Stránka 1 z 1

Vir- facebook

Napsal: 20 srp 2011 08:54
od ruza71
Může mít někdo pomoci jednodušší způsob jak spustit facebook, nějaký vir s facebooku napadl moje pc a nemůžu jet znova spustit, projel jsem je všemi možnými antiviry, díky za pomoc.
Jsem pouhý uživatel, nevím jak co kde funguje, ale chtěl bych to s Vaši pomocí opravit. PC funguje normálně, jen facebook nefunguje díky viru youtube a nevím jak to odstranit.

Re: Vir- facebook

Napsal: 20 srp 2011 12:26
od Caroprd111
Zdravím a vítám vás na našem bezpečnostním fóru viry.cz :welcome:

Můj nick je Caroprd111. Budu se vám v tomto topicu věnovat a snažit se odstranit všechny vaše problémy s počítačem. :)
Než začneme, přečtěte si prosím následující poznámky.
  • Pokud nemáte, zálohujte si všechna důležitá data. Infikovaný počítač je nevyzpytatelný.
  • Důsledně a pečlivě si přečtěte celý postup, poté pokračujte po jednotlivých krocích.
  • Prosím, nespouštějte žádné další programy na vlastní pěst, zejména ComboFix. Zbytečně tím můžete zkomplikovat odvirování, dokonce i znefunkčnit systém.
  • Absence příznaků nemusí vždy znamenat, že je počítač čistý, proto vždy spolupracujte až do doby, než vám napíšu, že je počítač v pořádku.
  • V případě, že něčemu nerozumíte nebo si nejste jist, neváhejte se mě zeptat.
  • Pokud bude log dlouhý a nevejde se do jednoho příspěvku, rozdělte jej do více příspěvků.

:arrow: Přečtěte si pravidla fóra a vložte sem log z RSIT. :)

Re: Vir- facebook

Napsal: 20 srp 2011 16:05
od ruza71
Snad jsem to udělal správně


Logfile of random's system information tool 1.09 (written by random/random)
Run by Obyvák at 2011-08-20 17:03:54
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 191 GB (40%) free of 477 GB
Total RAM: 3071 MB (62% free)


======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-152049171-1801674531-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-152049171-1801674531-1004UA.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Obyvák\Data aplikací\Mozilla\Firefox\Profiles\vid6xk54.default

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon Easy-PhotoPrint EX
"Path"=C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@comrade.gamespy.com/comrade]
"Description"=
"Path"=C:\Program Files\GameSpy\Comrade\npcomrade.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18]
"Description"=Veetle TV Core
"Path"=C:\Program Files\Veetle\plugins\npVeetle.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=C:\Program Files\Veetle\Player\npvlc.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-09-22 61888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2009-11-25 202080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{55cde9e7-696c-47c4-8e21-7210b8aeb103}]
Toolbar BHO - C:\PROGRA~1\SMILEY~2\bar\1.bin\1wbar.dll [2010-12-09 675840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5ed22e89-62fa-47ec-bd8d-374d849d436c}]
Search Assistant BHO - C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wSrcAs.dll [2010-12-09 53248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{984A9162-8891-4D19-8CFE-17648BB4E1EC}]
GamePlayLabsBHO Class - C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\GamePlayLabs Plugin\BHO.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-08-19 305328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [2011-05-21 1007160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-05-04 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}]
Ask Toolbar BHO - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL [2010-05-12 245760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\20101006190848\ICQToolBar.dll [2010-10-04 1049912]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2009-11-25 1496408]
{FE063DB9-4EC0-403e-8DD8-394C54984B2C} - Ask Toolbar - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL [2010-05-12 245760]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]
{d3ca5551-fc2e-4d09-8ece-263607acf9fc} - SmileyCentral - C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbar.dll [2010-12-09 675840]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-08-19 305328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2011-01-12 2219184]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-11-22 16858112]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2009-11-02 2508104]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-09-04 767312]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352]
"nwiz"=nwiz.exe /installquiet []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-04-03 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-04-03 13670504]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2007-05-10 624248]
""= []
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-09-16 1164584]
"NPSStartup"= []
"SmileyCentralIE_1w Browser Plugin Loader"=C:\PROGRA~1\SMILEY~2\bar\1.bin\1wbrmon.exe [2010-12-09 20480]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-01-31 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"4StoryPrePatch"=C:\Program Files\Gameforge4D\4Story\PrePatch.exe [2010-10-20 319488]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"wxpdrv"=C:\WINDOWS\services32.exe []
"tray_ico"= []
"tray_ico0"=C:\WINDOWS\update.tray-3-0\svchost.exe []
"tray_ico1"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"8850112.exe"=C:\WINDOWS\TEMP\8850112.exe []
"sysdriver32.exe"=C:\WINDOWS\sysdriver32.exe rezerv []
"sysdriver32_.exe"=C:\WINDOWS\sysdriver32_.exe rezerv []
"9656773.exe"=C:\DOCUME~1\OBYVK~1\LOCALS~1\Temp\9656773.exe []
"6351787.exe"=C:\WINDOWS\TEMP\6351787.exe []
"83981145-loader2.exe"=C:\WINDOWS\TEMP\83981145-loader2.exe []
"6317838.exe"=C:\WINDOWS\TEMP\6317838.exe []
"l1rezerv.exe"=C:\WINDOWS\l1rezerv.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-05-12 39408]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [2009-11-20 434176]
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2010-07-29 95576]
"ICQ"=C:\Program Files\ICQ7.1\ICQ.exe [2011-01-05 133432]
"Steam"=C:\Program Files\Steam\Steam.exe [2011-08-04 1242448]
"Google Update"=C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2011-08-05 136176]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Aktualizovat ESET licenci.lnk - C:\Program Files\ESET\MiNODLogin\MiNODLogin.exe

C:\Documents and Settings\Obyvák\Nabídka Start\Programy\Po spuštění
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa]
C:\WINDOWS\system32\antiwpa.dll [2006-07-22 5376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
"EnableSecureUIAPaths"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Průvodce přenesením souborů a nastavení"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Hry\TrackMania Nations ESWC\TmNationsESWC.exe"="C:\Hry\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"J:\TrackMania Nations ESWC\TmNationsESWC.exe"="J:\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"C:\Program Files\Codemasters\F1 2010\F1_2010_game.exe"="C:\Program Files\Codemasters\F1 2010\F1_2010_game.exe:*:Enabled:F1 2010"
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB.exe"
"C:\Program Files\Codemasters\DiRT 3\dirt3_game.exe"="C:\Program Files\Codemasters\DiRT 3\dirt3_game.exe:*:Enabled:DiRT 3"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe"="C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe:*:Enabled:Assassin's Creed II"
"C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe"="C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe:*:Enabled:Assassin's Creed II Update"
"C:\Program Files\Ubisoft\Assassin's Creed II\UPlayBrowser.exe"="C:\Program Files\Ubisoft\Assassin's Creed II\UPlayBrowser.exe:*:Enabled:Assassin's Creed II Uplay"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
"C:\Documents and Settings\Obyvák\Dokumenty\Downloads\Flash-Player.exe"="C:\Documents and Settings\Obyvák\Dokumenty\Downloads\Flash-Player.exe:*:Enabled:C:\Documents and Settings\Obyvák\Dokumenty\Downloads\Flash-Player.exe"
"C:\WINDOWS\update.1\svchost.exe"="C:\WINDOWS\update.1\svchost.exe:*:Enabled:C:\WINDOWS\update.1\svchost.exe"
"C:\WINDOWS\update.tray-3-0\svchost.exe"="C:\WINDOWS\update.tray-3-0\svchost.exe:*:Enabled:C:\WINDOWS\update.tray-3-0\svchost.exe"
"C:\WINDOWS\update.2\svchost.exe"="C:\WINDOWS\update.2\svchost.exe:*:Enabled:C:\WINDOWS\update.2\svchost.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll

======List of files/folders created in the last 1 month======

2011-08-20 17:03:54 ----D---- C:\rsit
2011-08-20 17:03:54 ----D---- C:\Program Files\trend micro
2011-08-20 16:02:09 ----D---- C:\Documents and Settings\Obyvák\Data aplikací\PCToolsFirewallPlus
2011-08-20 15:43:28 ----A---- C:\WINDOWS\BDTSupport.dll
2011-08-20 15:43:27 ----A---- C:\WINDOWS\SGDetectionTool.dll
2011-08-20 15:43:27 ----A---- C:\WINDOWS\PCTBDRes.dll
2011-08-20 15:43:27 ----A---- C:\WINDOWS\PCTBDCore.dll
2011-08-20 15:41:59 ----A---- C:\WINDOWS\system32\drivers\pctEFA.sys
2011-08-20 15:41:59 ----A---- C:\WINDOWS\system32\drivers\pctDS.sys
2011-08-20 15:41:58 ----A---- C:\WINDOWS\system32\drivers\pctgntdi.sys
2011-08-20 15:41:53 ----A---- C:\WINDOWS\system32\drivers\PCTCore.sys
2011-08-20 15:41:53 ----A---- C:\WINDOWS\system32\drivers\PCTAppEvent.sys
2011-08-20 15:41:52 ----A---- C:\WINDOWS\system32\drivers\PCTSD.sys
2011-08-20 15:41:50 ----A---- C:\WINDOWS\system32\drivers\pctplsg.sys
2011-08-20 15:20:01 ----D---- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter
2011-08-20 14:49:33 ----A---- C:\WINDOWS\system32\drivers\Cat.DB
2011-08-20 14:48:58 ----D---- C:\Program Files\PC Tools Security
2011-08-20 14:48:58 ----D---- C:\Program Files\Common Files\PC Tools
2011-08-20 14:47:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\PC Tools
2011-08-20 13:13:38 ----D---- C:\_OTL
2011-08-20 11:50:39 ----A---- C:\Boot.bak
2011-08-20 11:50:33 ----RASHD---- C:\cmdcons
2011-08-20 11:48:47 ----A---- C:\WINDOWS\zip.exe
2011-08-20 11:48:47 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-08-20 11:48:47 ----A---- C:\WINDOWS\SWSC.exe
2011-08-20 11:48:47 ----A---- C:\WINDOWS\SWREG.exe
2011-08-20 11:48:47 ----A---- C:\WINDOWS\sed.exe
2011-08-20 11:48:47 ----A---- C:\WINDOWS\PEV.exe
2011-08-20 11:48:47 ----A---- C:\WINDOWS\NIRCMD.exe
2011-08-20 11:48:47 ----A---- C:\WINDOWS\MBR.exe
2011-08-20 11:48:47 ----A---- C:\WINDOWS\grep.exe
2011-08-20 11:48:42 ----SD---- C:\ComboFix
2011-08-20 11:46:28 ----D---- C:\WINDOWS\ERDNT
2011-08-20 11:46:28 ----A---- C:\WINDOWS\system32\CF15156.exe
2011-08-20 11:33:36 ----D---- C:\Qoobox
2011-08-20 10:14:24 ----D---- C:\Documents and Settings\Obyvák\Data aplikací\Malwarebytes
2011-08-20 10:14:21 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-08-20 10:14:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-08-20 10:14:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-08-20 10:14:17 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-08-19 21:23:45 ----D---- C:\Program Files\ESET
2011-08-19 21:23:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2011-08-19 16:33:30 ----D---- C:\WINDOWS\update.7.1
2011-08-19 12:07:31 ----D---- C:\WINDOWS\ufa
2011-08-19 12:07:31 ----D---- C:\WINDOWS\rpcminer
2011-08-19 12:07:31 ----D---- C:\WINDOWS\phoenix
2011-08-19 12:00:06 ----A---- C:\WINDOWS\btc_client_iplist.txt
2011-08-19 11:58:06 ----HD---- C:\WINDOWS\update.5.0
2011-08-19 11:58:00 ----A---- C:\WINDOWS\iecheck_iplist.txt
2011-08-19 11:57:42 ----A---- C:\WINDOWS\unrar.exe
2011-08-19 11:57:34 ----HD---- C:\WINDOWS\update.2
2011-08-19 11:57:13 ----A---- C:\WINDOWS\iplist.txt
2011-08-19 11:56:32 ----A---- C:\WINDOWS\front_ip_list.txt
2011-08-19 11:56:23 ----D---- C:\WINDOWS\av_ico
2011-08-19 11:54:15 ----HD---- C:\WINDOWS\update.1
2011-08-19 11:54:02 ----HD---- C:\WINDOWS\update.tray-3-0-lnk
2011-08-19 11:54:02 ----HD---- C:\WINDOWS\update.tray-3-0
2011-08-19 11:43:51 ----A---- C:\WINDOWS\winlog-ids.txt
2011-08-19 11:43:51 ----A---- C:\WINDOWS\winlog-dirs.txt
2011-08-15 06:29:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avanquest
2011-08-10 23:45:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-08-10 23:44:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-08-10 23:44:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-08-10 23:42:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-08-10 23:42:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2562937$
2011-07-25 10:37:48 ----D---- C:\HryMafia
2011-07-23 14:42:07 ----A---- C:\WINDOWS\nsreg.dat
2011-07-23 14:42:01 ----D---- C:\Program Files\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2011-08-20 17:03:59 ----D---- C:\WINDOWS\Prefetch
2011-08-20 17:03:54 ----RD---- C:\Program Files
2011-08-20 17:02:38 ----A---- C:\WINDOWS\WINCMD.INI
2011-08-20 16:18:04 ----D---- C:\WINDOWS\Temp
2011-08-20 16:07:11 ----D---- C:\WINDOWS\system32\CatRoot2
2011-08-20 16:06:53 ----D---- C:\Documents and Settings\Obyvák\Data aplikací\ICQ
2011-08-20 16:06:46 ----D---- C:\Program Files\Steam
2011-08-20 16:05:07 ----D---- C:\WINDOWS\system32\drivers
2011-08-20 16:04:34 ----D---- C:\WINDOWS\system32\config
2011-08-20 16:04:16 ----D---- C:\WINDOWS\system32\wbem
2011-08-20 16:04:16 ----D---- C:\WINDOWS\Registration
2011-08-20 16:04:04 ----HD---- C:\WINDOWS\inf
2011-08-20 16:04:04 ----D---- C:\WINDOWS
2011-08-20 16:03:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-08-20 16:03:20 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2011-08-20 15:42:18 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-08-20 15:42:00 ----SHD---- C:\System Volume Information
2011-08-20 15:41:45 ----SHD---- C:\WINDOWS\Installer
2011-08-20 15:41:45 ----D---- C:\WINDOWS\WinSxS
2011-08-20 15:41:45 ----D---- C:\Config.Msi
2011-08-20 15:22:14 ----D---- C:\WINDOWS\system32
2011-08-20 14:48:58 ----D---- C:\Program Files\Common Files
2011-08-20 14:30:17 ----A---- C:\WINDOWS\NeroDigital.ini
2011-08-20 12:35:31 ----AC---- C:\WINDOWS\ntbtlog.txt
2011-08-20 12:03:08 ----D---- C:\Documents and Settings
2011-08-20 11:56:09 ----D---- C:\WINDOWS\AppPatch
2011-08-20 11:50:40 ----RASH---- C:\boot.ini
2011-08-20 11:12:08 ----D---- C:\WINDOWS\msapps
2011-08-19 12:00:35 ----D---- C:\WINDOWS\system32\Restore
2011-08-19 11:57:53 ----D---- C:\WINDOWS\system32\drivers\etc
2011-08-18 22:04:18 ----D---- C:\Documents and Settings\Obyvák\Data aplikací\Skype
2011-08-18 22:00:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\Easybits GO
2011-08-18 13:40:39 ----D---- C:\Documents and Settings\Obyvák\Data aplikací\go
2011-08-16 10:26:46 ----RD---- C:\Hudba
2011-08-15 06:29:18 ----D---- C:\Program Files\Avanquest update
2011-08-11 10:11:20 ----D---- C:\WINDOWS\Microsoft.NET
2011-08-11 10:11:18 ----RSD---- C:\WINDOWS\assembly
2011-08-10 23:46:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-08-10 23:45:17 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-08-10 23:45:17 ----A---- C:\WINDOWS\imsins.BAK
2011-08-10 23:45:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2011-08-10 23:44:42 ----HD---- C:\WINDOWS\$hf_mig$
2011-08-10 23:42:58 ----A---- C:\WINDOWS\system32\MRT.exe
2011-08-10 23:42:50 ----D---- C:\Program Files\Internet Explorer
2011-08-09 17:20:36 ----D---- C:\WINDOWS\system32\DirectX
2011-08-09 17:12:43 ----D---- C:\Program Files\Ubisoft
2011-08-09 17:12:42 ----HD---- C:\Program Files\InstallShield Installation Information
2011-08-09 11:31:25 ----D---- C:\Hry
2011-08-09 11:27:12 ----D---- C:\Program Files\EA Sports
2011-08-09 11:15:43 ----D---- C:\Program Files\Electronic Arts
2011-08-09 11:15:41 ----D---- C:\ProgramData
2011-08-09 11:15:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
2011-08-09 10:40:03 ----D---- C:\fotky
2011-08-01 12:12:45 ----D---- C:\DVD
2011-07-28 14:32:09 ----D---- C:\WINDOWS\Network Diagnostic
2011-07-25 17:08:54 ----A---- C:\WINDOWS\system32\mshtml.dll
2011-07-24 11:30:05 ----D---- C:\Documents and Settings\Obyvák\Data aplikací\vlc
2011-07-23 16:51:30 ----D---- C:\Documents and Settings\Obyvák\Data aplikací\.minecraft
2011-07-23 14:42:14 ----D---- C:\Documents and Settings\Obyvák\Data aplikací\Mozilla

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-04-27 45648]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2005-05-16 6656]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2005-11-03 63488]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-05-17 697328]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2010-08-03 55256]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-12-21 141264]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2010-12-21 134000]
R2 irda;Protokol IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-14 88192]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2010-12-21 33120]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-11-27 4630016]
R3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-04-03 10232128]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2007-11-17 54016]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2007-11-17 22016]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2007-10-12 13312]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S1 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2008-04-14 31744]
S3 8e61c8ff;8e61c8ff; C:\WINDOWS\4291322254:1906194176.exe []
S3 aw0wmqf2;aw0wmqf2; C:\WINDOWS\system32\drivers\aw0wmqf2.sys []
S3 EagleXNt;EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys []
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2008-05-02 17536]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2010-04-27 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2010-04-27 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2010-04-27 123648]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2008-01-29 602112]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2010-07-29 238952]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-05-04 153376]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2008-01-29 163840]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-04-03 154216]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-10-29 90112]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-10-29 189248]
R2 SNMP;SNMP; C:\WINDOWS\System32\snmp.exe [2008-04-14 32768]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-06-12 656896]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2011-01-12 810144]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-12 135664]
S2 SmileyCentralIE_1wService;SmileyCentral Service; C:\PROGRA~1\SMILEY~2\bar\1.bin\1wbarsvc.exe [2010-12-09 28766]
S2 srvbtcclient;srvbtcclient; C:\WINDOWS\update.5.0\svchost.exe srv []
S2 srviecheck;srviecheck; C:\WINDOWS\update.2\svchost.exe srv []
S2 srvsysdriver32;srvsysdriver32; C:\WINDOWS\sysdriver32.exe srv []
S2 wxpdrivers;wxpdrivers; C:\WINDOWS\update.1\svchost.exe srv []
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2011-01-12 33584]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-12 135664]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-05-12 182768]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 LPDSVC;Tiskový server TCP/IP; C:\WINDOWS\system32\tcpsvcs.exe [2008-04-14 19456]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S3 SNMPTRAP;Zachytávání pro službu SNMP; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Vir- facebook

Napsal: 20 srp 2011 16:14
od Caroprd111
:arrow: Používáte toolbary?


:arrow: Stáhněte OTL http://oldtimer.geekstogo.com/OTL.exe na plochu
  • Spusťte, poté do spodního políčka vložte následující skript.

Kód: Vybrat vše

 
safebootminimal 
safebootnetwork
drivers32
savembr:0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
/md5start
scecli.dll
autochk.exe
csrss.exe
explorer.exe
lsass.exe
services.exe
smss.exe
spoolsv.exe
svchost.exe
userinit.exe
winlogon.exe
atapi.sys
cdrom.sys 
ndis.sys
ntfs.sys
tcpip.sys
%SystemDrive%\PhysicalMBR.bin
/md5stop
C:\windows\system32\spool\prtprocs|dll;true;true;true /FP
%systemroot%\system32\drivers\*.sys /5
%systemroot%\system32\drivers\*.sys /X 
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\*.* /5
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\config\*.sav 
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\*.* /U /s
%systemroot%\*. /mp /s
%ALLUSERSPROFILE%\Data Aplikací\*.*
%ALLUSERSPROFILE%\Data Aplikací\*.exe /s
%ALLUSERSPROFILE%\Dáta aplikácií\*.*
%ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s
%APPDATA%\*.
%APPDATA%\*.*
%APPDATA%\*.exe /s
%SYSTEMDRIVE%\*.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c
type c:\boot.ini >> test.txt /c
*crack*
*keygen*
  • Označte položku Pro všechny uživatele.
  • Označte položky Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
  • Klikněte na tlačítko Prohledat
  • Po dokončení, sem vložte logy OTL.Txt a Extras.txt

Re: Vir- facebook

Napsal: 21 srp 2011 19:56
od ruza71
OTL logfile created on: 21.8.2011 20:44:40 - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\Obyvák\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,00 Gb Total Physical Memory | 2,29 Gb Available Physical Memory | 76,32% Memory free
4,84 Gb Paging File | 4,15 Gb Available in Paging File | 85,57% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465,75 Gb Total Space | 182,50 Gb Free Space | 39,18% Space Free | Partition Type: NTFS
Drive K: | 1,91 Gb Total Space | 1,36 Gb Free Space | 71,05% Space Free | Partition Type: FAT

Computer Name: DOMA-C7C92CF28B | User Name: Obyvák | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found -- C:\WINDOWS\4291322254:1906194176.exe
PRC - [2011.08.21 10:53:04 | 000,960,576 | ---- | M] (SmileyCentral) -- C:\Program Files\SmileyCentralIE_1w\bar\setups\SmileyCentralAuto.exe
PRC - [2011.08.20 12:53:31 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Obyvák\Plocha\OTL (1).exe
PRC - [2011.08.06 04:21:27 | 001,017,912 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
PRC - [2011.08.05 17:54:32 | 000,140,952 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Update\1.3.21.65\GoogleCrashHandler.exe
PRC - [2011.08.04 07:17:26 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2011.01.05 10:18:50 | 000,133,432 | ---- | M] (ICQ, LLC.) -- C:\Program Files\ICQ7.1\ICQ.exe
PRC - [2010.12.09 20:56:09 | 000,020,480 | ---- | M] (SmileyCentral) -- C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbrmon.exe
PRC - [2010.10.20 11:48:26 | 000,319,488 | ---- | M] (Zamiinc) -- C:\Program Files\Gameforge4D\4Story\PrePatch.exe
PRC - [2010.09.16 22:04:06 | 001,164,584 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010.07.29 09:50:16 | 000,238,952 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2010.07.29 09:47:08 | 000,095,576 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
PRC - [2010.06.12 11:09:52 | 000,656,896 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2010.04.01 11:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2010.01.03 17:07:48 | 000,246,520 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2009.11.20 10:17:12 | 000,434,176 | ---- | M] (Sony Ericsson Mobile Communications AB) -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
PRC - [2009.11.02 02:30:00 | 002,508,104 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2009.04.30 11:23:26 | 000,090,112 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
PRC - [2008.06.24 16:06:06 | 001,840,424 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
PRC - [2008.04.14 14:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008.01.29 12:25:10 | 000,602,112 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
PRC - [2008.01.29 12:24:46 | 000,163,840 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
PRC - [2007.05.10 22:46:20 | 000,624,248 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
PRC - [2007.02.04 12:02:14 | 000,079,400 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe


========== Modules (No Company Name) ==========

MOD - [2011.08.06 04:21:25 | 000,400,440 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Chrome\Application\13.0.782.112\ppgooglenaclpluginchrome.dll
MOD - [2011.08.06 04:21:24 | 004,118,072 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Chrome\Application\13.0.782.112\pdf.dll
MOD - [2011.08.06 04:20:16 | 000,327,736 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Chrome\Application\13.0.782.112\Locales\cs.dll
MOD - [2011.08.06 04:19:58 | 000,104,520 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Chrome\Application\13.0.782.112\avutil-50.dll
MOD - [2011.08.06 04:19:56 | 000,203,848 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Chrome\Application\13.0.782.112\avformat-52.dll
MOD - [2011.08.06 04:19:55 | 001,846,344 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Chrome\Application\13.0.782.112\avcodec-52.dll
MOD - [2011.08.06 02:29:30 | 006,338,720 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Chrome\Application\13.0.782.112\gcswf32.dll
MOD - [2011.08.05 07:41:47 | 014,401,832 | ---- | M] () -- C:\Program Files\Steam\bin\libcef.dll
MOD - [2011.08.05 07:41:44 | 000,190,248 | ---- | M] () -- C:\Program Files\Steam\bin\chromehtml.dll
MOD - [2011.08.05 07:41:43 | 000,914,216 | ---- | M] () -- C:\Program Files\Steam\bin\avcodec-52.dll
MOD - [2011.08.05 07:41:43 | 000,155,432 | ---- | M] () -- C:\Program Files\Steam\bin\avformat-52.dll
MOD - [2011.08.05 07:41:43 | 000,091,432 | ---- | M] () -- C:\Program Files\Steam\bin\avutil-50.dll
MOD - [2011.01.05 10:18:56 | 000,733,184 | ---- | M] () -- C:\Program Files\ICQ7.1\MDb.dll
MOD - [2010.09.22 21:12:20 | 000,016,832 | ---- | M] () -- C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll
MOD - [2010.09.16 22:04:50 | 000,095,528 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2010.09.16 22:04:06 | 001,164,584 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2010.01.03 17:07:48 | 000,246,520 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
MOD - [2009.11.20 14:45:06 | 000,294,912 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\Calendar.dll
MOD - [2009.11.17 14:03:10 | 000,745,472 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\MmsKrnl.dll
MOD - [2009.10.13 09:45:30 | 000,225,280 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\VistaCalendar.dll
MOD - [2009.10.05 16:54:20 | 000,200,704 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\LogoEdit.dll
MOD - [2009.07.29 11:43:08 | 000,155,648 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\CAgdLNote.dll
MOD - [2009.06.24 15:48:04 | 000,282,624 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\Messaging.dll
MOD - [2009.06.16 17:10:48 | 000,155,648 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\Contacts.dll
MOD - [2009.06.03 17:25:48 | 000,053,248 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\VObject.dll
MOD - [2009.04.30 11:23:26 | 000,090,112 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
MOD - [2009.04.28 11:17:58 | 000,208,896 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\CAgdOutlook.dll
MOD - [2009.04.01 08:33:10 | 000,106,496 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\CalEngine.dll
MOD - [2009.03.26 15:41:32 | 000,315,392 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\MelodyEdit.dll
MOD - [2009.02.14 05:04:38 | 000,756,040 | ---- | M] () -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL
MOD - [2008.11.07 15:05:06 | 000,196,608 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\Report.dll
MOD - [2008.10.26 05:42:14 | 000,065,376 | ---- | M] () -- C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll
MOD - [2008.06.20 18:04:19 | 000,247,296 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.dll
MOD - [2008.04.14 14:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008.01.29 12:25:10 | 000,602,112 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
MOD - [2008.01.29 12:24:46 | 000,163,840 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
MOD - [2008.01.29 12:18:40 | 000,454,656 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll
MOD - [2008.01.29 12:17:38 | 000,102,400 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll
MOD - [2007.05.10 22:25:20 | 002,469,888 | ---- | M] () -- C:\Program Files\Adobe\Acrobat 8.0\PDFMaker\Common\AdobePDFMakerX.dll
MOD - [2006.10.27 15:35:18 | 000,436,512 | ---- | M] () -- C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll
MOD - [2006.07.22 23:49:26 | 000,005,376 | ---- | M] () -- C:\WINDOWS\system32\antiwpa.dll
MOD - [2004.05.25 16:06:58 | 000,417,792 | ---- | M] () -- C:\WINDOWS\system32\ac3filter.ax


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (SpyEmrgSrv)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011.03.16 10:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.01.12 16:44:02 | 000,033,584 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2011.01.12 16:41:42 | 000,810,144 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2010.12.09 20:56:09 | 000,028,766 | ---- | M] (SmileyCentral) [Auto | Stopped] -- C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbarsvc.exe -- (SmileyCentralIE_1wService)
SRV - [2010.07.29 09:50:16 | 000,238,952 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010.06.12 11:09:52 | 000,656,896 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Running] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.01.03 17:07:48 | 000,246,520 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.04.30 11:23:26 | 000,090,112 | ---- | M] () [Auto | Running] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- (OMSI download service)
SRV - [2008.04.07 09:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008.01.29 12:25:10 | 000,602,112 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2008.01.29 12:24:46 | 000,163,840 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp)


========== Driver Services (SafeList) ==========

DRV - [2011.07.06 19:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010.12.21 15:04:06 | 000,141,264 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2010.12.21 15:04:06 | 000,115,008 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010.12.21 13:47:38 | 000,134,000 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epfw.sys -- (epfw)
DRV - [2010.12.21 13:47:38 | 000,033,120 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2010.08.03 12:28:36 | 000,055,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdi.sys -- (epfwtdi)
DRV - [2010.06.14 02:32:54 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010.05.17 15:12:06 | 000,697,328 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010.05.08 15:59:30 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2010.04.27 04:25:16 | 000,123,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2010.04.27 04:25:16 | 000,098,432 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV - [2010.04.27 04:25:16 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV - [2008.05.02 11:58:12 | 000,017,536 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2007.11.27 20:06:42 | 004,630,016 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.11.17 15:43:56 | 000,022,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2007.11.17 15:43:46 | 000,054,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2007.10.12 15:53:10 | 000,013,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2007.09.17 15:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2006.07.01 22:42:58 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.11.03 16:40:07 | 000,063,488 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2005.08.10 14:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005.05.16 15:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2001.08.17 21:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie


IE - HKU\.DEFAULT\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\20101006190848\ICQToolBar.dll (ICQ)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\20101006190848\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\..\URLSearchHook: {339a0dff-d9af-439b-92bc-636220fb3dae} - C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wSrcAs.dll (SmileyCentral)
IE - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\20101006190848\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..network.proxy.type: 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@comrade.gamespy.com/comrade: C:\Program Files\GameSpy\Comrade\npcomrade.dll (IGN Entertainment)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Obyvák\Data aplikací\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.07.23 14:42:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2011.08.19 21:23:46 | 000,000,000 | ---D | M]

[2011.07.23 14:42:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Obyvák\Data aplikací\Mozilla\Extensions
[2011.07.23 14:42:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2010.05.17 11:17:59 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010.07.09 14:15:09 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011.07.08 09:29:03 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.01.01 10:00:00 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2010.01.01 10:00:00 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2010.01.01 10:00:00 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2010.01.01 10:00:00 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2010.01.01 10:00:00 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2011.08.19 17:34:25 | 000,202,984 | -H-- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 facebook.com
O1 - Hosts: 127.0.0.1 www.facebook.com
O1 - Hosts: 127.0.0.1 af-za.facebook.com
O1 - Hosts: 127.0.0.1 az-az.facebook.com
O1 - Hosts: 127.0.0.1 id-id.facebook.com
O1 - Hosts: 127.0.0.1 ms-my.facebook.com
O1 - Hosts: 127.0.0.1 bs-ba.facebook.com
O1 - Hosts: 127.0.0.1 ca-es.facebook.com
O1 - Hosts: 127.0.0.1 cs-cz.facebook.com
O1 - Hosts: 127.0.0.1 cy-gb.facebook.com
O1 - Hosts: 127.0.0.1 da-dk.facebook.com
O1 - Hosts: 127.0.0.1 de-de.facebook.com
O1 - Hosts: 127.0.0.1 et-ee.facebook.com
O1 - Hosts: 127.0.0.1 en-gb.facebook.com
O1 - Hosts: 127.0.0.1 es-la.facebook.com
O1 - Hosts: 127.0.0.1 eo-eo.facebook.com
O1 - Hosts: 127.0.0.1 eu-es.facebook.com
O1 - Hosts: 127.0.0.1 tl-ph.facebook.com
O1 - Hosts: 127.0.0.1 fo-fo.facebook.com
O1 - Hosts: 127.0.0.1 fr-fr.facebook.com
O1 - Hosts: 127.0.0.1 fy-nl.facebook.com
O1 - Hosts: 127.0.0.1 ga-ie.facebook.com
O1 - Hosts: 127.0.0.1 gl-es.facebook.com
O1 - Hosts: 127.0.0.1 ko-kr.facebook.com
O1 - Hosts: 50053 more lines...
O2 - BHO: (Podpora odkazu pro Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Toolbar BHO) - {55cde9e7-696c-47c4-8e21-7210b8aeb103} - C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbar.dll (SmileyCentral)
O2 - BHO: (Search Assistant BHO) - {5ed22e89-62fa-47ec-bd8d-374d849d436c} - C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wSrcAs.dll (SmileyCentral)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (Ask Toolbar BHO) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (Ask.com)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\20101006190848\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (SmileyCentral) - {d3ca5551-fc2e-4d09-8ece-263607acf9fc} - C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbar.dll (SmileyCentral)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (Ask.com)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\..\Toolbar\WebBrowser: (SmileyCentral) - {D3CA5551-FC2E-4D09-8ECE-263607ACF9FC} - C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbar.dll (SmileyCentral)
O3 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\..\Toolbar\WebBrowser: (Ask Toolbar) - {FE063DB9-4EC0-403E-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (Ask.com)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [4StoryPrePatch] C:\Program Files\Gameforge4D\4Story\PrePatch.exe (Zamiinc)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SmileyCentralIE_1w Browser Plugin Loader] C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbrmon.exe (SmileyCentral)
O4 - HKLM..\Run: [tray_ico] File not found
O4 - HKLM..\Run: [tray_ico1] File not found
O4 - HKLM..\Run: [tray_ico2] File not found
O4 - HKLM..\Run: [tray_ico3] File not found
O4 - HKLM..\Run: [tray_ico4] File not found
O4 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004..\Run: [ICQ] C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
O4 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004..\Run: [SpyEmergency] File not found
O4 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKLM..\RunOnce: [SmileyCentral Installer] C:\Program Files\SmileyCentralIE_1w\bar\setups\SmileyCentral Installer(00ae68dd).exe (SmileyCentral)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Aktualizovat ESET licenci.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1454471165-152049171-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\nvLsp.dll (NVIDIA)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 88.146.135.10 217.11.242.22 213.29.58.9
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\Antiwpa: DllName - antiwpa.dll - C:\WINDOWS\System32\antiwpa.dll ()
O24 - Desktop Components:0 () - http://www.email.cz/getAttachment?sessi ... %F5%A3%10s
O24 - Desktop Components:1 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O31 - SafeBoot: AlternateShell - services32.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.05.08 14:09:56 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

SafeBootMin: AppMgmt - File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PEVSystemStart - Service
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: procexp90.Sys - Driver
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: AppMgmt - File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PEVSystemStart - Service
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: procexp90.Sys - Driver
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} -
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2011.08.20 17:03:54 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.08.20 17:03:54 | 000,000,000 | ---D | C] -- C:\rsit
[2011.08.20 16:02:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Obyvák\Data aplikací\PCToolsFirewallPlus
[2011.08.20 15:43:27 | 002,029,520 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll
[2011.08.20 15:43:27 | 001,533,904 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDRes.dll
[2011.08.20 15:43:27 | 000,149,456 | ---- | C] (PC Tools) -- C:\WINDOWS\SGDetectionTool.dll
[2011.08.20 15:41:59 | 000,656,320 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctEFA.sys
[2011.08.20 15:41:59 | 000,338,880 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctDS.sys
[2011.08.20 15:41:58 | 000,253,096 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2011.08.20 15:41:53 | 000,263,888 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2011.08.20 15:41:53 | 000,160,576 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2011.08.20 15:41:52 | 000,233,976 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTSD.sys
[2011.08.20 15:41:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\PC Tools Security
[2011.08.20 15:41:50 | 000,070,664 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2011.08.20 15:25:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\MediaGet2
[2011.08.20 15:20:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter
[2011.08.20 14:48:58 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools Security
[2011.08.20 14:48:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2011.08.20 14:47:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\PC Tools
[2011.08.20 13:32:18 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Obyvák\Recent
[2011.08.20 13:13:38 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.08.20 12:53:26 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Obyvák\Plocha\OTL (1).exe
[2011.08.20 11:50:33 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011.08.20 11:48:47 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011.08.20 11:48:47 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011.08.20 11:48:47 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011.08.20 11:48:47 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011.08.20 11:48:42 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011.08.20 11:46:28 | 000,390,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF15156.exe
[2011.08.20 11:46:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011.08.20 11:33:36 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.08.20 11:33:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Obyvák\Nabídka Start\Programy\Nástroje pro správu
[2011.08.20 10:14:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Obyvák\Data aplikací\Malwarebytes
[2011.08.20 10:14:21 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.08.20 10:14:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.08.20 10:14:17 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.08.20 10:14:17 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.08.19 21:23:45 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011.08.19 21:23:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2011.08.19 16:33:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\update.7.1
[2011.08.19 12:07:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\ufa
[2011.08.19 12:07:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\rpcminer
[2011.08.19 12:07:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\phoenix
[2011.08.19 11:58:06 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.5.0
[2011.08.19 11:57:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Data aplikací\WinRAR
[2011.08.19 11:57:34 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.2
[2011.08.19 11:56:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\av_ico
[2011.08.19 11:54:15 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.1
[2011.08.19 11:54:02 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-3-0-lnk
[2011.08.19 11:54:02 | 000,000,000 | -H-D | C] -- C:\WINDOWS\update.tray-3-0
[2011.08.15 06:29:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Avanquest
[2011.08.09 21:58:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Obyvák\Plocha\TRENČÍN
[2011.08.09 17:18:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Ubisoft
[2011.07.27 08:04:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Obyvák\Plocha\Bobří pohár ceny_files
[2011.07.25 10:37:48 | 000,000,000 | ---D | C] -- C:\HryMafia
[2011.07.24 17:41:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Obyvák\Plocha\Mencl
[2011.07.23 14:42:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Mozilla
[2011.07.23 14:42:01 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2010.08.20 20:33:59 | 000,567,816 | ---- | C] (Google Inc.) -- C:\Program Files\googleupdatesetup.exe
[2010.08.15 14:16:50 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\Documents and Settings\All Users\Data aplikací\hpe1FC5.dll
[2010.07.29 20:28:19 | 020,615,928 | ---- | C] (Jadris ) -- C:\Program Files\qip 2010.exe
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\*.tmp files -> C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\*.tmp -> ]
[18 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011.08.21 20:47:08 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2011.08.21 20:27:00 | 000,001,030 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-152049171-1801674531-1004UA.job
[2011.08.21 19:59:00 | 000,000,940 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011.08.21 17:59:00 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011.08.21 12:27:07 | 000,004,420 | ---- | M] () -- C:\WINDOWS\WINCMD.INI
[2011.08.21 11:27:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-152049171-1801674531-1004Core.job
[2011.08.21 07:46:15 | 000,276,202 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2011.08.21 07:43:05 | 000,000,000 | ---- | M] () -- C:\WINDOWS\4291322254
[2011.08.21 07:43:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.08.20 16:04:04 | 000,639,522 | ---- | M] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2011.08.20 15:41:53 | 000,001,684 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Spyware Doctor.lnk
[2011.08.20 15:25:50 | 000,368,023 | ---- | M] () -- C:\Documents and Settings\Obyvák\Dokumenty\PC Tools Spyware Doctor 8.0.0.651 + Key.rar
[2011.08.20 15:21:10 | 000,000,974 | ---- | M] () -- C:\Documents and Settings\Obyvák\Plocha\FileHunter.lnk
[2011.08.20 14:47:49 | 000,512,992 | ---- | M] () -- C:\Documents and Settings\Obyvák\Plocha\sdsetup.exe
[2011.08.20 14:30:17 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011.08.20 13:48:47 | 000,007,800 | ---- | M] () -- C:\Documents and Settings\Obyvák\Dokumenty\cc_20110820_134837.reg
[2011.08.20 12:53:31 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Obyvák\Plocha\OTL (1).exe
[2011.08.20 12:09:23 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.08.20 12:02:20 | 2145,386,496 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2011.08.20 11:50:40 | 000,000,343 | RHS- | M] () -- C:\boot.ini
[2011.08.20 11:46:24 | 000,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF15156.exe
[2011.08.20 10:14:21 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.08.20 08:43:54 | 000,001,000 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\SRDownloader (3).nast
[2011.08.19 21:25:19 | 000,000,819 | ---- | M] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Aktualizovat ESET licenci.lnk
[2011.08.19 21:25:19 | 000,000,789 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Aktualizovat ESET licenci.lnk
[2011.08.19 20:17:37 | 000,000,920 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\SRDownloader.nast
[2011.08.19 20:15:29 | 000,055,624 | ---- | M] () -- C:\Documents and Settings\Obyvák\Dokumenty\cc_20110819_201513.reg
[2011.08.19 17:34:25 | 000,202,984 | -H-- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011.08.19 17:34:25 | 000,000,734 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hîsts
[2011.08.19 16:33:30 | 000,000,178 | ---- | M] () -- C:\WINDOWS\info1
[2011.08.19 12:07:30 | 005,589,370 | ---- | M] () -- C:\WINDOWS\phoenix.rar
[2011.08.19 12:07:30 | 001,075,284 | ---- | M] () -- C:\WINDOWS\rpcminer.rar
[2011.08.19 12:07:30 | 000,246,272 | ---- | M] () -- C:\WINDOWS\unrar.exe
[2011.08.19 12:07:30 | 000,182,617 | ---- | M] () -- C:\WINDOWS\ufa.rar
[2011.08.19 11:57:42 | 000,904,792 | ---- | M] () -- C:\WINDOWS\geoiplist.rar
[2011.08.19 11:57:25 | 000,000,000 | ---- | M] () -- C:\WINDOWS\loader2.exe_ok
[2011.08.19 11:54:25 | 000,000,227 | ---- | M] () -- C:\Boot.bak
[2011.08.18 13:40:30 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2011.08.18 06:48:11 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\{79D5C5C1-48B1-42DC-9E96-D7E45D0BBE23}
[2011.08.16 11:23:30 | 000,002,266 | ---- | M] () -- C:\Documents and Settings\Obyvák\Plocha\Google Chrome.lnk
[2011.08.12 07:44:15 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\{BF79CE97-6362-4241-8D9D-F678044D7030}
[2011.08.12 07:44:02 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\{FD41F09D-1CAE-44F5-9268-0D171F2F28AE}
[2011.08.10 23:46:55 | 000,444,600 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.08.10 23:46:55 | 000,441,522 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2011.08.10 23:46:55 | 000,084,178 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2011.08.10 23:46:55 | 000,072,476 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.08.10 23:45:17 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011.08.09 17:26:54 | 000,000,209 | ---- | M] () -- C:\Documents and Settings\Obyvák\Plocha\Assassin's Creed II.url
[2011.08.09 17:18:52 | 000,001,821 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Assassin's Creed II.lnk
[2011.08.02 11:37:30 | 000,000,789 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Průzkumník licencí MiNODLogin.lnk
[2011.08.02 08:46:36 | 000,000,801 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\MiNODServer.lnk
[2011.08.01 11:42:36 | 000,006,287 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\SRDownloader (3).err
[2011.07.28 21:42:23 | 000,000,246 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\SRDownloader.err
[2011.07.25 17:08:54 | 005,969,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2011.07.25 10:35:20 | 000,038,400 | ---- | M] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.07.24 17:39:00 | 001,606,732 | ---- | M] () -- C:\Documents and Settings\Obyvák\Plocha\NP579-m.zip
[2011.07.23 14:42:07 | 000,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2011.07.23 14:42:03 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Mozilla Firefox.lnk
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\*.tmp files -> C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\*.tmp -> ]
[18 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.08.20 15:43:28 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
[2011.08.20 15:43:27 | 000,002,125 | ---- | C] () -- C:\WINDOWS\UDB.zip
[2011.08.20 15:43:27 | 000,000,882 | ---- | C] () -- C:\WINDOWS\RegSDImport.xml
[2011.08.20 15:43:27 | 000,000,879 | ---- | C] () -- C:\WINDOWS\RegISSImport.xml
[2011.08.20 15:43:27 | 000,000,131 | ---- | C] () -- C:\WINDOWS\IDB.zip
[2011.08.20 15:41:53 | 000,001,684 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Spyware Doctor.lnk
[2011.08.20 15:25:46 | 000,368,023 | ---- | C] () -- C:\Documents and Settings\Obyvák\Dokumenty\PC Tools Spyware Doctor 8.0.0.651 + Key.rar
[2011.08.20 15:20:02 | 000,000,974 | ---- | C] () -- C:\Documents and Settings\Obyvák\Plocha\FileHunter.lnk
[2011.08.20 15:17:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\4291322254
[2011.08.20 14:49:33 | 000,639,522 | ---- | C] () -- C:\WINDOWS\System32\drivers\Cat.DB
[2011.08.20 14:47:51 | 000,512,992 | ---- | C] () -- C:\Documents and Settings\Obyvák\Plocha\sdsetup.exe
[2011.08.20 13:48:38 | 000,007,800 | ---- | C] () -- C:\Documents and Settings\Obyvák\Dokumenty\cc_20110820_134837.reg
[2011.08.20 11:50:39 | 000,000,227 | ---- | C] () -- C:\Boot.bak
[2011.08.20 11:50:36 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2011.08.20 11:48:47 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011.08.20 11:48:47 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011.08.20 11:48:47 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011.08.20 11:48:47 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011.08.20 11:48:47 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011.08.20 10:14:21 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.08.20 10:04:56 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2011.08.19 20:15:15 | 000,055,624 | ---- | C] () -- C:\Documents and Settings\Obyvák\Dokumenty\cc_20110819_201513.reg
[2011.08.19 12:07:30 | 005,589,370 | ---- | C] () -- C:\WINDOWS\phoenix.rar
[2011.08.19 12:07:30 | 001,075,284 | ---- | C] () -- C:\WINDOWS\rpcminer.rar
[2011.08.19 12:07:30 | 000,182,617 | ---- | C] () -- C:\WINDOWS\ufa.rar
[2011.08.19 11:57:43 | 004,636,907 | ---- | C] () -- C:\WINDOWS\geoiplist
[2011.08.19 11:57:42 | 000,904,792 | ---- | C] () -- C:\WINDOWS\geoiplist.rar
[2011.08.19 11:57:42 | 000,246,272 | ---- | C] () -- C:\WINDOWS\unrar.exe
[2011.08.19 11:57:34 | 000,000,178 | ---- | C] () -- C:\WINDOWS\info1
[2011.08.19 11:57:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\loader2.exe_ok
[2011.08.18 06:48:11 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\{79D5C5C1-48B1-42DC-9E96-D7E45D0BBE23}
[2011.08.12 07:44:15 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\{BF79CE97-6362-4241-8D9D-F678044D7030}
[2011.08.12 07:44:02 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\{FD41F09D-1CAE-44F5-9268-0D171F2F28AE}
[2011.08.09 17:26:54 | 000,000,209 | ---- | C] () -- C:\Documents and Settings\Obyvák\Plocha\Assassin's Creed II.url
[2011.08.09 17:18:52 | 000,001,821 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Assassin's Creed II.lnk
[2011.08.02 09:11:36 | 000,000,789 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Průzkumník licencí MiNODLogin.lnk
[2011.08.02 08:46:36 | 000,000,801 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\MiNODServer.lnk
[2011.07.24 17:40:37 | 001,606,732 | ---- | C] () -- C:\Documents and Settings\Obyvák\Plocha\NP579-m.zip
[2011.07.23 14:42:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011.07.23 14:42:03 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Mozilla Firefox.lnk
[2011.07.03 11:30:20 | 000,000,246 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\SRDownloader.err
[2011.07.03 11:22:10 | 000,000,920 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\SRDownloader.nast
[2011.06.10 13:46:09 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\{39B69F4B-B702-4471-87B0-A12B778BE790}
[2011.06.10 13:45:53 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\{9FAB2FAA-7274-4525-8EEB-03BD29240579}
[2011.05.02 06:18:38 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\{998CF610-0AB7-4CC9-9484-1ADB827A5B5A}
[2011.05.02 06:18:28 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\{257F78BA-D19A-4F48-BA09-2CCE13FF05FC}
[2011.04.23 22:10:00 | 000,000,394 | ---- | C] () -- C:\WINDOWS\capture.ini
[2011.04.15 19:01:58 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2011.04.09 18:55:28 | 000,179,261 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2010.11.21 14:14:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2010.11.13 23:26:57 | 000,309,184 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2010.10.29 09:51:44 | 000,138,056 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010.10.29 09:51:44 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Obyvák\Data aplikací\PnkBstrK.sys
[2010.10.29 09:47:57 | 000,189,248 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2010.10.29 09:47:56 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2010.10.29 09:47:55 | 002,601,752 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_moh.exe
[2010.10.26 06:50:41 | 000,006,287 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\SRDownloader (3).err
[2010.10.23 10:28:28 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010.10.23 10:28:28 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010.10.23 10:28:21 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Obyvák\Data aplikací\$_hpcst$.hpc
[2010.10.10 15:44:32 | 000,001,000 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\SRDownloader (3).nast
[2010.09.28 10:53:21 | 000,002,857 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\SRDownloader (2).err
[2010.09.28 10:47:06 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\SRDownloader (2).nast
[2010.08.28 10:34:10 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\prfh0405.dat
[2010.08.28 10:34:10 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\prfc0405.dat
[2010.08.26 08:00:42 | 018,591,058 | ---- | C] () -- C:\Program Files\csm podzim09.exe
[2010.08.24 07:40:07 | 000,001,205 | ---- | C] () -- C:\WINDOWS\disney.ini
[2010.06.13 16:54:52 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.06.05 09:37:32 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010.06.05 09:37:30 | 000,038,400 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.06.02 19:37:10 | 000,302,592 | ---- | C] () -- C:\WINDOWS\mauninst.exe
[2010.05.31 19:01:25 | 000,000,082 | ---- | C] () -- C:\Documents and Settings\Obyvák\Data aplikací\default.pls
[2010.05.17 15:24:11 | 000,005,376 | ---- | C] () -- C:\WINDOWS\System32\antiwpa.dll
[2010.05.15 15:49:22 | 000,075,932 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
[2010.05.15 15:49:22 | 000,074,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
[2010.05.15 15:49:09 | 000,202,784 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2010.05.15 15:49:09 | 000,006,944 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2010.05.13 19:44:29 | 000,003,636 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2010.05.12 16:06:31 | 000,000,412 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2010.05.10 21:48:11 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.05.10 21:40:01 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2010.05.10 20:08:06 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2010.05.10 19:58:54 | 000,004,420 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2010.05.08 15:51:34 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010.05.08 15:50:39 | 000,278,944 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.05.08 15:17:30 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\fusioncache.dat
[2010.05.08 14:11:07 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010.05.08 14:07:56 | 000,023,544 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010.04.03 22:55:32 | 002,183,470 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2008.04.14 14:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008.04.14 14:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008.04.14 14:00:00 | 000,444,600 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008.04.14 14:00:00 | 000,441,522 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2008.04.14 14:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008.04.14 14:00:00 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2008.04.14 14:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008.04.14 14:00:00 | 000,084,178 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2008.04.14 14:00:00 | 000,072,476 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008.04.14 14:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008.04.14 14:00:00 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2008.04.14 14:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008.04.14 14:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008.04.14 14:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008.04.14 14:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008.04.14 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2007.10.25 17:26:10 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2007.03.09 20:58:06 | 000,025,734 | ---- | C] () -- C:\WINDOWS\System32\drivers\klop.dat
[2005.10.14 11:56:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 11:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 11:56:50 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 11:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 11:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005.10.14 11:56:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 11:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 11:56:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2005.10.14 11:56:48 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\MMSwitch.dll
[2005.10.14 11:56:48 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\MMAVILNG.exe
[2002.01.07 15:45:58 | 000,000,091 | ---- | C] () -- C:\WINDOWS\LSD.INI

========== LOP Check ==========

[2011.03.19 14:53:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alternative Software Ltd
[2011.08.15 06:29:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Avanquest
[2010.08.15 14:17:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\BVRP Software
[2010.05.12 16:03:47 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2011.05.29 12:48:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Codemasters
[2010.05.11 21:24:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.05.12 14:12:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Pro
[2011.05.29 12:48:39 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\DSS
[2011.08.18 22:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Easybits GO
[2011.08.09 11:15:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
[2011.08.19 21:23:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.05.10 21:16:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2010.10.24 14:50:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2010.10.23 12:35:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Samsung
[2010.05.12 16:06:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ScanSoft
[2011.08.21 07:38:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2010.12.10 21:04:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Ubisoft
[2011.07.23 16:51:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\.minecraft
[2010.12.26 11:40:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Alternative Software Ltd
[2010.10.08 19:03:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\BlackBean
[2011.05.21 07:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Canon
[2010.05.12 16:25:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Canon Easy-WebPrint EX
[2010.06.20 14:04:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\DAEMON Tools Lite
[2010.05.17 15:16:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\DAEMON Tools Pro
[2010.05.10 19:56:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\ESET
[2010.05.17 11:56:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Facebook
[2011.08.20 15:20:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter
[2011.08.18 13:40:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\go
[2011.08.21 07:46:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\ICQ
[2010.11.16 23:13:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Itsth
[2010.10.03 10:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Leadertech
[2010.05.11 20:48:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Opera
[2010.10.23 10:44:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\PC Suite
[2011.08.20 16:05:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\PCToolsFirewallPlus
[2010.10.23 10:28:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Samsung
[2010.05.12 16:06:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\ScanSoft
[2010.12.10 21:04:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Ubisoft
[2011.05.17 19:05:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Unity
[2010.08.29 09:24:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\WORK

========== Purity Check ==========



========== Custom Scans ==========


< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 14:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation)
"swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -- [2010.05.12 07:08:41 | 000,039,408 | ---- | M] (Google Inc.)
"MSMSGS" = "C:\Program Files\Messenger\msmsgs.exe" /background -- [2008.04.14 08:52:38 | 001,695,232 | ---- | M] (Microsoft Corporation)
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 -- [2008.06.24 16:06:06 | 001,840,424 | ---- | M] (Nero AG)
"DAEMON Tools Lite" = "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun -- [2010.04.01 11:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd)
"Sony Ericsson PC Suite" = "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon -- [2009.11.20 10:17:12 | 000,434,176 | ---- | M] (Sony Ericsson Mobile Communications AB)
"AutoStartNPSAgent" = C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe -- [2010.07.29 09:47:08 | 000,095,576 | ---- | M] (Samsung Electronics Co., Ltd.)
"ICQ" = "C:\Program Files\ICQ7.1\ICQ.exe" silent loginmode=4 -- [2011.01.05 10:18:50 | 000,133,432 | ---- | M] (ICQ, LLC.)
"Steam" = "C:\Program Files\Steam\Steam.exe" -silent -- [2011.08.04 07:17:26 | 001,242,448 | ---- | M] (Valve Corporation)
"Google Update" = "C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c -- [2011.08.05 17:54:32 | 000,136,176 | ---- | M] (Google Inc.)
"SpyEmergency" = C:\Program Files\NETGATE\Spy Emergency\SpyEmergency.exe

Re: Vir- facebook

Napsal: 21 srp 2011 19:56
od ruza71
< MD5 for: ATAPI.SYS >
[2008.04.14 14:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 14:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 14:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2008.04.14 14:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\dllcache\autochk.exe

< MD5 for: CDROM.SYS >
[2008.04.14 14:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.14 14:00:00 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CSRSS.EXE >
[2008.04.14 08:52:18 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\ServicePackFiles\i386\csrss.exe
[2008.04.14 14:00:00 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\system32\csrss.exe
[2008.04.14 14:00:00 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\system32\dllcache\csrss.exe

< MD5 for: EXPLORER.EXE >
[2008.04.14 14:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008.04.14 14:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: LSASS.EXE >
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.14 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys
[2008.04.14 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: NTFS.SYS >
[2008.04.14 00:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\ServicePackFiles\i386\ntfs.sys
[2008.04.14 14:00:00 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\dllcache\ntfs.sys
[2008.04.14 14:00:00 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\drivers\ntfs.sys
[2004.08.03 23:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\cmdcons\NTFS.SYS

< MD5 for: SCECLI.DLL >
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 14:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 14:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2009.02.09 13:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009.02.09 13:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 13:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\services.exe
[2008.04.14 14:00:00 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008.04.14 08:52:46 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\ServicePackFiles\i386\services.exe

< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe

< MD5 for: SPOOLSV.EXE >
[2010.08.17 15:19:36 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 -- C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[2010.08.17 15:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\dllcache\spoolsv.exe
[2010.08.17 15:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\spoolsv.exe
[2008.04.14 14:00:00 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=CB1090BCA0E7B40D0B5B4E4D66531809 -- C:\WINDOWS\$NtUninstallKB2347290$\spoolsv.exe
[2008.04.14 08:52:50 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=CB1090BCA0E7B40D0B5B4E4D66531809 -- C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe

< MD5 for: SVCHOST.EXE >
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.14 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.04.14 14:00:00 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 14:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 14:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 14:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 14:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >
[2006.12.25 22:00:00 | 000,027,136 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8R.DLL
[2007.05.22 05:00:00 | 000,027,136 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD94.DLL
[2006.12.25 22:00:00 | 000,069,632 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8R.DLL
[2007.05.22 05:00:00 | 000,069,632 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP94.DLL
[2008.07.06 14:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006.10.26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008.07.06 14:06:10 | 000,147,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\x64\filterpipelineprintproc.dll

< %systemroot%\system32\drivers\*.sys /5 >

< %systemroot%\system32\drivers\*.sys /X >
[2008.04.14 08:51:38 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv01nt5.dll
[2008.04.14 08:51:38 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv02nt5.dll
[2008.04.14 08:51:38 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv05nt5.dll
[2008.04.14 08:51:38 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv07nt5.dll
[2008.04.14 08:51:38 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv08nt5.dll
[2008.04.14 08:51:38 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv09nt5.dll
[2008.04.14 08:51:38 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv11nt5.dll
[2006.12.29 20:21:08 | 000,064,352 | ---- | M] () -- C:\WINDOWS\system32\drivers\ativmc20.cod
[2008.04.14 08:51:38 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv01nt5.dll
[2008.04.14 08:51:38 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv02nt5.dll
[2008.04.14 08:51:38 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv04nt5.dll
[2008.04.14 08:51:38 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv06nt5.dll
[2008.04.14 08:51:38 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv10nt5.dll
[2011.08.20 16:04:04 | 000,639,522 | ---- | M] () -- C:\WINDOWS\system32\drivers\Cat.DB
[2008.04.14 08:51:40 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
[2007.04.02 21:36:04 | 000,129,045 | ---- | M] () -- C:\WINDOWS\system32\drivers\cxthsfs2.cty
[2010.05.15 19:46:51 | 000,202,784 | -HS- | M] () -- C:\WINDOWS\system32\drivers\fidbox.dat
[2010.05.15 19:46:11 | 000,003,380 | -HS- | M] () -- C:\WINDOWS\system32\drivers\fidbox.idx
[2010.05.15 20:07:29 | 000,006,944 | -HS- | M] () -- C:\WINDOWS\system32\drivers\fidbox2.dat
[2010.05.15 19:46:11 | 000,001,628 | -HS- | M] () -- C:\WINDOWS\system32\drivers\fidbox2.idx
[2008.04.14 14:00:00 | 003,440,660 | ---- | M] () -- C:\WINDOWS\system32\drivers\gm.dls
[2008.04.14 14:00:00 | 000,000,646 | ---- | M] () -- C:\WINDOWS\system32\drivers\gmreadme.txt
[2010.05.15 15:49:22 | 000,075,932 | ---- | M] () -- C:\WINDOWS\system32\drivers\klick.dat
[2010.05.15 15:49:22 | 000,074,396 | ---- | M] () -- C:\WINDOWS\system32\drivers\klin.dat
[2007.03.09 20:58:06 | 000,025,734 | ---- | M] () -- C:\WINDOWS\system32\drivers\klop.dat
[2011.01.28 14:57:18 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2011.01.28 14:57:21 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
[2006.12.29 20:02:50 | 000,067,866 | ---- | M] () -- C:\WINDOWS\system32\drivers\netwlan5.img
[2007.11.17 15:22:04 | 000,003,636 | ---- | M] () -- C:\WINDOWS\system32\drivers\nvphy.bin
[2008.04.14 08:51:56 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\siint5.dll
[2008.04.14 08:52:06 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\vchnt5.dll

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.05.17 15:12:06 | 000,697,328 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\system32\*.* /5 >
[2011.08.20 11:46:24 | 000,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\CF15156.exe
[2011.08.21 07:46:15 | 000,276,202 | ---- | M] () -- C:\WINDOWS\system32\NvApps.xml
[2011.08.20 12:09:23 | 000,002,278 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[18 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\*.dll /lockedfiles >
[18 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\config\*.sav >
[2010.05.08 17:29:37 | 000,524,288 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.05.08 15:24:28 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2010.05.08 17:29:37 | 011,272,192 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.05.08 17:29:37 | 002,621,440 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\*.* /U /s >
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[12 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\d075bf91c50a4232b7fe7eba84f1ecf7\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\d075bf91c50a4232b7fe7eba84f1ecf7\*.tmp -> ]
[18 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\*. /mp /s >

< %ALLUSERSPROFILE%\Data Aplikací\*.* >
[2010.05.08 15:30:46 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\desktop.ini
[2010.05.10 21:40:01 | 000,000,032 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\ezsid.dat
[2010.08.15 14:16:50 | 000,148,736 | ---- | M] (Avanquest Software) -- C:\Documents and Settings\All Users\Data Aplikací\hpe1FC5.dll

< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
[2010.06.27 13:55:19 | 000,056,969 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\ASPEncoder\Uninstaller.exe
[2010.06.27 13:55:27 | 000,057,409 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\ControlPanel\Uninstaller.exe
[2010.06.27 13:55:34 | 000,054,128 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Converter\Uninstaller.exe
[2010.10.16 12:21:35 | 000,054,153 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DFXPlugin\Uninstaller.exe
[2010.06.27 13:55:36 | 000,056,458 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DivXDecoderShortcut\Uninstaller.exe
[2010.10.16 12:22:11 | 000,056,765 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DivXPlusShortcuts\Uninstaller.exe
[2010.06.27 13:55:35 | 000,054,174 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSAACDecoder\Uninstaller.exe
[2010.06.27 13:55:37 | 000,057,532 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSASPDecoder\Uninstaller.exe
[2010.06.27 13:55:38 | 000,054,166 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSAVCDecoder\Uninstaller.exe
[2010.06.27 13:55:38 | 000,057,054 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSDesktopComponents\Uninstaller.exe
[2010.06.27 13:55:27 | 000,054,101 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\MPEG2Plugin\Uninstaller.exe
[2010.06.27 13:55:26 | 000,052,963 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\MSVC80CRTRedist\Uninstaller.exe
[2010.10.16 12:22:00 | 000,057,691 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Player\Uninstaller.exe
[2010.06.27 13:55:22 | 000,054,073 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Qt4.5\Uninstaller.exe
[2010.10.16 12:29:44 | 000,144,696 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\DivX\RunAsUser\RUNASUSERPROCESS.exe
[2010.10.16 11:52:06 | 000,876,824 | ---- | M] (DivX, Inc. ) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Setup\DivXSetup.exe
[2010.06.27 13:55:33 | 000,054,644 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\TranscodeEngine\Uninstaller.exe
[2010.10.16 12:21:38 | 000,084,038 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\TransferWizard\Uninstaller.exe
[2010.10.16 12:22:01 | 000,053,600 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Update\Uninstaller.exe
[2010.10.16 12:22:10 | 000,056,997 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\WebPlayer\Uninstaller.exe
[2011.07.11 09:55:47 | 000,348,544 | ---- | M] (EasyBits Software AS) -- C:\Documents and Settings\All Users\Data Aplikací\Easybits GO\EasyBitsGO.exe
[2011.07.11 09:55:48 | 000,014,208 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Easybits GO\ezShell64Run.exe
[2011.07.11 09:55:49 | 000,578,432 | ---- | M] (EasyBits Software AS) -- C:\Documents and Settings\All Users\Data Aplikací\Easybits GO\RemoveGO.exe
[2011.07.11 09:55:49 | 000,663,424 | ---- | M] (EasyBits Media) -- C:\Documents and Settings\All Users\Data Aplikací\Easybits GO\Svc\GOUpdate.exe
[2011.08.19 21:36:00 | 000,527,024 | ---- | M] (Google Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Google\Google Toolbar\Update\GoogleToolbarInstaller_updater_signed.exe
[2011.08.20 14:48:37 | 067,671,112 | ---- | M] (PC Tools ) -- C:\Documents and Settings\All Users\Data Aplikací\PC Tools\DownloadManager\Spyware Doctor8.0\sdsetup_dl.exe

< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >

< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >

< %APPDATA%\*. >
[2011.07.23 16:51:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\.minecraft
[2010.10.29 09:30:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Adobe
[2010.12.26 11:40:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Alternative Software Ltd
[2010.10.08 19:03:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\BlackBean
[2011.05.21 07:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Canon
[2010.05.12 16:25:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Canon Easy-WebPrint EX
[2011.04.23 22:06:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Corel
[2010.06.20 14:04:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\DAEMON Tools Lite
[2010.05.17 15:16:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\DAEMON Tools Pro
[2010.07.03 21:17:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\DivX
[2011.07.18 23:53:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\dvdcss
[2010.05.10 19:56:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\ESET
[2010.05.17 11:56:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Facebook
[2011.08.20 15:20:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter
[2011.08.18 13:40:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\go
[2010.08.20 20:40:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Google
[2010.05.13 18:40:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Help
[2011.08.21 07:46:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\ICQ
[2010.05.08 14:13:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Identities
[2010.05.10 20:04:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\InstallShield
[2010.11.16 23:13:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Itsth
[2010.10.03 10:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Leadertech
[2011.05.18 21:59:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Macromedia
[2011.08.20 10:14:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Malwarebytes
[2010.11.05 20:47:56 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Microsoft
[2011.07.23 14:42:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Mozilla
[2010.05.12 18:26:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Nero
[2010.08.28 12:52:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\NVIDIA
[2010.05.11 20:48:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Opera
[2010.10.23 10:44:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\PC Suite
[2011.08.20 16:05:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\PCToolsFirewallPlus
[2010.10.23 10:28:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Samsung
[2010.05.12 16:06:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\ScanSoft
[2011.08.18 22:04:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Skype
[2011.07.11 09:55:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\skypePM
[2010.05.17 11:17:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Sun
[2010.12.10 21:04:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Ubisoft
[2011.05.17 19:05:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Unity
[2011.07.24 11:30:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\vlc
[2010.05.12 16:40:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\WinRAR
[2010.08.29 09:24:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\WORK

< %APPDATA%\*.* >
[2010.10.23 10:28:21 | 000,002,528 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\$_hpcst$.hpc
[2011.04.20 10:28:20 | 000,000,082 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\default.pls
[2010.05.08 15:51:12 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\desktop.ini
[2010.08.29 09:24:19 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\LSDSet.Txt
[2001.03.05 02:05:48 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\Nic.txt
[2010.10.29 09:51:44 | 000,138,056 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\PnkBstrK.sys

< %APPDATA%\*.exe /s >
[2010.05.17 11:56:43 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Documents and Settings\Obyvák\Data aplikací\Facebook\uninstall.exe
[2011.07.05 16:33:22 | 001,371,248 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter\FileHunter.exe
[2011.06.29 20:40:00 | 001,658,480 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter\pumpa.exe
[2011.08.20 15:21:10 | 000,032,508 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter\uninstall.exe
[2011.07.17 22:32:58 | 000,810,096 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter\update.exe
[2010.10.29 09:47:59 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Documents and Settings\Obyvák\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2010.11.21 14:43:07 | 000,704,512 | ---- | M] (TODO: <Company name>) -- C:\Documents and Settings\Obyvák\Data aplikací\Samsung\New PC Studio\LiveUpdate\NPSUpdateAgent.exe
[2010.08.05 02:14:55 | 000,875,296 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\Obyvák\Data aplikací\Sun\Java\JRERunOnce.exe

< %SYSTEMDRIVE%\*.exe >
[2007.02.12 21:10:44 | 002,705,744 | ---- | M] (Microsoft Corporation) -- C:\VCREDI~3.EXE

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-10 21:47:05

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0\0

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
PENDINGFILERENAMEOPERATIONS REG_MULTI_SZ \??\C:\Program Files\SmileyCentralIE_1w\bar\setups\SmileyCentralAuto.exe\0\0\0

< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=AlwaysOff /fastdetect /usepmtimer

< *crack* >

< *keygen* >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB47457$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 816 bytes -> C:\WINDOWS\4291322254:1906194176.exe
@Alternate Data Stream - 6144 bytes -> C:\WINDOWS\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:430C6D84
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:C31F31E6
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8

< End of report >

Re: Vir- facebook

Napsal: 21 srp 2011 19:56
od ruza71
< MD5 for: ATAPI.SYS >
[2008.04.14 14:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.14 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 14:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\cmdcons\autochk.exe
[2008.04.14 08:52:12 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 14:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2008.04.14 14:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\dllcache\autochk.exe

< MD5 for: CDROM.SYS >
[2008.04.14 14:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008.04.14 09:10:02 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.14 00:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.14 14:00:00 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CSRSS.EXE >
[2008.04.14 08:52:18 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\ServicePackFiles\i386\csrss.exe
[2008.04.14 14:00:00 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\system32\csrss.exe
[2008.04.14 14:00:00 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=628CE66E3FD35BFC7969DBAC245DC069 -- C:\WINDOWS\system32\dllcache\csrss.exe

< MD5 for: EXPLORER.EXE >
[2008.04.14 14:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008.04.14 14:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: LSASS.EXE >
[2008.04.14 08:52:30 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2008.04.14 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2008.04.14 00:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.14 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys
[2008.04.14 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: NTFS.SYS >
[2008.04.14 00:45:54 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\ServicePackFiles\i386\ntfs.sys
[2008.04.14 14:00:00 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\dllcache\ntfs.sys
[2008.04.14 14:00:00 | 000,574,976 | ---- | M] (Microsoft Corporation) MD5=78A08DD6A8D65E697C18E1DB01C5CDCA -- C:\WINDOWS\system32\drivers\ntfs.sys
[2004.08.03 23:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\cmdcons\NTFS.SYS

< MD5 for: SCECLI.DLL >
[2008.04.14 08:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 14:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 14:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SERVICES.EXE >
[2009.02.09 13:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009.02.09 13:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 13:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\services.exe
[2008.04.14 14:00:00 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008.04.14 08:52:46 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\ServicePackFiles\i386\services.exe

< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE
[2008.04.14 08:52:48 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\dllcache\smss.exe
[2008.04.14 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe

< MD5 for: SPOOLSV.EXE >
[2010.08.17 15:19:36 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=258DD5D4283FD9F9A7166BE9AE45CE73 -- C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[2010.08.17 15:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\dllcache\spoolsv.exe
[2010.08.17 15:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) MD5=60784F891563FB1B767F70117FC2428F -- C:\WINDOWS\system32\spoolsv.exe
[2008.04.14 14:00:00 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=CB1090BCA0E7B40D0B5B4E4D66531809 -- C:\WINDOWS\$NtUninstallKB2347290$\spoolsv.exe
[2008.04.14 08:52:50 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=CB1090BCA0E7B40D0B5B4E4D66531809 -- C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe

< MD5 for: SVCHOST.EXE >
[2008.04.14 08:52:50 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.14 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.04.14 14:00:00 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.14 00:50:18 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

< MD5 for: USERINIT.EXE >
[2008.04.14 08:52:52 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 14:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 14:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 14:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 14:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< C:\windows\system32\spool\prtprocs|dll;true;true;true /FP >
[2006.12.25 22:00:00 | 000,027,136 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8R.DLL
[2007.05.22 05:00:00 | 000,027,136 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD94.DLL
[2006.12.25 22:00:00 | 000,069,632 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8R.DLL
[2007.05.22 05:00:00 | 000,069,632 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP94.DLL
[2008.07.06 14:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006.10.26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008.07.06 14:06:10 | 000,147,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\x64\filterpipelineprintproc.dll

< %systemroot%\system32\drivers\*.sys /5 >

< %systemroot%\system32\drivers\*.sys /X >
[2008.04.14 08:51:38 | 000,004,255 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv01nt5.dll
[2008.04.14 08:51:38 | 000,003,967 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv02nt5.dll
[2008.04.14 08:51:38 | 000,003,615 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv05nt5.dll
[2008.04.14 08:51:38 | 000,003,647 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv07nt5.dll
[2008.04.14 08:51:38 | 000,003,135 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv08nt5.dll
[2008.04.14 08:51:38 | 000,003,711 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv09nt5.dll
[2008.04.14 08:51:38 | 000,003,775 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\adv11nt5.dll
[2006.12.29 20:21:08 | 000,064,352 | ---- | M] () -- C:\WINDOWS\system32\drivers\ativmc20.cod
[2008.04.14 08:51:38 | 000,021,183 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv01nt5.dll
[2008.04.14 08:51:38 | 000,011,359 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv02nt5.dll
[2008.04.14 08:51:38 | 000,025,471 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv04nt5.dll
[2008.04.14 08:51:38 | 000,014,143 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv06nt5.dll
[2008.04.14 08:51:38 | 000,017,279 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\atv10nt5.dll
[2011.08.20 16:04:04 | 000,639,522 | ---- | M] () -- C:\WINDOWS\system32\drivers\Cat.DB
[2008.04.14 08:51:40 | 000,015,423 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
[2007.04.02 21:36:04 | 000,129,045 | ---- | M] () -- C:\WINDOWS\system32\drivers\cxthsfs2.cty
[2010.05.15 19:46:51 | 000,202,784 | -HS- | M] () -- C:\WINDOWS\system32\drivers\fidbox.dat
[2010.05.15 19:46:11 | 000,003,380 | -HS- | M] () -- C:\WINDOWS\system32\drivers\fidbox.idx
[2010.05.15 20:07:29 | 000,006,944 | -HS- | M] () -- C:\WINDOWS\system32\drivers\fidbox2.dat
[2010.05.15 19:46:11 | 000,001,628 | -HS- | M] () -- C:\WINDOWS\system32\drivers\fidbox2.idx
[2008.04.14 14:00:00 | 003,440,660 | ---- | M] () -- C:\WINDOWS\system32\drivers\gm.dls
[2008.04.14 14:00:00 | 000,000,646 | ---- | M] () -- C:\WINDOWS\system32\drivers\gmreadme.txt
[2010.05.15 15:49:22 | 000,075,932 | ---- | M] () -- C:\WINDOWS\system32\drivers\klick.dat
[2010.05.15 15:49:22 | 000,074,396 | ---- | M] () -- C:\WINDOWS\system32\drivers\klin.dat
[2007.03.09 20:58:06 | 000,025,734 | ---- | M] () -- C:\WINDOWS\system32\drivers\klop.dat
[2011.01.28 14:57:18 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2011.01.28 14:57:21 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
[2006.12.29 20:02:50 | 000,067,866 | ---- | M] () -- C:\WINDOWS\system32\drivers\netwlan5.img
[2007.11.17 15:22:04 | 000,003,636 | ---- | M] () -- C:\WINDOWS\system32\drivers\nvphy.bin
[2008.04.14 08:51:56 | 000,003,901 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\siint5.dll
[2008.04.14 08:52:06 | 000,011,325 | ---- | M] (Intel(R) Corporation) -- C:\WINDOWS\system32\drivers\vchnt5.dll

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.05.17 15:12:06 | 000,697,328 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\system32\*.* /5 >
[2011.08.20 11:46:24 | 000,390,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\CF15156.exe
[2011.08.21 07:46:15 | 000,276,202 | ---- | M] () -- C:\WINDOWS\system32\NvApps.xml
[2011.08.20 12:09:23 | 000,002,278 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[18 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\*.dll /lockedfiles >
[18 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\config\*.sav >
[2010.05.08 17:29:37 | 000,524,288 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.05.08 15:24:28 | 000,262,144 | ---- | M] () -- C:\WINDOWS\system32\config\security.sav
[2010.05.08 17:29:37 | 011,272,192 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.05.08 17:29:37 | 002,621,440 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\*.* /U /s >
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[12 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\d075bf91c50a4232b7fe7eba84f1ecf7\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\d075bf91c50a4232b7fe7eba84f1ecf7\*.tmp -> ]
[18 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\*. /mp /s >

< %ALLUSERSPROFILE%\Data Aplikací\*.* >
[2010.05.08 15:30:46 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\desktop.ini
[2010.05.10 21:40:01 | 000,000,032 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\ezsid.dat
[2010.08.15 14:16:50 | 000,148,736 | ---- | M] (Avanquest Software) -- C:\Documents and Settings\All Users\Data Aplikací\hpe1FC5.dll

< %ALLUSERSPROFILE%\Data Aplikací\*.exe /s >
[2010.06.27 13:55:19 | 000,056,969 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\ASPEncoder\Uninstaller.exe
[2010.06.27 13:55:27 | 000,057,409 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\ControlPanel\Uninstaller.exe
[2010.06.27 13:55:34 | 000,054,128 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Converter\Uninstaller.exe
[2010.10.16 12:21:35 | 000,054,153 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DFXPlugin\Uninstaller.exe
[2010.06.27 13:55:36 | 000,056,458 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DivXDecoderShortcut\Uninstaller.exe
[2010.10.16 12:22:11 | 000,056,765 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DivXPlusShortcuts\Uninstaller.exe
[2010.06.27 13:55:35 | 000,054,174 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSAACDecoder\Uninstaller.exe
[2010.06.27 13:55:37 | 000,057,532 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSASPDecoder\Uninstaller.exe
[2010.06.27 13:55:38 | 000,054,166 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSAVCDecoder\Uninstaller.exe
[2010.06.27 13:55:38 | 000,057,054 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\DSDesktopComponents\Uninstaller.exe
[2010.06.27 13:55:27 | 000,054,101 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\MPEG2Plugin\Uninstaller.exe
[2010.06.27 13:55:26 | 000,052,963 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\MSVC80CRTRedist\Uninstaller.exe
[2010.10.16 12:22:00 | 000,057,691 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Player\Uninstaller.exe
[2010.06.27 13:55:22 | 000,054,073 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Qt4.5\Uninstaller.exe
[2010.10.16 12:29:44 | 000,144,696 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\DivX\RunAsUser\RUNASUSERPROCESS.exe
[2010.10.16 11:52:06 | 000,876,824 | ---- | M] (DivX, Inc. ) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Setup\DivXSetup.exe
[2010.06.27 13:55:33 | 000,054,644 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\TranscodeEngine\Uninstaller.exe
[2010.10.16 12:21:38 | 000,084,038 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\TransferWizard\Uninstaller.exe
[2010.10.16 12:22:01 | 000,053,600 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\Update\Uninstaller.exe
[2010.10.16 12:22:10 | 000,056,997 | ---- | M] (DivX, Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\DivX\WebPlayer\Uninstaller.exe
[2011.07.11 09:55:47 | 000,348,544 | ---- | M] (EasyBits Software AS) -- C:\Documents and Settings\All Users\Data Aplikací\Easybits GO\EasyBitsGO.exe
[2011.07.11 09:55:48 | 000,014,208 | ---- | M] () -- C:\Documents and Settings\All Users\Data Aplikací\Easybits GO\ezShell64Run.exe
[2011.07.11 09:55:49 | 000,578,432 | ---- | M] (EasyBits Software AS) -- C:\Documents and Settings\All Users\Data Aplikací\Easybits GO\RemoveGO.exe
[2011.07.11 09:55:49 | 000,663,424 | ---- | M] (EasyBits Media) -- C:\Documents and Settings\All Users\Data Aplikací\Easybits GO\Svc\GOUpdate.exe
[2011.08.19 21:36:00 | 000,527,024 | ---- | M] (Google Inc.) -- C:\Documents and Settings\All Users\Data Aplikací\Google\Google Toolbar\Update\GoogleToolbarInstaller_updater_signed.exe
[2011.08.20 14:48:37 | 067,671,112 | ---- | M] (PC Tools ) -- C:\Documents and Settings\All Users\Data Aplikací\PC Tools\DownloadManager\Spyware Doctor8.0\sdsetup_dl.exe

< %ALLUSERSPROFILE%\Dáta aplikácií\*.* >

< %ALLUSERSPROFILE%\Dáta aplikácií\*.exe /s >

< %APPDATA%\*. >
[2011.07.23 16:51:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\.minecraft
[2010.10.29 09:30:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Adobe
[2010.12.26 11:40:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Alternative Software Ltd
[2010.10.08 19:03:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\BlackBean
[2011.05.21 07:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Canon
[2010.05.12 16:25:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Canon Easy-WebPrint EX
[2011.04.23 22:06:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Corel
[2010.06.20 14:04:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\DAEMON Tools Lite
[2010.05.17 15:16:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\DAEMON Tools Pro
[2010.07.03 21:17:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\DivX
[2011.07.18 23:53:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\dvdcss
[2010.05.10 19:56:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\ESET
[2010.05.17 11:56:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Facebook
[2011.08.20 15:20:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter
[2011.08.18 13:40:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\go
[2010.08.20 20:40:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Google
[2010.05.13 18:40:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Help
[2011.08.21 07:46:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\ICQ
[2010.05.08 14:13:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Identities
[2010.05.10 20:04:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\InstallShield
[2010.11.16 23:13:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Itsth
[2010.10.03 10:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Leadertech
[2011.05.18 21:59:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Macromedia
[2011.08.20 10:14:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Malwarebytes
[2010.11.05 20:47:56 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Microsoft
[2011.07.23 14:42:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Mozilla
[2010.05.12 18:26:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Nero
[2010.08.28 12:52:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\NVIDIA
[2010.05.11 20:48:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Opera
[2010.10.23 10:44:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\PC Suite
[2011.08.20 16:05:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\PCToolsFirewallPlus
[2010.10.23 10:28:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Samsung
[2010.05.12 16:06:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\ScanSoft
[2011.08.18 22:04:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Skype
[2011.07.11 09:55:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\skypePM
[2010.05.17 11:17:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Sun
[2010.12.10 21:04:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Ubisoft
[2011.05.17 19:05:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\Unity
[2011.07.24 11:30:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\vlc
[2010.05.12 16:40:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\WinRAR
[2010.08.29 09:24:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Obyvák\Data aplikací\WORK

< %APPDATA%\*.* >
[2010.10.23 10:28:21 | 000,002,528 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\$_hpcst$.hpc
[2011.04.20 10:28:20 | 000,000,082 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\default.pls
[2010.05.08 15:51:12 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\desktop.ini
[2010.08.29 09:24:19 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\LSDSet.Txt
[2001.03.05 02:05:48 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\Nic.txt
[2010.10.29 09:51:44 | 000,138,056 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\PnkBstrK.sys

< %APPDATA%\*.exe /s >
[2010.05.17 11:56:43 | 000,050,354 | ---- | M] (Facebook, Inc.) -- C:\Documents and Settings\Obyvák\Data aplikací\Facebook\uninstall.exe
[2011.07.05 16:33:22 | 001,371,248 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter\FileHunter.exe
[2011.06.29 20:40:00 | 001,658,480 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter\pumpa.exe
[2011.08.20 15:21:10 | 000,032,508 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter\uninstall.exe
[2011.07.17 22:32:58 | 000,810,096 | ---- | M] () -- C:\Documents and Settings\Obyvák\Data aplikací\FileHunter\update.exe
[2010.10.29 09:47:59 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Documents and Settings\Obyvák\Data aplikací\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2010.11.21 14:43:07 | 000,704,512 | ---- | M] (TODO: <Company name>) -- C:\Documents and Settings\Obyvák\Data aplikací\Samsung\New PC Studio\LiveUpdate\NPSUpdateAgent.exe
[2010.08.05 02:14:55 | 000,875,296 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\Obyvák\Data aplikací\Sun\Java\JRERunOnce.exe

< %SYSTEMDRIVE%\*.exe >
[2007.02.12 21:10:44 | 002,705,744 | ---- | M] (Microsoft Corporation) -- C:\VCREDI~3.EXE

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /s >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-10 21:47:05

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager" /v BootExecute /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
BOOTEXECUTE REG_MULTI_SZ autocheck autochk *\0\0

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager" /v "PendingFileRenameOperations" /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\SESSION MANAGER
PENDINGFILERENAMEOPERATIONS REG_MULTI_SZ \??\C:\Program Files\SmileyCentralIE_1w\bar\setups\SmileyCentralAuto.exe\0\0\0

< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=AlwaysOff /fastdetect /usepmtimer

< *crack* >

< *keygen* >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB47457$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 816 bytes -> C:\WINDOWS\4291322254:1906194176.exe
@Alternate Data Stream - 6144 bytes -> C:\WINDOWS\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:430C6D84
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:DFC5A2B2
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:C31F31E6
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:A8ADE5D8

< End of report >

Re: Vir- facebook

Napsal: 21 srp 2011 19:59
od ruza71
OTL Extras logfile created on: 21.8.2011 20:44:40 - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\Obyvák\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,00 Gb Total Physical Memory | 2,29 Gb Available Physical Memory | 76,32% Memory free
4,84 Gb Paging File | 4,15 Gb Available in Paging File | 85,57% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465,75 Gb Total Space | 182,50 Gb Free Space | 39,18% Space Free | Partition Type: NTFS
Drive K: | 1,91 Gb Total Space | 1,36 Gb Free Space | 71,05% Space Free | Partition Type: FAT

Computer Name: DOMA-C7C92CF28B | User Name: Obyvák | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-1454471165-152049171-1801674531-1004\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1
"DisableThumbnailCache" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\ICQ7.1\ICQ.exe" = C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.1\aolload.exe" = C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\usmt\migwiz.exe" = C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Průvodce přenesením souborů a nastavení -- (Microsoft Corporation)
"C:\Program Files\ICQ7.1\ICQ.exe" = C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.1\aolload.exe" = C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)
"C:\Hry\TrackMania Nations ESWC\TmNationsESWC.exe" = C:\Hry\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC -- ()
"J:\TrackMania Nations ESWC\TmNationsESWC.exe" = J:\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe" = C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher -- (Ubisoft)
"C:\Program Files\Codemasters\F1 2010\F1_2010_game.exe" = C:\Program Files\Codemasters\F1 2010\F1_2010_game.exe:*:Enabled:F1 2010
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server -- (PeeringPortal)
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server -- (PeeringPortal)
"C:\Program Files\Codemasters\DiRT 3\dirt3_game.exe" = C:\Program Files\Codemasters\DiRT 3\dirt3_game.exe:*:Enabled:DiRT 3 -- (Codemasters Software Company Limited)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe" = C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe:*:Enabled:Assassin's Creed II -- ()
"C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe" = C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe:*:Enabled:Assassin's Creed II Update -- (Ubisoft)
"C:\Program Files\Ubisoft\Assassin's Creed II\UPlayBrowser.exe" = C:\Program Files\Ubisoft\Assassin's Creed II\UPlayBrowser.exe:*:Enabled:Assassin's Creed II Uplay -- (Ubisoft Entertainment)
"C:\Documents and Settings\Obyvák\Dokumenty\Downloads\Flash-Player.exe" = C:\Documents and Settings\Obyvák\Dokumenty\Downloads\Flash-Player.exe:*:Enabled:C:\Documents and Settings\Obyvák\Dokumenty\Downloads\Flash-Player.exe
"C:\WINDOWS\update.1\svchost.exe" = C:\WINDOWS\update.1\svchost.exe:*:Enabled:C:\WINDOWS\update.1\svchost.exe
"C:\WINDOWS\update.tray-3-0\svchost.exe" = C:\WINDOWS\update.tray-3-0\svchost.exe:*:Enabled:C:\WINDOWS\update.tray-3-0\svchost.exe
"C:\WINDOWS\update.2\svchost.exe" = C:\WINDOWS\update.2\svchost.exe:*:Enabled:C:\WINDOWS\update.2\svchost.exe
"C:\Program Files\DivX\DivX Update\DivXUpdate.exe" = C:\Program Files\DivX\DivX Update\DivXUpdate.exe:*:Enabled:DivX Update -- ()
"C:\Program Files\Gameforge4D\4Story\PrePatch.exe" = C:\Program Files\Gameforge4D\4Story\PrePatch.exe:*:Enabled:PrePatch -- (Zamiinc)
"C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe" = C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome -- (Google Inc.)
"C:\Program Files\DivX\DivX Plus Player\DivX Plus Player.exe" = C:\Program Files\DivX\DivX Plus Player\DivX Plus Player.exe:*:Enabled:DivX Plus Player -- ()
"C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Update\1.3.21.65\GoogleCrashHandler.exe" = C:\Documents and Settings\Obyvák\Local Settings\Data aplikací\Google\Update\1.3.21.65\GoogleCrashHandler.exe:*:Enabled:Instalační program Google -- (Google Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series" = Canon MP140 series
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP520_series" = Canon MP520 series
"{129DDEC1-A6A3-3D60-AABE-76E6E5334922}" = Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - CSY
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 26
"{2DEFE818-5963-44CD-AF3C-963226BFD42E}_is1" = RE/MAX PhotoLab
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 6.011.00
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{361AA6F2-124E-4E98-9402-83B1445B8448}" = GameSpy Comrade
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{434D0831-3E0C-4D03-A5D4-5E1000008400}" = F1 2010
"{434D0FA0-1558-4D8E-AC3D-BD1000008200}" = DiRT 3
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{489FAF63-F121-4D7D-96E9-2B9DD69496CE}" = LEDA SD - Programové vybavení
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{505AFDC0-5E72-4928-8368-5DEA385E3647}" = CorelDRAW Graphics Suite 12
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5E65E94D-69F2-4850-9E93-6459C53A0F50}" = Microsoft .NET Framework 1.1 Czech Language Pack
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{68F45351-B08A-4EFC-8414-408485473BB3}" = 102 Dalmatians Puppies to the Rescue
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C2EDF63-C83B-4AAD-AC26-1784660F618B}" = Advanced Disk Cleaner
"{6FE8B722-4D7E-3CD7-BB3A-3AD1684B1295}" = Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - CSY
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71BFC818-0CED-42D6-9C87-5142918957EE}" = ICQ7.1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74DCC43B-33C9-3389-BD0D-33EB37973657}" = Microsoft .NET Framework 3.5 Language Pack - csy
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}" = Assassin's Creed II
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0405-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Czech) 12
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0015-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_ENTERPRISE_{294B4278-CF7B-40B9-86A1-2D3FF0C2C524}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_ENTERPRISE_{10EC59E5-9BCE-4884-BB1A-E28627220232}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-0044-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_ENTERPRISE_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}_ENTERPRISE_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-1033-F400-7760-000000000003}" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"{AC76BA86-7AD7-1029-7B44-A94000000001}" = Adobe Reader 9.4.3 - Czech
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.8 Game
"{D6C9AF27-9414-46C8-B9D8-D878BA041033}" = Nero 8
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{EF702442-B623-4B6A-B41D-412584301725}_is1" = Easy2Sync for Outlook 4.03
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F1E1BA46-6167-4A33-95F0-A4A4475DC499}" = ESET Smart Security
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Balíček ovladače systému Windows - Nokia pccsmcfd (10/12/2007 6.85.4.0)
"4StoryCZ_is1" = 4Story 3.5
"7-Zip" = 7-Zip 4.65
"Adobe Acrobat 8 Professional - English, Français, Deutsch" = Adobe Acrobat 8.1.0 Professional
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AskTBar Uninstall" = Ask Toolbar
"Atf" = Atf Profi
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"Crash Bandicoot (pSX 1.13 emulation)" = Crash Bandicoot (pSX 1.13 emulation)
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DesetiPrsty" = DesetiPrsty 4.41
"DivX Setup.divx.com" = DivX Setup
"DVD Shrink_is1" = DVD Shrink 3.2
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"ENTERPRISE" = Microsoft Office Enterprise 2007
"GFWL_{434D0831-3E0C-4D03-A5D4-5E1000008400}" = F1 2010
"GFWL_{434D0FA0-1558-4D8E-AC3D-BD1000008200}" = DiRT 3
"ICQToolbar" = ICQ Toolbar
"ie8" = Windows Internet Explorer 8
"InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"Mafia II DLC Jimmy's Vendetta_is1" = Mafia II DLC Jimmy's Vendetta
"Mafia II_is1" = Mafia II DLC Joe's Adventures
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware verze 1.51.1.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack - csy" = Microsoft .NET Framework 3.5 Language Pack - CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 5.0.1 (x86 cs)" = Mozilla Firefox 5.0.1 (x86 cs)
"MP Navigator 3.1" = Canon MP Navigator 3.1
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"Opera 11.10.2092" = Opera 11.10
"PunkBusterSvc" = PunkBuster Services
"QIP Infium JadrisPack 3.3.0" = QIP Infium JadrisPack 3.3.0
"SmileyCentralIE_1wbar Uninstall" = SmileyCentral
"SopCast" = SopCast 3.3.2
"Spy Emergency_is1" = Spy Emergency
"Totalcmd" = Total Commander (Remove or Repair)
"Veetle TV" = Veetle TV 0.9.18
"VLC media player" = VLC media player 1.0.5
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1454471165-152049171-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Game Organizer" = EasyBits GO
"Google Chrome" = Google Chrome
"Sweet Home 3D" = Sweet Home 3D
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 20.8.2011 4:01:40 | Computer Name = DOMA-C7C92CF28B | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace OTL.exe, verze 3.2.26.5, zablokovaný modul hungapp,
verze 0.0.0.0, adresa bloku 0x00000000.

Error - 20.8.2011 4:13:22 | Computer Name = DOMA-C7C92CF28B | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace OTL.exe, verze 3.2.26.5, zablokovaný modul hungapp,
verze 0.0.0.0, adresa bloku 0x00000000.

Error - 20.8.2011 5:24:38 | Computer Name = DOMA-C7C92CF28B | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace SpyEmergency.exe, verze 8.0.505.0, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 20.8.2011 8:50:56 | Computer Name = DOMA-C7C92CF28B | Source = crypt32 | ID = 131083
Description = Extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou
aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>
se nezdařilo. Chyba: Při ověření se systémovými hodinami nebo časovým razítkem
podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.


Error - 20.8.2011 8:50:56 | Computer Name = DOMA-C7C92CF28B | Source = crypt32 | ID = 131083
Description = Extrakce kořenového seznamu jiného výrobce ze souboru CAB pro automatickou
aktualizaci v: <http://www.download.windowsupdate.com/m ... ootstl.cab>
se nezdařilo. Chyba: Při ověření se systémovými hodinami nebo časovým razítkem
podepsaného souboru bylo zjištěno, že požadovaný certifikát je mimo lhůtu platnosti.


Error - 20.8.2011 9:21:45 | Computer Name = DOMA-C7C92CF28B | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace FileHunter.exe, verze 0.0.0.0, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 21.8.2011 1:02:22 | Computer Name = DOMA-C7C92CF28B | Source = Application Error | ID = 1000
Description = Chybující aplikace services.exe, verze 5.1.2600.5755, chybující modul
unknown, verze 0.0.0.0, adresa chyby 0x000528d0.

Error - 21.8.2011 1:38:04 | Computer Name = DOMA-C7C92CF28B | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace iexplore.exe, verze 8.0.6001.18702, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 21.8.2011 4:45:05 | Computer Name = DOMA-C7C92CF28B | Source = Chrome | ID = 1
Description =

Error - 21.8.2011 4:45:18 | Computer Name = DOMA-C7C92CF28B | Source = Chrome | ID = 1
Description =

[ OSession Events ]
Error - 17.12.2010 7:09:33 | Computer Name = DOMA-C7C92CF28B | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 35
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 21.8.2011 6:20:39 | Computer Name = DOMA-C7C92CF28B | Source = Service Control Manager | ID = 7023
Description = Služba Sledování umístění v síti (NLA) byla ukončena s následující
chybou: %%127

Error - 21.8.2011 6:20:39 | Computer Name = DOMA-C7C92CF28B | Source = Service Control Manager | ID = 7023
Description = Služba Sledování umístění v síti (NLA) byla ukončena s následující
chybou: %%127

Error - 21.8.2011 8:56:37 | Computer Name = DOMA-C7C92CF28B | Source = Service Control Manager | ID = 7023
Description = Služba Sledování umístění v síti (NLA) byla ukončena s následující
chybou: %%127

Error - 21.8.2011 12:38:21 | Computer Name = DOMA-C7C92CF28B | Source = Service Control Manager | ID = 7023
Description = Služba Sledování umístění v síti (NLA) byla ukončena s následující
chybou: %%127

Error - 21.8.2011 13:35:35 | Computer Name = DOMA-C7C92CF28B | Source = Service Control Manager | ID = 7023
Description = Služba Sledování umístění v síti (NLA) byla ukončena s následující
chybou: %%127

Error - 21.8.2011 13:35:48 | Computer Name = DOMA-C7C92CF28B | Source = Service Control Manager | ID = 7023
Description = Služba Sledování umístění v síti (NLA) byla ukončena s následující
chybou: %%127

Error - 21.8.2011 14:38:34 | Computer Name = DOMA-C7C92CF28B | Source = Service Control Manager | ID = 7023
Description = Služba Sledování umístění v síti (NLA) byla ukončena s následující
chybou: %%127

Error - 21.8.2011 14:38:34 | Computer Name = DOMA-C7C92CF28B | Source = Service Control Manager | ID = 7023
Description = Služba Sledování umístění v síti (NLA) byla ukončena s následující
chybou: %%127

Error - 21.8.2011 14:38:34 | Computer Name = DOMA-C7C92CF28B | Source = Service Control Manager | ID = 7023
Description = Služba Sledování umístění v síti (NLA) byla ukončena s následující
chybou: %%127

Error - 21.8.2011 14:42:09 | Computer Name = DOMA-C7C92CF28B | Source = Service Control Manager | ID = 7023
Description = Služba Sledování umístění v síti (NLA) byla ukončena s následující
chybou: %%127


< End of report >

Re: Vir- facebook

Napsal: 21 srp 2011 20:01
od Caroprd111
Windows je legální?

Re: Vir- facebook

Napsal: 22 srp 2011 06:51
od ruza71
Není legální

Re: Vir- facebook

Napsal: 22 srp 2011 10:52
od Caroprd111
Podle pravidel fóra se zde nelegálním softwarem nezabýváme - nelegální programy představují bezpečnostní hrozbu a navíc tím porušujete zákon. :spam:

:closed: