OTL logfile created on: 1.7.2010 16:07:05 - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = D:\Documents and Settings\ondra\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1 023,00 Mb Total Physical Memory | 343,00 Mb Available Physical Memory | 34,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 67,00% Paging File free
Paging file location(s): D:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 39,06 Gb Total Space | 0,70 Gb Free Space | 1,78% Space Free | Partition Type: NTFS
Drive D: | 109,99 Gb Total Space | 0,99 Gb Free Space | 0,90% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 494,61 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JELEN
Current User Name: ondra
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010.07.01 16:05:22 | 000,574,464 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\ondra\Plocha\OTL.exe
PRC - [2010.06.17 11:28:53 | 001,238,352 | ---- | M] (Valve Corporation) -- D:\Program Files\Steam\Steam.exe
PRC - [2010.05.30 09:31:50 | 000,892,928 | RHS- | M] (PSY7cWk) -- D:\Documents and Settings\ondra\Local Settings\Temp\T8SoB.exe
PRC - [2010.05.09 14:30:16 | 000,483,395 | RHS- | M] (QoSxssp) -- D:\Documents and Settings\ondra\Local Settings\Temp\5a9v7.exe
PRC - [2010.03.30 11:16:12 | 001,107,336 | ---- | M] (LogMeIn Inc.) -- D:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2010.03.25 18:42:36 | 000,388,096 | ---- | M] (Trend Micro Inc.) -- D:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
PRC - [2009.11.11 11:57:36 | 001,451,520 | ---- | M] (Nokia) -- D:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
PRC - [2009.10.27 10:26:36 | 000,657,408 | ---- | M] (Nokia) -- D:\Program Files\PC Connectivity Solution\ServiceLayer.exe
PRC - [2009.10.27 10:15:44 | 000,132,608 | ---- | M] (Nokia) -- D:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2009.10.27 10:15:02 | 000,120,832 | ---- | M] (Nokia) -- D:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
PRC - [2009.08.11 19:47:02 | 000,491,768 | ---- | M] (COMODO) -- D:\Program Files\COMODO\EasyVPN\crdphService.exe
PRC - [2009.08.11 19:46:24 | 000,045,304 | ---- | M] () -- D:\Program Files\COMODO\EasyVPN\Vpnservice.exe
PRC - [2009.07.03 16:49:06 | 001,029,456 | ---- | M] (Lavasoft) -- D:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009.04.23 15:51:38 | 000,691,656 | ---- | M] (DT Soft Ltd) -- D:\Program Files\DAEMON Tools Lite\daemon.exe
PRC - [2009.02.05 22:08:45 | 000,081,000 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009.02.05 22:08:40 | 000,138,680 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009.02.05 22:08:26 | 000,254,040 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009.02.05 22:06:04 | 000,352,920 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009.02.05 22:01:25 | 000,018,752 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009.01.15 18:42:46 | 007,430,144 | ---- | M] (OpenOffice.org) -- D:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2009.01.15 18:42:44 | 007,434,240 | ---- | M] (OpenOffice.org) -- D:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2008.10.17 10:39:50 | 002,810,880 | ---- | M] (mIRC Co. Ltd.) -- D:\Program Files\mIRC\mirc.exe
PRC - [2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
PRC - [2001.06.26 20:44:14 | 000,424,067 | ---- | M] (Blizzard North) -- D:\hry\Diablo II\Game.exe
========== Modules (SafeList) ==========
MOD - [2010.07.01 16:05:22 | 000,574,464 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\ondra\Plocha\OTL.exe
MOD - [2009.02.05 22:07:43 | 000,139,264 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\AhJsctNs.dll
MOD - [2008.04.14 08:49:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2010.03.30 11:16:12 | 001,107,336 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- D:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2010.03.03 14:45:11 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009.10.27 10:26:36 | 000,657,408 | ---- | M] (Nokia) [On_Demand | Running] -- D:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009.08.11 19:47:02 | 000,491,768 | ---- | M] (COMODO) [Auto | Running] -- D:\Program Files\COMODO\EasyVPN\crdphService.exe -- (CrdphService)
SRV - [2009.08.11 19:46:24 | 000,045,304 | ---- | M] () [Auto | Running] -- D:\Program Files\COMODO\EasyVPN\Vpnservice.exe -- (EasyVpnAdpt)
SRV - [2009.07.03 16:49:06 | 001,029,456 | ---- | M] (Lavasoft) [Auto | Running] -- D:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2009.02.05 22:08:40 | 000,138,680 | ---- | M] (ALWIL Software) [Auto | Running] -- D:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2009.02.05 22:08:26 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009.02.05 22:06:04 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- D:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009.02.05 22:01:25 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2008.07.29 20:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
========== Driver Services (SafeList) ==========
DRV - [2010.04.29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2009.11.16 12:31:49 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009.08.04 06:34:57 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- D:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009.07.03 16:49:08 | 000,064,160 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- D:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009.02.05 22:08:10 | 000,094,032 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- D:\WINDOWS\system32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2009.02.05 22:07:23 | 000,114,768 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP)
DRV - [2009.02.05 22:07:12 | 000,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- D:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009.02.05 22:06:20 | 000,051,376 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2009.02.05 22:06:10 | 000,023,152 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2009.02.05 22:05:11 | 000,026,944 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2008.12.10 11:08:54 | 000,017,424 | ---- | M] (Comodo, Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\cmdatp.sys -- (ATP)
DRV - [2008.08.26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008.05.12 18:30:02 | 003,007,488 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2008.01.30 03:41:42 | 000,025,216 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\tap0901.sys -- (tap0901)
DRV - [2004.11.09 17:04:26 | 001,342,080 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\cmuda3.sys -- (cmuda3)
DRV - [2001.08.17 22:05:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\OVCD.sys -- (QCDonner)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1060284298-287218729-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://seznam.cz/
IE - HKU\S-1-5-21-1060284298-287218729-1606980848-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1060284298-287218729-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://www.seznam.cz/"
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems:
bkmrksync@nokia.com:1.0.0.723
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3789
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\
bkmrksync@nokia.com: D:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010.01.07 16:44:36 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010.06.26 13:00:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010.06.26 13:00:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\
eplgTb@eset.com: D:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2009.07.31 20:28:03 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Mozilla\Extensions
[2010.06.30 17:00:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Mozilla\Firefox\Profiles\qtn4qc4n.default\extensions
[2010.03.01 13:29:36 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- D:\Documents and Settings\ondra\Data aplikací\Mozilla\Firefox\Profiles\qtn4qc4n.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009.08.03 23:42:03 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- D:\Documents and Settings\ondra\Data aplikací\Mozilla\Firefox\Profiles\qtn4qc4n.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2009.08.04 06:38:15 | 000,002,399 | ---- | M] () -- D:\Documents and Settings\ondra\Data aplikací\Mozilla\Firefox\Profiles\qtn4qc4n.default\searchplugins\daemon-search.xml
[2010.06.30 17:00:42 | 000,000,955 | ---- | M] () -- D:\Documents and Settings\ondra\Data aplikací\Mozilla\Firefox\Profiles\qtn4qc4n.default\searchplugins\icqplugin.xml
[2010.06.30 16:50:42 | 000,000,000 | ---D | M] -- D:\Program Files\Mozilla Firefox\extensions
[2009.07.31 20:30:05 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2008.11.11 09:38:54 | 000,663,552 | ---- | M] (BitComet) -- D:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2009.07.15 20:42:42 | 000,000,638 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2009.07.15 20:42:42 | 000,001,687 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2009.07.15 20:42:42 | 000,001,367 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2009.07.15 20:42:42 | 000,000,654 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2009.07.15 20:42:42 | 000,001,179 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2001.10.25 16:00:00 | 000,000,737 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll (BitComet)
O3 - HKU\S-1-5-21-1060284298-287218729-1606980848-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKLM..\Run: [3i0xcLrEpJlGBlzL4rqM3AO] D:\Documents and Settings\ondra\Local Settings\Temp\5a9v7.exe (QoSxssp)
O4 - HKLM..\Run: [avast!] D:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [CmPCIaudio] File not found
O4 - HKLM..\Run: [HKLM] D:\Documents and Settings\ondra\Local Settings\Temp\T8SoB.exe (PSY7cWk)
O4 - HKLM..\Run: [L07WGZr36fRQtwyzUcj] D:\Documents and Settings\ondra\Local Settings\Temp\T8SoB.exe (PSY7cWk)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] D:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [StartCCC] D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-1060284298-287218729-1606980848-1003..\Run: [7EfxRIQSMJOUgwF3QES4ujzx1] D:\Documents and Settings\ondra\Local Settings\Temp\T8SoB.exe (PSY7cWk)
O4 - HKU\S-1-5-21-1060284298-287218729-1606980848-1003..\Run: [Comodo EasyVPN] D:\Program Files\COMODO\EasyVPN\EasyVPN.exe (COMODO)
O4 - HKU\S-1-5-21-1060284298-287218729-1606980848-1003..\Run: [DAEMON Tools Lite] D:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1060284298-287218729-1606980848-1003..\Run: [HKCU] D:\Documents and Settings\ondra\Local Settings\Temp\T8SoB.exe (PSY7cWk)
O4 - HKU\S-1-5-21-1060284298-287218729-1606980848-1003..\Run: [PC Suite Tray] D:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKU\S-1-5-21-1060284298-287218729-1606980848-1003..\Run: [rVSL8Klen6Kveo4] D:\Documents and Settings\ondra\Local Settings\Temp\5a9v7.exe (QoSxssp)
O4 - HKU\S-1-5-21-1060284298-287218729-1606980848-1003..\Run: [Steam] D:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: D:\Documents and Settings\ondra\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.0.lnk = D:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = D:\DOCUME~1\ondra\LOCALS~1\Temp\T8SoB.exe (PSY7cWk)
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1060284298-287218729-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1060284298-287218729-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = D:\DOCUME~1\ondra\LOCALS~1\Temp\5a9v7.exe (QoSxssp)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - D:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: D:\Documents and Settings\ondra\Data aplikací\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\ondra\Data aplikací\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.09.18 21:54:59 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009.08.21 10:31:07 | 000,000,053 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009.08.21 10:31:07 | 000,000,053 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2001.04.18 16:23:00 | 000,000,041 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{61e6dbd8-80b0-11de-ba81-00690009b26d}\Shell - "" = AutoRun
O33 - MountPoints2\{61e6dbd8-80b0-11de-ba81-00690009b26d}\Shell\AutoRun\command - "" = G:\SETUP.EXE -- [2001.04.30 18:33:00 | 000,032,768 | R--- | M] ()
O33 - MountPoints2\{7dda6af3-4cff-11de-b11b-00690009b26d}\Shell\AutoRun\command - "" = cv8j.exe
O33 - MountPoints2\{7dda6af3-4cff-11de-b11b-00690009b26d}\Shell\open\Command - "" = cv8j.exe
O33 - MountPoints2\{c9c842de-0a33-11dd-b276-806d6172696f}\Shell\AutoRun\command - "" = lcw.exe
O33 - MountPoints2\{c9c842de-0a33-11dd-b276-806d6172696f}\Shell\open\Command - "" = lcw.exe
O33 - MountPoints2\{c9c842df-0a33-11dd-b276-806d6172696f}\Shell\AutoRun\command - "" = lcw.exe
O33 - MountPoints2\{c9c842df-0a33-11dd-b276-806d6172696f}\Shell\open\Command - "" = lcw.exe
O33 - MountPoints2\C\Shell\AutoRun\command - "" = lcw.exe
O33 - MountPoints2\C\Shell\open\Command - "" = lcw.exe
O33 - MountPoints2\D\Shell\AutoRun\command - "" = lcw.exe
O33 - MountPoints2\D\Shell\open\Command - "" = lcw.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - D:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - D:\WINDOWS\system32\ias [2009.07.31 18:22:23 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - D:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - D:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - D:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - D:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - D:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - D:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - D:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - D:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - D:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - D:\WINDOWS\System32\ir50_32.dll ()
Drivers32: vidc.VP60 - D:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - D:\WINDOWS\system32\vp6vfw.dll (On2.com)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (32664708049797120)
========== Files/Folders - Created Within 30 Days ==========
[2010.07.01 16:05:16 | 000,574,464 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\ondra\Plocha\OTL.exe
[2010.06.29 20:59:13 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Plocha\gp4
[2010.06.29 20:59:05 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Plocha\fotky
[2010.06.29 20:58:46 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Plocha\Tomas_Klus
[2010.06.29 20:58:00 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Plocha\Guitar Pro 5
[2010.06.29 10:28:26 | 000,000,000 | ---D | C] -- D:\Program Files\mIRC
[2010.06.24 17:31:24 | 003,516,965 | ---- | C] (Max Prasak) -- D:\Documents and Settings\ondra\Plocha\D2instcz.exe
[2010.06.24 17:28:22 | 000,094,208 | ---- | C] (Blizzard Entertainment) -- D:\WINDOWS\DIIUnin.exe
[2010.06.24 12:38:35 | 000,000,000 | ---D | C] -- D:\Program Files\Diablo II
[2010.06.24 11:39:52 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Plocha\Rehoc Leader Roster
[2010.06.23 14:01:01 | 000,000,000 | ---D | C] -- D:\Program Files\Guitar Pro 5
[2010.06.23 09:30:18 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Data aplikací\Turbine
[2010.06.23 09:26:29 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Plocha\Need For Speed Pro Street - Soundtrack
[2010.06.22 17:53:09 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Local Settings\Data aplikací\Turbine
[2010.06.22 16:46:13 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Local Settings\Data aplikací\ApplicationHistory
[2010.06.22 16:43:44 | 000,000,000 | ---D | C] -- D:\WINDOWS\System32\URTTEMP
[2010.06.22 14:04:22 | 000,000,000 | RH-D | C] -- D:\Documents and Settings\ondra\Recent
[2010.06.19 10:49:16 | 000,000,000 | ---D | C] -- D:\Program Files\Trend Micro
[2010.06.18 13:11:53 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Dokumenty\Electronic Arts
[2010.06.18 13:02:45 | 000,447,752 | R--- | C] (On2.com) -- D:\WINDOWS\System32\vp6vfw.dll
[2010.06.18 13:02:44 | 000,000,000 | ---D | C] -- D:\Program Files\Microsoft WSE
[2010.06.17 11:27:08 | 000,000,000 | ---D | C] -- D:\Program Files\Steam
[2010.06.16 12:24:13 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Data aplikací\Trymedia
[2010.06.08 13:19:27 | 000,000,000 | -HSD | C] -- D:\Documents and Settings\ondra\IECompatCache
[2010.06.06 21:36:43 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Plocha\WowBgTweaker_v2.1
[2010.06.05 18:38:04 | 000,293,376 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\browserchoice.exe
[2010.06.04 22:42:43 | 001,342,080 | ---- | C] (C-Media Inc) -- D:\WINDOWS\System32\drivers\cmuda3.sys
[2010.06.04 22:42:43 | 000,036,864 | ---- | C] (C-Media) -- D:\WINDOWS\System32\CMUDA3.DLL
[2010.06.04 22:42:43 | 000,032,768 | ---- | C] (C-Media Corporation) -- D:\WINDOWS\System32\UDAPROP3.DLL
[2010.06.04 22:42:42 | 002,596,864 | ---- | C] (C-Media Corporation) -- D:\WINDOWS\System\CMICNFG3.CPL
[2010.06.04 22:42:42 | 000,917,504 | ---- | C] (C-Media Electronics Inc.) -- D:\WINDOWS\System\CMDS3D3.DLL
[2010.06.04 22:42:42 | 000,712,704 | ---- | C] (Sensaura Ltd) -- D:\WINDOWS\System32\AUDIO3D3.DLL
[2010.06.04 22:42:42 | 000,712,704 | ---- | C] (Sensaura Ltd) -- D:\WINDOWS\System32\dllcache\a3d.dll
[2010.06.04 22:42:42 | 000,712,704 | ---- | C] (Sensaura Ltd) -- D:\WINDOWS\System32\a3d.dll
[2010.06.04 22:42:42 | 000,000,000 | ---D | C] -- D:\Program Files\C-Media PCI Audio
[2010.06.04 22:22:13 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Data aplikací\GetRightToGo
[2010.06.04 22:12:49 | 000,000,000 | ---D | C] -- D:\Documents and Settings\ondra\Dokumenty\Přijaté soubory
[4 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
[3 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010.07.01 16:08:40 | 001,179,612 | -H-- | M] () -- D:\Documents and Settings\ondra\Data aplikací\cglogs.dat
[2010.07.01 16:05:22 | 000,574,464 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\ondra\Plocha\OTL.exe
[2010.07.01 15:29:05 | 000,002,441 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\HiJackThis.lnk
[2010.07.01 13:37:05 | 000,000,472 | ---- | M] () -- D:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010.07.01 11:15:12 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2010.07.01 11:13:56 | 000,000,430 | ---- | M] () -- D:\WINDOWS\System32\drivers\etc\hosts.ics
[2010.07.01 11:13:14 | 000,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT
[2010.07.01 11:13:05 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2010.07.01 11:12:57 | 1072,549,888 | -HS- | M] () -- D:\hiberfil.sys
[2010.06.30 17:10:04 | 006,029,312 | -H-- | M] () -- D:\Documents and Settings\ondra\NTUSER.DAT
[2010.06.30 17:10:04 | 000,000,178 | -HS- | M] () -- D:\Documents and Settings\ondra\ntuser.ini
[2010.06.30 17:09:35 | 002,107,604 | -H-- | M] () -- D:\Documents and Settings\ondra\Local Settings\Data aplikací\IconCache.db
[2010.06.30 12:26:48 | 260,814,907 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\CZ+CZ_titulky_by_Striker.rar
[2010.06.29 22:19:56 | 183,533,664 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\HIMYM-S04E17-The_Front_Porch.rar
[2010.06.29 22:07:38 | 183,531,606 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\HIMYM-S04E16-Sorry__Bro.rar
[2010.06.29 21:24:04 | 183,496,886 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\HIMYM-S04E14-The_Possimpible.rar
[2010.06.29 21:12:20 | 183,531,619 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\HIMYM-S04E13-Three_Days_of_Snow.rar
[2010.06.29 10:28:27 | 000,000,626 | ---- | M] () -- D:\Documents and Settings\All Users\Plocha\mIRC.lnk
[2010.06.27 16:10:36 | 000,178,176 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\zpevnik_tabor2010.doc
[2010.06.24 19:33:50 | 000,073,820 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\snow_hey_oh.gp3
[2010.06.24 19:31:27 | 000,060,304 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\dani_california_ver4.gp3
[2010.06.24 19:25:05 | 000,024,940 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\Blue_Effect_-_Sluneční_hrob.gp5
[2010.06.24 19:04:16 | 000,037,407 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\Divokej_Bill_-_Malování.gp3
[2010.06.24 18:44:28 | 000,011,295 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\Nohavica, Jaromir - Kometa.gp5-by-
www.get-the-tab.com.zip
[2010.06.24 18:44:00 | 000,021,242 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\Nohavica, Jaromir - Kometa.gp5
[2010.06.24 17:33:46 | 000,028,761 | ---- | M] () -- D:\WINDOWS\DIIUnin.dat
[2010.06.24 17:32:31 | 000,001,452 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\Diablo II - Lord of Destruction.lnk
[2010.06.24 17:31:32 | 003,516,965 | ---- | M] (Max Prasak) -- D:\Documents and Settings\ondra\Plocha\D2instcz.exe
[2010.06.24 17:28:25 | 000,001,452 | ---- | M] () -- D:\Documents and Settings\All Users\Plocha\Diablo II.lnk
[2010.06.24 17:28:22 | 000,094,208 | ---- | M] (Blizzard Entertainment) -- D:\WINDOWS\DIIUnin.exe
[2010.06.24 17:28:22 | 000,002,829 | ---- | M] () -- D:\WINDOWS\DIIUnin.pif
[2010.06.24 12:59:01 | 000,021,840 | ---- | M] () -- D:\WINDOWS\System32\SIntfNT.dll
[2010.06.24 12:59:00 | 000,017,212 | ---- | M] () -- D:\WINDOWS\System32\SIntf32.dll
[2010.06.24 12:59:00 | 000,012,067 | ---- | M] () -- D:\WINDOWS\System32\SIntf16.dll
[2010.06.24 12:56:46 | 011,759,475 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\Diablo 2 Crack.rar
[2010.06.24 11:38:03 | 002,437,442 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\1277149710_sb_rehocleaderroster.rar
[2010.06.24 10:04:24 | 001,417,608 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT
[2010.06.23 14:02:08 | 000,020,880 | ---- | M] () -- D:\Documents and Settings\ondra\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2010.06.23 14:01:23 | 000,000,619 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\Guitar Pro 5.lnk
[2010.06.23 11:24:49 | 000,001,889 | ---- | M] () -- D:\Documents and Settings\All Users\Plocha\The Sims™ 3 Povolání snů.lnk
[2010.06.22 16:46:14 | 000,000,125 | ---- | M] () -- D:\Documents and Settings\ondra\Local Settings\Data aplikací\fusioncache.dat
[2010.06.22 16:45:47 | 001,021,366 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI
[2010.06.22 16:45:47 | 000,440,684 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2010.06.22 16:45:47 | 000,437,056 | ---- | M] () -- D:\WINDOWS\System32\perfh005.dat
[2010.06.22 16:45:47 | 000,082,440 | ---- | M] () -- D:\WINDOWS\System32\perfc005.dat
[2010.06.22 16:45:47 | 000,071,002 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2010.06.22 16:43:12 | 000,001,638 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\The Lord of the Rings Online.lnk
[2010.06.22 15:03:12 | 000,053,760 | ---- | M] () -- D:\Documents and Settings\ondra\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.06.19 11:02:50 | 000,530,701 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\RobertVarga_8-6-2009-21-06-54_Sims_3_Censor.rar
[2010.06.18 13:02:16 | 000,001,723 | ---- | M] () -- D:\Documents and Settings\All Users\Plocha\The Sims™ 3.lnk
[2010.06.17 15:59:58 | 182,298,881 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\04-13 - Three Days of Snow.rar
[2010.06.17 11:34:12 | 000,000,664 | ---- | M] () -- D:\Documents and Settings\All Users\Plocha\Steam.lnk
[2010.06.17 11:26:33 | 001,588,224 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\SteamInstall.msi
[2010.06.07 11:51:59 | 000,089,829 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\NHL MATCH.JPG
[2010.06.06 21:36:18 | 004,147,105 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\WowBgTweaker_v2.1.rar
[2010.06.06 08:53:07 | 000,001,503 | ---- | M] () -- D:\Documents and Settings\All Users\Plocha\Výběr prohlížeče.lnk
[2010.06.04 22:44:34 | 000,000,165 | ---- | M] () -- D:\WINDOWS\System\Cmicnfg3.ini
[2010.06.04 22:22:41 | 000,000,404 | ---- | M] () -- D:\Documents and Settings\All Users\Plocha\Resume Driver Detective.lnk
[2010.06.04 21:57:58 | 000,000,016 | ---- | M] () -- D:\WINDOWS\wininit.ini
[2010.06.04 21:38:50 | 000,001,324 | ---- | M] () -- D:\WINDOWS\System32\d3d9caps.dat
[2010.06.03 21:14:02 | 000,551,398 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\HIMYM titulky.rar
[2010.06.03 00:09:44 | 000,000,439 | ---- | M] () -- D:\Documents and Settings\ondra\Plocha\Zástupce - RelicCOH.lnk
[4 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
[3 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010.06.30 12:25:06 | 260,814,907 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\CZ+CZ_titulky_by_Striker.rar
[2010.06.29 22:19:33 | 183,533,664 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\HIMYM-S04E17-The_Front_Porch.rar
[2010.06.29 22:07:27 | 183,531,606 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\HIMYM-S04E16-Sorry__Bro.rar
[2010.06.29 21:23:57 | 183,496,886 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\HIMYM-S04E14-The_Possimpible.rar
[2010.06.29 21:11:49 | 183,531,619 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\HIMYM-S04E13-Three_Days_of_Snow.rar
[2010.06.29 20:59:05 | 000,178,176 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\zpevnik_tabor2010.doc
[2010.06.29 10:28:27 | 000,000,626 | ---- | C] () -- D:\Documents and Settings\All Users\Plocha\mIRC.lnk
[2010.06.24 19:53:07 | 000,021,242 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\Nohavica, Jaromir - Kometa.gp5
[2010.06.24 19:33:50 | 000,073,820 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\snow_hey_oh.gp3
[2010.06.24 19:31:27 | 000,060,304 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\dani_california_ver4.gp3
[2010.06.24 19:25:04 | 000,024,940 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\Blue_Effect_-_Sluneční_hrob.gp5
[2010.06.24 19:04:15 | 000,037,407 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\Divokej_Bill_-_Malování.gp3
[2010.06.24 18:44:27 | 000,011,295 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\Nohavica, Jaromir - Kometa.gp5-by-
www.get-the-tab.com.zip
[2010.06.24 17:32:31 | 000,001,452 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\Diablo II - Lord of Destruction.lnk
[2010.06.24 17:28:25 | 000,028,761 | ---- | C] () -- D:\WINDOWS\DIIUnin.dat
[2010.06.24 17:28:25 | 000,001,452 | ---- | C] () -- D:\Documents and Settings\All Users\Plocha\Diablo II.lnk
[2010.06.24 17:28:22 | 000,002,829 | ---- | C] () -- D:\WINDOWS\DIIUnin.pif
[2010.06.24 12:57:17 | 000,021,840 | ---- | C] () -- D:\WINDOWS\System32\SIntfNT.dll
[2010.06.24 12:57:16 | 000,017,212 | ---- | C] () -- D:\WINDOWS\System32\SIntf32.dll
[2010.06.24 12:57:16 | 000,012,067 | ---- | C] () -- D:\WINDOWS\System32\SIntf16.dll
[2010.06.24 12:56:36 | 011,759,475 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\Diablo 2 Crack.rar
[2010.06.24 11:37:47 | 002,437,442 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\1277149710_sb_rehocleaderroster.rar
[2010.06.23 14:01:23 | 000,000,619 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\Guitar Pro 5.lnk
[2010.06.23 11:24:41 | 000,001,889 | ---- | C] () -- D:\Documents and Settings\All Users\Plocha\The Sims™ 3 Povolání snů.lnk
[2010.06.22 16:46:14 | 000,000,125 | ---- | C] () -- D:\Documents and Settings\ondra\Local Settings\Data aplikací\fusioncache.dat
[2010.06.22 16:43:12 | 000,001,638 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\The Lord of the Rings Online.lnk
[2010.06.19 11:02:48 | 000,530,701 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\RobertVarga_8-6-2009-21-06-54_Sims_3_Censor.rar
[2010.06.19 10:49:17 | 000,002,441 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\HiJackThis.lnk
[2010.06.18 13:02:16 | 000,001,723 | ---- | C] () -- D:\Documents and Settings\All Users\Plocha\The Sims™ 3.lnk
[2010.06.17 15:59:45 | 182,298,881 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\04-13 - Three Days of Snow.rar
[2010.06.17 15:53:18 | 183,517,184 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\HIMYM-S04E12-Benefits.avi
[2010.06.17 11:27:11 | 000,000,664 | ---- | C] () -- D:\Documents and Settings\All Users\Plocha\Steam.lnk
[2010.06.17 11:26:23 | 001,588,224 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\SteamInstall.msi
[2010.06.06 21:36:05 | 004,147,105 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\WowBgTweaker_v2.1.rar
[2010.06.06 08:53:07 | 000,001,503 | ---- | C] () -- D:\Documents and Settings\All Users\Plocha\Výběr prohlížeče.lnk
[2010.06.04 22:44:34 | 000,000,165 | ---- | C] () -- D:\WINDOWS\System\Cmicnfg3.ini
[2010.06.04 22:43:10 | 000,028,672 | ---- | C] () -- D:\WINDOWS\CmiPCIUninstall.exe
[2010.06.04 22:42:43 | 000,233,472 | ---- | C] () -- D:\WINDOWS\System32\CMRMDRV3.exe
[2010.06.04 22:42:43 | 000,028,672 | ---- | C] () -- D:\WINDOWS\System32\CMRMDRV3.DLL
[2010.06.04 22:22:41 | 000,000,404 | ---- | C] () -- D:\Documents and Settings\All Users\Plocha\Resume Driver Detective.lnk
[2010.06.04 21:57:58 | 000,000,016 | ---- | C] () -- D:\WINDOWS\wininit.ini
[2010.06.04 21:40:10 | 1072,549,888 | -HS- | C] () -- D:\hiberfil.sys
[2010.06.03 21:14:01 | 000,551,398 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\HIMYM titulky.rar
[2010.06.03 00:09:44 | 000,000,439 | ---- | C] () -- D:\Documents and Settings\ondra\Plocha\Zástupce - RelicCOH.lnk
[2010.04.26 20:28:53 | 000,000,262 | ---- | C] () -- D:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009.08.13 16:07:09 | 000,139,456 | ---- | C] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009.08.04 06:34:57 | 000,721,904 | ---- | C] () -- D:\WINDOWS\System32\drivers\sptd.sys
[2008.10.07 10:13:30 | 000,197,912 | ---- | C] () -- D:\WINDOWS\System32\physxcudart_20.dll
[2008.10.07 10:13:22 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSwedish.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSpanish.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelPortugese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelKorean.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelJapanese.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelGerman.dll
[2008.10.07 10:13:20 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelFrench.dll
[2008.04.14 08:51:46 | 000,755,200 | ---- | C] () -- D:\WINDOWS\System32\ir50_32.dll
[2008.04.14 08:51:46 | 000,338,432 | ---- | C] () -- D:\WINDOWS\System32\ir41_qcx.dll
[2008.04.14 08:51:46 | 000,200,192 | ---- | C] () -- D:\WINDOWS\System32\ir50_qc.dll
[2008.04.14 08:51:46 | 000,183,808 | ---- | C] () -- D:\WINDOWS\System32\ir50_qcx.dll
[2008.04.14 08:51:46 | 000,120,320 | ---- | C] () -- D:\WINDOWS\System32\ir41_qc.dll
[1999.08.12 00:00:00 | 001,708,032 | ---- | C] () -- D:\WINDOWS\System32\MSO97V.DLL
[1999.08.12 00:00:00 | 000,036,864 | ---- | C] () -- D:\WINDOWS\System32\DOCOBJ.DLL
[1999.08.12 00:00:00 | 000,032,768 | ---- | C] () -- D:\WINDOWS\System32\MSORFS.DLL
[1999.08.12 00:00:00 | 000,032,768 | ---- | C] () -- D:\WINDOWS\System32\HLINKPRX.DLL
[1997.06.13 23:56:08 | 000,056,832 | ---- | C] () -- D:\WINDOWS\System32\iyvu9_32.dll
========== LOP Check ==========
[2009.08.04 06:38:46 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.08.07 10:23:06 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Data aplikací\ESET
[2009.07.31 20:30:07 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Data aplikací\ICQ
[2010.01.07 16:27:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Data aplikací\Installations
[2010.01.19 20:16:31 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Data aplikací\OviInstallerCache
[2009.08.07 11:11:35 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Data aplikací\PC Suite
[2009.11.09 12:16:34 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Data aplikací\TrackMania
[2009.08.20 13:36:47 | 000,000,000 | -H-D | M] -- D:\Documents and Settings\All Users\Data aplikací\{EF63305C-BAD7-4144-9208-D65528260864}
[2009.08.04 06:46:12 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\DAEMON Tools Lite
[2009.08.05 20:46:20 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\ESET
[2010.06.20 00:38:37 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Facebook
[2010.06.04 22:22:39 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\GetRightToGo
[2010.06.28 16:15:42 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\ICQ
[2009.08.02 13:26:24 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Nokia
[2009.08.13 17:10:16 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\OpenOffice.org
[2009.08.02 13:26:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\PC Suite
[2009.08.28 15:29:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\SPORE
[2010.03.12 20:11:56 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\TeamViewer
[2010.06.23 09:30:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Turbine
[2010.07.01 13:37:05 | 000,000,472 | ---- | M] () -- D:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = D:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 08:52:18 | 000,015,360 | ---- | M] (Microsoft Corporation)
"DAEMON Tools Lite" = "D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun -- [2009.04.23 15:51:38 | 000,691,656 | ---- | M] (DT Soft Ltd)
"Comodo EasyVPN" = "D:\Program Files\COMODO\EasyVPN\EasyVPN.exe" -- [2009.09.28 18:36:40 | 003,563,768 | ---- | M] (COMODO)
"PC Suite Tray" = "D:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray -- [2009.11.11 11:57:36 | 001,451,520 | ---- | M] (Nokia)
"Steam" = "D:\Program Files\Steam\Steam.exe" -silent -- [2010.06.17 11:28:53 | 001,238,352 | ---- | M] (Valve Corporation)
"HKCU" = D:\DOCUME~1\ondra\LOCALS~1\Temp\T8SoB.exe -- [2010.05.30 09:31:50 | 000,892,928 | RHS- | M] (PSY7cWk)
"rVSL8Klen6Kveo4" = D:\DOCUME~1\ondra\LOCALS~1\Temp\5a9v7.exe -- [2010.05.09 14:30:16 | 000,483,395 | RHS- | M] (QoSxssp)
"7EfxRIQSMJOUgwF3QES4ujzx1" = D:\DOCUME~1\ondra\LOCALS~1\Temp\T8SoB.exe -- [2010.05.30 09:31:50 | 000,892,928 | RHS- | M] (PSY7cWk)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]
"" =
< c:\windows\*.* /U >
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.03.03 16:59:28 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Adobe
[2009.07.31 20:00:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\ATI
[2009.12.28 14:08:24 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\COMODO
[2009.08.04 06:46:12 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\DAEMON Tools Lite
[2010.03.06 21:59:32 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\dvdcss
[2009.08.05 20:46:20 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\ESET
[2010.06.20 00:38:37 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Facebook
[2010.06.04 22:22:39 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\GetRightToGo
[2010.06.29 12:04:06 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Hamachi
[2010.06.28 16:15:42 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\ICQ
[2009.07.31 18:33:06 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Identities
[2009.07.31 20:41:27 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Macromedia
[2009.07.31 22:24:50 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Malwarebytes
[2010.06.22 17:53:06 | 000,000,000 | --SD | M] -- D:\Documents and Settings\ondra\Data aplikací\Microsoft
[2010.07.01 14:51:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\mIRC
[2009.07.31 20:28:03 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Mozilla
[2009.08.02 13:26:24 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Nokia
[2009.08.13 17:10:16 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\OpenOffice.org
[2009.08.02 13:26:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\PC Suite
[2010.06.20 15:52:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Skype
[2010.06.20 16:02:27 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\skypePM
[2009.08.28 15:29:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\SPORE
[2010.03.31 07:25:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Sun
[2010.06.01 13:08:20 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\teamspeak2
[2010.03.12 20:11:56 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\TeamViewer
[2010.06.23 09:30:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Turbine
[2010.03.05 15:47:34 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\Ventrilo
[2010.06.22 13:55:04 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\vlc
[2009.07.31 23:14:09 | 000,000,000 | ---D | M] -- D:\Documents and Settings\ondra\Data aplikací\WinRAR
< %APPDATA%\*.exe /s >
[2010.05.16 20:59:42 | 000,050,354 | ---- | M] (Facebook, Inc.) -- D:\Documents and Settings\ondra\Data aplikací\Facebook\uninstall.exe
[2009.09.02 22:19:33 | 001,961,720 | ---- | M] (Adobe Systems Incorporated) -- D:\Documents and Settings\ondra\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
[2010.06.19 10:49:17 | 000,388,096 | R--- | M] (Trend Micro Inc.) -- D:\Documents and Settings\ondra\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
[2010.06.18 13:02:45 | 000,010,134 | R--- | M] () -- D:\Documents and Settings\ondra\Data aplikací\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
< MD5 for: AGP440.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- D:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: CDROM.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- D:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- D:\WINDOWS\system32\cryptsvc.dll
[2008.04.14 08:51:40 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- D:\WINDOWS\system32\dllcache\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- D:\WINDOWS\system32\dllcache\eventlog.dll
[2008.04.14 08:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- D:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- D:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- D:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2008.04.14 00:01:30 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- D:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
< MD5 for: ISAPNP.SYS >
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- D:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.04.14 07:57:54 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- D:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- D:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- D:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- D:\WINDOWS\system32\dllcache\ndis.sys
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- D:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- D:\WINDOWS\system32\dllcache\netlogon.dll
[2008.04.14 08:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- D:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- D:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- D:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- D:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- D:\WINDOWS\system32\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- D:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- D:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- D:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- D:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- D:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- D:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- D:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- D:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- D:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- D:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- D:\WINDOWS\system32\dllcache\ws2_32.dll
[2008.04.14 08:52:08 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- D:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008.05.12 17:56:04 | 000,397,312 | ---- | M] (Advanced Micro Devices, Inc.)
Unable to obtain MD5 -- D:\WINDOWS\system32\ATIDEMGX.dll
[2009.03.08 04:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\dxtmsft.dll
[2009.03.08 04:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\dxtrans.dll
[2008.04.14 08:51:50 | 001,384,479 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\msvbvm60.dll
[4 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009.08.04 06:34:57 | 000,721,904 | ---- | M] ()
Unable to obtain MD5 -- D:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2009.07.31 20:06:37 | 000,094,208 | ---- | M] () -- D:\WINDOWS\system32\config\default.sav
[2009.07.31 20:06:36 | 001,093,632 | ---- | M] () -- D:\WINDOWS\system32\config\software.sav
[2009.07.31 20:06:36 | 000,507,904 | ---- | M] () -- D:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[2008.05.12 17:56:04 | 000,397,312 | ---- | M] (Advanced Micro Devices, Inc.)
Unable to obtain MD5 -- D:\WINDOWS\system32\ATIDEMGX.dll
[2009.03.08 04:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\dxtmsft.dll
[2009.03.08 04:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\dxtrans.dll
[2008.04.14 08:51:50 | 001,384,479 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- D:\WINDOWS\system32\msvbvm60.dll
[4 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2010.07.01 11:13:15 | 000,000,795 | ---- | M] () -- D:\WINDOWS\system32\VpnService.log
[2010.07.01 11:15:12 | 000,002,206 | ---- | M] () -- D:\WINDOWS\system32\wpa.dbl
[4 D:\WINDOWS\system32\*.tmp files -> D:\WINDOWS\system32\*.tmp -> ]
< End of report >