Já si log, pro lepší orientaci, rozdělím do více příspěvků.
OTL logfile created on: 15.5.2010 9:47:28 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\install
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 66,00% Memory free
12,00 Gb Paging File | 11,00 Gb Available in Paging File | 93,00% Paging File free
Paging file location(s): C:\pagefile.sys 10000 100000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 174,30 Gb Free Space | 74,85% Space Free | Partition Type: NTFS
Drive D: | 465,76 Gb Total Space | 51,25 Gb Free Space | 11,00% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 698,46 Gb Total Space | 365,31 Gb Free Space | 52,30% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive P: | 273,44 Gb Total Space | 249,66 Gb Free Space | 91,31% Space Free | Partition Type: NTFS
Drive Q: | 273,44 Gb Total Space | 249,66 Gb Free Space | 91,31% Space Free | Partition Type: NTFS
Drive R: | 273,44 Gb Total Space | 249,66 Gb Free Space | 91,31% Space Free | Partition Type: NTFS
Computer Name: PC01
Current User Name: karnik
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.05.15 09:45:54 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\install\OTL.exe
PRC - [2010.04.16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010.03.26 19:39:36 | 002,477,304 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
PRC - [2010.03.26 19:39:36 | 001,864,888 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
PRC - [2010.03.26 19:39:36 | 001,455,432 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
PRC - [2010.03.26 19:39:36 | 000,115,560 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2010.03.26 19:39:36 | 000,108,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2009.08.07 15:32:48 | 000,863,232 | ---- | M] (IVT Corporation) -- C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
PRC - [2009.08.07 15:12:46 | 000,315,478 | ---- | M] (IVT Corporation) -- C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe
PRC - [2009.08.07 15:10:46 | 000,102,503 | ---- | M] (IVT Corporation) -- C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe
PRC - [2009.08.07 15:09:26 | 000,143,467 | ---- | M] (IVT Corporation) -- C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe
PRC - [2008.11.24 23:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2008.11.24 23:31:08 | 000,239,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PRC - [2008.05.26 23:19:14 | 000,123,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PRC - [2008.04.28 06:14:00 | 000,073,728 | ---- | M] (Software 2000 Limited) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE
PRC - [2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008.04.10 20:07:20 | 000,413,696 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2008.04.01 15:43:23 | 000,098,304 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe
PRC - [2008.04.01 15:42:01 | 000,020,572 | ---- | M] () -- C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
PRC - [2008.01.16 00:54:54 | 000,037,376 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
PRC - [2006.07.08 01:14:38 | 000,576,320 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliType Pro\itype.exe
PRC - [2006.05.12 16:04:08 | 000,439,248 | ---- | M] (RealVNC Ltd.) -- C:\Program Files\RealVNC\VNC4\winvnc4.exe
PRC - [2003.12.05 15:41:44 | 000,049,152 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
PRC - [2003.10.03 19:52:50 | 000,061,440 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
PRC - [2002.12.17 17:26:22 | 007,520,337 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL$SPZSQL2006\Binn\sqlservr.exe
PRC - [1999.03.24 17:57:10 | 000,043,520 | ---- | M] () -- C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
========== Modules (SafeList) ==========
MOD - [2010.05.15 09:45:54 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\install\OTL.exe
MOD - [2008.04.14 05:19:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2006.05.12 16:04:10 | 000,043,488 | ---- | M] (RealVNC Ltd.) -- C:\Program Files\RealVNC\VNC4\wm_hooks.dll
========== Win32 Services (SafeList) ==========
SRV - [2010.04.16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010.03.26 19:39:36 | 002,477,304 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2010.03.26 19:39:36 | 001,864,888 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService)
SRV - [2010.03.26 19:39:36 | 000,341,320 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC)
SRV - [2010.03.26 19:39:36 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2010.03.26 19:39:36 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2009.10.27 10:26:36 | 000,657,408 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009.08.18 19:21:43 | 003,093,880 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2009.08.07 15:32:48 | 000,863,232 | ---- | M] (IVT Corporation) [Auto | Running] -- C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe -- (BlueSoleilCS)
SRV - [2009.08.07 15:10:46 | 000,102,503 | ---- | M] (IVT Corporation) [On_Demand | Running] -- C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe -- (BsHelpCS)
SRV - [2009.08.07 15:09:26 | 000,143,467 | ---- | M] (IVT Corporation) [Auto | Running] -- C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe -- (BsMobileCS)
SRV - [2009.05.27 03:27:04 | 029,262,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$SONY_MEDIAMGR2) SQL Server (SONY_MEDIAMGR2)
SRV - [2008.11.24 23:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2008.11.24 23:31:08 | 000,239,968 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser)
SRV - [2008.11.24 23:31:08 | 000,045,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper)
SRV - [2008.07.29 19:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008.04.10 20:08:44 | 000,212,992 | ---- | M] (IDT, Inc.) [Auto | Stopped] -- C:\WINDOWS\system32\stacsv.exe -- (STacSV)
SRV - [2006.05.12 16:04:08 | 000,439,248 | ---- | M] (RealVNC Ltd.) [Auto | Running] -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe -- (WinVNC4)
SRV - [2003.10.22 18:19:22 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\hpzipm12.exe -- (Pml Driver HPZ12)
SRV - [2002.12.17 17:26:22 | 007,520,337 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft SQL Server\MSSQL$SPZSQL2006\Binn\sqlservr.exe -- (MSSQL$SPZSQL2006)
SRV - [2002.12.17 17:23:30 | 000,311,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft SQL Server\MSSQL$SPZSQL2006\Binn\sqlagent.EXE -- (SQLAgent$SPZSQL2006)
========== Driver Services (SafeList) ==========
DRV - [2010.05.11 08:13:15 | 001,347,504 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100514.023\NAVEX15.SYS -- (NAVEX15)
DRV - [2010.05.11 08:13:15 | 000,085,552 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100514.023\NAVENG.SYS -- (NAVENG)
DRV - [2010.04.04 00:55:31 | 010,232,128 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2010.03.26 19:59:30 | 000,162,048 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wpshelper.sys -- (WpsHelper)
DRV - [2010.03.26 19:42:32 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2010.03.26 19:39:37 | 000,042,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\WPSDRVnt.sys -- (WPS)
DRV - [2010.03.26 19:39:36 | 000,421,424 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2010.03.26 19:39:36 | 000,320,560 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2010.03.26 19:39:36 | 000,281,648 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)
DRV - [2010.03.26 19:39:36 | 000,188,080 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2010.03.26 19:39:36 | 000,092,488 | ---- | M] (Symantec Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys -- (SysPlant)
DRV - [2010.03.26 19:39:36 | 000,050,064 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Teefer2.sys -- (Teefer2)
DRV - [2010.03.26 19:39:36 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2010.03.26 19:39:36 | 000,026,416 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2010.03.26 19:39:36 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon)
DRV - [2009.08.27 10:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2009.08.27 10:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2009.07.16 14:48:17 | 000,229,208 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\VMM.sys -- (vmm)
DRV - [2009.07.08 10:17:36 | 000,039,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2009.06.17 14:02:46 | 000,029,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btnetBus.sys -- (btnetBUs)
DRV - [2009.06.17 14:02:16 | 000,027,528 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2009.06.17 14:02:08 | 000,033,800 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2009.06.17 14:01:50 | 000,014,088 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btnetdrv.sys -- (BT)
DRV - [2009.06.17 14:01:42 | 000,025,480 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV - [2009.06.17 14:01:36 | 000,020,744 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BtHidBus.sys -- (BtHidBus)
DRV - [2009.06.17 14:01:10 | 000,032,392 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)
DRV - [2009.06.17 14:01:04 | 000,014,856 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)
DRV - [2009.06.05 11:42:28 | 000,017,408 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\netaapl.sys -- (Netaapl)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.04.13 20:46:20 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\61883.sys -- (61883)
DRV - [2008.04.13 20:46:20 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avc.sys -- (Avc)
DRV - [2008.04.13 20:46:09 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msdv.sys -- (MSDV)
DRV - [2008.04.13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008.04.10 20:10:10 | 001,271,032 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2007.01.31 15:33:46 | 000,005,632 | ---- | M] (GRISOFT, s.r.o.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\avgarkt.sys -- (AVG Anti-Rootkit)
DRV - [2007.01.31 14:25:46 | 000,246,680 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1e5132.sys -- (e1express) Intel(R)
DRV - [2007.01.31 14:23:53 | 000,041,728 | ---- | M] (Sonic Focus, Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sfng32.sys -- (sfng32)
DRV - [2007.01.29 07:20:34 | 000,059,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VMNetSrv.sys -- (VPCNetS2)
DRV - [2007.01.18 14:00:28 | 000,003,968 | ---- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AvgArCln.sys -- (AvgArCln)
DRV - [2005.11.21 07:48:20 | 000,016,512 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
DRV - [2005.01.28 15:36:00 | 000,171,008 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2004.03.10 17:27:18 | 000,011,264 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\asapiW2k.sys -- (ASAPIW2k)
DRV - [2002.03.19 10:29:16 | 000,014,165 | ---- | M] (Pinnacle Systems GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Pclepci.sys -- (PCLEPCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.cz/
IE - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "
http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems:
bkmrksync@nokia.com:1.0.0.723
FF - HKLM\software\mozilla\Firefox\Extensions\\
bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010.01.19 11:09:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.20 08:52:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.05.10 08:32:43 | 000,000,000 | ---D | M]
[2010.03.26 18:31:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Mozilla\Extensions
[2010.03.26 18:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Mozilla\Firefox\Profiles\fzaj81g2.default\extensions
[2010.03.26 18:31:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\karnik.EKG\Data aplikací\Mozilla\Firefox\Profiles\fzaj81g2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.03.26 18:31:48 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\karnik.EKG\Data aplikací\Mozilla\Firefox\Profiles\fzaj81g2.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010.03.30 11:04:37 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008.05.12 09:10:21 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008.03.24 20:21:00 | 002,889,088 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
O1 HOSTS File: ([2008.08.18 10:05:11 | 000,259,265 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 192.168.8.1 eshop..cz
O1 - Hosts: 127.0.0.1
http://www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1
http://www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1
http://www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1
http://www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
http://www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1
http://www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1
http://www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1
http://www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1
http://www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1
http://www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1
http://www.136136.net
O1 - Hosts: 9008 more lines...
O2 - BHO: (Winamp Toolbar BHO) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [BtTray] C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe (IVT Corporation)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe (Hewlett-Packard)
O4 - HKLM..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe ()
O4 - HKLM..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe (Hewlett-Packard)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-3320928065-3168867863-2979219259-1144\..Trusted Domains: ekgfoto.cz ([remote] HTTPS in Místní intranet)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}
http://download.microsoft.com/download/ ... ontrol.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}
http://www.nvidia.com/content/DriverDow ... ab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microso ... 2241351078 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}
http://download.mcafee.com/molbin/iss-l ... cfscan.cab (McFreeScan Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.8.1 192.168.8.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ekg.local
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\WINDOWS\system32\skype4com.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (rundll32.exe) - File not found
O20 - HKLM Winlogon: Shell - (ngts.vao) - File not found
O20 - HKLM Winlogon: Shell - (uvibls) - File not found
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.02.05 21:01:22 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008.02.05 21:47:38 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: VIDC.MJPG - C:\WINDOWS\System32\pvmjpg21.dll (Pegasus Imaging Corporation)
Drivers32: VIDC.PIM1 - C:\WINDOWS\System32\pclepim1.dll (Pinnacle Systems)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (32383177238511616)
========== Files/Folders - Created Within 30 Days ==========
[2010.05.13 20:56:24 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.05.13 20:56:24 | 000,000,000 | ---D | C] -- C:\rsit
[2010.05.11 21:22:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\McAfee.com
[2010.05.11 18:27:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\NVIDIA Corporation
[2010.05.11 18:26:54 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2010.05.11 18:26:12 | 002,646,632 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcuvenc.dll
[2010.05.11 18:26:12 | 002,030,184 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcuvid.dll
[2010.05.11 18:26:12 | 000,061,440 | ---- | C] (Khronos Group) -- C:\WINDOWS\System32\OpenCL.dll
[2010.05.11 18:26:10 | 011,647,592 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvcompiler.dll
[2010.05.11 18:26:04 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2010.05.11 18:10:03 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab
[2010.05.11 18:07:02 | 000,000,000 | ---D | C] -- C:\AVGTemp
[2010.05.10 09:11:28 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.05.07 15:06:11 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.05.07 15:06:11 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.05.07 15:06:11 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.05.07 15:06:11 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.05.07 15:04:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.05.07 15:04:57 | 000,390,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF24674.exe
[2010.05.07 15:04:38 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.05.05 22:55:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\karnik.EKG\Dokumenty\register
[2010.05.05 21:34:07 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010.05.05 21:32:03 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010.05.05 21:30:12 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010.05.05 20:17:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2010.04.20 08:54:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010.04.20 08:44:54 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
[2004.12.13 09:57:36 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\RCCOLLAB.DLL
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.05.15 09:42:04 | 000,004,559 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.05.15 09:36:32 | 000,003,800 | ---- | M] () -- C:\CEZ-UZIV.OPT
[2010.05.15 09:36:10 | 000,000,620 | ---- | M] () -- C:\CEZ-WIN.OPT
[2010.05.15 09:34:07 | 000,276,202 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010.05.15 09:33:56 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.05.15 09:10:10 | 000,009,409 | ---- | M] () -- C:\WINDOWS\System32\LOCALSERVICE.INI
[2010.05.15 09:10:06 | 000,001,168 | ---- | M] () -- C:\WINDOWS\System32\bscs.ini
[2010.05.15 09:09:58 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.05.15 09:09:53 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.05.14 20:03:27 | 006,815,744 | -H-- | M] () -- C:\Documents and Settings\karnik.EKG\NTUSER.DAT
[2010.05.14 20:03:27 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\karnik.EKG\ntuser.ini
[2010.05.14 19:54:07 | 000,121,812 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Plocha\Nissin.doc
[2010.05.14 19:53:35 | 000,002,563 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Plocha\Microsoft Office Word 2007.lnk
[2010.05.14 19:28:05 | 000,002,477 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Plocha\Microsoft Office Excel 2007.lnk
[2010.05.14 10:03:02 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\iTunes.lnk
[2010.05.13 20:39:40 | 000,000,435 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.05.13 18:37:21 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.05.13 17:04:32 | 000,856,064 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Plocha\Cezar.doc
[2010.05.13 16:11:13 | 019,348,480 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Plocha\Prezentace_NIKON_KALENDAR.ppt
[2010.05.13 15:57:45 | 000,001,564 | ---- | M] () -- C:\LAST-DIR.OPT
[2010.05.13 11:13:00 | 000,052,208 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Plocha\EKG_backorder.xls
[2010.05.12 08:14:53 | 000,098,096 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2010.05.11 18:41:18 | 000,010,234 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Dokumenty\test psao.docx
[2010.05.11 18:30:30 | 000,391,528 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.05.11 18:19:08 | 000,002,829 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Plocha\EKG s.r.o..pif
[2010.05.10 08:32:44 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Adobe Reader 9.lnk
[2010.05.07 15:04:35 | 000,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF24674.exe
[2010.05.06 15:37:44 | 000,002,481 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Plocha\Microsoft Office PowerPoint 2007.lnk
[2010.05.05 21:37:11 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\QuickTime Player.lnk
[2010.05.05 21:16:35 | 000,000,633 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.05.05 21:16:35 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2010.05.05 08:45:09 | 008,317,851 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Plocha\obr1.eps
[2010.05.04 09:58:00 | 000,035,840 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Plocha\Se stativem na cestách.doc
[2010.04.29 18:01:57 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Plocha\SORTIMENTY_10_X_09_.xls
[2010.04.26 15:58:12 | 000,256,512 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2010.04.23 12:09:01 | 000,025,088 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Dokumenty\HD.doc
[2010.04.20 08:59:57 | 000,002,187 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Safari.lnk
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.05.14 08:57:19 | 000,121,812 | ---- | C] () -- C:\Documents and Settings\karnik.EKG\Plocha\Nissin.doc
[2010.05.13 17:04:32 | 000,856,064 | ---- | C] () -- C:\Documents and Settings\karnik.EKG\Plocha\Cezar.doc
[2010.05.13 16:11:13 | 019,348,480 | ---- | C] () -- C:\Documents and Settings\karnik.EKG\Plocha\Prezentace_NIKON_KALENDAR.ppt
[2010.05.13 11:13:00 | 000,052,208 | ---- | C] () -- C:\Documents and Settings\karnik.EKG\Plocha\EKG_backorder.xls
[2010.05.11 18:41:17 | 000,010,234 | ---- | C] () -- C:\Documents and Settings\karnik.EKG\Dokumenty\test psao.docx
[2010.05.11 18:26:12 | 000,009,046 | ---- | C] () -- C:\WINDOWS\System32\nvinfo.pb
[2010.05.11 18:26:10 | 002,183,470 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010.05.07 15:06:11 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.05.07 15:06:11 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.05.07 15:06:11 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.05.07 15:06:11 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.05.07 15:06:11 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.05.05 21:34:53 | 000,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\iTunes.lnk
[2010.05.05 08:45:06 | 008,317,851 | ---- | C] () -- C:\Documents and Settings\karnik.EKG\Plocha\obr1.eps
[2010.05.04 09:15:54 | 000,035,840 | ---- | C] () -- C:\Documents and Settings\karnik.EKG\Plocha\Se stativem na cestách.doc
[2010.04.27 09:54:36 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\karnik.EKG\Plocha\SORTIMENTY_10_X_09_.xls
[2010.04.23 12:09:00 | 000,025,088 | ---- | C] () -- C:\Documents and Settings\karnik.EKG\Dokumenty\HD.doc
[2010.04.20 08:52:01 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\QuickTime Player.lnk
[2010.04.20 08:45:00 | 000,002,187 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Safari.lnk
[2009.09.17 12:45:59 | 000,002,488 | ---- | C] () -- C:\WINDOWS\System32\SHORTCUT.INI
[2009.09.17 12:45:26 | 000,000,269 | ---- | C] () -- C:\WINDOWS\System32\REMOTEDEVICE.INI
[2009.09.17 12:43:26 | 000,009,409 | ---- | C] () -- C:\WINDOWS\System32\LOCALSERVICE.INI
[2009.09.17 12:43:00 | 000,000,096 | ---- | C] () -- C:\WINDOWS\System32\LOCALDEVICE.INI
[2009.09.17 12:40:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\BSPRINT.INI
[2009.08.07 15:32:52 | 000,001,168 | ---- | C] () -- C:\WINDOWS\System32\bscs.ini
[2009.08.07 15:09:30 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\BsMobileCSps.dll
[2009.06.17 14:02:46 | 000,029,192 | ---- | C] () -- C:\WINDOWS\System32\drivers\btnetBus.sys
[2009.06.11 13:08:27 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\HPPLVS.dll
[2009.01.19 12:45:46 | 000,198,144 | ---- | C] () -- C:\WINDOWS\System32\_psisdecd.dll
[2008.10.14 19:18:57 | 002,392,064 | ---- | C] () -- C:\WINDOWS\System32\videotrans.dll
[2008.10.14 19:18:57 | 000,215,040 | ---- | C] () -- C:\WINDOWS\System32\videoformat.dll
[2008.10.14 19:18:57 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\imgscaler.dll
[2008.10.14 19:18:57 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\img_utils.dll
[2008.10.14 19:18:57 | 000,017,920 | ---- | C] () -- C:\WINDOWS\System32\videocore.dll
[2008.10.14 19:18:54 | 000,217,088 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008.10.14 19:18:54 | 000,128,512 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2008.05.26 23:22:14 | 000,015,552 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2008.05.26 23:22:10 | 000,021,464 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2008.05.26 23:22:04 | 000,014,910 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2008.04.01 15:42:38 | 000,074,752 | ---- | C] () -- C:\WINDOWS\System32\jst.dll
[2008.04.01 15:42:38 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\PMLJNI.dll
[2008.04.01 15:40:35 | 000,008,104 | ---- | C] () -- C:\WINDOWS\hplj3380.ini
[2008.04.01 15:40:10 | 000,000,375 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2008.04.01 15:39:07 | 000,001,376 | ---- | C] () -- C:\WINDOWS\hpbvnstp.ini
[2008.04.01 15:38:57 | 000,221,184 | R--- | C] () -- C:\WINDOWS\System32\HP3AIOZ6.dll
[2008.03.05 17:41:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2008.03.01 19:30:56 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.02.20 12:25:58 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\Msvcrt10.dll
[2008.02.20 12:25:55 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\PdfPorts.dll
[2008.02.17 14:14:24 | 000,000,017 | ---- | C] () -- C:\WINDOWS\MovingPicture.ini
[2008.02.07 10:05:18 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\hppatusg01.dll
[2008.02.07 07:47:57 | 000,000,301 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.02.07 07:46:52 | 000,004,559 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2007.12.05 02:41:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007.03.05 14:34:28 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007.03.01 11:17:48 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2007.03.01 11:17:48 | 000,880,640 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2007.03.01 11:17:48 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2007.03.01 11:16:58 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\tvqenc.dll
[2004.08.17 16:49:10 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2004.08.17 16:49:10 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2004.08.17 16:49:10 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2004.08.17 16:49:10 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2004.08.17 16:49:10 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
[2004.03.18 09:44:29 | 001,663,068 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2003.09.26 14:42:46 | 000,002,421 | ---- | C] () -- C:\WINDOWS\System32\scrubber.ini
[2002.05.03 23:40:32 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
[2001.10.24 12:48:28 | 000,000,033 | ---- | C] () -- C:\WINDOWS\hppcap.ini
========== LOP Check ==========
[2010.03.26 17:39:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.PC01\Data aplikací\Windows Desktop Search
[2009.12.30 10:23:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Bluetooth
[2010.01.19 11:04:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Installations
[2008.02.22 11:00:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2008.02.07 18:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Pinnacle
[2008.06.05 17:32:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SmartSound Software Inc
[2008.07.14 15:34:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Sony
[2010.04.21 09:28:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.04.20 08:55:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009.09.29 09:38:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.06.09 08:36:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008.03.01 17:37:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik\Data aplikací\Canon
[2008.02.29 19:03:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik\Data aplikací\Leadertech
[2008.02.28 15:59:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik\Data aplikací\Nokia
[2008.02.22 11:00:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik\Data aplikací\PC Suite
[2009.01.26 19:51:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik\Data aplikací\Publish Providers
[2008.10.10 15:44:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik\Data aplikací\Sony
[2008.12.26 12:48:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik\Data aplikací\Windows Desktop Search
[2009.01.19 17:25:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik\Data aplikací\Windows Search
[2010.04.08 18:14:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Canon
[2010.03.26 20:34:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\EPSON
[2010.03.26 18:32:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\PC Suite
[2010.04.01 12:45:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Publish Providers
[2010.04.01 12:45:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Sony
[2010.03.26 17:46:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Windows Desktop Search
[2010.04.07 11:48:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Windows Search
[2010.03.26 17:44:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Windows Small Business Server
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"QuickTime Task" = "C:\Program Files\QuickTime\QTTask.exe" -atboottime -- [2010.03.17 21:53:36 | 000,421,888 | ---- | M] (Apple Inc.)
"ctfmon.exe" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 05:22:17 | 000,015,360 | ---- | M] (Microsoft Corporation)
< c:\windows\*.* /U >
[5 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.05.06 16:10:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Adobe
[2010.04.20 08:59:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Apple Computer
[2010.04.08 18:14:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Canon
[2010.04.08 16:02:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\CyberLink
[2010.04.21 08:52:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\dvdcss
[2010.03.26 20:34:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\EPSON
[2010.03.26 18:07:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Google
[2010.03.26 17:45:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Identities
[2010.04.12 12:51:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Macromedia
[2010.05.11 18:09:03 | 000,000,000 | --SD | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Microsoft
[2010.03.26 18:31:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Mozilla
[2010.03.26 18:32:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\PC Suite
[2010.04.01 12:45:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Publish Providers
[2010.04.01 12:45:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Sony
[2010.03.30 11:03:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Sun
[2010.04.09 21:05:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Winamp
[2010.03.26 17:46:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Windows Desktop Search
[2010.04.07 11:48:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Windows Search
[2010.03.26 17:44:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\Windows Small Business Server
[2010.04.07 14:51:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\karnik.EKG\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
[2010.02.01 03:45:40 | 000,038,784 | ---- | M] () -- C:\Documents and Settings\karnik.EKG\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe