OTL.Txt
(1./2)_____________________
OTL logfile created on: 16.2.2014 13:48:42 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\CrieS\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
3,48 Gb Total Physical Memory | 1,38 Gb Available Physical Memory | 39,56% Memory free
6,96 Gb Paging File | 4,25 Gb Available in Paging File | 61,05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 698,54 Gb Total Space | 400,73 Gb Free Space | 57,37% Space Free | Partition Type: NTFS
Drive G: | 4,05 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: CRIES-PC | User Name: CrieS | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2014.02.16 13:47:21 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\CrieS\Downloads\OTL.exe
PRC - [2014.02.14 12:12:30 | 000,052,568 | ---- | M] () -- C:\Users\CrieS\AppData\Local\PirritSuggestor\PirritService.exe
PRC - [2014.02.14 12:12:28 | 000,190,808 | ---- | M] () -- C:\Users\CrieS\AppData\Local\PirritSuggestor\PirritDesktop.exe
PRC - [2014.02.14 11:29:08 | 000,059,904 | ---- | M] () -- C:\Program Files (x86)\Pirrit\AutoUpdater.exe
PRC - [2014.02.10 10:41:19 | 045,198,176 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\19.0.1326.63\opera.exe
PRC - [2014.02.10 10:41:19 | 001,378,144 | ---- | M] () -- C:\Program Files (x86)\Opera\19.0.1326.63\opera_crashreporter.exe
PRC - [2014.02.04 15:47:44 | 002,552,856 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
PRC - [2014.01.09 08:24:11 | 001,771,544 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe
PRC - [2014.01.09 08:24:11 | 000,159,768 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\loggingserver.exe
PRC - [2013.11.11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
PRC - [2013.11.07 22:03:50 | 004,956,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe
PRC - [2013.09.24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
PRC - [2013.08.11 14:54:08 | 000,051,992 | ---- | M] (cake bake) -- C:\Program Files (x86)\WBDesktop.Updater.exe
PRC - [2012.09.23 20:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.07.13 16:27:00 | 000,769,432 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
========== Modules (No Company Name) ==========
MOD - [2014.02.16 12:21:02 | 016,287,624 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll
MOD - [2014.02.14 12:12:28 | 000,190,808 | ---- | M] () -- C:\Users\CrieS\AppData\Local\PirritSuggestor\PirritDesktop.exe
MOD - [2014.02.10 10:41:21 | 000,907,616 | ---- | M] () -- C:\Program Files (x86)\Opera\19.0.1326.63\libGLESv2.dll
MOD - [2014.02.10 10:41:21 | 000,108,896 | ---- | M] () -- C:\Program Files (x86)\Opera\19.0.1326.63\libEGL.dll
MOD - [2014.02.10 10:41:20 | 000,890,208 | ---- | M] () -- C:\Program Files (x86)\Opera\19.0.1326.63\ffmpegsumo.dll
MOD - [2014.02.10 10:41:19 | 001,378,144 | ---- | M] () -- C:\Program Files (x86)\Opera\19.0.1326.63\opera_crashreporter.exe
MOD - [2014.02.04 15:47:44 | 002,552,856 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
MOD - [2014.01.09 08:24:11 | 000,519,704 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\log4cplusU.dll
========== Services (SafeList) ==========
SRV:
64bit: - [2012.09.28 15:43:40 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:
64bit: - [2012.09.28 02:38:16 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:
64bit: - [2012.04.25 14:02:52 | 000,031,000 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Windows\SysNative\hpservice.exe -- (hpsrv)
SRV:
64bit: - [2009.07.14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014.02.14 12:12:30 | 000,052,568 | ---- | M] () [Auto | Start_Pending] -- C:\Users\CrieS\AppData\Local\PirritSuggestor\PirritService.exe -- (PirritDesktop)
SRV - [2014.02.14 11:29:08 | 000,059,904 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Pirrit\AutoUpdater.exe -- (PirritUpdater)
SRV - [2014.01.27 20:02:50 | 000,571,816 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014.01.09 08:24:11 | 001,771,544 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe -- (vToolbarUpdater17.3.0)
SRV - [2013.11.11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2013.09.24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2013.09.06 01:41:08 | 000,240,736 | ---- | M] (WildTangent) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe -- (GamesAppIntegrationService)
SRV - [2013.08.11 14:54:08 | 000,051,992 | ---- | M] (cake bake) [Auto | Running] -- C:\Program Files (x86)\WBDesktop.Updater.exe -- (WebCake Desktop Updater)
SRV - [2013.02.28 17:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.11.02 13:10:47 | 000,794,112 | ---- | M] (Hewlett-Packard Company) [On_Demand | Stopped] -- C:\Users\CrieS\AppData\Roaming\Hewlett-Packard\hpqwmiex.exe -- (hpqwmiex)
SRV - [2012.09.23 20:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.07.13 16:27:00 | 000,769,432 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011.06.28 17:12:08 | 002,413,056 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)
SRV - [2010.10.12 18:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2013.11.07 14:04:41 | 000,046,368 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:
64bit: - [2013.11.05 21:55:48 | 000,150,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:
64bit: - [2013.11.04 21:52:42 | 000,240,920 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:
64bit: - [2013.10.31 23:00:18 | 000,212,280 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:
64bit: - [2013.10.31 22:49:46 | 000,294,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:
64bit: - [2013.10.24 22:25:58 | 000,194,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:
64bit: - [2013.10.01 00:52:08 | 000,123,704 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:
64bit: - [2013.09.10 00:43:02 | 000,031,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:
64bit: - [2013.08.01 15:07:06 | 000,251,192 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:
64bit: - [2012.10.31 20:24:57 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:
64bit: - [2012.10.31 15:59:36 | 004,747,840 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:
64bit: - [2012.10.31 10:49:49 | 000,030,592 | ---- | M] (REALiX(tm)) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\HWiNFO64A.SYS -- (HWiNFO32)
DRV:
64bit: - [2012.09.28 03:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:
64bit: - [2012.09.28 02:12:52 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:
64bit: - [2012.05.14 07:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:
64bit: - [2012.04.25 14:02:52 | 000,043,800 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelerometer.sys -- (Accelerometer)
DRV:
64bit: - [2012.04.25 14:02:52 | 000,030,488 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hpdskflt.sys -- (hpdskflt)
DRV:
64bit: - [2012.04.09 10:13:58 | 000,057,472 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.2)
DRV:
64bit: - [2012.03.01 07:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2011.10.14 04:37:44 | 000,396,848 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:
64bit: - [2011.05.30 16:03:34 | 000,338,536 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:
64bit: - [2011.03.11 07:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011.03.11 07:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2011.02.17 08:11:08 | 000,428,136 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:
64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009.07.14 00:31:10 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:
64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-697164410-2571323111-710328384-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.ividi.org/?src=tbhp&id=fe ... e&affilt=3
IE - HKU\S-1-5-21-697164410-2571323111-710328384-1000\..\SearchScopes,DefaultScope = {961E1816-EBD0-4139-95CB-4B55631EBC4E}
IE - HKU\S-1-5-21-697164410-2571323111-710328384-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-697164410-2571323111-710328384-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
http://www1.delta-search.com/?q={search ... 6&tsp=4954
IE - HKU\S-1-5-21-697164410-2571323111-710328384-1000\..\SearchScopes\{961E1816-EBD0-4139-95CB-4B55631EBC4E}: "URL" =
http://search.ividi.org/?q={searchTerms ... lt=3&r=744
IE - HKU\S-1-5-21-697164410-2571323111-710328384-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-697164410-2571323111-710328384-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-21-697164410-2571323111-710328384-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=
http://127.0.0.1:9880
========== FireFox ==========
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_44.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.3.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\CrieS\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
eplgTb@eset.com: C:\PROGRAM FILES\ESET\ESET SMART SECURITY\MOZILLA THUNDERBIRD
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
[2014.02.16 10:13:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\CrieS\AppData\Roaming\Mozilla\Firefox\Profiles\extensions
[2014.02.13 21:01:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\CrieS\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions
[2013.06.30 09:44:04 | 000,242,624 | ---- | M] () (No name found) -- C:\Users\CrieS\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
fhdp3@freehdsp.tv.xpi
[2014.02.13 21:01:33 | 000,036,924 | ---- | M] () (No name found) -- C:\Users\CrieS\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\
suggestor@suggestor.pirrit.com.xpi
[2013.09.26 18:39:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
========== Chrome ==========
CHR - default_search_provider: Search (Enabled)
CHR - default_search_provider: search_url =
http://search.ividi.org/?q={searchTerms ... e&affilt=3
CHR - default_search_provider: suggest_url = ,
CHR - Extension: Dokumenty Google = C:\Users\CrieS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: YouTube = C:\Users\CrieS\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Users\CrieS\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Web Cake = C:\Users\CrieS\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh\1.0.3_1\
CHR - Extension: iVidi Chrome Toolbar = C:\Users\CrieS\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef\1.0_1\
CHR - Extension: FreeHDSport TV 3 = C:\Users\CrieS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbdbmopeebalgaeghmjoegpkngglikgn\3.1_0\
CHR - Extension: AVG Security Toolbar = C:\Users\CrieS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.3.0.49_1\
CHR - Extension: Pen\u011B\u017Eenka Google = C:\Users\CrieS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0\
CHR - Extension: Gmail = C:\Users\CrieS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2014.02.16 11:22:57 | 000,000,741 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (FreeHDSport TV) - {11111111-1111-1111-1111-110311531136} - C:\Program Files (x86)\FreeHDSport TV\FreeHDSport TV-bho.dll File not found
O2 - BHO: (WebCake) - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - Reg Error: Value error. File not found
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (ividi Helper Object) - {8B8B2E80-1444-451D-AC8E-EB9A847F3887} - C:\Program Files (x86)\Unitech LLC\ividi\1.8.23.0\bh\ividi.dll (Unitech LLC)
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files (x86)\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe (Corel Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-697164410-2571323111-710328384-1000..\Run: [] File not found
O4 - HKU\S-1-5-21-697164410-2571323111-710328384-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-697164410-2571323111-710328384-1000..\Run: [FixMyRegistry] C:\Program Files (x86)\SmartTweak Software\FixMyRegistry\FixMyRegistry.exe ()
O4 - HKU\S-1-5-21-697164410-2571323111-710328384-1000..\Run: [RGSC] C:\Hry\GTA IV PC Version\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc.)
O4 - HKU\S-1-5-21-697164410-2571323111-710328384-1000..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1F26202A-BAB9-43CC-A407-0C3E93954E14}: DhcpNameServer = 192.168.1.21 192.168.1.30
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{73615AFA-91DF-475B-B833-F33DCEA58445}: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.3.0\ViProtocol.dll (AVG Secure Search)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:
64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012.04.25 09:51:38 | 000,536,936 | R--- | M] (Gaming Minds Studios GmbH) - G:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2012.04.25 09:51:38 | 000,420,633 | R--- | M] () - G:\autodata.zip -- [ CDFS ]
O32 - AutoRun File - [2012.04.25 09:51:38 | 000,000,047 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{16d5096a-72f2-11e2-b508-082e5f9a4fc0}\Shell - "" = AutoRun
O33 - MountPoints2\{16d5096a-72f2-11e2-b508-082e5f9a4fc0}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2012.04.25 09:51:38 | 000,536,936 | R--- | M] (Gaming Minds Studios GmbH)
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2012.04.25 09:51:38 | 000,536,936 | R--- | M] (Gaming Minds Studios GmbH)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs:
64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2014.02.16 12:38:15 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2014.02.16 12:38:15 | 000,000,000 | ---D | C] -- C:\rsit
[2014.02.16 12:21:02 | 000,692,616 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014.02.16 12:21:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2014.02.16 11:53:26 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2014.02.16 10:13:43 | 000,000,000 | ---D | C] -- C:\Users\CrieS\Desktop\RK_Quarantine
[2014.02.16 10:06:41 | 002,152,960 | ---- | C] (Farbar) -- C:\Users\CrieS\Desktop\FRST64.exe
[2014.02.16 10:05:46 | 000,000,000 | ---D | C] -- C:\FRST
[2014.02.16 10:03:21 | 000,000,000 | ---D | C] -- C:\Users\CrieS\AppData\Local\Opera Software
[2014.02.16 10:03:20 | 000,000,000 | ---D | C] -- C:\Users\CrieS\AppData\Roaming\Opera Software
[2014.02.16 10:03:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2014.02.16 03:01:55 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2014.02.16 00:30:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2014.02.14 21:03:11 | 000,000,000 | ---D | C] -- C:\Users\CrieS\AppData\Local\PirritSuggestor
[2014.02.14 06:51:18 | 000,000,000 | ---D | C] -- C:\Users\CrieS\AppData\Roaming\TorTemp
[2014.02.13 21:02:34 | 000,018,816 | ---- | C] (Systweak Inc., (
www.systweak.com)) -- C:\Windows\SysNative\roboot64.exe
[2014.02.13 21:02:30 | 000,000,000 | ---D | C] -- C:\Users\CrieS\AppData\Roaming\systweak
[2014.02.13 21:02:01 | 000,000,000 | ---D | C] -- C:\Users\CrieS\AppData\Local\Pirrit Suggestor
[2014.02.13 21:01:59 | 000,000,000 | ---D | C] -- C:\Users\CrieS\AppData\Roaming\Pirrit
[2014.02.13 21:01:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pirrit
[2014.02.12 07:12:50 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\%LocalAppData%
[2014.02.12 06:49:54 | 000,000,000 | -HSD | C] -- C:\found.004
[2013.08.11 14:54:09 | 000,051,992 | ---- | C] (cake bake) -- C:\Program Files (x86)\WBDesktop.Updater.exe
[2012.10.31 10:54:33 | 001,165,616 | ---- | C] (AMD Inc.) -- C:\Program Files\catalyst_mobility_64-bit_util.exe
[2 C:\Users\CrieS\Desktop\*.tmp files -> C:\Users\CrieS\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 7 Days ==========
[2014.02.16 13:54:05 | 000,000,950 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.02.16 13:52:34 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2014.02.16 13:39:05 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.02.16 13:39:05 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.02.16 13:37:16 | 000,229,000 | ---- | M] () -- C:\Users\CrieS\Desktop\orig.jpg
[2014.02.16 12:21:02 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014.02.16 12:21:02 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014.02.16 11:57:55 | 000,158,897 | ---- | M] () -- C:\Users\CrieS\Desktop\Bez názvu1.png
[2014.02.16 11:57:34 | 000,207,774 | ---- | M] () -- C:\Users\CrieS\Desktop\Bez názvu.jpg
[2014.02.16 11:40:10 | 000,187,461 | ---- | M] () -- C:\Users\CrieS\Desktop\obr1.jpg
[2014.02.16 11:29:13 | 000,000,946 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.02.16 11:28:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.02.16 11:28:50 | 2801,197,056 | -HS- | M] () -- C:\hiberfil.sys
[2014.02.16 11:06:29 | 000,286,225 | ---- | M] () -- C:\Users\CrieS\Desktop\Bez názvu.png
[2014.02.16 10:36:39 | 000,294,044 | ---- | M] () -- C:\Users\CrieS\Desktop\obr.jpg
[2014.02.16 10:08:38 | 000,015,327 | ---- | M] () -- C:\Users\CrieS\Desktop\LM.bat
[2014.02.16 10:03:33 | 002,152,960 | ---- | M] (Farbar) -- C:\Users\CrieS\Desktop\FRST64.exe
[2014.02.16 10:03:10 | 000,001,129 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2014.02.16 00:30:26 | 000,002,255 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014.02.15 22:27:24 | 549,550,661 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2014.02.15 22:07:28 | 000,000,219 | ---- | M] () -- C:\Users\CrieS\Desktop\Dota 2.url
[2014.02.13 14:02:14 | 001,759,824 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014.02.13 14:02:14 | 000,731,756 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2014.02.13 14:02:14 | 000,717,460 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014.02.13 14:02:14 | 000,164,510 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2014.02.13 14:02:14 | 000,145,482 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2 C:\Users\CrieS\Desktop\*.tmp files -> C:\Users\CrieS\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.02.16 13:52:34 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2014.02.16 13:37:16 | 000,229,000 | ---- | C] () -- C:\Users\CrieS\Desktop\orig.jpg
[2014.02.16 11:57:55 | 000,158,897 | ---- | C] () -- C:\Users\CrieS\Desktop\Bez názvu1.png
[2014.02.16 11:56:49 | 000,207,774 | ---- | C] () -- C:\Users\CrieS\Desktop\Bez názvu.jpg
[2014.02.16 11:40:10 | 000,187,461 | ---- | C] () -- C:\Users\CrieS\Desktop\obr1.jpg
[2014.02.16 11:06:20 | 000,286,225 | ---- | C] () -- C:\Users\CrieS\Desktop\Bez názvu.png
[2014.02.16 10:36:39 | 000,294,044 | ---- | C] () -- C:\Users\CrieS\Desktop\obr.jpg
[2014.02.16 10:08:38 | 000,015,327 | ---- | C] () -- C:\Users\CrieS\Desktop\LM.bat
[2014.02.16 10:03:12 | 000,001,129 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2014.02.16 10:03:12 | 000,001,129 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2014.02.16 00:30:26 | 000,002,255 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014.02.15 22:07:28 | 000,000,219 | ---- | C] () -- C:\Users\CrieS\Desktop\Dota 2.url
[2014.01.23 01:30:34 | 000,000,132 | ---- | C] () -- C:\Users\CrieS\AppData\Roaming\Adobe Formát GIF CS5 – předvolby
[2013.11.28 20:13:39 | 000,000,600 | ---- | C] () -- C:\Users\CrieS\AppData\Roaming\winscp.rnd
[2013.11.26 14:12:12 | 000,001,480 | ---- | C] () -- C:\Users\CrieS\AppData\Local\Adobe Uložit pro web 12.0 Prefs
[2013.09.25 14:50:49 | 000,000,132 | ---- | C] () -- C:\Users\CrieS\AppData\Roaming\Adobe Formát BMP CS5 – předvolby
[2013.08.13 13:53:50 | 000,003,004 | ---- | C] () -- C:\Program Files (x86)\WebCakeLayers.crx
[2013.02.15 22:21:07 | 000,000,750 | ---- | C] () -- C:\Windows\MyHeritage.INI
[2013.02.15 22:19:57 | 000,454,656 | ---- | C] () -- C:\Windows\SysWow64\PaintX.dll
[2013.02.06 10:13:24 | 000,000,180 | ---- | C] () -- C:\Users\CrieS\.packettracer
[2012.11.26 20:16:07 | 000,000,132 | ---- | C] () -- C:\Users\CrieS\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
[2012.11.01 20:09:10 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.10.31 20:35:52 | 001,739,046 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012.09.28 02:29:54 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.09.28 02:29:54 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.05.02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 06:30:56 | 014,165,504 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 05:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.09.22 10:13:31 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\AVG2014
[2013.07.25 18:53:57 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Babylon
[2013.03.31 18:18:43 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012.10.31 20:26:51 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\DAEMON Tools Lite
[2012.12.04 13:04:21 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\ESET
[2013.02.13 10:13:32 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\fizzy
[2013.09.28 17:00:56 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Kalypso Media
[2013.05.14 19:33:06 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Mount&Blade Warband
[2013.02.15 22:25:54 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\MyHeritage
[2014.02.16 10:03:20 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Opera Software
[2014.02.13 21:01:59 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Pirrit
[2012.11.01 16:04:17 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Synaptics
[2014.02.14 06:54:57 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\systweak
[2013.02.15 22:19:57 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\The Complete Genealogy Reporter - FTB
[2013.10.12 09:58:48 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\The Creative Assembly
[2014.01.14 22:08:03 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\TS3Client
[2013.09.22 10:12:25 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\TuneUp Software
[2013.09.26 18:39:08 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Unitech LLC
[2013.10.01 11:26:39 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Unity
[2012.12.03 14:54:03 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\WildTangent
[2013.09.27 10:13:29 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013.09.27 10:13:29 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2014.02.12 07:02:23 | 000,000,000 | ---D | M] -- C:\Users\TEMP\AppData\Roaming\AVG2014
[2013.09.27 10:13:29 | 000,000,000 | ---D | M] -- C:\Users\TEMP\AppData\Roaming\TuneUp Software
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009.07.14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 06:08:49 | 000,032,546 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012.10.31 17:05:39 | 000,000,946 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012.10.31 17:05:40 | 000,000,950 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
< >
< MD5 for: ATAPI.SYS >
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009.07.14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010.11.20 14:24:26 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\SysWOW64\autochk.exe
[2009.07.14 02:14:12 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=41E4C8EBA464E7D6A5BA5E8827732AEB -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_e1ca436d2314b860\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\SysNative\autochk.exe
[2009.07.14 02:38:56 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=8B7F8E882A649D81CEA1EDE9BBB68FFF -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7600.16385_none_3de8def0db722996\autochk.exe
[2010.11.20 13:16:54 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\drivers\cdrom.sys
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_8363d00ecae4322d\cdrom.sys
[2009.07.14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys
[2010.11.20 10:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2011.02.26 07:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\explorer.exe
[2011.02.26 07:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009.07.14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011.02.26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009.10.31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\SysWOW64\explorer.exe
[2011.02.26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011.02.25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009.08.03 07:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009.10.31 07:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009.08.03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010.11.20 14:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009.10.31 07:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009.08.03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009.07.14 02:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009.10.31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011.02.26 07:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009.08.03 07:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
< MD5 for: HAL.DLL >
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\SysNative\hal.dll
[2009.07.14 02:47:48 | 000,263,232 | ---- | M] (Microsoft Corporation) MD5=C0A6F6E05E14FBCAEDE7796C8590B7AC -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7600.16385_none_071de44b735b3dfc\hal.dll
[2010.11.20 14:33:34 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: SCECLI.DLL >
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\SysWOW64\scecli.dll
[2009.07.14 02:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\SysNative\scecli.dll
[2009.07.14 02:41:53 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2010.11.20 13:21:04 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 14:27:25 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SERVICES.EXE >
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009.07.14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SVCHOST.EXE >
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2010.11.20 14:33:57 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2013.01.04 06:41:01 | 001,893,224 | ---- | M] (Microsoft Corporation) MD5=5CFB7AB8F9524D1A1E14369DE63B83CC -- C:\Windows\SysNative\drivers\tcpip.sys
[2013.01.04 06:41:01 | 001,893,224 | ---- | M] (Microsoft Corporation) MD5=5CFB7AB8F9524D1A1E14369DE63B83CC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.17206_none_0f6a6af57fd59de6\tcpip.sys
[2012.03.30 11:19:17 | 001,877,872 | ---- | M] (Microsoft Corporation) MD5=5EFD096DEF47F8B88EF591DA92143440 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21178_none_0faa5514992a39a7\tcpip.sys
[2012.03.30 12:09:53 | 001,895,280 | ---- | M] (Microsoft Corporation) MD5=624C5B3AA4C99B3184BB922D9ECE3FF0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16986_none_0f140fa780164fde\tcpip.sys
[2013.01.03 06:57:12 | 001,876,824 | ---- | M] (Microsoft Corporation) MD5=692969AB90BDA19F56E27BF89A9260E2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.21415_none_0fe8397098fc3d71\tcpip.sys
[2012.03.30 11:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
[2009.07.14 02:45:55 | 001,898,576 | ---- | M] (Microsoft Corporation) MD5=912107716BAB424C7870E8E6AF5E07E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7600.16385_none_0f1303f98017479d\tcpip.sys
[2012.03.30 12:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
[2013.01.03 07:00:54 | 001,913,192 | ---- | M] (Microsoft Corporation) MD5=B62A953F2BF3922C8764A29C34A22899 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18042_none_112187237d20143a\tcpip.sys
[2013.01.04 06:47:43 | 001,901,416 | ---- | M] (Microsoft Corporation) MD5=B8C1AAC0523E1C33AEB0EF7572144BA2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22209_none_11dd678a9616f2c8\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010.11.20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009.07.14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009.07.14 02:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010.11.20 14:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010.11.20 14:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009.07.14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009.10.28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009.10.28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< >
< %systemroot%*.* /U /s >
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[5 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[8 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[1 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[133 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
[1 C:\Windows\Temp\avg_a01288\ProgData\*.tmp files -> C:\Windows\Temp\avg_a01288\ProgData\*.tmp -> ]
[1 C:\Windows\Temp\avg_a01288\ProgFiles\AVG Secure Search\*.tmp files -> C:\Windows\Temp\avg_a01288\ProgFiles\AVG Secure Search\*.tmp -> ]
[1 C:\Windows\Temp\avg_a02672\ProgData\*.tmp files -> C:\Windows\Temp\avg_a02672\ProgData\*.tmp -> ]
[1 C:\Windows\Temp\avg_a02672\ProgFiles\AVG Secure Search\*.tmp files -> C:\Windows\Temp\avg_a02672\ProgFiles\AVG Secure Search\*.tmp -> ]
[1 C:\Windows\Temp\avg_a03796\ProgData\*.tmp files -> C:\Windows\Temp\avg_a03796\ProgData\*.tmp -> ]
[1 C:\Windows\Temp\avg_a03796\ProgFiles\AVG Secure Search\*.tmp files -> C:\Windows\Temp\avg_a03796\ProgFiles\AVG Secure Search\*.tmp -> ]
[1 C:\Windows\Temp\avg_a04336\ProgData\*.tmp files -> C:\Windows\Temp\avg_a04336\ProgData\*.tmp -> ]
[1 C:\Windows\Temp\avg_a04336\ProgFiles\AVG Secure Search\*.tmp files -> C:\Windows\Temp\avg_a04336\ProgFiles\AVG Secure Search\*.tmp -> ]
[1 C:\Windows\Temp\avg_a04932\ProgData\*.tmp files -> C:\Windows\Temp\avg_a04932\ProgData\*.tmp -> ]
[1 C:\Windows\Temp\avg_a04932\ProgFiles\AVG Secure Search\*.tmp files -> C:\Windows\Temp\avg_a04932\ProgFiles\AVG Secure Search\*.tmp -> ]
[1 C:\Windows\Temp\avg_a05476\ProgData\*.tmp files -> C:\Windows\Temp\avg_a05476\ProgData\*.tmp -> ]
[1 C:\Windows\Temp\avg_a05476\ProgFiles\AVG Secure Search\*.tmp files -> C:\Windows\Temp\avg_a05476\ProgFiles\AVG Secure Search\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2012.12.31 20:19:31 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Adobe
[2012.11.01 20:14:34 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\ATI
[2013.09.22 10:13:31 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\AVG2014
[2013.07.25 18:53:57 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Babylon
[2013.03.31 18:18:43 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013.02.12 14:48:23 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Corel
[2012.10.31 20:26:51 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\DAEMON Tools Lite
[2012.12.04 13:04:21 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\ESET
[2013.02.13 10:13:32 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\fizzy
[2012.11.02 13:10:47 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Hewlett-Packard
[2012.11.02 13:10:46 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\hpqLog
[2012.10.31 10:18:02 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Identities
[2012.10.31 15:59:39 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\InstallShield
[2013.09.28 17:00:56 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Kalypso Media
[2012.11.06 14:32:42 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Macromedia
[2009.07.14 16:36:38 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Media Center Programs
[2014.01.21 20:48:41 | 000,000,000 | --SD | M] -- C:\Users\CrieS\AppData\Roaming\Microsoft
[2013.05.14 19:33:06 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Mount&Blade Warband
[2013.07.25 18:52:45 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Mozilla
[2013.02.15 22:25:54 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\MyHeritage
[2013.01.28 16:37:40 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Nero
[2014.02.16 10:03:20 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Opera Software
[2014.02.13 21:01:59 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Pirrit
[2013.09.04 20:08:20 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\PSpad
[2014.02.16 14:42:08 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Skype
[2012.11.01 16:04:17 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Synaptics
[2014.02.14 06:54:57 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\systweak
[2013.02.15 22:19:57 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\The Complete Genealogy Reporter - FTB
[2013.10.12 09:58:48 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\The Creative Assembly
[2014.02.14 06:53:14 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\TorTemp
[2014.01.14 22:08:03 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\TS3Client
[2013.09.22 10:12:25 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\TuneUp Software
[2013.09.26 18:39:08 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Unitech LLC
[2013.10.01 11:26:39 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\Unity
[2014.02.15 03:31:35 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\vlc
[2012.12.03 14:54:03 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\WildTangent
[2012.11.01 16:33:14 | 000,000,000 | ---D | M] -- C:\Users\CrieS\AppData\Roaming\WinRAR
< %APPDATA%\*.exe /s >
[2012.11.02 13:10:47 | 000,794,112 | ---- | M] (Hewlett-Packard Company) -- C:\Users\CrieS\AppData\Roaming\Hewlett-Packard\hpqwmiex.exe
[2013.03.31 18:16:57 | 000,054,776 | ---- | M] (Adobe Systems Inc.) -- C:\Users\CrieS\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2013.09.30 21:21:39 | 000,004,286 | R--- | M] () -- C:\Users\CrieS\AppData\Roaming\Microsoft\Installer\{BDE637EA-7109-456A-BAE9-A37ABF526584}\_6FEFF9B68218417F98F549.exe
[2013.09.30 21:21:39 | 000,004,286 | R--- | M] () -- C:\Users\CrieS\AppData\Roaming\Microsoft\Installer\{BDE637EA-7109-456A-BAE9-A37ABF526584}\_7A5D72FB06F00C1AAC73EC.exe
[2013.09.30 21:21:39 | 000,004,286 | R--- | M] () -- C:\Users\CrieS\AppData\Roaming\Microsoft\Installer\{BDE637EA-7109-456A-BAE9-A37ABF526584}\_907B688FD32B11E51C14A9.exe
[2011.12.21 17:38:42 | 000,113,680 | ---- | M] () -- C:\Users\CrieS\AppData\Roaming\MyHeritage\Bin\Convert\Convertor.exe
[2011.12.21 17:38:44 | 000,113,680 | ---- | M] () -- C:\Users\CrieS\AppData\Roaming\MyHeritage\Bin\Convert\ConvertorFDB.exe
[2011.12.21 17:38:46 | 000,047,104 | ---- | M] () -- C:\Users\CrieS\AppData\Roaming\MyHeritage\Bin\Convert\depcheck.exe
[2011.12.21 17:01:20 | 000,110,592 | ---- | M] () -- C:\Users\CrieS\AppData\Roaming\MyHeritage\Bin\Convert\gbtest.exe
[2011.12.21 17:01:34 | 000,058,896 | ---- | M] () -- C:\Users\CrieS\AppData\Roaming\MyHeritage\Bin\Detect\Detect.exe
[2014.02.14 06:51:59 | 009,166,177 | ---- | M] ( ) -- C:\Users\CrieS\AppData\Roaming\TorTemp\_\install-torload.exe
[2013.09.26 20:25:05 | 004,012,152 | ---- | M] (WildTangent, Inc.) -- C:\Users\CrieS\AppData\Roaming\WildTangent\Updater\GameConsole\GameConsole-4.0.30.26.exe
[2012.11.29 02:52:04 | 000,049,824 | ---- | M] (WildTangent) -- C:\Users\CrieS\AppData\Roaming\WildTangent\Updater\GameConsole\Park-{eecd7878-6094-4c62-9ed9-25ef716b0dda}.exe
[2012.12.03 14:54:25 | 000,213,560 | ---- | M] (WildTangent, Inc.) -- C:\Users\CrieS\AppData\Roaming\WildTangent\WildTangent Games\App\Downloads\bridgeconstructor\Download\brandinfo_wildgames_1.0.0.354.exe
[2012.12.03 14:54:23 | 000,466,688 | ---- | M] (WildTangent, Inc.) -- C:\Users\CrieS\AppData\Roaming\WildTangent\WildTangent Games\App\Downloads\bridgeconstructor\Download\catalyst_1.0.0.442.exe
[2012.12.03 14:54:24 | 000,083,304 | ---- | M] (WildTangent, Inc.) -- C:\Users\CrieS\AppData\Roaming\WildTangent\WildTangent Games\App\Downloads\bridgeconstructor\Download\pkgtype_1.0.0.65.exe
[2012.12.03 14:54:26 | 000,231,912 | ---- | M] (WildTangent, Inc.) -- C:\Users\CrieS\AppData\Roaming\WildTangent\WildTangent Games\App\Downloads\bridgeconstructor\Download\prodinfo_bridgeconstructor_1.0.1.3004.exe
[2012.05.22 02:34:34 | 000,571,040 | ---- | M] (WildTangent, Inc.) -- C:\Users\CrieS\AppData\Roaming\WildTangent\WildTangent Games\App\Update\Updater.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job >
[2014.02.16 11:29:13 | 000,000,946 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2014.02.16 13:54:05 | 000,000,950 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2014.02.16 12:21:02 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\system32\FlashPlayerApp.exe
[2014.02.16 12:21:02 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\system32\FlashPlayerCPLApp.cpl
< %SYSTEMDRIVE%\*.exe >
[2007.11.07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"DAEMON Tools Lite" = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun -- [2012.04.17 16:19:40 | 003,671,872 | ---- | M] (DT Soft Ltd)
"FixMyRegistry" = C:\Program Files (x86)\SmartTweak Software\FixMyRegistry\FixMyRegistry.exe /ot /as -- [2012.10.19 19:41:12 | 001,795,768 | ---- | M] ()
"Steam" = "C:\Program Files (x86)\Steam\steam.exe" -silent -- [2014.02.11 06:45:53 | 001,824,000 | ---- | M] (Valve Corporation)
"Skype" = "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun -- [2013.02.28 17:50:02 | 018,642,024 | R--- | M] (Skype Technologies S.A.)
"RGSC" = C:\Hry\GTA IV PC Version\Rockstar Games Social Club\RGSCLauncher.exe /silent -- [2008.11.14 14:35:36 | 000,305,064 | R--- | M] (Take-Two Interactive Software, Inc.)
"" =
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2013.02.22 05:10:00 | 000,757,376 | ---- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2014.02.02 00:42:39 | 000,866,632 | ---- | M] (Google Inc.) MD5=5640B4C10682FBC39C86C8C7A8392B5E -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2014.02.16 13:52:34 | 000,000,512 | ---- | M] () MD5=292CBFADA444CFF8F78D75FB00D3EB6F -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2012.10.12 07:38:55 | 057,217,859 | ---- | M] () -- \Hry\GTA IV PATCH 1.0.3.0 + CRACK\GTA IV 1.0.3.0 Crack + Patch.rar
[2003.12.05 13:52:40 | 000,000,796 | ---- | M] () -- \Hry\GTA San Andreas\data\Decision\Craig\crack1.ped
[2009.01.19 13:27:44 | 000,083,645 | ---- | M] () -- \Hry\M&B Warband – kopie\Mount&Blade Warband\Sounds\Fire_Small_Crackle_Slick_op.ogg
[2010.05.05 19:15:06 | 000,699,192 | ---- | M] () -- \Hry\M&B Warband\Mount&Blade Warband\Modules\1860s Old America v. 0.99g\Textures\cracked_ground_a.dds
[2010.05.05 19:15:06 | 000,699,192 | ---- | M] () -- \Hry\M&B Warband\Mount&Blade Warband\Modules\1860s Old America v. 0.99g\Textures\cracked_ground_a_high.dds
[2013.04.09 17:55:20 | 002,034,060 | ---- | M] () -- \Hry\M&B Warband\Mount&Blade Warband\Modules\totsk\Sounds\Fire_Small_Crackle_Slick_op.wav
[2009.01.19 13:27:44 | 000,083,645 | ---- | M] () -- \Hry\M&B Warband\Mount&Blade Warband\Sounds\Fire_Small_Crackle_Slick_op.ogg
[2008.07.03 16:52:32 | 000,000,553 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS20\PATH\crack1.pth
[2008.07.03 16:52:32 | 000,000,664 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS20\PATH\crack2.pth
[2008.07.03 16:52:32 | 000,000,671 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS20\PATH\crack31.pth
[2008.07.03 16:52:32 | 000,000,444 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS20\PATH\crack32.pth
[2008.08.05 23:35:44 | 000,011,714 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS20\Scripts\crack.cfg
[2008.09.10 18:38:44 | 000,005,107 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS20\Scripts\sl_crack.cfg
[2008.06.28 12:48:10 | 000,000,553 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS91\PATH\crack1.pth
[2008.06.28 12:48:10 | 000,000,664 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS91\PATH\crack2.pth
[2008.06.28 12:48:10 | 000,000,671 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS91\PATH\crack31.pth
[2008.06.28 12:48:10 | 000,000,444 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS91\PATH\crack32.pth
[2008.11.16 00:31:46 | 000,011,889 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS91\Scripts\crack.cfg
[2008.11.11 21:19:10 | 000,005,930 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Areas\BIOS91\Scripts\sl_crack.cfg
[2008.11.02 15:30:18 | 000,019,998 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Models\Characters\Things\IceParts\ice_crack.CMF
[2008.09.22 19:56:06 | 000,001,467 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Scripts\emitters\emgfx\Presets\Sparks\red_crack_sparks.cfg
[2008.11.02 15:30:18 | 000,001,916 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Scripts\environments\Things\ice_crack.phys
[2008.09.10 18:38:40 | 000,385,688 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Tracks\Characters\Actors\_Hero\Hero_sledge_crack_fall.CHA
[2007.03.05 17:34:24 | 000,641,764 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Tracks\Characters\Actors\Muffled_half\Muffled_cracking_the_door.CHA
[2007.08.20 17:06:02 | 000,004,380 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Tracks\Characters\Devices\Sledge\crack_fall.CHA
[2008.06.28 16:20:32 | 000,006,760 | ---- | M] () -- \Program Files (x86)\505games\1C\Cryostasis\Data\Tracks\Characters\Devices\Sledge\crack_fall_all.CHA
[2002.12.18 17:10:46 | 000,092,827 | ---- | M] () -- \Program Files (x86)\Corel\Corel Graphics 12\Custom Data\Bumpmap\Cracks.cpt
[2002.12.16 18:44:50 | 000,016,068 | ---- | M] () -- \Program Files (x86)\Corel\Corel Graphics 12\Custom Data\Canvas\cracks2c.pcx
[2002.12.16 18:44:30 | 000,010,560 | ---- | M] () -- \Program Files (x86)\Corel\Corel Graphics 12\Custom Data\Tiles\CRACKS2M.CPT
[2014.02.15 22:11:03 | 000,015,770 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota\addons\nian\resource\flash3\images\items\firecrackers.png
[2014.02.06 16:13:11 | 000,000,748 | ---- | M] () -- \Users\CrieS\AppData\Roaming\Microsoft\Windows\Recent\Rome-total-war-2-CRACK-by-LukaSsQo.lnk
[2014.02.06 12:56:07 | 000,000,778 | ---- | M] () -- \Users\CrieS\AppData\Roaming\Microsoft\Windows\Recent\Total-War-Rome-2-(2013)-CZ-+-CRACK.part1.lnk
[2014.02.06 16:09:09 | 000,000,778 | ---- | M] () -- \Users\CrieS\AppData\Roaming\Microsoft\Windows\Recent\Total-War-Rome-2-(2013)-CZ-+-CRACK.part2.lnk
[2014.02.06 16:09:05 | 000,000,778 | ---- | M] () -- \Users\CrieS\AppData\Roaming\Microsoft\Windows\Recent\Total-War-Rome-2-(2013)-CZ-+-CRACK.part3.lnk
[2014.02.06 16:08:59 | 000,000,778 | ---- | M] () -- \Users\CrieS\AppData\Roaming\Microsoft\Windows\Recent\Total-War-Rome-2-(2013)-CZ-+-CRACK.part5.lnk
[2014.02.06 16:08:49 | 000,000,778 | ---- | M] () -- \Users\CrieS\AppData\Roaming\Microsoft\Windows\Recent\Total-War-Rome-2-(2013)-CZ-+-CRACK.part6.lnk
[2011.04.14 15:37:40 | 009,250,287 | ---- | M] () -- \Users\CrieS\Desktop\Hry\New folder (2)\SWORDS_AND_SANDALS_2_ALREADY_CRACKED_(FULL).zip
[2012.11.05 19:00:33 | 1992,294,400 | ---- | M] () -- \Users\CrieS\Downloads\Avatar-PC-(pc-hra+crack+patch).part1 (1).rar
[2012.11.06 19:51:26 | 1892,278,595 | ---- | M] () -- \Users\CrieS\Downloads\Avatar-PC-(pc-hra+crack+patch).part2 (1).rar
[2012.11.06 01:05:19 | 1892,278,595 | ---- | M] () -- \Users\CrieS\Downloads\Avatar-PC-(pc-hra+crack+patch).part2.rar
[2013.05.02 20:57:48 | 678,444,987 | ---- | M] () -- \Users\CrieS\Downloads\Mount-and-blade-Warband-(hra+patch+crack).rar
[2013.09.28 16:32:46 | 1100,000,000 | ---- | M] () -- \Users\CrieS\Downloads\Port-royale-3+crack,cestina,patch.part1 (1).rar
[2013.09.27 01:01:15 | 1100,000,000 | ---- | M] () -- \Users\CrieS\Downloads\Port-royale-3+crack,cestina,patch.part2.rar
[2013.09.28 13:19:25 | 1100,000,000 | ---- | M] () -- \Users\CrieS\Downloads\Port-royale-3+crack,cestina,patch.part3.rar
[2013.09.28 14:59:11 | 967,025,965 | ---- | M] () -- \Users\CrieS\Downloads\Port-royale-3+crack,cestina,patch.part4.rar
[2014.02.06 16:13:09 | 001,068,281 | ---- | M] () -- \Users\CrieS\Downloads\Rome-total-war-2-CRACK-by-LukaSsQo.rar
[2013.10.10 20:55:18 | 1610,612,736 | ---- | M] () -- \Users\CrieS\Downloads\Total-War-Rome-2-(2013)-CZ-+-CRACK.part1.rar
[2013.10.11 00:05:04 | 1610,612,736 | ---- | M] () -- \Users\CrieS\Downloads\Total-War-Rome-2-(2013)-CZ-+-CRACK.part2.rar
[2013.10.11 11:16:14 | 1610,612,736 | ---- | M] () -- \Users\CrieS\Downloads\Total-War-Rome-2-(2013)-CZ-+-CRACK.part3.rar
[2013.10.11 17:28:58 | 1610,612,736 | ---- | M] () -- \Users\CrieS\Downloads\Total-War-Rome-2-(2013)-CZ-+-CRACK.part4.rar
[2013.10.11 17:27:13 | 1610,612,736 | ---- | M] () -- \Users\CrieS\Downloads\Total-War-Rome-2-(2013)-CZ-+-CRACK.part5.rar
[2013.10.11 17:31:45 | 035,295,472 | ---- | M] () -- \Users\CrieS\Downloads\Total-War-Rome-2-(2013)-CZ-+-CRACK.part6.rar
< *keygen* /s >
[2011.10.07 16:10:26 | 000,098,304 | ---- | M] () -- \Hry\Call of Duty 4 - Modern Warfare\Keygen-COD4.exe
[2012.05.12 19:34:09 | 000,313,344 | ---- | M] () -- \Users\CrieS\Desktop\Programy\Adobe Photoshop CS5 CZ\Adobe Photoshop CS5 CZ - KEYGEN.exe
[2012.05.12 19:34:09 | 000,313,344 | ---- | M] () -- \Users\CrieS\Desktop\Programy\Adobe Photoshop CS5 CZ\Crack\Adobe Photoshop CS5 CZ - KEYGEN.exe
[2012.05.12 19:53:24 | 000,003,121 | ---- | M] () -- \Users\CrieS\Desktop\Programy\Adobe Photoshop CS5 CZ\Crack\KeyGen-Readme.txt
< *loader* /s >
[2010.11.03 18:52:14 | 000,003,153 | ---- | M] () -- \Hry\GTA San Andreas\mods\deathmatch\resources\race_model_reloader\modelreloader_client.lua
[2012.06.28 16:12:36 | 000,000,941 | ---- | M] () -- \Hry\Killing Floor\Killing Floor\KF_revLoader – zástupce.lnk
[2009.05.01 22:49:58 | 000,034,304 | ---- | M] () -- \Hry\Killing Floor\Killing Floor\KF_revLoader.exe
[2010.03.09 04:28:40 | 005,297,608 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\Photodownloader.exe
[2010.03.09 01:38:58 | 000,011,161 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\bitmaps\main_window\C_LoadError.png
[2010.03.09 01:38:58 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\da_dk\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\de_de\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\en_us\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\es_es\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\fi_fi\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\fr_fr\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\it_it\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\ja_jp\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\ko_kr\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\nl_nl\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\no_no\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\pt_br\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\sv_se\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,308 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\zh_cn\Photodownloader.ini
[2010.03.09 01:39:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS5\apd\shared_assets\locales\zh_tw\Photodownloader.ini
[2007.11.13 03:54:34 | 000,070,944 | ---- | M] () -- \Program Files (x86)\AGEIA Technologies\demos\physxloader.dll
[2014.01.09 08:24:09 | 000,004,178 | ---- | M] () -- \Program Files (x86)\AVG Secure Search\Chrome\content\icons\loader.gif
[2014.01.09 08:24:09 | 000,019,497 | ---- | M] () -- \Program Files (x86)\AVG Secure Search\UninstallRes\ClientPackage\Images\uninstall\loader.gif
[2006.10.26 13:40:34 | 000,057,344 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7Debug\coloader.dll
[2006.10.26 13:40:34 | 000,005,120 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7Debug\coloader.tlb
[2010.03.18 23:21:56 | 000,063,312 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7Debug\coloader80.dll
[2010.03.18 00:17:14 | 000,004,096 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VS7Debug\coloader80.tlb
[2012.12.06 23:38:40 | 000,268,344 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2012.12.06 23:38:40 | 000,019,000 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2011.12.30 04:33:17 | 002,475,304 | ---- | M] () -- \Program Files (x86)\CyberLink\PhotoDirector\Kernel\CES\CES_3DLoaderFBX.dll
[2012.02.06 07:37:36 | 000,124,200 | ---- | M] () -- \Program Files (x86)\CyberLink\PhotoDirector\Koan\pyloader.dll
[2011.12.30 04:33:33 | 000,006,629 | ---- | M] () -- \Program Files (x86)\CyberLink\PhotoDirector\Presentation\UI\Import\ThumbnailLoader.kc
[2011.12.30 04:33:37 | 000,012,172 | ---- | M] () -- \Program Files (x86)\CyberLink\PhotoDirector\System\PyUploader.kc
[2011.12.30 04:33:37 | 000,188,136 | ---- | M] () -- \Program Files (x86)\CyberLink\PhotoDirector\System\_PyUploader.pyd
[2011.12.30 04:33:37 | 000,007,658 | ---- | M] () -- \Program Files (x86)\CyberLink\PhotoDirector\System\Model\SlideShowProduction\ProfileLoader.kc
[2009.07.22 09:17:52 | 000,019,992 | ---- | M] () -- \Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SqlResourceLoader.dll
[2010.03.18 23:21:56 | 000,063,312 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\coloader80.dll
[2010.03.18 01:57:18 | 000,001,373 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\coloader80.dll.manifest
[2010.03.18 00:17:14 | 000,004,096 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\coloader80.tlb
[2009.08.31 04:51:22 | 000,001,648 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 10.0\VC\atlmfc\include\afxribboninfoloader.h
[2009.08.31 04:51:22 | 000,004,525 | ---- | M] () -- \Program Files (x86)\Microsoft Visual Studio 10.0\VC\atlmfc\src\mfc\afxribboninfoloader.cpp
[2013.10.23 21:07:40 | 000,007,825 | ---- | M] () -- \Program Files (x86)\Steam\remoteui\static\libs\images\ajax-loader.gif
[2014.01.09 22:41:42 | 000,169,384 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Half-Life\cstrike\models\qloader.mdl
[2014.01.09 21:51:43 | 000,352,548 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Half-Life\valve\models\loader.mdl
[2014.01.09 22:04:25 | 000,012,764 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Half-Life\valve\sound\ambience\loader_hydra1.wav
[2014.01.09 22:04:07 | 000,012,164 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Half-Life\valve\sound\ambience\loader_step1.wav
[2012.05.21 22:56:04 | 000,002,196 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\GamePlay_Loader.html
[2012.07.19 00:18:28 | 000,000,598 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\EULA\images\downloader_bg_400.gif
[2013.06.13 23:04:54 | 000,009,106 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\Scripts\gameplay_loader.js
[2013.06.13 23:04:54 | 000,002,355 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\Skins\default\gameplay_loader.css
[2012.12.06 23:38:40 | 000,364,088 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll
[2012.12.06 23:38:40 | 000,019,000 | ---- | M] () -- \Program Files\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2009.07.22 09:17:50 | 000,027,672 | ---- | M] () -- \Program Files\Microsoft SQL Server\100\Tools\Binn\SqlResourceLoader.dll
[2009.07.22 09:17:50 | 000,027,672 | ---- | M] () -- \Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SqlResourceLoader.dll
[2012.06.09 19:19:38 | 000,055,296 | ---- | M] () -- \Program Files\WinRAR\Formats\ace32loader.exe
[2012.07.26 22:47:04 | 000,000,232 | ---- | M] () -- \ProgramData\Nero\Nero 10\OnlineServices\NOSWebConfig\MySpace\uploadError.xml
[2012.12.04 17:00:50 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.12.04 17:00:50 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2012.12.04 17:00:50 | 000,009,772 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\retina\
loader@2x.png
[2012.10.01 12:36:00 | 000,387,800 | ---- | M] () -- \ProgramData\TERA\launcher\live\downloader.bundle
[2012.07.09 23:11:00 | 000,693,704 | ---- | M] () -- \ProgramData\TERA\launcher\live\downloader.dll
[2014.02.11 06:03:29 | 000,001,206 | ---- | M] () -- \System Volume Information\SystemRestore\FRStaging\Windows\Tasks\FreeHDSport TV-codedownloader.job
[2012.07.26 22:47:04 | 000,000,232 | ---- | M] () -- \Users\All Users\Nero\Nero 10\OnlineServices\NOSWebConfig\MySpace\uploadError.xml
[2012.12.04 17:00:50 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2012.12.04 17:00:50 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2012.12.04 17:00:50 | 000,009,772 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\retina\
loader@2x.png
[2012.10.01 12:36:00 | 000,387,800 | ---- | M] () -- \Users\All Users\TERA\launcher\live\downloader.bundle
[2012.07.09 23:11:00 | 000,693,704 | ---- | M] () -- \Users\All Users\TERA\launcher\live\downloader.dll
[2014.02.16 00:30:37 | 000,004,178 | ---- | M] () -- \Users\CrieS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.3.0.49_1\content\icons\loader.gif
[2014.02.15 22:44:36 | 000,111,438 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25LQ1C2N\AdLoader-8123c724cc0668230ba8270eea997632.min[1].js
[2014.02.15 16:46:36 | 000,001,537 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25LQ1C2N\AdLoader[1].htm
[2014.02.15 16:46:36 | 000,111,438 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2YMI8AJO\AdLoader-8123c724cc0668230ba8270eea997632.min[1].js
[2014.02.15 21:13:20 | 000,001,537 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2YMI8AJO\AdLoader[1].htm
[2014.02.16 12:18:07 | 000,000,723 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2YMI8AJO\downloaderror[1].js
[2014.02.16 12:18:07 | 000,001,174 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2YMI8AJO\downloader[1].js
[2014.02.16 00:20:02 | 000,005,615 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2YMI8AJO\pagePlatformLoader[1].js
[2014.02.16 00:20:51 | 000,027,094 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2YMI8AJO\sf_preloader[1].js
[9 \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2YMI8AJO\*.tmp files -> \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2YMI8AJO\*.tmp -> ]
[2014.02.13 20:53:35 | 000,001,537 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CC0GC26C\AdLoader[1].htm
[2014.02.15 22:44:35 | 000,001,537 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T186XZ2V\AdLoader[1].htm
[2014.02.15 21:13:20 | 000,111,438 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YRUOXW62\AdLoader-8123c724cc0668230ba8270eea997632.min[1].js
[2014.01.31 19:19:23 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0CHE1FM8\iframeToasterLoader[1].htm
[2014.01.31 19:50:06 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0CHE1FM8\iframeToasterLoader[2].htm
[2014.01.31 21:06:43 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0CHE1FM8\iframeToasterLoader[3].htm
[2014.02.06 17:13:05 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0CHE1FM8\iframeToasterLoader[4].htm
[2014.02.06 17:13:05 | 000,007,246 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0CHE1FM8\mpvPopUpLoader[1].js
[2014.02.14 15:46:12 | 000,005,615 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0CHE1FM8\pagePlatformLoader[1].js
[2014.01.25 13:59:45 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0XRHWTUU\iframeToasterLoader[1].htm
[2014.01.25 16:21:23 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0XRHWTUU\iframeToasterLoader[2].htm
[2014.01.25 16:34:17 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0XRHWTUU\iframeToasterLoader[3].htm
[2014.02.07 12:48:17 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0XRHWTUU\iframeToasterLoader[4].htm
[2014.01.25 20:16:34 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\iframeToasterLoader[1].htm
[2014.01.26 08:16:39 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\iframeToasterLoader[2].htm
[2014.01.31 17:39:28 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\iframeToasterLoader[3].htm
[2014.01.31 19:39:26 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\iframeToasterLoader[4].htm
[2014.02.14 15:54:27 | 000,005,011 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\iframeToasterLoader[5].htm
[2014.02.14 15:46:47 | 000,007,246 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\mpvPopUpLoader[1].js
[2014.01.31 13:29:40 | 000,017,859 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\mpvToasterLoader[1].js
[2014.02.14 15:46:47 | 000,017,859 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\mpvToasterLoader[2].js
[2014.01.26 14:16:40 | 000,005,615 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\pagePlatformLoader[1].js
[2014.01.31 13:28:36 | 000,005,615 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\pagePlatformLoader[2].js
[2014.01.26 14:51:54 | 000,063,383 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\sf_preloader[1].js
[2014.01.31 13:29:32 | 000,066,162 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\sf_preloader[2].js
[2014.02.04 12:25:18 | 000,070,059 | ---- | M] () -- \Users\CrieS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7BA2BUES\sf_preloader[3].js