OTL.txt part.1
OTL logfile created on: 30.12.2012 12:16:05 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Michal Posvar\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
2,00 Gb Total Physical Memory | 1,13 Gb Available Physical Memory | 56,47% Memory free
4,23 Gb Paging File | 3,20 Gb Available in Paging File | 75,58% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 290,14 Gb Total Space | 16,97 Gb Free Space | 5,85% Space Free | Partition Type: NTFS
Drive D: | 7,95 Gb Total Space | 1,61 Gb Free Space | 20,23% Space Free | Partition Type: NTFS
Computer Name: MICHALPOSVAR | User Name: Michal Posvar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.12.30 12:14:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Michal Posvar\Desktop\OTL.exe
PRC - [2012.12.06 09:04:02 | 000,916,960 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012.10.30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012.10.30 23:50:56 | 000,133,912 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2012.10.10 21:15:04 | 001,258,856 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012.10.02 20:29:14 | 000,864,616 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2012.10.02 20:28:55 | 001,820,520 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012.09.29 19:54:26 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.06.11 15:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
PRC - [2012.06.11 15:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE
PRC - [2010.02.14 16:00:00 | 001,304,016 | ---- | M] (CANON INC.) -- C:\Windows\System32\spool\drivers\w32x86\3\CNABCSWK.EXE
PRC - [2010.01.11 16:00:00 | 000,226,784 | ---- | M] (CANON INC.) -- C:\Windows\System32\spool\drivers\w32x86\3\CNAP2LAK.EXE
PRC - [2009.12.06 16:00:00 | 000,181,696 | ---- | M] (CANON INC.) -- C:\Windows\System32\spool\drivers\w32x86\3\CNAP2RPK.EXE
PRC - [2009.07.17 14:32:00 | 003,576,320 | ---- | M] (Native Instruments GmbH) -- C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
PRC - [2009.04.11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008.09.24 13:32:48 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008.04.30 09:27:50 | 000,417,792 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2007.07.12 15:36:12 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007.05.28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2007.04.13 07:49:00 | 000,101,528 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe
========== Modules (No Company Name) ==========
MOD - [2012.12.06 09:04:01 | 002,397,152 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012.02.20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012.02.20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009.11.16 20:31:58 | 000,069,632 | ---- | M] () -- C:\Program Files\PSPad editor\PSPadShell.dll
MOD - [2007.10.02 14:41:38 | 000,319,488 | ---- | M] () -- C:\Program Files\WinRAR\rarlng.dll
MOD - [2007.09.20 17:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe -- (BlueSoleilCS)
SRV - [2012.12.11 23:09:34 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.12.06 09:04:01 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012.10.30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012.10.30 23:50:56 | 000,133,912 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
SRV - [2012.10.10 21:15:04 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012.10.02 13:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012.09.29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.09.29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012.07.13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.06.11 15:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012.06.11 15:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE -- (BBSvc)
SRV - [2011.03.16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009.07.17 14:32:00 | 003,576,320 | ---- | M] (Native Instruments GmbH) [Auto | Running] -- C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe -- (NIHardwareService)
SRV - [2008.10.13 19:29:58 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008.10.03 17:46:49 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2008.09.24 13:32:48 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2008.04.30 09:27:50 | 000,417,792 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
SRV - [2008.01.19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.07.12 15:36:12 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2007.05.28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2007.04.13 07:49:00 | 000,101,528 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\VcommMgr.sys -- (VcommMgr)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\VComm.sys -- (VComm)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIMMP)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIM)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\muvee Technologies\muvee autoProducer 6.1 -- (NTIDrvr)
DRV - File not found [Kernel | Auto | Stopped] -- -- (Nsynas32)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\MICHAL~1\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | Boot | Stopped] -- System32\Drivers\BtHidBus.sys -- (BtHidBus)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\btcusb.sys -- (Btcsrusb)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btnetdrv.sys -- (BT)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (ajx9nb3d)
DRV - [2012.10.30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012.10.30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012.10.30 23:51:58 | 000,199,320 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis2.sys -- (aswNdis2)
DRV - [2012.10.30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012.10.30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2012.10.30 23:51:57 | 000,058,680 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2012.10.30 23:51:56 | 000,106,560 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswFW.sys -- (aswFW)
DRV - [2012.10.30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012.10.30 23:51:56 | 000,020,624 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswKbd.sys -- (aswKbd)
DRV - [2012.10.10 21:14:28 | 010,837,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012.09.29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012.09.21 10:26:08 | 000,012,112 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis.sys -- (aswNdis)
DRV - [2011.02.09 22:15:38 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2009.11.26 00:06:34 | 000,034,384 | ---- | M] (Screaming Bee LLC) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ScreamingBAudio.sys -- (SCREAMINGBDRIVER)
DRV - [2009.04.11 05:45:24 | 000,113,664 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rmcast.sys -- (RMCAST)
DRV - [2008.10.22 12:35:20 | 000,029,832 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btnetBus.sys -- (btnetBUs)
DRV - [2008.10.11 12:40:34 | 000,685,816 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2008.07.15 17:12:38 | 001,173,016 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ha20x2k.sys -- (ha20x2k)
DRV - [2008.07.15 17:11:14 | 000,092,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\emupia2k.sys -- (emupia)
DRV - [2008.07.15 17:10:28 | 000,157,208 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2008.07.15 17:09:44 | 000,014,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV - [2008.07.15 17:08:36 | 000,127,000 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2008.07.15 17:08:08 | 000,347,080 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ctdvda2k.sys -- (ctdvda2k)
DRV - [2008.07.15 17:07:18 | 000,527,384 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctaud2k.sys -- (ctaud2k)
DRV - [2008.07.15 17:06:46 | 000,511,000 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctac32k.sys -- (ctac32k)
DRV - [2008.07.15 16:23:42 | 000,072,728 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\CTHWIUT.DLL -- (CTHWIUT.DLL)
DRV - [2008.07.15 16:23:22 | 000,170,520 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\CT20XUT.DLL -- (CT20XUT.DLL)
DRV - [2008.07.15 16:22:46 | 001,323,544 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\CTEXFIFX.DLL -- (CTEXFIFX.DLL)
DRV - [2008.03.19 08:29:26 | 001,176,064 | ---- | M] (Hauppauge Computer Works) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HCW85BDA.sys -- (HCW85BDA)
DRV - [2007.10.03 17:18:12 | 000,099,840 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2007.05.21 17:04:24 | 000,029,568 | ---- | M] (Cristalink Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TTM57SLUsb.sys -- (TTM57SLUsb)
DRV - [2005.12.12 17:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PS2.sys -- (Ps2)
DRV - [2004.02.09 13:06:22 | 000,015,360 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NetMotCM.sys -- (ndiscm)
DRV - [1999.09.10 11:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\Windows\System32\drivers\ASPI32.SYS -- (ASPI32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-159780402-3137050833-2999077547-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/
IE - HKU\S-1-5-21-159780402-3137050833-2999077547-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-159780402-3137050833-2999077547-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-159780402-3137050833-2999077547-1000\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No CLSID value found
IE - HKU\S-1-5-21-159780402-3137050833-2999077547-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-159780402-3137050833-2999077547-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-159780402-3137050833-2999077547-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-159780402-3137050833-2999077547-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
IE - HKU\S-1-5-21-159780402-3137050833-2999077547-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
IE - HKU\S-1-5-21-159780402-3137050833-2999077547-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
IE - HKU\S-1-5-21-159780402-3137050833-2999077547-1003\..\SearchScopes,DefaultScope =
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.cz/"
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0033-ABCDEFFEDCBA%7D:6.0.33
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:7.0.1474
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:2.5.6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:4.0.1.0
FF - prefs.js..network.proxy.backup.ftp: "94.23.56.105"
FF - prefs.js..network.proxy.backup.ftp_port: 80
FF - prefs.js..network.proxy.backup.gopher: "109.69.2.6"
FF - prefs.js..network.proxy.backup.gopher_port: 8080
FF - prefs.js..network.proxy.backup.socks: "94.23.56.105"
FF - prefs.js..network.proxy.backup.socks_port: 80
FF - prefs.js..network.proxy.backup.ssl: "94.23.56.105"
FF - prefs.js..network.proxy.backup.ssl_port: 80
FF - prefs.js..network.proxy.ftp: "178.170.101.200"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "109.88.13.122"
FF - prefs.js..network.proxy.gopher_port: 8080
FF - prefs.js..network.proxy.http: "178.170.101.200"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.no_proxies_on: ""
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "178.170.101.200"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "178.170.101.200"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - prefs.js..network.proxy.type: 4
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2852: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Michal Posvar\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012.12.24 14:17:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.12.26 11:06:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.12.06 09:03:50 | 000,000,000 | ---D | M]
[2008.10.10 18:59:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michal Posvar\AppData\Roaming\mozilla\Extensions
[2012.12.26 11:06:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michal Posvar\AppData\Roaming\mozilla\Firefox\Profiles\ayzwwxfw.default\extensions
[2012.11.29 21:12:47 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\Michal Posvar\AppData\Roaming\mozilla\Firefox\Profiles\ayzwwxfw.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010.11.20 22:35:35 | 000,000,000 | ---D | M] (Tamper Data) -- C:\Users\Michal Posvar\AppData\Roaming\mozilla\Firefox\Profiles\ayzwwxfw.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2012.11.22 07:24:55 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Michal Posvar\AppData\Roaming\mozilla\Firefox\Profiles\ayzwwxfw.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012.09.03 10:54:14 | 000,199,396 | ---- | M] () (No name found) -- C:\Users\Michal Posvar\AppData\Roaming\mozilla\firefox\profiles\ayzwwxfw.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2012.12.06 09:03:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012.12.06 09:03:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012.12.06 09:03:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\temp
[2012.12.24 14:17:04 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012.12.06 09:04:03 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012.02.16 13:28:19 | 000,002,208 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\heureka-cz.xml
[2012.02.16 13:28:19 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2012.02.16 13:28:19 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2012.02.16 13:28:19 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2012.02.16 13:28:19 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2012.12.27 15:17:50 | 000,000,724 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - No CLSID value found.
O3 - HKU\S-1-5-21-159780402-3137050833-2999077547-1000\..\Toolbar\WebBrowser: (no name) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CNAP2 Launcher] C:\Windows\System32\spool\drivers\w32x86\3\CNAP2LAK.EXE (CANON INC.)
O4 - HKLM..\Run: [ICQ Sniffer] File not found
O4 - HKU\S-1-5-21-159780402-3137050833-2999077547-1000..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-159780402-3137050833-2999077547-1000..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKU\S-1-5-21-159780402-3137050833-2999077547-1000..\Run: [OEXPRESS] File not found
O4 - HKU\S-1-5-21-159780402-3137050833-2999077547-1003..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Michal Posvar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_02243903.lnk = C:\Users\Michal Posvar\AppData\Local\Temp\_uninst_02243903.bat ()
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: mojebanka.cz ([*] https in Trusted sites)
O15 - HKU\S-1-5-21-159780402-3137050833-2999077547-1000\..Trusted Domains: mojebanka.cz ([*] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Reg Error: Value error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 10.9.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.46.172.36 213.46.172.37
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{14AB3A8C-44B8-485B-B195-02F23D2EAEE3}: DhcpNameServer = 213.46.172.36 213.46.172.37
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{53FEB01E-42C4-4313-B6BD-111D0FCEB76D}: DhcpNameServer = 213.46.172.36 213.46.172.37
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Michal Posvar\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Michal Posvar\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.04.25 20:42:28 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{9eabbe64-9789-11dd-a92e-001fc6059860}\Shell - "" = AutoRun
O33 - MountPoints2\{9eabbe64-9789-11dd-a92e-001fc6059860}\Shell\AutoRun\command - "" = M:\LANLauncher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS
http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\Windows\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (
www.helixcommunity.org)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2012.12.30 12:14:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Michal Posvar\Desktop\OTL.exe
[2012.12.30 12:09:00 | 000,147,456 | ---- | C] (Eric_71) -- C:\Users\Michal Posvar\Desktop\MbrScan.exe
[2012.12.30 11:59:14 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.12.30 10:59:26 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012.12.30 10:57:36 | 001,754,528 | ---- | C] (Bleeping Computer, LLC) -- C:\Users\Michal Posvar\Desktop\rkill.com
[2012.12.30 00:15:47 | 000,000,000 | ---D | C] -- C:\Users\Michal Posvar\Desktop\mbar-1.01.0.1011
[2012.12.29 20:50:49 | 000,000,000 | --SD | C] -- C:\ComboFix
[2012.12.29 14:56:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2012.12.29 14:45:53 | 000,000,000 | ---D | C] -- C:\Users\Michal Posvar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012.12.29 14:45:51 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012.12.29 14:45:32 | 001,187,896 | ---- | C] (Piriform Ltd) -- C:\Users\Michal Posvar\Desktop\ccleaner.exe
[2012.12.27 17:34:02 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.12.27 17:34:02 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.12.27 17:34:02 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.12.27 17:01:53 | 000,663,552 | ---- | C] (ESET) -- C:\Users\Michal Posvar\Desktop\ESETUninstaller.exe
[2012.12.27 16:30:42 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.12.27 16:30:05 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012.12.27 16:25:13 | 005,015,826 | R--- | C] (Swearware) -- C:\Users\Michal Posvar\Desktop\ComboFix.exe
[2012.12.27 14:23:51 | 000,000,000 | ---D | C] -- C:\Users\Michal Posvar\Desktop\RK_Quarantine
[2012.12.26 21:18:18 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Michal Posvar\Desktop\tdsskiller.exe
[2012.12.26 15:49:18 | 000,000,000 | ---D | C] -- C:\Users\Michal Posvar\AppData\Roaming\Malwarebytes
[2012.12.26 15:48:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.12.26 15:48:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.12.26 15:48:07 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012.12.26 15:48:07 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012.12.26 15:47:41 | 010,669,952 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Michal Posvar\Desktop\mbam-setup-1.65.1.1000.exe
[2012.12.25 16:07:14 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012.12.25 16:07:14 | 000,000,000 | ---D | C] -- C:\rsit
[2012.12.24 14:18:52 | 000,021,256 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2012.12.24 14:18:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2012.12.24 14:18:50 | 000,361,032 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2012.12.24 14:18:42 | 000,106,560 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
[2012.12.24 14:17:31 | 000,199,320 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
[2012.12.24 14:17:31 | 000,054,232 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2012.12.24 14:17:31 | 000,035,928 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2012.12.24 14:17:30 | 000,738,504 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2012.12.24 14:17:30 | 000,020,624 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswKbd.sys
[2012.12.24 14:17:29 | 000,058,680 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2012.12.24 14:16:49 | 000,012,112 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
[2012.12.24 14:16:48 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012.12.24 14:16:47 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2012.12.24 14:16:18 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2012.12.24 14:16:18 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012.12.24 12:26:32 | 000,000,000 | ---D | C] -- C:\Users\Michal Posvar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mega Codec Pack
[2012.12.24 12:26:23 | 000,000,000 | ---D | C] -- C:\Program Files\Mega Codec Pack
[2012.12.23 13:46:46 | 000,000,000 | ---D | C] -- C:\Users\Michal Posvar\Desktop\dj-doemixxx-pimp-spi
[2012.12.21 07:01:02 | 000,293,376 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2012.12.21 07:01:02 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2012.12.13 19:17:00 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012.12.13 19:16:59 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012.12.13 19:16:59 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012.12.13 19:16:58 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012.12.13 19:16:58 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012.12.13 19:16:56 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012.12.13 19:16:56 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012.12.13 19:16:54 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012.12.13 03:09:10 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wdfres.dll
[2012.12.13 03:08:59 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFPlatform.dll
[2012.12.13 03:08:59 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winusb.dll
[2012.12.13 03:08:58 | 000,047,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\WdfLdr.sys
[2012.12.13 03:08:56 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFx.dll
[2012.12.13 03:08:56 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFCoinstaller.dll
[2012.12.13 03:05:14 | 000,376,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnet.dll
[2012.12.13 03:05:14 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnsvr.exe
[2012.12.13 03:05:05 | 002,048,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012.12.13 03:03:56 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012.12.09 10:06:17 | 000,000,000 | ---D | C] -- C:\Users\Michal Posvar\Desktop\seminárky
[2012.12.06 09:03:45 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2008.12.13 22:47:57 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Michal Posvar\AppData\Roaming\pcouffin.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.12.30 12:18:35 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2012.12.30 12:14:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Michal Posvar\Desktop\OTL.exe
[2012.12.30 12:11:00 | 000,000,954 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012.12.30 12:09:24 | 000,000,512 | ---- | M] () -- C:\Users\Michal Posvar\Desktop\Dump_Hdd0_DR0.mbr
[2012.12.30 12:09:15 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.12.30 12:09:01 | 000,147,456 | ---- | M] (Eric_71) -- C:\Users\Michal Posvar\Desktop\MbrScan.exe
[2012.12.30 11:59:14 | 000,003,968 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012.12.30 11:59:14 | 000,000,950 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.12.30 11:59:13 | 000,003,968 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012.12.30 11:59:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.12.30 11:59:06 | 2146,738,176 | -HS- | M] () -- C:\hiberfil.sys
[2012.12.30 11:55:10 | 000,055,432 | ---- | M] () -- C:\Windows\System32\BMXStateBkp-{00000001-00000000-00000000-00001102-00000005-00211102}.rfx
[2012.12.30 11:55:10 | 000,055,432 | ---- | M] () -- C:\Windows\System32\BMXState-{00000001-00000000-00000000-00001102-00000005-00211102}.rfx
[2012.12.30 11:55:10 | 000,000,788 | ---- | M] () -- C:\Windows\System32\DVCState-{00000001-00000000-00000000-00001102-00000005-00211102}.rfx
[2012.12.30 11:54:50 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012.12.30 10:59:53 | 005,015,826 | R--- | M] (Swearware) -- C:\Users\Michal Posvar\Desktop\ComboFix.exe
[2012.12.30 10:57:46 | 001,754,528 | ---- | M] (Bleeping Computer, LLC) -- C:\Users\Michal Posvar\Desktop\rkill.com
[2012.12.30 00:00:01 | 000,000,386 | ---- | M] () -- C:\Windows\tasks\NeroLiveEpgUpdate-MichalPosvar-PC_Michal-Posvar.job
[2012.12.29 17:17:13 | 004,024,744 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012.12.29 14:56:23 | 000,000,857 | ---- | M] () -- C:\Users\Michal Posvar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_02243903.lnk
[2012.12.29 14:53:24 | 150,118,424 | ---- | M] () -- C:\Users\Michal Posvar\Desktop\setup_11.0.0.1245.x01_2012_12_29_17_18.exe
[2012.12.29 14:49:56 | 000,316,272 | ---- | M] () -- C:\Users\Michal Posvar\Documents\cc_20121229_144944.reg
[2012.12.29 14:45:53 | 000,000,806 | ---- | M] () -- C:\Users\Michal Posvar\Desktop\CCleaner.lnk
[2012.12.29 14:45:33 | 001,187,896 | ---- | M] (Piriform Ltd) -- C:\Users\Michal Posvar\Desktop\ccleaner.exe
[2012.12.27 17:01:54 | 000,663,552 | ---- | M] (ESET) -- C:\Users\Michal Posvar\Desktop\ESETUninstaller.exe
[2012.12.27 15:52:16 | 000,647,886 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2012.12.27 15:52:16 | 000,637,344 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012.12.27 15:52:16 | 000,139,136 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2012.12.27 15:52:16 | 000,120,848 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012.12.27 14:16:40 | 000,758,272 | ---- | M] () -- C:\Users\Michal Posvar\Desktop\RogueKiller.exe
[2012.12.26 21:18:19 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Michal Posvar\Desktop\tdsskiller.exe
[2012.12.26 19:18:03 | 000,395,501 | ---- | M] () -- C:\Users\Michal Posvar\Desktop\Bez názvu 2.jpg
[2012.12.26 15:48:10 | 000,000,908 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.12.26 15:47:44 | 010,669,952 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Michal Posvar\Desktop\mbam-setup-1.65.1.1000.exe
[2012.12.26 15:00:00 | 000,000,386 | ---- | M] () -- C:\Windows\tasks\NeroLiveEpgUpdate-MICHALPOSVAR_Michal-Posvar.job
[2012.12.26 11:06:01 | 000,550,017 | ---- | M] () -- C:\Users\Michal Posvar\Desktop\adwcleaner.exe
[2012.12.25 16:07:01 | 000,781,383 | ---- | M] () -- C:\Users\Michal Posvar\Desktop\RSIT.exe
[2012.12.24 14:17:29 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2012.12.24 14:01:29 | 000,002,875 | ---- | M] () -- C:\Users\Michal Posvar\Desktop\Sharedaccess.reg
[2012.12.24 13:37:55 | 000,001,356 | ---- | M] () -- C:\Users\Michal Posvar\AppData\Local\d3d9caps.dat
[2012.12.24 13:18:55 | 070,003,712 | ---- | M] () -- C:\Users\Michal Posvar\Desktop\ess_nt32_csy.msi
[2012.12.22 14:40:31 | 000,174,592 | ---- | M] () -- C:\Users\Michal Posvar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012.12.19 18:55:24 | 000,001,175 | ---- | M] () -- C:\Users\Michal Posvar\AppData\Roaming\vso_ts_preview.xml
[2012.12.17 23:59:35 | 000,004,002 | ---- | M] () -- C:\Windows\WDICT32.INI
[2012.12.16 14:12:54 | 000,034,304 | ---- | M] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2012.12.16 11:50:29 | 000,293,376 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2012.12.15 20:02:31 | 086,296,999 | ---- | M] () -- C:\Users\Michal Posvar\FRIKY FLINK - ghettotriphopreggaefunkybreaks live on E2_22.9.2012.mp3
[2012.12.11 23:09:33 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012.12.11 23:09:33 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.12.30 12:18:35 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2012.12.30 12:09:24 | 000,000,512 | ---- | C] () -- C:\Users\Michal Posvar\Desktop\Dump_Hdd0_DR0.mbr
[2012.12.30 11:59:06 | 2146,738,176 | -HS- | C] () -- C:\hiberfil.sys
[2012.12.29 14:56:23 | 000,000,857 | ---- | C] () -- C:\Users\Michal Posvar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_02243903.lnk
[2012.12.29 14:50:46 | 150,118,424 | ---- | C] () -- C:\Users\Michal Posvar\Desktop\setup_11.0.0.1245.x01_2012_12_29_17_18.exe
[2012.12.29 14:49:47 | 000,316,272 | ---- | C] () -- C:\Users\Michal Posvar\Documents\cc_20121229_144944.reg
[2012.12.29 14:45:53 | 000,000,806 | ---- | C] () -- C:\Users\Michal Posvar\Desktop\CCleaner.lnk
[2012.12.27 17:34:02 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.12.27 17:34:02 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.12.27 17:34:02 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.12.27 17:34:02 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.12.27 17:34:02 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.12.27 14:16:38 | 000,758,272 | ---- | C] () -- C:\Users\Michal Posvar\Desktop\RogueKiller.exe
[2012.12.26 19:18:01 | 000,395,501 | ---- | C] () -- C:\Users\Michal Posvar\Desktop\Bez názvu 2.jpg
[2012.12.26 15:48:10 | 000,000,908 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.12.26 11:05:59 | 000,550,017 | ---- | C] () -- C:\Users\Michal Posvar\Desktop\adwcleaner.exe
[2012.12.25 16:07:00 | 000,781,383 | ---- | C] () -- C:\Users\Michal Posvar\Desktop\RSIT.exe
[2012.12.24 14:01:28 | 000,002,875 | ---- | C] () -- C:\Users\Michal Posvar\Desktop\Sharedaccess.reg
[2012.12.24 13:17:04 | 070,003,712 | ---- | C] () -- C:\Users\Michal Posvar\Desktop\ess_nt32_csy.msi
[2012.12.13 03:09:30 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012.12.13 03:09:30 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012.11.16 14:55:43 | 256,825,686 | ---- | C] () -- C:\Users\Michal Posvar\DJ Elmur live on radio StreetCulture 12.11. 2012.mp3
[2012.11.01 15:18:39 | 086,296,999 | ---- | C] () -- C:\Users\Michal Posvar\FRIKY FLINK - ghettotriphopreggaefunkybreaks live on E2_22.9.2012.mp3
[2012.09.07 14:50:49 | 001,008,989 | ---- | C] () -- C:\Users\Michal Posvar\TNod 1.4.2.1 Final.rar
[2012.08.29 08:25:57 | 000,768,427 | ---- | C] () -- C:\Users\Michal Posvar\hugo toxxx - lobster at fuck a place.m4a
[2012.01.30 22:47:30 | 000,000,186 | ---- | C] () -- C:\Users\Michal Posvar\AppData\Roaming\MapReverseConverter.dat
[2011.11.21 11:28:54 | 000,164,864 | ---- | C] () -- C:\Windows\UNWISE.EXE
[2011.11.21 11:13:17 | 000,182,784 | ---- | C] () -- C:\Windows\System32\DGVorbis.dll
[2011.11.21 11:13:16 | 000,049,152 | ---- | C] () -- C:\Windows\System32\mp3enc.dll
[2011.11.21 11:13:16 | 000,028,672 | ---- | C] () -- C:\Windows\System32\vorbisfile.dll
[2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011.09.06 10:51:47 | 038,142,282 | ---- | C] () -- C:\Users\Michal Posvar\James Cole - Nadzemi V2 Master.wav
[2011.07.14 14:29:27 | 000,000,043 | ---- | C] () -- C:\Windows\Aurora Media Workshop.INI
[2010.12.19 10:04:31 | 000,001,175 | ---- | C] () -- C:\Users\Michal Posvar\AppData\Roaming\vso_ts_preview.xml
[2010.08.05 14:56:31 | 2097,217,938 | ---- | C] () -- C:\Users\Michal Posvar\archive.nkx
[2010.08.05 14:39:53 | 000,623,688 | ---- | C] () -- C:\Users\Michal Posvar\unnks.exe
[2010.06.11 12:41:05 | 000,000,008 | ---- | C] () -- C:\Program Files\VData.ndb
[2010.05.01 15:31:02 | 024,342,970 | ---- | C] () -- C:\Users\Michal Posvar\Návrat Supercrooo - Big Time jak kráva.avi
[2009.11.28 22:28:08 | 000,004,096 | -H-- | C] () -- C:\Users\Michal Posvar\AppData\Local\keyfile3.drm
[2009.06.07 17:00:48 | 006,088,037 | ---- | C] () -- C:\Users\Michal Posvar\Hugo_Toxxx_-_Volte_Me__Ch3F_remix__long_one.mp3
[2009.02.25 18:42:18 | 007,910,400 | ---- | C] () -- C:\Users\Michal Posvar\afterparty_enemy_rmx(10).mp3
[2009.01.22 22:23:22 | 021,017,468 | ---- | C] () -- C:\Users\Michal Posvar\AppData\Roaming\x-dvd-ripper-ultimate.exe
[2008.12.18 19:59:40 | 000,023,027 | ---- | C] () -- C:\Users\Michal Posvar\check.ini
[2008.12.13 22:47:57 | 000,087,608 | ---- | C] () -- C:\Users\Michal Posvar\AppData\Roaming\inst.exe
[2008.12.13 22:47:57 | 000,007,887 | ---- | C] () -- C:\Users\Michal Posvar\AppData\Roaming\pcouffin.cat
[2008.12.13 22:47:57 | 000,001,144 | ---- | C] () -- C:\Users\Michal Posvar\AppData\Roaming\pcouffin.inf
[2008.10.16 11:31:19 | 000,000,101 | ---- | C] () -- C:\Users\Michal Posvar\AppData\Local\fusioncache.dat
[2008.10.08 16:56:33 | 000,000,270 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2008.10.07 15:42:39 | 000,174,592 | ---- | C] () -- C:\Users\Michal Posvar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.10.02 02:11:12 | 000,001,356 | ---- | C] () -- C:\Users\Michal Posvar\AppData\Local\d3d9caps.dat
========== ZeroAccess Check ==========
[2006.11.02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012.06.28 14:23:56 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Ableton
[2012.11.16 15:11:24 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Audacity
[2011.08.09 10:19:36 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Autodesk
[2009.07.04 08:09:20 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Boolat Games
[2012.07.29 12:17:15 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\BSplayer PRO
[2008.10.11 13:29:35 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Cakewalk
[2011.10.04 17:21:07 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Canon
[2010.07.13 23:03:06 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.07.03 20:27:06 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\ESET
[2009.03.21 20:45:44 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Farm Mania
[2012.01.30 23:08:40 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\GARMIN
[2008.10.25 22:35:24 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\GHISLER
[2012.09.06 19:06:59 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\ICQ
[2011.01.31 11:59:39 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Leadertech
[2008.12.07 22:30:54 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Miranda
[2010.06.16 20:41:38 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\MusicLab
[2010.03.19 14:22:26 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\muvee Technologies
[2009.01.06 23:50:38 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\PeerNetworking
[2010.09.28 03:52:49 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Propellerhead Software
[2010.10.14 15:13:49 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Publish Providers
[2010.02.06 13:09:13 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Screaming Bee
[2012.01.26 21:26:33 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Sony
[2010.06.22 07:15:24 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Steinberg
[2011.08.10 17:29:15 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\SynthMaker
[2011.10.02 14:52:09 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Tenebril
[2012.12.24 12:28:18 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\uTorrent
[2012.12.19 18:55:24 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\Vso
[2009.08.29 20:30:08 | 000,000,000 | ---D | M] -- C:\Users\Michal Posvar\AppData\Roaming\YoudaGames