Prvni .....................................
OTViewIt logfile created on: 12.3.2009 17:12:30 - Run 3
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Users\User\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
4,00 Gb Total Physical Memory | 2,56 Gb Available Physical Memory | 64,04% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free
Paging file location(s): ?:\pagefile.sys;
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97,66 Gb Total Space | 34,35 Gb Free Space | 35,17% Space Free | Partition Type: NTFS
Drive D: | 368,10 Gb Total Space | 155,17 Gb Free Space | 42,15% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RAMMON
Current User Name: User
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2009.02.05 22:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
[2009.02.05 22:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
[2006.10.26 12:40:34 | 00,335,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
[2006.11.12 21:02:08 | 00,076,544 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files (x86)\ArcSoft\Magic-i 3\uMgiSvr.exe
[2008.09.24 14:32:48 | 00,935,208 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
[2009.02.28 01:40:59 | 00,075,064 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
[2009.03.12 02:13:27 | 00,189,072 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrB.exe
[2004.12.13 03:34:32 | 00,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
[2009.02.05 22:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
[2009.02.05 22:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
[2008.02.14 00:09:40 | 00,486,856 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
[2004.06.16 05:03:26 | 00,221,184 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
[2009.01.26 15:31:16 | 02,144,088 | ---- | M] (Safer Networking Limited) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
[2009.01.15 22:58:35 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe
[2003.06.10 16:50:22 | 01,393,664 | ---- | M] (Asiamajor Inc.) -- C:\Program Files (x86)\V-Gear BEE\VBService.exe
[2007.12.21 12:34:24 | 00,090,112 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files (x86)\WinFast\WFDTV\DTVSchdl.exe
[2007.12.19 15:09:20 | 02,846,720 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files (x86)\WinFast\WFDTV\WFWIZ.exe
[2008.10.15 01:04:34 | 00,039,792 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Reader 8.0\Reader\reader_sl.exe
[2008.12.02 10:02:08 | 00,111,928 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
[2009.02.05 22:08:45 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
[2009.03.07 13:23:48 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Java\jre6\bin\jusched.exe
[2006.09.10 21:56:24 | 00,992,176 | ---- | M] (Macrovision Corporation) -- C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe
[2009.03.12 17:01:00 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Users\User\Downloads\OTViewIt.exe
========== (O23) Win32 Services ==========
[2009.02.05 22:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
[2009.02.05 22:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
[2009.02.05 22:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
[2009.02.05 22:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
File not found -- -- (CertPropSvc [Unknown | Stopped])
[2008.01.05 12:26:41 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2008.01.05 12:25:45 | 00,093,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
File not found -- -- (DcomLaunch [Unknown | Running])
File not found -- -- (DPS [Unknown | Running])
[2008.01.19 09:00:14 | 00,344,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehrecvr.exe -- (ehRecvr [On_Demand | Running])
[2008.01.19 09:00:14 | 00,153,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Running])
[2008.01.05 12:23:12 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
[2007.12.14 10:46:28 | 00,047,624 | ---- | M] () -- C:\Program Files (x86)\GIGABYTE\GEST\GSvr.exe -- (GEST Service [On_Demand | Stopped])
File not found -- -- (GoogleUpdateBeta [Auto | Stopped])
File not found -- -- (gpsvc [Unknown | Running])
[2005.04.03 23:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2006.11.02 10:46:05 | 00,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\keyiso.dll -- (KeyIso [On_Demand | Stopped])
[2006.10.26 12:40:34 | 00,335,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe -- (MDM [Auto | Running])
[2006.11.12 21:02:08 | 00,076,544 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files (x86)\ArcSoft\Magic-i 3\uMgiSvr.exe -- (MgiSvr [Auto | Running])
[2006.10.27 00:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
[2006.11.02 14:34:14 | 00,000,000 | ---D | M] -- C:\Windows\System32\Msdtc -- (MSDTC [Unknown | Stopped])
[2008.09.24 14:32:48 | 00,935,208 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0 [Auto | Running])
[2008.01.19 08:35:36 | 00,592,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netlogon.dll -- (Netlogon [On_Demand | Stopped])
[2008.01.05 12:23:05 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
[2006.10.26 18:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
[2006.10.26 12:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2008.01.19 08:33:19 | 00,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\perfhost.exe -- (PerfHost [On_Demand | Stopped])
[2009.02.28 01:40:59 | 00,075,064 | ---- | M] () -- C:\Windows\System32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
[2009.03.12 02:13:27 | 00,189,072 | ---- | M] () -- C:\Windows\System32\PnkBstrB.exe -- (PnkBstrB [Auto | Running])
File not found -- -- (RpcSs [Unknown | Running])
[2008.01.19 08:36:19 | 00,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SCardSvr.dll -- (SCardSvr [Unknown | Stopped])
File not found -- -- (Schedule [Unknown | Running])
File not found -- -- (SCPolicySvc [Unknown | Stopped])
[2008.11.19 09:09:44 | 00,104,944 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service [On_Demand | Stopped])
File not found -- -- (TuneUp.Defrag [On_Demand | Stopped])
File not found -- -- (TuneUp.ProgramStatisticsSvc [Auto | Running])
[2004.12.13 03:34:32 | 00,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper [Auto | Running])
[2006.11.02 07:35:15 | 00,060,994 | ---- | M] () -- C:\Windows\System32\wbem\vds.mof -- (vds [On_Demand | Stopped])
[2006.11.02 07:35:15 | 00,055,846 | ---- | M] () -- C:\Windows\System32\wbem\vss.mof -- (VSS [On_Demand | Stopped])
File not found -- -- (WdiServiceHost [Unknown | Stopped])
File not found -- -- (WdiSystemHost [Unknown | Running])
[2008.01.19 09:00:47 | 01,216,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [Auto | Running])
[2008.05.27 06:18:43 | 00,439,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe -- (WSearch [Auto | Running])
========== Driver Services ==========
[2008.01.19 09:12:01 | 00,486,456 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_adp94xx.inf_31bf3856ad364e35_6.0.6001.18000_none_5e0fcb9b69814f7b\adp94xx.sys -- (adp94xx [Disabled | Stopped])
[2008.01.19 09:11:40 | 00,342,584 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_adpahci.inf_31bf3856ad364e35_6.0.6001.18000_none_c05c13aa3dfbc961\adpahci.sys -- (adpahci [Disabled | Stopped])
[2008.01.19 09:10:01 | 00,126,520 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_adpu160m.inf_31bf3856ad364e35_6.0.6001.18000_none_f2feed0b63bf261d\adpu160m.sys -- (adpu160m [Disabled | Stopped])
[2008.01.19 09:11:12 | 00,185,912 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_adpu320.inf_31bf3856ad364e35_6.0.6001.18000_none_f4cbbad1148c6b4a\adpu320.sys -- (adpu320 [Disabled | Stopped])
[2008.03.31 23:52:26 | 00,018,488 | ---- | M] (Acer Laboratories Inc.) -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\aliide.sys -- (aliide [Disabled | Stopped])
[2008.01.19 09:09:34 | 00,090,680 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_arc.inf_31bf3856ad364e35_6.0.6001.18000_none_7bfed8c7803713cf\arc.sys -- (arc [Disabled | Stopped])
[2008.01.19 09:09:37 | 00,091,192 | ---- | M] (Adaptec, Inc.) -- C:\Windows\WinSxS\amd64_arcsas.inf_31bf3856ad364e35_6.0.6001.18000_none_771684264153c2d4\arcsas.sys -- (arcsas [Disabled | Stopped])
File not found -- -- (ARCSOFTVIRTUALCAPTURE [On_Demand | Running])
File not found -- -- (aswFsBlk [Auto | Running])
File not found -- -- (aswMonFlt [Auto | Running])
File not found -- -- (aswRdr [System | Running])
File not found -- -- (aswSP [System | Running])
File not found -- -- (aswTdi [System | Running])
File not found -- -- (atksgt [Auto | Running])
[2006.09.18 22:30:15 | 00,018,432 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\WinSxS\amd64_brmfcsto.inf_31bf3856ad364e35_6.0.6001.18000_none_800ff95700142785\BrFiltLo.sys -- (BrFiltLo [On_Demand | Stopped])
[2006.09.18 22:30:15 | 00,008,704 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\WinSxS\amd64_brmfcsto.inf_31bf3856ad364e35_6.0.6001.18000_none_800ff95700142785\BrFiltUp.sys -- (BrFiltUp [On_Demand | Stopped])
[2008.03.31 23:52:26 | 00,020,536 | ---- | M] (CMD Technology, Inc.) -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\cmdide.sys -- (cmdide [Disabled | Stopped])
File not found -- -- (CX88VID [On_Demand | Running])
[2008.01.05 12:22:47 | 00,146,176 | ---- | M] (Intel Corporation) -- C:\Windows\WinSxS\amd64_nete1g3e.inf_31bf3856ad364e35_6.0.6001.18000_none_04b0c96be9c034d3\E1G6032E.sys -- (E1G60 [On_Demand | Stopped])
[2008.01.19 09:11:53 | 00,397,368 | ---- | M] (Emulex) -- C:\Windows\WinSxS\amd64_elxstor.inf_31bf3856ad364e35_6.0.6001.18000_none_08ac13ff69b034ee\elxstor.sys -- (elxstor [Disabled | Stopped])
[2007.10.16 15:15:26 | 00,036,416 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\ET5Drv.sys -- (ET5Drv [On_Demand | Stopped])
[2008.03.31 23:22:24 | 00,020,544 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\Windows\gdrv.sys -- (gdrv [On_Demand | Stopped])
[2008.01.19 09:08:42 | 00,047,672 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\WinSxS\amd64_hpcisss.inf_31bf3856ad364e35_6.0.6001.18000_none_d59c6600292b9522\HpCISSs.sys -- (HpCISSs [Disabled | Stopped])
[2008.01.19 09:11:31 | 00,290,872 | ---- | M] (Intel Corporation) -- C:\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys -- (iaStorV [Disabled | Stopped])
File not found -- -- (IntcAzAudAddService [On_Demand | Running])
File not found -- -- (JRAID [Boot | Running])
File not found -- -- (lirsgt [Auto | Running])
[2008.01.19 09:09:57 | 00,113,720 | ---- | M] (LSI Logic) -- C:\Windows\WinSxS\amd64_lsi_fc.inf_31bf3856ad364e35_6.0.6001.18000_none_c59b4ac1fa719137\lsi_fc.sys -- (LSI_FC [Disabled | Stopped])
[2008.01.19 09:09:48 | 00,105,016 | ---- | M] (LSI Logic) -- C:\Windows\WinSxS\amd64_lsi_sas.inf_31bf3856ad364e35_6.0.6001.18000_none_5b86b7f9e8ff0dc5\lsi_sas.sys -- (LSI_SAS [Disabled | Stopped])
[2008.01.19 09:09:56 | 00,113,720 | ---- | M] (LSI Logic) -- C:\Windows\WinSxS\amd64_lsi_scsi.inf_31bf3856ad364e35_6.0.6001.18000_none_f883c787da42af0c\lsi_scsi.sys -- (LSI_SCSI [Disabled | Stopped])
[2008.01.19 09:08:18 | 00,035,896 | ---- | M] (LSI Corporation) -- C:\Windows\WinSxS\amd64_megasas.inf_31bf3856ad364e35_6.0.6001.18000_none_8c5ef0c0070fb814\megasas.sys -- (megasas [Disabled | Stopped])
[2008.04.01 00:04:29 | 00,001,088 | ---- | M] () -- C:\Windows\System32\wbem\mpsdrv.mof -- (mpsdrv [On_Demand | Running])
[2006.10.14 04:04:34 | 05,942,912 | ---- | M] (NVIDIA Corporation) -- C:\Windows\WinSxS\amd64_nv_lh.inf_31bf3856ad364e35_6.0.6001.18000_none_4a8627558332bbba\nvlddmkm.sys -- (nvlddmkm [On_Demand | Running])
[2008.01.19 09:10:12 | 00,128,056 | ---- | M] (NVIDIA Corporation) -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvraid.sys -- (nvraid [Disabled | Stopped])
[2008.01.19 09:08:50 | 00,054,328 | ---- | M] (NVIDIA Corporation) -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys -- (nvstor [Disabled | Stopped])
[2008.01.19 09:12:10 | 01,221,176 | ---- | M] (QLogic Corporation) -- C:\Windows\WinSxS\amd64_ql2300.inf_31bf3856ad364e35_6.0.6001.18000_none_90b29e0f5eb4b0a1\ql2300.sys -- (ql2300 [Disabled | Stopped])
File not found -- -- (regi [Auto | Running])
File not found -- -- (RTL8169 [On_Demand | Running])
[2006.09.30 00:51:44 | 00,023,040 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\Windows\WinSxS\amd64_macrovision-protection-safedisc_31bf3856ad364e35_6.0.6000.16386_none_b794b0d578b7ec2e\secdrv.sys -- (secdrv [Auto | Running])
[2008.01.19 09:09:28 | 00,078,392 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\WinSxS\amd64_sisraid4.inf_31bf3856ad364e35_6.0.6001.18000_none_8460e59f708bb476\sisraid4.sys -- (SiSRaid4 [Disabled | Stopped])
File not found -- -- (sptd [Boot | Running])
[2006.09.18 22:36:40 | 00,003,066 | ---- | M] () -- C:\Windows\System32\wbem\tcpip.mof -- (Tcpip [Boot | Running])
[2008.01.19 09:11:28 | 00,284,728 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\WinSxS\amd64_uliahci.inf_31bf3856ad364e35_6.0.6001.18000_none_a21b1cbb80e47096\uliahci.sys -- (uliahci [Disabled | Stopped])
[2006.11.02 12:51:19 | 00,174,696 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\WinSxS\amd64_ulsata2.inf_31bf3856ad364e35_6.0.6001.18000_none_9ce1027f4768b389\ulsata2.sys -- (ulsata2 [Disabled | Stopped])
[2008.03.31 23:52:26 | 00,020,536 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\viaide.sys -- (viaide [Disabled | Stopped])
[2008.01.19 09:10:22 | 00,149,048 | ---- | M] (VIA Technologies Inc.,Ltd) -- C:\Windows\WinSxS\amd64_vsmraid.inf_31bf3856ad364e35_6.0.6001.18000_none_508698a452d25e17\vsmraid.sys -- (vsmraid [Disabled | Stopped])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=
http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=
http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=
http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=
http://go.microsoft.com/fwlink/?LinkId=69157
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\Windows\system32\blank.htm
"Search Page"=
http://go.microsoft.com/fwlink/?LinkId=54896
"Start Page"=
http://www.google.cz/
"StartPageCache"=
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{855F3B16-6D32-4fe6-8A56-BBB695989046}" (HKLM) -- C:\Program Files (x86)\ICQToolbar\toolbaru.dll (IE Toolbar)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}" (HKLM) -- C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-3165705971-866493375-3708113550-1000\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\Windows\system32\blank.htm
"Search Page"=
http://go.microsoft.com/fwlink/?LinkId=54896
"Start Page"=
http://www.google.cz/
"StartPageCache"=
[HKEY_USERS\S-1-5-21-3165705971-866493375-3708113550-1000\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{855F3B16-6D32-4fe6-8A56-BBB695989046}" (HKLM) -- C:\Program Files (x86)\ICQToolbar\toolbaru.dll (IE Toolbar)
[HKEY_USERS\S-1-5-21-3165705971-866493375-3708113550-1000\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}" (HKLM) -- C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
[HKEY_USERS\S-1-5-21-3165705971-866493375-3708113550-1000\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
[HKEY_USERS\S-1-5-21-3165705971-866493375-3708113550-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
========== (O1) Hosts File ==========
HOSTS File = (297277 bytes) - C:\Windows\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
::1 localhost
127.0.0.1
http://www.007guard.com" onclick="window.open(this.href);return false;
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1
http://www.008k.com" onclick="window.open(this.href);return false;
127.0.0.1 008k.com
127.0.0.1
http://www.00hq.com" onclick="window.open(this.href);return false;
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1
http://www.032439.com" onclick="window.open(this.href);return false;
127.0.0.1 032439.com
127.0.0.1
http://www.0scan.com" onclick="window.open(this.href);return false;
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1
http://www.1000gratisproben.com" onclick="window.open(this.href);return false;
127.0.0.1 1001namen.com
127.0.0.1
http://www.1001namen.com" onclick="window.open(this.href);return false;
127.0.0.1 100888290cs.com
127.0.0.1
http://www.100888290cs.com" onclick="window.open(this.href);return false;
127.0.0.1
http://www.100sexlinks.com" onclick="window.open(this.href);return false;
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1
http://www.10sek.com" onclick="window.open(this.href);return false;
127.0.0.1
http://www.1-2005-search.com" onclick="window.open(this.href);return false;
10269 more lines...
========== (O2) BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} (HKLM) -- C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
{055FD26D-3A88-4e15-963D-DC8493744B1D} (HKLM) -- C:\Program Files (x86)\ICQToolbar\toolbaru.dll (IE Toolbar)
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} (HKLM) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
{EEE6C35C-6118-11DC-9C72-001320C79847} (HKLM) -- C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
========== (O3) Toolbars ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{855F3B16-6D32-4fe6-8A56-BBB695989046}" (HKLM) -- C:\Program Files (x86)\ICQToolbar\toolbaru.dll (IE Toolbar)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}" (HKLM) -- C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{855F3B16-6D32-4FE6-8A56-BBB695989046}" (HKLM) -- C:\Program Files (x86)\ICQToolbar\toolbaru.dll (IE Toolbar)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}" (HKLM) -- C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
[HKEY_USERS\S-1-5-21-3165705971-866493375-3708113550-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{855F3B16-6D32-4FE6-8A56-BBB695989046}" (HKLM) -- C:\Program Files (x86)\ICQToolbar\toolbaru.dll (IE Toolbar)
[HKEY_USERS\S-1-5-21-3165705971-866493375-3708113550-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}" (HKLM) -- C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
"GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe ()
"QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
"SunJavaUpdateSched"="C:\Program Files (x86)\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
"SweetIM"=C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
"WinFast Schedule"="C:\Program Files (x86)\WinFast\WFDTV\WFWIZ.exe" (Leadtek Research Inc.)
"WinFastDTV"="C:\Program Files (x86)\WinFast\WFDTV\DTVSchdl.exe" (Leadtek Research Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
"ehTray.exe"=C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
"Google Update"="C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe" /c File not found
"ISUSPM"="C:\Program Files (x86)\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler (InstallShield Software Corporation)
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup (InstallShield Software Corporation)
"ISUSScheduler"="C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start (Macrovision Corporation)
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
"SpybotSD TeaTimer"=C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
"WMPNSCFG"=C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-3165705971-866493375-3708113550-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
"ehTray.exe"=C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
"Google Update"="C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe" /c File not found
"ISUSPM"="C:\Program Files (x86)\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler (InstallShield Software Corporation)
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup (InstallShield Software Corporation)
"ISUSScheduler"="C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start (Macrovision Corporation)
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
"SpybotSD TeaTimer"=C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
"WMPNSCFG"=C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoActiveDesktop"=1
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"ConsentPromptBehaviorAdmin"=2
"ConsentPromptBehaviorUser"=1
"EnableInstallerDetection"=1
"EnableLUA"=1
"EnableSecureUIAPaths"=1
"EnableVirtualization"=1
"PromptOnSecureDesktop"=1
"ValidateAdminCodeSignatures"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"scforceoption"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"FilterAdministratorToken"=0
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=1
"CF_BITMAP"=2
"CF_OEMTEXT"=7
"CF_DIB"=8
"CF_PALETTE"=9
"CF_UNICODETEXT"=13
"CF_DIBV5"=17
========== (O8) IE Context Menu Extensions ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xportovat do aplikace Microsoft Excel: C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE [2006.10.27 14:07:36 | 17,891,112 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-3165705971-866493375-3708113550-1000\Software\Microsoft\Internet Explorer\MenuExt\]
E&xportovat do aplikace Microsoft Excel: C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE [2006.10.27 14:07:36 | 17,891,112 | ---- | M] (Microsoft Corporation)
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Button: Odeslat do aplikace OneNote -- %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2006.10.26 20:32:42 | 00,604,000 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Menu: Od&eslat do aplikace OneNote -- %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [2006.10.26 20:32:42 | 00,604,000 | ---- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [2006.10.26 19:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}: Menu: Spybot - Search && Destroy Configuration -- %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [2008.09.15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)
{E59EB121-F339-4851-A3BA-FE49C35617C2}: Button: ICQ6 -- %ProgramFiles%\ICQ6\ICQ.exe [2008.09.01 16:08:21 | 00,173,304 | ---- | M] (ICQ, Inc.)
{E59EB121-F339-4851-A3BA-FE49C35617C2}: Menu: ICQ6 -- %ProgramFiles%\ICQ6\ICQ.exe [2008.09.01 16:08:21 | 00,173,304 | ---- | M] (ICQ, Inc.)
========== (O12) Internet Explorer Plugins ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" =
http://activex.microsoft.com/controls/find.asp?ext=" onclick="window.open(this.href);return false;%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
48 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
48 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
48 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
48 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-21-3165705971-866493375-3708113550-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
48 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}: C:\Program Files (x86)\Yahoo!\Common\yinsthelper.dll -- YInstStarter Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}:
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab" onclick="window.open(this.href);return false; -- Java Plug-in 1.6.0_12
{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab" onclick="window.open(this.href);return false; -- Java Plug-in 1.6.0_12
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab" onclick="window.open(this.href);return false; -- Java Plug-in 1.6.0_12
========== (O17) DNS Name Servers ==========
{3E1F1BDF-1904-4A88-A2C3-EA636F3CE37A} (Servers: | Description: Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.0))
{AD795081-0EA1-4FD8-9A23-AE3159469506} (Servers: | Description: Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.0))
========== (O20) HKLM Winlogon Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=explorer.exe
>[2008.10.29 07:29:41 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\explorer.exe
========== (O21) SSODL Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED} (HKLM) -- C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
========== Shell Execute Hooks ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" (HKLM) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
========== HKLM *SecurityProviders* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders"=credssp.dll
>[2008.01.19 08:33:59 | 00,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\credssp.dll
========== LSA *Security Packages* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages"=kerberos,msv1_0,schannel,wdigest,tspkg,
>[2008.01.19 08:36:42 | 00,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\TSpkg.dll
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== MountPoints2 ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{af662630-735b-11dd-b3cb-001d7d050cf1}\Shell]
""=AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{af662630-735b-11dd-b3cb-001d7d050cf1}\Shell\AutoRun\command]
""=M:\Enterprise_Launcher.exe -- File not found
========== Files/Folders - Created Within 30 Days ==========
[2009.03.12 02:43:02 | 00,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Malwarebytes
[2009.03.12 02:43:01 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009.03.12 02:43:01 | 00,000,848 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.03.12 02:42:59 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009.03.12 02:42:58 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009.03.12 02:42:58 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2009.03.11 15:14:28 | 00,268,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schannel.dll
[2009.03.07 13:23:44 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2009.03.04 01:09:51 | 00,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Nero
[2009.03.02 15:31:00 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009.03.02 15:27:30 | 00,001,805 | ---- | C] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009.03.02 15:27:13 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2009.03.02 15:27:13 | 00,380,928 | ---- | C] () -- C:\Windows\System32\actskin4.ocx
[2009.03.02 14:56:32 | 46,082,5871 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2009.02.28 22:00:37 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2009.02.28 17:08:36 | 00,000,146 | ---- | C] () -- C:\Users\User\AppData\Roaming\default.rss
[2009.02.28 02:25:25 | 00,189,072 | ---- | C] () -- C:\Windows\System32\PnkBstrB.xtr
[2009.02.27 20:15:54 | 00,000,000 | ---D | C] -- C:\ProgramData\LightScribe
[2009.02.27 20:15:43 | 00,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Nero
[2009.02.27 18:33:27 | 00,002,589 | ---- | C] () -- C:\Users\Public\Desktop\Nero StartSmart.lnk
[2009.02.27 18:25:52 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Nero
[2009.02.27 18:25:19 | 00,000,000 | ---D | C] -- C:\ProgramData\Nero
[2009.02.27 18:25:17 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nero
[2009.02.26 19:46:50 | 00,042,320 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2009.02.26 16:39:15 | 00,013,287 | ---- | C] () -- C:\Users\User\Desktop\Zápis o kontrole elektroinstalace.docx
[2009.02.24 15:33:59 | 00,000,000 | ---D | C] -- C:\ProgramData\2DBoy
[2009.02.24 15:32:16 | 00,000,672 | ---- | C] () -- C:\Users\Public\Desktop\World of Goo.lnk
[2009.02.21 17:57:28 | 00,054,156 | -H-- | C] () -- C:\Windows\QTFont.qfn
[2009.02.21 17:57:28 | 00,001,409 | ---- | C] () -- C:\Windows\QTFont.for
[2009.02.20 20:53:34 | 00,000,000 | ---D | C] -- C:\Users\User\Documents\EA Games
[2009.02.20 20:53:28 | 00,000,838 | ---- | C] () -- C:\Users\User\Desktop\MirrorsEdge.lnk
[2009.02.16 00:00:47 | 00,428,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2009.02.16 00:00:47 | 00,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2009.02.16 00:00:46 | 00,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2009.02.16 00:00:46 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2009.02.16 00:00:46 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2009.02.11 23:26:57 | 00,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\ACD Systems
[2009.02.11 23:26:57 | 00,000,000 | ---D | C] -- C:\Users\User\AppData\Local\ACD Systems
[2009.02.11 22:54:13 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2009.02.11 22:47:53 | 00,002,082 | ---- | C] () -- C:\Users\Public\Desktop\ACDSee Photo Manager 2009.lnk
[2009.02.11 22:47:45 | 00,000,000 | ---D | C] -- C:\ProgramData\ACD Systems
[2009.02.11 22:47:41 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ACD Systems
[2009.02.11 22:47:41 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\ACD Systems
[2009.02.11 22:45:57 | 00,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Downloaded Installations
[2009.02.11 22:28:14 | 00,027,904 | ---- | C] (TuneUp Software) -- C:\Windows\System32\uxtuneup.dll
[2009.02.11 22:28:14 | 00,017,152 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2009.02.11 22:28:00 | 00,000,496 | ---- | C] () -- C:\Windows\tasks\1-Click Maintenance.job
[2009.02.11 22:28:00 | 00,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\TuneUp Software
[2009.02.11 22:27:56 | 00,001,741 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2009.02.11 22:27:56 | 00,001,669 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2009.lnk
[2009.02.11 22:27:40 | 00,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2009.02.11 22:27:40 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\TuneUp Utilities 2009
[2009.02.11 22:27:10 | 00,000,000 | -HSD | C] -- C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357}
[2009.02.11 17:56:17 | 06,069,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll
[2009.02.11 17:56:17 | 03,580,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll
[2009.02.11 17:56:16 | 01,166,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll
[2009.02.11 17:56:16 | 00,458,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2009.02.11 17:56:15 | 00,827,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll
[2009.02.11 17:56:15 | 00,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2009.02.11 17:56:14 | 01,383,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2009.02.11 17:56:14 | 00,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll
[2009.02.11 17:56:14 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
========== Files - Modified Within 30 Days ==========
[1 C:\Windows\System32\*.tmp files]
[2009.03.12 17:15:29 | 00,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{7A705C21-3085-4974-B8A0-989943ECD5D4}.job
[2009.03.12 17:08:51 | 00,000,496 | ---- | M] () -- C:\Windows\tasks\1-Click Maintenance.job
[2009.03.12 17:08:40 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009.03.12 17:08:37 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009.03.12 17:08:18 | 42,933,86240 | -HS- | M] () -- C:\hiberfil.sys
[2009.03.12 17:07:26 | 03,442,722 | -H-- | M] () -- C:\Users\User\AppData\Local\IconCache.db
[2009.03.12 04:29:25 | 00,000,146 | ---- | M] () -- C:\Users\User\AppData\Roaming\default.rss
[2009.03.12 02:50:12 | 00,128,512 | ---- | M] () -- C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.03.12 02:43:01 | 00,000,848 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.03.12 02:13:27 | 00,189,072 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2009.03.12 02:13:27 | 00,189,072 | ---- | M] () -- C:\Windows\System32\PnkBstrB.exe
[2009.03.02 15:27:30 | 00,001,805 | ---- | M] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009.03.02 15:27:28 | 00,000,000 | ---- | M] () -- C:\Windows\System32\config.nt
[2009.03.02 14:57:27 | 46,082,5871 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2009.02.28 01:40:59 | 00,075,064 | ---- | M] () -- C:\Windows\System32\PnkBstrA.exe
[2009.02.27 18:33:27 | 00,002,589 | ---- | M] () -- C:\Users\Public\Desktop\Nero StartSmart.lnk
[2009.02.26 19:46:50 | 00,042,320 | ---- | M] () -- C:\Windows\System32\xfcodec.dll
[2009.02.26 17:20:19 | 00,013,287 | ---- | M] () -- C:\Users\User\Desktop\Zápis o kontrole elektroinstalace.docx
[2009.02.24 15:32:16 | 00,000,672 | ---- | M] () -- C:\Users\Public\Desktop\World of Goo.lnk
[2009.02.21 17:57:28 | 00,054,156 | -H-- | M] () -- C:\Windows\QTFont.qfn
[2009.02.21 17:57:28 | 00,001,409 | ---- | M] () -- C:\Windows\QTFont.for
[2009.02.21 11:20:13 | 00,001,097 | ---- | M] () -- C:\Users\User\Desktop\Spybot - Search & Destroy.lnk
[2009.02.21 11:09:54 | 00,001,724 | ---- | M] () -- C:\Users\User\Desktop\CCleaner.lnk
[2009.02.20 20:53:28 | 00,000,838 | ---- | M] () -- C:\Users\User\Desktop\MirrorsEdge.lnk
[2009.02.11 23:12:26 | 00,099,880 | ---- | M] () -- C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
[2009.02.11 22:47:53 | 00,002,082 | ---- | M] () -- C:\Users\Public\Desktop\ACDSee Photo Manager 2009.lnk
[2009.02.11 22:27:56 | 00,001,741 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2009.02.11 22:27:56 | 00,001,669 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2009.lnk
[2009.02.11 10:19:42 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009.02.11 10:19:34 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009.02.10 17:58:41 | 00,000,790 | ---- | M] () -- C:\Users\User\Desktop\HLSW.lnk
< End of report >