Díky za snahu!
Ještě popíšu situaci. Zkoušel jsem Win7 s uživatelským účtem, tj. bez admin práv a co je podstatné - firewall pouze od MS, antivir žádný! Je to testovací instalace, zda to jde bez Antiviru utáhnout a evidentně nelze.
Následně nainstalován Avast 5, Spybot, AdAware - full scan nic, esen online scan taky nic. Že jsem nakažen poznám podle toho, že Avast zařve ve chvíli, kdy mi to automaticky začne nahrávat stránku (tohle je ona: hxxp://www3.coantys-46td.xorg.pl/?p=p52dcWpnaV%2FRlsijZFaZp29plGOIpKTSasiVyWWYaZqal5Ru ).
Řeším tedy hlavně to, jak to, že to nic nezachytí a stejně se to projevuje. Snad se bude někomu hodit (já provedu přinejhorším reinstall systému). Ve Firefoxu se to spustí, i když jsem jen na stránce google.com a pravednes.cz (proskenovano pomocí AVG link scanner), doplnky mám jen Tab Mix Plus a AdBlock).
A tady jsou výpisy:
OTL logfile created on: 22.5.2010 20:00:00 - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Jerry\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 024,00 Mb Total Physical Memory | 182,00 Mb Available Physical Memory | 18,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 32,00% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74,43 Gb Total Space | 2,73 Gb Free Space | 3,67% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1,93 Gb Total Space | 0,01 Gb Free Space | 0,30% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 14,89 Gb Total Space | 13,12 Gb Free Space | 88,11% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Computer Name: JAREK-PC
Current User Name: Jarek
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.05.22 19:57:47 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Users\Jerry\Downloads\OTL.exe
PRC - [2010.05.22 17:52:55 | 010,196,424 | ---- | M] (Microsoft Corporation) -- C:\Users\Jerry\Downloads\windows-kb890830-v3.7.exe
PRC - [2010.05.22 17:10:16 | 000,840,416 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010.05.22 17:10:15 | 001,314,704 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010.05.19 22:36:00 | 000,811,590 | ---- | M] ( ) -- C:\Users\Jerry\Desktop\Miranda SG4 Black Edition\miranda32.exe
PRC - [2010.05.15 17:30:08 | 000,322,352 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2010.05.11 03:48:16 | 021,105,544 | ---- | M] () -- C:\Users\Jerry\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2010.05.06 22:59:42 | 002,815,192 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010.05.06 22:59:38 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010.04.30 11:51:06 | 000,058,312 | ---- | M] (Microsoft Corporation) -- c:\46bd6d0f38b4933c38eedc5be78950\mrtstub.exe
PRC - [2010.04.01 19:59:58 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009.10.31 07:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.09.09 07:50:00 | 003,514,112 | ---- | M] (Ghisler Software GmbH) -- C:\totalcmd\TOTALCMD.EXE
PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.06.17 13:44:11 | 000,085,160 | ---- | M] (Elaborate Bytes AG) -- C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
========== Modules (SafeList) ==========
MOD - [2010.05.22 19:57:47 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Users\Jerry\Downloads\OTL.exe
MOD - [2009.07.14 03:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspicli.dll
MOD - [2009.07.14 03:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sechost.dll
MOD - [2009.07.14 03:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samcli.dll
MOD - [2009.07.14 03:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\profapi.dll
MOD - [2009.07.14 03:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netutils.dll
MOD - [2009.07.14 03:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\KernelBase.dll
MOD - [2009.07.14 03:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
MOD - [2009.07.14 03:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devobj.dll
MOD - [2009.07.14 03:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptbase.dll
MOD - [2009.07.14 03:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll
MOD - [2009.07.14 03:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
MOD - [2009.07.14 03:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2010.05.22 17:10:15 | 001,314,704 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010.05.06 22:59:38 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010.05.06 22:59:38 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010.05.06 22:59:38 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.07.14 03:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wwansvc.dll -- (WwanSvc)
SRV - [2009.07.14 03:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbiosrvc.dll -- (WbioSrvc)
SRV - [2009.07.14 03:16:17 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpo.dll -- (Power)
SRV - [2009.07.14 03:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2009.07.14 03:16:15 | 000,053,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sppuinotify.dll -- (sppuinotify)
SRV - [2009.07.14 03:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\pnrpsvc.dll -- (PNRPsvc) Protokol PNRP (Peer Name Resolution Protocol)
SRV - [2009.07.14 03:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\pnrpsvc.dll -- (p2pimsvc)
SRV - [2009.07.14 03:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\provsvc.dll -- (HomeGroupProvider)
SRV - [2009.07.14 03:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009.07.14 03:15:36 | 000,194,560 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\ListSvc.dll -- (HomeGroupListener)
SRV - [2009.07.14 03:15:21 | 000,797,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009.07.14 03:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2009.07.14 03:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\defragsvc.dll -- (defragsvc)
SRV - [2009.07.14 03:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\bdesvc.dll -- (BDESVC)
SRV - [2009.07.14 03:14:58 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AxInstSv.dll -- (AxInstSV) Instalační program ovládacích prvků ActiveX (AxInstSV)
SRV - [2009.07.14 03:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appidsvc.dll -- (AppIDSvc)
SRV - [2009.07.14 03:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\sppsvc.exe -- (sppsvc)
SRV - [2009.06.10 23:14:05 | 000,128,848 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
========== Driver Services (SafeList) ==========
DRV - [2010.05.22 17:54:35 | 000,028,752 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\MpEngineStore\MpKsl6f730163.sys -- (MpKsl6f730163)
DRV - [2010.05.08 12:54:02 | 000,099,984 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV - [2010.05.06 22:39:23 | 000,046,672 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010.05.06 22:39:00 | 000,164,048 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010.05.06 22:34:27 | 000,023,376 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010.05.06 22:34:10 | 000,051,792 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2010.05.06 22:33:47 | 000,019,024 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010.04.02 09:11:16 | 000,087,536 | ---- | M] (CyberLink Corp.) [2010/05/16 18:35:55] [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl -- ({1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC})
DRV - [2010.02.04 17:53:02 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009.12.18 00:25:12 | 000,026,024 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2009.12.11 09:44:02 | 000,133,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecpkg.sys -- (KSecPkg)
DRV - [2009.09.27 23:12:22 | 009,509,832 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009.08.09 23:25:56 | 000,029,696 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VClone.sys -- (VClone)
DRV - [2009.07.14 03:26:21 | 000,015,952 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\cmdide.sys -- (cmdide)
DRV - [2009.07.14 03:26:17 | 000,297,552 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpahci.sys -- (adpahci)
DRV - [2009.07.14 03:26:15 | 000,422,976 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adp94xx.sys -- (adp94xx)
DRV - [2009.07.14 03:26:15 | 000,159,312 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsbs.sys -- (amdsbs)
DRV - [2009.07.14 03:26:15 | 000,146,512 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpu320.sys -- (adpu320)
DRV - [2009.07.14 03:26:15 | 000,086,608 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arcsas.sys -- (arcsas)
DRV - [2009.07.14 03:26:15 | 000,079,952 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsata.sys -- (amdsata)
DRV - [2009.07.14 03:26:15 | 000,076,368 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arc.sys -- (arc)
DRV - [2009.07.14 03:26:15 | 000,023,616 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\amdxata.sys -- (amdxata)
DRV - [2009.07.14 03:26:15 | 000,014,400 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\aliide.sys -- (aliide)
DRV - [2009.07.14 03:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvstor.sys -- (nvstor)
DRV - [2009.07.14 03:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvraid.sys -- (nvraid)
DRV - [2009.07.14 03:20:44 | 000,044,624 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nfrd960.sys -- (nfrd960)
DRV - [2009.07.14 03:20:37 | 000,089,168 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas.sys -- (LSI_SAS)
DRV - [2009.07.14 03:20:36 | 000,332,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iaStorV.sys -- (iaStorV)
DRV - [2009.07.14 03:20:36 | 000,235,584 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MegaSR.sys -- (MegaSR)
DRV - [2009.07.14 03:20:36 | 000,096,848 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2009.07.14 03:20:36 | 000,095,824 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_fc.sys -- (LSI_FC)
DRV - [2009.07.14 03:20:36 | 000,054,864 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas2.sys -- (LSI_SAS2)
DRV - [2009.07.14 03:20:36 | 000,041,040 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iirsp.sys -- (iirsp)
DRV - [2009.07.14 03:20:36 | 000,030,800 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\megasas.sys -- (megasas)
DRV - [2009.07.14 03:20:36 | 000,013,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hwpolicy.sys -- (hwpolicy)
DRV - [2009.07.14 03:20:28 | 000,453,712 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\elxstor.sys -- (elxstor)
DRV - [2009.07.14 03:20:28 | 000,070,720 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\djsvs.sys -- (aic78xx)
DRV - [2009.07.14 03:20:28 | 000,067,152 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HpSAMD.sys -- (HpSAMD)
DRV - [2009.07.14 03:20:28 | 000,046,160 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\fsdepends.sys -- (FsDepends)
DRV - [2009.07.14 03:19:11 | 000,141,904 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vsmraid.sys -- (vsmraid)
DRV - [2009.07.14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009.07.14 03:19:10 | 000,159,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vhdmp.sys -- (vhdmp)
DRV - [2009.07.14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009.07.14 03:19:10 | 000,032,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vdrvroot.sys -- (vdrvroot)
DRV - [2009.07.14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\wimmount.sys -- (WIMMount)
DRV - [2009.07.14 03:19:10 | 000,016,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\viaide.sys -- (viaide)
DRV - [2009.07.14 03:19:04 | 001,383,488 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql2300.sys -- (ql2300)
DRV - [2009.07.14 03:19:04 | 000,173,648 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\rdyboost.sys -- (rdyboost)
DRV - [2009.07.14 03:19:04 | 000,106,064 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql40xx.sys -- (ql40xx)
DRV - [2009.07.14 03:19:04 | 000,077,888 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\sisraid4.sys -- (SiSRaid4)
DRV - [2009.07.14 03:19:04 | 000,043,088 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pcw.sys -- (pcw)
DRV - [2009.07.14 03:19:04 | 000,040,016 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\SiSRaid2.sys -- (SiSRaid2)
DRV - [2009.07.14 03:19:04 | 000,021,072 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\stexstor.sys -- (stexstor)
DRV - [2009.07.14 03:17:54 | 000,369,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\cng.sys -- (CNG)
DRV - [2009.07.14 02:57:25 | 000,272,128 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\Brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2009.07.14 02:02:41 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rdpbus.sys -- (rdpbus)
DRV - [2009.07.14 02:01:41 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV - [2009.07.14 01:55:00 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)
DRV - [2009.07.14 01:53:51 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\wfplwf.sys -- (WfpLwf)
DRV - [2009.07.14 01:52:44 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ndiscap.sys -- (NdisCap)
DRV - [2009.07.14 01:52:04 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vwififlt.sys -- (vwififlt)
DRV - [2009.07.14 01:52:02 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifibus.sys -- (vwifibus)
DRV - [2009.07.14 01:52:00 | 000,163,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\1394ohci.sys -- (1394ohci)
DRV - [2009.07.14 01:51:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\umpass.sys -- (UmPass)
DRV - [2009.07.14 01:51:08 | 000,004,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV - [2009.07.14 01:46:55 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MTConfig.sys -- (MTConfig)
DRV - [2009.07.14 01:45:26 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CompositeBus.sys -- (CompositeBus)
DRV - [2009.07.14 01:36:52 | 000,050,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\appid.sys -- (AppID)
DRV - [2009.07.14 01:33:50 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\scfilter.sys -- (scfilter)
DRV - [2009.07.14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009.07.14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009.07.14 01:24:05 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\discache.sys -- (discache)
DRV - [2009.07.14 01:19:21 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HidBatt.sys -- (HidBatt)
DRV - [2009.07.14 01:16:36 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\acpipmi.sys -- (AcpiPmi)
DRV - [2009.07.14 01:11:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdppm.sys -- (AmdPPM)
DRV - [2009.07.14 00:54:14 | 000,026,624 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009.07.14 00:53:33 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbMdm.sys -- (BrUsbMdm)
DRV - [2009.07.14 00:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbSer.sys -- (BrUsbSer)
DRV - [2009.07.14 00:53:32 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrSerWdm.sys -- (BrSerWdm)
DRV - [2009.07.14 00:53:28 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltLo.sys -- (BrFiltLo)
DRV - [2009.07.14 00:53:28 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltUp.sys -- (BrFiltUp)
DRV - [2009.07.14 00:02:53 | 000,545,792 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netr73.sys -- (netr73)
DRV - [2009.07.14 00:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009.07.14 00:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2009.07.14 00:02:48 | 003,100,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\evbdx.sys -- (ebdrv)
DRV - [2009.07.14 00:02:48 | 000,430,080 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\bxvbdx.sys -- (b06bdrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-253896119-1284465707-2055066879-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-253896119-1284465707-2055066879-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.cz/
IE - HKU\S-1-5-21-253896119-1284465707-2055066879-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = cs
IE - HKU\S-1-5-21-253896119-1284465707-2055066879-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 20 71 D7 00 7A F0 CA 01 [binary data]
IE - HKU\S-1-5-21-253896119-1284465707-2055066879-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.05.13 16:03:57 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.05.20 21:06:34 | 000,000,000 | ---D | M]
[2010.05.04 20:48:26 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.04.01 18:51:34 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.04.01 18:51:34 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.04.01 18:51:34 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.04.01 18:51:34 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.04.01 18:51:34 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2010.05.21 22:06:00 | 000,395,418 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1
www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1
www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1
www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1
www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1
www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1
www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1
www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1
www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1
www.10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1
www.1-2005-search.com
O1 - Hosts: 13652 more lines...
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKU\S-1-5-21-253896119-1284465707-2055066879-1003..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [*WerKernelReporting] C:\Windows\System32\WerFault.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [BrowserChoice] C:\Windows\System32\browserchoice.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [ehssetup] C:\Windows\ehome\ehssetup.DLL (Microsoft Corporation)
O4 - HKLM..\RunOnce: [iessetup] File not found
O4 - HKLM..\RunOnce: [wmssetup] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Jerry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Jarek\AppData\Roaming\Dropbox\bin\Dropbox.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKU\S-1-5-21-253896119-1284465707-2055066879-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKU\S-1-5-21-253896119-1284465707-2055066879-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O9 - Extra Button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll File not found
O9 - Extra 'Tools' menuitem : Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009.12.04 11:42:38 | 000,000,095 | -HS- | M] () - H:\autorun.bak -- [ FAT32 ]
O32 - AutoRun File - [2010.05.19 23:31:12 | 000,000,245 | -HS- | M] () - H:\autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009.07.14 04:37:08 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
========== Files/Folders - Created Within 30 Days ==========
[2010.05.22 19:37:30 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.05.22 19:37:24 | 000,000,000 | ---D | C] -- C:\rsit
[2010.05.22 17:54:35 | 000,000,000 | ---D | C] -- C:\Windows\System32\MpEngineStore
[2010.05.22 17:53:22 | 000,000,000 | ---D | C] -- C:\46bd6d0f38b4933c38eedc5be78950
[2010.05.22 17:10:50 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2010.05.22 17:10:45 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2010.05.22 17:07:15 | 000,000,000 | -H-D | C] -- C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010.05.22 17:06:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2010.05.22 17:06:59 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2010.05.21 20:27:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2010.05.21 20:27:58 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010.05.20 23:52:25 | 000,164,048 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2010.05.20 23:52:25 | 000,046,672 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2010.05.20 23:52:25 | 000,023,376 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2010.05.20 23:52:25 | 000,019,024 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2010.05.20 23:52:22 | 000,051,792 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2010.05.20 23:52:03 | 000,165,032 | ---- | C] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2010.05.20 23:52:03 | 000,038,848 | ---- | C] (ALWIL Software) -- C:\Windows\System32\avastSS.scr
[2010.05.20 23:52:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Alwil Software
[2010.05.20 23:52:01 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010.05.20 21:27:12 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010.05.20 21:06:16 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2010.05.20 21:05:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2010.05.20 21:05:53 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2010.05.20 21:05:21 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010.05.20 21:05:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2010.05.20 21:03:33 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Local\Microsoft Help
[2010.05.20 21:03:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2010.05.20 21:03:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2010.05.20 21:02:56 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010.05.20 20:23:40 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Roaming\Skype
[2010.05.20 19:57:54 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2010.05.18 23:14:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Macromedia
[2010.05.18 23:14:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2010.05.18 23:13:56 | 000,000,000 | ---D | C] -- C:\Windows\Downloaded Installations
[2010.05.16 18:36:09 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2010.05.16 18:35:42 | 000,000,000 | ---D | C] -- C:\Program Files\InstallShield Installation Information
[2010.05.16 18:35:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\CyberLink
[2010.05.16 18:34:22 | 000,505,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcp71.dll
[2010.05.16 18:34:22 | 000,353,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcr71.dll
[2010.05.16 18:34:22 | 000,029,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3a.dll
[2010.05.16 18:34:22 | 000,000,000 | ---D | C] -- C:\Program Files\CyberLink
[2010.05.16 18:30:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp
[2010.05.16 18:25:07 | 000,000,000 | ---D | C] -- C:\Program Files\AC3Filter
[2010.05.16 15:34:35 | 000,000,000 | ---D | C] -- C:\Windows\System32\appmgmt
[2010.05.16 13:23:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2010.05.15 23:07:25 | 000,142,864 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\drivers\VBoxDrv.sys
[2010.05.15 23:07:10 | 000,041,744 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\drivers\VBoxUSBMon.sys
[2010.05.15 23:07:09 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2010.05.15 19:00:09 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AbiSuite
[2010.05.13 17:51:59 | 000,000,000 | ---D | C] -- C:\Program Files\GNU
[2010.05.13 16:03:39 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010.05.13 16:03:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2010.05.13 16:03:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010.05.13 16:03:13 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Local\Apple
[2010.05.13 16:03:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2010.05.12 17:36:50 | 000,000,000 | ---D | C] -- C:\totalcmd
[2010.05.12 17:36:50 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Roaming\GHISLER
[2010.05.11 21:51:16 | 000,000,000 | ---D | C] -- C:\Program Files\GRETECH
[2010.05.10 23:25:58 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Local\Adobe
[2010.05.10 21:25:57 | 000,000,000 | ---D | C] -- C:\QIP 2010 JadrisPack
[2010.05.10 21:08:49 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Local\Paint.NET
[2010.05.10 21:08:49 | 000,000,000 | ---D | C] -- C:\Program Files\Paint.NET
[2010.05.08 12:54:02 | 000,099,984 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\drivers\VBoxNetAdp.sys
[2010.05.07 00:06:09 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2010.05.07 00:02:08 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe Media Player
[2010.05.07 00:00:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2010.05.07 00:00:54 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010.05.07 00:00:47 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Roaming\Macromedia
[2010.05.07 00:00:41 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Roaming\Adobe
[2010.05.07 00:00:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2010.05.06 23:59:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010.05.05 23:30:34 | 000,000,000 | ---D | C] -- C:\Program Files\Elaborate Bytes
[2010.05.05 05:50:08 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2010.05.05 05:49:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\OEM
[2010.05.04 23:11:31 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Roaming\FastStone
[2010.05.04 23:11:26 | 000,000,000 | ---D | C] -- C:\Program Files\FastStone Image Viewer
[2010.05.04 22:02:11 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Roaming\WinRAR
[2010.05.04 22:01:50 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2010.05.04 21:59:48 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Roaming\Softland
[2010.05.04 21:59:47 | 000,022,856 | ---- | C] (Softland) -- C:\Windows\System32\dopdfmn7.dll
[2010.05.04 21:59:47 | 000,019,784 | ---- | C] (Softland) -- C:\Windows\System32\dopdfmi7.dll
[2010.05.04 21:59:46 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\GdiPlus.dll
[2010.05.04 21:59:45 | 000,000,000 | ---D | C] -- C:\Program Files\Softland
[2010.05.04 21:56:16 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Roaming\uTorrent
[2010.05.04 21:56:16 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2010.05.04 21:48:52 | 000,000,000 | ---D | C] -- C:\Program Files\viewer-portable
[2010.05.04 21:22:50 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2010.05.04 21:01:12 | 000,221,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010.05.04 20:48:25 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2010.05.04 20:42:18 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browserchoice.exe
[2010.05.04 20:26:03 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2010.05.04 20:25:44 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2010.05.04 20:25:39 | 000,490,088 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvuninst.exe
[2010.05.04 20:23:32 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2010.05.04 20:23:30 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2010.05.04 20:23:30 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2010.05.04 20:23:30 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2010.05.04 20:23:28 | 003,954,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2010.05.04 20:23:28 | 003,899,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2010.05.04 20:23:26 | 001,037,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lsasrv.dll
[2010.05.04 20:23:26 | 000,133,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ksecpkg.sys
[2010.05.04 20:23:25 | 000,293,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2010.05.04 20:23:25 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\t2embed.dll
[2010.05.04 20:23:25 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2010.05.04 20:23:24 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010.05.04 20:23:19 | 001,320,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnroll.dll
[2010.05.04 20:23:19 | 000,507,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe
[2010.05.04 20:23:19 | 000,442,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe
[2010.05.04 20:23:18 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2010.05.04 20:22:59 | 002,614,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2010.05.04 20:22:58 | 001,328,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2010.05.04 20:22:58 | 000,427,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2010.05.04 20:22:58 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avifil32.dll
[2010.05.04 20:22:58 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mciavi32.dll
[2010.05.04 20:03:31 | 000,000,000 | R--D | C] -- C:\Users\Jarek\Searches
[2010.05.04 20:03:22 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Roaming\Identities
[2010.05.04 20:03:20 | 000,000,000 | R--D | C] -- C:\Users\Jarek\Contacts
[2010.05.04 20:03:09 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Local\VirtualStore
[2010.05.04 20:03:07 | 000,000,000 | --SD | C] -- C:\Users\Jarek\AppData\Roaming\Microsoft
[2010.05.04 20:03:07 | 000,000,000 | R--D | C] -- C:\Users\Jarek\Videos
[2010.05.04 20:03:07 | 000,000,000 | R--D | C] -- C:\Users\Jarek\Saved Games
[2010.05.04 20:03:07 | 000,000,000 | R--D | C] -- C:\Users\Jarek\Pictures
[2010.05.04 20:03:07 | 000,000,000 | R--D | C] -- C:\Users\Jarek\Music
[2010.05.04 20:03:07 | 000,000,000 | R--D | C] -- C:\Users\Jarek\Links
[2010.05.04 20:03:07 | 000,000,000 | R--D | C] -- C:\Users\Jarek\Favorites
[2010.05.04 20:03:07 | 000,000,000 | R--D | C] -- C:\Users\Jarek\Downloads
[2010.05.04 20:03:07 | 000,000,000 | R--D | C] -- C:\Users\Jarek\Dokumenty
[2010.05.04 20:03:07 | 000,000,000 | R--D | C] -- C:\Users\Jarek\Desktop
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\AppData\Local\Temporary Internet Files
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Šablony
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Soubory cookie
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\SendTo
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Poslední
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Okolní tiskárny
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Okolní síť
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Documents\Obrázky
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Nabídka Start
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Local Settings
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Documents\Hudba
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\AppData\Local\History
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Documents\Filmy
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Dokumenty
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\Data aplikací
[2010.05.04 20:03:07 | 000,000,000 | -HSD | C] -- C:\Users\Jarek\AppData\Local\Data aplikací
[2010.05.04 20:03:07 | 000,000,000 | -H-D | C] -- C:\Users\Jarek\AppData
[2010.05.04 20:03:07 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Local\Temp
[2010.05.04 20:03:07 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Local\Microsoft
[2010.05.04 20:03:07 | 000,000,000 | ---D | C] -- C:\Users\Jarek\AppData\Roaming\Media Center Programs
[2010.05.04 20:00:31 | 000,000,000 | -HSD | C] -- C:\ProgramData\Šablony
[2010.05.04 20:00:31 | 000,000,000 | -HSD | C] -- C:\Recovery
[2010.05.04 20:00:31 | 000,000,000 | -HSD | C] -- C:\ProgramData\Plocha
[2010.05.04 20:00:31 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Obrázky
[2010.05.04 20:00:31 | 000,000,000 | -HSD | C] -- C:\ProgramData\Oblíbené položky
[2010.05.04 20:00:31 | 000,000,000 | -HSD | C] -- C:\ProgramData\Nabídka Start
[2010.05.04 20:00:31 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Hudba
[2010.05.04 20:00:31 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Filmy
[2010.05.04 20:00:31 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty
[2010.05.04 20:00:31 | 000,000,000 | -HSD | C] -- C:\ProgramData\Data aplikací
[2010.05.04 19:54:05 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2010.05.04 19:51:05 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2010.05.04 19:50:44 | 000,000,000 | -HSD | C] -- C:\System Volume Information
========== Files - Modified Within 30 Days ==========
[2010.05.22 19:59:03 | 000,786,432 | -HS- | M] () -- C:\Users\Jarek\NTUSER.DAT
[2010.05.22 17:19:03 | 000,010,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010.05.22 17:19:03 | 000,010,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010.05.22 17:15:09 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010.05.22 17:12:42 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010.05.22 17:11:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010.05.22 17:11:43 | 804,954,112 | -HS- | M] () -- C:\hiberfil.sys
[2010.05.22 17:10:44 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2010.05.22 17:10:43 | 000,015,880 | ---- | M] () -- C:\Windows\System32\lsdelete.exe
[2010.05.22 17:07:14 | 000,001,100 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2010.05.21 22:06:00 | 000,395,418 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010.05.21 15:43:50 | 003,763,744 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010.05.20 23:52:25 | 000,002,005 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010.05.20 23:52:22 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2010.05.20 19:57:48 | 213,151,985 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010.05.19 23:23:32 | 001,445,734 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010.05.19 23:23:32 | 000,622,422 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2010.05.19 23:23:32 | 000,606,992 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010.05.19 23:23:32 | 000,118,604 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2010.05.19 23:23:32 | 000,103,370 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010.05.18 22:55:06 | 000,000,125 | ---- | M] () -- C:\Windows\FlashDecompiler.INI
[2010.05.16 18:35:52 | 000,002,063 | ---- | M] () -- C:\Users\Public\Desktop\CyberLink PowerDVD 10.lnk
[2010.05.16 18:30:37 | 000,029,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msxml3a.dll
[2010.05.16 18:30:36 | 000,505,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcp71.dll
[2010.05.16 18:30:36 | 000,353,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcr71.dll
[2010.05.16 13:25:22 | 000,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2010.05.13 16:03:47 | 000,001,815 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010.05.12 17:36:52 | 000,000,632 | ---- | M] () -- C:\Users\Public\Desktop\Total Commander.lnk
[2010.05.11 21:51:25 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\GOM Player.lnk
[2010.05.11 00:09:50 | 000,000,010 | RHS- | M] () -- C:\config.sys
[2010.05.10 21:26:06 | 000,001,618 | ---- | M] () -- C:\Users\Jarek\Desktop\QIP 2010 JadrisPack.lnk
[2010.05.10 21:09:20 | 000,001,176 | ---- | M] () -- C:\Users\Public\Desktop\Paint.NET.lnk
[2010.05.10 21:06:56 | 000,057,560 | ---- | M] () -- C:\Users\Jarek\AppData\Local\GDIPFONTCACHEV1.DAT
[2010.05.10 18:39:51 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010.05.08 12:54:02 | 000,142,864 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\drivers\VBoxDrv.sys
[2010.05.08 12:54:02 | 000,099,984 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\drivers\VBoxNetAdp.sys
[2010.05.08 12:54:02 | 000,041,744 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\drivers\VBoxUSBMon.sys
[2010.05.06 22:59:57 | 000,038,848 | ---- | M] (ALWIL Software) -- C:\Windows\System32\avastSS.scr
[2010.05.06 22:59:36 | 000,165,032 | ---- | M] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2010.05.06 22:39:23 | 000,046,672 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2010.05.06 22:39:00 | 000,164,048 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2010.05.06 22:34:27 | 000,023,376 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2010.05.06 22:34:10 | 000,051,792 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2010.05.06 22:33:47 | 000,019,024 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2010.05.06 10:36:38 | 000,221,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010.05.05 23:30:48 | 000,001,208 | ---- | M] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk
[2010.05.04 23:11:27 | 000,001,063 | ---- | M] () -- C:\Users\Public\Desktop\FastStone Image Viewer.lnk
[2010.05.04 21:56:16 | 000,000,913 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2010.05.04 20:48:27 | 000,001,885 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.05.04 20:07:40 | 000,524,288 | -HS- | M] () -- C:\Users\Jarek\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010.05.04 20:07:40 | 000,524,288 | -HS- | M] () -- C:\Users\Jarek\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010.05.04 20:07:40 | 000,065,536 | -HS- | M] () -- C:\Users\Jarek\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010.05.04 20:07:38 | 000,779,050 | -H-- | M] () -- C:\Users\Jarek\AppData\Local\IconCache.db
[2010.05.04 20:03:07 | 000,000,020 | -HS- | M] () -- C:\Users\Jarek\ntuser.ini
[2010.05.04 19:55:16 | 000,068,220 | ---- | M] () -- C:\Windows\System32\license.rtf
========== Files Created - No Company Name ==========
[2010.05.22 17:51:24 | 000,015,880 | ---- | C] () -- C:\Windows\System32\lsdelete.exe
[2010.05.22 17:15:05 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010.05.22 17:07:14 | 000,001,100 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2010.05.20 23:52:25 | 000,002,005 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010.05.20 19:57:48 | 213,151,985 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010.05.18 22:55:06 | 000,000,125 | ---- | C] () -- C:\Windows\FlashDecompiler.INI
[2010.05.16 18:35:52 | 000,002,063 | ---- | C] () -- C:\Users\Public\Desktop\CyberLink PowerDVD 10.lnk
[2010.05.16 18:25:07 | 000,497,664 | ---- | C] () -- C:\Windows\System32\ac3filter.acm
[2010.05.16 13:25:22 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.05.13 16:03:47 | 000,001,815 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010.05.12 17:36:52 | 000,000,632 | ---- | C] () -- C:\Users\Public\Desktop\Total Commander.lnk
[2010.05.12 17:36:50 | 000,000,545 | ---- | C] () -- C:\Windows\UC.PIF
[2010.05.12 17:36:50 | 000,000,545 | ---- | C] () -- C:\Windows\RAR.PIF
[2010.05.12 17:36:50 | 000,000,545 | ---- | C] () -- C:\Windows\PKZIP.PIF
[2010.05.12 17:36:50 | 000,000,545 | ---- | C] () -- C:\Windows\PKUNZIP.PIF
[2010.05.12 17:36:50 | 000,000,545 | ---- | C] () -- C:\Windows\NOCLOSE.PIF
[2010.05.12 17:36:50 | 000,000,545 | ---- | C] () -- C:\Windows\LHA.PIF
[2010.05.12 17:36:50 | 000,000,545 | ---- | C] () -- C:\Windows\ARJ.PIF
[2010.05.11 21:51:25 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\GOM Player.lnk
[2010.05.10 21:26:06 | 000,001,618 | ---- | C] () -- C:\Users\Jarek\Desktop\QIP 2010 JadrisPack.lnk
[2010.05.10 21:09:20 | 000,001,176 | ---- | C] () -- C:\Users\Public\Desktop\Paint.NET.lnk
[2010.05.10 18:39:51 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010.05.05 23:30:48 | 000,001,208 | ---- | C] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk
[2010.05.04 23:11:27 | 000,001,063 | ---- | C] () -- C:\Users\Public\Desktop\FastStone Image Viewer.lnk
[2010.05.04 21:59:47 | 000,007,549 | ---- | C] () -- C:\Windows\System32\dopdf7.ctm
[2010.05.04 21:56:16 | 000,000,913 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2010.05.04 20:48:27 | 000,001,885 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010.05.04 20:03:07 | 000,786,432 | -HS- | C] () -- C:\Users\Jarek\NTUSER.DAT
[2010.05.04 20:03:07 | 000,524,288 | -HS- | C] () -- C:\Users\Jarek\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010.05.04 20:03:07 | 000,524,288 | -HS- | C] () -- C:\Users\Jarek\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010.05.04 20:03:07 | 000,262,144 | -HS- | C] () -- C:\Users\Jarek\ntuser.dat.LOG1
[2010.05.04 20:03:07 | 000,065,536 | -HS- | C] () -- C:\Users\Jarek\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010.05.04 20:03:07 | 000,000,020 | -HS- | C] () -- C:\Users\Jarek\ntuser.ini
[2010.05.04 20:03:07 | 000,000,000 | -HS- | C] () -- C:\Users\Jarek\ntuser.dat.LOG2
[2010.05.04 19:50:47 | 804,954,112 | -HS- | C] () -- C:\hiberfil.sys
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
========== LOP Check ==========
[2010.05.12 17:36:50 | 000,000,000 | ---D | M] -- C:\Users\Jarek\AppData\Roaming\GHISLER
[2010.05.04 21:59:48 | 000,000,000 | ---D | M] -- C:\Users\Jarek\AppData\Roaming\Softland
[2010.05.15 17:30:19 | 000,000,000 | ---D | M] -- C:\Users\Jarek\AppData\Roaming\uTorrent
[2010.05.10 23:30:49 | 000,000,000 | ---D | M] -- C:\Users\Jerry\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010.05.22 19:33:53 | 000,000,000 | ---D | M] -- C:\Users\Jerry\AppData\Roaming\Dropbox
[2010.05.22 18:24:44 | 000,000,000 | ---D | M] -- C:\Users\Jerry\AppData\Roaming\GHISLER
[2010.05.15 14:16:24 | 000,000,000 | ---D | M] -- C:\Users\Jerry\AppData\Roaming\Softland
[2010.05.22 20:02:51 | 000,000,000 | ---D | M] -- C:\Users\Jerry\AppData\Roaming\uTorrent
[2010.05.22 17:15:09 | 000,000,370 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009.07.14 06:53:46 | 000,004,494 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========