Úkony provedeny. Dr. Web Curelt ohlásil nějaké infikované soubory, sedm kusů (jednalo se o soubory redakčního systému phpRS resp. staré zálohy webu) a pak něco v common files. Akorát nevím jestli je někde z toho log...
Přikládám log z CrystalDiskInfo:
----------------------------------------------------------------------------
CrystalDiskInfo 4.0.2 (C) 2008-2011 hiyohiyo
Crystal Dew World :
http://crystalmark.info/----------------------------------------------------------------------------
OS : Windows Vista Home Premium Edition SP2 [6.0 Build 6002] (x86)
Date : 2011/07/07 15:39:30
-- Controller Map ----------------------------------------------------------
+ Řadiče úložiště Intel(R) 82801G (řada ICH7) v režimu Ultra ATA - 27DF [ATA]
- Kanál IDE (0)
- Kanál IDE (1)
+ Řadič úložiště Intel(R) 82801GB/GR/GH (řada ICH7) s rozhraním Serial ATA - 27C0 [ATA]
+ Kanál IDE (0)
- TSSTcorp CDDVDW SH-S223F ATA Device
- WDC WD5000AACS-00G8B1 ATA Device
- Kanál IDE (1)
- Iniciátor iSCSI společnosti Microsoft [SCSI]
-- Disk List ---------------------------------------------------------------
(1) WDC WD5000AACS-00G8B1 : 500.1 GB [0-2-0, pd1]
----------------------------------------------------------------------------
(1) WDC WD5000AACS-00G8B1
----------------------------------------------------------------------------
Model : WDC WD5000AACS-00G8B1
Firmware : 05.04C05
Serial Number : WD-WCAUK0177939
Disk Size : 500.1 GB (8.4/137.4/500.1)
Buffer Size : 16384 KB
Queue Depth : 32
# of Sectors : 976773168
Rotation Rate : Neznámy údaj
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : SATA/300
Power On Hours : 7168 hod.
Power On Count : 1748 krát
Temparature : 42 C (107 F)
Health Status : Dobrý
Features : S.M.A.R.T., AAM, 48bit LBA, NCQ
APM Level : ----
AAM Level : 80FEh [OFF]
-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000000 Počet chyb čtení
03 134 133 _21 00000000188B Čas na roztočení ploten
04 _99 _99 __0 0000000006EE Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 100 253 __0 000000000000 Počet chybných hledání
09 _91 _91 __0 000000001C00 Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C _99 _99 __0 0000000006D4 Počet cyklů zapnutí zařízení
C0 200 200 __0 000000000009 Počet vypnutí disku
C1 200 200 __0 0000000006EE Počet cyklů načítání/vymazání
C2 105 102 __0 00000000002A Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 100 253 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 100 253 __0 000000000000 Počet chyb při zápisu sektorů
-- IDENTIFY_DEVICE ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 42 7A 3F FF C8 37 00 10 00 00 00 00 00 3F 00 00
010: 00 00 00 00 20 20 20 20 20 57 44 2D 57 43 41 55
020: 4B 30 31 37 37 39 33 39 00 00 80 00 00 32 30 35
030: 2E 30 34 43 30 35 57 44 43 20 57 44 35 30 30 30
040: 41 41 43 53 2D 30 30 47 38 42 31 20 20 20 20 20
050: 20 20 20 20 20 20 20 20 20 20 20 20 20 20 80 10
060: 00 00 2F 00 40 01 00 00 00 00 00 07 3F FF 00 10
070: 00 3F FC 10 00 FB 01 10 FF FF 0F FF 00 00 00 07
080: 00 03 00 78 00 78 00 78 00 78 00 00 00 00 00 00
090: 00 00 00 00 00 00 00 1F 07 06 00 00 00 44 00 40
0A0: 01 FE 00 00 74 6B 7F 61 41 23 74 69 BC 41 41 23
0B0: 20 7F 00 38 00 38 00 00 FF FE 00 00 80 FE 00 00
0C0: 00 00 00 00 00 00 00 00 60 30 3A 38 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 50 01 4E E1 56 EF 85 D8
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 10
0F0: 40 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 29 00 00 00 00 00 00 00 00 16 BA 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 30 3F 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 10 0E 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 01 10 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 7B A5
Logy z OTL:
OTL.txtOTL logfile created on: 7.7.2011 15:42:57 - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Jarda\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,50 Gb Total Physical Memory | 2,39 Gb Available Physical Memory | 68,28% Memory free
7,18 Gb Paging File | 6,17 Gb Available in Paging File | 85,98% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465,76 Gb Total Space | 109,72 Gb Free Space | 23,56% Space Free | Partition Type: NTFS
Computer Name: JARDA-PC | User Name: Jarda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Users\Jarda\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Windows\System32\NLSSRV32.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Windows\System32\audiodg.exe (Microsoft Corporation)
PRC - C:\Genius\ioCentre\gMouseTask.exe ()
PRC - C:\Genius\ioCentre\gKbdTask.exe ()
PRC - C:\Genius\ioCentre\gKbStatus.exe ()
PRC - C:\Genius\ioCentre\gIMMgm.exe ()
PRC - C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
PRC - C:\Program Files\TO2SSM\McciTrayApp.exe (Motive Communications, Inc.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\CNAC8SWK.EXE (CANON INC.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\CNAP2RPK.EXE (CANON INC.)
PRC - C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
PRC - C:\Genius\ioCentre\gDeskMgm.exe ()
PRC - C:\Genius\ioCentre\gTaskBar.exe ()
PRC - C:\Program Files\ASUS\GamerOSD\GamerOSD.exe (ASUSTeK Computer Inc.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\CNAP2LAK.EXE (CANON INC.)
PRC - C:\Genius\ioCentre\gTaskSwitch.exe ()
PRC - C:\Genius\ioCentre\gZoom.exe ()
PRC - C:\Genius\ioCentre\gAutoPan.exe ()
PRC - C:\Genius\ioCentre\gAutoScroll.exe ()
========== Modules (SafeList) ========== MOD - C:\Users\Jarda\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (nlsX86cc) -- C:\Windows\System32\NLSSRV32.EXE (Nalpeiron Ltd.)
SRV - (EhttpSrv) -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (ESET)
SRV - (ekrn) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ATKFUSService) -- C:\Windows\System32\ATKFUSService.exe (ASUSTeK COMPUTER INC.)
========== Driver Services (SafeList) ========== DRV - (eamonm) -- C:\Windows\System32\drivers\eamonm.sys (ESET)
DRV - (epfw) -- C:\Windows\System32\drivers\epfw.sys (ESET)
DRV - (ehdrv) -- C:\Windows\System32\drivers\ehdrv.sys (ESET)
DRV - (epfwwfp) -- C:\Windows\System32\drivers\epfwwfp.sys (ESET)
DRV - (Epfwndis) -- C:\Windows\System32\drivers\epfwndis.sys (ESET)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (npf) -- C:\Windows\System32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (RTL8169) -- C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (VIAHdAudAddService) -- C:\Windows\System32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (MREMP50) -- C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) -- C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (EIO) -- C:\Windows\System32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (atkdisplf) -- C:\Windows\System32\drivers\ATKDispLowFilter.sys (ASUSTeK Computer Inc.)
DRV - (asusgsb) -- C:\Windows\System32\drivers\asusgsb.sys (ASUSTeK Computer Inc.)
DRV - (Axtmvprt) -- C:\Windows\System32\drivers\Axtmvprt.sys (Axesstel)
DRV - (Axtmvmdm) -- C:\Windows\System32\drivers\Axtmvmdm.sys (Axesstel)
DRV - (Axtmvflt) -- C:\Windows\System32\drivers\Axtmvflt.sys (Axesstel)
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
DRV - (StarOpen) -- C:\Windows\System32\drivers\StarOpen.sys ()
DRV - (gMouPS2) -- C:\Windows\System32\drivers\gMouPS2.sys ( Mouse Upfilter Driver )
DRV - (sscdmdm) -- C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) -- C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) -- C:\Windows\System32\drivers\sscdbus.sys (MCCI)
========== Standard Registry (All) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearchIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.centrum.cz/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E6 B8 D5 A9 72 61 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google Custom Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://seznam.cz/"
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.10
FF - prefs.js..extensions.enabledItems:
foxdie_ext_ocelot@foxdie.us:3.6.4
FF - prefs.js..extensions.enabledItems:
refspoof@mozdev.org:0.9.5
FF - prefs.js..extensions.enabledItems: {ea614400-e918-4741-9a97-7a972ff7c30b}:2.1.14
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16
FF - prefs.js..extensions.enabledItems:
Foxdie@tanjihay.com:3.6.4
FF - prefs.js..extensions.enabledItems:
FoxdieGraphite@tanjihay.com:3.6.4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009.08.28 21:27:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011.05.31 13:33:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011.05.31 13:33:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.07.06 22:16:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.07.06 19:13:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010.10.29 23:48:23 | 000,000,000 | ---D | M]
[2009.08.28 14:59:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Extensions
[2009.08.28 14:59:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2011.07.06 19:22:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions
[2011.07.06 19:22:38 | 000,000,000 | ---D | M] (SeoQuake) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2011.07.06 19:22:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2011.07.06 19:22:37 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011.06.15 14:03:46 | 000,000,000 | ---D | M] (Seznam lištička) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
[2011.07.06 19:22:40 | 000,000,000 | ---D | M] ("Flash Video Downloader - CENZURA") -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions\artur.dubovoy@gmail.com
[2011.07.06 19:22:39 | 000,000,000 | ---D | M] (AutoProxy) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions\autoproxy@autoproxy.org
[2011.07.06 19:22:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions\Foxdie@tanjihay.com
[2011.07.06 19:22:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions\foxdie_ext_ocelot@foxdie.us
[2011.07.06 19:22:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions\FoxdieGraphite@tanjihay.com
[2011.07.06 19:22:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions\refspoof@mozdev.org
[2011.07.06 19:22:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\extensions\staged-xpis
[2010.02.03 15:35:06 | 000,002,057 | ---- | M] () -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\searchplugins\firmycz.xml
[2011.06.29 20:04:23 | 000,000,950 | ---- | M] () -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\searchplugins\icqplugin-1.xml
[2011.03.05 12:31:20 | 000,000,950 | ---- | M] () -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\searchplugins\icqplugin-2.xml
[2011.03.05 12:56:14 | 000,000,950 | ---- | M] () -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\searchplugins\icqplugin-3.xml
[2011.03.23 10:28:42 | 000,000,950 | ---- | M] () -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\searchplugins\icqplugin-4.xml
[2011.02.27 19:26:37 | 000,001,056 | ---- | M] () -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\searchplugins\icqplugin.xml
[2010.02.03 15:35:06 | 000,002,052 | ---- | M] () -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\searchplugins\mapycz.xml
[2010.02.03 15:35:07 | 000,002,195 | ---- | M] () -- C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\amkikk3h.default\searchplugins\zbocz.xml
[2011.07.06 19:13:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.07.06 19:13:08 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) --
File not found (No name found) -- C:\USERS\JARDA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMKIKK3H.DEFAULT\EXTENSIONS\{317B5128-0B0B-49B2-B2DB-1E7560E16C74}.XPI
File not found (No name found) -- C:\USERS\JARDA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMKIKK3H.DEFAULT\EXTENSIONS\{A7C6CF7F-112C-4500-A7EA-39801A327E5F}.XPI
File not found (No name found) -- C:\USERS\JARDA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMKIKK3H.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
File not found (No name found) -- C:\USERS\JARDA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMKIKK3H.DEFAULT\EXTENSIONS\ARTUR.DUBOVOY@GMAIL.COM.XPI
File not found (No name found) -- C:\USERS\JARDA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AMKIKK3H.DEFAULT\EXTENSIONS\AUTOPROXY@AUTOPROXY.ORG.XPI
[2009.08.28 21:27:10 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011.06.25 16:01:52 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007.04.10 17:21:08 | 000,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2006.10.26 20:12:16 | 000,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2011.06.06 12:55:30 | 000,183,696 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2011.06.15 09:52:38 | 000,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2011.06.15 09:52:38 | 000,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2011.06.15 09:52:38 | 000,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2011.06.15 09:52:38 | 000,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2011.06.15 09:52:38 | 000,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2011.06.15 09:52:38 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2011.06.15 09:52:38 | 000,001,096 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: ([2011.03.21 02:38:51 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (no name) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - No CLSID value found.
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKLM\..\Toolbar: (@C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [CNAP2 Launcher] C:\Windows\System32\spool\drivers\w32x86\3\CNAP2LAK.EXE (CANON INC.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe ()
O4 - HKLM..\Run: [PDVD9LanguageShortcut] C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl9] C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe (Motive Communications, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - C:\Program Files\ICQ7.4\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\NapiNSP.dll (Společnost Microsoft)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\winrnr.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Bejeweled%203/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Bejeweled%203/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/pub/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\Windows\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\Windows\System32\sysdm.cpl (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\System32\browseui.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Jarda\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Jarda\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\System32\credssp.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\System32\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\System32\tspkg.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ========== [2011.07.07 15:39:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
[2011.07.07 15:39:13 | 000,000,000 | ---D | C] -- C:\Program Files\CrystalDiskInfo
[2011.07.07 15:29:49 | 000,000,000 | R--D | C] -- C:\Users\Jarda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 9
[2011.07.07 13:28:53 | 000,000,000 | ---D | C] -- C:\Users\Jarda\Desktop\backups
[2011.07.07 13:26:04 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Users\Jarda\Desktop\OTL.exe
[2011.07.07 00:12:47 | 000,000,000 | ---D | C] -- C:\Users\Jarda\AppData\Local\ElevatedDiagnostics
[2011.07.06 23:38:35 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011.07.06 23:38:27 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2011.07.06 23:34:25 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011.07.06 23:32:46 | 000,000,000 | ---D | C] -- C:\Users\Jarda\AppData\Local\temp
[2011.07.06 23:31:58 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011.07.06 22:29:09 | 004,132,805 | R--- | C] (Swearware) -- C:\Users\Jarda\Desktop\ComboFix.exe
[2011.07.06 22:11:47 | 000,000,000 | ---D | C] -- C:\Users\Jarda\AppData\Local\Adobe
[2011.06.27 10:47:03 | 000,000,000 | ---D | C] -- C:\Users\Jarda\Documents\web spolupráce
[2011.06.27 10:36:24 | 000,000,000 | ---D | C] -- C:\Users\Jarda\Desktop\Sport - fotoškola
[2011.06.26 22:47:29 | 000,000,000 | ---D | C] -- C:\Users\Jarda\Desktop\literatura foto sken
[2011.06.25 12:26:24 | 000,000,000 | ---D | C] -- C:\Users\Jarda\Desktop\Zdroje info foto handouty
[2011.06.17 08:07:11 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2011.06.14 23:07:50 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011.06.14 23:07:49 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011.06.14 23:07:49 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011.06.14 23:07:49 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011.06.13 14:22:38 | 000,000,000 | ---D | C] -- C:\Users\Jarda\AppData\Local\{C42875C7-BFFF-4FAD-BAB2-DB36FD85263E}
[2011.06.13 14:22:38 | 000,000,000 | ---D | C] -- C:\Users\Jarda\AppData\Local\{117FAD5C-92A1-4EAB-8305-9004B13E8B7B}
[2011.06.08 09:35:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaimaRadio
[2011.06.08 09:35:16 | 000,000,000 | ---D | C] -- C:\Users\Jarda\AppData\Roaming\RaimaRadio
[2011.06.08 09:35:15 | 000,000,000 | ---D | C] -- C:\Program Files\RaimaRadio
[2011.06.08 09:20:15 | 000,000,000 | ---D | C] -- C:\Users\Jarda\AppData\Roaming\COWON
[2011.06.08 09:17:01 | 000,000,000 | ---D | C] -- C:\WMP3E_Temp
[2009.11.08 16:42:30 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Jarda\AppData\Roaming\pcouffin.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011.07.07 15:39:14 | 000,001,765 | ---- | M] () -- C:\Users\Jarda\Desktop\CrystalDiskInfo.lnk
[2011.07.07 15:29:52 | 000,036,917 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2011.07.07 15:29:52 | 000,036,917 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011.07.07 15:29:19 | 000,004,112 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.07.07 15:29:19 | 000,004,112 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.07.07 15:29:04 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.07.07 15:28:59 | 3757,236,224 | -HS- | M] () -- C:\hiberfil.sys
[2011.07.07 15:28:58 | 459,668,592 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011.07.07 13:26:07 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\Jarda\Desktop\OTL.exe
[2011.07.07 13:25:56 | 000,040,138 | ---- | M] () -- C:\Users\Jarda\Desktop\crystaldiskinfo.htm
[2011.07.07 13:25:25 | 070,143,712 | ---- | M] () -- C:\Users\Jarda\Desktop\launch.exe
[2011.07.07 00:36:51 | 000,000,134 | ---- | M] () -- C:\Users\Jarda\Desktop\Microsoft Fix it.url
[2011.07.06 22:36:44 | 000,607,226 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2011.07.06 22:36:44 | 000,595,798 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.07.06 22:36:44 | 000,117,890 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2011.07.06 22:36:44 | 000,103,872 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.07.06 22:24:24 | 004,132,805 | R--- | M] (Swearware) -- C:\Users\Jarda\Desktop\ComboFix.exe
[2011.07.05 13:03:56 | 001,606,351 | ---- | M] () -- C:\Users\Jarda\Desktop\FF_studijni_plany_prezencni_2011-12.pdf
[2011.07.05 11:19:10 | 000,379,946 | ---- | M] () -- C:\Users\Jarda\Desktop\FF_studijni_plany_kombinovane_2011-12.pdf
[2011.07.04 14:34:46 | 000,199,680 | ---- | M] () -- C:\Users\Jarda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.07.03 19:33:00 | 000,155,735 | ---- | M] () -- C:\Users\Jarda\Desktop\Prava_a_povinnosti_uchazecu_o_ECDL_Certifikat_01.pdf
[2011.07.03 19:02:12 | 004,878,195 | ---- | M] () -- C:\Users\Jarda\Desktop\zppc.pdf
[2011.07.03 18:17:53 | 000,002,675 | ---- | M] () -- C:\Users\Jarda\Desktop\Microsoft Office Word 2007.lnk
[2011.07.03 17:45:10 | 005,935,883 | ---- | M] () -- C:\Users\Jarda\Desktop\manual new modem.pdf
[2011.07.03 17:19:59 | 000,129,176 | ---- | M] () -- C:\Users\Jarda\Desktop\metodikabp2010.pdf
[2011.07.03 17:09:10 | 000,393,209 | ---- | M] () -- C:\Users\Jarda\Desktop\diplomky_TULvB.pdf
[2011.07.03 13:25:52 | 000,116,051 | ---- | M] () -- C:\Users\Jarda\Desktop\2010_11_Temata_diplomovych_praci_KZ.pdf
[2011.06.29 07:44:27 | 000,393,856 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011.06.26 08:45:56 | 000,256,000 | ---- | M] () -- C:\Windows\PEV.exe
[2011.06.20 20:49:46 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011.06.17 08:07:20 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011.06.08 09:35:19 | 000,000,772 | ---- | M] () -- C:\Users\Jarda\Desktop\RaimaRadio.lnk
[2011.06.07 18:27:21 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2011.07.07 15:39:14 | 000,001,765 | ---- | C] () -- C:\Users\Jarda\Desktop\CrystalDiskInfo.lnk
[2011.07.07 13:25:55 | 000,040,138 | ---- | C] () -- C:\Users\Jarda\Desktop\crystaldiskinfo.htm
[2011.07.07 13:23:50 | 070,143,712 | ---- | C] () -- C:\Users\Jarda\Desktop\launch.exe
[2011.07.07 00:35:49 | 000,000,134 | ---- | C] () -- C:\Users\Jarda\Desktop\Microsoft Fix it.url
[2011.07.07 00:03:58 | 3757,236,224 | -HS- | C] () -- C:\hiberfil.sys
[2011.07.06 22:30:57 | 459,668,592 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011.07.05 13:03:55 | 001,606,351 | ---- | C] () -- C:\Users\Jarda\Desktop\FF_studijni_plany_prezencni_2011-12.pdf
[2011.07.05 11:19:09 | 000,379,946 | ---- | C] () -- C:\Users\Jarda\Desktop\FF_studijni_plany_kombinovane_2011-12.pdf
[2011.07.03 19:32:59 | 000,155,735 | ---- | C] () -- C:\Users\Jarda\Desktop\Prava_a_povinnosti_uchazecu_o_ECDL_Certifikat_01.pdf
[2011.07.03 19:02:11 | 004,878,195 | ---- | C] () -- C:\Users\Jarda\Desktop\zppc.pdf
[2011.07.03 17:45:09 | 005,935,883 | ---- | C] () -- C:\Users\Jarda\Desktop\manual new modem.pdf
[2011.07.03 17:19:59 | 000,129,176 | ---- | C] () -- C:\Users\Jarda\Desktop\metodikabp2010.pdf
[2011.07.03 17:09:08 | 000,393,209 | ---- | C] () -- C:\Users\Jarda\Desktop\diplomky_TULvB.pdf
[2011.07.03 13:25:52 | 000,116,051 | ---- | C] () -- C:\Users\Jarda\Desktop\2010_11_Temata_diplomovych_praci_KZ.pdf
[2011.06.17 08:07:20 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011.06.17 08:07:20 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011.06.08 09:35:19 | 000,000,772 | ---- | C] () -- C:\Users\Jarda\Desktop\RaimaRadio.lnk
[2011.05.10 21:50:24 | 000,036,917 | ---- | C] () -- C:\ProgramData\nvModes.001
[2011.05.10 21:50:23 | 000,036,917 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2011.03.20 23:31:18 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011.03.20 23:31:18 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011.03.20 23:31:18 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011.03.20 23:31:18 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011.03.20 23:31:18 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011.01.30 17:51:11 | 000,000,058 | ---- | C] () -- C:\Users\Jarda\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
[2010.12.16 18:48:48 | 000,130,048 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2010.07.29 21:04:04 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010.06.15 18:18:16 | 000,000,085 | -HS- | C] () -- C:\ProgramData\.zreglib
[2010.03.05 01:39:30 | 000,000,033 | ---- | C] () -- C:\Windows\Multimedia manager.INI
[2010.03.04 23:47:25 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2010.03.04 23:39:59 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2009.11.16 18:33:38 | 000,053,299 | ---- | C] () -- C:\Windows\System32\pthreadVC.dll
[2009.11.08 16:43:28 | 000,001,041 | ---- | C] () -- C:\Users\Jarda\AppData\Roaming\vso_ts_preview.xml
[2009.11.08 16:42:30 | 000,007,887 | ---- | C] () -- C:\Users\Jarda\AppData\Roaming\pcouffin.cat
[2009.11.08 16:42:30 | 000,001,144 | ---- | C] () -- C:\Users\Jarda\AppData\Roaming\pcouffin.inf
[2009.09.22 21:05:01 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2009.09.22 21:04:59 | 000,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009.09.22 21:04:55 | 000,103,736 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2009.09.16 17:27:58 | 000,508,224 | ---- | C] () -- C:\Windows\System32\ICCProfiles.dll
[2009.09.01 23:54:26 | 000,004,096 | -H-- | C] () -- C:\Users\Jarda\AppData\Local\keyfile3.drm
[2009.08.30 11:06:22 | 000,024,206 | ---- | C] () -- C:\Users\Jarda\AppData\Roaming\UserTile.png
[2009.08.28 21:47:52 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.08.28 21:47:51 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.08.28 16:13:49 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009.08.28 14:17:16 | 000,007,680 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[2009.08.28 14:17:14 | 000,014,654 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2009.08.28 14:10:54 | 000,761,856 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009.08.28 14:10:54 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009.08.28 13:45:26 | 000,199,680 | ---- | C] () -- C:\Users\Jarda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.01.21 08:46:38 | 000,607,226 | ---- | C] () -- C:\Windows\System32\perfh005.dat
[2008.01.21 08:46:38 | 000,286,912 | ---- | C] () -- C:\Windows\System32\perfi005.dat
[2008.01.21 08:46:38 | 000,117,890 | ---- | C] () -- C:\Windows\System32\perfc005.dat
[2008.01.21 08:46:38 | 000,034,724 | ---- | C] () -- C:\Windows\System32\perfd005.dat
[2007.08.01 05:39:28 | 000,012,536 | ---- | C] () -- C:\Windows\System32\drivers\ASUSHWIO.SYS
[2006.11.02 14:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:47:37 | 000,393,856 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006.11.02 12:33:01 | 000,595,798 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,103,872 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2005.10.14 11:56:50 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2005.10.14 11:56:50 | 000,921,600 | ---- | C] () -- C:\Windows\System32\VorbisEnc.dll
[2005.10.14 11:56:50 | 000,344,064 | ---- | C] () -- C:\Windows\System32\xvid.dll
[2005.10.14 11:56:50 | 000,237,568 | ---- | C] () -- C:\Windows\System32\OggDS.dll
[2005.10.14 11:56:50 | 000,188,416 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2005.10.14 11:56:50 | 000,155,136 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2005.10.14 11:56:50 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ogg.dll
[2001.01.12 11:49:38 | 000,021,504 | ---- | C] () -- C:\Windows\System32\zlib.dll
========== LOP Check ========== [2009.08.29 13:03:50 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Acronis
[2011.07.06 22:16:37 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\AIMP
[2009.08.30 14:20:50 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Ashampoo
[2010.12.16 18:40:57 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Audacity
[2010.09.01 08:41:07 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\CoSoSys
[2011.06.08 09:32:00 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\COWON
[2011.01.30 17:51:11 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\DonationCoder
[2010.10.12 14:11:12 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Downloaded Installations
[2010.09.24 15:20:17 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\ESET
[2011.05.25 19:26:36 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\FileZilla
[2011.07.06 22:16:37 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\GHISLER
[2011.02.15 10:26:15 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\ICQ
[2010.12.22 18:57:01 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\IrfanView
[2010.12.25 23:14:48 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Leadertech
[2011.05.18 23:45:48 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Live Downloader
[2010.10.12 14:58:02 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Nitro PDF
[2010.03.10 09:59:22 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Opera
[2009.08.30 11:06:22 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\PeerNetworking
[2009.08.28 23:42:05 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\QIP
[2011.06.08 09:35:44 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\RaimaRadio
[2010.12.03 15:21:03 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Samsung
[2011.05.18 15:34:39 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\SpinTop
[2011.05.24 22:37:49 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\uTorrent
[2009.11.08 16:52:08 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Vso
[2010.08.08 21:55:58 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Western Digital
[2010.12.16 22:04:47 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\XMedia Recode
[2011.03.26 03:42:08 | 000,000,000 | ---D | M] -- C:\Users\Jarda\AppData\Roaming\Zoner
[2011.07.07 09:42:46 | 000,032,596 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:2F4A0A6B
< End of report >