OTL logfile created on: 12.12.2012 18:19:41 - Run 1
OTL by OldTimer - Version Folder = C:\Documents and Settings\Zdeněk Valíček\Plocha
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,99 Gb Total Physical Memory | 1,72 Gb Available Physical Memory | 57,42% Memory free
4,83 Gb Paging File | 3,66 Gb Available in Paging File | 75,75% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 169,27 Gb Total Space | 55,90 Gb Free Space | 33,03% Space Free | Partition Type: NTFS
Drive D: | 128,82 Gb Total Space | 3,65 Gb Free Space | 2,83% Space Free | Partition Type: NTFS

Computer Name: VALICEK | User Name: Zdeněk Valíček | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2012.12.12 18:15:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Zdeněk Valíček\Plocha\OTL.exe
PRC - [2012.11.28 04:43:18 | 001,242,728 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
PRC - [2012.10.30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.09.14 17:09:23 | 000,212,432 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Update\\GoogleCrashHandler.exe
PRC - [2012.01.04 21:24:50 | 000,793,048 | ---- | M] (PC Tools) -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
PRC - [2009.10.18 22:20:03 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009.09.14 15:35:51 | 000,212,992 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Temp\RtkBtMnt.exe
PRC - [2008.08.07 14:29:58 | 000,045,056 | ---- | M] (Acer Inc.) -- C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe
PRC - [2008.07.08 17:18:40 | 000,466,944 | ---- | M] () -- C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
PRC - [2008.06.09 23:36:14 | 000,870,920 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LManager.exe
PRC - [2008.05.07 16:41:14 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008.05.07 16:41:12 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008.04.14 05:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.07.24 10:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2007.04.11 10:10:00 | 000,394,856 | R--- | M] (WinZip Computing, S.L.) -- C:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2007.04.01 08:02:38 | 000,568,176 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2007.02.13 00:43:44 | 000,065,536 | ---- | M] (O2Micro International) -- C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
PRC - [2007.01.04 18:48:50 | 000,112,152 | ---- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
PRC - [2005.04.17 11:30:48 | 000,085,184 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\VPTray.exe
PRC - [2005.04.17 11:30:40 | 001,706,176 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe
PRC - [2005.04.17 11:30:32 | 000,019,648 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe
PRC - [2005.04.08 14:54:52 | 000,161,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC - [2005.04.08 14:52:32 | 000,185,968 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC - [2005.04.08 14:52:30 | 000,048,752 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2004.12.14 10:12:02 | 000,483,328 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe

========== Modules (No Company Name) ==========

MOD - [2012.12.12 13:12:44 | 002,038,784 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12121200\algo.dll
MOD - [2012.11.28 04:43:17 | 000,460,904 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\Application\23.0.1271.95\ppgooglenaclpluginchrome.dll
MOD - [2012.11.28 04:43:16 | 012,456,040 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\Application\23.0.1271.95\PepperFlash\pepflashplayer.dll
MOD - [2012.11.28 04:43:15 | 004,008,040 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\Application\23.0.1271.95\pdf.dll
MOD - [2012.11.28 04:42:30 | 000,587,880 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\Application\23.0.1271.95\libglesv2.dll
MOD - [2012.11.28 04:42:29 | 000,124,520 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\Application\23.0.1271.95\libegl.dll
MOD - [2012.11.28 04:42:22 | 000,157,304 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\Application\23.0.1271.95\avutil-51.dll
MOD - [2012.11.28 04:42:21 | 002,168,952 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\Application\23.0.1271.95\avcodec-54.dll
MOD - [2012.11.28 04:42:21 | 000,275,576 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\Application\23.0.1271.95\avformat-54.dll
MOD - [2012.11.16 19:13:48 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_53b7da2a\mscorlib.dll
MOD - [2012.11.16 19:13:45 | 000,843,776 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_f65a7fbf\system.drawing.dll
MOD - [2012.11.16 19:13:37 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_f6051a6e\system.xml.dll
MOD - [2012.11.16 19:13:32 | 003,035,136 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\\1.0.5000.0__b77a5c561934e089_fea4771a\
MOD - [2012.11.16 19:13:15 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_62da4d42\system.dll
MOD - [2012.11.16 19:13:01 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2012.11.16 19:12:59 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\\1.0.5000.0__b77a5c561934e089\
MOD - [2012.06.13 22:46:12 | 000,471,040 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2008.09.08 18:19:56 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2008.09.08 18:19:56 | 000,372,736 | ---- | M] () -- c:\windows\assembly\gac\\1.0.5000.0__b03f5f7f11d50a3a\
MOD - [2008.07.08 17:18:40 | 000,466,944 | ---- | M] () -- C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
MOD - [2008.04.14 05:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008.04.04 01:54:28 | 000,003,072 | ---- | M] () -- C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTrayLOC.dll
MOD - [2008.02.28 21:44:22 | 001,024,000 | ---- | M] () -- C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\ACE.dll
MOD - [2008.02.28 21:44:20 | 000,098,304 | ---- | M] () -- C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\ACEXML.dll
MOD - [2008.02.28 21:44:20 | 000,061,440 | ---- | M] () -- C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\ACEXML_Parser.dll
MOD - [2007.04.01 08:00:28 | 002,842,624 | ---- | M] () -- C:\WINDOWS\system32\btwicons.dll
MOD - [2007.04.01 07:57:16 | 000,053,248 | ---- | M] () -- C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll
MOD - [2005.10.20 16:20:24 | 000,208,896 | ---- | M] () -- C:\Program Files\Acer\Empowering Technology\ePower\DialogDLL.dll
MOD - [2005.10.11 12:18:54 | 000,028,672 | ---- | M] () -- C:\Program Files\Acer\Empowering Technology\ePower\SysHook.dll
MOD - [2003.06.07 21:30:08 | 000,057,344 | ---- | M] () -- C:\Program Files\Launch Manager\PowerUtl.dll

========== Services (SafeList) ==========

SRV - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.07.13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.01.04 21:24:50 | 000,793,048 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2008.10.15 22:49:33 | 000,074,360 | ---- | M] (Autodesk, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service)
SRV - [2008.05.07 16:41:14 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2007.07.24 10:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2007.02.13 00:43:44 | 000,065,536 | ---- | M] (O2Micro International) [Auto | Running] -- C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe -- (o2flash)
SRV - [2007.01.04 18:48:50 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2005.04.17 11:30:42 | 000,124,608 | ---- | M] (symantec) [On_Demand | Stopped] -- C:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam)
SRV - [2005.04.17 11:30:40 | 001,706,176 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2005.04.17 11:30:32 | 000,019,648 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch)
SRV - [2005.04.08 14:54:52 | 000,161,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr)
SRV - [2005.04.08 14:54:50 | 000,083,568 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc)
SRV - [2005.04.08 14:52:32 | 000,185,968 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr)
SRV - [2005.04.05 10:17:22 | 000,206,552 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc)
SRV - [2005.03.30 20:48:22 | 000,992,864 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc)

========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\933daef6.sys -- (933daef6)
DRV - [2012.10.30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012.10.30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012.10.30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012.10.30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012.10.30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012.10.30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012.10.30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.09.17 09:00:00 | 001,601,184 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20121210.007\NAVEX15.SYS -- (NAVEX15)
DRV - [2012.09.17 09:00:00 | 000,092,704 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20121210.007\NAVENG.SYS -- (NAVENG)
DRV - [2012.08.01 01:34:46 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Unknown] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11220.sys -- (EraserUtilDrv11220)
DRV - [2012.08.01 01:34:45 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2008.12.31 12:59:58 | 003,453,440 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2008.11.17 14:23:16 | 003,636,864 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw5x32.sys -- (NETw5x32)
DRV - [2008.10.31 12:52:16 | 000,093,184 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2008.10.09 14:42:42 | 000,017,408 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\KMWDFILTER.sys -- (KMWDFILTER)
DRV - [2008.06.12 17:30:12 | 000,043,608 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\o2sd.sys -- (O2SDRDR)
DRV - [2008.05.21 01:53:00 | 004,800,000 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2008.05.13 20:49:12 | 000,051,288 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\o2media.sys -- (O2MDRDR)
DRV - [2008.03.19 13:26:24 | 000,175,104 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2007.12.26 06:23:10 | 000,017,968 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TpChoice.sys -- (TpChoice)
DRV - [2007.10.01 13:59:46 | 001,769,984 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snp2uvc.sys -- (SNP2UVC)
DRV - [2007.04.17 19:09:28 | 000,011,032 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\regi.sys -- (regi)
DRV - [2007.03.31 21:02:42 | 000,876,384 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2007.03.31 21:02:40 | 000,055,352 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2007.03.23 18:50:42 | 000,067,960 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2007.03.23 18:50:24 | 000,149,123 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2007.03.23 18:50:08 | 000,037,424 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2007.03.23 18:49:54 | 000,539,072 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2007.03.01 21:22:04 | 000,988,032 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2007.03.01 21:21:24 | 000,210,688 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2007.03.01 21:21:22 | 000,731,136 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005.04.05 10:17:02 | 000,267,192 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\symtdi.sys -- (SYMTDI)
DRV - [2005.04.05 10:17:00 | 000,017,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\symredrv.sys -- (SYMREDRV)
DRV - [2005.04.01 19:36:04 | 000,123,200 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent)
DRV - [2005.03.30 20:48:20 | 000,372,832 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2005.02.04 19:14:32 | 000,053,896 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL)
DRV - [2005.02.04 19:14:30 | 000,324,232 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" ={ ... rer:source?}
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = ... lz=1I7ACAW

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = ... tensa_5630
IE - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]
IE - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" ={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\..\SearchScopes\{06A805AF-9EA7-48CE-962A-BC609030FDFD}: "URL" ={searchT ... lz=1I7ACAW
IE - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: ""
FF - "Search Results"
FF - "Search Results"
FF - "Search Results"
FF - prefs.js..keyword.URL: " ... PN10645&q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\ C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\ C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\ C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\;version= C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\;version= C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\;version= C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\;version=: File not found
FF - HKLM\Software\MozillaPlugins\,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\ Update;version=3: C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\ Update;version=9: C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Update\\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.12.08 21:48:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ C:\Program Files\AVAST Software\Avast\WebRep\FF [2012.12.11 22:52:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.06.19 17:11:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.06.26 13:15:39 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{1650a312-02bc-40ee-977e-83f158701739}: C:\Program Files\SiteAdvisor\6172\FF\
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\ C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010.12.08 21:48:50 | 000,000,000 | ---D | M]

[2012.12.09 22:12:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Mozilla\Firefox\Profiles\1rbz6ag0.default\extensions
[2010.06.20 22:04:24 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Mozilla\Firefox\Profiles\1rbz6ag0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.12.09 22:12:45 | 000,002,687 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Mozilla\Firefox\Profiles\1rbz6ag0.default\searchplugins\Search_Results.xml
[2012.12.09 22:12:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010.06.26 13:15:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011.08.17 18:44:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2010.06.19 17:11:17 | 000,000,000 | ---D | M] (Talkback) -- C:\Program Files\Mozilla Firefox\extensions\
[2010.06.26 13:15:29 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009.10.18 22:20:47 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD\FIREFOX\EXT
[2007.03.12 10:10:41 | 000,066,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jar50.dll
[2007.03.12 10:10:41 | 000,054,376 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jsd3250.dll
[2007.03.12 10:10:41 | 000,034,952 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\myspell.dll
[2007.03.12 10:10:41 | 000,046,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\spellchk.dll
[2007.03.12 10:10:41 | 000,172,144 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\xpinstal.dll
[2011.05.04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2006.06.04 21:11:07 | 000,001,118 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\centrum-cz.xml
[2006.06.04 21:11:07 | 000,000,661 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2006.06.04 21:11:07 | 000,001,674 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2006.08.25 16:16:33 | 000,001,302 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2006.06.04 21:11:07 | 000,000,765 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml

========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Zden\u011Bk Val\u00ED\u010Dek\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\23.0.1271.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Zden\u011Bk Val\u00ED\u010Dek\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\23.0.1271.95\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Zden\u011Bk Val\u00ED\u010Dek\Local Settings\Data aplikac\u00ED\Google\Chrome\Application\23.0.1271.95\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Zden\u011Bk Val\u00ED\u010Dek\Local Settings\Data aplikac\u00ED\Google\Chrome\User Data\PepperFlash\\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Zden\u011Bk Val\u00ED\u010Dek\Local Settings\Data aplikac\u00ED\Google\Update\\npGoogleUpdate3.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\
CHR - Extension: avast! WebRep = C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\
CHR - Extension: Gmail = C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012.12.11 23:16:14 | 000,000,900 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts:
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (WebTranslator) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\TRANSLAT\WEBIE.DLL ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Boot] C:\Program Files\Acer\Empowering Technology\ePower\Boot.exe ()
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe ()
O4 - HKLM..\Run: [eRecoveryService] C:\Program Files\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKU\.DEFAULT..\Run: [braviax] File not found
O4 - HKU\S-1-5-18..\Run: [braviax] File not found
O4 - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer Empowering Technology.lnk = C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe (Acer Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Acrobat Speed Launcher.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Akcelerátor spuštění AutoCADu.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O4 - Startup: C:\Documents and Settings\Zdeněk Valíček\Nabídka Start\Programy\Po spuštění\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-2823653281-3228338932-1293869941-1009\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - C:\Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést výběr do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést výběr do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\TRANSLAT\WEBIE.DLL ()
O9 - Extra Button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\TRANSLAT\WEBIE.DLL ()
O9 - Extra 'Tools' menuitem : Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\TRANSLAT\WEBIE.DLL ()
O9 - Extra 'Tools' menuitem : Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\TRANSLAT\WEBIE.DLL ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} ... 4025214812 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} ... (Java Plug-in 1.6.0_26)
O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} ... (IPSUploader4 Control)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} ... (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} ... (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} ... (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} ... (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C70C109-653A-4E25-9931-48F1E143B5B5}: DhcpNameServer =
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (cru629.dat) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - (C:\WINDOWS\system32\NavLogon.dll) - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\ACERTX.BMP
O24 - Desktop BackupWallPaper: C:\WINDOWS\ACERTX.BMP
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.07.10 01:36:16 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{4a421e83-ab86-11df-832d-00215d442170}\Shell - "" = AutoRun
O33 - MountPoints2\{4a421e83-ab86-11df-832d-00215d442170}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\ [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

Restore point Set: OTL Restore Point

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\ (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2012.12.12 18:15:28 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Zdeněk Valíček\Plocha\OTL.exe
[2012.12.12 18:05:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012.12.11 22:55:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zdeněk Valíček\Plocha\RK_Quarantine
[2012.12.11 22:52:37 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012.12.11 22:52:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\avast! Free Antivirus
[2012.12.11 22:52:36 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012.12.11 22:52:35 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012.12.11 22:52:35 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012.12.11 22:52:35 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012.12.11 22:52:35 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012.12.11 22:52:35 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012.12.11 22:52:35 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012.12.11 22:52:06 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012.12.11 22:52:05 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012.12.11 22:51:45 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012.12.11 22:51:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2012.12.11 22:09:13 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Zdeněk Valíček\Nabídka Start\Programy\Nástroje pro správu
[2012.12.11 22:00:20 | 000,688,992 | R--- | C] (Swearware) -- C:\Documents and Settings\Zdeněk Valíček\Plocha\dds.exe
[2012.12.11 21:44:22 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.12.11 21:44:21 | 000,000,000 | ---D | C] -- C:\rsit
[2012.12.11 18:13:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\searchresultstb
[2012.12.11 18:13:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zdeněk Valíček\AppData
[2012.12.09 22:13:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Torch
[2012.12.09 22:13:33 | 000,773,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr100.dll
[2012.12.09 22:12:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\ilividtoolbarguid
[2012.12.09 22:12:44 | 000,000,000 | ---D | C] -- C:\Program Files\Search Results Toolbar
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2012.12.12 18:24:59 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.12.12 18:15:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Zdeněk Valíček\Plocha\OTL.exe
[2012.12.12 18:14:01 | 000,001,062 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2823653281-3228338932-1293869941-1009UA.job
[2012.12.12 18:14:00 | 000,001,010 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2823653281-3228338932-1293869941-1009Core.job
[2012.12.12 17:54:07 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012.12.12 17:53:13 | 000,000,332 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012.12.12 17:51:43 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012.12.12 17:51:23 | 3215,835,136 | -HS- | M] () -- C:\hiberfil.sys
[2012.12.12 00:20:40 | 000,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
[2012.12.11 22:52:37 | 000,001,697 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2012.12.11 22:52:35 | 000,002,552 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012.12.11 22:42:29 | 000,756,224 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Plocha\RogueKiller.exe
[2012.12.11 22:00:30 | 000,688,992 | R--- | M] (Swearware) -- C:\Documents and Settings\Zdeněk Valíček\Plocha\dds.exe
[2012.12.11 21:35:49 | 000,545,819 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Plocha\adwcleaner (1).exe
[2012.12.11 19:19:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012.12.11 19:14:03 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\RMSchedule.job
[2012.12.11 18:28:02 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes Anti-Malware.lnk
[2012.12.05 20:38:47 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012.12.05 20:38:44 | 000,081,920 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012.12.12 18:24:59 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.12.11 22:52:37 | 000,001,697 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2012.12.11 22:52:35 | 000,000,332 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2012.12.11 22:42:28 | 000,756,224 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Plocha\RogueKiller.exe
[2012.12.11 21:35:49 | 000,545,819 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Plocha\adwcleaner (1).exe
[2012.12.11 18:28:02 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes Anti-Malware.lnk
[2012.02.15 17:06:37 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012.01.28 19:51:17 | 000,037,336 | ---- | C] () -- C:\WINDOWS\System32\CleanMFT32.exe
[2009.09.16 17:20:25 | 000,019,314 | ---- | C] () -- C:\Program Files\Common Files\yhub.reg
[2009.09.16 17:20:25 | 000,017,711 | ---- | C] () -- C:\Documents and Settings\LocalService\Data aplikací\xagud.ban
[2009.09.16 17:20:25 | 000,015,894 | ---- | C] () -- C:\Documents and Settings\LocalService\Data aplikací\yqucobytuk.dl
[2009.09.16 17:20:25 | 000,015,433 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\wove.lib
[2009.09.16 17:20:25 | 000,013,653 | ---- | C] () -- C:\Documents and Settings\LocalService\Data aplikací\yxon.ban
[2009.09.16 17:20:25 | 000,012,396 | ---- | C] () -- C:\Program Files\Common Files\muryd.lib
[2009.09.16 17:20:25 | 000,010,111 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\jyvybepa.inf
[2009.09.16 16:57:16 | 000,019,981 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\nojijufyv.ban
[2009.09.16 16:57:16 | 000,019,979 | ---- | C] () -- C:\Program Files\Common Files\riri.pif
[2009.09.16 16:57:16 | 000,019,504 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\ywata.bin
[2009.09.16 16:57:16 | 000,015,787 | ---- | C] () -- C:\Documents and Settings\LocalService\Data aplikací\lukoqaku.bat
[2009.09.16 16:57:16 | 000,015,372 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\foca.inf
[2009.09.16 16:57:16 | 000,014,625 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\yniwag.dll
[2009.09.16 16:57:16 | 000,014,237 | ---- | C] () -- C:\Program Files\Common Files\yhar.ban
[2009.09.16 16:57:16 | 000,012,862 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\pizuxu.pif
[2009.08.28 19:51:51 | 000,012,935 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\dugiwewam.pif
[2009.08.27 21:37:11 | 000,019,830 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\vehofok.bin
[2009.08.27 21:37:11 | 000,018,901 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\exozibysac._sy
[2009.08.27 21:37:11 | 000,018,372 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\zelugu.bat
[2009.08.27 21:37:11 | 000,017,708 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\ulysojotak.pif
[2009.08.27 21:37:11 | 000,015,015 | ---- | C] () -- C:\Documents and Settings\LocalService\Data aplikací\hesofydig.vbs
[2009.08.27 21:37:11 | 000,014,578 | ---- | C] () -- C:\Documents and Settings\LocalService\Data aplikací\ytyp.ban
[2009.08.27 21:37:11 | 000,013,688 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\ojyrici.reg
[2009.08.27 21:37:11 | 000,013,368 | ---- | C] () -- C:\Program Files\Common Files\cabi.bin
[2009.08.27 21:37:11 | 000,012,892 | ---- | C] () -- C:\Program Files\Common Files\vuhox.sys
[2009.08.27 21:37:11 | 000,011,375 | ---- | C] () -- C:\Program Files\Common Files\ximosa.reg
[2009.08.27 21:37:11 | 000,010,408 | ---- | C] () -- C:\Program Files\Common Files\keji._sy
[2009.08.27 20:56:49 | 000,019,957 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\otumiwa.pif
[2009.08.27 20:56:49 | 000,018,741 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\ozipywu.pif
[2009.08.27 20:56:49 | 000,018,546 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\livuwykyva.dat
[2009.08.27 20:56:49 | 000,016,868 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\rako.bin
[2009.08.27 20:56:49 | 000,015,716 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\pukic.reg
[2009.08.27 20:56:49 | 000,013,595 | ---- | C] () -- C:\Program Files\Common Files\carabarah.lib
[2009.08.27 20:56:49 | 000,011,782 | ---- | C] () -- C:\Program Files\Common Files\nonobugob.lib
[2009.08.27 20:56:48 | 000,019,757 | ---- | C] () -- C:\Program Files\Common Files\mefofa.reg
[2009.08.27 20:56:48 | 000,016,985 | ---- | C] () -- C:\Program Files\Common Files\yzibik.bat
[2009.08.27 20:56:48 | 000,016,756 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\onyrej.db
[2009.08.27 20:56:48 | 000,016,161 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\alevifavec.pif
[2009.08.27 20:56:48 | 000,015,380 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\qifuwunaz.lib
[2009.08.27 20:56:48 | 000,013,721 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\
[2009.08.27 20:56:48 | 000,012,721 | ---- | C] () -- C:\Program Files\Common Files\dihybivyd.scr
[2009.08.27 20:56:48 | 000,010,097 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\enibire.ban
[2009.08.27 20:52:29 | 000,000,104 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\154.bat
[2008.11.01 22:05:53 | 000,081,920 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.10.28 11:23:01 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Data aplikací\ezsid.dat
[2008.10.15 20:54:52 | 000,000,134 | ---- | C] () -- C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\fusioncache.dat
[2008.10.15 16:50:44 | 000,001,004 | -HS- | C] () -- C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys

========== ZeroAccess Check ==========

[2008.09.08 18:16:10 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini



"" = %SystemRoot%\system32\shdocvw.dll -- [2008.04.14 05:00:00 | 001,499,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009.02.09 11:56:05 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008.04.14 05:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2008.10.15 22:42:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Autodesk
[2012.12.11 22:51:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
[2011.03.14 16:45:36 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\Common Files
[2012.12.11 22:03:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2012.12.11 19:14:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2011.12.14 19:10:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\tmp
[2009.07.22 20:44:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\vsosdk
[2008.10.15 00:23:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\WinZip
[2008.10.15 08:06:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
[2008.10.15 22:42:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Autodesk
[2012.01.02 20:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer
[2009.06.16 16:39:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer Pro
[2009.05.16 21:59:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\FileZilla
[2010.04.12 20:14:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\ICQ
[2012.12.11 18:13:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\ilividtoolbarguid
[2008.10.15 23:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\InterVideo
[2012.08.06 18:44:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Product_RM
[2012.02.04 19:17:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Registry Mechanic
[2010.11.21 19:21:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\SAMSUNG Drivers Update Utility
[2012.12.11 18:13:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\searchresultstb
[2009.08.02 10:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Vso
[2008.10.15 20:56:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Windows Desktop Search
[2008.10.28 22:38:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Windows Search

========== Purity Check ==========

========== Custom Scans ==========

< >
[2008.04.14 05:00:00 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2008.09.08 19:10:50 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2008.10.15 00:10:50 | 000,000,284 | ---- | C] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2010.06.19 17:14:20 | 000,001,010 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2823653281-3228338932-1293869941-1009Core.job
[2010.06.19 17:14:21 | 000,001,062 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2823653281-3228338932-1293869941-1009UA.job
[2012.01.28 19:51:23 | 000,000,292 | ---- | C] () -- C:\WINDOWS\Tasks\RMSchedule.job
[2012.12.11 22:52:35 | 000,000,332 | -H-- | C] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job

< >

< MD5 for: ATAPI.SYS >
[2008.04.14 05:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\
[2008.04.14 05:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2008.04.14 05:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\I386\AUTOCHK.EXE
[2008.04.14 05:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\autochk.exe
[2008.04.14 05:00:00 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=C7A9FF12C63E2E448722B02C71A8C431 -- C:\WINDOWS\system32\dllcache\autochk.exe

< MD5 for: CDROM.SYS >
[2008.04.14 05:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\
[2008.04.14 05:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\
[2008.04.14 05:00:00 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys

[2008.04.14 05:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\explorer.exe
[2008.04.14 05:00:00 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: HAL.DLL >
[2008.04.14 05:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\I386\
[2008.04.14 05:00:00 | 020,102,206 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\
[2008.04.14 05:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE -- C:\WINDOWS\system32\hal.dll

< MD5 for: SCECLI.DLL >
[2008.04.14 05:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008.04.14 05:00:00 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll

[2009.02.09 12:18:56 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=3D107D45CCFDB266E91D84B52CD7F430 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\dllcache\services.exe
[2009.02.09 12:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) MD5=9EF697AF07BB8DD82C3B02CA953A95B7 -- C:\WINDOWS\system32\services.exe
[2008.04.14 05:00:00 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=F0D2AE69035092BF22DAD6B50FAB85C2 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe

< MD5 for: SVCHOST.EXE >
[2012.09.29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008.04.14 05:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008.04.14 05:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2008.04.14 05:00:00 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

[2008.04.14 05:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008.04.14 05:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\system32\userinit.exe

[2012.09.29 19:54:26 | 000,218,184 | ---- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008.04.14 05:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 05:00:00 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\system32\winlogon.exe

< >

< %systemroot%*.* /U /s >
[14 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[1 C:\WINDOWS\twain_32\*.tmp files -> C:\WINDOWS\twain_32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2012.01.28 17:51:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Adobe
[2008.10.15 23:06:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\AdobeUM
[2008.10.15 23:01:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Ahead
[2008.10.15 23:07:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Apple Computer
[2008.10.15 20:55:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\ATI
[2008.10.15 22:42:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Autodesk
[2012.01.02 20:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer
[2009.06.16 16:39:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer Pro
[2008.10.25 17:56:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Corel
[2009.05.16 21:59:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\FileZilla
[2008.10.15 22:56:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Help
[2010.12.19 13:18:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\HP
[2012.12.11 18:14:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\HPAppData
[2010.12.09 22:36:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\HpUpdate
[2010.04.12 20:14:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\ICQ
[2008.10.15 08:05:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Identities
[2012.12.11 18:13:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\ilividtoolbarguid
[2008.10.15 08:05:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\InstallShield
[2008.10.15 23:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\InterVideo
[2009.05.16 11:33:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Macromedia
[2009.09.16 16:54:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Malwarebytes
[2012.02.04 19:04:28 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Microsoft
[2010.06.19 17:11:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Mozilla
[2012.08.06 18:44:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Product_RM
[2010.03.11 19:37:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Real
[2012.02.04 19:17:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Registry Mechanic
[2010.11.21 19:21:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\SAMSUNG Drivers Update Utility
[2012.12.11 18:13:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\searchresultstb
[2008.09.08 18:38:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\SiteAdvisor
[2010.12.15 22:19:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Skype
[2010.12.15 20:37:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\skypePM
[2008.11.09 22:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Sun
[2012.11.18 20:19:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\vlc
[2009.08.02 10:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Vso
[2008.10.15 20:56:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Windows Desktop Search
[2008.10.28 22:38:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Windows Search

< %APPDATA%\*.exe /s >
[2007.08.18 08:54:02 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer\AC3 Filter\ac3config.exe
[2007.08.18 08:53:50 | 000,016,384 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer\AC3 Filter\dialog_patch.exe
[2008.04.13 16:26:54 | 000,036,396 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer\AC3 Filter\uninstall.exe
[2008.04.01 10:51:06 | 000,691,717 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer\FFDShow\unins000.exe
[2008.03.29 16:42:00 | 000,103,424 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer\Haali media splitter\dsmux.exe
[2008.03.29 16:42:02 | 000,335,872 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer\Haali media splitter\gdsmux.exe
[2008.03.29 16:41:54 | 000,135,168 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer\Haali media splitter\mkv2vfr.exe
[2008.06.10 08:11:02 | 000,041,412 | ---- | M] () -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\BSplayer\Haali media splitter\uninstall.exe
[2009.06.09 22:54:48 | 001,915,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Macromedia\Flash Player\\bin\fpupdateax\fpupdateax.exe
[2010.12.13 18:00:05 | 000,506,024 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Real\Update\setup3.13\setup.exe
[2011.01.26 20:12:21 | 000,510,120 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Real\Update\setup3.14\setup.exe
[2012.09.25 15:56:33 | 000,449,176 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\rnupgagent.exe
[2012.09.25 18:57:47 | 027,433,440 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\stub_data\RealPlayer.exe
[2012.09.25 18:57:01 | 000,760,128 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Zdeněk Valíček\Data aplikací\Real\Update\UpgradeHelper\RealPlayer\10.20\agent\stub_exe\RealPlayer.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job >
[2012.12.11 19:19:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2012.12.12 17:53:13 | 000,000,332 | -H-- | M] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job
[2012.12.12 18:14:00 | 000,001,010 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2823653281-3228338932-1293869941-1009Core.job
[2012.12.12 18:14:01 | 000,001,062 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2823653281-3228338932-1293869941-1009UA.job
[2012.12.11 19:14:03 | 000,000,292 | ---- | M] () -- C:\WINDOWS\Tasks\RMSchedule.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008.07.10 03:27:52 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2008.07.10 03:27:52 | 001,093,632 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2008.07.10 03:27:52 | 000,499,712 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2012.12.12 17:52:09 | 000,000,147 | ---- | M] () -- C:\WINDOWS\system32\agent.log
[2012.12.11 19:14:02 | 000,000,404 | ---- | M] () -- C:\WINDOWS\system32\AppLog.log
[2012.12.11 22:52:35 | 000,002,552 | ---- | M] () -- C:\WINDOWS\system32\CONFIG.NT
[2012.12.12 17:54:07 | 000,001,158 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2008.04.14 05:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation)
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" -- [2008.01.22 10:13:20 | 000,152,872 | ---- | M] (Nero AG)
"Google Update" = "C:\Documents and Settings\Zdeněk Valíček\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c -- [2010.06.19 17:14:17 | 000,136,176 | ---- | M] (Google Inc.)

< >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2007.03.12 10:10:40 | 007,633,008 | ---- | M] (Mozilla Corporation) MD5=7B4EFF333F1B963812F6BEDC06CA2758 -- C:\Program Files\Mozilla Firefox\firefox.exe

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2009.03.08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\Program Files\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Opera\opera.exe /md5 >

< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2012.12.12 18:24:59 | 000,000,512 | ---- | M] () MD5=7FB37A3E5185CB825A5AADF89E5F74BA -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2005.02.26 07:39:02 | 001,830,912 | ---- | M] () -- \Program Files\1stbenison\All Converter\cracked.exe
[2008.11.12 21:25:49 | 000,000,369 | ---- | M] () -- \Program Files\1stbenison\All Converter\cracked.ini
[1999.06.11 19:18:36 | 000,092,827 | ---- | M] () -- \Program Files\COREL\Corel Graphics 11\Custom Data\Bumpmap\Cracks.cpt
[2002.01.30 17:31:34 | 000,016,068 | ---- | M] () -- \Program Files\COREL\Corel Graphics 11\Custom Data\Canvas\cracks2c.pcx
[2002.01.30 18:15:39 | 000,010,560 | ---- | M] () -- \Program Files\COREL\Corel Graphics 11\Custom Data\Tiles\CRACKS2M.CPT
[2005.08.30 14:13:16 | 000,003,556 | ---- | M] () -- \Program Files\Macromedia\Dreamweaver 8\Configuration\Content\Reference\PHP\CrackF.html

< *keygen* /s >
[2005.08.30 14:13:12 | 000,013,367 | ---- | M] () -- \Program Files\Macromedia\Dreamweaver 8\Configuration\Content\Reference\HTML\KEYGEN.html

