This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Keylogger - find it and remove it - how?

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings, just yesterday the online game I play had started showing signs of being compromised, and indeed it was, I got hacked, and the administrators sent me an email, saying they'd reset my password, but urging me to clean my system of any possible causes for this problem. So I suspect I have a keylogger in my computer, thus I don't want to change my password as of yet. I would be eternally grateful if you advised me how to locate and eradicate the keylogger (If it indeed is the source of my problem). I have no idea what should I do in situations like this, I appreciate any kind of advice or help you might give me… Please help! :o
Alright, posting here, OTL.txt:

OTL logfile created on: 3.8.2010 20:55:36 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Johny\Desktop\OTL
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1 023,00 Mb Total Physical Memory | 276,00 Mb Available Physical Memory | 27,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 59,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149,05 Gb Total Space | 9,68 Gb Free Space | 6,49% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOHNY-PC
Current User Name: Johny
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Johny\Desktop\OTL\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
PRC - C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
PRC - C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Microsoft LifeChat\LifeChat.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\audiodg.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - C:\Program Files\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Johny\Desktop\OTL\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (NanoServiceMain) – C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (ISPwdSvc) – C:\Program Files\Norton Internet Security\isPwdSvc.exe (Symantec Corporation)
SRV - (comHost) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (LiveUpdate Notice Ex) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SymAppCore) – C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (SSHDRV65) – C:\Windows\System32\drivers\SSHDRV65.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (npf) – C:\Windows\System32\drivers\npf.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (PSINAflt) – C:\Windows\System32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (PSINProt) – C:\Windows\System32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINKNC) – C:\Windows\System32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (PSINProc) – C:\Windows\System32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (PSINFile) – C:\Windows\System32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - ({1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}) – C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl (CyberLink Corp.)
DRV - (SYMNDISV) – C:\Windows\System32\Drivers\SYMNDISV.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\Windows\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\Windows\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (usbaudio) Ovladač zvuků USB (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20080309.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20080309.003\NAVENG.SYS (Symantec Corporation)
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20080305.002\IDSvix86.sys (Symantec Corporation)
DRV - (WINUSB) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvm60x32.sys (NVIDIA Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (MTsensor) – C:\Windows\System32\drivers\ASACPI.sys ()
DRV - (ADIHdAudAddService) – C:\Windows\System32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (k750bus) Sony Ericsson 750 driver (WDM) – C:\Windows\System32\drivers\k750bus.sys (MCCI)
DRV - (k750obex) – C:\Windows\System32\drivers\k750obex.sys (MCCI)
DRV - (k750mgmt) – C:\Windows\System32\drivers\k750mgmt.sys (MCCI)
DRV - (k750mdm) – C:\Windows\System32\drivers\k750mdm.sys (MCCI)
DRV - (k750mdfl) – C:\Windows\System32\drivers\k750mdfl.sys (MCCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2009.02.04 22:48:12 | 000,000,000 | —D | M] – C:\Users\Johny\AppData\Roaming\Mozilla\Extensions
[2009.02.04 22:48:12 | 000,000,000 | —D | M] – C:\Users\Johny\AppData\Roaming\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2006.09.18 23:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBHO.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [LifeChat] C:\Program Files\Microsoft LifeChat\LifeChat.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PSUNMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WindowsLivePhone] C:\Program Files\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [ICQ] C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O4 - HKCU..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [WindowsLivePhone] C:\Program Files\Windows Live\Device Manager\msgrdvmn.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Johny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xportovat; do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat; do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/…NPUpldcs-cz.cab (MSN Photo Upload Tool)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/Game…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Johny\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Johny\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010.08.03 20:54:30 | 000,000,000 | —D | C] – C:\Users\Johny\Desktop\OTL
[2010.08.02 15:13:46 | 000,000,000 | —D | C] – C:\Users\Johny\Desktop\Linda Italská hudba
[2010.08.01 16:38:11 | 000,000,000 | —D | C] – C:\Users\Johny\AppData\Roaming\Panda Security
[2010.08.01 16:24:28 | 000,000,000 | —D | C] – C:\ProgramData\Panda Security
[2010.08.01 16:24:28 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2010.07.12 15:04:29 | 000,000,000 | —D | C] – C:\Users\Johny\AppData\Local\IsolatedStorage
[2010.07.07 10:13:29 | 000,000,000 | —D | C] – C:\Program Files\AVIVA
[2010.07.07 10:12:01 | 000,000,000 | —D | C] – C:\Users\Johny\Desktop\IllustrationGN verze 1.2.7 kompilace DSF

========== Files - Modified Within 30 Days ==========

[2010.08.03 20:55:30 | 004,718,592 | -HS- | M] () – C:\Users\Johny\NTUSER.DAT
[2010.08.03 20:18:06 | 000,000,940 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010.08.03 20:15:30 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010.08.03 20:14:46 | 000,016,384 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2010.08.03 20:14:45 | 000,004,176 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010.08.03 20:14:45 | 000,004,176 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010.08.03 20:14:30 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010.08.03 20:14:18 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010.08.03 20:13:47 | 1073,078,272 | -HS- | M] () – C:\hiberfil.sys
[2010.08.03 20:12:03 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010.08.03 20:11:33 | 000,524,288 | -HS- | M] () – C:\Users\Johny\NTUSER.DAT{fd40ee77-3384-11dd-a40a-001bfcb8800a}.TMContainer00000000000000000002.regtrans-ms
[2010.08.03 20:11:33 | 000,065,536 | -HS- | M] () – C:\Users\Johny\NTUSER.DAT{fd40ee77-3384-11dd-a40a-001bfcb8800a}.TM.blf
[2010.08.03 16:51:43 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{6144159C-E1E5-4C47-881F-180A1A541162}.job
[2010.08.03 01:54:46 | 004,450,710 | -H– | M] () – C:\Users\Johny\AppData\Local\IconCache.db
[2010.08.02 20:15:00 | 000,000,546 | —- | M] () – C:\Windows\tasks\Norton Internet Security - Run Full System Scan - Johny.job
[2010.08.02 17:38:40 | 000,013,234 | —- | M] () – C:\Users\Johny\Documents\Are You Still Mad.docx
[2010.08.02 16:08:59 | 000,011,617 | —- | M] () – C:\Users\Johny\Desktop\Krystle Carrara July 28 at 6.docx
[2010.08.01 16:25:28 | 000,000,264 | —- | M] () – C:\Windows\System32\PSUNCpl.dat
[2010.08.01 15:57:37 | 000,124,464 | —- | M] (Symantec Corporation) – C:\Windows\System32\drivers\SYMEVENT.SYS
[2010.08.01 15:57:37 | 000,010,635 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.CAT
[2010.08.01 15:57:37 | 000,000,806 | —- | M] () – C:\Windows\System32\drivers\SYMEVENT.INF
[2010.07.31 22:58:03 | 001,441,792 | —- | M] () – C:\Users\Johny\Video0011.3gp
[2010.07.26 11:44:54 | 002,283,759 | —- | M] () – C:\Users\Johny\Desktop\marina_ohnoglasses.pdf
[2010.07.10 17:13:21 | 000,011,365 | —- | M] () – C:\Users\Johny\Desktop\mails.docx
[2010.07.10 00:22:38 | 172,800,311 | —- | M] () – C:\Windows\MEMORY.DMP
[2010.07.07 10:13:32 | 000,001,954 | —- | M] () – C:\Users\Public\Desktop\IllustrationGN.lnk
[2010.07.07 10:11:37 | 002,788,201 | —- | M] () – C:\Users\Johny\Desktop\IllustrationGN verze 1.2.7 kompilace DSF.zip
[2010.07.07 09:06:51 | 002,788,201 | —- | M] () – C:\Users\Johny\Desktop\pojišťovna.zip

========== Files Created - No Company Name ==========

[2010.08.02 17:38:38 | 000,013,234 | —- | C] () – C:\Users\Johny\Documents\Are You Still Mad.docx
[2010.08.02 16:08:55 | 000,011,617 | —- | C] () – C:\Users\Johny\Desktop\Krystle Carrara July 28 at 6.docx
[2010.08.01 16:25:28 | 000,000,264 | —- | C] () – C:\Windows\System32\PSUNCpl.dat
[2010.07.31 22:57:37 | 001,441,792 | —- | C] () – C:\Users\Johny\Video0011.3gp
[2010.07.26 11:44:53 | 002,283,759 | —- | C] () – C:\Users\Johny\Desktop\marina_ohnoglasses.pdf
[2010.07.10 17:13:15 | 000,011,365 | —- | C] () – C:\Users\Johny\Desktop\mails.docx
[2010.07.07 10:13:32 | 000,001,954 | —- | C] () – C:\Users\Public\Desktop\IllustrationGN.lnk
[2010.07.07 10:11:26 | 002,788,201 | —- | C] () – C:\Users\Johny\Desktop\IllustrationGN verze 1.2.7 kompilace DSF.zip
[2010.07.07 09:06:35 | 002,788,201 | —- | C] () – C:\Users\Johny\Desktop\pojišťovna.zip
[2009.09.17 09:01:19 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009.08.10 17:11:04 | 000,047,104 | —- | C] () – C:\Windows\System32\KMVIDC32.DLL
[2009.08.03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009.04.04 21:59:59 | 000,717,296 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2008.09.06 20:52:42 | 000,000,025 | —- | C] () – C:\Windows\cdplayer.ini
[2008.07.13 15:05:16 | 000,000,518 | —- | C] () – C:\Windows\SIERRA.INI
[2008.01.17 20:38:47 | 000,000,060 | —- | C] () – C:\Windows\CoolYouTubeDownloader.ini
[2007.11.26 21:29:16 | 000,061,440 | —- | C] () – C:\Windows\System32\cygz.dll
[2007.11.18 02:09:21 | 000,043,520 | —- | C] () – C:\Windows\System32\CmdLineExt03.dll
[2007.11.18 00:27:59 | 000,021,840 | —- | C] () – C:\Windows\System32\SIntfNT.dll
[2007.11.18 00:27:59 | 000,017,212 | —- | C] () – C:\Windows\System32\SIntf32.dll
[2007.11.18 00:27:59 | 000,012,067 | —- | C] () – C:\Windows\System32\SIntf16.dll
[2007.11.11 17:13:11 | 000,006,824 | —- | C] () – C:\Windows\hpdj3500.ini
[2007.11.11 16:53:17 | 000,007,680 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2007.11.11 16:39:20 | 000,010,288 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2006.11.02 09:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2005.10.14 12:56:50 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2005.10.14 12:56:50 | 000,921,600 | —- | C] () – C:\Windows\System32\VorbisEnc.dll
[2005.10.14 12:56:50 | 000,761,856 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2005.10.14 12:56:50 | 000,344,064 | —- | C] () – C:\Windows\System32\xvid.dll
[2005.10.14 12:56:50 | 000,237,568 | —- | C] () – C:\Windows\System32\OggDS.dll
[2005.10.14 12:56:50 | 000,188,416 | —- | C] () – C:\Windows\System32\vorbis.dll
[2005.10.14 12:56:50 | 000,155,136 | —- | C] () – C:\Windows\System32\unrar.dll
[2005.10.14 12:56:50 | 000,045,056 | —- | C] () – C:\Windows\System32\ogg.dll
[1997.06.14 02:56:08 | 000,056,832 | —- | C] () – C:\Windows\System32\iyvu9_32.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2000.03.20 02:00:00 | 000,148,992 | RHS- | M] () – C:\arcldr.exe
[2000.03.20 02:00:00 | 000,162,816 | RHS- | M] () – C:\arcsetup.exe


< MD5 for: AGP440.SYS >
[2008.01.19 09:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008.01.19 09:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008.01.19 09:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008.01.19 09:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows.old.000\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows.old.001\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows.old.002\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows.old.003\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows.old.004\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows.old.005\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows.old.008\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows.old.008\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows.old\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\drivers\AGP440.sys
[2006.11.02 11:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009.04.11 08:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\drivers\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009.04.11 08:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008.01.19 09:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008.01.19 09:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows.old.000\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows.old.001\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows.old.002\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows.old.003\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows.old.004\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows.old.005\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows.old.008\Windows\System32\drivers\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows.old.008\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows.old\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2006.11.02 11:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008.01.19 07:06:48 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008.01.19 07:06:48 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008.01.19 06:33:23 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
[2000.03.20 02:00:00 | 000,084,976 | —- | M] (Microsoft Corporation) MD5=F4D5D4CC7B704608FC686D248981F461 – C:\WINNT\system32\drivers\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.000\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.001\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.001\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.002\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.002\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.003\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.003\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.004\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.004\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.005\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.005\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.008\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old.008\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows.old\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006.11.02 11:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2000.03.20 02:00:00 | 000,044,816 | —- | M] (Microsoft Corporation) MD5=F8156F89260C46D7B953C9BE35E4C5E0 – C:\WINNT\system32\dllcache\eventlog.dll
[2000.03.20 02:00:00 | 000,044,816 | —- | M] (Microsoft Corporation) MD5=F8156F89260C46D7B953C9BE35E4C5E0 – C:\WINNT\system32\eventlog.dll

< MD5 for: IASTORV.SYS >
[2008.01.19 09:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008.01.19 09:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows.old.000\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows.old.001\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows.old.002\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows.old.003\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows.old.004\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows.old.005\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows.old.008\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows.old.008\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows.old\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\drivers\iaStorV.sys
[2006.11.02 11:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2000.03.20 02:00:00 | 000,356,112 | —- | M] (Microsoft Corporation) MD5=13689FD40AC9D323BB6B71E78CE89709 – C:\WINNT\system32\dllcache\netlogon.dll
[2000.03.20 02:00:00 | 000,356,112 | —- | M] (Microsoft Corporation) MD5=13689FD40AC9D323BB6B71E78CE89709 – C:\WINNT\system32\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.000\Windows\System32\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.001\Windows\System32\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.001\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.002\Windows\System32\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.002\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.003\Windows\System32\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.003\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.004\Windows\System32\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.004\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.005\Windows\System32\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.005\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.008\Windows\System32\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old.008\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old\Windows\System32\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows.old\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2006.11.02 11:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2009.04.11 08:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008.01.19 09:35:36 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2007.01.05 22:59:42 | 000,035,920 | —- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 – C:\Windows\System32\drivers\nvstor.sys
[2007.01.05 22:59:42 | 000,035,920 | —- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_45f67928\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows.old.000\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows.old.001\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows.old.002\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows.old.003\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows.old.004\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows.old.005\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows.old.008\Windows\System32\drivers\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows.old.008\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows.old\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2006.11.02 11:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008.01.19 09:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008.01.19 09:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008.01.19 09:36:19 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.000\Windows\System32\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.000\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.001\Windows\System32\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.001\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.002\Windows\System32\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.002\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.003\Windows\System32\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.003\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.004\Windows\System32\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.004\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.005\Windows\System32\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.005\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.008\Windows\System32\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old.008\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old\Windows\System32\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows.old\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2006.11.02 11:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2009.04.11 08:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
[2000.03.20 02:00:00 | 000,110,352 | —- | M] (Microsoft Corporation) MD5=D7213A69DF9B6790877DAE52D5F0B8E5 – C:\WINNT\system32\dllcache\scecli.dll
[2000.03.20 02:00:00 | 000,110,352 | —- | M] (Microsoft Corporation) MD5=D7213A69DF9B6790877DAE52D5F0B8E5 – C:\WINNT\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009.03.08 13:31:42 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\dxtmsft.dll
[2009.03.08 13:31:37 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\dxtrans.dll
[2009.04.11 08:27:47 | 000,241,128 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2009.04.11 08:28:23 | 000,228,352 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009.04.04 22:00:01 | 000,717,296 | —- | M] () Unable to obtain MD5 – C:\Windows\System32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2006.11.02 12:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006.11.02 12:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006.11.02 12:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006.11.02 12:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006.11.02 12:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

========== Files - Unicode (All) ==========
[2010.06.05 09:54:13 | 000,015,270 | —- | M] ()(C:\Users\Johny\Desktop\????.docx) – C:\Users\Johny\Desktop\زوّد.docx
[2010.06.05 09:52:52 | 000,011,794 | —- | M] ()(C:\Users\Johny\Desktop\?? ????.docx) – C:\Users\Johny\Desktop\عن طريق.docx
[2010.06.05 09:52:50 | 000,011,794 | —- | C] ()(C:\Users\Johny\Desktop\?? ????.docx) – C:\Users\Johny\Desktop\عن طريق.docx
[2010.06.04 06:29:11 | 000,015,270 | —- | C] ()(C:\Users\Johny\Desktop\????.docx) – C:\Users\Johny\Desktop\زوّد.docx
[2010.04.13 23:12:25 | 000,011,454 | —- | M] ()(C:\Users\Johny\Documents\??????? ???? ?????.docx) – C:\Users\Johny\Documents\Мужчины моей жизни.docx
[2010.04.13 22:57:59 | 000,011,454 | —- | C] ()(C:\Users\Johny\Documents\??????? ???? ?????.docx) – C:\Users\Johny\Documents\Мужчины моей жизни.docx
[2010.04.05 21:39:29 | 000,011,235 | —- | M] ()(C:\Users\Johny\Documents\???????? - ???????.docx) – C:\Users\Johny\Documents\неАнгелы - Отпусти.docx
[2010.04.05 21:39:27 | 000,011,235 | —- | C] ()(C:\Users\Johny\Documents\???????? - ???????.docx) – C:\Users\Johny\Documents\неАнгелы - Отпусти.docx
[2010.03.11 23:40:55 | 000,010,749 | —- | M] ()(C:\Users\Johny\Documents\?? ????????? ????.docx) – C:\Users\Johny\Documents\Ти признайся мені.docx
[2010.03.11 23:40:47 | 000,010,749 | —- | C] ()(C:\Users\Johny\Documents\?? ????????? ????.docx) – C:\Users\Johny\Documents\Ти признайся мені.docx
< End of report >
And here Extras.txt:

OTL Extras logfile created on: 3.8.2010 20:55:36 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Johny\Desktop\OTL
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1 023,00 Mb Total Physical Memory | 276,00 Mb Available Physical Memory | 27,00% Memory free
2,00 Gb Paging File | 1,00 Gb Available in Paging File | 59,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149,05 Gb Total Space | 9,68 Gb Free Space | 6,49% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JOHNY-PC
Current User Name: Johny
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D20EF64-40EC-4F9E-8D3D-BD58E414CB88}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{1F7E0DB0-780A-4E75-954D-0AE105046C3B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4335EEB2-2103-45E3-AF5D-901638E3DCAE}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{58937FFC-E459-4181-ACD8-6A45557DFCC2}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{8AE6258A-6589-4196-A6E4-F7D045318111}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{9616DE79-386C-4265-B296-AAD39761A124}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{A1799A5F-929B-4383-B60B-CB134A7FAE00}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{AED591A2-025C-4E76-8BA7-8157688EECD5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{C9E723F9-C828-4C36-A751-7DD6F52DB542}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D80BF9C7-DE3C-451E-9FC2-EC0E03821974}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=c:\windows\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1D25BF6D-3414-42A3-807B-76D15840ACB0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{22027625-30FC-4F9D-9FB1-B60CE7D44ACB}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{2867935F-6409-4641-972C-761E2BE869CD}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{316617F6-1B2E-49CE-8EBC-E6728B4A1322}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{3378E7E9-EADB-4C1D-A07A-10518A1A27B9}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{33D5038E-6C42-4355-8048-2F240EBA0581}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{46C07269-6366-404A-8F19-A5B510B25E1B}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{4C1C0230-FCBC-4F5A-8AE3-60DB784D00DD}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4D1F001F-D73B-42E0-86BE-6428AF7F6782}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{5F4EF7E3-23FC-46E4-A545-0D6A6DF196E0}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{64ACA9B2-003D-4E3E-9F78-DE4E8966DD97}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{6D78C979-BC1B-47E8-9A02-466C5E72C16E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6FFA50D7-2057-407C-8EB8-27179FEDD252}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{780EB54F-0691-4311-BC2D-76DEAECD1F81}" = protocol=17 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{793C4E21-5D8A-4A97-BA76-78E89E6F32FA}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{7B437C87-48E4-4FA5-9EAA-C84F31C55719}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{834AA4DD-52C1-47CD-BCF0-BD0008E4D83E}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8E6035D7-1C37-438E-9A01-9C91417A1D2B}" = protocol=6 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{AEA51A8B-1FB0-44AE-8DE9-FAC90421E111}" = protocol=6 | dir=in | app=c:\program files\icq7.2\aolload.exe |
"{B394207B-90E3-4F90-A8BD-D4690A39F8AA}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C1281164-A34A-4661-A2E5-DB23D533B12F}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D314125F-9AD1-4163-A453-8396C85DC5CC}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{D44CFE00-48B4-405F-A247-ECE5EAEF6259}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D4A1BB6D-4438-462B-BC1A-6C5002F1C8D1}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D4C8FA1E-29DA-4F7F-A15D-01D1EF53E1F7}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{E174B9BB-DF37-4025-81E3-2C1F4ABBCC8C}" = dir=in | app=c:\program files\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe |
"{EE337431-2140-4CE6-9C54-1BF7B86C7E0D}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{F2A60047-8B0D-46C8-923A-8A2438C9F293}" = dir=in | app=c:\program files\cyberlink\powerdvd10\powerdvd9.exe |
"{F82444B6-DCB7-4199-8B52-39FADCDCED91}" = protocol=17 | dir=in | app=c:\program files\icq7.2\icq.exe |
"{FA3E87E4-08AF-48BD-8EEE-3E2E6E551619}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{FC8F626D-61FE-43C4-990B-944F1033BEB5}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"TCP Query User{02261877-E608-4171-AFDC-A87E52ED1305}C:\program files\vampire the masquerade - redemption\vampire.exe" = protocol=6 | dir=in | app=c:\program files\vampire the masquerade - redemption\vampire.exe |
"TCP Query User{217228F4-C0A8-4135-86BC-5D8EBB735849}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{463F1016-A523-42DC-8A32-2C5BDD5EF4D5}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{634BD875-E59A-411F-8606-E7468400ADB2}C:\program files\microsoft games\dungeon siege\dsloa.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\dungeon siege\dsloa.exe |
"TCP Query User{82CFCBF7-BBDE-4874-8792-663A4EDDC0AB}C:\program files\microsoft games\dungeon siege\dungeonsiege.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\dungeon siege\dungeonsiege.exe |
"TCP Query User{B178F4AB-2E72-4571-A3C6-65B43E62B0F4}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{B57432B3-B30E-40EE-B729-9D8BD8DCE1F7}C:\windows\system32\dpnsvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dpnsvr.exe |
"UDP Query User{22A7BE1D-E7B5-432D-BD6B-5F6F1431C51B}C:\program files\vampire the masquerade - redemption\vampire.exe" = protocol=17 | dir=in | app=c:\program files\vampire the masquerade - redemption\vampire.exe |
"UDP Query User{327A6F42-28EF-400A-93A0-29CA73ED020C}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{395A083A-7C2A-4EE6-9EC6-B70F2B616013}C:\windows\system32\dpnsvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dpnsvr.exe |
"UDP Query User{436691BA-31CF-48D0-9786-588A942272CF}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{52753EE6-F763-4DA6-A280-58D3FBB0719E}C:\program files\microsoft games\dungeon siege\dungeonsiege.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\dungeon siege\dungeonsiege.exe |
"UDP Query User{87BF1519-63F3-4F9E-8ED6-298D50C6E546}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{8D671622-8ABD-41B8-BC0D-A9325EEA21DF}C:\program files\microsoft games\dungeon siege\dsloa.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\dungeon siege\dsloa.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{068B46A0-8858-4CEB-80BC-A4AE787A05FC}" = Windows Live Sync
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Pomocník pro přihlášení ke službě Windows Live ID
"{0BAA95A7-4303-11D6-851F-00C0CA129740}" = Heroes of Might and Magic® II
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D097338-B4FA-4F29-9C43-8D7A970A007E}" = Windows Live Fotogalerie
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Nástroj pro odesílání služby Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 19
"{2E38A4D9-F653-4A3E-9D99-94318B799455}" = IllustrationGenerationNext
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CCAD2EF-CFF2-4637-82AA-AABF370282D3}" = ccCommon
"{3D4D4CBF-79F3-4E38-A1DC-30646F030443}" = Microsoft LifeChat
"{48185814-A224-447A-81DA-71BD20580E1B}" = Norton Internet Security
"{4843B611-8FCB-4428-8C23-31D0A5EAE164}" = Norton Confidential Browser Component
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}" = Norton Internet Security
"{6530EB5E-F2BE-45D3-906B-E4AFFF2D1588}" = Windows Live Device Manager
"{71E40B32-5173-4538-8996-5822DD18E8D4}" = Windows Live Messenger
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{830D8CBD-C668-49e2-A969-C2C2106332E0}" = Norton AntiVirus
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_HOMESTUDENTR_{294B4278-CF7B-40B9-86A1-2D3FF0C2C524}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_HOMESTUDENTR_{10EC59E5-9BCE-4884-BB1A-E28627220232}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}_HOMESTUDENTR_{E12F9D31-4025-4BC6-B1B2-AB262C5580B0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}_HOMESTUDENTR_{1FC5BC34-0301-40D2-9432-05BA220277B8}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}" = Google Earth
"{9A129ABC-A53A-4209-A21E-D5DEDFB7CCA8}" = Norton Protection Center
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{AC76BA86-7AD7-5676-5A64-E98530000001}" = Extended Language Support Fonts Package
"{B0490CEE-D5ED-431A-88EB-772D9DB70C0C}" = Windows Live Movie Maker
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B7C61755-DB48-4003-948F-3D34DB8EAF69}" = MSRedist
"{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver
"{BFF86E9F-5A90-425D-A9C7-457D909D034E}" = SymNet
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D353CC51-430D-4C6F-9B7E-52003DA1E05A}" = Norton Confidential Web Protection Component
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton Internet Security
"{E3F328E4-EB9F-4ABF-8FF3-5AD0472743D8}" = Windows Live Essentials
"{E5A10EF8-DBF3-4251-A9CA-423311DBBFC8}" = Windows Live Mail
"{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton Internet Security
"{E7C8C055-7925-4577-A694-AE84EEAD18F5}" = Symantec Real Time Storage Protection Component
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{EDFB64A7-5BFD-4137-943D-5663149A15F5}" = Heroes of Might and Magic III Complete
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4DB525F-A986-4249-B98B-42A8066251CA}" = AV
"{FEB2D0CA-9912-4AA1-8FBE-CFD852F9F1FC}" = Panda Cloud Antivirus
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.9 (Unicode)
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"Diablo II" = Diablo II
"Free Video to Mp3 Converter_is1" = Free Video to Mp3 Converter version 2.5
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{0BAA95A7-4303-11D6-851F-00C0CA129740}" = Heroes of Might and Magic® II
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"InstallShield_{EDFB64A7-5BFD-4137-943D-5663149A15F5}" = Heroes of Might and Magic III Complete
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NVIDIA Drivers" = NVIDIA Drivers
"Panda Cloud Antivirus" = Panda Cloud Antivirus
"Shockwave" = Shockwave
"Sierra Utilities" = Sierra Utilities
"SymSetup.{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}" = Norton Internet Security (Symantec Corporation)
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"World of Warcraft" = World of Warcraft

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1.8.2010 10:27:07 | Computer Name = Johny-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 1.8.2010 10:27:09 | Computer Name = Johny-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 1.8.2010 10:55:43 | Computer Name = Johny-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 1.8.2010 11:56:26 | Computer Name = Johny-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 1.8.2010 17:45:56 | Computer Name = Johny-PC | Source = ESENT | ID = 467
Description = Windows (2352) Windows: Databáze C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb:
Index System_ItemFolderPathDisplayNarrow405 tabulky SystemIndex_0A je poškozen
(0).

Error - 1.8.2010 17:45:58 | Computer Name = Johny-PC | Source = Windows Search Service | ID = 7040
Description =

Error - 2.8.2010 6:56:32 | Computer Name = Johny-PC | Source = Application Hang | ID = 1002
Description = Program iexplore.exe verze 8.0.6001.18928 přestal spolupracovat se
systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací
o tomto problému, vyhledejte historii problému v ovládacím panelu Oznámení a řešení
problémů. ID procesu: 16f0 Čas zahájení: 01cb321dc2943853 Čas ukončení: 14

Error - 2.8.2010 10:42:18 | Computer Name = Johny-PC | Source = Application Error | ID = 1000
Description = Chybující aplikace AcroRd32.exe, verze [removed], časové razítko 0x446abf60,
chybující modul WININET.dll, verze 8.0.6001.18928, časové razítko 0x4bdfb7f7, kód
výjimky 0xc0000005, posun chyby 0x0000168e, ID procesu 0x12dc, čas spuštění aplikace
0x01cb321de053e1b3.

Error - 2.8.2010 19:42:58 | Computer Name = Johny-PC | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error Initialization of the COM subsystem failed.
Error code: 0x8007041D

Error - 3.8.2010 14:54:16 | Computer Name = Johny-PC | Source = SideBySide | ID = 16842785
Description = Generování kontextu aktivace pro C:\Users\Johny\Downloads\drvupdate-amd64.exe
se nezdařilo. Závislé sestavení Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
nelze najít. Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

[ OSession Events ]
Error - 15.8.2008 15:33:24 | Computer Name = Johny-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 203
seconds with 180 seconds of active time. This session ended with a crash.

Error - 29.8.2008 11:38:07 | Computer Name = Johny-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 4553
seconds with 420 seconds of active time. This session ended with a crash.

Error - 22.9.2008 11:30:31 | Computer Name = Johny-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1268
seconds with 1260 seconds of active time. This session ended with a crash.

Error - 6.10.2008 10:43:18 | Computer Name = Johny-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 4535
seconds with 1860 seconds of active time. This session ended with a crash.

Error - 12.11.2008 9:24:36 | Computer Name = Johny-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 3515
seconds with 1680 seconds of active time. This session ended with a crash.

Error - 3.6.2009 14:53:19 | Computer Name = Johny-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 21800
seconds with 2040 seconds of active time. This session ended with a crash.

Error - 30.9.2009 12:29:09 | Computer Name = Johny-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 5982
seconds with 1200 seconds of active time. This session ended with a crash.

Error - 22.12.2009 10:02:54 | Computer Name = Johny-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 975
seconds with 900 seconds of active time. This session ended with a crash.

Error - 4.4.2010 7:43:10 | Computer Name = Johny-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 190
seconds with 120 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 2.8.2010 19:42:55 | Computer Name = Johny-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 2.8.2010 19:42:56 | Computer Name = Johny-PC | Source = DCOM | ID = 10005
Description =

Error - 2.8.2010 19:55:31 | Computer Name = Johny-PC | Source = DCOM | ID = 10010
Description =

Error - 2.8.2010 20:02:38 | Computer Name = Johny-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 2.8.2010 20:08:24 | Computer Name = Johny-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 3.8.2010 4:36:20 | Computer Name = Johny-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 3.8.2010 4:41:48 | Computer Name = Johny-PC | Source = DCOM | ID = 10010
Description =

Error - 3.8.2010 11:15:44 | Computer Name = Johny-PC | Source = volsnap | ID = 393252
Description = Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného
uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error - 3.8.2010 12:47:33 | Computer Name = Johny-PC | Source = DCOM | ID = 10010
Description =

Error - 3.8.2010 14:15:37 | Computer Name = Johny-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
Hello there, I did as you asked and here's the scan: I am deeply sorry, but I instinctively selected my language as the installation language, I didn't think the results would come up in czech as well. I will translate what it says: It generally says that it had made a quick scan, which took 11 mins, and that it detected one infected "register key" (Does that make sense in english?). No other infected processes, modules, files etc were detected. The infected register key (HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> Quarantined and deleted successfully.) was "Quarantined and deleted successfully". I hope this is all you need to know, if not, then I will run another scan in english. Sorry for the inconvenience. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Verze databáze: 4388 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18928 4.8.2010 17:18:05 mbam-log-2010-08-04 (17-18-05).txt Typ skenu: Rychlý sken Skenované objekty: 132501 Uplynulý čas: 11 minuta(y), 17 sekunda(y) Infikované procesy v paměti: 0 Infikované moduly v paměti: 0 Infikované klíče registru: 1 Infikované hodnoty registru: 0 Infikované datové položky registru: 0 Infikované složky: 0 Infikované soubory: 0 Infikované procesy v paměti: (Žádné škodlivé položky nebyly zjištěny) Infikované moduly v paměti: (Žádné škodlivé položky nebyly zjištěny) Infikované klíče registru: HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> Quarantined and deleted successfully. Infikované hodnoty registru: (Žádné škodlivé položky nebyly zjištěny) Infikované datové položky registru: (Žádné škodlivé položky nebyly zjištěny) Infikované složky: (Žádné škodlivé položky nebyly zjištěny) Infikované soubory: (Žádné škodlivé položky nebyly zjištěny) Also my computer is behaving normally, nothing out of the ordinary.
Your translation was fine :thumbup:

Lets run one more tool.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Oh boy - I downloaded the programme as you asked, turning off my Antivirus, and it restarted my computer (sort of) and upon entering my password to turn my pc on, it has started scanning in that DOS-box sort of design. A progress úercentuelle bar (Where it fills in with green, you know what I mean) appeared and at the same time it reported an error about some route that couldn't be found. Both these closed and only the DOS-box remained, stating that it is getting ready to scan. For a long time nothing happened, so I closed the DOS box and restarted my computer in order to be able to access the internet and double check your instructions. Nevertheless when I try running ComboFix now, it only shows that progress bar and when it fills up, nothing really happens, only my desktop icons flash and that's all. A "ComboFix" file was created in my /C, but there are no logs in it. Did I mess it up? :D Also, another file was created therein at the same time, its name "32788R22FWJFW", and it's full of lots of different stuff, but no logs there, so what went wrong?
If everything is running alright lets just forget combofix.
  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI