OTL logfile created on: 3/15/2013 10:30:18 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Madleska\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
1.99 Gb Total Physical Memory | 1.12 Gb Available Physical Memory | 56.48% Memory free
3.98 Gb Paging File | 3.04 Gb Available in Paging File | 76.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 100.00 Gb Total Space | 56.01 Gb Free Space | 56.01% Space Free | Partition Type: NTFS
Drive D: | 122.87 Gb Total Space | 93.67 Gb Free Space | 76.24% Space Free | Partition Type: NTFS
Drive E: | 1.86 Gb Total Space | 0.34 Gb Free Space | 18.24% Space Free | Partition Type: FAT
Computer Name: MAZLIK | User Name: Madleska | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/03/14 17:02:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Madleska\Desktop\OTL.exe
PRC - [2012/12/18 20:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/10/10 11:55:04 | 000,085,344 | ---- | M] (Software602 a.s.) -- C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe
PRC - [2011/02/26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/01/12 16:53:14 | 000,233,472 | ---- | M] (Vodafone Group) -- C:\Program Files\Vodafone\Via The Phone\VodafoneConnectorService.exe
PRC - [2009/12/22 03:31:26 | 000,217,088 | ---- | M] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe
PRC - [2009/11/19 13:05:42 | 000,284,160 | ---- | M] (ASUSTek) -- C:\Program Files\ASUS\LivCam\LivCam.exe
PRC - [2009/08/19 02:35:56 | 000,219,136 | ---- | M] () -- C:\Windows\System32\AsusService.exe
PRC - [2009/07/20 10:47:14 | 000,083,240 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
PRC - [2009/07/14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/02 03:03:12 | 002,352,416 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
PRC - [2009/07/02 03:03:12 | 000,795,936 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2009/07/02 03:03:12 | 000,582,944 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
========== Modules (No Company Name) ==========
MOD - [2012/11/28 14:13:52 | 000,087,952 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/11/28 14:13:30 | 001,242,512 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009/09/15 13:30:42 | 000,376,832 | ---- | M] () -- C:\Program Files\ASUS\LivCam\SMIUtility.dll
MOD - [2009/07/02 03:03:24 | 000,132,384 | ---- | M] () -- C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll
========== Services (SafeList) ==========
SRV - [2013/03/15 11:40:46 | 000,258,776 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/01/08 12:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/12/18 20:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/10/10 11:55:04 | 000,085,344 | ---- | M] (Software602 a.s.) [Auto | Running] -- C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe -- (602XML Updater)
SRV - [2010/06/07 15:22:16 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/01/15 13:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2010/01/12 16:53:14 | 000,233,472 | ---- | M] (Vodafone Group) [Auto | Running] -- C:\Program Files\Vodafone\Via The Phone\VodafoneConnectorService.exe -- (VodafoneConnectorService)
SRV - [2009/12/22 03:31:26 | 000,217,088 | ---- | M] (Teruten) [Auto | Running] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2009/08/19 02:35:56 | 000,219,136 | ---- | M] () [Auto | Running] -- C:\Windows\System32\AsusService.exe -- (AsusService)
SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/02 03:03:12 | 000,582,944 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2008/11/11 08:38:06 | 000,620,544 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Madleska\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2011/02/09 14:03:00 | 000,011,832 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\AsUpIO.sys -- (AsUpIO)
DRV - [2009/12/22 03:31:26 | 000,036,640 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009/12/15 13:05:42 | 000,102,912 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2009/12/15 13:05:42 | 000,101,120 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbdev.sys -- (hwusbdev)
DRV - [2009/12/15 13:05:42 | 000,023,424 | ---- | M] (Huawei Tech. Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewdcsc.sys -- (Huawei)
DRV - [2009/10/05 18:31:50 | 001,221,632 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/07/27 08:06:45 | 000,051,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C)
DRV - [2009/07/20 10:29:40 | 000,013,880 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\kbfiltr.sys -- (kbfiltr)
DRV - [2009/07/14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/14 00:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/01 05:46:20 | 000,043,944 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btusbflt.sys -- (btusbflt)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search bar =
http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://fr.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... -SearchBox
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\${searchCLSID}: "URL" =
http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... -SearchBox
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{130FD34A-E07E-45CA-A72B-08E0CF713CF5}: "URL" =
http://slovnik.seznam.cz/?q={searchTerm ... ckSearch_5
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{157CB46F-F568-45E2-9D11-A8D5EA97ACAC}: "URL" =
http://slovnik.seznam.cz/?q={searchTerm ... ckSearch_5
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{65AEC1C8-4030-4918-A49A-957360487F3B}: "URL" =
http://www.mapy.cz/?query={searchTerms} ... ckSearch_5
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{6D710949-428E-4B12-AF6A-F4862F7C8E62}: "URL" =
http://websearch.ask.com/custom/java/re ... tid=OSJ000
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{8D8737F3-22C6-46BD-B391-E3AC85B31515}: "URL" =
http://www.webhledani.cz/results.aspx?i ... earchTerms}
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{8F22A5E3-934B-401F-8835-4A7B2118E4C1}: "URL" =
http://www.google.com/search?q={searchT ... f8&oe=utf8
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{B7451F89-9A0B-40F6-A1D2-B29B00E4B5D7}: "URL" =
http://www.firmy.cz/phr/{searchTerms}?s ... ckSearch_5
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{C4906FE9-9266-465C-AC31-1922CF359125}: "URL" =
http://www.zbozi.cz/?q={searchTerms}&r= ... ckSearch_5
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{C4F6FAB6-2517-4F4A-B5FC-8E0D537FEB35}: "URL" =
http://encyklopedie.seznam.cz/search?q= ... ckSearch_5
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..\SearchScopes\{DAE03473-0AC9-4E0F-84A7-2C52DAC62EC6}: "URL" =
http://search.seznam.cz/?q={searchTerms ... ckSearch_5
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_7_700_141.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@software602.cz/602XML Filler: C:\Program Files\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Madleska\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
[2013/03/04 08:48:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Madleska\AppData\Roaming\Mozilla\Firefox\Profiles\gmdlyf6v.default\extensions
O1 HOSTS File: ([2013/03/14 18:14:46 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [LivCam] C:\Program Files\ASUS\LivCam\LivCam.exe (ASUSTek)
O4 - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4 - HKU\S-1-5-21-3615316729-2245769125-108544927-1001..\Run: [FileHippo.com] C:\Program Files\FileHippo.com\UpdateChecker.exe (FileHippo.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O7 - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: mojebanka.cz ([*] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mojebanka.cz ([etrading] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mojebanka.cz ([www] https in Trusted sites)
O15 - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..Trusted Domains: localhost ([]http in Internet)
O15 - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..Trusted Domains: mojebanka.cz ([*] https in Důvěryhodné servery)
O15 - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..Trusted Domains: mojebanka.cz ([etrading] https in Důvěryhodné servery)
O15 - HKU\S-1-5-21-3615316729-2245769125-108544927-1001\..Trusted Domains: mojebanka.cz ([www] https in Důvěryhodné servery)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4}
http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx (WRC Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.30.64.53 217.30.64.54
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9B766C40-51B0-4741-8C73-F763007B5AE9}: DhcpNameServer = 10.200.209.33
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9E7AB497-FDE1-455B-A4C7-6236EF91CB0C}: DhcpNameServer = 217.30.64.53 217.30.64.54
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2013/03/14 16:45:12 | 000,000,000 | R--D | M] - C:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2013/03/14 16:45:12 | 000,000,000 | R--D | M] - D:\Autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/03/15 22:21:01 | 000,000,000 | ---D | C] -- C:\Users\Madleska\AppData\Roaming\TuneUp Software
[2013/03/15 19:18:52 | 000,000,000 | ---D | C] -- C:\windows\System32\EventProviders
[2013/03/15 17:21:08 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013/03/14 18:22:26 | 000,000,000 | ---D | C] -- C:\windows\temp
[2013/03/14 18:14:53 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2013/03/14 18:10:06 | 000,000,000 | ---D | C] -- C:\Users\Madleska\AppData\Local\temp
[2013/03/14 17:48:45 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2013/03/14 17:48:45 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2013/03/14 17:48:45 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2013/03/14 17:48:33 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013/03/14 17:48:23 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/03/14 17:47:47 | 000,000,000 | ---D | C] -- C:\windows\erdnt
[2013/03/14 17:32:09 | 005,039,189 | ---- | C] (Swearware) -- C:\Users\Madleska\Desktop\ComboFix.exe
[2013/03/14 17:03:28 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/03/14 17:02:15 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Madleska\Desktop\OTL.exe
[2013/03/14 16:55:29 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Madleska\Desktop\tdsskiller.exe
[2013/03/14 16:45:12 | 000,000,000 | R--D | C] -- C:\Autorun.inf
[2013/03/14 16:38:18 | 000,000,000 | ---D | C] -- C:\UsbFix
[2013/03/14 16:35:44 | 001,016,787 | ---- | C] (El Desaparecido - SosVirus.org) -- C:\Users\Madleska\Desktop\UsbFix.exe
[2013/03/14 15:30:23 | 000,000,000 | ---D | C] -- C:\windows\ERUNT
[2013/03/14 15:30:08 | 000,000,000 | ---D | C] -- C:\JRT
[2013/03/14 14:25:03 | 000,000,000 | ---D | C] -- C:\rsit
[2013/03/14 01:35:03 | 000,627,200 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeeds.dll
[2013/03/14 01:34:59 | 000,606,208 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mstime.dll
[2013/03/14 01:34:58 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iedkcs32.dll
[2013/03/14 01:34:57 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\iepeers.dll
[2013/03/14 01:34:57 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\licmgr10.dll
[2013/03/14 01:34:56 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ieui.dll
[2013/03/14 01:34:56 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\url.dll
[2013/03/14 01:34:56 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedsbs.dll
[2013/03/14 01:34:56 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jsproxy.dll
[2013/03/14 01:34:56 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeedssync.exe
[2013/03/14 01:34:55 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mshtml.tlb
[2013/03/14 01:34:55 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\html.iec
[2013/03/05 22:24:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/03/05 22:22:23 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/03/05 22:22:19 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013/03/05 22:22:19 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/03/05 18:03:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/03/05 18:03:02 | 000,000,000 | ---D | C] -- C:\Users\Madleska\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/03/05 18:01:07 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\windows\System32\javaws.exe
[2013/03/05 18:00:27 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\windows\System32\javaw.exe
[2013/03/05 18:00:27 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\windows\System32\WindowsAccessBridge.dll
[2013/03/05 18:00:26 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\windows\System32\java.exe
[2013/02/16 18:50:20 | 000,000,000 | ---D | C] -- C:\Users\Madleska\AppData\Roaming\Seznam.cz
[2013/02/16 10:38:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/02/16 10:38:05 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2013/02/16 10:38:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2013/02/16 09:40:23 | 000,000,000 | ---D | C] -- C:\Users\Madleska\AppData\Roaming\Apple Computer
[2013/02/16 09:40:23 | 000,000,000 | ---D | C] -- C:\Users\Madleska\AppData\Local\Apple Computer
[2013/02/16 09:38:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2013/02/16 09:34:10 | 000,000,000 | ---D | C] -- C:\Users\Madleska\AppData\Local\Apple
[2013/02/16 09:33:56 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2013/02/16 09:32:20 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2013/02/16 09:31:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2013/02/16 09:31:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2013/02/14 17:46:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/02/14 01:04:04 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\win32k.sys
[2013/02/14 01:03:27 | 003,957,608 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntkrnlpa.exe
[2013/02/14 01:03:26 | 003,902,312 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntoskrnl.exe
[2013/02/14 01:03:22 | 000,187,240 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\drivers\FWPKCLNT.SYS
[2013/02/14 01:02:59 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\conhost.exe
[2013/02/14 01:02:59 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\winsrv.dll
[2013/02/14 01:02:59 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/02/14 01:02:57 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/02/14 01:02:57 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/02/14 01:02:57 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/02/14 01:02:57 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/02/14 01:02:57 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/02/14 01:02:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/02/14 01:02:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/02/14 01:02:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/02/14 01:02:57 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/02/14 01:02:56 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/02/14 01:02:56 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/02/14 01:02:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/02/14 01:02:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/02/14 01:02:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/02/14 01:02:56 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\windows\System32\api-ms-win-core-console-l1-1-0.dll
[2011/10/31 20:20:57 | 003,511,776 | ---- | C] (Piriform Ltd) -- C:\Users\Madleska\ccsetup312.exe
[2011/10/18 19:50:21 | 002,556,672 | ---- | C] (Piriform Ltd) -- C:\Users\Madleska\rcsetup141.exe
[2011/10/17 18:24:51 | 003,900,600 | ---- | C] (AVG Technologies) -- C:\Users\Madleska\avg_avc_stb_all_2012_1831.exe
[2011/06/06 17:20:57 | 003,080,864 | ---- | C] (Adobe Systems, Inc.) -- C:\Users\Madleska\install_flash_player.exe
[2011/06/06 16:30:53 | 008,442,984 | ---- | C] (Mozilla) -- C:\Users\Madleska\Firefox Setup 3.6.17.exe
[2009/10/11 14:48:40 | 003,211,616 | ---- | C] (Ghisler Software GmbH) -- C:\Program Files\tcmd750a.exe
[2009/08/07 13:50:18 | 057,187,288 | ---- | C] (Nero AG) -- C:\Program Files\Nero-9.4.12.3_free.exe
========== Files - Modified Within 30 Days ==========
[2013/03/15 22:35:34 | 000,631,526 | ---- | M] () -- C:\windows\System32\perfh005.dat
[2013/03/15 22:35:34 | 000,616,242 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2013/03/15 22:35:34 | 000,122,148 | ---- | M] () -- C:\windows\System32\perfc005.dat
[2013/03/15 22:35:34 | 000,106,622 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2013/03/15 22:34:30 | 000,009,920 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/15 22:34:30 | 000,009,920 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/15 22:27:05 | 000,065,536 | ---- | M] () -- C:\windows\System32\Ikeext.etl
[2013/03/15 22:26:46 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013/03/15 22:25:13 | 1602,691,072 | -HS- | M] () -- C:\hiberfil.sys
[2013/03/15 21:40:00 | 000,000,914 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2013/03/15 17:29:48 | 000,001,875 | ---- | M] () -- C:\Users\Madleska\Desktop\Update Checker.lnk
[2013/03/15 17:28:00 | 000,000,925 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/03/15 17:23:00 | 000,001,949 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/03/15 17:03:11 | 000,043,162 | ---- | M] () -- C:\Users\Madleska\Documents\cc_20130315_170303.reg
[2013/03/15 11:40:31 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\System32\FlashPlayerApp.exe
[2013/03/15 11:40:31 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\windows\System32\FlashPlayerCPLApp.cpl
[2013/03/14 21:14:01 | 000,815,616 | ---- | M] () -- C:\Users\Madleska\Desktop\RogueKiller.exe
[2013/03/14 21:05:13 | 000,890,798 | ---- | M] () -- C:\Users\Madleska\Desktop\SecurityCheck.exe
[2013/03/14 18:14:46 | 000,000,027 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts
[2013/03/14 17:32:19 | 005,039,189 | ---- | M] (Swearware) -- C:\Users\Madleska\Desktop\ComboFix.exe
[2013/03/14 17:02:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Madleska\Desktop\OTL.exe
[2013/03/14 16:55:37 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Madleska\Desktop\tdsskiller.exe
[2013/03/14 16:35:53 | 001,016,787 | ---- | M] (El Desaparecido - SosVirus.org) -- C:\Users\Madleska\Desktop\UsbFix.exe
[2013/03/14 11:27:56 | 000,000,556 | ---- | M] () -- C:\windows\System32\MyDefrag.debuglog
[2013/03/14 11:27:04 | 000,001,962 | ---- | M] () -- C:\Users\Public\Desktop\FULL-DISKfighter.lnk
[2013/03/10 14:30:16 | 000,009,830 | ---- | M] () -- C:\Users\Madleska\Documents\cc_20130310_143006.reg
[2013/03/05 22:24:04 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/03/05 18:00:06 | 000,094,112 | ---- | M] (Oracle Corporation) -- C:\windows\System32\WindowsAccessBridge.dll
[2013/03/05 18:00:05 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\windows\System32\javaws.exe
[2013/03/05 18:00:05 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\windows\System32\javaw.exe
[2013/03/05 18:00:05 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\windows\System32\java.exe
[2013/03/05 18:00:04 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\windows\System32\npdeployJava1.dll
[2013/03/05 18:00:04 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\windows\System32\deployJava1.dll
[2013/02/28 17:16:41 | 000,132,096 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\url.dll
[2013/02/28 17:16:20 | 000,606,208 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\mstime.dll
[2013/02/28 17:16:16 | 000,627,200 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msfeeds.dll
[2013/02/28 17:16:16 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msfeedsbs.dll
[2013/02/28 17:16:10 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\licmgr10.dll
[2013/02/28 17:16:09 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\jsproxy.dll
[2013/02/28 17:16:07 | 000,381,440 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iedkcs32.dll
[2013/02/28 17:16:07 | 000,185,856 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\iepeers.dll
[2013/02/28 17:16:07 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\ieui.dll
[2013/02/28 17:15:16 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\msfeedssync.exe
[2013/02/28 15:51:56 | 000,386,048 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\html.iec
[2013/02/28 14:26:56 | 001,638,912 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\mshtml.tlb
[2013/02/25 17:17:29 | 000,002,064 | ---- | M] () -- C:\Users\Madleska\Documents\cc_20130225_171708.reg
[2013/02/16 10:38:06 | 000,002,521 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2013/02/14 18:49:26 | 000,000,658 | ---- | M] () -- C:\Users\Madleska\Documents\cc_20130214_184919.reg
[2013/02/14 08:49:43 | 000,421,752 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2013/03/15 17:23:00 | 000,001,949 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/03/15 17:22:57 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/03/15 17:03:07 | 000,043,162 | ---- | C] () -- C:\Users\Madleska\Documents\cc_20130315_170303.reg
[2013/03/14 21:14:01 | 000,815,616 | ---- | C] () -- C:\Users\Madleska\Desktop\RogueKiller.exe
[2013/03/14 21:05:11 | 000,890,798 | ---- | C] () -- C:\Users\Madleska\Desktop\SecurityCheck.exe
[2013/03/14 17:48:45 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2013/03/14 17:48:45 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2013/03/14 17:48:45 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2013/03/14 17:48:45 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2013/03/14 17:48:45 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2013/03/14 11:27:56 | 000,000,556 | ---- | C] () -- C:\windows\System32\MyDefrag.debuglog
[2013/03/14 11:27:04 | 000,001,962 | ---- | C] () -- C:\Users\Public\Desktop\FULL-DISKfighter.lnk
[2013/03/10 14:30:11 | 000,009,830 | ---- | C] () -- C:\Users\Madleska\Documents\cc_20130310_143006.reg
[2013/03/05 22:24:04 | 000,001,753 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/02/25 17:17:15 | 000,002,064 | ---- | C] () -- C:\Users\Madleska\Documents\cc_20130225_171708.reg
[2013/02/16 10:38:06 | 000,002,521 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2013/02/16 09:33:57 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013/02/14 18:49:23 | 000,000,658 | ---- | C] () -- C:\Users\Madleska\Documents\cc_20130214_184919.reg
[2013/02/14 17:46:03 | 000,000,925 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/13 20:56:33 | 000,450,417 | ---- | C] () -- C:\Users\Madleska\P1010036.JPG
[2012/09/13 20:56:33 | 000,443,738 | ---- | C] () -- C:\Users\Madleska\P1010038.JPG
[2012/09/13 20:56:33 | 000,442,870 | ---- | C] () -- C:\Users\Madleska\P1010037.JPG
[2012/01/31 18:15:44 | 000,030,568 | ---- | C] () -- C:\windows\MusiccityDownload.exe
[2012/01/24 20:34:01 | 000,007,680 | ---- | C] () -- C:\Users\Madleska\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/23 06:56:16 | 004,738,560 | ---- | C] () -- C:\windows\System32\x264vfw.dll
[2011/09/25 16:56:26 | 000,216,064 | ---- | C] ( ) -- C:\windows\System32\lagarith.dll
[2011/07/12 15:56:50 | 000,074,752 | ---- | C] () -- C:\windows\System32\ff_vfw.dll
[2011/06/22 18:46:10 | 054,097,776 | ---- | C] () -- C:\Users\Madleska\PSB210_231.exe
[2011/06/07 10:13:38 | 000,974,848 | ---- | C] () -- C:\windows\System32\cis-2.4.dll
[2011/06/07 10:13:38 | 000,081,920 | ---- | C] () -- C:\windows\System32\issacapi_bs-2.3.dll
[2011/06/07 10:13:38 | 000,065,536 | ---- | C] () -- C:\windows\System32\issacapi_pe-2.3.dll
[2011/06/07 10:13:38 | 000,057,344 | ---- | C] () -- C:\windows\System32\issacapi_se-2.3.dll
[2010/06/03 20:46:23 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
========== ZeroAccess Check ==========
[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >