Virus log information:
Object "NULLBYTE Spyware/Adware" found in File System! Action Taken: Entries Removed.
Object "Spyware.NetScreenWatch Spyware/Adware" found in File System! Action Taken: File Deleted.
Object "Cydoor.TOPicks.a Spyware/Adware" found in File System! Action Taken: File Deleted.
Object "Backdoor (IRCBot) Trojans Spyware/Adware" found in File System! Action Taken: Entries Removed.
Object "RegSort Corrupted Adware/Spyware" found in File System! Action Taken: Entries Removed.
Object "AntiSpyware Pro XP Corrupted Adware/Spyware" found in File System! Action Taken: Entries Removed.
Object "Winvestigator Commercial KeyLogger" found in File System! Action Taken: Entries Removed.
Object "Conficker.C Worm" found in File System! Action Taken: Entries Removed.
Entry "HKCR\Access.AccDictionary.1" refers to invalid object "{6460C4D3-7B41-20C0-988C-4652A0E6F836}". Action Taken: Entries Removed.
Entry "HKCR\AcroIEHelperShim.AcroIEHelperShimObj" refers to invalid object "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}". Action Taken: Entries Removed.
Entry "HKCR\JavaPlugin.FamilyVersionSupport" refers to invalid object "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}". Action Taken: Entries Removed.
Entry "HKCR\RPShellExtension.QTExtractImage" refers to invalid object "{9BAF2374-771E-437b-A752-2B584A5B9200}". Action Taken: Entries Removed.
Entry "HKCR\RPShellExtension.RPExtractImage" refers to invalid object "{F2DE7395-2AE7-4b40-A159-F7EF3C266D9C}". Action Taken: Entries Removed.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\Program Files\Creative\Shared Files\Software Update\CTPID.ocx". Action Taken: Entries Removed.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.2\CTPID.ocx". Action Taken: Entries Removed.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.2\CTSUEngn.ocx". Action Taken: Entries Removed.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.8\CTSUEngn.ocx". Action Taken: Entries Removed.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\gp.ocx". Action Taken: Entries Removed.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\MVSGif.ocx". Action Taken: Entries Removed.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\sysreqlab3.dll". Action Taken: Entries Removed.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\system32\qdiagh.ocx". Action Taken: Entries Removed.
Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications" refers to invalid object "". Action Taken: Entries Removed.
File C:\WINDOWS\NIRCMD.exe infected by "Malware.Win32 (ES)" Virus! Action Taken: File Renamed.
File C:\Documents and Settings\Alan\Dokumenty\DVDFab\Temp\Update\Update.exe tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMCoreA.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMCoreB.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMCoreC.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMCoreD.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMCoreE.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMDataServicesA.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMDataServicesB.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMDataServicesC.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMDataServicesD.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMDataServicesE.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreA.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreB.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreC.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreD.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreE.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreF.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreG.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreH.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreI.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMIndexStoreJ.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMSearchA.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMSearchB.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMSearchC.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMSearchD.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\Common Files\Nero\Lib\NMSearchE.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\Program Files\TC UP\PLUGINS\Media\FreeDownloadManager\Firefox\extension\components\component.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063094.exe infected by "Malware.Win32 (ES)" Virus! Action Taken: File Renamed.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063099.pif infected by "Malware.Win32 (ES)" Virus! Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063101.exe infected by "Malware.Win32 (ES)" Virus! Action Taken: File Renamed.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063142.exe infected by "Malware.Win32 (ES)" Virus! Action Taken: File Renamed.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063261.exe infected by "Malware.Win32 (ES)" Virus! Action Taken: File Renamed.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063266.pif infected by "Malware.Win32 (ES)" Virus! Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063268.exe infected by "Malware.Win32 (ES)" Virus! Action Taken: File Renamed.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063312.exe infected by "Malware.Win32 (ES)" Virus! Action Taken: File Renamed.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063314.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063315.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063316.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063317.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063318.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063319.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063320.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063321.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063322.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063323.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063324.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063325.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063326.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063327.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063328.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063329.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063330.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063331.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063332.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063333.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063334.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063335.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063336.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063337.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063338.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
File C:\System Volume Information\_restore{2923B724-EB27-4DF0-89A0-AD9E2D867E48}\RP171\A0063339.dll tagged as "NULL.Corrupted". Action Taken: File Deleted.
A tady je MWAV Log:
24 V 2010 13:51:26 - **********************************************************
24 V 2010 13:51:26 - eScan Anti Virus & Spyware Toolkit Utility.
24 V 2010 13:51:26 - Copyright © MicroWorld Technologies
24 V 2010 13:51:26 - **********************************************************
24 V 2010 13:51:26 - Source: C:\DOCUME~1\Alan\Plocha\mwav.exe
24 V 2010 13:51:26 - Version 12.0.19 (C:\DOCUMENTS AND SETTINGS\ALAN\LOCAL SETTINGS\TEMP\MEXETMP.EX~)
24 V 2010 13:51:26 - Log File: C:\Documents and Settings\Alan\Local Settings\temp\MWAV.LOG
24 V 2010 13:51:26 - MWAV Registered: TRUE
24 V 2010 13:51:26 - User Account: Alan (Administrator Mode)
24 V 2010 13:51:26 - OS Type: Windows Workstation
24 V 2010 13:51:26 - OS: Windows XP [OS Install Date: 05 Sep 2008 22:46:15]
24 V 2010 13:51:26 - Ver: Service Pack 3 (Build 2600)
24 V 2010 13:51:26 - System Up Time: 36 Minutes, 5 Seconds
24 V 2010 13:51:26 - Windows Root Folder: C:\WINDOWS
24 V 2010 13:51:26 - Windows Sys32 Folder: C:\WINDOWS\system32
24 V 2010 13:51:26 - DHCP NameServer: 10.0.0.138
24 V 2010 13:51:26 - Interface0 DHCPNameServer: 10.0.0.138
24 V 2010 13:51:26 - Local Fixed Drives: c:\,d:\,e:\,f:\,g:\,j:\
24 V 2010 13:51:26 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
24 V 2010 13:51:26 - [CREATED ZIP FILE: C:\Documents and Settings\Alan\Local Settings\temp\pinfect.zip]
24 V 2010 13:51:26 - ****** Files/Folders created/modified during last fortnight in Windows and ROOT Folder ******
24 V 2010 13:51:27 - C:\WINDOWS\MBR.exe (77312), 23-May-2010 [Added C:\WINDOWS\MBR.exe to ZIP FILE]
24 V 2010 13:51:27 - C:\WINDOWS\NIRCMD.exe (31232), 23-May-2010, NirSoft, NirCmd
24 V 2010 13:51:27 - C:\WINDOWS\R.COM (147968), 24-May-2010, Microsoft Corporation, Microsoft® Windows® Operating System
24 V 2010 13:51:27 - C:\WINDOWS\SWREG.exe (161792), 23-May-2010, SteelWerX, SteelWerX Registry Editor
24 V 2010 13:51:27 - C:\WINDOWS\SWSC.exe (136704), 23-May-2010, SteelWerX, SteelWerX Service Controller
24 V 2010 13:51:27 - C:\WINDOWS\SWXCACLS.exe (212480), 23-May-2010, SteelWerX, SteelWerX Extended Configurator ACLists
24 V 2010 13:51:28 - C:\WINDOWS\system32\ac3filter.acm (421888), 20-May-2010 [Added C:\WINDOWS\system32\ac3filter.acm to ZIP FILE]
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DCompiler_36.dll (1374232), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DCompiler_37.dll (1420824), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DCompiler_38.dll (1491992), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DCompiler_39.dll (1493528), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DCompiler_40.dll (2036576), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DCompiler_41.dll (1846632), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DCompiler_42.dll (1974616), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\d3dcsx_42.dll (5501792), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\d3dx10_36.dll (444776), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\d3dx10_37.dll (462864), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\d3dx10_38.dll (467984), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\d3dx10_39.dll (467984), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\d3dx10_40.dll (452440), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\d3dx10_41.dll (453456), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\d3dx10_42.dll (453456), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\d3dx11_42.dll (235344), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\d3dx9_36.dll (3734536), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DX9_37.dll (3786760), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DX9_38.dll (3850760), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DX9_39.dll (3851784), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DX9_40.dll (4379984), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DX9_41.dll (4178264), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\D3DX9_42.dll (1892184), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\deployJava1.dll (411368), 20-May-2010, Sun Microsystems, Inc., Java(TM) Platform SE 6 U20
24 V 2010 13:51:28 - C:\WINDOWS\system32\eEmpty.exe (34048), 24-May-2010, MicroWorld Technologies Inc., eScan For Windows
24 V 2010 13:51:28 - C:\WINDOWS\system32\javacpl.cpl (73728), 20-May-2010, Sun Microsystems, Inc., Java(TM) Platform SE 6 U20
24 V 2010 13:51:28 - C:\WINDOWS\system32\OpenAL32.dll (109144), 18-May-2010, Portions (C) Creative Labs Inc. and NVIDIA Corp., Standard OpenAL(TM) Library
24 V 2010 13:51:28 - C:\WINDOWS\system32\T.COM (137216), 24-May-2010, Microsoft Corporation, Microsoft(R) Windows (R) 2000 Operating System
24 V 2010 13:51:28 - C:\WINDOWS\system32\TASKMGR.COM (137216), 24-May-2010, Microsoft Corporation, Microsoft(R) Windows (R) 2000 Operating System
24 V 2010 13:51:28 - C:\WINDOWS\system32\wrap_oal.dll (445016), 18-May-2010, Creative Labs, Creative Labs OpenAL32
24 V 2010 13:51:28 - C:\WINDOWS\system32\X3DAudio1_3.dll (25608), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\X3DAudio1_4.dll (25608), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\X3DAudio1_5.dll (23376), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\X3DAudio1_6.dll (22360), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\X3DAudio1_7.dll (22360), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\xactengine2_10.dll (267272), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\xactengine3_0.dll (238088), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\xactengine3_1.dll (238088), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\xactengine3_2.dll (238088), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\xactengine3_3.dll (235856), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\xactengine3_4.dll (235352), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\xactengine3_5.dll (238936), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\xactengine3_6.dll (238936), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\XAPOFX1_0.dll (65032), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\XAPOFX1_1.dll (68616), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:28 - C:\WINDOWS\system32\XAPOFX1_2.dll (70992), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:29 - C:\WINDOWS\system32\XAPOFX1_3.dll (69464), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:29 - C:\WINDOWS\system32\XAPOFX1_4.dll (74072), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:29 - C:\WINDOWS\system32\XAudio2_0.dll (479752), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:29 - C:\WINDOWS\system32\XAudio2_1.dll (507400), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:29 - C:\WINDOWS\system32\XAudio2_2.dll (509448), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:29 - C:\WINDOWS\system32\XAudio2_3.dll (514384), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:29 - C:\WINDOWS\system32\XAudio2_4.dll (517448), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:29 - C:\WINDOWS\system32\XAudio2_5.dll (515416), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:29 - C:\WINDOWS\system32\XAudio2_6.dll (528216), 17-May-2010, Microsoft Corporation, Microsoft® DirectX for Windows®
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\BACKUP.11671991.mexe.com (2353736), 24-May-2010, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility (MWAV)
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\bdc.exe (91904), 24-May-2010, MicroWorld Tech, eScan
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\bdfltlib2k.dll (231944), 24-May-2010, MicroWorld Technologies Inc., eScan for Windows
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\clean.bat (11), 24-May-2010 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\clean.bat to ZIP FILE]
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\DEVCON.EXE (61184), 24-May-2010, Microsoft Corporation, Microsoft® Windows® Operating System
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\download.exe (934920), 24-May-2010, MicroWorld Technologies Inc., eScan
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\eEmpty.exe (34048), 24-May-2010, MicroWorld Technologies Inc., eScan For Windows
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\encdec.dll (120328), 24-May-2010, MicroWorld Technologies Inc., eScan/MailScan/eConceal
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\erootdrv.sys (13832), 24-May-2010, MicroWorld Technologies Inc., eScan/MWAV
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\mexe.com (2386504), 24-May-2010, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility (MWAV)
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\msvclnt.dll (236040), 24-May-2010, MicroWorld Technologies Inc., MailScan
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\MWAVSCAN.COM (2353736), 24-May-2010, MicroWorld Technologies Inc., MicroWorld AntiVirus Toolkit Utility (MWAV)
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\plugins.htm (3498), 24-May-2010 [Added C:\DOCUME~1\Alan\LOCALS~1\Temp\plugins.htm to ZIP FILE]
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\red32.dll (10248), 24-May-2010, Microsoft Corporation, Microsoft® Windows® Operating System
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\reload.exe (154632), 24-May-2010, MicroWorld Technologies Inc., eScan for Windows
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\setpriv.exe (64008), 24-May-2010, MicroWorld Technologies Inc, eScan AntiVirus Toolkit Utility
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\unregx.exe (61960), 24-May-2010, MicroWorld Technologies Inc, MicroWorld AntiVirus Toolkit Utility
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\UPDLL10.DLL (747528), 12-May-2010, MicroWorld Technologies Inc., eScan/MailScan/MWAV
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\viewtcp.exe (573960), 24-May-2010, MicroWorld Technologies Inc., ViewTCP
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\0CA96315C2.sys (8), 03-Feb-2010 [HSR] [Added C:\Documents and Settings\All Users\Data aplikací\0CA96315C2.sys to ZIP FILE]
24 V 2010 13:51:29 - C:\WINDOWS\$hf_mig$, 20-Apr-2006 [H] [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\CSC, 18-Mar-2007 [HS] [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\ERDNT, 23-May-2010 [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\Fonts, 20-Apr-2006 [SR] [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\ftpcache, 01-Nov-2008 [HS] [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\ie7, 05-Jan-2008 [H] [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\ie8, 22-May-2009 [H] [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\inf, 20-Apr-2006 [H] [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\logo_1.exe, 24-May-2010 [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\Logs, 17-May-2010 [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\PIF, 18-Dec-2006 [H] [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\RUNDL132.EXE, 24-May-2010 [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\ShellNew, 28-May-2006 [H] [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\VDLL.DLL, 24-May-2010 [Folder]
24 V 2010 13:51:29 - C:\WINDOWS\system32\runouce.exe, 24-May-2010 [Folder]
24 V 2010 13:51:29 - C:\cmdcons, 20-Nov-2008 [HSR] [Folder]
24 V 2010 13:51:29 - C:\ComboFix, 23-May-2010 [Folder]
24 V 2010 13:51:29 - C:\MoTemp, 17-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Qoobox, 23-May-2010 [Folder]
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\AVCBack, 24-May-2010 [Folder]
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\FtpTemp, 24-May-2010 [Folder]
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\FtpTempF, 24-May-2010 [Folder]
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\Log, 24-May-2010 [Folder]
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\plugins, 24-May-2010 [Folder]
24 V 2010 13:51:29 - C:\DOCUME~1\Alan\LOCALS~1\Temp\tmp0000584c, 24-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\GetRightToGo, 19-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\GTek, 17-Dec-2008 [H] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\Microsoft, 19-Apr-2006 [S] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\Data aplikací, 19-Apr-2006 [H] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\Dokumenty, 19-Apr-2006 [S] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\IECompatCache, 22-May-2009 [HS] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\IETldCache, 22-May-2009 [HS] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\Local Settings, 19-Apr-2006 [H] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\Okolní síť, 19-Apr-2006 [H] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\Okolní tiskárny, 19-Apr-2006 [H] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\PrivacIE, 22-May-2009 [HS] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\Recent, 24-May-2010 [HS] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\SendTo, 19-Apr-2006 [HR] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\UserData, 19-Apr-2006 [HS] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\Alan\Data aplikací\..\Šablony, 19-Apr-2006 [H] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\Apple, 19-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\ArcSoft, 05-Jan-2009 [H] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\GTek, 17-Dec-2008 [H] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\IObit, 17-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\Microsoft, 20-Apr-2006 [S] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\MicroWorld, 24-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\PC Drivers HeadQuarters, 19-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\PC Drivers HeadQuarters Inc, 19-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\{5E80195C-322F-4958-B480-817CAC450BC4}, 04-Oct-2009 [H] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\..\Data aplikací, 20-Apr-2006 [H] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\..\DRM, 19-Apr-2006 [HS] [Folder]
24 V 2010 13:51:29 - C:\Documents and Settings\All Users\Data aplikací\..\Šablony, 20-Apr-2006 [H] [Folder]
24 V 2010 13:51:29 - C:\Program Files\Alcohol Soft, 13-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Program Files\AnalogX, 18-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Program Files\CanonBJ, 12-Jun-2007 [H] [Folder]
24 V 2010 13:51:29 - C:\Program Files\Creative Installation Information, 09-Dec-2009 [H] [Folder]
24 V 2010 13:51:29 - C:\Program Files\jv16 PowerTools 2009, 18-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Program Files\PC Drivers HeadQuarters, 19-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Program Files\QuickTime, 19-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Program Files\Sony Setup, 20-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Program Files\XP Codec Pack, 20-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Program Files\Common Files\Apple, 19-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Program Files\Common Files\Creative Labs Shared, 18-May-2010 [Folder]
24 V 2010 13:51:29 - C:\Program Files\Common Files\MicroWorld, 24-May-2010 [Folder]
24 V 2010 13:51:29 - *********************************************************************************************
24 V 2010 13:51:29 - Command Line Options Given: /xsign
24 V 2010 13:51:41 - Latest Date of files inside MWAV: Mon May 24 13:09:49 2010.
24 V 2010 13:51:41 - Plugins FileCount: 681 Sign Version: 7.31809
24 V 2010 13:51:42 - Loading/Creating FileScan Database C:\Documents and Settings\All Users\Data aplikací\MicroWorld\MWAV\ESCANDBX.MDB [Log: C:\Documents and Settings\Alan\Local Settings\temp\ESCANDB.LOG]
24 V 2010 13:51:42 - Loaded/Created FileScan Database...
24 V 2010 13:51:42 - Loading AV Library [DB]...
24 V 2010 13:51:44 - AV Library Loaded [DB-DIRECT].
24 V 2010 13:51:44 - MWAV doing self scanning...
24 V 2010 13:51:45 - MWAV files are clean.
24 V 2010 13:51:53 - Virus Database Date: 24 May 2010
24 V 2010 13:51:53 - Virus Database Count: 6064267
24 V 2010 13:52:17 - **********************************************************
24 V 2010 13:52:17 - eScan Anti Virus & Spyware Toolkit Utility.
24 V 2010 13:52:17 - Copyright © MicroWorld Technologies
24 V 2010 13:52:17 -
24 V 2010 13:52:17 - Support: support@escanav.com
24 V 2010 13:52:17 - Web: http://www.escanav.com
24 V 2010 13:52:17 - **********************************************************
24 V 2010 13:52:17 - Version 12.0.19[DB] (C:\DOCUMENTS AND SETTINGS\ALAN\LOCAL SETTINGS\TEMP\MEXETMP.EX~)
24 V 2010 13:52:17 - Log File: C:\Documents and Settings\Alan\Local Settings\temp\MWAV.LOG
24 V 2010 13:52:17 - User Account: Alan (Administrator Mode)
24 V 2010 13:52:17 - Windows Root Folder: C:\WINDOWS
24 V 2010 13:52:17 - Windows Sys32 Folder: C:\WINDOWS\system32
24 V 2010 13:52:17 - OS: Windows XP [OS Install Date: 05 Sep 2008 22:46:15]
24 V 2010 13:52:17 - Ver: Service Pack 3 (Build 2600)
24 V 2010 13:52:17 - Latest Date of files inside MWAV: Mon May 24 13:09:49 2010.
24 V 2010 13:52:17 - Plugins FileCount: 681 Sign Version: 7.31809
24 V 2010 13:52:17 - Options Selected by User:
24 V 2010 13:52:17 - Memory Check: Enabled
24 V 2010 13:52:17 - Registry Check: Enabled
24 V 2010 13:52:17 - StartUp Folder Check: Enabled
24 V 2010 13:52:17 - System Folder Check: Enabled
24 V 2010 13:52:17 - Services Check: Enabled
24 V 2010 13:52:17 - Scan Spyware: Enabled
24 V 2010 13:52:17 - Drive Check: Enabled
24 V 2010 13:52:17 - All Drive Check

24 V 2010 13:52:17 - Drive Selected = C:\
24 V 2010 13:52:17 - Folder Check: Disabled
24 V 2010 13:52:17 - SCAN: All_Files
24 V 2010 13:52:17 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
24 V 2010 13:52:17 - ***** Scanning Memory Files *****
24 V 2010 13:52:47 - ***** Scanning Registry Files *****
24 V 2010 13:52:59 - ERROR(3)!!! Invalid Entry vidc.LEAD = LCODCCMP.DLL (in key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32). Action Taken: Removing it.
24 V 2010 13:52:59 - ERROR(3)!!! Invalid Entry vidc.CDV5 = cdv5codc.dll (in key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32). Action Taken: Removing it.
24 V 2010 13:52:59 - ERROR(3)!!! Invalid Entry vidc.CLLC = cllccodc.dll (in key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32). Action Taken: Removing it.
24 V 2010 13:52:59 - ERROR(3)!!! Invalid Entry vidc.CUVC = cuvccodc.dll (in key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32). Action Taken: Removing it.
24 V 2010 13:52:59 - ERROR(3)!!! Invalid Entry vidc.CDVH = cdvhcodc.dll (in key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32). Action Taken: Removing it.
24 V 2010 13:52:59 - ERROR(3)!!! Invalid Entry vidc.CMIC = cmiccodc.dll (in key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32). Action Taken: Removing it.
24 V 2010 13:53:00 - ***** Scanning StartUp Folders *****
24 V 2010 13:53:11 - ***** Scanning Service Files *****
24 V 2010 13:53:11 - ERROR(2)!!! Invalid Entry system32\drivers\ALCXSENS.SYS. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\ALCXSENS.
24 V 2010 13:53:13 - ERROR(2)!!! Invalid Entry \??\C:\WINDOWS\system32\drivers\ASUSHWIO.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\ASUSHWIO.
24 V 2010 13:53:14 - ERROR(2)!!! Invalid Entry \??\C:\DOCUME~1\Alan\LOCALS~1\Temp\catchme.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\catchme.
24 V 2010 13:53:14 - ERROR(2)!!! Invalid Entry \??\C:\DOCUME~1\Alan\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\cpuz132.
24 V 2010 13:53:15 - ERROR(2)!!! Invalid Entry system32\drivers\cx88vid.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\CX23880.
24 V 2010 13:53:15 - ERROR(2)!!! Invalid Entry system32\drivers\cxavxbar.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\CXAVXBAR.
24 V 2010 13:53:15 - ERROR(2)!!! Invalid Entry system32\drivers\CX88TUNE.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\CXTUNE.
24 V 2010 13:53:17 - ERROR(2)!!! Invalid Entry \??\H:\INSTALL\GMSIPCI.SYS. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\GMSIPCI.
24 V 2010 13:53:20 - ERROR(2)!!! Invalid Entry system32\DRIVERS\nvcap.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\nvcap.
24 V 2010 13:53:23 - C:\WINDOWS\system32\Drivers\sptd.sys not Scanned. Possibly password protected...
24 V 2010 13:53:25 - ERROR(2)!!! Invalid Entry system32\DRIVERS\SymIM.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\SymIM.
24 V 2010 13:53:25 - ERROR(2)!!! Invalid Entry system32\DRIVERS\SymIM.sys. Action Taken: Removing HKLM\SYSTEM\CurrentControlSet\Services\SymIMMP.
24 V 2010 13:53:27 - ***** Scanning Registry and File system for Adware/Spyware *****
24 V 2010 13:53:29 - Loading Spyware Signatures from new External Database [Name: C:\DOCUME~1\Alan\LOCALS~1\temp\spydb.avs, Size: 942705]...
24 V 2010 13:53:29 - Indexed Spyware Databases Successfully Created...
24 V 2010 13:55:48 - Key found with NULL Character: HKLM\Software\Microsoft\Windows\CurrentVersion\System !!!
24 V 2010 13:55:48 - Deleting Registry Key: HKLM\Software\Microsoft\Windows\CurrentVersion\System
24 V 2010 13:55:48 - Object "NULLBYTE Spyware/Adware" found in File System! Action Taken: Entries Removed.
24 V 2010 13:55:50 - Offending file found: C:\WINDOWS\iun6002.exe
24 V 2010 13:55:50 - System found infected with Spyware.NetScreenWatch Spyware/Adware (iun6002.exe)! Action taken: File Deleted.
24 V 2010 13:55:50 - Object "Spyware.NetScreenWatch Spyware/Adware" found in File System! Action Taken: File Deleted.
24 V 2010 13:56:12 - Offending file found: C:\Documents and Settings\Alan\Dokumenty\My FlashThemes\DEFAULT.SWF
24 V 2010 13:56:12 - System found infected with Cydoor.TOPicks.a Spyware/Adware (DEFAULT.SWF)! Action taken: File Deleted.
24 V 2010 13:56:12 - Object "Cydoor.TOPicks.a Spyware/Adware" found in File System! Action Taken: File Deleted.
24 V 2010 13:56:41 - Offending Registry Entry found: HKCU\Software\Microsoft\OLE
24 V 2010 13:56:41 - System found infected with Backdoor (IRCBot) Trojans Spyware/Adware (HKCU\Software\Microsoft\OLE)! Action taken: Entries Removed.
24 V 2010 13:56:41 - Object "Backdoor (IRCBot) Trojans Spyware/Adware" found in File System! Action Taken: Entries Removed.
24 V 2010 13:56:41 - Offending Registry Entry found: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AlwaysUnloadDLL
24 V 2010 13:56:41 - System found infected with RegSort Corrupted Adware/Spyware (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AlwaysUnloadDLL)! Action taken: Entries Removed.
24 V 2010 13:56:41 - Object "RegSort Corrupted Adware/Spyware" found in File System! Action Taken: Entries Removed.
24 V 2010 13:56:42 - Offending file found: C:\WINDOWS\Downloaded Program Files\setup.inf
24 V 2010 13:56:42 - System found infected with combo Spyware/Adware (C:\WINDOWS\Downloaded Program Files\setup.inf)! Action taken: File Deleted.
24 V 2010 13:56:43 - Offending Registry Entry found: HKCU\Software\Microsoft\Windows\CurrentVersion\Drivers
24 V 2010 13:56:43 - System found infected with AntiSpyware Pro XP Corrupted Adware/Spyware (HKCU\Software\Microsoft\Windows\CurrentVersion\Drivers)! Action taken: Entries Removed.
24 V 2010 13:56:43 - Object "AntiSpyware Pro XP Corrupted Adware/Spyware" found in File System! Action Taken: Entries Removed.
24 V 2010 13:56:43 - Offending Registry Entry found: HKCR\wvfile
24 V 2010 13:56:43 - System found infected with Winvestigator Commercial KeyLogger (HKCR\wvfile)! Action taken: Entries Removed.
24 V 2010 13:56:43 - Object "Winvestigator Commercial KeyLogger" found in File System! Action Taken: Entries Removed.
24 V 2010 13:56:43 - Offending Registry Entry found: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters/TcpNumConnections
24 V 2010 13:56:43 - System found infected with Conficker.C Worm (HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters/TcpNumConnections)! Action taken: Entries Removed.
24 V 2010 13:56:43 - Object "Conficker.C Worm" found in File System! Action Taken: Entries Removed.
24 V 2010 13:56:43 - Scanning MountPoints2 RegKey...
24 V 2010 13:56:43 - Scanning CLSID RegKey...
24 V 2010 13:56:43 - Entry "HKCR\Access.AccDictionary.1" refers to invalid object "{6460C4D3-7B41-20C0-988C-4652A0E6F836}". Action Taken: Entries Removed.
24 V 2010 13:56:43 - Entry "HKCR\AcroIEHelperShim.AcroIEHelperShimObj" refers to invalid object "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}". Action Taken: Entries Removed.
24 V 2010 13:56:43 - Entry "HKCR\JavaPlugin.FamilyVersionSupport" refers to invalid object "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}". Action Taken: Entries Removed.
24 V 2010 13:56:44 - Entry "HKCR\RPShellExtension.QTExtractImage" refers to invalid object "{9BAF2374-771E-437b-A752-2B584A5B9200}". Action Taken: Entries Removed.
24 V 2010 13:56:44 - Entry "HKCR\RPShellExtension.RPExtractImage" refers to invalid object "{F2DE7395-2AE7-4b40-A159-F7EF3C266D9C}". Action Taken: Entries Removed.
24 V 2010 13:56:44 - Scanning ModuleUsage RegKey...
24 V 2010 13:56:44 - Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\Program Files\Creative\Shared Files\Software Update\CTPID.ocx". Action Taken: Entries Removed.
24 V 2010 13:56:44 - Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.2\CTPID.ocx". Action Taken: Entries Removed.
24 V 2010 13:56:44 - Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.2\CTSUEngn.ocx". Action Taken: Entries Removed.
24 V 2010 13:56:44 - Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.8\CTSUEngn.ocx". Action Taken: Entries Removed.
24 V 2010 13:56:45 - Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\gp.ocx". Action Taken: Entries Removed.
24 V 2010 13:56:45 - Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\MVSGif.ocx". Action Taken: Entries Removed.
24 V 2010 13:56:45 - Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\sysreqlab3.dll". Action Taken: Entries Removed.
24 V 2010 13:56:45 - Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\system32\qdiagh.ocx". Action Taken: Entries Removed.
24 V 2010 13:56:45 - Scanning ExternalApp RegKey...
24 V 2010 13:56:45 - Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications" refers to invalid object "". Action Taken: Entries Removed.
24 V 2010 13:56:45 - Scanning SharedDLL RegKey...
24 V 2010 13:56:56 - Scanning Installer RegKey...
24 V 2010 13:57:05 - Scanning FileExtension RegKey...
24 V 2010 13:57:06 - Scanning ARPCache RegKey...
24 V 2010 13:57:06 - ***** Scanning Registry Files *****
24 V 2010 13:57:07 - Clearing Temporary sub-folders as Spyware/Adware found in system...
24 V 2010 13:57:07 - ** Value in HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\main/Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
24 V 2010 13:57:07 - ** Value in HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main/Start Page = http://mystart.incredimail.com/
24 V 2010 13:57:07 - ** Value in HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\main/Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
24 V 2010 13:57:07 - ***** Scanning System32 Folders *****
24 V 2010 13:57:11 - Scanning File C:\WINDOWS\NIRCMD.exe (????)
24 V 2010 13:57:13 - File C:\WINDOWS\NIRCMD.exe infected by "Malware.Win32 (ES)" Virus! Action Taken: File Renamed.
24 V 2010 13:57:28 - ScanFile took 8.44 Secs [C:\WINDOWS\system32\AppSetup.exe]...
24 V 2010 14:00:36 - ***** Scanning Drive C:\ *****
24 V 2010 14:09:32 - Scanning File C:\Documents and Settings\Alan\Dokumenty\DVDFab\Temp\Update\Update.exe
24 V 2010 14:09:33 - File C:\Documents and Settings\Alan\Dokumenty\DVDFab\Temp\Update\Update.exe tagged as "NULL.Corrupted". Action Taken: File Deleted.
24 V 2010 14:16:02 - C:\Documents and Settings\Alan\Local Settings\Data aplikací\Microsoft\Windows\UsrClass.dat.LOG not Scanned. Possibly password protected...
24 V 2010 14:16:44 - C:\Documents and Settings\Alan\ntuser.dat.LOG not Scanned. Possibly password protected...
24 V 2010 14:16:56 - INVALID ATTRIBUTES FOR FOLDER [C:\Documents and Settings\Alan\Oblíbené položky\RapidShare\Hudba...]. IGNORING.
24 V 2010 14:17:02 - INVALID ATTRIBUTES FOR FOLDER [C:\Documents and Settings\Alan\Oblíbené položky\Zvuky..]. IGNORING.
24 V 2010 14:26:46 - INVALID ATTRIBUTES FOR FOLDER [C:\Documents and Settings\All Users\Data aplikac?ncrediMail]. IGNORING.
24 V 2010 14:31:20 - C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft\Windows\UsrClass.dat.LOG not Scanned. Possibly password protected...
24 V 2010 14:31:21 - C:\Documents and Settings\LocalService\ntuser.dat.LOG not Scanned. Possibly password protected...
24 V 2010 14:31:21 - C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft\Windows\UsrClass.dat.LOG not Scanned. Possibly password protected...
24 V 2010 14:31:22 - C:\Documents and Settings\NetworkService\ntuser.dat.LOG not Scanned. Possibly password protected...
24 V 2010 14:56:21 - ScanFile took 6.00 Secs [C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\AcroForm.api]...