OTL logfile created on: 18.11.2014 19:26:31 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Kristinka\Desktop
64bit-Windows Server 2003 Service Pack 2 (Version = 5.2.3790) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000405 | Country: Czech Republic | Language: CSY | Date Format: d.M.yyyy
4,00 Gb Total Physical Memory | 3,02 Gb Available Physical Memory | 75,44% Memory free
7,74 Gb Paging File | 6,90 Gb Available in Paging File | 89,09% Paging File free
Paging file location(s): e:\pagefile.sys 4092 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149,05 Gb Total Space | 119,13 Gb Free Space | 79,93% Space Free | Partition Type: NTFS
Drive D: | 465,75 Gb Total Space | 277,46 Gb Free Space | 59,57% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 128,73 Gb Free Space | 55,28% Space Free | Partition Type: NTFS
Computer Name: VESELI | User Name: Kristinka | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014.11.18 19:25:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kristinka\Desktop\OTL.exe
PRC - [2014.10.29 17:25:52 | 000,182,696 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Java\jre7\bin\jqs.exe
PRC - [2014.10.22 05:05:02 | 000,854,344 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014.06.05 03:19:38 | 000,093,040 | ---- | M] (TomTom) -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2013.09.12 12:06:22 | 001,337,752 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
========== Modules (No Company Name) ==========
MOD - [2014.10.22 05:04:57 | 008,910,664 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll
MOD - [2014.10.22 05:04:48 | 001,681,224 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ffmpegsumo.dll
MOD - [2007.02.18 13:00:00 | 000,061,440 | ---- | M] () -- C:\WINDOWS\SysWOW64\devenum.dll
MOD - [2007.02.18 13:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\SysWOW64\msdmo.dll
========== Services (SafeList) ==========
SRV:
64bit: - [2013.09.12 12:06:22 | 001,337,752 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe -- (ekrn)
SRV - [2014.11.12 19:39:21 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014.10.29 17:25:52 | 000,182,696 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files (x86)\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2014.07.23 07:44:16 | 000,438,616 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Stopped] -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service)
SRV - [2014.06.05 03:19:38 | 000,093,040 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2014.04.03 19:21:48 | 000,315,008 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.05.25 09:32:50 | 000,067,584 | ---- | M] (CobianSoft, Luis Cobian) [Auto | Running] -- C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe -- (cbVSCService11)
SRV - [2010.08.18 01:31:42 | 000,111,616 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\spoolsv.exe -- (Spooler)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2008.07.25 11:17:02 | 000,069,632 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2007.02.18 13:00:00 | 000,077,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc)
SRV - [2006.10.18 19:05:24 | 000,913,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
========== Driver Services (SafeList) ==========
DRV - [2013.11.07 18:46:29 | 000,024,104 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2007.02.18 13:00:00 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\SysWow64\mnmdd.dll -- (mnmdd)
DRV - [2007.02.18 13:00:00 | 000,002,864 | ---- | M] (Microsoft Corporation) [Adapter | On_Demand | Unknown] -- C:\WINDOWS\SysWow64\winsock.dll -- (Winsock)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-902231566-1358511475-2049901558-1002\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\SysWOW64\dvmurl.dll (DeviceVM Inc.)
IE - HKU\S-1-5-21-902231566-1358511475-2049901558-1002\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-902231566-1358511475-2049901558-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-902231566-1358511475-2049901558-1002\..\SearchScopes\{FD63BF63-BFFF-4B8F-9D26-4267DF7F17DD}: "URL" =
http://www.google.com/custom?q={searchT ... BFORID%3A1
IE - HKU\S-1-5-21-902231566-1358511475-2049901558-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.0-git-20131101-0403: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
eplgTb@eset.com: C:\PROGRAM FILES\ESET\ESET SMART SECURITY\MOZILLA THUNDERBIRD [2013.11.03 10:26:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013.11.03 10:26:05 | 000,000,000 | ---D | M]
[2014.08.23 15:46:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kristinka\Application Data\Mozilla\Extensions
[2014.08.23 15:46:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kristinka\Application Data\Mozilla\Extensions\
home2@tomtom.com
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Documents and Settings\Kristinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_1\
CHR - Extension: No name found = C:\Documents and Settings\Kristinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Documents and Settings\Kristinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Documents and Settings\Kristinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Documents and Settings\Kristinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fgkeilefmpmbamgcejhjpiecahcbipip\1.3.4_0\
CHR - Extension: No name found = C:\Documents and Settings\Kristinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\
CHR - Extension: No name found = C:\Documents and Settings\Kristinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pficdecjkdlnacnnbkociacmdbpmhdoc\1.0.0.7_0\
CHR - Extension: No name found = C:\Documents and Settings\Kristinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
Hosts file not found
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3:
64bit: - HKU\S-1-5-21-902231566-1358511475-2049901558-1002\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - %SystemRoot%\system32\browseui.dll File not found
O3 - HKU\S-1-5-21-902231566-1358511475-2049901558-1002\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4:
64bit: - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4:
64bit: - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4:
64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:
64bit: - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-902231566-1358511475-2049901558-1002..\Run: [DuckCapture] C:\Program Files (x86)\DuckLink\DuckCapture\DuckCapture.exe (DuckLink Software)
O4 - HKU\S-1-5-21-902231566-1358511475-2049901558-1002..\Run: [GarminExpressTrayApp] C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe File not found
O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe File not found
O4 - HKU\S-1-5-19..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-902231566-1358511475-2049901558-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - %SystemRoot%\System32\mswsock.dll File not found
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - %SystemRoot%\System32\winrnr.dll File not found
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - %SystemRoot%\System32\mswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - %SystemRoot%\system32\mswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - %SystemRoot%\system32\mswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - %SystemRoot%\system32\mswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - %SystemRoot%\system32\mswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - %SystemRoot%\system32\mswsock.dll File not found
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{16C4CAFF-34EF-43A1-B178-92C97EAAE932}: DhcpNameServer = 192.168.1.1
O18:
64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll File not found
O18:
64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Handler\http\0x00000001 - No CLSID value found
O18:
64bit: - Protocol\Handler\http\oledb - No CLSID value found
O18:
64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Handler\https\0x00000001 - No CLSID value found
O18:
64bit: - Protocol\Handler\https\oledb - No CLSID value found
O18:
64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll File not found
O18:
64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - %SystemRoot%\system32\inetcomm.dll File not found
O18:
64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll File not found
O18:
64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - %SystemRoot%\system32\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll File not found
O18:
64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:
64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18:
64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18:
64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18:
64bit: - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll File not found
O18:
64bit: - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - %SystemRoot%\system32\SHELL32.dll File not found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - File not found
O20:
64bit: - HKLM Winlogon: UIHost - (%SystemRoot%\system32\logonui.exe) - File not found
O20:
64bit: - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: System - (lsass.exe) - File not found
O20 - HKLM Winlogon: UserInit - (userinit) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - File not found
O20:
64bit: - Winlogon\Notify\crypt32chain: DllName - (crypt32.dll) - File not found
O20:
64bit: - Winlogon\Notify\cryptnet: DllName - (cryptnet.dll) - File not found
O20:
64bit: - Winlogon\Notify\cscdll: DllName - (cscdll.dll) - File not found
O20:
64bit: - Winlogon\Notify\dimsntfy: DllName - (dimsntfy.dll) - File not found
O20:
64bit: - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O20:
64bit: - Winlogon\Notify\sclgntfy: DllName - (sclgntfy.dll) - File not found
O20:
64bit: - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - File not found
O20:
64bit: - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - File not found
O20:
64bit: - Winlogon\Notify\termsrv: DllName - (wlnotify.dll) - File not found
O20:
64bit: - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - File not found
O20 - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O20 - Winlogon\Notify\SensLogn: DllName - (WlNotify.dll) - File not found
O20 - Winlogon\Notify\Schedule: DllName - (wlnotify.dll) - File not found
O20 - Winlogon\Notify\wlballoon: DllName - (wlnotify.dll) - File not found
O21:
64bit: - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll File not found
O21:
64bit: - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll File not found
O21:
64bit: - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll File not found
O21:
64bit: - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll File not found
O22:
64bit: - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - %SystemRoot%\system32\browseui.dll File not found
O22:
64bit: - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - %SystemRoot%\system32\browseui.dll File not found
O28:
64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013.11.02 20:51:12 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
Drivers32:
64bit: aux - File not found
Drivers32:
64bit: aux1 - File not found
Drivers32:
64bit: midi - File not found
Drivers32:
64bit: midi1 - File not found
Drivers32:
64bit: midimapper - File not found
Drivers32:
64bit: mixer - File not found
Drivers32:
64bit: mixer1 - File not found
Drivers32:
64bit: msacm.imaadpcm - File not found
Drivers32:
64bit: msacm.msadpcm - File not found
Drivers32:
64bit: msacm.msg711 - File not found
Drivers32:
64bit: msacm.msgsm610 - File not found
Drivers32:
64bit: msacm.trspch - File not found
Drivers32:
64bit: vidc.i420 - File not found
Drivers32:
64bit: vidc.iv31 - File not found
Drivers32:
64bit: vidc.iv32 - File not found
Drivers32:
64bit: vidc.iv41 - File not found
Drivers32:
64bit: vidc.iv50 - File not found
Drivers32:
64bit: vidc.iyuv - File not found
Drivers32:
64bit: vidc.mrle - File not found
Drivers32:
64bit: vidc.msvc - File not found
Drivers32:
64bit: vidc.uyvy - File not found
Drivers32:
64bit: vidc.yuy2 - File not found
Drivers32:
64bit: vidc.yvu9 - File not found
Drivers32:
64bit: vidc.yvyu - File not found
Drivers32:
64bit: wave - File not found
Drivers32:
64bit: wave1 - File not found
Drivers32:
64bit: wavemapper - File not found
Drivers32: msacm.l3acm - C:\WINDOWS\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\SysWow64\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\SysWow64\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\SysWow64\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\SysWow64\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\SysWow64\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\SysWOW64\ir50_32.dll (Intel Corporation)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2014.11.18 19:25:07 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kristinka\Desktop\OTL.exe
[2014.11.16 19:22:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kristinka\My Documents\NeroVision
[2014.11.12 19:39:11 | 004,918,960 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerInstaller.exe
[2014.11.02 12:05:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kristinka\Application Data\Malwarebytes
[2014.11.02 12:04:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2014.10.29 17:26:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014.10.29 17:26:13 | 000,272,808 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaws.exe
[2014.10.29 17:26:05 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaw.exe
[2014.10.29 17:26:05 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\java.exe
[2014.10.29 17:26:05 | 000,098,216 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
[2014.10.29 17:26:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Java
[2014.10.28 19:43:43 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014.10.26 17:41:42 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Kristinka\Recent
[2014.10.26 17:35:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2014.10.26 17:35:07 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014.10.26 17:20:43 | 000,000,000 | ---D | C] -- C:\FRST
[2014.10.26 17:20:16 | 002,113,024 | ---- | C] (Farbar) -- C:\Documents and Settings\Kristinka\Desktop\FRST64.exe
[2014.10.26 17:20:16 | 000,112,640 | ---- | C] (forum.viry.cz) -- C:\Documents and Settings\Kristinka\Desktop\FRSTLauncher.exe
[2014.10.26 17:15:18 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2014.10.26 17:15:18 | 000,000,000 | ---D | C] -- C:\rsit
[2 C:\WINDOWS\SysWow64\*.tmp files -> C:\WINDOWS\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014.11.18 19:27:16 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2014.11.18 19:25:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kristinka\Desktop\OTL.exe
[2014.11.18 19:23:24 | 001,222,144 | ---- | M] () -- C:\Documents and Settings\Kristinka\Desktop\RSITx64.exe
[2014.11.18 19:10:17 | 000,000,406 | ---- | M] () -- C:\WINDOWS\tasks\Opera scheduled Autoupdate 1383476416.job
[2014.11.18 19:09:26 | 000,000,948 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014.11.18 19:09:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014.11.17 20:44:48 | 000,000,952 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014.11.17 20:39:00 | 000,000,914 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014.11.17 13:05:01 | 000,000,664 | ---- | M] () -- C:\WINDOWS\SysWow64\d3d9caps.dat
[2014.11.12 19:39:20 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014.11.12 19:39:20 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014.11.12 19:39:11 | 004,918,960 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerInstaller.exe
[2014.11.06 21:31:35 | 000,008,826 | ---- | M] () -- C:\Documents and Settings\Kristinka\Desktop\Snap 2014-11-06 at 21.31.35.png
[2014.11.06 21:29:50 | 000,008,481 | ---- | M] () -- C:\Documents and Settings\Kristinka\Desktop\Snap 2014-11-06 at 21.29.50.png
[2014.10.31 16:06:08 | 000,002,319 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2014.10.29 17:27:37 | 001,998,336 | ---- | M] () -- C:\Documents and Settings\Kristinka\Desktop\adwcleaner_4.002 (1).exe
[2014.10.29 17:25:53 | 000,098,216 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
[2014.10.29 17:25:51 | 000,272,808 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaws.exe
[2014.10.29 17:25:51 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaw.exe
[2014.10.29 17:25:51 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\java.exe
[2014.10.29 17:25:51 | 000,145,408 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javacpl.cpl
[2014.10.29 08:01:04 | 000,001,867 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2014.10.26 17:52:23 | 000,275,814 | ---- | M] () -- C:\Documents and Settings\Kristinka\My Documents\cc_20141026_174835.reg
[2014.10.26 17:18:06 | 000,112,640 | ---- | M] (forum.viry.cz) -- C:\Documents and Settings\Kristinka\Desktop\FRSTLauncher.exe
[2014.10.26 17:17:41 | 002,113,024 | ---- | M] (Farbar) -- C:\Documents and Settings\Kristinka\Desktop\FRST64.exe
[2 C:\WINDOWS\SysWow64\*.tmp files -> C:\WINDOWS\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.11.18 19:27:16 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2014.11.18 19:23:23 | 001,222,144 | ---- | C] () -- C:\Documents and Settings\Kristinka\Desktop\RSITx64.exe
[2014.11.16 18:39:58 | 000,000,952 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014.11.16 18:39:58 | 000,000,948 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014.11.06 21:31:35 | 000,008,826 | ---- | C] () -- C:\Documents and Settings\Kristinka\Desktop\Snap 2014-11-06 at 21.31.35.png
[2014.11.06 21:29:50 | 000,008,481 | ---- | C] () -- C:\Documents and Settings\Kristinka\Desktop\Snap 2014-11-06 at 21.29.50.png
[2014.10.29 17:27:36 | 001,998,336 | ---- | C] () -- C:\Documents and Settings\Kristinka\Desktop\adwcleaner_4.002 (1).exe
[2014.10.29 08:26:46 | 000,000,406 | ---- | C] () -- C:\WINDOWS\tasks\Opera scheduled Autoupdate 1383476416.job
[2014.10.26 17:48:44 | 000,275,814 | ---- | C] () -- C:\Documents and Settings\Kristinka\My Documents\cc_20141026_174835.reg
[2014.08.23 15:34:59 | 000,138,862 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-902231566-1358511475-2049901558-1004-0.dat
[2014.07.27 05:57:25 | 000,081,680 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2014.07.27 05:57:23 | 002,232,126 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-902231566-1358511475-2049901558-1002-0.dat
[2014.07.27 05:57:23 | 000,138,862 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2013.12.02 18:28:52 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Kristinka\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.11.18 18:08:55 | 000,000,664 | ---- | C] () -- C:\WINDOWS\SysWow64\d3d9caps.dat
[2013.11.14 20:05:09 | 000,000,171 | ---- | C] () -- C:\Documents and Settings\Kristinka\default.pls
[2013.11.14 20:04:41 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2013.11.03 11:26:02 | 000,216,064 | ---- | C] () -- C:\WINDOWS\SysWow64\gcapi_dll.dll
[2013.11.02 21:37:34 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2013.11.02 21:15:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2013.11.02 21:11:03 | 000,542,818 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2013.11.02 21:00:48 | 000,037,376 | ---- | C] () -- C:\WINDOWS\CPLUTL64.EXE
[2013.11.02 20:55:37 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
========== ZeroAccess Check ==========
[2013.11.02 21:10:34 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = %SystemRoot%\system32\shdocvw.dll
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\SysWOW64\shdocvw.dll -- [2013.09.24 08:07:10 | 001,520,128 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\WINDOWS\system32\wbem\fastprox.dll
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\SysWOW64\wbem\fastprox.dll -- [2009.03.19 19:51:22 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\WINDOWS\system32\wbem\wbemess.dll
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.11.03 10:27:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ESET
[2013.11.03 11:25:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Foxit Software
[2013.11.02 21:04:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\GHISLER
[2013.11.09 14:40:21 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Canon Easy-WebPrint EX
[2013.11.07 19:05:32 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013.11.07 19:05:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2013.11.03 10:26:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2014.07.27 05:19:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Garmin
[2014.07.27 05:20:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Package Cache
[2014.08.23 15:46:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
[2013.12.01 17:55:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bohouš\Application Data\Canon Easy-WebPrint EX
[2013.11.03 11:47:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bohouš\Application Data\ESET
[2014.02.26 21:06:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bohouš\Application Data\Foxit Software
[2014.08.23 12:39:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bohouš\Application Data\Garmin
[2014.02.09 18:13:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bohouš\Application Data\GHISLER
[2013.11.03 11:26:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\Foxit Software
[2014.07.27 05:19:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\Garmin
[2014.11.17 12:30:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanička\Application Data\.minecraft
[2014.08.15 16:34:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanička\Application Data\.mnaucraft
[2013.12.09 15:23:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanička\Application Data\Canon
[2013.11.11 19:32:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanička\Application Data\Canon Easy-WebPrint EX
[2013.11.03 11:50:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanička\Application Data\ESET
[2014.08.22 18:25:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanička\Application Data\Foxit Software
[2013.11.03 18:18:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanička\Application Data\GHISLER
[2013.11.03 12:49:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanička\Application Data\Opera Software
[2014.03.31 13:28:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Hanička\Application Data\Unity
[2013.11.07 19:05:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Canon
[2013.11.09 14:40:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Canon Easy-WebPrint EX
[2014.02.08 19:29:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\DuckLink
[2013.11.03 11:42:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\ESET
[2013.11.16 11:17:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Foxit Software
[2014.07.27 05:21:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Garmin
[2013.11.03 13:04:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\GHISLER
[2013.11.23 16:52:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Opera Software
[2014.08.23 15:46:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\TomTom
[2014.10.26 19:49:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Petr\Application Data\.minecraft
[2013.12.20 09:01:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Petr\Application Data\Canon
[2013.11.03 11:45:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Petr\Application Data\ESET
[2014.03.25 10:25:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Petr\Application Data\Foxit Software
[2013.11.03 12:01:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Petr\Application Data\GHISLER
[2013.11.03 11:58:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Petr\Application Data\Jpeg Resampler
[2013.11.03 12:00:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Petr\Application Data\Opera Software
========== Purity Check ==========
========== Custom Scans ==========
< >
[2013.11.02 20:48:32 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2013.11.02 20:57:04 | 000,032,648 | ---- | C] () -- C:\WINDOWS\Tasks\SchedLgU.Txt
[2013.11.02 20:57:05 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2013.11.11 19:32:09 | 000,000,914 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2014.10.29 08:26:46 | 000,000,406 | ---- | C] () -- C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1383476416.job
[2014.11.16 18:39:58 | 000,000,948 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2014.11.16 18:39:58 | 000,000,952 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
< >
< MD5 for: AGP440.SYS >
[2007.02.18 13:00:00 | 011,678,589 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\amd64\sp2.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2007.02.18 13:00:00 | 011,678,589 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\amd64\sp2.cab:atapi.sys
< MD5 for: AUTOCHK.EXE >
[2007.02.18 13:00:00 | 000,594,944 | ---- | M] (Microsoft Corporation) MD5=39ECC326D3F5531A13A1C0F0B43A8EDD -- C:\WINDOWS\SysWOW64\autochk.exe
< MD5 for: CRYPTSVC.DLL >
[2007.02.18 13:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=FEB85DA744DD3F41A427CF6D2BC04FE4 -- C:\WINDOWS\SysWOW64\cryptsvc.dll
< MD5 for: EXPLORER.EXE >
[2007.02.18 13:00:00 | 001,053,184 | ---- | M] (Microsoft Corporation) MD5=A26C39540F8BE3729846E360E2C57344 -- C:\WINDOWS\SysWOW64\explorer.exe
[2007.02.18 13:00:00 | 001,364,480 | ---- | M] (Microsoft Corporation) MD5=AE7A08C05F72A9242734C03230A5CD7F -- C:\WINDOWS\explorer.exe
< MD5 for: HAL.DLL >
[2007.02.18 13:00:00 | 011,678,589 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\amd64\sp2.cab:hal.dll
[2010.11.09 00:41:22 | 000,280,064 | ---- | M] (Microsoft Corporation) MD5=82F4104C2D9774B58A9244FC3B0EE07C -- C:\WINDOWS\$hf_mig$\KB2393802\SP2QFE\hal.dll
[2012.04.11 21:31:20 | 000,280,064 | ---- | M] (Microsoft Corporation) MD5=82F4104C2D9774B58A9244FC3B0EE07C -- C:\WINDOWS\$hf_mig$\KB2676562\SP2QFE\hal.dll
[2013.03.08 16:24:30 | 000,280,064 | ---- | M] (Microsoft Corporation) MD5=82F4104C2D9774B58A9244FC3B0EE07C -- C:\WINDOWS\$hf_mig$\KB2813170\SP2QFE\hal.dll
[2009.03.19 19:41:44 | 000,280,064 | ---- | M] (Microsoft Corporation) MD5=82F4104C2D9774B58A9244FC3B0EE07C -- C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\hal.dll
< MD5 for: ISAPNP.SYS >
[2007.02.18 13:00:00 | 011,678,589 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\amd64\sp2.cab:isapnp.sys
< MD5 for: NETLOGON.DLL >
[2007.02.18 13:00:00 | 000,430,592 | ---- | M] (Microsoft Corporation) MD5=451564B8F22461D90CF8ED3945637845 -- C:\WINDOWS\SysWOW64\netlogon.dll
< MD5 for: SCECLI.DLL >
[2007.02.18 13:00:00 | 000,188,928 | ---- | M] (Microsoft Corporation) MD5=E7B7FD7D8907DADED4928E922608887F -- C:\WINDOWS\SysWOW64\scecli.dll
< MD5 for: SMSS.EXE >
[2007.02.18 13:00:00 | 000,053,760 | ---- | M] (Microsoft Corporation) MD5=97E9B4A202E645E7826BE7597B335C47 -- C:\WINDOWS\SysWOW64\smss.exe
< MD5 for: SVCHOST.EXE >
[2007.02.18 13:00:00 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=C09CCFE81DEC9B162533D7184D705682 -- C:\WINDOWS\SysWOW64\svchost.exe
< MD5 for: TCPIP.SYS >
[2007.02.18 13:00:00 | 000,768,000 | ---- | M] (Microsoft Corporation) MD5=C013E7F14FD378A16F5B7A4B5A7050E9 -- C:\WINDOWS\$NtUninstallKB2509553$\tcpip.sys
[2011.03.03 12:47:32 | 000,784,896 | ---- | M] (Microsoft Corporation) MD5=CE9A7AC526636585A126FACE243F4574 -- C:\WINDOWS\$hf_mig$\KB2509553\SP2QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2007.02.18 13:00:00 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=B5FEB3B971A8B8C81CE9DE65031A87E5 -- C:\WINDOWS\SysWOW64\userinit.exe
< MD5 for: WS2_32.DLL >
[2007.02.18 13:00:00 | 000,083,456 | ---- | M] (Microsoft Corporation) MD5=5C34F97D87B2A8C9CB4422E67F2DAB61 -- C:\WINDOWS\SysWOW64\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[21 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[21 C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[3 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[1 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\*.tmp files -> C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\*.tmp -> ]
[2 C:\WINDOWS\SysWOW64\*.tmp files -> C:\WINDOWS\SysWOW64\*.tmp -> ]
[1 C:\WINDOWS\SysWOW64\config\systemprofile\Local Settings\Temp\*.tmp files -> C:\WINDOWS\SysWOW64\config\systemprofile\Local Settings\Temp\*.tmp -> ]
[38 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
[2013.11.02 21:18:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ATI
[2013.11.09 14:40:21 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Canon Easy-WebPrint EX
[2013.11.07 19:05:32 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013.11.07 19:05:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2013.11.03 10:26:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2014.07.27 05:19:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Garmin
[2014.11.02 12:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2014.11.16 16:17:59 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2014.11.12 13:35:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2014.07.27 05:20:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Package Cache
[2014.10.15 15:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2013.11.03 12:06:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sun
[2014.08.23 15:46:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
[2014.10.23 18:47:58 | 036,281,408 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Documents and Settings\All Users\Application Data\Garmin\Core Update Service\APP-express-windows-3.2.21.0\GarminExpressInstaller.exe
[2014.11.02 12:05:52 | 019,828,376 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
[2014.07.27 05:04:50 | 000,887,896 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Documents and Settings\All Users\Application Data\Package Cache\{817c6bb8-ea2d-4e12-abbc-e33c3de43f64}\GarminExpressInstaller.exe
[2014.07.27 05:18:48 | 000,455,592 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\Package Cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\vcredist_x86.exe
[2014.07.23 07:44:36 | 000,194,560 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Documents and Settings\All Users\Application Data\Package Cache\8F5483FC98168EE3021845147749691550F70B6D\LifetimeUninstaller.exe
[2014.07.27 05:04:59 | 000,887,896 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Application Data\Package Cache\E15AD80FC74277EF2048312E9A71AF56B2EBA622\redist\dotNetFx40_Client_setup.exe
< %APPDATA%\*. >
[2013.11.23 16:52:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Adobe
[2013.11.14 20:05:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Ahead
[2013.11.03 11:42:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\ATI
[2013.11.07 19:05:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Canon
[2013.11.09 14:40:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Canon Easy-WebPrint EX
[2014.02.08 19:29:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\DuckLink
[2014.08.18 21:19:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\dvdcss
[2013.11.03 11:42:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\ESET
[2013.12.04 21:01:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\FastStone
[2013.11.16 11:17:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Foxit Software
[2014.07.27 05:21:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Garmin
[2013.11.03 13:04:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\GHISLER
[2013.11.03 11:42:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Identities
[2013.11.07 18:42:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\InstallShield
[2013.11.23 16:52:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Macromedia
[2014.11.02 12:05:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Malwarebytes
[2014.11.08 16:03:34 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Kristinka\Application Data\Microsoft
[2014.08.23 15:46:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Mozilla
[2013.11.23 16:52:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Opera Software
[2013.11.03 14:49:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\Sun
[2014.08.23 15:46:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\TomTom
[2014.11.16 19:19:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristinka\Application Data\vlc
< %APPDATA%\*.exe /s >
[2014.10.29 17:23:52 | 000,145,408 | ---- | M] () -- C:\Documents and Settings\Kristinka\Application Data\Sun\Java\jre1.7.0_71\lzma.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2014.11.17 13:05:01 | 000,000,664 | ---- | M] () -- C:\WINDOWS\system32\d3d9caps.dat
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"CTFMON.EXE" = C:\WINDOWS\system32\ctfmon.exe -- [2007.02.18 13:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation)
"DuckCapture" = "C:\Program Files (x86)\DuckLink\DuckCapture\DuckCapture.exe" /autorun -- [2011.11.03 21:21:28 | 000,436,736 | ---- | M] (DuckLink Software)
"GarminExpressTrayApp" = "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" -- [2014.07.23 07:44:36 | 000,688,984 | ---- | M] (Garmin Ltd or its subsidiaries)
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_SZ C:\WINDOWS\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_SZ C:\WINDOWS\system32\svchost.exe -k netsvcs
< >
< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=1
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Professional x64 Edition" /noexecute=optin /fastdetect /usepmtimer
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2014.11.18 19:27:16 | 000,000,512 | ---- | M] () MD5=3BB843F4E1CA1522F5478ECA82877739 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
< *keygen* /s >
< *AntiWPA* /s >
< *loader* /s >
[2013.11.03 11:00:05 | 000,002,435 | ---- | M] () -- \Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\G9QFSTIV\39-1-deferred-loader[1].js
[2013.11.03 11:00:03 | 000,000,940 | ---- | M] () -- \Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\G9QFSTIV\39-1-loader[1].js
[2013.11.03 11:00:06 | 000,007,806 | ---- | M] () -- \Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CHEVOHAR\product-image-loader[1].gif
[2014.03.10 16:56:16 | 000,010,762 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fgkeilefmpmbamgcejhjpiecahcbipip\1.3.3_0\img\hdpi\misc\loader.gif
[2014.03.10 16:56:16 | 000,006,142 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fgkeilefmpmbamgcejhjpiecahcbipip\1.3.3_0\img\mdpi\misc\loader.gif
[2014.09.10 09:20:48 | 000,010,762 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fgkeilefmpmbamgcejhjpiecahcbipip\1.3.4_0\img\hdpi\misc\loader.gif
[2014.09.10 09:20:48 | 000,006,142 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fgkeilefmpmbamgcejhjpiecahcbipip\1.3.4_0\img\mdpi\misc\loader.gif
[2014.03.15 10:32:32 | 000,003,061 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Temporary Internet Files\Content.IE5\0AXLW1Y0\rmsloaderdelayeddiv[1].js
[2014.01.11 10:17:49 | 000,003,061 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Temporary Internet Files\Content.IE5\0BTRTWLJ\rmsloaderdelayeddiv[1].js
[2014.02.15 12:42:06 | 000,003,061 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Temporary Internet Files\Content.IE5\76YLBX71\rmsloaderdelayeddiv[1].js
[2014.03.12 14:27:22 | 000,007,813 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Temporary Internet Files\Content.IE5\84L4PY2T\ajax-loader1[1].gif
[2014.03.08 09:43:27 | 000,003,061 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Temporary Internet Files\Content.IE5\84L4PY2T\rmsloaderdelayeddiv[1].js
[2014.03.29 23:36:20 | 000,019,105 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Temporary Internet Files\Content.IE5\EN7LI86W\loader[1].js
[2014.08.02 07:29:54 | 000,005,727 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Temporary Internet Files\Content.IE5\FQLK1IL4\loader[1].js
[2014.08.02 07:30:49 | 000,010,120 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Temporary Internet Files\Content.IE5\G5I7KD27\loader-global[1].gif
[2014.08.02 07:30:53 | 000,005,727 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Temporary Internet Files\Content.IE5\G5I7KD27\loader[1].js
[2014.03.12 07:54:58 | 000,008,288 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Temporary Internet Files\Content.IE5\O1GHTNQZ\loader[1].gif
[2014.03.08 09:28:02 | 000,013,138 | ---- | M] () -- \Documents and Settings\Bohouš\Local Settings\Temporary Internet Files\Content.IE5\Y4FKLYPA\loader_black[1].gif
[2014.10.05 11:51:12 | 000,051,570 | ---- | M] () -- \Documents and Settings\Hanička\Application Data\.mnaucraft\.minecraft\ForgeModLoader-client-0.log
[2014.09.10 15:06:55 | 000,043,872 | ---- | M] () -- \Documents and Settings\Hanička\Application Data\.mnaucraft\.minecraft\ForgeModLoader-client-0.log.1
[2014.09.10 15:01:05 | 000,000,000 | ---- | M] () -- \Documents and Settings\Hanička\Application Data\.mnaucraft\.minecraft\ForgeModLoader-client-0.log.1.lck
[2014.10.05 11:44:25 | 000,000,000 | ---- | M] () -- \Documents and Settings\Hanička\Application Data\.mnaucraft\.minecraft\ForgeModLoader-client-0.log.lck
[2014.10.05 08:18:20 | 000,044,672 | ---- | M] () -- \Documents and Settings\Hanička\Application Data\.mnaucraft\.minecraft\ForgeModLoader-client-1.log
[2014.10.05 07:41:50 | 000,089,925 | ---- | M] () -- \Documents and Settings\Hanička\Application Data\.mnaucraft\.minecraft\ForgeModLoader-client-2.log
[2014.09.30 10:01:04 | 000,000,273 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gafhhbahpojnjfhpepjjfjojbphnogmn\11.73.5.91_0\js\URILoaderContentScript.js
[2014.07.24 14:53:16 | 000,072,638 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Application Data\Skype\Apps\login\images\loader.gif
[2014.07.24 14:53:16 | 000,003,032 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Application Data\Skype\Apps\login\images\loader.png
[2014.07.24 14:53:16 | 000,006,012 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Application Data\Skype\Apps\login\images\normal\loader_15fps.gif
[2014.07.24 14:53:16 | 000,021,956 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Application Data\Skype\Apps\login\images\normal\loader_30fps.gif
[2014.07.24 14:53:16 | 000,009,772 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Application Data\Skype\Apps\login\images\retina\
loader@2x.png
[2014.10.19 12:17:06 | 000,001,980 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\G5I7KD27\AdLoader[1].htm
[2013.11.11 19:31:38 | 000,000,723 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\G5I7KD27\downloaderror[1].js
[2013.11.11 19:31:38 | 000,001,174 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\G5I7KD27\downloader[1].js
[2014.09.30 13:36:01 | 000,001,980 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\G9QFSTIV\AdLoader[1].htm
[2014.10.31 16:06:31 | 000,001,980 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\G9QFSTIV\AdLoader[3].htm
[2014.03.31 13:30:06 | 000,001,737 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\G9QFSTIV\ajax-loader[1].gif
[2014.06.12 16:46:08 | 000,009,427 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\G9QFSTIV\ajax-loader[2].gif
[2014.01.28 07:12:43 | 000,000,723 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\G9QFSTIV\downloaderror[1].js
[2013.11.29 15:00:28 | 000,003,061 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\G9QFSTIV\rmsloaderdelayeddiv[1].js
[2014.04.03 11:36:22 | 000,003,061 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\G9QFSTIV\rmsloaderdelayeddiv[2].js
[2014.09.14 14:00:16 | 000,018,715 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\SD2RC1Y7\AdLoader-a5fa12058ddb9a8919d6906ba95d7c57.min[1].js
[2014.01.28 07:12:43 | 000,001,174 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\SD2RC1Y7\downloader[1].js
[2014.09.14 13:53:07 | 000,010,520 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\SD2RC1Y7\loader-grey-on-transparent[1].gif
[2014.09.10 12:04:02 | 000,005,727 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\SD2RC1Y7\loader[1].js
[2014.03.06 13:03:28 | 000,003,061 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\SD2RC1Y7\rmsloaderdelayeddiv[1].js
[2014.03.31 13:22:25 | 000,003,061 | ---- | M] () -- \Documents and Settings\Hanička\Local Settings\Temporary Internet Files\Content.IE5\SD2RC1Y7\rmsloaderdelayeddiv[2].js
[2014.09.10 09:20:48 | 000,010,762 | ---- | M] () -- \Documents and Settings\Kristinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fgkeilefmpmbamgcejhjpiecahcbipip\1.3.4_0\img\hdpi\misc\loader.gif
[2014.09.10 09:20:48 | 000,006,142 | ---- | M] () -- \Documents and Settings\Kristinka\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fgkeilefmpmbamgcejhjpiecahcbipip\1.3.4_0\img\mdpi\misc\loader.gif
[2014.09.30 22:48:09 | 000,000,200 | ---- | M] () -- \GameTeamPokeCraft\config\TConPreloader.cfg
[2002.09.25 21:05:38 | 000,113,664 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[2006.07.14 10:39:46 | 000,106,496 | ---- | M] () -- \Program Files (x86)\Common Files\Ahead\Lib\NeGuideStoreLoader.dll
[2014.07.23 07:43:16 | 000,042,496 | ---- | M] () -- \Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MyDownloader.Core.dll
[2014.03.22 23:48:50 | 000,001,234 | ---- | M] () -- \RECYCLER\S-1-5-21-902231566-1358511475-2049901558-1003\Dc6\client\models\smd\ValveStudioModelLoader.class
[2014.03.22 23:48:52 | 000,001,038 | ---- | M] () -- \RECYCLER\S-1-5-21-902231566-1358511475-2049901558-1003\Dc6\migration\MigrationLoader.class
[2007.02.18 13:00:00 | 000,036,352 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[2 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2007.02.18 13:00:00 | 000,036,352 | ---- | M] () -- \WINDOWS\SysWOW64\dmloader.dll
[2 \WINDOWS\SysWOW64\*.tmp files -> \WINDOWS\SysWOW64\*.tmp -> ]
< *minodlogin* /s >
< *tnod* /s >
[2013.11.03 10:07:30 | 000,000,846 | ---- | M] () -- \Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SD2RC1Y7\lastnode[1].gif
< *AutoKMS* /s >
< *activator* /s >
< *serial* /s >
[2012.09.27 00:12:26 | 000,970,752 | ---- | M] () -- \Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2012.09.26 23:20:14 | 000,847,872 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2014.02.12 21:46:18 | 000,131,072 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2013.11.03 11:11:01 | 000,970,752 | ---- | M] () -- \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014.02.15 09:30:14 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\6c29ee2bedfe88dcd66993f1af135ad8\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.02.14 06:17:30 | 002,345,472 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\9860da66bf0219612908e7412b0a6e2e\System.Runtime.Serialization.ni.dll
[2014.02.15 09:27:08 | 003,070,976 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\a6de627d236a7f6764a0ad03183ec712\System.Runtime.Serialization.ni.dll
[2014.02.15 09:26:53 | 000,396,288 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\c1476ee10f122c21f8f98aece892becb\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.02.15 09:24:16 | 002,981,888 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v2.0.50727_64\System.Runtime.Seri#\dc3d0dfe2285ccf6d0f7ab9b3d61fd6d\System.Runtime.Serialization.ni.dll
[2014.07.29 05:07:39 | 000,311,296 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\a2f2c4c0abfbc3e4ce9aecbd147b1906\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.07.29 05:07:32 | 002,658,304 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\d6b8ab1088fcd3734582c0fa6b52bdda\System.Runtime.Serialization.ni.dll
[2014.07.29 05:09:24 | 000,009,216 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml.Serializ#\ffc5006a9b8e647e0ad89e68e0bfa40e\System.Xml.Serialization.ni.dll
[2014.07.29 05:11:17 | 003,424,768 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\53dddb365bca7203f49b7d2f0dc9c935\System.Runtime.Serialization.ni.dll
[2014.07.29 05:11:25 | 000,376,832 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_64\System.Runtime.Seri#\a6d5113221e92b37937dfa2725f37bf4\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014.07.29 05:14:19 | 000,010,240 | ---- | M] () -- \WINDOWS\assembly\NativeImages_v4.0.30319_64\System.Xml.Serializ#\3881cbbdff38b7af9f20eb48565dcf41\System.Xml.Serialization.ni.dll
[2010.03.18 12:16:28 | 001,026,936 | R--- | M] () -- \WINDOWS\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\System.Runtime.Serialization.dll.amd64
[2010.03.18 12:16:28 | 001,026,936 | R--- | M] () -- \WINDOWS\Installer\$PatchCache$\Managed\DFC90B5F2B0FFA63D84FD16F6BF37C4B\4.0.30319\System.Runtime.Serialization.dll.x86
[2014.07.28 20:14:47 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2014.07.28 20:14:45 | 001,039,040 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014.07.28 20:14:55 | 000,012,080 | ---- | M] () -- \WINDOWS\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
[2008.07.25 11:17:00 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2012.09.27 00:12:26 | 000,970,752 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2013.09.11 05:06:54 | 001,039,040 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 12:16:28 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2012.01.21 16:40:04 | 000,012,080 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework\v4.0.30319\System.Xml.Serialization.dll
[2008.07.25 10:59:50 | 000,131,072 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework64\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2012.09.26 23:20:14 | 000,847,872 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2013.09.11 05:06:54 | 001,039,040 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.dll
[2010.03.18 12:16:28 | 000,122,264 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2012.01.21 16:40:04 | 000,012,080 | ---- | M] () -- \WINDOWS\Microsoft.NET\Framework64\v4.0.30319\System.Xml.Serialization.dll
[2007.02.18 13:00:00 | 000,016,896 | ---- | M] () -- \WINDOWS\system32\serialui.dll
[2 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2007.02.18 13:00:00 | 000,016,896 | ---- | M] () -- \WINDOWS\SysWOW64\serialui.dll
[2 \WINDOWS\SysWOW64\*.tmp files -> \WINDOWS\SysWOW64\*.tmp -> ]
< *w7lxe* /s >
< End of report >