CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011.08.26 11:29:09 | 000,000,000 | ---D | C] -- C:\_OTL
[2011.08.25 21:57:15 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Radek\Plocha\OTL.exe
[2011.08.25 21:24:42 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2011.08.25 20:54:26 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011.08.25 20:19:41 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011.08.25 20:19:41 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011.08.25 20:19:41 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011.08.25 20:19:41 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011.08.25 19:56:52 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Radek\Recent
[2011.08.25 19:55:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
[2011.08.25 19:55:50 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.08.25 19:38:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011.08.25 19:37:39 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.08.25 19:33:23 | 004,182,373 | R--- | C] (Swearware) -- C:\Documents and Settings\Radek\Plocha\ComboFix.exe
[2011.08.24 15:16:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radek\Data aplikací\Malwarebytes
[2011.08.24 15:01:23 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.08.24 15:01:06 | 000,000,000 | ---D | C] -- C:\rsit
[2011.08.24 14:17:07 | 000,064,512 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2011.08.24 14:16:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Lavasoft
[2011.08.24 14:16:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
[2011.08.24 14:16:55 | 000,000,000 | ---D | C] -- C:\Program Files\Ad-Aware
[2011.08.24 14:12:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\COMODO
[2011.08.24 14:12:05 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2011.08.24 14:07:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Comodo
[2011.08.24 13:51:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radek\Nabídka Start\Programy\HiJackThis
[2011.08.24 13:51:40 | 000,000,000 | ---D | C] -- C:\Programy
[2007.12.07 23:58:19 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Radek\Data aplikací\pcouffin.sys
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011.08.26 13:16:08 | 000,012,700 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.08.26 13:11:00 | 000,001,046 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1847444920-2511039311-3333254768-1007UA.job
[2011.08.26 12:37:13 | 000,000,948 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011.08.26 12:21:10 | 000,000,944 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011.08.26 12:20:27 | 000,000,450 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011.08.26 12:20:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.08.25 21:49:22 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Radek\Plocha\OTL.exe
[2011.08.25 21:41:20 | 000,004,487 | ---- | M] () -- C:\Documents and Settings\Radek\Data aplikací\24B2.078
[2011.08.25 20:09:15 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011.08.25 20:08:17 | 000,060,416 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\ALCFDRTM.VER
[2011.08.25 19:59:34 | 000,000,556 | ---- | M] () -- C:\Documents and Settings\Radek\Dokumenty\cc_20110825_195932.reg
[2011.08.25 19:59:05 | 000,002,176 | ---- | M] () -- C:\Documents and Settings\Radek\Dokumenty\cc_20110825_195903.reg
[2011.08.25 19:58:37 | 000,475,896 | ---- | M] () -- C:\Documents and Settings\Radek\Dokumenty\cc_20110825_195810.reg
[2011.08.25 19:44:10 | 000,002,528 | ---- | M] () -- C:\Documents and Settings\Radek\Data aplikací\$_hpcst$.hpc
[2011.08.25 19:25:10 | 004,182,373 | R--- | M] (Swearware) -- C:\Documents and Settings\Radek\Plocha\ComboFix.exe
[2011.08.25 18:11:00 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1847444920-2511039311-3333254768-1007Core.job
[2011.08.25 14:48:19 | 000,000,492 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Markéta Mášová.job
[2011.08.24 15:15:50 | 000,002,444 | -H-- | M] () -- C:\aaw7boot.cmd
[2011.08.24 14:12:41 | 000,001,653 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\COMODO Firewall.lnk
[2011.08.24 13:51:51 | 000,002,523 | ---- | M] () -- C:\Documents and Settings\Radek\Plocha\HiJackThis.lnk
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.08.25 20:19:41 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011.08.25 20:19:41 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011.08.25 20:19:41 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011.08.25 20:19:41 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011.08.25 20:19:41 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011.08.25 19:59:33 | 000,000,556 | ---- | C] () -- C:\Documents and Settings\Radek\Dokumenty\cc_20110825_195932.reg
[2011.08.25 19:59:04 | 000,002,176 | ---- | C] () -- C:\Documents and Settings\Radek\Dokumenty\cc_20110825_195903.reg
[2011.08.25 19:58:14 | 000,475,896 | ---- | C] () -- C:\Documents and Settings\Radek\Dokumenty\cc_20110825_195810.reg
[2011.08.25 19:44:10 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Radek\Data aplikací\$_hpcst$.hpc
[2011.08.24 15:15:13 | 000,002,444 | -H-- | C] () -- C:\aaw7boot.cmd
[2011.08.24 14:17:37 | 000,000,450 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011.08.24 14:12:41 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\COMODO Firewall.lnk
[2011.08.24 13:51:41 | 000,002,523 | ---- | C] () -- C:\Documents and Settings\Radek\Plocha\HiJackThis.lnk
[2011.07.21 12:24:49 | 000,182,272 | ---- | C] () -- C:\Documents and Settings\Radek\Data aplikací\dwm.exe
[2011.07.21 12:24:23 | 000,004,487 | ---- | C] () -- C:\Documents and Settings\Radek\Data aplikací\24B2.078
[2011.07.18 11:35:26 | 000,169,472 | ---- | C] () -- C:\WINDOWS\gbot111.exe
[2011.07.17 18:44:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\loader2.exe_ok
[2011.07.15 16:37:41 | 000,246,272 | ---- | C] () -- C:\WINDOWS\unrar.exe
[2011.07.15 16:35:01 | 000,110,592 | ---- | C] () -- C:\WINDOWS\l1rezerv.exe
[2011.07.15 16:31:57 | 000,232,960 | ---- | C] () -- C:\WINDOWS\sysdriver32_.exe
[2011.07.15 16:31:07 | 000,232,960 | ---- | C] () -- C:\WINDOWS\sysdriver32.exe
[2011.05.24 23:44:26 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\OVDecode.dll
[2010.10.20 10:15:39 | 000,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys
[2010.04.17 09:57:28 | 000,000,028 | ---- | C] () -- C:\WINDOWS\MotionDVSTUDIO.INI
[2010.01.23 11:25:42 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010.01.23 11:25:40 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010.01.23 11:25:27 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010.01.23 11:25:27 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.01.23 11:25:21 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010.01.23 11:25:09 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009.10.06 19:35:41 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009.09.27 15:38:55 | 000,020,628 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009.05.29 21:07:42 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008.12.18 20:23:00 | 000,138,512 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.12.18 20:22:43 | 000,201,440 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2008.12.18 20:22:13 | 000,066,872 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2008.12.17 20:22:49 | 000,000,045 | -H-- | C] () -- C:\WINDOWS\dsez7408.dat
[2008.12.02 13:34:59 | 000,003,439 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2007.12.21 22:10:52 | 000,000,043 | ---- | C] () -- C:\WINDOWS\prdelka.INI
[2007.12.07 23:58:19 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Radek\Data aplikací\ezpinst.exe
[2007.12.07 23:58:19 | 000,007,824 | ---- | C] () -- C:\Documents and Settings\Radek\Data aplikací\pcouffin.cat
[2007.12.07 23:58:19 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Radek\Data aplikací\pcouffin.inf
[2007.11.07 13:30:58 | 000,000,289 | ---- | C] () -- C:\WINDOWS\Wininit.ini
[2007.08.24 12:05:08 | 000,001,508 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007.07.23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2007.07.23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2007.07.12 23:17:55 | 000,011,776 | ---- | C] () -- C:\Documents and Settings\Radek\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007.03.06 18:09:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VideoExe.INI
[2007.03.06 17:53:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PhoneBkExe.INI
[2007.03.06 17:50:11 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MelodyExe.INI
[2007.03.06 17:12:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\FileMgrExe.INI
[2007.03.06 17:10:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MessageExe.INI
[2007.02.23 19:37:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EngineExe.INI
[2007.02.23 19:37:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PanelExe.INI
[2007.02.23 19:37:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\AlbumExe.INI
[2007.02.17 17:02:30 | 000,001,582 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2007.01.18 17:37:20 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2007.01.18 17:37:20 | 000,036,864 | R--- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2007.01.08 12:33:10 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2006.12.09 21:23:53 | 000,000,373 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2006.11.10 20:15:20 | 000,001,743 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\QTSBandwidthCache
[2006.10.18 18:01:01 | 000,319,488 | R--- | C] () -- C:\WINDOWS\System32\MafiaSetup.exe
[2006.10.14 21:15:33 | 000,036,972 | ---- | C] () -- C:\WINDOWS\System32\ActPanel.dll
[2006.09.26 16:20:35 | 000,118,784 | R--- | C] () -- C:\WINDOWS\bwUnin-7.2.0.157-8876480SL.exe
[2006.09.23 19:11:52 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2006.09.20 15:04:45 | 000,000,070 | ---- | C] () -- C:\WINDOWS\Morpheus.INI
[2006.09.20 14:59:43 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\mo001.dat
[2006.09.20 14:58:54 | 000,341,584 | ---- | C] () -- C:\WINDOWS\System32\uninstall.exe
[2006.09.18 22:21:48 | 001,317,152 | R--- | C] () -- C:\WINDOWS\System32\drivers\lvcm.sys
[2006.09.18 22:21:48 | 000,009,255 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2006.09.18 22:19:05 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\InstMed.exe
[2006.09.18 22:17:45 | 000,081,920 | R--- | C] () -- C:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
[2006.09.18 21:23:06 | 000,086,214 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2006.09.18 21:23:06 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2006.09.18 21:23:06 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2006.09.18 21:23:06 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2006.09.18 21:23:06 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2006.09.18 21:23:06 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2006.09.18 21:23:06 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2006.09.18 21:23:06 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2006.09.18 21:23:06 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2006.09.18 21:23:06 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2006.09.18 21:23:06 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2006.09.18 21:23:06 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2006.09.18 21:23:06 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2006.09.18 21:23:06 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2006.09.18 21:23:06 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2006.09.18 21:23:06 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2006.09.18 21:23:06 | 000,000,099 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2006.09.18 21:18:54 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CDED68ECHP.ini
[2006.09.18 19:31:24 | 000,036,864 | R--- | C] () -- C:\WINDOWS\System32\ctrldll.dll
[2006.09.18 19:31:24 | 000,032,768 | R--- | C] () -- C:\WINDOWS\System32\rmctrl.exe
[2006.09.18 19:17:18 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006.09.18 18:59:17 | 000,000,676 | ---- | C] () -- C:\WINDOWS\im32st.dat
[2006.09.18 18:54:44 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\NMOCOD.DLL
[2006.09.18 18:22:02 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006.09.18 16:05:51 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006.05.30 15:18:18 | 000,085,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\InCDfs.sys
[2005.09.14 00:27:53 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005.09.14 00:27:12 | 000,137,256 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005.09.14 00:22:02 | 000,157,184 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2005.09.14 00:21:43 | 000,000,786 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005.09.14 00:21:36 | 000,429,172 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2005.09.14 00:21:36 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2005.09.14 00:21:36 | 000,078,294 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2005.09.14 00:21:36 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2005.09.14 00:21:28 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2005.09.14 00:21:26 | 000,432,778 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005.09.14 00:21:26 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2005.09.14 00:21:26 | 000,067,734 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005.09.14 00:21:26 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2005.09.14 00:21:26 | 000,004,486 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2005.09.14 00:21:24 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2005.09.14 00:21:24 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2005.09.14 00:21:21 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2005.09.14 00:21:21 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2005.09.14 00:21:17 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2005.09.14 00:21:13 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2005.09.13 23:17:20 | 000,516,096 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2005.09.13 23:17:12 | 000,121,995 | R--- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2005.09.13 22:34:55 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005.09.13 22:31:39 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005.02.01 16:10:30 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\exasd_.dll
[2003.08.20 21:12:36 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\MADLib.dll
[2003.07.16 13:09:32 | 000,202,752 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2003.05.08 00:27:48 | 000,902,318 | ---- | C] () -- C:\WINDOWS\System32\mos.exe
[2002.10.06 20:42:58 | 000,105,472 | ---- | C] () -- C:\WINDOWS\System32\oggds.dll
[2002.10.05 01:04:26 | 000,092,672 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2002.10.05 01:04:26 | 000,080,384 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2002.10.05 01:04:18 | 000,021,504 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2002.05.17 22:18:30 | 000,039,936 | ---- | C] () -- C:\WINDOWS\System32\mp4fil32.dll
[1999.12.02 07:12:00 | 000,000,100 | ---- | C] () -- C:\WINDOWS\System32\msconsysi.dat
[1999.04.11 22:54:20 | 000,281,600 | ---- | C] () -- C:\WINDOWS\System32\cncs232.dll
[1999.01.27 13:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1998.07.30 16:02:04 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\NUMERALG.DLL
[1998.03.03 10:37:32 | 000,182,784 | ---- | C] () -- C:\WINDOWS\System32\DAOLIBS.DLL
[1997.06.13 07:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[1996.02.23 21:34:48 | 000,014,629 | ---- | C] () -- C:\WINDOWS\System32\declw.dll
[1996.02.22 19:09:20 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\decln.dll
========== LOP Check ==========
[2009.09.26 14:13:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\avg7
[2010.03.20 11:57:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.09.26 14:13:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Grisoft
[2010.01.19 23:25:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2008.08.02 15:16:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\JollyBear
[2006.10.17 21:33:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\MumboJumbo
[2010.04.17 09:57:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Panasonic
[2008.10.26 21:59:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Simply Super Software
[2008.12.04 21:49:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2008.08.02 17:13:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2006.09.18 21:25:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\UDL
[2009.11.25 11:13:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2006.12.10 16:18:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\Atari
[2009.08.19 11:24:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\AVG7
[2006.10.06 20:45:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\Balloon Express
[2006.09.20 15:05:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\BearShare
[2007.09.07 19:53:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\COWON
[2010.03.20 15:47:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\DAEMON Tools Lite
[2007.12.07 14:43:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\Dcads Advanced Toolbar
[2010.03.28 14:48:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\Euro4
[2010.06.19 12:18:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\Facebook
[2006.12.12 12:29:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\flightgear.org
[2006.12.12 20:31:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\fltk.org
[2006.10.27 19:11:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\funkitron
[2009.12.26 13:13:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\Hide IP NG
[2010.01.19 23:32:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\ICQ
[2007.05.30 20:54:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\ICQ Toolbar
[2006.09.19 09:19:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\ICQLite
[2008.06.28 19:29:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\MobileAction
[2006.10.06 16:52:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\Morpheus
[2008.10.26 21:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\Simply Super Software
[2006.09.20 19:30:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jakub Máša\Data aplikací\Zoner
[2006.09.18 18:23:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Data aplikací\AVG7
[2007.01.12 12:41:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Atari
[2009.06.22 11:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\AVG7
[2008.01.28 11:47:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\COWON
[2008.07.03 21:43:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\ICQ
[2007.06.04 20:54:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\ICQ Toolbar
[2007.11.03 17:42:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\ICQLite
[2008.05.16 09:26:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Vso
[2011.08.26 12:20:27 | 000,000,450 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 05:22:17 | 000,015,360 | ---- | M] (Microsoft Corporation)
"LDM" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe -- [2007.03.04 11:29:29 | 000,067,128 | ---- | M] (Logitech Inc.)
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" -- [2006.06.01 13:32:12 | 000,094,208 | ---- | M] (Nero AG)
"swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -- [2007.06.21 07:53:50 | 000,068,856 | ---- | M] (Google Inc.)
"MSMSGS" = "C:\Program Files\Messenger\msmsgs.exe" /background -- [2008.04.14 05:22:36 | 001,695,232 | ---- | M] (Microsoft Corporation)
< c:\windows\*.* /U >
[1 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2008.01.27 16:21:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Adobe
[2008.04.05 21:39:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Apple Computer
[2007.01.12 12:41:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Atari
[2009.06.22 11:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\AVG7
[2008.01.28 11:47:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\COWON
[2008.01.18 12:30:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Google
[2005.09.13 23:20:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Help
[2008.07.03 21:43:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\ICQ
[2007.06.04 20:54:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\ICQ Toolbar
[2007.11.03 17:42:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\ICQLite
[2005.09.13 22:33:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Identities
[2006.11.22 22:11:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Macromedia
[2011.08.24 15:16:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Malwarebytes
[2011.08.25 19:57:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Media Player Classic
[2011.08.24 13:51:41 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Radek\Data aplikací\Microsoft
[2007.09.15 13:00:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Mozilla
[2010.05.23 15:16:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Real
[2007.03.17 21:30:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Skype
[2008.12.02 14:06:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Sun
[2007.09.15 13:00:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Talkback
[2008.05.16 09:26:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radek\Data aplikací\Vso
< %APPDATA%\*.exe /s >
[2011.07.21 12:24:49 | 000,182,272 | ---- | M] () -- C:\Documents and Settings\Radek\Data aplikací\dwm.exe
[2007.12.07 23:58:19 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\Radek\Data aplikací\ezpinst.exe
[2011.07.21 12:24:21 | 000,173,056 | ---- | M] () -- C:\Documents and Settings\Radek\Data aplikací\Microsoft\conhost.exe
[2011.08.24 13:51:41 | 000,388,096 | R--- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Radek\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
< MD5 for: AGP440.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp1.cab:atapi.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004.08.17 15:57:28 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2004.08.03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\i386\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\ServicePackFiles\i386\autochk.exe
[2008.04.14 05:22:10 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\$NtServicePackUninstall$\autochk.exe
[2004.08.17 15:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\I386\AUTOCHK.EXE
< MD5 for: CDROM.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp1.cab:cdrom.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:cdrom.sys
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008.04.13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2009.12.22 20:39:20 | 000,062,592 | ---- | M] (Microsoft Corporation) MD5=7B53584D94E9D8716B2DE91D5F1CB42D -- C:\WINDOWS\system32\dllcache\cdrom.sys
[2004.08.17 15:57:28 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2004.08.17 15:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
[2008.04.14 05:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\system32\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 05:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[2004.08.17 15:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 05:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004.08.17 15:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: HAL.DLL >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:hal.dll
[2003.04.16 14:00:00 | 010,174,968 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp1.cab:hal.dll
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:hal.dll
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:hal.dll
[2008.04.13 20:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2008.04.13 20:31:28 | 000,131,840 | ---- | M] (Microsoft Corporation) MD5=6F61D3287A6A15A08A9433222C09D17F -- C:\WINDOWS\system32\HAL.DLL
[2004.08.17 15:57:28 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\$NtServicePackUninstall$\hal.dll
< MD5 for: CHANGER.SYS >
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:Changer.sys
[2004.08.17 15:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\I386\sp2.cab:Changer.sys
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:Changer.sys
[2008.04.13 20:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\ServicePackFiles\i386\changer.sys
< MD5 for: IASTOR.SYS >
[2004.03.24 18:00:00 | 000,274,816 | ---- | M] (Intel Corporation) MD5=9B5D077B6033BB41AB5AF0E28E566164 -- C:\driver\rai\intel\ICH5R\Floppy\iastor.sys
[2004.03.23 06:13:58 | 000,467,200 | ---- | M] (Intel Corporation) MD5=F26BFD48B1C314E0F23BF77ACFA75940 -- C:\driver\rai\intel\ICH6R\Floppy\iastor.sys
< MD5 for: ISAPNP.SYS >
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:isapnp.sys
[2008.12.04 10:10:21 | 023,890,583 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:isapnp.sys
[2001.10.24 11:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys
[2003.04.16 14:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
[2008.04.14 04:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\system32\drivers\isapnp.sys
< MD5 for: LSASS.EXE >
[2004.08.17 15:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\ServicePackFiles\i386\lsass.exe
[2008.04.14 05:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\system32\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008.04.13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2004.08.03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
< MD5 for: NETLOGON.DLL >
[2004.08.17 15:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 05:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NVATABUS.SYS >
[2004.01.13 11:36:00 | 000,063,744 | ---- | M] (NVIDIA Corporation) MD5=06F86506555644CBA020CD2CFFE28668 -- C:\driver\Chi\nvidia\NvAtaBus.sys
< MD5 for: NVRAID.SYS >
[2004.01.13 11:36:00 | 000,057,472 | ---- | M] (NVIDIA Corporation) MD5=E182F94D65DEDA3668C23EE5BC8E980F -- C:\driver\Chi\nvidia\nvraid.sys
< MD5 for: SCECLI.DLL >
[2004.08.17 15:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 05:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SMSS.EXE >
[2004.08.17 15:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\$NtServicePackUninstall$\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\ServicePackFiles\i386\smss.exe
[2008.04.14 05:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\system32\smss.exe
[2004.08.17 15:49:28 | 000,481,792 | ---- | M] (Microsoft Corporation) MD5=CB56F803D2CAF6B3F32E82D2F73F4B3A -- C:\WINDOWS\I386\SYSTEM32\SMSS.EXE
< MD5 for: SVCHOST.EXE >
[2011.07.18 11:35:20 | 000,340,480 | ---- | M] () MD5=1733B4BD3F88618E348977328B384762 -- C:\WINDOWS\update.5.0\svchost.exe
[2011.07.15 16:09:49 | 001,170,432 | -H-- | M] () MD5=2ED651EA0565B4C3C0F7F4EE372FEFC7 -- C:\WINDOWS\update.1\svchost.exe
[2011.07.15 16:09:49 | 001,170,432 | -H-- | M] () MD5=2ED651EA0565B4C3C0F7F4EE372FEFC7 -- C:\WINDOWS\update.tray-3-0-lnk\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008.04.14 05:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe
[2004.08.17 15:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2011.07.15 16:32:12 | 000,483,328 | ---- | M] () MD5=EFB19E06A994F184B781A3C948E77E6E -- C:\WINDOWS\update.2\svchost.exe
< MD5 for: TCPIP.SYS >
[2006.04.20 13:51:50 | 000,359,808 | ---- | M] (Microsoft Corporation) MD5=1DBF125862891817F374F407626967F4 -- C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.04.13 21:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 13:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2004.08.03 23:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 13:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[2006.04.20 14:18:35 | 000,360,576 | ---- | M] (Microsoft Corporation) MD5=B2220C618B42A2212A59D91EBD6FC4B4 -- C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008.04.14 05:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe
[2004.08.17 15:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
< MD5 for: VIAMRAID.SYS >
[2004.03.29 07:45:32 | 000,073,600 | ---- | M] (VIA Technologies inc,.ltd) MD5=65864ABA65EEE06EA586009301834E43 -- C:\driver\rai\via\VIARaid\driver\2003IA32\viamraid.sys
[2004.03.29 07:45:32 | 000,073,600 | ---- | M] (VIA Technologies inc,.ltd) MD5=65864ABA65EEE06EA586009301834E43 -- C:\driver\rai\via\VIARaid\driver\Win2000\viamraid.sys
[2004.03.29 07:45:36 | 000,073,600 | ---- | M] (VIA Technologies inc,.ltd) MD5=65864ABA65EEE06EA586009301834E43 -- C:\driver\rai\via\VIARaid\driver\Winxp\viamraid.sys
< MD5 for: VIASRAID.SYS >
[2003.08.05 08:14:30 | 000,077,056 | ---- | M] (VIA Technologies inc,.ltd) MD5=2EAB80850163B2A123D09F34574BEDCF -- C:\driver\rai\via\SataRaid\SATA\2003IA32\viasraid.sys
[2003.08.05 08:14:32 | 000,077,056 | ---- | M] (VIA Technologies inc,.ltd) MD5=2EAB80850163B2A123D09F34574BEDCF -- C:\driver\rai\via\SataRaid\SATA\Winxp\viasraid.sys
[2003.08.05 08:14:30 | 000,078,796 | ---- | M] (VIA Technologies inc,.ltd) MD5=4E5C34099227570FB04CBEEE11B1BCA3 -- C:\driver\rai\via\SataRaid\SATA\Win2000\viasraid.sys
[2003.08.05 08:14:32 | 000,080,240 | ---- | M] (VIA Technologies inc,.ltd) MD5=7B49F476B041FC1F316A9386D598E998 -- C:\driver\rai\via\SataRaid\SATA\Winnt40\viasraid.sys
< MD5 for: WINLOGON.EXE >
[2004.08.17 15:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008.04.14 05:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WS2_32.DLL >
[2004.08.17 15:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
[2008.04.14 05:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010.03.20 11:57:51 | 000,691,696 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2005.09.14 00:25:41 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2005.09.14 00:25:40 | 000,638,976 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2005.09.14 00:25:40 | 000,462,848 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2011.08.26 13:16:08 | 000,012,700 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs
< *crack* /s >
[2007.05.04 13:14:31 | 000,000,371 | ---- | M] () -- \Documents and Settings\Jakub Máša\Cookies\jakub máša@likecrack[2].txt
[2007.05.04 13:14:31 | 000,000,086 | ---- | M] () -- \Documents and Settings\Jakub Máša\Cookies\jakub máš
a@www.likecrack[2].txt
[2007.03.10 22:16:04 | 000,040,579 | ---- | M] () -- \Documents and Settings\Jakub Máša\Plocha\ATEAM\kubiček-pupiček\downloads\Torrents\Removed\GTA[1].Grand.Theft.Auto.San.Andreas.DVD.with.CRACK(1).torrent
[2003.12.05 13:52:40 | 000,000,796 | ---- | M] () -- \Program Files\GTA San Andreas\data\Decision\Craig\crack1.ped
[2006.10.05 21:34:39 | 000,174,904 | ---- | M] () -- \Program Files\Singles\Texture\crackerbox.dds
[2006.01.26 18:10:32 | 000,174,861 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\m02_sec_03_PC\m02_s3_PC_floorcrack.rsb
[2006.01.26 18:10:32 | 000,349,613 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\m02_sec_03_PC\m02_s3_PC_floorcracked.rsb
[2006.01.26 18:11:46 | 001,398,189 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\m07_sec_01_pc\m07_decal_cracks.rsb
[2006.01.26 18:11:48 | 001,398,189 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\m07_sec_01_pc\m07_s1_concrete_crack_02.rsb
[2006.01.26 18:12:12 | 000,349,613 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\m08_sec_02_PC\m08_s2_PC_floorcrackdecal1.rsb
[2006.01.26 18:13:00 | 000,011,077 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\m10_sec_02_pc\M10_S1_crackedgrnd.rsb
[2006.01.26 18:13:12 | 000,087,405 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\m11_sec_01_pc\m11_pc_edgecrack.rsb
[2006.01.26 18:13:28 | 000,087,525 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\m11_sec_02_pc\m11_pc_crackg.rsb
[2006.01.26 18:13:28 | 000,087,405 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\m11_sec_02_pc\m11_pc_edgecrack.rsb
[2006.01.26 18:13:38 | 000,349,613 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\m12_sec_01_pc\M12_s1_PC_ceilingcrack01.rsb
[2006.01.26 18:13:48 | 000,349,613 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\m12_sec_03_pc\m12_s3_PC_conwallcracked.rsb
[2006.01.26 18:15:26 | 000,011,077 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\mp07_rt_syria\mp07_jvm_ceiling_cracked.rsb
[2006.01.26 18:16:12 | 000,087,469 | R--- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\map\mpcl_03_bunkers\mpcl_03_cracks1.rsb
[2006.01.26 18:18:50 | 000,032,933 | ---- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\textures\cracked_glass.rsb
[2006.01.26 18:19:08 | 000,349,613 | ---- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\textures\object\obj_d_crack01.rsb
[2006.01.26 18:19:08 | 001,398,189 | ---- | M] () -- \Program Files\Ubisoft\Red Storm Entertainment\Rainbow Six Lockdown\data\textures\object\obj_d_crack02_faint.rsb
< *keygen* /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:54997B77
< End of report >