a zde OTL...
OTL logfile created on: 22.2.2010 20:04:11 - Run 1
OTL by OldTimer - Version 3.1.30.1 Folder = c:\Programy\Antivir
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 64,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): E:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97,65 Gb Total Space | 70,26 Gb Free Space | 71,95% Space Free | Partition Type: NTFS
Drive D: | 200,43 Gb Total Space | 80,59 Gb Free Space | 40,21% Space Free | Partition Type: NTFS
Drive E: | 111,79 Gb Total Space | 12,59 Gb Free Space | 11,26% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SPACESTAR
Current User Name: Radim
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.02.22 19:57:01 | 000,549,376 | ---- | M] (OldTimer Tools) -- c:\Programy\Antivir\OTL.exe
PRC - [2010.01.08 00:51:02 | 000,380,928 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe
PRC - [2009.11.14 18:00:31 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009.06.01 21:20:12 | 000,222,968 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2009.01.16 17:35:32 | 000,090,112 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
PRC - [2009.01.12 14:04:00 | 002,908,160 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files\WinFast\WFDTV\WFWIZ.exe
PRC - [2008.09.27 17:52:00 | 000,162,304 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2008.09.23 17:59:00 | 000,109,056 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.09.14 06:02:10 | 001,080,264 | ---- | M] (C. Ghisler & Co.) -- C:\totalcmd\TOTALCMD.EXE
PRC - [2006.02.28 11:42:38 | 000,229,376 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2004.12.13 04:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
========== Modules (SafeList) ==========
MOD - [2010.02.22 19:57:01 | 000,549,376 | ---- | M] (OldTimer Tools) -- c:\Programy\Antivir\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - [2010.01.08 00:51:02 | 000,380,928 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2009.11.14 18:00:31 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2009.06.01 21:20:12 | 000,222,968 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.03.04 10:25:12 | 000,621,056 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008.09.24 04:49:20 | 000,055,816 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\GIGABYTE\GEST\GSvr.exe -- (GEST Service)
SRV - [2008.09.23 17:59:00 | 000,109,056 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2008.09.19 17:26:12 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008.05.02 01:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2007.12.05 00:41:00 | 000,155,716 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
SRV - [2007.05.11 01:09:48 | 001,050,120 | ---- | M] (O&O Software GmbH) [Disabled | Stopped] -- C:\WINDOWS\system32\oodag.exe -- (O&O Defrag)
SRV - [2006.10.30 02:34:02 | 000,122,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2006.02.28 11:42:38 | 000,229,376 | ---- | M] (Apple Computer, Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2004.12.13 04:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
SRV - [2003.07.28 19:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - [2010.02.20 14:45:45 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2010.02.07 19:19:56 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008.12.25 01:56:42 | 000,433,792 | R--- | M] (Leadtek Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wfeaglxt.sys -- (WFLR6654) WinFast DTV1800 H (XC4000)
DRV - [2008.09.24 04:47:38 | 000,030,008 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ET5Drv.sys -- (ET5Drv)
DRV - [2008.09.19 02:09:17 | 000,020,747 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP) AEGIS Protocol (IEEE 802.1x)
DRV - [2008.05.15 11:07:00 | 000,061,424 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- c:\Program Files\CyberLink\PowerDVD8\000.fcl -- ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054})
DRV - [2008.04.14 00:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE)
DRV - [2008.04.14 00:15:38 | 000,026,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser.sys -- (usbser)
DRV - [2008.04.13 23:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) Ovladač zvukové karty USB (WDM)
DRV - [2008.04.13 21:06:06 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008.02.29 02:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2008.02.29 02:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2008.02.29 02:12:48 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2008.02.14 10:04:06 | 004,676,096 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008.01.03 15:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007.12.05 00:41:00 | 007,435,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006.09.01 11:32:50 | 000,003,712 | ---- | M] (Logitech Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LBeepKE.sys -- (LBeepKE)
DRV - [2004.12.23 17:27:56 | 000,027,392 | ---- | M] (Ulead Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ULCDRHlp.sys -- (ULCDRHlp)
DRV - [2004.12.20 19:37:14 | 000,020,016 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\PxHelp20.sys -- (PxHelp20)
DRV - [2001.10.25 15:00:00 | 000,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.aukro.cz/
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\S-1-5-21-1645522239-2139871995-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\S-1-5-21-1645522239-2139871995-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://novinky.cz/"
FF - prefs.js..extensions.enabledItems:
DTToolbar@toolbarnet.com:1.1.1.0014
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.1.13
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.4.1
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..keyword.URL: "
http://search.icq.com/search/afe_result ... id=afex&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.02.19 16:36:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.02.19 16:36:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009.08.22 12:41:25 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2008.09.19 01:53:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Extensions
[2010.02.21 23:22:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\extensions
[2010.02.10 12:42:02 | 000,000,000 | ---D | M] (FlashGot) -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2010.02.07 19:20:18 | 000,002,055 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\daemon-search.xml
[2010.02.19 08:31:10 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-1.xml
[2009.08.09 07:38:38 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-10.xml
[2009.09.16 17:43:52 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-11.xml
[2009.10.28 19:16:23 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-12.xml
[2009.12.16 13:04:05 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-13.xml
[2010.01.06 16:03:53 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-14.xml
[2010.01.15 22:02:48 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-15.xml
[2008.12.20 09:04:20 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-2.xml
[2009.02.04 20:38:43 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-3.xml
[2009.03.05 17:58:52 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-4.xml
[2009.03.28 11:19:21 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-5.xml
[2009.04.23 22:44:01 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-6.xml
[2009.04.28 21:18:57 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-7.xml
[2009.06.13 11:48:36 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-8.xml
[2009.07.23 21:34:10 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-9.xml
[2008.03.31 08:52:00 | 000,000,168 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin.gif
[2008.03.31 08:52:00 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin.src
[2009.06.07 13:21:06 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin.xml
[2010.02.21 13:26:22 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.06.20 08:01:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.02.19 16:36:54 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.02.19 16:36:54 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.02.19 16:36:54 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.02.19 16:36:54 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.02.19 16:36:54 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2010.02.19 08:44:33 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Podpora odkazu pro Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe (Leadtek Research Inc.)
O4 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe (Leadtek Research Inc.)
O4 - Startup: C:\Documents and Settings\Radim\Nabídka Start\Programy\Po spuštění\SystemExplorerDisabled [2008.12.04 17:21:41 | 000,000,000 | -H-D | M]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = [binary data]
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
https://download.macromedia.com/pub/sho ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/ ... mvadvd.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
http://icq.oberon-media.com/Gameshell/G ... meHost.cab (Oberon Flash Game Host)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\OrCAD\ORCAD_~1.0_D\tools\Capture\itss.dll File not found
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\OrCAD\ORCAD_~1.0_D\tools\Capture\itss.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.09.19 01:41:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O Software GmbH)
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008.09.19 03:26:42 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55172488459452416)
========== Files/Folders - Created Within 30 Days ==========
[2010.02.22 14:44:44 | 000,000,000 | ---D | C] -- C:\Program Files\HD Tune
[2010.02.22 14:33:01 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Radim\Recent
[2010.02.21 23:42:39 | 000,433,792 | R--- | C] (Leadtek Research Inc.) -- C:\WINDOWS\System32\drivers\wfeaglxt.sys
[2010.02.21 14:56:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\DoctorWeb
[2010.02.19 21:18:04 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2010.02.19 16:56:40 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.02.19 09:34:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\Local Settings\Data aplikací\FreeFixer
[2010.02.19 09:34:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\Data aplikací\FreeFixer
[2010.02.19 08:39:53 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010.02.18 14:44:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\Data aplikací\Malwarebytes
[2010.02.18 14:43:56 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.02.18 14:43:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.02.17 23:21:37 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.02.17 23:18:38 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.02.17 23:18:37 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.02.17 23:18:37 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.02.17 23:18:37 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.02.17 23:18:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.02.17 23:14:34 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.02.07 19:20:18 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar
[2010.02.07 19:19:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\Data aplikací\DAEMON Tools Lite
[2010.02.07 19:18:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.01.30 13:24:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\Data aplikací\Mikrotik
[2008.09.19 01:44:29 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2008.09.19 01:44:16 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2008.09.19 01:44:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2008.09.18 21:08:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[13 C:\Documents and Settings\All Users\Data aplikací\*.tmp files -> C:\Documents and Settings\All Users\Data aplikací\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.02.22 19:22:45 | 000,003,396 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.02.22 18:32:28 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\Radim\ntuser.dat
[2010.02.22 18:32:28 | 000,000,002 | ---- | M] () -- C:\WINDOWS\System32\Dvbpws.dll
[2010.02.22 18:01:08 | 000,000,192 | ---- | M] () -- C:\WINDOWS\winamp.ini
[2010.02.22 17:59:08 | 000,051,472 | ---- | M] () -- C:\Documents and Settings\Radim\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2010.02.22 17:00:33 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.02.22 14:44:44 | 000,000,622 | ---- | M] () -- C:\Documents and Settings\Radim\Plocha\HD Tune.lnk
[2010.02.22 14:38:37 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.02.22 14:38:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.02.22 14:38:28 | 001,135,253 | ---- | M] () -- C:\WINDOWS\System32\oodbs.lor
[2010.02.22 14:33:01 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\Radim\ntuser.ini
[2010.02.22 13:51:25 | 001,518,360 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.02.22 13:47:37 | 000,000,143 | ---- | M] () -- C:\Documents and Settings\Radim\Plocha\DrWeb.csv
[2010.02.22 05:21:58 | 000,018,432 | ---- | M] () -- C:\Documents and Settings\Radim\Plocha\DrWeb1.xls
[2010.02.22 05:20:52 | 000,000,284 | ---- | M] () -- C:\Documents and Settings\Radim\Plocha\DrWeb1.csv
[2010.02.22 00:01:07 | 000,001,433 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\WinFast PVR2.lnk
[2010.02.21 21:40:45 | 000,000,158 | ---- | M] () -- C:\WINDOWS\matlab.ini
[2010.02.21 14:48:36 | 000,002,504 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010.02.21 12:49:03 | 000,002,275 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.02.20 14:45:45 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\gdrv.sys
[2010.02.19 22:48:10 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.02.19 18:09:35 | 000,000,390 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2010.02.19 08:44:33 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.02.18 14:58:19 | 000,000,012 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\cqfyto.dat
[2010.02.18 13:56:11 | 003,861,435 | R--- | M] () -- C:\Documents and Settings\Radim\Plocha\ComboFix.exe
[2010.02.17 23:21:40 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.02.09 15:46:45 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.02.07 19:19:56 | 000,691,696 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[13 C:\Documents and Settings\All Users\Data aplikací\*.tmp files -> C:\Documents and Settings\All Users\Data aplikací\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.02.22 14:44:44 | 000,000,622 | ---- | C] () -- C:\Documents and Settings\Radim\Plocha\HD Tune.lnk
[2010.02.22 05:21:58 | 000,018,432 | ---- | C] () -- C:\Documents and Settings\Radim\Plocha\DrWeb1.xls
[2010.02.22 05:20:52 | 000,000,284 | ---- | C] () -- C:\Documents and Settings\Radim\Plocha\DrWeb1.csv
[2010.02.22 00:01:07 | 000,001,433 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\WinFast PVR2.lnk
[2010.02.21 20:53:04 | 000,000,143 | ---- | C] () -- C:\Documents and Settings\Radim\Plocha\DrWeb.csv
[2010.02.19 22:47:46 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\Dvbpws.dll
[2010.02.18 14:58:19 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\Radim\Data aplikací\cqfyto.dat
[2010.02.17 23:21:40 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.02.17 23:21:38 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.02.17 23:18:38 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.02.17 23:18:38 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.02.17 23:18:37 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.02.17 23:18:37 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.02.17 23:18:37 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.02.17 23:14:19 | 003,861,435 | R--- | C] () -- C:\Documents and Settings\Radim\Plocha\ComboFix.exe
[2010.02.17 19:04:12 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\NetworkService\Data aplikací\cqfyto.dat
[2009.12.21 17:49:32 | 000,000,030 | ---- | C] () -- C:\WINDOWS\pslabeler3.ini
[2009.12.21 16:00:32 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
[2009.08.22 13:09:36 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\SYNSOACC.dll
[2009.08.22 13:09:30 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\bgspmnt.dll
[2009.08.22 13:09:20 | 000,000,571 | ---- | C] () -- C:\WINDOWS\System32\FeMakro.ini
[2009.08.22 13:09:20 | 000,000,497 | ---- | C] () -- C:\WINDOWS\System32\FeAnim.ini
[2009.04.01 13:54:23 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2009.02.27 15:12:23 | 000,000,158 | ---- | C] () -- C:\WINDOWS\matlab.ini
[2008.12.02 23:01:27 | 000,000,192 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2008.10.13 18:11:56 | 000,000,146 | ---- | C] () -- C:\WINDOWS\capture.INI
[2008.10.13 17:45:42 | 000,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfpct60n.dll
[2008.10.13 17:45:41 | 000,903,168 | ---- | C] () -- C:\WINDOWS\System32\mitmdl30.dll
[2008.10.13 17:45:41 | 000,251,904 | ---- | C] () -- C:\WINDOWS\System32\orant71.dll
[2008.10.13 17:45:41 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\lffax60n.dll
[2008.10.13 17:45:41 | 000,141,824 | ---- | C] () -- C:\WINDOWS\System32\lfcmp60n.dll
[2008.10.13 17:45:41 | 000,110,080 | ---- | C] () -- C:\WINDOWS\System32\lfpng60n.dll
[2008.10.13 17:45:41 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\lftif60n.dll
[2008.10.13 17:45:41 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\lfpcx60n.dll
[2008.10.13 17:45:41 | 000,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfeps60n.dll
[2008.10.13 17:45:41 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\lfbmp60n.dll
[2008.10.13 17:45:41 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\lfpsd60n.dll
[2008.10.13 17:45:41 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\lftga60n.dll
[2008.10.13 17:45:41 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwpg60n.dll
[2008.10.13 17:45:41 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwmf60n.dll
[2008.10.13 17:45:41 | 000,018,432 | ---- | C] () -- C:\WINDOWS\System32\lfmsp60n.dll
[2008.10.13 17:45:41 | 000,017,920 | ---- | C] () -- C:\WINDOWS\System32\lfmac60n.dll
[2008.10.13 17:43:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SPLASH.INI
[2008.09.21 18:20:30 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS6s.DLL
[2008.09.21 18:18:05 | 000,000,532 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008.09.19 22:28:27 | 000,000,293 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.09.19 17:52:15 | 000,003,396 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2008.09.19 17:18:40 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008.09.19 02:09:33 | 000,290,918 | ---- | C] () -- C:\WINDOWS\System32\Install7x.dll
[2008.09.19 01:58:49 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008.09.19 01:58:48 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2008.09.19 01:58:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oodcnt.INI
[2008.09.19 01:56:20 | 000,064,200 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2008.09.18 22:52:31 | 000,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys
[2008.09.18 22:01:12 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.09.18 21:26:35 | 000,009,728 | ---- | C] () -- C:\Documents and Settings\Radim\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.09.18 20:55:12 | 000,000,510 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.12.05 00:41:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007.12.05 00:41:00 | 001,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007.12.05 00:41:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007.12.05 00:41:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007.12.05 00:41:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2003.04.09 14:38:04 | 000,005,664 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002.03.21 14:39:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\UNACEV2.DLL
========== LOP Check ==========
[2008.09.21 13:32:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ACD Systems
[2009.12.21 15:18:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2009.12.24 09:25:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonIJScan
[2010.02.07 19:19:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.06.20 08:01:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2009.04.29 15:04:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Installations
[2009.03.11 14:43:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2009.05.26 18:26:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ScanSoft
[2008.09.21 18:18:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SSScanAppDataDir
[2008.09.21 18:18:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SSScanWizard
[2010.02.20 14:43:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SystemExplorer
[2009.11.27 15:07:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2008.12.04 17:24:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2008.09.21 11:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\ACD Systems
[2008.11.12 21:49:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\CadSoft
[2009.12.24 09:25:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Canon
[2010.02.07 19:31:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\DAEMON Tools Lite
[2010.02.02 16:16:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\FileZilla
[2010.02.19 09:34:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\FreeFixer
[2010.02.21 12:55:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\ICQ
[2009.11.27 15:07:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\langmaster.sz
[2008.09.18 20:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\MetaProducts
[2010.01.30 13:24:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Mikrotik
[2009.06.29 16:07:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Nokia
[2009.09.12 09:04:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\PC Suite
[2010.01.15 20:57:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\pdfforge
[2009.08.22 13:09:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\pdfMachine
[2008.11.17 17:24:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\ProfiCAD
[2008.09.21 18:18:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\ScanSoft
[2010.01.15 20:57:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Search Settings
[2008.09.25 20:24:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Thunderbird
[2008.12.04 17:24:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\TuneUp Software
[2010.02.19 18:09:35 | 000,000,390 | ---- | M] () -- C:\WINDOWS\Tasks\1-Click Maintenance.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
[2004.08.17 14:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2004.08.17 14:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2004.08.17 14:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
< %SYSTEMDRIVE%\sceclt.dll /s /md5 >
< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >
< %SYSTEMDRIVE%\logevent.dll /s /md5 >
< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >
< %SYSTEMDRIVE%\viasraid.sys /s /md5 >
< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >
< %SYSTEMDRIVE%\viamraid.sys /s /md5 >
< %SYSTEMDRIVE%\nvata.sys /s /md5 >
< %SYSTEMROOT%\*. /mp /s >
< %SYSTEMROOT%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMROOT%\Tasks\*.job /lockedfiles >
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0230417D
< End of report >