Re: Prosím o pomoc bráchu Mc_Murphyho.
Napsal: 21 zář 2012 13:29
Takže nové OTL:
OTL logfile created on: 21.9.2012 13:53:50 - Run 2
OTL by OldTimer - Version 3.2.64.0 Folder = C:\Documents and Settings\Lukáš\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1023,29 Mb Total Physical Memory | 334,02 Mb Available Physical Memory | 32,64% Memory free
2,40 Gb Paging File | 1,81 Gb Available in Paging File | 75,43% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 7,53 Gb Free Space | 38,54% Space Free | Partition Type: NTFS
Drive D: | 129,51 Gb Total Space | 82,40 Gb Free Space | 63,62% Space Free | Partition Type: NTFS
Drive E: | 3,95 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Computer Name: BERKOSI | User Name: Lukáš | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2012.09.19 15:17:09 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
PRC - [2012.09.08 11:39:17 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011.10.25 14:44:42 | 000,793,048 | ---- | M] (PC Tools) -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
PRC - [2011.10.08 06:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011.05.16 12:22:26 | 000,326,504 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\DriverScanner\driverscanner.exe
PRC - [2011.05.16 12:22:26 | 000,025,464 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe
PRC - [2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.11.15 02:59:50 | 002,836,304 | ---- | M] (Xfire Inc.) -- D:\hovno\Xfire\xfire.exe
PRC - [2006.07.13 16:59:48 | 000,131,131 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
PRC - [2006.07.13 16:59:32 | 000,065,599 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
PRC - [2006.04.03 18:04:02 | 000,020,543 | ---- | M] (Apache Software Foundation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
========== Modules (No Company Name) ==========
MOD - [2012.09.08 11:39:15 | 002,244,064 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012.08.15 12:01:39 | 009,465,032 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
MOD - [2011.05.16 12:22:26 | 000,407,400 | ---- | M] () -- C:\Program Files\Uniblue\DriverScanner\locale\br\br.dll
MOD - [2011.05.16 12:22:26 | 000,071,016 | ---- | M] () -- C:\Program Files\Uniblue\DriverScanner\InstallerExtensions.dll
MOD - [2011.05.16 12:22:26 | 000,018,792 | ---- | M] () -- C:\Program Files\Uniblue\DriverScanner\cwebpage.dll
MOD - [2008.04.14 08:51:48 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2006.04.03 18:04:02 | 000,876,544 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\libeay32.dll
MOD - [2006.04.03 18:04:02 | 000,159,744 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\ssleay32.dll
MOD - [2006.04.03 18:04:02 | 000,024,691 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_auth.so
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012.09.08 11:39:16 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2011.10.25 14:44:42 | 000,793,048 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2011.10.08 06:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011.06.08 14:02:00 | 000,633,856 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2006.07.13 16:59:48 | 000,131,131 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe -- (nSvcIp)
SRV - [2006.07.13 16:59:32 | 000,065,599 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe -- (nSvcLog)
SRV - [2006.04.03 18:04:02 | 000,020,543 | ---- | M] (Apache Software Foundation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe -- (ForcewareWebInterface)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2011.12.30 16:07:27 | 000,239,168 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011.08.17 10:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011.08.17 10:56:22 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011.08.17 09:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011.08.17 09:56:26 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2008.08.26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2006.08.14 14:51:28 | 000,105,344 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvata.sys -- (nvata)
DRV - [2006.07.12 07:38:30 | 000,020,480 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006.07.12 07:38:28 | 000,057,856 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006.07.01 22:42:58 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006.03.18 04:18:58 | 000,392,960 | R--- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2005.08.18 00:00:00 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt -- (EverestDriver)
DRV - [2005.08.10 16:06:28 | 000,019,968 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfsync02.sys -- (sfsync02)
DRV - [2005.08.10 14:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfdrv01.sys -- (sfdrv01)
DRV - [2005.05.16 15:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfhlp02.sys -- (sfhlp02)
DRV - [2004.08.13 20:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ie ... earchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" = http://dts.search-results.com/sr?src=ie ... earchTerms}
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.my-tools-app.com/?babsrc= ... earchTerms}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?sr ... 18F38C59DD}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://home.sweetim.com/?st=1&barid={26 ... 18F38C59DD}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes,bProtectorDefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTer ... 18f38c59dd
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?clien ... 0937A611F1
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{399a1442-7377-49e7-8d77-6dc9ed5968c1}: "URL" = http://www.zbozi.cz/?q={searchTerms}&so ... earch_6826
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{5cf5d387-d87c-4408-9a6b-301b0713d62a}: "URL" = http://www.mapy.cz/?query={searchTerms} ... earch_6826
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.ph ... &ch_id=osd
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{8172f457-818d-46db-941f-2bbe53e156af}: "URL" = http://www.searchqu.com/web?src=ieb&app ... earchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browse ... earchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ie ... earchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" = http://dts.search-results.com/sr?src=ie ... earchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... V=IENOSGBR
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.my-tools-app.com/?babsrc= ... earchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{DCDBBF03-BC10-457D-911F-EFB0321D22BE}: "URL" = ${SRCH_SCP_URL}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{eb97f7df-1773-4916-aae6-5af74da8c69d}: "URL" = http://www.firmy.cz/phr/{searchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?sr ... 18F38C59DD}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/xilisoftdownl ... 6BC0977554}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1005\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - No CLSID value found
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaultthis.engineName: "BitTorrentBar Customized Web Search"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledAddons: 4fbf236e66dfc@4fbf236e66e35.info:1.0
FF - prefs.js..extensions.enabledAddons: 4fd39b2e7d3c3@4fd39b2e7d3fd.info:5.1
FF - prefs.js..extensions.enabledAddons: 4fd3a50b5e081@4fd3a50b5e0b9.info:5.1
FF - prefs.js..extensions.enabledAddons: adapter@babylontc.com:1.0.0.1
FF - prefs.js..extensions.enabledAddons: ffxtlbr@babylon.com:1.1.9
FF - prefs.js..extensions.enabledAddons: ffxtlbra@softonic.com:1.6.0
FF - prefs.js..extensions.enabledAddons: info@bflix.info:5.0
FF - prefs.js..extensions.enabledAddons: info@my-tools-app.com:1.1
FF - prefs.js..extensions.enabledAddons: info@thebflix.com:4.0
FF - prefs.js..extensions.enabledAddons: ocr@babylon.com:1.1
FF - prefs.js..extensions.enabledAddons: plugin@yontoo.com:1.20.00
FF - prefs.js..extensions.enabledAddons: {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:3.15.1.0
FF - prefs.js..extensions.enabledAddons: {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}:2.0
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.as ... ource=2&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.12.23 13:14:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.08 11:39:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012.09.19 11:30:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Extensions
[2012.09.19 11:56:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions
[2012.06.07 16:05:04 | 000,000,000 | ---D | M] (Xilisoft Download Youtube Toolbar) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC}
[2012.08.21 14:37:17 | 000,000,000 | ---D | M] (DVDVideoSoftTB) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012.08.29 14:38:01 | 000,000,000 | ---D | M] (BitTorrentBar Community Toolbar) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2012.06.07 18:54:51 | 000,000,000 | ---D | M] (DealPly) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
[2012.01.07 17:27:59 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2012.06.07 18:54:49 | 000,000,000 | ---D | M] (ADDICT-THING) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\4fbf236e66dfc@4fbf236e66e35.info
[2012.06.09 21:02:16 | 000,000,000 | ---D | M] (TheBflix) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\4fd39b2e7d3c3@4fd39b2e7d3fd.info
[2012.06.09 21:35:34 | 000,000,000 | ---D | M] (TheBflix) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\4fd3a50b5e081@4fd3a50b5e0b9.info
[2012.06.09 21:02:18 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\ffxtlbr@babylon.com
[2012.07.30 09:13:11 | 000,000,000 | ---D | M] (softonic.com) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\ffxtlbra@softonic.com
[2012.06.07 18:54:50 | 000,000,000 | ---D | M] (TheBflix) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\info@bflix.info
[2012.06.07 18:54:50 | 000,000,000 | ---D | M] (MyTools extension) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\info@my-tools-app.com
[2012.06.07 18:54:51 | 000,000,000 | ---D | M] (Bflix) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\info@thebflix.com
[2012.07.30 08:00:05 | 000,000,000 | ---D | M] (Yontoo) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\plugin@yontoo.com
[2012.06.07 19:08:42 | 000,000,000 | ---D | M] (Yandex.Bar) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\yasearch@yandex.ru
[2012.06.09 21:02:16 | 000,021,707 | ---- | M] () (No name found) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\adapter@babylontc.com.xpi
[2012.06.09 21:02:18 | 000,011,148 | ---- | M] () (No name found) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\ocr@babylon.com.xpi
[2012.06.07 16:53:36 | 000,002,324 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\askcom.xml
[2012.05.30 08:39:58 | 000,000,929 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\conduit.xml
[2012.07.07 14:18:31 | 000,009,633 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\my-web-search.xml
[2012.02.10 12:58:43 | 000,000,544 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\MyTools.xml
[2012.08.23 13:06:27 | 000,002,519 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\Search_Results.xml
[2012.07.30 07:58:44 | 000,002,062 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\softonic.xml
[2012.03.18 13:57:55 | 000,003,974 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\sweetim.xml
[2012.09.19 11:56:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.06.09 20:52:46 | 000,000,000 | ---D | M] (GameTap) -- C:\Program Files\Mozilla Firefox\extensions\GameTapPlayer@gametap.com
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\4FBF236E66DFC@4FBF236E66E35.INFO
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\4FD39B2E7D3C3@4FD39B2E7D3FD.INFO
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\4FD3A50B5E081@4FD3A50B5E0B9.INFO
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\ADAPTER@BABYLONTC.COM.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\FFXTLBR@BABYLON.COM
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\FFXTLBRA@SOFTONIC.COM
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\INFO@BFLIX.INFO
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\INFO@MY-TOOLS-APP.COM
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\INFO@THEBFLIX.COM
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\OCR@BABYLON.COM.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\PLUGIN@YONTOO.COM
[2012.09.08 11:39:17 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.08.21 11:09:00 | 000,002,349 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012.08.31 10:41:02 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2012.08.31 10:41:02 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2012.08.23 13:06:27 | 000,002,519 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2012.08.31 10:41:02 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2012.08.31 10:41:02 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2012.08.31 10:41:02 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2012.09.20 16:51:52 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (no name) - !!{98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\Toolbar\WebBrowser: (no name) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - No CLSID value found.
O4 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004..\Run: [DriverScanner] C:\Program Files\Uniblue\DriverScanner\launcher.exe (Uniblue Systems Limited)
O4 - HKU\S-1-5-21-1935655697-1958367476-682003330-1005..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe File not found
O4 - Startup: C:\Documents and Settings\Lukáš\Nabídka Start\Programy\Po spuštění\Xfire.lnk = D:\hovno\Xfire\xfire.exe (Xfire Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} Reg Error: Key error. (GameTap Player)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{322D9B46-694A-4DBB-97DC-616396B5B612}: NameServer = 85.93.160.254,85.93.160.118
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.10.18 09:38:40 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004.11.18 22:59:22 | 000,000,000 | R--D | M] - E:\AutoRun -- [ UDF ]
O32 - AutoRun File - [2004.11.18 22:25:54 | 000,684,032 | R--- | M] (Electronic Arts Inc.) - E:\AutoRun.exe -- [ UDF ]
O32 - AutoRun File - [2004.11.18 22:58:27 | 000,000,103 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2004.11.14 16:08:54 | 000,929,792 | R--- | M] (Electronic Arts Inc.) - E:\AutoRunGUI.dll -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2012.09.20 20:24:38 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Lukáš\Recent
[2012.09.20 20:24:38 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012.09.20 17:56:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lukáš\Data aplikací\Malwarebytes
[2012.09.20 17:56:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2012.09.20 17:54:51 | 010,524,080 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Lukáš\Plocha\mbam-setup-1.65.0.1400.exe
[2012.09.20 16:54:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012.09.20 13:21:14 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012.09.20 13:19:55 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012.09.20 13:19:55 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012.09.20 13:19:55 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012.09.20 13:19:55 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012.09.20 13:19:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.09.20 13:19:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2012.09.20 13:09:55 | 004,753,679 | R--- | C] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\ComboFix.exe
[2012.09.20 13:08:46 | 001,678,240 | ---- | C] (Bleeping Computer, LLC) -- C:\Documents and Settings\Lukáš\Plocha\rkill.com
[2012.09.20 11:40:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Lukáš\Nabídka Start\Programy\Nástroje pro správu
[2012.09.20 11:40:38 | 000,492,146 | R--- | C] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\dds.exe
[2012.09.19 18:38:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lukáš\Plocha\RK_Quarantine
[2012.09.19 15:17:42 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
[2012.09.19 12:18:52 | 003,178,400 | ---- | C] (McAfee, Inc.) -- C:\Documents and Settings\Lukáš\Plocha\MCPR.exe
[2012.09.19 11:09:42 | 000,245,760 | ---- | C] (Ask.com) -- C:\Program Files\Uninstall Ask Toolbar.dll
[2012.09.18 19:34:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Trymedia
[2012.09.18 18:54:27 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.09.18 18:54:26 | 000,000,000 | ---D | C] -- C:\rsit
[2012.09.18 18:06:21 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.09.15 16:33:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lukáš\Dokumenty\LOTR The Return of the King (tm) Data
[2012.09.15 12:02:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lukáš\Data aplikací\My Battle for Middle-earth Files
[2012.09.15 12:01:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\EA GAMES
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 7 Days ==========
[2012.09.21 13:55:39 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.09.21 13:01:15 | 000,000,914 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.09.21 11:02:28 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2012.09.21 10:21:24 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\DriverScanner.job
[2012.09.21 10:21:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.09.20 18:58:23 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Lukáš.job
[2012.09.20 17:54:39 | 010,524,080 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Lukáš\Plocha\mbam-setup-1.65.0.1400.exe
[2012.09.20 16:51:52 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012.09.20 16:44:17 | 004,753,679 | R--- | M] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\ComboFix.exe
[2012.09.20 13:21:16 | 000,000,339 | RHS- | M] () -- C:\boot.ini
[2012.09.20 13:08:15 | 001,678,240 | ---- | M] (Bleeping Computer, LLC) -- C:\Documents and Settings\Lukáš\Plocha\rkill.com
[2012.09.20 11:40:32 | 000,492,146 | R--- | M] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\dds.exe
[2012.09.20 09:27:17 | 000,002,504 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012.09.19 18:36:00 | 001,382,912 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RogueKiller.exe
[2012.09.19 15:17:09 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
[2012.09.19 12:18:42 | 003,178,400 | ---- | M] (McAfee, Inc.) -- C:\Documents and Settings\Lukáš\Plocha\MCPR.exe
[2012.09.18 19:35:47 | 000,000,010 | ---- | M] () -- C:\WINDOWS\popcinfo.dat
[2012.09.18 18:54:06 | 000,781,383 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RSIT.exe
[2012.09.18 18:42:23 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.09.18 18:06:23 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.09.20 13:21:16 | 000,000,223 | ---- | C] () -- C:\Boot.bak
[2012.09.20 13:21:15 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2012.09.20 13:19:55 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012.09.20 13:19:55 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012.09.20 13:19:55 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012.09.20 13:19:55 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012.09.20 13:19:55 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012.09.19 18:38:32 | 001,382,912 | ---- | C] () -- C:\Documents and Settings\Lukáš\Plocha\RogueKiller.exe
[2012.09.19 15:24:22 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.09.19 11:33:09 | 000,172,464 | ---- | C] () -- C:\Program Files\4zres.dll
[2012.09.19 11:29:26 | 000,172,440 | ---- | C] () -- C:\Program Files\4wres.dll
[2012.09.18 18:54:16 | 000,781,383 | ---- | C] () -- C:\Documents and Settings\Lukáš\Plocha\RSIT.exe
[2012.09.18 18:06:23 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[2012.07.03 21:42:40 | 000,159,552 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2012.07.02 22:28:33 | 000,000,268 | ---- | C] () -- C:\WINDOWS\game.ini
[2012.04.09 09:53:54 | 000,000,105 | ---- | C] () -- C:\WINDOWS\KA.ini
[2012.04.07 13:40:07 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\74e69b9a20b79bcd8ad1e149f6c34ba4_c
[2012.03.27 09:07:57 | 000,000,010 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2012.01.28 17:32:20 | 000,000,176 | ---- | C] () -- C:\WINDOWS\disneysy.ini
[2012.01.21 10:22:15 | 000,000,204 | ---- | C] () -- C:\WINDOWS\RomeTW Demo.ini
[2011.12.31 12:34:39 | 000,292,700 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011.12.31 12:34:39 | 000,292,700 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011.12.31 12:34:39 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011.12.31 12:33:57 | 002,783,770 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2011.12.23 16:07:27 | 000,037,336 | ---- | C] () -- C:\WINDOWS\System32\CleanMFT32.exe
[2011.12.05 16:54:53 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2011.11.11 09:20:25 | 000,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011.11.11 09:20:25 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Lukáš\Data aplikací\PnkBstrK.sys
[2011.11.11 09:20:02 | 000,103,736 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2011.11.11 09:19:58 | 000,066,872 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2011.11.11 09:19:57 | 002,434,856 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_bc2.exe
[2011.11.02 07:33:29 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2011.10.24 18:34:01 | 000,000,157 | ---- | C] () -- C:\Documents and Settings\Lukáš\default.pls
[2011.10.23 12:19:28 | 000,001,211 | ---- | C] () -- C:\WINDOWS\disney.ini
[2011.10.22 11:46:05 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011.10.22 10:24:36 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2011.10.21 21:24:13 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2011.10.21 21:24:07 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.10.18 20:19:24 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.10.18 17:29:12 | 000,017,722 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2011.10.18 17:28:03 | 000,017,470 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2011.10.18 17:28:01 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2011.10.18 17:27:50 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2011.10.18 10:30:13 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011.10.18 10:29:01 | 000,272,576 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.10.18 09:40:55 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011.10.18 09:35:55 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
========== ZeroAccess Check ==========
[2011.10.26 09:22:02 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
========== LOP Check ==========
[2012.02.09 12:01:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\100
[2012.08.08 19:14:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ADDICT-THING
[2011.10.21 20:02:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3
[2011.10.22 11:07:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3 XPack Trial
[2011.10.22 10:27:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3 YPack Trial
[2012.06.07 16:52:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ask
[2012.09.20 09:27:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2012.08.21 11:08:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Babylon
[2012.09.20 19:06:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\BasicScan
[2012.08.23 23:41:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\boost_interprocess
[2011.10.31 08:20:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2012.07.03 21:46:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\EA Core
[2012.07.04 23:50:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
[2012.06.09 20:53:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\GameTap Web Player
[2012.09.20 19:06:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IBUpdaterService
[2011.10.21 18:49:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2012.01.14 00:07:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Installations
[2012.07.30 11:53:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\InstallMate
[2011.12.30 15:20:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IObit
[2012.07.05 21:41:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\KONAMI
[2012.01.14 11:08:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NokiaInstallerCache
[2012.06.09 21:34:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\OptimizerPro
[2011.12.30 16:38:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Origin
[2012.01.14 00:14:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2012.01.07 10:14:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Premium
[2012.07.30 07:59:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Tarma Installer
[2012.01.05 10:11:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2012.06.09 21:34:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TheBflixUpdater
[2012.04.11 13:44:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Vivendi Universal Games
[2011.10.26 10:40:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\{1B0B54CA-AA7D-41D3-A84A-29E7C9CB13A2}
[2012.06.09 21:04:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Babylon
[2012.09.18 18:10:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\BitTorrent
[2012.09.18 18:10:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite
[2011.12.23 13:20:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DDMSettings
[2011.10.23 12:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Disney Interactive
[2012.06.07 08:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DVDVideoSoft
[2012.06.07 08:29:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DVDVideoSoftIEHelpers
[2012.05.26 08:40:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\GetRightToGo
[2012.09.20 14:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ICQ
[2011.12.30 15:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\IObit
[2011.10.26 10:15:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Leadertech
[2012.02.26 21:54:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mount&Blade Warband
[2012.09.15 12:32:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\My Battle for Middle-earth Files
[2012.01.14 11:05:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Nokia
[2012.06.07 16:53:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\OpenCandy
[2012.05.25 17:25:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Optimizer Pro
[2011.12.30 16:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Origin
[2012.01.14 11:06:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PC Suite
[2012.09.20 10:00:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PerformerSoft
[2012.09.19 11:14:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PriceGong
[2012.04.11 17:58:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\searchcoreband
[2011.12.06 20:55:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\searchquband
[2012.02.10 13:22:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\TeamViewer
[2012.06.07 16:05:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4
[2012.09.18 18:46:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Uniblue
[2012.06.07 16:06:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Xilisoft
[2012.09.19 11:54:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Yandex
========== Purity Check ==========
========== Custom Scans ==========
< netsvc >
[2011.10.18 09:36:40 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2011.10.18 09:42:05 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2011.10.22 01:53:10 | 000,000,440 | -H-- | C] () -- C:\WINDOWS\Tasks\Norton Security Scan for Lukáš.job
[2012.02.09 11:56:17 | 000,000,260 | ---- | C] () -- C:\WINDOWS\Tasks\DriverScanner.job
[2012.06.28 09:49:57 | 000,000,914 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
< MD5 for: ATAPI.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\erdnt\cache\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2006.03.02 14:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe
< MD5 for: CDROM.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2006.03.02 14:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\erdnt\cache\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2006.03.02 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: HAL.DLL >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.14 00:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.14 00:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2006.03.02 14:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
< MD5 for: SCECLI.DLL >
[2006.03.02 14:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\erdnt\cache\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SVCHOST.EXE >
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\erdnt\cache\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2006.03.02 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB2509553$\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\erdnt\cache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2006.03.02 14:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\erdnt\cache\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2006.03.02 14:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2006.03.02 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\erdnt\cache\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< %systemroot%*.* /U /s >
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[83 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2011.10.22 11:47:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Adobe
[2011.10.22 11:48:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\AdobeUM
[2011.12.30 15:49:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Ahead
[2012.06.09 21:04:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Babylon
[2012.09.18 18:10:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\BitTorrent
[2012.09.18 18:10:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite
[2011.12.23 13:20:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DDMSettings
[2011.10.23 12:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Disney Interactive
[2011.11.23 18:41:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DivX
[2012.06.07 08:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DVDVideoSoft
[2012.06.07 08:29:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DVDVideoSoftIEHelpers
[2012.05.26 08:40:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\GetRightToGo
[2012.09.20 14:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ICQ
[2011.10.18 09:43:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Identities
[2012.01.07 14:58:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\InstallShield
[2011.12.30 15:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\IObit
[2011.10.26 10:15:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Leadertech
[2011.10.18 20:18:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Macromedia
[2012.09.20 17:56:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Malwarebytes
[2012.06.10 14:04:49 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft
[2012.02.26 21:54:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mount&Blade Warband
[2011.12.06 23:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla
[2012.09.15 12:32:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\My Battle for Middle-earth Files
[2012.01.14 11:05:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Nokia
[2012.08.05 22:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\NVIDIA
[2012.06.07 16:53:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\OpenCandy
[2012.05.25 17:25:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Optimizer Pro
[2011.12.30 16:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Origin
[2012.01.14 11:06:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PC Suite
[2012.09.20 10:00:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PerformerSoft
[2012.09.19 11:14:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PriceGong
[2012.04.11 17:58:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\searchcoreband
[2011.12.06 20:55:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\searchquband
[2012.09.21 13:50:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Skype
[2012.02.10 13:22:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\TeamViewer
[2012.06.07 16:05:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4
[2012.09.18 18:46:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Uniblue
[2012.08.29 13:05:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\vlc
[2012.01.21 14:45:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\WinRAR
[2012.05.05 21:53:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Xfire
[2012.06.07 16:06:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Xilisoft
[2012.09.19 11:54:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Yandex
< %APPDATA%\*.exe /s >
[2012.04.20 19:08:46 | 005,837,432 | ---- | M] (Uniblue Systems Ltd ) -- C:\Documents and Settings\Lukáš\Data aplikací\OpenCandy\0386E49A0A4A4BB9A564C114184CD54F\speedupmypcROW.exe
[2011.06.09 21:03:56 | 005,845,528 | ---- | M] (Uniblue Systems Ltd ) -- C:\Documents and Settings\Lukáš\Data aplikací\OpenCandy\E3BD74482391407C99EE97C4B9B5E1EB\driverscanner (33).exe
[2010.02.16 11:57:38 | 000,197,632 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\TbHelper2.exe
[2009.11.25 11:12:00 | 000,042,496 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\uninstall.exe
[2012.06.07 16:05:04 | 000,059,188 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\UninstallToolbar.exe
[2009.11.25 11:12:00 | 000,056,832 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\update.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job >
[2012.09.21 13:01:15 | 000,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012.09.21 10:21:24 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\DriverScanner.job
[2012.09.20 18:58:23 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\Tasks\Norton Security Scan for Lukáš.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2011.10.18 10:28:18 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2011.10.18 10:28:18 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2011.10.18 10:28:18 | 000,466,944 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2012.09.20 09:27:17 | 000,002,504 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT
[2012.09.21 10:21:36 | 000,000,000 | ---- | M] () -- C:\WINDOWS\system32\nmp.log
[2012.09.18 18:42:23 | 000,013,646 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %userprofile%\Plocha\*.* >
[2012.01.07 23:50:04 | 000,001,823 | -H-- | M] () -- C:\Documents and Settings\Lukáš\Plocha\Age of Empires III - The Asian Dynasties.lnk
[2012.01.07 23:42:49 | 000,001,816 | -H-- | M] () -- C:\Documents and Settings\Lukáš\Plocha\Age of Empires III.lnk
[2012.09.20 16:44:17 | 004,753,679 | R--- | M] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\ComboFix.exe
[2012.09.20 16:54:49 | 000,012,418 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\ComboFix.txt
[2012.09.20 11:40:32 | 000,492,146 | R--- | M] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\dds.exe
[2012.09.20 11:41:21 | 000,010,680 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\dds.txt
[2012.09.19 15:59:37 | 000,048,628 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\Extras.Txt
[2012.02.25 14:55:32 | 000,000,609 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\GameSpy Arcade.lnk
[2012.09.20 18:36:36 | 000,025,804 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\mbam-log-2012-09-20 (18-36-24).txt
[2012.09.20 17:54:39 | 010,524,080 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Lukáš\Plocha\mbam-setup-1.65.0.1400.exe
[2012.09.19 12:18:42 | 003,178,400 | ---- | M] (McAfee, Inc.) -- C:\Documents and Settings\Lukáš\Plocha\MCPR.exe
[2012.09.19 15:17:09 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
[2012.09.19 15:59:15 | 000,225,138 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\OTL.Txt
[2012.09.20 13:08:15 | 001,678,240 | ---- | M] (Bleeping Computer, LLC) -- C:\Documents and Settings\Lukáš\Plocha\rkill.com
[2012.09.20 13:59:02 | 000,004,022 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\Rkill.txt
[2012.09.19 18:39:36 | 000,002,386 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RKreport[1].txt
[2012.09.19 20:01:24 | 000,002,154 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RKreport[2].txt
[2012.09.19 20:01:38 | 000,002,525 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RKreport[3].txt
[2012.09.19 20:02:06 | 000,001,416 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RKreport[4].txt
[2012.09.19 20:48:49 | 000,001,188 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RKreport[5].txt
[2012.09.19 18:36:00 | 001,382,912 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RogueKiller.exe
[2012.09.18 18:54:06 | 000,781,383 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RSIT.exe
[2011.10.21 20:17:07 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\Tento počítač.lnk
< %userprofile%\Desktop\*.* >
< %ALLUSERSPROFILE%\Plocha\*.* >
[2012.09.18 18:06:23 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[2012.06.07 18:52:42 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Mozilla Firefox.lnk
[2012.09.21 11:02:28 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
< %ALLUSERSPROFILE%\Desktop\*.* >
< *crack* /s >
< *keygen* /s >
< *loader* /s >
[2012.01.02 10:00:38 | 000,002,602 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Babylon\LocalUI\img\controls\b9_preloader.gif
[2011.04.05 13:30:42 | 000,002,602 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Babylon\LocalUI\img-ie6\controls\b9_preloader.gif
[2012.02.29 10:15:20 | 000,072,638 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.gif
[2012.02.29 10:15:20 | 000,003,032 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.png
[2012.07.17 14:18:16 | 000,009,051 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite\MediaInfo\img\loader.gif
[2012.07.17 14:18:16 | 000,016,119 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.jpg
[2012.07.17 14:18:16 | 000,018,434 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.png
[2012.07.17 14:18:16 | 000,009,283 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\ImageInfoLoader.js
[2012.07.17 14:18:16 | 000,001,898 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\NewsLoader.js
[2012.05.30 08:39:56 | 000,010,145 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\conduitCommon\modules\3.13.0.6\ExternalLibraryLoader.jsm
[2012.07.16 23:10:04 | 000,010,145 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\conduitCommon\modules\3.14.1.0\ExternalLibraryLoader.jsm
[2012.08.27 17:55:08 | 000,010,145 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\conduitCommon\modules\3.15.1.0\ExternalLibraryLoader.jsm
[2012.01.11 13:44:22 | 000,010,144 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\conduitCommon\modules\3.9.0.3\ExternalLibraryLoader.jsm
[2012.08.21 14:45:32 | 000,000,847 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome\CT2269050\content\tb\al\ac\img\ajax-loader.gif
[2012.08.21 14:45:32 | 000,001,135 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome\CT2269050\content\tb\al\ac\img\loader-icon.png
[2012.08.21 14:45:32 | 000,003,208 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome\CT2269050\content\tb\al\ui\gf\img\loader.gif
[2012.08.21 14:45:32 | 000,001,849 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome\CT2269050\content\tb\al\wa\TWITTER\resources\ajax-loader.gif
[2012.08.27 17:55:08 | 000,010,145 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\modules\ExternalLibraryLoader.jsm
[2012.09.21 12:58:26 | 000,105,903 | ---- | M] () -- \Documents and Settings\Lukáš\Local Settings\Temporary Internet Files\Content.IE5\IK3P3MDY\AdLoader-427d9fd2a91e2f2c023aefe9f69a01d0.min[1].js
[2012.09.21 12:58:26 | 000,000,753 | ---- | M] () -- \Documents and Settings\Lukáš\Local Settings\Temporary Internet Files\Content.IE5\J7GRF4PI\AdLoader[1].htm
[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.dll
[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.tlb
[2012.02.02 22:50:58 | 000,348,160 | ---- | M] () -- \Program Files\GameSpy Arcade\Services\_common\PortraitLoader.dll
[2011.10.21 18:47:09 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\IMAGES\XtraPreloader\loader.jpg
[2011.10.21 18:47:09 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png
[2011.10.21 18:47:09 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\MUICoreLib\xtraLoader.swf
[2011.10.21 18:49:23 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.6\Xtraz\icq\content\profile_lightboxs\preloader.html
[2012.01.25 14:39:42 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.6\Xtraz\icq\content\rps\preloader02.swf
[2012.01.25 14:38:55 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.6\Xtraz\icq\content\warsheep\preloader02.swf
[2012.01.25 14:37:30 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.6\Xtraz\icq\content\zoopaloola\preloader02.swf
[2009.05.31 04:21:00 | 000,071,008 | ---- | M] () -- \Program Files\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll
[2003.10.14 15:05:18 | 000,004,960 | ---- | M] () -- \Program Files\PopCap Games\Zuma Deluxe\images\LoaderBar.gif
[2003.10.14 15:03:28 | 000,001,064 | ---- | M] () -- \Program Files\PopCap Games\Zuma Deluxe\images\_LoaderBar.gif
[2006.03.02 14:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll
[2004.08.03 22:59:38 | 000,230,400 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\osloader.exe
[2004.08.03 22:59:38 | 000,278,016 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\osloader.ntd
[2002.12.12 01:14:32 | 000,033,280 | ---- | M] () -- \WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmloader.dll
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll
[2008.04.14 00:01:48 | 000,230,912 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe
[2008.04.14 00:01:50 | 000,278,528 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2011.11.22 15:12:58 | 000,012,532 | ---- | M] () -- \WINDOWS\system32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dllcache\dmloader.dll
< *RemoveWAT* /s >
< *minodlogin* /s >
< *tnod* /s >
[2003.04.11 17:13:14 | 000,059,006 | R--- | M] () -- \Program Files\THQ\Hledá se Nemo\resources\universal\TestNode.co2
< *TemDono* /s >
< *AutoKMS* /s >
< *KMSEmulator* /s >
< *activator* /s >
< *serial* /s >
[2004.08.17 15:44:16 | 000,030,301 | ---- | M] () -- \cmdcons\SERIAL.SY_
[2011.03.10 00:43:26 | 000,413,696 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.0.60310.0\System.Runtime.Serialization.dll
[2012.06.09 20:57:42 | 001,186,816 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.0.60310.0\System.Runtime.Serialization.ni.dll
[2010.04.07 23:48:30 | 000,970,752 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2011.05.16 12:22:26 | 000,025,984 | ---- | M] () -- \Program Files\Uniblue\DriverScanner\ds_move_serial.exe
[2004.08.17 15:43:56 | 000,028,416 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\grserial.sys
[2006.03.02 14:00:00 | 000,064,640 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\serial.sys
[2011.10.30 03:03:08 | 000,131,072 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2011.10.29 03:05:30 | 000,970,752 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2011.10.30 03:08:37 | 002,345,472 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\afd6134c090faf8c29cd64d4835142b2\System.Runtime.Serialization.ni.dll
[2008.07.25 11:17:00 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2008.07.25 11:17:00 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\GAC13875\System.Runtime.Serialization.Formatters.Soap.dll
[2010.04.07 23:48:30 | 000,970,752 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2008.04.14 07:47:26 | 000,028,416 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\grserial.sys
[2008.04.14 07:51:10 | 000,064,256 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\serial.sys
[2006.03.02 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dpserial.dll
[2006.03.02 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\serialui.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2006.03.02 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dllcache\dpserial.dll
[2006.03.02 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\dllcache\serialui.dll
[2008.04.14 07:51:10 | 000,064,256 | ---- | M] () -- \WINDOWS\system32\drivers\serial.sys
< *w7lxe* /s >
< *AutoRearm* /s >
< HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /s >
"SoundMAXPnP" = C:\Program Files\Analog Devices\Core\smax4pnp.exe -- [2006.07.20 23:04:38 | 000,847,872 | R--- | M] (Analog Devices, Inc.)
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"DriverScanner" = "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000 -- [2011.05.16 12:22:26 | 000,338,296 | ---- | M] (Uniblue Systems Limited)
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 08:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
< HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run /s >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.09.21 13:55:39 | 000,000,512 | ---- | M] () MD5=ECDA6F11F9ABEE1F861F09B95279AF79 -- C:\PhysicalMBR.bin
========== Files - Unicode (All) ==========
[2012.05.19 22:45:41 | 000,000,000 | ---D | M](C:\Documents and Settings\Luká?\Data aplikací\Xfire) -- C:\Documents and Settings\Luká\Data aplikací\Xfire
[2012.01.14 00:15:28 | 000,000,000 | ---D | M](C:\Documents and Settings\Luká?\Data aplikací\Nokia) -- C:\Documents and Settings\Luká\Data aplikací\Nokia
========== Alternate Data Streams ==========
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
< End of report >
OTL logfile created on: 21.9.2012 13:53:50 - Run 2
OTL by OldTimer - Version 3.2.64.0 Folder = C:\Documents and Settings\Lukáš\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1023,29 Mb Total Physical Memory | 334,02 Mb Available Physical Memory | 32,64% Memory free
2,40 Gb Paging File | 1,81 Gb Available in Paging File | 75,43% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 7,53 Gb Free Space | 38,54% Space Free | Partition Type: NTFS
Drive D: | 129,51 Gb Total Space | 82,40 Gb Free Space | 63,62% Space Free | Partition Type: NTFS
Drive E: | 3,95 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Computer Name: BERKOSI | User Name: Lukáš | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2012.09.19 15:17:09 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
PRC - [2012.09.08 11:39:17 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011.10.25 14:44:42 | 000,793,048 | ---- | M] (PC Tools) -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
PRC - [2011.10.08 06:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011.05.16 12:22:26 | 000,326,504 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\DriverScanner\driverscanner.exe
PRC - [2011.05.16 12:22:26 | 000,025,464 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe
PRC - [2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.11.15 02:59:50 | 002,836,304 | ---- | M] (Xfire Inc.) -- D:\hovno\Xfire\xfire.exe
PRC - [2006.07.13 16:59:48 | 000,131,131 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
PRC - [2006.07.13 16:59:32 | 000,065,599 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
PRC - [2006.04.03 18:04:02 | 000,020,543 | ---- | M] (Apache Software Foundation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
========== Modules (No Company Name) ==========
MOD - [2012.09.08 11:39:15 | 002,244,064 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012.08.15 12:01:39 | 009,465,032 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
MOD - [2011.05.16 12:22:26 | 000,407,400 | ---- | M] () -- C:\Program Files\Uniblue\DriverScanner\locale\br\br.dll
MOD - [2011.05.16 12:22:26 | 000,071,016 | ---- | M] () -- C:\Program Files\Uniblue\DriverScanner\InstallerExtensions.dll
MOD - [2011.05.16 12:22:26 | 000,018,792 | ---- | M] () -- C:\Program Files\Uniblue\DriverScanner\cwebpage.dll
MOD - [2008.04.14 08:51:48 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2006.04.03 18:04:02 | 000,876,544 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\libeay32.dll
MOD - [2006.04.03 18:04:02 | 000,159,744 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\ssleay32.dll
MOD - [2006.04.03 18:04:02 | 000,024,691 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\modules\mod_auth.so
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012.09.08 11:39:16 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2011.10.25 14:44:42 | 000,793,048 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2011.10.08 06:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011.06.08 14:02:00 | 000,633,856 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2006.07.13 16:59:48 | 000,131,131 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe -- (nSvcIp)
SRV - [2006.07.13 16:59:32 | 000,065,599 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe -- (nSvcLog)
SRV - [2006.04.03 18:04:02 | 000,020,543 | ---- | M] (Apache Software Foundation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe -- (ForcewareWebInterface)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2011.12.30 16:07:27 | 000,239,168 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011.08.17 10:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011.08.17 10:56:22 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011.08.17 09:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011.08.17 09:56:26 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2008.08.26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2006.08.14 14:51:28 | 000,105,344 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvata.sys -- (nvata)
DRV - [2006.07.12 07:38:30 | 000,020,480 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006.07.12 07:38:28 | 000,057,856 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006.07.01 22:42:58 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006.03.18 04:18:58 | 000,392,960 | R--- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2005.08.18 00:00:00 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt -- (EverestDriver)
DRV - [2005.08.10 16:06:28 | 000,019,968 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfsync02.sys -- (sfsync02)
DRV - [2005.08.10 14:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfdrv01.sys -- (sfdrv01)
DRV - [2005.05.16 15:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfhlp02.sys -- (sfhlp02)
DRV - [2004.08.13 20:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ie ... earchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" = http://dts.search-results.com/sr?src=ie ... earchTerms}
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.my-tools-app.com/?babsrc= ... earchTerms}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?sr ... 18F38C59DD}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://home.sweetim.com/?st=1&barid={26 ... 18F38C59DD}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes,bProtectorDefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTer ... 18f38c59dd
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?clien ... 0937A611F1
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{399a1442-7377-49e7-8d77-6dc9ed5968c1}: "URL" = http://www.zbozi.cz/?q={searchTerms}&so ... earch_6826
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{5cf5d387-d87c-4408-9a6b-301b0713d62a}: "URL" = http://www.mapy.cz/?query={searchTerms} ... earch_6826
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://search.icq.com/search/results.ph ... &ch_id=osd
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{8172f457-818d-46db-941f-2bbe53e156af}: "URL" = http://www.searchqu.com/web?src=ieb&app ... earchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browse ... earchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ie ... earchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2426}: "URL" = http://dts.search-results.com/sr?src=ie ... earchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.as ... V=IENOSGBR
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.my-tools-app.com/?babsrc= ... earchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{DCDBBF03-BC10-457D-911F-EFB0321D22BE}: "URL" = ${SRCH_SCP_URL}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{eb97f7df-1773-4916-aae6-5af74da8c69d}: "URL" = http://www.firmy.cz/phr/{searchTerms}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?sr ... 18F38C59DD}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/xilisoftdownl ... 6BC0977554}
IE - HKU\S-1-5-21-1935655697-1958367476-682003330-1005\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - No CLSID value found
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaultthis.engineName: "BitTorrentBar Customized Web Search"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.seznam.cz/"
FF - prefs.js..extensions.enabledAddons: 4fbf236e66dfc@4fbf236e66e35.info:1.0
FF - prefs.js..extensions.enabledAddons: 4fd39b2e7d3c3@4fd39b2e7d3fd.info:5.1
FF - prefs.js..extensions.enabledAddons: 4fd3a50b5e081@4fd3a50b5e0b9.info:5.1
FF - prefs.js..extensions.enabledAddons: adapter@babylontc.com:1.0.0.1
FF - prefs.js..extensions.enabledAddons: ffxtlbr@babylon.com:1.1.9
FF - prefs.js..extensions.enabledAddons: ffxtlbra@softonic.com:1.6.0
FF - prefs.js..extensions.enabledAddons: info@bflix.info:5.0
FF - prefs.js..extensions.enabledAddons: info@my-tools-app.com:1.1
FF - prefs.js..extensions.enabledAddons: info@thebflix.com:4.0
FF - prefs.js..extensions.enabledAddons: ocr@babylon.com:1.1
FF - prefs.js..extensions.enabledAddons: plugin@yontoo.com:1.20.00
FF - prefs.js..extensions.enabledAddons: {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:3.15.1.0
FF - prefs.js..extensions.enabledAddons: {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}:2.0
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.as ... ource=2&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.12.23 13:14:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.08 11:39:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012.09.19 11:30:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Extensions
[2012.09.19 11:56:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions
[2012.06.07 16:05:04 | 000,000,000 | ---D | M] (Xilisoft Download Youtube Toolbar) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC}
[2012.08.21 14:37:17 | 000,000,000 | ---D | M] (DVDVideoSoftTB) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012.08.29 14:38:01 | 000,000,000 | ---D | M] (BitTorrentBar Community Toolbar) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2012.06.07 18:54:51 | 000,000,000 | ---D | M] (DealPly) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
[2012.01.07 17:27:59 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2012.06.07 18:54:49 | 000,000,000 | ---D | M] (ADDICT-THING) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\4fbf236e66dfc@4fbf236e66e35.info
[2012.06.09 21:02:16 | 000,000,000 | ---D | M] (TheBflix) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\4fd39b2e7d3c3@4fd39b2e7d3fd.info
[2012.06.09 21:35:34 | 000,000,000 | ---D | M] (TheBflix) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\4fd3a50b5e081@4fd3a50b5e0b9.info
[2012.06.09 21:02:18 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\ffxtlbr@babylon.com
[2012.07.30 09:13:11 | 000,000,000 | ---D | M] (softonic.com) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\ffxtlbra@softonic.com
[2012.06.07 18:54:50 | 000,000,000 | ---D | M] (TheBflix) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\info@bflix.info
[2012.06.07 18:54:50 | 000,000,000 | ---D | M] (MyTools extension) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\info@my-tools-app.com
[2012.06.07 18:54:51 | 000,000,000 | ---D | M] (Bflix) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\info@thebflix.com
[2012.07.30 08:00:05 | 000,000,000 | ---D | M] (Yontoo) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\plugin@yontoo.com
[2012.06.07 19:08:42 | 000,000,000 | ---D | M] (Yandex.Bar) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\yasearch@yandex.ru
[2012.06.09 21:02:16 | 000,021,707 | ---- | M] () (No name found) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\adapter@babylontc.com.xpi
[2012.06.09 21:02:18 | 000,011,148 | ---- | M] () (No name found) -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\ocr@babylon.com.xpi
[2012.06.07 16:53:36 | 000,002,324 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\askcom.xml
[2012.05.30 08:39:58 | 000,000,929 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\conduit.xml
[2012.07.07 14:18:31 | 000,009,633 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\my-web-search.xml
[2012.02.10 12:58:43 | 000,000,544 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\MyTools.xml
[2012.08.23 13:06:27 | 000,002,519 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\Search_Results.xml
[2012.07.30 07:58:44 | 000,002,062 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\softonic.xml
[2012.03.18 13:57:55 | 000,003,974 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\searchplugins\sweetim.xml
[2012.09.19 11:56:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.06.09 20:52:46 | 000,000,000 | ---D | M] (GameTap) -- C:\Program Files\Mozilla Firefox\extensions\GameTapPlayer@gametap.com
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\4FBF236E66DFC@4FBF236E66E35.INFO
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\4FD39B2E7D3C3@4FD39B2E7D3FD.INFO
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\4FD3A50B5E081@4FD3A50B5E0B9.INFO
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\ADAPTER@BABYLONTC.COM.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\FFXTLBR@BABYLON.COM
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\FFXTLBRA@SOFTONIC.COM
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\INFO@BFLIX.INFO
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\INFO@MY-TOOLS-APP.COM
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\INFO@THEBFLIX.COM
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\OCR@BABYLON.COM.XPI
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\LUKáš\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\ITHPSUV9.DEFAULT\EXTENSIONS\PLUGIN@YONTOO.COM
[2012.09.08 11:39:17 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.08.21 11:09:00 | 000,002,349 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2012.08.31 10:41:02 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2012.08.31 10:41:02 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2012.08.23 13:06:27 | 000,002,519 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2012.08.31 10:41:02 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2012.08.31 10:41:02 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2012.08.31 10:41:02 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2012.09.20 16:51:52 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (no name) - !!{98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\..\Toolbar\WebBrowser: (no name) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - No CLSID value found.
O4 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004..\Run: [DriverScanner] C:\Program Files\Uniblue\DriverScanner\launcher.exe (Uniblue Systems Limited)
O4 - HKU\S-1-5-21-1935655697-1958367476-682003330-1005..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe File not found
O4 - Startup: C:\Documents and Settings\Lukáš\Nabídka Start\Programy\Po spuštění\Xfire.lnk = D:\hovno\Xfire\xfire.exe (Xfire Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1935655697-1958367476-682003330-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} Reg Error: Key error. (GameTap Player)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{322D9B46-694A-4DBB-97DC-616396B5B612}: NameServer = 85.93.160.254,85.93.160.118
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011.10.18 09:38:40 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004.11.18 22:59:22 | 000,000,000 | R--D | M] - E:\AutoRun -- [ UDF ]
O32 - AutoRun File - [2004.11.18 22:25:54 | 000,684,032 | R--- | M] (Electronic Arts Inc.) - E:\AutoRun.exe -- [ UDF ]
O32 - AutoRun File - [2004.11.18 22:58:27 | 000,000,103 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2004.11.14 16:08:54 | 000,929,792 | R--- | M] (Electronic Arts Inc.) - E:\AutoRunGUI.dll -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2012.09.20 20:24:38 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Lukáš\Recent
[2012.09.20 20:24:38 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012.09.20 17:56:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lukáš\Data aplikací\Malwarebytes
[2012.09.20 17:56:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2012.09.20 17:54:51 | 010,524,080 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Lukáš\Plocha\mbam-setup-1.65.0.1400.exe
[2012.09.20 16:54:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012.09.20 13:21:14 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012.09.20 13:19:55 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012.09.20 13:19:55 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012.09.20 13:19:55 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012.09.20 13:19:55 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012.09.20 13:19:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.09.20 13:19:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2012.09.20 13:09:55 | 004,753,679 | R--- | C] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\ComboFix.exe
[2012.09.20 13:08:46 | 001,678,240 | ---- | C] (Bleeping Computer, LLC) -- C:\Documents and Settings\Lukáš\Plocha\rkill.com
[2012.09.20 11:40:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Lukáš\Nabídka Start\Programy\Nástroje pro správu
[2012.09.20 11:40:38 | 000,492,146 | R--- | C] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\dds.exe
[2012.09.19 18:38:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lukáš\Plocha\RK_Quarantine
[2012.09.19 15:17:42 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
[2012.09.19 12:18:52 | 003,178,400 | ---- | C] (McAfee, Inc.) -- C:\Documents and Settings\Lukáš\Plocha\MCPR.exe
[2012.09.19 11:09:42 | 000,245,760 | ---- | C] (Ask.com) -- C:\Program Files\Uninstall Ask Toolbar.dll
[2012.09.18 19:34:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Trymedia
[2012.09.18 18:54:27 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.09.18 18:54:26 | 000,000,000 | ---D | C] -- C:\rsit
[2012.09.18 18:06:21 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.09.15 16:33:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lukáš\Dokumenty\LOTR The Return of the King (tm) Data
[2012.09.15 12:02:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lukáš\Data aplikací\My Battle for Middle-earth Files
[2012.09.15 12:01:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\EA GAMES
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 7 Days ==========
[2012.09.21 13:55:39 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.09.21 13:01:15 | 000,000,914 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012.09.21 11:02:28 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2012.09.21 10:21:24 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\DriverScanner.job
[2012.09.21 10:21:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.09.20 18:58:23 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Lukáš.job
[2012.09.20 17:54:39 | 010,524,080 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Lukáš\Plocha\mbam-setup-1.65.0.1400.exe
[2012.09.20 16:51:52 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012.09.20 16:44:17 | 004,753,679 | R--- | M] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\ComboFix.exe
[2012.09.20 13:21:16 | 000,000,339 | RHS- | M] () -- C:\boot.ini
[2012.09.20 13:08:15 | 001,678,240 | ---- | M] (Bleeping Computer, LLC) -- C:\Documents and Settings\Lukáš\Plocha\rkill.com
[2012.09.20 11:40:32 | 000,492,146 | R--- | M] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\dds.exe
[2012.09.20 09:27:17 | 000,002,504 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012.09.19 18:36:00 | 001,382,912 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RogueKiller.exe
[2012.09.19 15:17:09 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
[2012.09.19 12:18:42 | 003,178,400 | ---- | M] (McAfee, Inc.) -- C:\Documents and Settings\Lukáš\Plocha\MCPR.exe
[2012.09.18 19:35:47 | 000,000,010 | ---- | M] () -- C:\WINDOWS\popcinfo.dat
[2012.09.18 18:54:06 | 000,781,383 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RSIT.exe
[2012.09.18 18:42:23 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.09.18 18:06:23 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.09.20 13:21:16 | 000,000,223 | ---- | C] () -- C:\Boot.bak
[2012.09.20 13:21:15 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2012.09.20 13:19:55 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012.09.20 13:19:55 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012.09.20 13:19:55 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012.09.20 13:19:55 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012.09.20 13:19:55 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012.09.19 18:38:32 | 001,382,912 | ---- | C] () -- C:\Documents and Settings\Lukáš\Plocha\RogueKiller.exe
[2012.09.19 15:24:22 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.09.19 11:33:09 | 000,172,464 | ---- | C] () -- C:\Program Files\4zres.dll
[2012.09.19 11:29:26 | 000,172,440 | ---- | C] () -- C:\Program Files\4wres.dll
[2012.09.18 18:54:16 | 000,781,383 | ---- | C] () -- C:\Documents and Settings\Lukáš\Plocha\RSIT.exe
[2012.09.18 18:06:23 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[2012.07.03 21:42:40 | 000,159,552 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2012.07.02 22:28:33 | 000,000,268 | ---- | C] () -- C:\WINDOWS\game.ini
[2012.04.09 09:53:54 | 000,000,105 | ---- | C] () -- C:\WINDOWS\KA.ini
[2012.04.07 13:40:07 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\74e69b9a20b79bcd8ad1e149f6c34ba4_c
[2012.03.27 09:07:57 | 000,000,010 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2012.01.28 17:32:20 | 000,000,176 | ---- | C] () -- C:\WINDOWS\disneysy.ini
[2012.01.21 10:22:15 | 000,000,204 | ---- | C] () -- C:\WINDOWS\RomeTW Demo.ini
[2011.12.31 12:34:39 | 000,292,700 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011.12.31 12:34:39 | 000,292,700 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011.12.31 12:34:39 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011.12.31 12:33:57 | 002,783,770 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2011.12.23 16:07:27 | 000,037,336 | ---- | C] () -- C:\WINDOWS\System32\CleanMFT32.exe
[2011.12.05 16:54:53 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2011.11.11 09:20:25 | 000,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011.11.11 09:20:25 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Lukáš\Data aplikací\PnkBstrK.sys
[2011.11.11 09:20:02 | 000,103,736 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2011.11.11 09:19:58 | 000,066,872 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2011.11.11 09:19:57 | 002,434,856 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_bc2.exe
[2011.11.02 07:33:29 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2011.10.24 18:34:01 | 000,000,157 | ---- | C] () -- C:\Documents and Settings\Lukáš\default.pls
[2011.10.23 12:19:28 | 000,001,211 | ---- | C] () -- C:\WINDOWS\disney.ini
[2011.10.22 11:46:05 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011.10.22 10:24:36 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2011.10.21 21:24:13 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2011.10.21 21:24:07 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\Lukáš\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.10.18 20:19:24 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.10.18 17:29:12 | 000,017,722 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2011.10.18 17:28:03 | 000,017,470 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2011.10.18 17:28:01 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2011.10.18 17:27:50 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2011.10.18 10:30:13 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011.10.18 10:29:01 | 000,272,576 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011.10.18 09:40:55 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011.10.18 09:35:55 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
========== ZeroAccess Check ==========
[2011.10.26 09:22:02 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
========== LOP Check ==========
[2012.02.09 12:01:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\100
[2012.08.08 19:14:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ADDICT-THING
[2011.10.21 20:02:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3
[2011.10.22 11:07:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3 XPack Trial
[2011.10.22 10:27:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Age of Empires 3 YPack Trial
[2012.06.07 16:52:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ask
[2012.09.20 09:27:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2012.08.21 11:08:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Babylon
[2012.09.20 19:06:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\BasicScan
[2012.08.23 23:41:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\boost_interprocess
[2011.10.31 08:20:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2012.07.03 21:46:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\EA Core
[2012.07.04 23:50:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
[2012.06.09 20:53:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\GameTap Web Player
[2012.09.20 19:06:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IBUpdaterService
[2011.10.21 18:49:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2012.01.14 00:07:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Installations
[2012.07.30 11:53:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\InstallMate
[2011.12.30 15:20:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IObit
[2012.07.05 21:41:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\KONAMI
[2012.01.14 11:08:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\NokiaInstallerCache
[2012.06.09 21:34:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\OptimizerPro
[2011.12.30 16:38:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Origin
[2012.01.14 00:14:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2012.01.07 10:14:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Premium
[2012.07.30 07:59:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Tarma Installer
[2012.01.05 10:11:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2012.06.09 21:34:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TheBflixUpdater
[2012.04.11 13:44:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Vivendi Universal Games
[2011.10.26 10:40:28 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\{1B0B54CA-AA7D-41D3-A84A-29E7C9CB13A2}
[2012.06.09 21:04:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Babylon
[2012.09.18 18:10:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\BitTorrent
[2012.09.18 18:10:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite
[2011.12.23 13:20:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DDMSettings
[2011.10.23 12:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Disney Interactive
[2012.06.07 08:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DVDVideoSoft
[2012.06.07 08:29:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DVDVideoSoftIEHelpers
[2012.05.26 08:40:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\GetRightToGo
[2012.09.20 14:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ICQ
[2011.12.30 15:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\IObit
[2011.10.26 10:15:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Leadertech
[2012.02.26 21:54:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mount&Blade Warband
[2012.09.15 12:32:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\My Battle for Middle-earth Files
[2012.01.14 11:05:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Nokia
[2012.06.07 16:53:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\OpenCandy
[2012.05.25 17:25:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Optimizer Pro
[2011.12.30 16:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Origin
[2012.01.14 11:06:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PC Suite
[2012.09.20 10:00:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PerformerSoft
[2012.09.19 11:14:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PriceGong
[2012.04.11 17:58:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\searchcoreband
[2011.12.06 20:55:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\searchquband
[2012.02.10 13:22:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\TeamViewer
[2012.06.07 16:05:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4
[2012.09.18 18:46:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Uniblue
[2012.06.07 16:06:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Xilisoft
[2012.09.19 11:54:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Yandex
========== Purity Check ==========
========== Custom Scans ==========
< netsvc >
[2011.10.18 09:36:40 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2011.10.18 09:42:05 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2011.10.22 01:53:10 | 000,000,440 | -H-- | C] () -- C:\WINDOWS\Tasks\Norton Security Scan for Lukáš.job
[2012.02.09 11:56:17 | 000,000,260 | ---- | C] () -- C:\WINDOWS\Tasks\DriverScanner.job
[2012.06.28 09:49:57 | 000,000,914 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
< MD5 for: ATAPI.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\erdnt\cache\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2006.03.02 14:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2006.03.02 14:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe
< MD5 for: CDROM.SYS >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2006.03.02 14:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\erdnt\cache\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2006.03.02 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: HAL.DLL >
[2006.03.02 14:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:hal.dll
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.14 00:01:30 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\HAL.DLL
[2008.04.14 00:01:34 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2006.03.02 14:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
< MD5 for: SCECLI.DLL >
[2006.03.02 14:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\erdnt\cache\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SVCHOST.EXE >
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\erdnt\cache\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2006.03.02 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB2509553$\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\erdnt\cache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2006.03.02 14:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\erdnt\cache\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2006.03.02 14:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: WINLOGON.EXE >
[2006.03.02 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\erdnt\cache\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< %systemroot%*.* /U /s >
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[83 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2011.10.22 11:47:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Adobe
[2011.10.22 11:48:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\AdobeUM
[2011.12.30 15:49:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Ahead
[2012.06.09 21:04:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Babylon
[2012.09.18 18:10:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\BitTorrent
[2012.09.18 18:10:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite
[2011.12.23 13:20:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DDMSettings
[2011.10.23 12:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Disney Interactive
[2011.11.23 18:41:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DivX
[2012.06.07 08:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DVDVideoSoft
[2012.06.07 08:29:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\DVDVideoSoftIEHelpers
[2012.05.26 08:40:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\GetRightToGo
[2012.09.20 14:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\ICQ
[2011.10.18 09:43:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Identities
[2012.01.07 14:58:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\InstallShield
[2011.12.30 15:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\IObit
[2011.10.26 10:15:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Leadertech
[2011.10.18 20:18:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Macromedia
[2012.09.20 17:56:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Malwarebytes
[2012.06.10 14:04:49 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Microsoft
[2012.02.26 21:54:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mount&Blade Warband
[2011.12.06 23:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Mozilla
[2012.09.15 12:32:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\My Battle for Middle-earth Files
[2012.01.14 11:05:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Nokia
[2012.08.05 22:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\NVIDIA
[2012.06.07 16:53:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\OpenCandy
[2012.05.25 17:25:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Optimizer Pro
[2011.12.30 16:36:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Origin
[2012.01.14 11:06:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PC Suite
[2012.09.20 10:00:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PerformerSoft
[2012.09.19 11:14:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\PriceGong
[2012.04.11 17:58:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\searchcoreband
[2011.12.06 20:55:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\searchquband
[2012.09.21 13:50:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Skype
[2012.02.10 13:22:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\TeamViewer
[2012.06.07 16:05:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4
[2012.09.18 18:46:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Uniblue
[2012.08.29 13:05:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\vlc
[2012.01.21 14:45:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\WinRAR
[2012.05.05 21:53:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Xfire
[2012.06.07 16:06:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Xilisoft
[2012.09.19 11:54:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lukáš\Data aplikací\Yandex
< %APPDATA%\*.exe /s >
[2012.04.20 19:08:46 | 005,837,432 | ---- | M] (Uniblue Systems Ltd ) -- C:\Documents and Settings\Lukáš\Data aplikací\OpenCandy\0386E49A0A4A4BB9A564C114184CD54F\speedupmypcROW.exe
[2011.06.09 21:03:56 | 005,845,528 | ---- | M] (Uniblue Systems Ltd ) -- C:\Documents and Settings\Lukáš\Data aplikací\OpenCandy\E3BD74482391407C99EE97C4B9B5E1EB\driverscanner (33).exe
[2010.02.16 11:57:38 | 000,197,632 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\TbHelper2.exe
[2009.11.25 11:12:00 | 000,042,496 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\uninstall.exe
[2012.06.07 16:05:04 | 000,059,188 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\UninstallToolbar.exe
[2009.11.25 11:12:00 | 000,056,832 | ---- | M] () -- C:\Documents and Settings\Lukáš\Data aplikací\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\update.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job >
[2012.09.21 13:01:15 | 000,000,914 | ---- | M] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012.09.21 10:21:24 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\DriverScanner.job
[2012.09.20 18:58:23 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\Tasks\Norton Security Scan for Lukáš.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2011.10.18 10:28:18 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2011.10.18 10:28:18 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2011.10.18 10:28:18 | 000,466,944 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2012.09.20 09:27:17 | 000,002,504 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT
[2012.09.21 10:21:36 | 000,000,000 | ---- | M] () -- C:\WINDOWS\system32\nmp.log
[2012.09.18 18:42:23 | 000,013,646 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %userprofile%\Plocha\*.* >
[2012.01.07 23:50:04 | 000,001,823 | -H-- | M] () -- C:\Documents and Settings\Lukáš\Plocha\Age of Empires III - The Asian Dynasties.lnk
[2012.01.07 23:42:49 | 000,001,816 | -H-- | M] () -- C:\Documents and Settings\Lukáš\Plocha\Age of Empires III.lnk
[2012.09.20 16:44:17 | 004,753,679 | R--- | M] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\ComboFix.exe
[2012.09.20 16:54:49 | 000,012,418 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\ComboFix.txt
[2012.09.20 11:40:32 | 000,492,146 | R--- | M] (Swearware) -- C:\Documents and Settings\Lukáš\Plocha\dds.exe
[2012.09.20 11:41:21 | 000,010,680 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\dds.txt
[2012.09.19 15:59:37 | 000,048,628 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\Extras.Txt
[2012.02.25 14:55:32 | 000,000,609 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\GameSpy Arcade.lnk
[2012.09.20 18:36:36 | 000,025,804 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\mbam-log-2012-09-20 (18-36-24).txt
[2012.09.20 17:54:39 | 010,524,080 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Lukáš\Plocha\mbam-setup-1.65.0.1400.exe
[2012.09.19 12:18:42 | 003,178,400 | ---- | M] (McAfee, Inc.) -- C:\Documents and Settings\Lukáš\Plocha\MCPR.exe
[2012.09.19 15:17:09 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lukáš\Plocha\OTL.exe
[2012.09.19 15:59:15 | 000,225,138 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\OTL.Txt
[2012.09.20 13:08:15 | 001,678,240 | ---- | M] (Bleeping Computer, LLC) -- C:\Documents and Settings\Lukáš\Plocha\rkill.com
[2012.09.20 13:59:02 | 000,004,022 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\Rkill.txt
[2012.09.19 18:39:36 | 000,002,386 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RKreport[1].txt
[2012.09.19 20:01:24 | 000,002,154 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RKreport[2].txt
[2012.09.19 20:01:38 | 000,002,525 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RKreport[3].txt
[2012.09.19 20:02:06 | 000,001,416 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RKreport[4].txt
[2012.09.19 20:48:49 | 000,001,188 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RKreport[5].txt
[2012.09.19 18:36:00 | 001,382,912 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RogueKiller.exe
[2012.09.18 18:54:06 | 000,781,383 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\RSIT.exe
[2011.10.21 20:17:07 | 000,000,104 | ---- | M] () -- C:\Documents and Settings\Lukáš\Plocha\Tento počítač.lnk
< %userprofile%\Desktop\*.* >
< %ALLUSERSPROFILE%\Plocha\*.* >
[2012.09.18 18:06:23 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
[2012.06.07 18:52:42 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Mozilla Firefox.lnk
[2012.09.21 11:02:28 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
< %ALLUSERSPROFILE%\Desktop\*.* >
< *crack* /s >
< *keygen* /s >
< *loader* /s >
[2012.01.02 10:00:38 | 000,002,602 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Babylon\LocalUI\img\controls\b9_preloader.gif
[2011.04.05 13:30:42 | 000,002,602 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Babylon\LocalUI\img-ie6\controls\b9_preloader.gif
[2012.02.29 10:15:20 | 000,072,638 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.gif
[2012.02.29 10:15:20 | 000,003,032 | ---- | M] () -- \Documents and Settings\All Users\Data aplikací\Skype\Apps\login\images\loader.png
[2012.07.17 14:18:16 | 000,009,051 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite\MediaInfo\img\loader.gif
[2012.07.17 14:18:16 | 000,016,119 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.jpg
[2012.07.17 14:18:16 | 000,018,434 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite\MediaInfo\img\logo_loader_page.png
[2012.07.17 14:18:16 | 000,009,283 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\ImageInfoLoader.js
[2012.07.17 14:18:16 | 000,001,898 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\DAEMON Tools Lite\MediaInfo\js\app\MediaInfo\NewsLoader.js
[2012.05.30 08:39:56 | 000,010,145 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\conduitCommon\modules\3.13.0.6\ExternalLibraryLoader.jsm
[2012.07.16 23:10:04 | 000,010,145 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\conduitCommon\modules\3.14.1.0\ExternalLibraryLoader.jsm
[2012.08.27 17:55:08 | 000,010,145 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\conduitCommon\modules\3.15.1.0\ExternalLibraryLoader.jsm
[2012.01.11 13:44:22 | 000,010,144 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\conduitCommon\modules\3.9.0.3\ExternalLibraryLoader.jsm
[2012.08.21 14:45:32 | 000,000,847 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome\CT2269050\content\tb\al\ac\img\ajax-loader.gif
[2012.08.21 14:45:32 | 000,001,135 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome\CT2269050\content\tb\al\ac\img\loader-icon.png
[2012.08.21 14:45:32 | 000,003,208 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome\CT2269050\content\tb\al\ui\gf\img\loader.gif
[2012.08.21 14:45:32 | 000,001,849 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome\CT2269050\content\tb\al\wa\TWITTER\resources\ajax-loader.gif
[2012.08.27 17:55:08 | 000,010,145 | ---- | M] () -- \Documents and Settings\Lukáš\Data aplikací\Mozilla\Firefox\Profiles\ithpsuv9.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\modules\ExternalLibraryLoader.jsm
[2012.09.21 12:58:26 | 000,105,903 | ---- | M] () -- \Documents and Settings\Lukáš\Local Settings\Temporary Internet Files\Content.IE5\IK3P3MDY\AdLoader-427d9fd2a91e2f2c023aefe9f69a01d0.min[1].js
[2012.09.21 12:58:26 | 000,000,753 | ---- | M] () -- \Documents and Settings\Lukáš\Local Settings\Temporary Internet Files\Content.IE5\J7GRF4PI\AdLoader[1].htm
[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.dll
[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VS7DEBUG\coloader.tlb
[2012.02.02 22:50:58 | 000,348,160 | ---- | M] () -- \Program Files\GameSpy Arcade\Services\_common\PortraitLoader.dll
[2011.10.21 18:47:09 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\IMAGES\XtraPreloader\loader.jpg
[2011.10.21 18:47:09 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png
[2011.10.21 18:47:09 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.6\imApp\theme\MUICoreLib\xtraLoader.swf
[2011.10.21 18:49:23 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.6\Xtraz\icq\content\profile_lightboxs\preloader.html
[2012.01.25 14:39:42 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.6\Xtraz\icq\content\rps\preloader02.swf
[2012.01.25 14:38:55 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.6\Xtraz\icq\content\warsheep\preloader02.swf
[2012.01.25 14:37:30 | 000,003,830 | ---- | M] () -- \Program Files\ICQ7.6\Xtraz\icq\content\zoopaloola\preloader02.swf
[2009.05.31 04:21:00 | 000,071,008 | ---- | M] () -- \Program Files\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll
[2003.10.14 15:05:18 | 000,004,960 | ---- | M] () -- \Program Files\PopCap Games\Zuma Deluxe\images\LoaderBar.gif
[2003.10.14 15:03:28 | 000,001,064 | ---- | M] () -- \Program Files\PopCap Games\Zuma Deluxe\images\_LoaderBar.gif
[2006.03.02 14:00:00 | 000,035,840 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\dmloader.dll
[2004.08.03 22:59:38 | 000,230,400 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\osloader.exe
[2004.08.03 22:59:38 | 000,278,016 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\osloader.ntd
[2002.12.12 01:14:32 | 000,033,280 | ---- | M] () -- \WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmloader.dll
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\dmloader.dll
[2008.04.14 00:01:48 | 000,230,912 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.exe
[2008.04.14 00:01:50 | 000,278,528 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\osloader.ntd
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2011.11.22 15:12:58 | 000,012,532 | ---- | M] () -- \WINDOWS\system32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2008.04.14 08:51:40 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dllcache\dmloader.dll
< *RemoveWAT* /s >
< *minodlogin* /s >
< *tnod* /s >
[2003.04.11 17:13:14 | 000,059,006 | R--- | M] () -- \Program Files\THQ\Hledá se Nemo\resources\universal\TestNode.co2
< *TemDono* /s >
< *AutoKMS* /s >
< *KMSEmulator* /s >
< *activator* /s >
< *serial* /s >
[2004.08.17 15:44:16 | 000,030,301 | ---- | M] () -- \cmdcons\SERIAL.SY_
[2011.03.10 00:43:26 | 000,413,696 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.0.60310.0\System.Runtime.Serialization.dll
[2012.06.09 20:57:42 | 001,186,816 | ---- | M] () -- \Program Files\Microsoft Silverlight\4.0.60310.0\System.Runtime.Serialization.ni.dll
[2010.04.07 23:48:30 | 000,970,752 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2011.05.16 12:22:26 | 000,025,984 | ---- | M] () -- \Program Files\Uniblue\DriverScanner\ds_move_serial.exe
[2004.08.17 15:43:56 | 000,028,416 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\grserial.sys
[2006.03.02 14:00:00 | 000,064,640 | ---- | M] () -- \WINDOWS\$NtServicePackUninstall$\serial.sys
[2011.10.30 03:03:08 | 000,131,072 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2011.10.29 03:05:30 | 000,970,752 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2011.10.30 03:08:37 | 002,345,472 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\afd6134c090faf8c29cd64d4835142b2\System.Runtime.Serialization.ni.dll
[2008.07.25 11:17:00 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2008.07.25 11:17:00 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\GAC13875\System.Runtime.Serialization.Formatters.Soap.dll
[2010.04.07 23:48:30 | 000,970,752 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2008.04.14 07:47:26 | 000,028,416 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\grserial.sys
[2008.04.14 07:51:10 | 000,064,256 | ---- | M] () -- \WINDOWS\ServicePackFiles\i386\serial.sys
[2006.03.02 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dpserial.dll
[2006.03.02 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\serialui.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2006.03.02 14:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dllcache\dpserial.dll
[2006.03.02 14:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\dllcache\serialui.dll
[2008.04.14 07:51:10 | 000,064,256 | ---- | M] () -- \WINDOWS\system32\drivers\serial.sys
< *w7lxe* /s >
< *AutoRearm* /s >
< HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /s >
"SoundMAXPnP" = C:\Program Files\Analog Devices\Core\smax4pnp.exe -- [2006.07.20 23:04:38 | 000,847,872 | R--- | M] (Analog Devices, Inc.)
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"DriverScanner" = "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000 -- [2011.05.16 12:22:26 | 000,338,296 | ---- | M] (Uniblue Systems Limited)
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 08:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
< HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run /s >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.09.21 13:55:39 | 000,000,512 | ---- | M] () MD5=ECDA6F11F9ABEE1F861F09B95279AF79 -- C:\PhysicalMBR.bin
========== Files - Unicode (All) ==========
[2012.05.19 22:45:41 | 000,000,000 | ---D | M](C:\Documents and Settings\Luká?\Data aplikací\Xfire) -- C:\Documents and Settings\Luká\Data aplikací\Xfire
[2012.01.14 00:15:28 | 000,000,000 | ---D | M](C:\Documents and Settings\Luká?\Data aplikací\Nokia) -- C:\Documents and Settings\Luká\Data aplikací\Nokia
========== Alternate Data Streams ==========
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
< End of report >