL logfile created on: 16.3.2010 8:17:59 - Run 1
OTL by OldTimer - Version 3.1.37.1 Folder = C:\Documents and Settings\Boza\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 023,00 Mb Total Physical Memory | 638,00 Mb Available Physical Memory | 62,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 84,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 22,95 Gb Total Space | 1,52 Gb Free Space | 6,62% Space Free | Partition Type: NTFS
Drive D: | 70,21 Gb Total Space | 0,22 Gb Free Space | 0,31% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 967,72 Mb Total Space | 137,73 Mb Free Space | 14,23% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive W: | 928,30 Gb Total Space | 923,13 Gb Free Space | 99,44% Space Free | Partition Type: NTFS
Drive X: | 928,30 Gb Total Space | 923,13 Gb Free Space | 99,44% Space Free | Partition Type: NTFS
Drive Y: | 928,30 Gb Total Space | 923,13 Gb Free Space | 99,44% Space Free | Partition Type: NTFS
Drive Z: | 928,30 Gb Total Space | 923,13 Gb Free Space | 99,44% Space Free | Partition Type: NTFS
Computer Name: THINKPAD
Current User Name: Boza
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - File not found -- C:\WINDOWS\explorer.exe
PRC - [2010.03.16 08:16:26 | 000,555,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Boza\Plocha\OTL.exe
PRC - [2009.11.25 00:51:35 | 000,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009.11.25 00:51:21 | 000,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009.11.25 00:48:48 | 000,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009.11.25 00:43:56 | 000,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2008.03.06 13:26:14 | 000,118,784 | R--- | M] (Bytemobile, Inc.) -- C:\WINDOWS\System32\bmwebcfg.exe
PRC - [2007.06.01 02:02:06 | 000,036,400 | ---- | M] (Lenovo) -- C:\WINDOWS\System32\ibmpmsvc.exe
PRC - [2007.03.02 17:49:00 | 000,037,680 | ---- | M] (Lenovo.) -- C:\WINDOWS\System32\TPHDEXLG.exe
PRC - [2002.09.20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
========== Modules (SafeList) ==========
MOD - [2010.03.16 08:16:26 | 000,555,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Boza\Plocha\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (WMPNetworkSvc)
SRV - [2009.11.25 00:51:35 | 000,138,680 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2009.11.25 00:51:21 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009.11.25 00:48:48 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009.11.25 00:43:56 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2008.07.29 18:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008.03.06 13:26:14 | 000,118,784 | R--- | M] (Bytemobile, Inc.) [Auto | Running] -- C:\WINDOWS\System32\bmwebcfg.exe -- (bmwebcfg)
SRV - [2007.06.01 02:02:06 | 000,036,400 | ---- | M] (Lenovo) [Auto | Running] -- C:\WINDOWS\System32\ibmpmsvc.exe -- (IBMPMSVC)
SRV - [2007.03.02 17:49:00 | 000,037,680 | ---- | M] (Lenovo.) [Auto | Running] -- C:\WINDOWS\System32\TPHDEXLG.exe -- (TPHDEXLGSVC)
SRV - [2007.02.16 18:49:50 | 000,411,168 | ---- | M] (Acronis) [Disabled | Stopped] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2006.05.12 14:04:08 | 000,439,248 | ---- | M] (RealVNC Ltd.) [Disabled | Stopped] -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe -- (WinVNC4)
SRV - [2005.11.22 15:20:28 | 000,036,864 | ---- | M] () [On_Demand | Stopped] -- C:\WINDOWS\System32\acs.exe -- (ACS)
SRV - [2005.08.25 17:55:56 | 000,016,384 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\OpenVPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2002.12.17 15:26:22 | 007,520,337 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002.12.17 15:23:30 | 000,311,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)
SRV - [2002.09.20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))
SRV - [1999.06.18 13:43:32 | 000,066,560 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\System32\Crypserv.exe -- (Crypkey License)
========== Driver Services (SafeList) ==========
DRV - [2009.11.25 00:50:59 | 000,094,160 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2009.11.25 00:50:12 | 000,114,768 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2009.11.25 00:50:00 | 000,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009.11.25 00:49:07 | 000,048,560 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2009.11.25 00:48:57 | 000,023,120 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2009.11.25 00:47:54 | 000,027,408 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2008.11.20 22:57:55 | 000,114,048 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\snapman.sys -- (snapman)
DRV - [2008.10.31 13:49:16 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2008.10.31 13:49:15 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\timntr.sys -- (timounter)
DRV - [2008.07.31 19:45:42 | 000,020,616 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BtHidBus.sys -- (BtHidBus)
DRV - [2008.07.02 13:58:48 | 000,026,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV - [2008.04.13 19:54:36 | 000,028,672 | ---- | M] (National Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nscirda.sys -- (NSCIRDA)
DRV - [2008.04.13 19:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\nmnt.sys -- (nm)
DRV - [2008.03.06 13:26:14 | 000,018,688 | R--- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\tcpipbm.sys -- (tcpipBM)
DRV - [2008.01.30 14:45:33 | 000,716,272 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\sptd.sys -- (sptd)
DRV - [2007.11.19 04:31:56 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\npf.sys -- (NPF) WinPcap Packet Driver (NPF)
DRV - [2007.06.01 02:01:30 | 000,021,424 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ibmpmdrv.sys -- (IBMPMDRV)
DRV - [2007.05.02 08:54:08 | 000,472,224 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ar5211.sys -- (AR5211)
DRV - [2007.03.02 17:49:00 | 000,100,656 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\Apsx86.sys -- (Shockprf)
DRV - [2007.03.02 17:47:00 | 000,019,760 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\ApsHM86.sys -- (TPDIGIMN)
DRV - [2006.11.16 22:02:24 | 001,133,568 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006.11.03 23:45:48 | 000,178,913 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\V0260Vid.sys -- (V0260VID)
DRV - [2005.12.15 14:27:52 | 000,034,639 | R--- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\FTD2XX.sys -- (FTD2XX)
DRV - [2005.07.25 10:04:08 | 000,048,640 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2005.07.05 14:57:06 | 000,017,699 | ---- | M] (IBM Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\TPHKDRV.sys -- (TPHKDRV)
DRV - [2005.04.20 01:38:00 | 000,016,384 | ---- | M] (IBM Corp.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\TPPWR.SYS -- (TPPWR)
DRV - [2005.02.11 09:24:00 | 000,079,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\k750obex.sys -- (k750obex)
DRV - [2005.02.11 09:22:00 | 000,081,728 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\k750mgmt.sys -- (k750mgmt)
DRV - [2005.02.11 09:21:00 | 000,089,872 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\k750mdm.sys -- (k750mdm)
DRV - [2005.02.11 09:21:00 | 000,006,576 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\k750mdfl.sys -- (k750mdfl)
DRV - [2005.02.11 09:19:00 | 000,055,216 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\k750bus.sys -- (k750bus) Sony Ericsson 750 driver (WDM)
DRV - [2004.10.14 01:27:54 | 000,054,272 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AvidXPSerial.sys -- (Serial)
DRV - [2004.10.08 04:00:00 | 000,006,796 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\TPPORT.SYS -- (TPPORT)
DRV - [2004.06.24 03:54:12 | 000,023,552 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\tap0801.sys -- (tap0801)
DRV - [2004.03.24 03:12:34 | 000,017,280 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\nsndis5.sys -- (NSNDIS5)
DRV - [2003.06.27 08:53:44 | 001,196,352 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2002.01.18 03:01:00 | 000,054,784 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\wlanNDS.sys -- (WLAN)
DRV - [2001.02.01 15:10:12 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aspi32.sys -- (Aspi32)
DRV - [1999.06.18 13:43:32 | 000,024,736 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\ckldrv.sys -- (NetworkX)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-329068152-492894223-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.cz/"
FF - prefs.js..extensions.enabledItems: anttoolbar@ant.com:2.0
FF - prefs.js..extensions.enabledItems: {C6128004-4838-4708-9A97-BB172D17767D}:1.6.1
FF - prefs.js..extensions.enabledItems: {43c35458-c907-439b-bcfd-07d373834689}:2.2.0
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.03.01 00:03:13 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.02.20 12:24:41 | 000,000,000 | ---D | M]
[2008.07.03 11:01:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Extensions
[2010.03.11 00:17:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions
[2010.01.25 10:55:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions\{43c35458-c907-439b-bcfd-07d373834689}
[2010.02.24 21:52:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions\{C6128004-4838-4708-9A97-BB172D17767D}
[2008.07.03 11:02:19 | 000,000,000 | ---D | M] (Media Pirate - The video downloader) -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions\{cc265d3d-3f6f-0170-a78b-bbbaef7a868c}
[2010.01.04 10:58:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010.01.15 21:52:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions\anttoolbar@ant.com
[2008.01.30 14:47:39 | 000,002,920 | ---- | M] () -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\searchplugins\daemon-search.xml
[2010.03.11 00:17:28 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010.03.11 12:56:43 | 000,000,027 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (WebTransBHO Class) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll File not found
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (WebTranslator) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll File not found
O3 - HKU\S-1-5-21-329068152-492894223-854245398-1003\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] File not found
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [BLOG] C:\Program Files\ThinkPad\UTILIT~1\BATLOGEX.DLL ()
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE ()
O4 - HKLM..\Run: [BMMMONWND] C:\Program Files\ThinkPad\UTILIT~1\BATINFEX.DLL ()
O4 - HKLM..\Run: [EZEJMNAP] C:\Program Files\ThinkPad\UTILIT~1\EZEJMNAP.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe File not found
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe ()
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (Lenovo.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-329068152-492894223-854245398-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-329068152-492894223-854245398-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\S-1-5-21-329068152-492894223-854245398-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O7 - HKU\S-1-5-21-329068152-492894223-854245398-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést výběr do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést výběr do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll File not found
O9 - Extra 'Tools' menuitem : &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll File not found
O9 - Extra 'Tools' menuitem : &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll File not found
O9 - Extra 'Tools' menuitem : Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll File not found
O9 - Extra 'Tools' menuitem : Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll File not found
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\tpfnf2: DllName - notifyf2.dll - C:\WINDOWS\System32\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - tphklock.dll - C:\WINDOWS\System32\tphklock.dll ()
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop Components:1 () - http://timeanddate.com/counters/customc ... c=0&p0=204
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.12.09 17:41:45 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:12:00 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:12:00 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:12:02 | 000,000,000 | RHSD | M] - F:\autorun.inf -- [ FAT ]
O32 - AutoRun File - [2010.03.16 08:11:58 | 000,000,000 | ---D | M] - W:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:11:59 | 000,000,000 | ---D | M] - X:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:11:59 | 000,000,000 | ---D | M] - Y:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:11:59 | 000,000,000 | ---D | M] - Z:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\System32\ias [2008.11.13 13:09:44 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54046588552609792)
========== Files/Folders - Created Within 30 Days ==========
[2010.03.16 08:16:23 | 000,555,008 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Boza\Plocha\OTL.exe
[2010.03.16 08:12:00 | 000,000,000 | RHSD | C] -- C:\autorun.inf
[2010.03.16 07:55:22 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.03.15 08:19:39 | 000,000,000 | ---D | C] -- C:\cistic
[2010.03.14 20:00:23 | 000,000,000 | ---D | C] -- C:\Program Files\HYCAD
[2010.03.14 19:58:44 | 004,265,121 | ---- | C] (Jiang.Jiang ) -- C:\HYCADSetUpEn.exe
[2010.03.14 15:59:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\runouce.exe
[2010.03.14 15:54:19 | 000,632,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2010.03.14 15:54:18 | 000,554,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2010.03.14 15:54:17 | 000,034,048 | ---- | C] (MicroWorld Technologies Inc.) -- C:\WINDOWS\System32\eEmpty.exe
[2010.03.14 15:54:15 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\TASKMGR.COM
[2010.03.14 15:54:15 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\T.COM
[2010.03.14 15:54:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MicroWorld
[2010.03.14 15:54:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2010.03.12 17:44:36 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\regedit.exe
[2010.03.11 10:01:38 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.03.11 09:56:25 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.03.11 09:25:21 | 000,000,000 | ---D | C] -- C:\rsit
[2010.03.11 00:17:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boza\Data aplikací\Uniblue
[2010.03.10 00:25:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boza\Data aplikací\Malwarebytes
[2010.03.10 00:03:06 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.03.10 00:03:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.03.10 00:03:04 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.03.10 00:03:04 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.03.09 23:32:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boza\Plocha\viry
[2010.03.08 23:44:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boza\Plocha\stirling philips
[2010.03.08 00:19:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boza\Plocha\Ladislav_Vodicka
[2010.03.04 21:08:56 | 000,000,000 | ---D | C] -- C:\Program Files\Free M4a to MP3 Converter
[2010.03.04 21:07:32 | 005,003,908 | ---- | C] (ManiacTools.com ) -- C:\Documents and Settings\Boza\Plocha\m4a-to-mp3-converter.exe
[2010.03.01 18:05:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2009.02.11 15:51:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Google
[2008.12.17 09:01:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Bytemobile
[2008.11.13 13:59:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Google
[2008.10.31 13:51:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Acronis
[2008.09.04 07:13:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2008.03.27 18:04:20 | 000,582,144 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Common Files\dao350.dll
[2008.03.14 17:17:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Apple
[2007.12.09 17:46:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2007.12.09 17:41:39 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2007.12.09 17:41:39 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.03.16 08:16:26 | 000,555,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Boza\Plocha\OTL.exe
[2010.03.16 08:13:14 | 001,099,298 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.03.16 08:13:14 | 000,459,288 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.03.16 08:13:14 | 000,455,900 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2010.03.16 08:13:14 | 000,090,434 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2010.03.16 08:13:14 | 000,079,078 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.03.16 08:12:04 | 000,207,206 | ---- | M] () -- C:\UsbFix_Upload_Me_THINKPAD.zip
[2010.03.16 08:01:57 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.03.16 08:01:29 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.03.16 08:01:18 | 1072,615,424 | -HS- | M] () -- C:\hiberfil.sys
[2010.03.16 08:00:08 | 006,815,744 | -H-- | M] () -- C:\Documents and Settings\Boza\NTUSER.DAT
[2010.03.16 08:00:08 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\Boza\ntuser.ini
[2010.03.16 07:55:00 | 000,000,940 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.03.16 07:54:39 | 001,775,837 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\UsbFix.exe
[2010.03.14 22:30:52 | 000,092,160 | ---- | M] () -- C:\Documents and Settings\Boza\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.03.14 20:00:26 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\HYCAD.lnk
[2010.03.14 19:58:44 | 004,265,121 | ---- | M] (Jiang.Jiang ) -- C:\HYCADSetUpEn.exe
[2010.03.14 18:13:09 | 000,083,456 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\kalendar.xls
[2010.03.14 15:54:18 | 000,632,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2010.03.14 15:54:17 | 000,554,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2010.03.14 15:54:16 | 000,034,048 | ---- | M] (MicroWorld Technologies Inc.) -- C:\WINDOWS\System32\eEmpty.exe
[2010.03.14 15:53:48 | 068,866,904 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\mwav.exe
[2010.03.14 15:42:12 | 000,082,086 | ---- | M] () -- C:\Documents and Settings\Boza\Dokumenty\cc_20100314_1541.reg
[2010.03.14 15:23:02 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.03.12 20:20:12 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.03.12 17:40:08 | 003,888,122 | R--- | M] () -- C:\Documents and Settings\Boza\Plocha\ComboFix.exe
[2010.03.12 11:16:15 | 000,028,936 | ---- | M] () -- C:\Documents and Settings\Boza\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2010.03.11 21:50:38 | 000,126,447 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\repair_technician.pdf
[2010.03.11 12:56:43 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.03.11 10:01:46 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.03.11 09:58:52 | 000,151,584 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.03.11 09:14:50 | 000,694,826 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\viry_login.bmp
[2010.03.10 00:03:09 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.03.09 23:55:49 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010.03.09 18:02:40 | 000,104,106 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\TAB119.jpg
[2010.03.09 00:51:49 | 000,207,242 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\karta_studium.jpg
[2010.03.07 02:44:11 | 008,419,220 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\fox on the run.flv
[2010.03.05 23:25:51 | 000,014,336 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\dynama.xls
[2010.03.05 22:28:39 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\Boza\PUTTY.RND
[2010.03.04 21:08:59 | 000,000,740 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\Free M4a to MP3 Converter.lnk
[2010.03.04 21:07:55 | 005,003,908 | ---- | M] (ManiacTools.com ) -- C:\Documents and Settings\Boza\Plocha\m4a-to-mp3-converter.exe
[2010.03.03 23:55:25 | 000,245,786 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\Pohled_spolecnosti_CEPS_na_fotovaltaiku_k_23_2.pdf
[2010.02.21 22:30:58 | 000,033,792 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\co nam jeste privezt;).doc
[2010.02.21 15:50:37 | 010,719,744 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\nizkootackove generatory.doc
[2010.02.18 10:45:18 | 000,034,304 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\dane.doc
[2010.02.16 20:22:03 | 000,504,007 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\dvojkolo.PNG
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.03.16 08:12:04 | 000,207,206 | ---- | C] () -- C:\UsbFix_Upload_Me_THINKPAD.zip
[2010.03.16 07:54:28 | 001,775,837 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\UsbFix.exe
[2010.03.15 19:28:38 | 1072,615,424 | -HS- | C] () -- C:\hiberfil.sys
[2010.03.14 20:00:26 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\HYCAD.lnk
[2010.03.14 15:54:17 | 000,000,522 | ---- | C] () -- C:\WINDOWS\System32\Microsoft.VC80.CRT.manifest
[2010.03.14 15:53:45 | 068,866,904 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\mwav.exe
[2010.03.14 15:41:57 | 000,082,086 | ---- | C] () -- C:\Documents and Settings\Boza\Dokumenty\cc_20100314_1541.reg
[2010.03.11 21:50:38 | 000,126,447 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\repair_technician.pdf
[2010.03.11 10:01:46 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.03.11 10:01:41 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.03.11 09:54:56 | 003,888,122 | R--- | C] () -- C:\Documents and Settings\Boza\Plocha\ComboFix.exe
[2010.03.11 09:14:49 | 000,694,826 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\viry_login.bmp
[2010.03.10 00:03:09 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.03.09 18:02:38 | 000,104,106 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\TAB119.jpg
[2010.03.09 00:51:24 | 000,207,242 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\karta_studium.jpg
[2010.03.07 02:41:35 | 008,419,220 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\fox on the run.flv
[2010.03.04 21:08:59 | 000,000,740 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\Free M4a to MP3 Converter.lnk
[2010.03.03 23:55:25 | 000,245,786 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\Pohled_spolecnosti_CEPS_na_fotovaltaiku_k_23_2.pdf
[2010.03.01 18:05:49 | 000,002,283 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.02.18 10:45:18 | 000,034,304 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\dane.doc
[2010.02.16 20:22:02 | 000,504,007 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\dvojkolo.PNG
[2009.08.28 09:55:34 | 000,001,031 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
[2008.12.25 13:56:26 | 000,000,090 | R--- | C] () -- C:\WINDOWS\System32\PRESTOUN.ini
[2008.11.25 21:22:43 | 000,000,080 | RHS- | C] () -- C:\WINDOWS\System32\FEEBB870E5.dll
[2008.11.25 10:28:18 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008.11.07 17:43:49 | 000,000,146 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2008.11.07 17:43:48 | 000,003,165 | R--- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2008.11.07 17:43:13 | 000,106,496 | R--- | C] () -- C:\WINDOWS\System32\VSHP1020.DLL
[2008.10.21 23:21:00 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2008.10.21 23:21:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2008.08.17 21:58:38 | 001,032,582 | ---- | C] () -- C:\WINDOWS\System32\alleg42.dll
[2008.06.20 13:17:31 | 000,024,736 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys
[2008.03.27 20:31:21 | 000,905,290 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2008.03.27 20:31:20 | 000,054,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\AvidXPSerial.sys
[2008.03.27 20:31:16 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\Cpuinf32.dll
[2008.03.27 18:04:20 | 000,073,184 | ---- | C] () -- C:\Program Files\Common Files\Dao2535.tlb
[2008.03.08 12:58:20 | 000,000,073 | ---- | C] () -- C:\WINDOWS\System32\adultpdf_Decrypt_reg.ini
[2007.12.29 02:34:16 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Boza\Local Settings\Data aplikací\PUTTY.RND
[2007.12.15 22:55:36 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2007.12.15 22:55:34 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007.12.15 22:55:34 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007.12.15 22:55:33 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007.12.15 22:55:32 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007.12.15 22:55:31 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007.12.15 22:43:52 | 000,092,160 | ---- | C] () -- C:\Documents and Settings\Boza\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.12.15 21:13:10 | 000,054,784 | ---- | C] () -- C:\WINDOWS\System32\drivers\wlanNDS.sys
[2007.12.15 21:13:10 | 000,050,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\wlanUSB.sys
[2007.12.09 21:17:35 | 000,000,124 | ---- | C] () -- C:\Documents and Settings\Boza\Local Settings\Data aplikací\fusioncache.dat
[2007.10.11 10:01:42 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007.01.25 23:04:12 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\mase32.dll
[2007.01.25 23:04:12 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\ma32.dll
[2006.10.30 11:58:33 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar_mpfc.dll
[2005.11.30 20:16:02 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\tphklock.dll
[2005.07.05 23:45:08 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\notifyf2.dll
[1996.02.01 18:25:42 | 000,943,616 | ---- | C] () -- C:\WINDOWS\System32\dfolder.dll
========== LOP Check ==========
[2008.11.21 17:12:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Acronis
[2010.03.14 15:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2008.04.03 14:33:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle
[2008.04.03 14:41:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle VideoSpin
[2008.04.13 20:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2009.02.23 19:33:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2008.04.19 13:47:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\VideoSpin
[2008.11.21 16:13:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Acronis
[2010.01.19 22:43:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\BitTyrant
[2008.12.17 02:13:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Bytemobile
[2008.02.07 18:00:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\COWON
[2008.01.30 14:47:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\DAEMON Tools
[2008.08.18 09:06:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Dev-Cpp
[2008.11.26 02:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\EZwebLynx
[2008.05.28 22:06:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\GARMIN
[2008.02.17 19:28:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\ICQ
[2008.12.25 16:22:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\MyPhoneExplorer
[2008.06.16 21:38:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Navigator
[2008.06.22 18:19:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Plagiarism-Finder
[2008.04.13 21:13:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Publish Providers
[2008.08.19 23:32:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\QIP
[2008.04.14 02:48:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Sony
[2008.01.13 19:58:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\SWI-Prolog
[2008.09.29 22:15:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\The Bat!
[2010.03.11 00:17:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Uniblue
[2009.12.01 23:15:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\VitySoft
[2007.12.16 23:46:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\WildPackets
[2007.12.15 21:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Wireshark
[2009.04.18 08:19:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\XnView
[2008.06.21 18:19:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\xpce
[2008.10.31 13:51:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Acronis
[2008.12.17 09:01:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Bytemobile
[2009.01.08 17:23:21 | 000,000,920 | ---- | M] () -- C:\WINDOWS\Tasks\BMMTask.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2010.03.14 19:58:44 | 004,265,121 | ---- | M] (Jiang.Jiang ) -- C:\HYCADSetUpEn.exe
[2008.04.14 04:22:42 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\regedit.exe
< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
< %SYSTEMDRIVE%\scecli.dll /s /md5 >
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
< %SYSTEMDRIVE%\sceclt.dll /s /md5 >
< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >
< %SYSTEMDRIVE%\logevent.dll /s /md5 >
< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
< %SYSTEMDRIVE%\atapi.sys /s /md5 >
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >
< %SYSTEMDRIVE%\viasraid.sys /s /md5 >
< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >
< %SYSTEMDRIVE%\viamraid.sys /s /md5 >
< %SYSTEMDRIVE%\nvata.sys /s /md5 >
< %SYSTEMROOT%\*. /mp /s >
< %SYSTEMROOT%\system32\*.dll /lockedfiles >
[2009.02.20 18:13:42 | 000,347,136 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\dxtmsft.dll
[2009.02.20 18:13:42 | 000,214,528 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\dxtrans.dll
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMROOT%\Tasks\*.job /lockedfiles >
< End of report >
OTL logfile created on: 16.3.2010 8:17:59 - Run 1
OTL by OldTimer - Version 3.1.37.1 Folder = C:\Documents and Settings\Boza\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 023,00 Mb Total Physical Memory | 638,00 Mb Available Physical Memory | 62,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 84,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 22,95 Gb Total Space | 1,52 Gb Free Space | 6,62% Space Free | Partition Type: NTFS
Drive D: | 70,21 Gb Total Space | 0,22 Gb Free Space | 0,31% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 967,72 Mb Total Space | 137,73 Mb Free Space | 14,23% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive W: | 928,30 Gb Total Space | 923,13 Gb Free Space | 99,44% Space Free | Partition Type: NTFS
Drive X: | 928,30 Gb Total Space | 923,13 Gb Free Space | 99,44% Space Free | Partition Type: NTFS
Drive Y: | 928,30 Gb Total Space | 923,13 Gb Free Space | 99,44% Space Free | Partition Type: NTFS
Drive Z: | 928,30 Gb Total Space | 923,13 Gb Free Space | 99,44% Space Free | Partition Type: NTFS
Computer Name: THINKPAD
Current User Name: Boza
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - File not found -- C:\WINDOWS\explorer.exe
PRC - [2010.03.16 08:16:26 | 000,555,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Boza\Plocha\OTL.exe
PRC - [2009.11.25 00:51:35 | 000,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009.11.25 00:51:21 | 000,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009.11.25 00:48:48 | 000,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009.11.25 00:43:56 | 000,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2008.03.06 13:26:14 | 000,118,784 | R--- | M] (Bytemobile, Inc.) -- C:\WINDOWS\System32\bmwebcfg.exe
PRC - [2007.06.01 02:02:06 | 000,036,400 | ---- | M] (Lenovo) -- C:\WINDOWS\System32\ibmpmsvc.exe
PRC - [2007.03.02 17:49:00 | 000,037,680 | ---- | M] (Lenovo.) -- C:\WINDOWS\System32\TPHDEXLG.exe
PRC - [2002.09.20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
========== Modules (SafeList) ==========
MOD - [2010.03.16 08:16:26 | 000,555,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Boza\Plocha\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (WMPNetworkSvc)
SRV - [2009.11.25 00:51:35 | 000,138,680 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2009.11.25 00:51:21 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009.11.25 00:48:48 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009.11.25 00:43:56 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2008.07.29 18:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008.03.06 13:26:14 | 000,118,784 | R--- | M] (Bytemobile, Inc.) [Auto | Running] -- C:\WINDOWS\System32\bmwebcfg.exe -- (bmwebcfg)
SRV - [2007.06.01 02:02:06 | 000,036,400 | ---- | M] (Lenovo) [Auto | Running] -- C:\WINDOWS\System32\ibmpmsvc.exe -- (IBMPMSVC)
SRV - [2007.03.02 17:49:00 | 000,037,680 | ---- | M] (Lenovo.) [Auto | Running] -- C:\WINDOWS\System32\TPHDEXLG.exe -- (TPHDEXLGSVC)
SRV - [2007.02.16 18:49:50 | 000,411,168 | ---- | M] (Acronis) [Disabled | Stopped] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2006.05.12 14:04:08 | 000,439,248 | ---- | M] (RealVNC Ltd.) [Disabled | Stopped] -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe -- (WinVNC4)
SRV - [2005.11.22 15:20:28 | 000,036,864 | ---- | M] () [On_Demand | Stopped] -- C:\WINDOWS\System32\acs.exe -- (ACS)
SRV - [2005.08.25 17:55:56 | 000,016,384 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\OpenVPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2002.12.17 15:26:22 | 007,520,337 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR)
SRV - [2002.12.17 15:23:30 | 000,311,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -- (SQLAgent$SONY_MEDIAMGR)
SRV - [2002.09.20 14:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))
SRV - [1999.06.18 13:43:32 | 000,066,560 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\System32\Crypserv.exe -- (Crypkey License)
========== Driver Services (SafeList) ==========
DRV - [2009.11.25 00:50:59 | 000,094,160 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2009.11.25 00:50:12 | 000,114,768 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2009.11.25 00:50:00 | 000,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009.11.25 00:49:07 | 000,048,560 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2009.11.25 00:48:57 | 000,023,120 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2009.11.25 00:47:54 | 000,027,408 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2008.11.20 22:57:55 | 000,114,048 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\snapman.sys -- (snapman)
DRV - [2008.10.31 13:49:16 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2008.10.31 13:49:15 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\timntr.sys -- (timounter)
DRV - [2008.07.31 19:45:42 | 000,020,616 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BtHidBus.sys -- (BtHidBus)
DRV - [2008.07.02 13:58:48 | 000,026,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV - [2008.04.13 19:54:36 | 000,028,672 | ---- | M] (National Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nscirda.sys -- (NSCIRDA)
DRV - [2008.04.13 19:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\nmnt.sys -- (nm)
DRV - [2008.03.06 13:26:14 | 000,018,688 | R--- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\tcpipbm.sys -- (tcpipBM)
DRV - [2008.01.30 14:45:33 | 000,716,272 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\sptd.sys -- (sptd)
DRV - [2007.11.19 04:31:56 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\npf.sys -- (NPF) WinPcap Packet Driver (NPF)
DRV - [2007.06.01 02:01:30 | 000,021,424 | ---- | M] (Lenovo.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ibmpmdrv.sys -- (IBMPMDRV)
DRV - [2007.05.02 08:54:08 | 000,472,224 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ar5211.sys -- (AR5211)
DRV - [2007.03.02 17:49:00 | 000,100,656 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\Apsx86.sys -- (Shockprf)
DRV - [2007.03.02 17:47:00 | 000,019,760 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\ApsHM86.sys -- (TPDIGIMN)
DRV - [2006.11.16 22:02:24 | 001,133,568 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006.11.03 23:45:48 | 000,178,913 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\V0260Vid.sys -- (V0260VID)
DRV - [2005.12.15 14:27:52 | 000,034,639 | R--- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\FTD2XX.sys -- (FTD2XX)
DRV - [2005.07.25 10:04:08 | 000,048,640 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2005.07.05 14:57:06 | 000,017,699 | ---- | M] (IBM Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\TPHKDRV.sys -- (TPHKDRV)
DRV - [2005.04.20 01:38:00 | 000,016,384 | ---- | M] (IBM Corp.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\TPPWR.SYS -- (TPPWR)
DRV - [2005.02.11 09:24:00 | 000,079,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\k750obex.sys -- (k750obex)
DRV - [2005.02.11 09:22:00 | 000,081,728 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\k750mgmt.sys -- (k750mgmt)
DRV - [2005.02.11 09:21:00 | 000,089,872 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\k750mdm.sys -- (k750mdm)
DRV - [2005.02.11 09:21:00 | 000,006,576 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\k750mdfl.sys -- (k750mdfl)
DRV - [2005.02.11 09:19:00 | 000,055,216 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\k750bus.sys -- (k750bus) Sony Ericsson 750 driver (WDM)
DRV - [2004.10.14 01:27:54 | 000,054,272 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AvidXPSerial.sys -- (Serial)
DRV - [2004.10.08 04:00:00 | 000,006,796 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\TPPORT.SYS -- (TPPORT)
DRV - [2004.06.24 03:54:12 | 000,023,552 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\tap0801.sys -- (tap0801)
DRV - [2004.03.24 03:12:34 | 000,017,280 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\nsndis5.sys -- (NSNDIS5)
DRV - [2003.06.27 08:53:44 | 001,196,352 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2002.01.18 03:01:00 | 000,054,784 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\wlanNDS.sys -- (WLAN)
DRV - [2001.02.01 15:10:12 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aspi32.sys -- (Aspi32)
DRV - [1999.06.18 13:43:32 | 000,024,736 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\ckldrv.sys -- (NetworkX)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-329068152-492894223-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.cz/"
FF - prefs.js..extensions.enabledItems: anttoolbar@ant.com:2.0
FF - prefs.js..extensions.enabledItems: {C6128004-4838-4708-9A97-BB172D17767D}:1.6.1
FF - prefs.js..extensions.enabledItems: {43c35458-c907-439b-bcfd-07d373834689}:2.2.0
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.03.01 00:03:13 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.02.20 12:24:41 | 000,000,000 | ---D | M]
[2008.07.03 11:01:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Extensions
[2010.03.11 00:17:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions
[2010.01.25 10:55:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions\{43c35458-c907-439b-bcfd-07d373834689}
[2010.02.24 21:52:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions\{C6128004-4838-4708-9A97-BB172D17767D}
[2008.07.03 11:02:19 | 000,000,000 | ---D | M] (Media Pirate - The video downloader) -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions\{cc265d3d-3f6f-0170-a78b-bbbaef7a868c}
[2010.01.04 10:58:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010.01.15 21:52:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\extensions\anttoolbar@ant.com
[2008.01.30 14:47:39 | 000,002,920 | ---- | M] () -- C:\Documents and Settings\Boza\Data aplikací\Mozilla\Firefox\Profiles\u7mx818s.default\searchplugins\daemon-search.xml
[2010.03.11 00:17:28 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010.03.11 12:56:43 | 000,000,027 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (WebTransBHO Class) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll File not found
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (WebTranslator) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll File not found
O3 - HKU\S-1-5-21-329068152-492894223-854245398-1003\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] File not found
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [BLOG] C:\Program Files\ThinkPad\UTILIT~1\BATLOGEX.DLL ()
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE ()
O4 - HKLM..\Run: [BMMMONWND] C:\Program Files\ThinkPad\UTILIT~1\BATINFEX.DLL ()
O4 - HKLM..\Run: [EZEJMNAP] C:\Program Files\ThinkPad\UTILIT~1\EZEJMNAP.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe File not found
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe ()
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (Lenovo.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-329068152-492894223-854245398-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-329068152-492894223-854245398-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\S-1-5-21-329068152-492894223-854245398-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O7 - HKU\S-1-5-21-329068152-492894223-854245398-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést výběr do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést výběr do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll File not found
O9 - Extra 'Tools' menuitem : &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll File not found
O9 - Extra 'Tools' menuitem : &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll File not found
O9 - Extra 'Tools' menuitem : Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll File not found
O9 - Extra 'Tools' menuitem : Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll File not found
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\tpfnf2: DllName - notifyf2.dll - C:\WINDOWS\System32\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - tphklock.dll - C:\WINDOWS\System32\tphklock.dll ()
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop Components:1 () - http://timeanddate.com/counters/customc ... c=0&p0=204
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.12.09 17:41:45 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:12:00 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:12:00 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:12:02 | 000,000,000 | RHSD | M] - F:\autorun.inf -- [ FAT ]
O32 - AutoRun File - [2010.03.16 08:11:58 | 000,000,000 | ---D | M] - W:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:11:59 | 000,000,000 | ---D | M] - X:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:11:59 | 000,000,000 | ---D | M] - Y:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.03.16 08:11:59 | 000,000,000 | ---D | M] - Z:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\System32\ias [2008.11.13 13:09:44 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54046588552609792)
========== Files/Folders - Created Within 30 Days ==========
[2010.03.16 08:16:23 | 000,555,008 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Boza\Plocha\OTL.exe
[2010.03.16 08:12:00 | 000,000,000 | RHSD | C] -- C:\autorun.inf
[2010.03.16 07:55:22 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.03.15 08:19:39 | 000,000,000 | ---D | C] -- C:\cistic
[2010.03.14 20:00:23 | 000,000,000 | ---D | C] -- C:\Program Files\HYCAD
[2010.03.14 19:58:44 | 004,265,121 | ---- | C] (Jiang.Jiang ) -- C:\HYCADSetUpEn.exe
[2010.03.14 15:59:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\runouce.exe
[2010.03.14 15:54:19 | 000,632,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2010.03.14 15:54:18 | 000,554,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2010.03.14 15:54:17 | 000,034,048 | ---- | C] (MicroWorld Technologies Inc.) -- C:\WINDOWS\System32\eEmpty.exe
[2010.03.14 15:54:15 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\TASKMGR.COM
[2010.03.14 15:54:15 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\T.COM
[2010.03.14 15:54:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MicroWorld
[2010.03.14 15:54:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2010.03.12 17:44:36 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\regedit.exe
[2010.03.11 10:01:38 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.03.11 09:56:25 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.03.11 09:25:21 | 000,000,000 | ---D | C] -- C:\rsit
[2010.03.11 00:17:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boza\Data aplikací\Uniblue
[2010.03.10 00:25:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boza\Data aplikací\Malwarebytes
[2010.03.10 00:03:06 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.03.10 00:03:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.03.10 00:03:04 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.03.10 00:03:04 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.03.09 23:32:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boza\Plocha\viry
[2010.03.08 23:44:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boza\Plocha\stirling philips
[2010.03.08 00:19:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Boza\Plocha\Ladislav_Vodicka
[2010.03.04 21:08:56 | 000,000,000 | ---D | C] -- C:\Program Files\Free M4a to MP3 Converter
[2010.03.04 21:07:32 | 005,003,908 | ---- | C] (ManiacTools.com ) -- C:\Documents and Settings\Boza\Plocha\m4a-to-mp3-converter.exe
[2010.03.01 18:05:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2009.02.11 15:51:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Google
[2008.12.17 09:01:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Bytemobile
[2008.11.13 13:59:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Google
[2008.10.31 13:51:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Acronis
[2008.09.04 07:13:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2008.03.27 18:04:20 | 000,582,144 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Common Files\dao350.dll
[2008.03.14 17:17:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Apple
[2007.12.09 17:46:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2007.12.09 17:41:39 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2007.12.09 17:41:39 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.03.16 08:16:26 | 000,555,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Boza\Plocha\OTL.exe
[2010.03.16 08:13:14 | 001,099,298 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.03.16 08:13:14 | 000,459,288 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.03.16 08:13:14 | 000,455,900 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2010.03.16 08:13:14 | 000,090,434 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2010.03.16 08:13:14 | 000,079,078 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.03.16 08:12:04 | 000,207,206 | ---- | M] () -- C:\UsbFix_Upload_Me_THINKPAD.zip
[2010.03.16 08:01:57 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.03.16 08:01:29 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.03.16 08:01:18 | 1072,615,424 | -HS- | M] () -- C:\hiberfil.sys
[2010.03.16 08:00:08 | 006,815,744 | -H-- | M] () -- C:\Documents and Settings\Boza\NTUSER.DAT
[2010.03.16 08:00:08 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\Boza\ntuser.ini
[2010.03.16 07:55:00 | 000,000,940 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.03.16 07:54:39 | 001,775,837 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\UsbFix.exe
[2010.03.14 22:30:52 | 000,092,160 | ---- | M] () -- C:\Documents and Settings\Boza\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.03.14 20:00:26 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\HYCAD.lnk
[2010.03.14 19:58:44 | 004,265,121 | ---- | M] (Jiang.Jiang ) -- C:\HYCADSetUpEn.exe
[2010.03.14 18:13:09 | 000,083,456 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\kalendar.xls
[2010.03.14 15:54:18 | 000,632,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll
[2010.03.14 15:54:17 | 000,554,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll
[2010.03.14 15:54:16 | 000,034,048 | ---- | M] (MicroWorld Technologies Inc.) -- C:\WINDOWS\System32\eEmpty.exe
[2010.03.14 15:53:48 | 068,866,904 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\mwav.exe
[2010.03.14 15:42:12 | 000,082,086 | ---- | M] () -- C:\Documents and Settings\Boza\Dokumenty\cc_20100314_1541.reg
[2010.03.14 15:23:02 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.03.12 20:20:12 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.03.12 17:40:08 | 003,888,122 | R--- | M] () -- C:\Documents and Settings\Boza\Plocha\ComboFix.exe
[2010.03.12 11:16:15 | 000,028,936 | ---- | M] () -- C:\Documents and Settings\Boza\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2010.03.11 21:50:38 | 000,126,447 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\repair_technician.pdf
[2010.03.11 12:56:43 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.03.11 10:01:46 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.03.11 09:58:52 | 000,151,584 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.03.11 09:14:50 | 000,694,826 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\viry_login.bmp
[2010.03.10 00:03:09 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.03.09 23:55:49 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010.03.09 18:02:40 | 000,104,106 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\TAB119.jpg
[2010.03.09 00:51:49 | 000,207,242 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\karta_studium.jpg
[2010.03.07 02:44:11 | 008,419,220 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\fox on the run.flv
[2010.03.05 23:25:51 | 000,014,336 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\dynama.xls
[2010.03.05 22:28:39 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\Boza\PUTTY.RND
[2010.03.04 21:08:59 | 000,000,740 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\Free M4a to MP3 Converter.lnk
[2010.03.04 21:07:55 | 005,003,908 | ---- | M] (ManiacTools.com ) -- C:\Documents and Settings\Boza\Plocha\m4a-to-mp3-converter.exe
[2010.03.03 23:55:25 | 000,245,786 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\Pohled_spolecnosti_CEPS_na_fotovaltaiku_k_23_2.pdf
[2010.02.21 22:30:58 | 000,033,792 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\co nam jeste privezt;).doc
[2010.02.21 15:50:37 | 010,719,744 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\nizkootackove generatory.doc
[2010.02.18 10:45:18 | 000,034,304 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\dane.doc
[2010.02.16 20:22:03 | 000,504,007 | ---- | M] () -- C:\Documents and Settings\Boza\Plocha\dvojkolo.PNG
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.03.16 08:12:04 | 000,207,206 | ---- | C] () -- C:\UsbFix_Upload_Me_THINKPAD.zip
[2010.03.16 07:54:28 | 001,775,837 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\UsbFix.exe
[2010.03.15 19:28:38 | 1072,615,424 | -HS- | C] () -- C:\hiberfil.sys
[2010.03.14 20:00:26 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\HYCAD.lnk
[2010.03.14 15:54:17 | 000,000,522 | ---- | C] () -- C:\WINDOWS\System32\Microsoft.VC80.CRT.manifest
[2010.03.14 15:53:45 | 068,866,904 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\mwav.exe
[2010.03.14 15:41:57 | 000,082,086 | ---- | C] () -- C:\Documents and Settings\Boza\Dokumenty\cc_20100314_1541.reg
[2010.03.11 21:50:38 | 000,126,447 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\repair_technician.pdf
[2010.03.11 10:01:46 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.03.11 10:01:41 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.03.11 09:54:56 | 003,888,122 | R--- | C] () -- C:\Documents and Settings\Boza\Plocha\ComboFix.exe
[2010.03.11 09:14:49 | 000,694,826 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\viry_login.bmp
[2010.03.10 00:03:09 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.03.09 18:02:38 | 000,104,106 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\TAB119.jpg
[2010.03.09 00:51:24 | 000,207,242 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\karta_studium.jpg
[2010.03.07 02:41:35 | 008,419,220 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\fox on the run.flv
[2010.03.04 21:08:59 | 000,000,740 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\Free M4a to MP3 Converter.lnk
[2010.03.03 23:55:25 | 000,245,786 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\Pohled_spolecnosti_CEPS_na_fotovaltaiku_k_23_2.pdf
[2010.03.01 18:05:49 | 000,002,283 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.02.18 10:45:18 | 000,034,304 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\dane.doc
[2010.02.16 20:22:02 | 000,504,007 | ---- | C] () -- C:\Documents and Settings\Boza\Plocha\dvojkolo.PNG
[2009.08.28 09:55:34 | 000,001,031 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\hpzinstall.log
[2008.12.25 13:56:26 | 000,000,090 | R--- | C] () -- C:\WINDOWS\System32\PRESTOUN.ini
[2008.11.25 21:22:43 | 000,000,080 | RHS- | C] () -- C:\WINDOWS\System32\FEEBB870E5.dll
[2008.11.25 10:28:18 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008.11.07 17:43:49 | 000,000,146 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2008.11.07 17:43:48 | 000,003,165 | R--- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2008.11.07 17:43:13 | 000,106,496 | R--- | C] () -- C:\WINDOWS\System32\VSHP1020.DLL
[2008.10.21 23:21:00 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2008.10.21 23:21:00 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2008.08.17 21:58:38 | 001,032,582 | ---- | C] () -- C:\WINDOWS\System32\alleg42.dll
[2008.06.20 13:17:31 | 000,024,736 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys
[2008.03.27 20:31:21 | 000,905,290 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2008.03.27 20:31:20 | 000,054,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\AvidXPSerial.sys
[2008.03.27 20:31:16 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\Cpuinf32.dll
[2008.03.27 18:04:20 | 000,073,184 | ---- | C] () -- C:\Program Files\Common Files\Dao2535.tlb
[2008.03.08 12:58:20 | 000,000,073 | ---- | C] () -- C:\WINDOWS\System32\adultpdf_Decrypt_reg.ini
[2007.12.29 02:34:16 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Boza\Local Settings\Data aplikací\PUTTY.RND
[2007.12.15 22:55:36 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2007.12.15 22:55:34 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007.12.15 22:55:34 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007.12.15 22:55:33 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007.12.15 22:55:32 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007.12.15 22:55:31 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007.12.15 22:43:52 | 000,092,160 | ---- | C] () -- C:\Documents and Settings\Boza\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.12.15 21:13:10 | 000,054,784 | ---- | C] () -- C:\WINDOWS\System32\drivers\wlanNDS.sys
[2007.12.15 21:13:10 | 000,050,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\wlanUSB.sys
[2007.12.09 21:17:35 | 000,000,124 | ---- | C] () -- C:\Documents and Settings\Boza\Local Settings\Data aplikací\fusioncache.dat
[2007.10.11 10:01:42 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007.01.25 23:04:12 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\mase32.dll
[2007.01.25 23:04:12 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\ma32.dll
[2006.10.30 11:58:33 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar_mpfc.dll
[2005.11.30 20:16:02 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\tphklock.dll
[2005.07.05 23:45:08 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\notifyf2.dll
[1996.02.01 18:25:42 | 000,943,616 | ---- | C] () -- C:\WINDOWS\System32\dfolder.dll
========== LOP Check ==========
[2008.11.21 17:12:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Acronis
[2010.03.14 15:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
[2008.04.03 14:33:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle
[2008.04.03 14:41:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle VideoSpin
[2008.04.13 20:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2009.02.23 19:33:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2008.04.19 13:47:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\VideoSpin
[2008.11.21 16:13:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Acronis
[2010.01.19 22:43:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\BitTyrant
[2008.12.17 02:13:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Bytemobile
[2008.02.07 18:00:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\COWON
[2008.01.30 14:47:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\DAEMON Tools
[2008.08.18 09:06:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Dev-Cpp
[2008.11.26 02:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\EZwebLynx
[2008.05.28 22:06:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\GARMIN
[2008.02.17 19:28:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\ICQ
[2008.12.25 16:22:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\MyPhoneExplorer
[2008.06.16 21:38:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Navigator
[2008.06.22 18:19:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Plagiarism-Finder
[2008.04.13 21:13:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Publish Providers
[2008.08.19 23:32:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\QIP
[2008.04.14 02:48:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Sony
[2008.01.13 19:58:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\SWI-Prolog
[2008.09.29 22:15:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\The Bat!
[2010.03.11 00:17:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Uniblue
[2009.12.01 23:15:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\VitySoft
[2007.12.16 23:46:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\WildPackets
[2007.12.15 21:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\Wireshark
[2009.04.18 08:19:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\XnView
[2008.06.21 18:19:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Boza\Data aplikací\xpce
[2008.10.31 13:51:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\Acronis
[2008.12.17 09:01:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Bytemobile
[2009.01.08 17:23:21 | 000,000,920 | ---- | M] () -- C:\WINDOWS\Tasks\BMMTask.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2010.03.14 19:58:44 | 004,265,121 | ---- | M] (Jiang.Jiang ) -- C:\HYCADSetUpEn.exe
[2008.04.14 04:22:42 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\regedit.exe
< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
< %SYSTEMDRIVE%\scecli.dll /s /md5 >
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
< %SYSTEMDRIVE%\sceclt.dll /s /md5 >
< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >
< %SYSTEMDRIVE%\logevent.dll /s /md5 >
< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
< %SYSTEMDRIVE%\atapi.sys /s /md5 >
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >
< %SYSTEMDRIVE%\viasraid.sys /s /md5 >
< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >
< %SYSTEMDRIVE%\viamraid.sys /s /md5 >
< %SYSTEMDRIVE%\nvata.sys /s /md5 >
< %SYSTEMROOT%\*. /mp /s >
< %SYSTEMROOT%\system32\*.dll /lockedfiles >
[2009.02.20 18:13:42 | 000,347,136 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\dxtmsft.dll
[2009.02.20 18:13:42 | 000,214,528 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\System32\dxtrans.dll
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMROOT%\Tasks\*.job /lockedfiles >
< End of report >