tak ted uz to neco vyplivlo.)
OTL logfile created on: 12.11.2014 12:06:29 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Dexter\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17358)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
4,00 Gb Total Physical Memory | 0,68 Gb Available Physical Memory | 17,05% Memory free
7,90 Gb Paging File | 4,60 Gb Available in Paging File | 58,21% Paging File free
Paging file location(s): e:\pagefile.sys 4000 8000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 59,53 Gb Total Space | 8,11 Gb Free Space | 13,62% Space Free | Partition Type: NTFS
Drive E: | 244,14 Gb Total Space | 48,74 Gb Free Space | 19,97% Space Free | Partition Type: NTFS
Drive F: | 454,49 Gb Total Space | 59,54 Gb Free Space | 13,10% Space Free | Partition Type: NTFS
Drive G: | 279,46 Gb Total Space | 159,16 Gb Free Space | 56,95% Space Free | Partition Type: NTFS
Drive I: | 350,39 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: DEXTER-PC | User Name: Dexter | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014.11.11 12:27:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dexter\Desktop\OTL.exe
PRC - [2014.10.21 17:52:24 | 022,869,088 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Drive\googledrivesync.exe
PRC - [2014.09.12 10:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014.07.31 20:15:04 | 004,085,896 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\avastui.exe
PRC - [2014.07.25 14:51:18 | 002,403,104 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2014.07.25 14:51:13 | 001,720,608 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2014.07.07 19:14:30 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014.07.02 18:44:41 | 000,411,936 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2013.01.02 14:10:28 | 002,448,032 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2013.01.02 13:38:50 | 000,073,984 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
PRC - [2012.08.14 08:47:18 | 000,203,640 | ---- | M] (X-Rite Inc.) -- C:\Program Files (x86)\X-Rite\Devices\Services\xrdd.exe
PRC - [2012.02.01 16:29:58 | 000,013,592 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2012.02.01 16:29:56 | 000,284,440 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2012.01.09 05:04:22 | 000,410,942 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\Utilities\adb.exe
PRC - [2011.03.23 15:38:56 | 003,344,736 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\InDesign.exe
PRC - [2010.07.22 22:10:47 | 000,402,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
PRC - [2010.07.16 11:45:00 | 004,293,640 | ---- | M] (ApoliSoft) -- C:\Program Files (x86)\Font Fitting Room Deluxe\ffr.exe
PRC - [2010.04.07 14:00:04 | 005,758,976 | ---- | M] (
http://www.emule-project.net) -- C:\Program Files (x86)\eMule\emule.exe
PRC - [2010.03.04 22:38:00 | 000,071,096 | ---- | M] () -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
PRC - [2009.10.08 14:12:06 | 000,049,152 | ---- | M] (Samsung) -- C:\Program Files (x86)\SEC\Natural Color Pro\NCProTray.exe
PRC - [2007.12.11 03:03:00 | 000,151,552 | R--- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\EPSON\BSTM\PG\E_L20IC2.EXE
PRC - [2007.11.21 18:27:56 | 000,143,360 | ---- | M] (Impacct) -- C:\Program Files (x86)\Plustek\OpticBook 3600\Am32Plus.exe
PRC - [2006.12.19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
========== Modules (No Company Name) ==========
MOD - [2014.11.12 10:31:20 | 001,175,040 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\wx._core_.pyd
MOD - [2014.11.12 10:31:20 | 001,160,704 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\_ssl.pyd
MOD - [2014.11.12 10:31:20 | 001,062,400 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\wx._controls_.pyd
MOD - [2014.11.12 10:31:20 | 000,811,008 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\wx._windows_.pyd
MOD - [2014.11.12 10:31:20 | 000,805,888 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\wx._gdi_.pyd
MOD - [2014.11.12 10:31:20 | 000,735,232 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\wx._misc_.pyd
MOD - [2014.11.12 10:31:20 | 000,713,216 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\_hashlib.pyd
MOD - [2014.11.12 10:31:20 | 000,686,080 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\unicodedata.pyd
MOD - [2014.11.12 10:31:20 | 000,557,056 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\pysqlite2._sqlite.pyd
MOD - [2014.11.12 10:31:20 | 000,525,640 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\windows._lib_cacheinvalidation.pyd
MOD - [2014.11.12 10:31:20 | 000,364,544 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\pythoncom27.dll
MOD - [2014.11.12 10:31:20 | 000,320,512 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32com.shell.shell.pyd
MOD - [2014.11.12 10:31:20 | 000,167,936 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32gui.pyd
MOD - [2014.11.12 10:31:20 | 000,128,512 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\_elementtree.pyd
MOD - [2014.11.12 10:31:20 | 000,127,488 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\pyexpat.pyd
MOD - [2014.11.12 10:31:20 | 000,122,368 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\wx._wizard.pyd
MOD - [2014.11.12 10:31:20 | 000,119,808 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32file.pyd
MOD - [2014.11.12 10:31:20 | 000,110,080 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\PyWinTypes27.dll
MOD - [2014.11.12 10:31:20 | 000,108,544 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32security.pyd
MOD - [2014.11.12 10:31:20 | 000,098,816 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32api.pyd
MOD - [2014.11.12 10:31:20 | 000,087,552 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\_ctypes.pyd
MOD - [2014.11.12 10:31:20 | 000,078,336 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\wx._animate.pyd
MOD - [2014.11.12 10:31:20 | 000,070,656 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\wx._html2.pyd
MOD - [2014.11.12 10:31:20 | 000,045,568 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\_socket.pyd
MOD - [2014.11.12 10:31:20 | 000,038,912 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32inet.pyd
MOD - [2014.11.12 10:31:20 | 000,035,840 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32process.pyd
MOD - [2014.11.12 10:31:20 | 000,027,136 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\_multiprocessing.pyd
MOD - [2014.11.12 10:31:20 | 000,025,600 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32pdh.pyd
MOD - [2014.11.12 10:31:20 | 000,024,064 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32pipe.pyd
MOD - [2014.11.12 10:31:20 | 000,022,528 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32ts.pyd
MOD - [2014.11.12 10:31:20 | 000,018,432 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32event.pyd
MOD - [2014.11.12 10:31:20 | 000,017,408 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32profile.pyd
MOD - [2014.11.12 10:31:20 | 000,011,264 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\win32crypt.pyd
MOD - [2014.11.12 10:31:20 | 000,010,240 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\select.pyd
MOD - [2014.11.12 10:31:20 | 000,007,168 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Temp\_MEI23682\hashobjs_ext.pyd
MOD - [2014.10.16 13:52:23 | 000,054,784 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\OdfWordAddin\fcddf9f1c6fa48c2795d2bd16a88539b\OdfWordAddin.ni.dll
MOD - [2014.10.16 13:52:18 | 002,108,416 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WordprocessingConve#\5d3f0e0521adff0f206605f4b8d9c8dc\WordprocessingConverter.ni.dll
MOD - [2014.10.16 13:52:15 | 000,454,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\OdfConverterLib\731d5e82f4c4715c2568b64f9b42b368\OdfConverterLib.ni.dll
MOD - [2014.10.16 13:52:14 | 000,163,328 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\OdfAddinLib\f07412c5be265cc3e5e0838edb50db04\OdfAddinLib.ni.dll
MOD - [2014.10.16 13:52:10 | 000,489,472 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\bde16ccd8150e03e17575c9a7ae4e3f5\IAStorUtil.ni.dll
MOD - [2014.10.15 11:06:15 | 011,922,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\b4001d722e320fa42cd87b04b5249b2d\System.Web.ni.dll
MOD - [2014.10.15 11:06:09 | 000,774,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b3011370dcbf33751d3b9dce8091c6c6\System.Runtime.Remoting.ni.dll
MOD - [2014.10.15 11:04:53 | 012,435,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1453d9e9a4989833ef3db4b22549ba1a\System.Windows.Forms.ni.dll
MOD - [2014.10.15 11:04:46 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\836e10dfd0811b303553216f5cb092ef\System.Drawing.ni.dll
MOD - [2014.10.15 11:04:38 | 005,467,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d49908aa93a23c84847b1f8b1b667860\System.Xml.ni.dll
MOD - [2014.10.15 11:04:34 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\237d509a79aeef6e4635b09450d98f2a\System.Configuration.ni.dll
MOD - [2014.10.15 11:04:11 | 003,348,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d97a5aa0eb7697aca7c6e90ae471af2b\WindowsBase.ni.dll
MOD - [2014.10.15 11:04:07 | 007,991,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\908ba9e296e92b4e14bdc2437edac603\System.ni.dll
MOD - [2014.09.14 21:25:53 | 000,044,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\stdole\d02d73b65be937cc029399f60a65413c\stdole.ni.dll
MOD - [2014.09.14 21:25:39 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\26b50aa1e86a984a5c0d53f2bbf95798\IAStorCommon.ni.dll
MOD - [2014.09.11 21:45:13 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll
MOD - [2014.07.07 19:14:31 | 019,329,904 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014.07.07 19:14:31 | 000,301,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswProperty.dll
MOD - [2013.07.08 13:43:52 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_cs_b77a5c561934e089\System.Runtime.Remoting.resources.dll
MOD - [2012.01.09 05:04:22 | 000,410,942 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\Utilities\adb.exe
MOD - [2010.11.13 03:36:45 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_cs_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010.03.26 21:09:12 | 000,095,680 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\unihan.dll
MOD - [2010.03.26 21:07:30 | 000,121,792 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\PMFileReader.dll
MOD - [2010.03.26 21:04:14 | 000,040,896 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\boost_threads.dll
MOD - [2010.03.26 21:04:06 | 000,018,368 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\boost_system.dll
MOD - [2010.03.26 21:03:58 | 000,654,784 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\boost_regex.dll
MOD - [2010.03.26 21:03:52 | 000,072,128 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\boost_filesystem.dll
MOD - [2010.03.26 21:02:46 | 000,061,888 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\ASLSupport.dll
MOD - [2010.03.26 21:02:10 | 000,046,016 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\aldvm32CJK.dll
MOD - [2010.03.26 21:02:04 | 000,051,136 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\aldfs32CJK.dll
MOD - [2010.02.22 04:50:20 | 000,060,416 | ---- | M] () -- C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\zlib1.dll
MOD - [2010.02.04 03:00:18 | 000,378,848 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\Plug-Ins\Filters\sangam readers\Reader For PageMaker.smrd
MOD - [2009.09.09 16:33:14 | 000,307,200 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\ScanApi.dll
MOD - [2008.12.13 09:47:26 | 000,026,112 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS5\tbbmalloc.dll
MOD - [2008.09.18 12:23:58 | 000,024,576 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\FineReader.dll
MOD - [2007.06.04 17:57:22 | 000,036,864 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\MaxReader.dll
MOD - [2007.05.30 16:48:06 | 000,167,936 | ---- | M] () -- C:\Program Files (x86)\Common Files\iMpacct\ControlFunc.dll
MOD - [2006.11.30 10:58:50 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\TWAINAPP.dll
MOD - [2006.05.15 15:24:18 | 000,122,938 | ---- | M] () -- C:\Program Files (x86)\Common Files\iMpacct\CommonFunc.dll
MOD - [2005.11.21 17:10:30 | 000,483,328 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\bmp2tiff.dll
MOD - [2005.09.21 14:38:54 | 000,081,920 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\Web Utility.dll
MOD - [2005.09.21 14:38:46 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\Wallpaper.dll
MOD - [2005.09.21 14:38:32 | 000,077,824 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\Scan Utility.dll
MOD - [2005.09.21 14:38:28 | 000,045,056 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\Power Save.dll
MOD - [2005.09.21 14:38:24 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\Positive Utility.dll
MOD - [2005.09.21 14:38:16 | 000,065,536 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\OCR Utility.dll
MOD - [2005.09.21 14:38:12 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\Negative Utility.dll
MOD - [2005.09.21 14:37:52 | 000,077,824 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\File Utility.dll
MOD - [2005.09.21 14:37:48 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\Fax Utility.dll
MOD - [2005.09.21 14:37:44 | 000,081,920 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\Email Utility.dll
MOD - [2005.09.21 14:37:36 | 000,073,728 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\Copy Utility.dll
MOD - [2005.09.21 14:37:24 | 000,045,056 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\Button Config.dll
MOD - [2005.09.21 14:37:00 | 000,065,536 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\BCR Utility.dll
MOD - [2005.09.21 14:36:54 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\Prndriver.dll
MOD - [2004.01.07 13:47:34 | 000,045,056 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\FzOCR.dll
MOD - [2004.01.07 13:47:24 | 000,045,056 | ---- | M] () -- C:\Program Files (x86)\Plustek\OpticBook 3600\PenPower.dll
========== Services (SafeList) ==========
SRV:
64bit: - [2014.09.19 02:25:49 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:
64bit: - [2014.07.25 14:51:10 | 018,956,064 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
SRV:
64bit: - [2014.07.07 19:14:30 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:
64bit: - [2013.06.29 08:20:44 | 000,077,824 | ---- | M] () [Auto | Running] -- C:\Program Files\NZBDrive\dokanx_mount.exe -- (DokanMounter)
SRV:
64bit: - [2013.06.13 20:31:10 | 000,357,144 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:
64bit: - [2013.05.27 06:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2012.11.22 15:35:22 | 000,828,072 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe -- (IswSvc)
SRV - [2014.10.18 20:18:22 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014.09.12 10:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014.07.25 14:51:13 | 001,720,608 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2014.07.02 18:44:41 | 000,411,936 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2014.03.20 23:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2013.09.11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013.01.02 14:10:28 | 002,448,032 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon)
SRV - [2012.08.14 08:47:18 | 000,203,640 | ---- | M] (X-Rite Inc.) [Auto | Running] -- C:\Program Files (x86)\X-Rite\Devices\Services\xrdd.exe -- (xrdd.exe)
SRV - [2012.02.01 16:29:58 | 000,013,592 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2012.01.26 19:47:58 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.03.04 22:38:00 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2006.12.19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2014.07.25 14:51:10 | 000,020,256 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV:
64bit: - [2014.07.07 19:15:35 | 000,427,360 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsp.sys -- (aswSP)
DRV:
64bit: - [2014.07.07 19:14:48 | 001,041,168 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:
64bit: - [2014.07.07 19:14:48 | 000,224,896 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:
64bit: - [2014.07.07 19:14:48 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:
64bit: - [2014.07.07 19:14:48 | 000,092,008 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswstm.sys -- (aswStm)
DRV:
64bit: - [2014.07.07 19:14:48 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:
64bit: - [2014.07.07 19:14:48 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:
64bit: - [2014.07.07 19:14:48 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:
64bit: - [2014.03.31 17:42:44 | 000,040,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:
64bit: - [2013.11.28 14:38:18 | 000,197,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:
64bit: - [2013.10.02 03:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2013.09.30 08:25:12 | 000,031,136 | ---- | M] (REALiX(tm)) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\HWiNFO64A.SYS -- (HWiNFO32)
DRV:
64bit: - [2013.06.29 08:18:14 | 000,057,160 | ---- | M] () [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\dokanx.sys -- (Dokan)
DRV:
64bit: - [2013.05.23 07:12:52 | 000,059,160 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:
64bit: - [2013.05.23 07:12:50 | 000,076,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:
64bit: - [2013.03.04 14:35:08 | 000,838,216 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:
64bit: - [2012.12.13 11:49:42 | 000,450,136 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vsdatant.sys -- (Vsdatant)
DRV:
64bit: - [2012.11.22 15:35:36 | 000,033,712 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
DRV:
64bit: - [2012.08.23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:
64bit: - [2012.03.01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2012.02.01 16:16:40 | 000,568,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:
64bit: - [2011.03.11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011.03.11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2010.11.20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010.07.01 18:11:24 | 000,012,352 | ---- | M] () [Kernel | "Start" not found. | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV:
64bit: - [2010.01.27 03:09:02 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:
64bit: - [2009.11.12 13:48:56 | 000,005,504 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\StarOpen.sys -- (StarOpen)
DRV:
64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009.02.24 18:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mcdbus.sys -- (mcdbus)
DRV - [2009.11.12 13:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\SysWow64\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009.02.24 18:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\mcdbus.sys -- (mcdbus)
DRV - [2006.08.28 17:12:04 | 000,013,312 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\MTictwl.sys -- (MagicTune)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-544068036-3592919291-2501284661-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-544068036-3592919291-2501284661-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-544068036-3592919291-2501284661-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-544068036-3592919291-2501284661-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-544068036-3592919291-2501284661-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8080
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
https://www.google.cz/"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:36.0a1
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wolfram.com/Mathematica: C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.4.2609412\npmathplugin.dll (Wolfram Research, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: File not found
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Nightly 36.0a1\extensions\\Components: C:\PROGRAM FILES\NIGHTLY\COMPONENTS
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Nightly 36.0a1\extensions\\Plugins: C:\PROGRAM FILES\NIGHTLY\PLUGINS
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F003DA68-8256-4b37-A6C4-350FA04494DF}: C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013.08.01 13:11:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014.07.07 19:14:49 | 000,000,000 | ---D | M]
[2012.11.17 13:23:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dexter\AppData\Roaming\Mozilla\Extensions
[2014.11.05 22:57:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dexter\AppData\Roaming\Mozilla\Firefox\Profiles\28tach34.default\extensions
[2014.11.05 22:57:35 | 000,979,610 | ---- | M] () (No name found) -- C:\Users\Dexter\AppData\Roaming\Mozilla\Firefox\Profiles\28tach34.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014.10.29 22:53:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
========== Chrome ==========
CHR - default_search_provider: (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.4 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
CHR - plugin: AdobeAAMDetect (Enabled) = C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
CHR - plugin: Wolfram Mathematica (Enabled) = C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.4.2609412\npmathplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll
CHR - plugin: Java Deployment Toolkit 7.0.250.17 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
O1 HOSTS File: ([2014.02.26 00:22:45 | 000,002,015 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 192.150.14.69
O1 - Hosts: 127.0.0.1 192.150.18.101
O1 - Hosts: 127.0.0.1 192.150.18.108
O1 - Hosts: 127.0.0.1 192.150.22.40
O1 - Hosts: 127.0.0.1 192.150.8.100
O1 - Hosts: 127.0.0.1 192.150.8.118
O1 - Hosts: 127.0.0.1 209-34-83-73.ood.opsource.net
O1 - Hosts: 127.0.0.1 3dns-1.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-4.adobe.com
O1 - Hosts: 127.0.0.1 3dns.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip2.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 41 more lines...
O2:
64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:
64bit: - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2:
64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:
64bit: - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
O2:
64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:
64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4:
64bit: - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [EPSON PageSTM TrayIcon01] C:\Program Files (x86)\EPSON\BSTM\PG\E_L20IC2.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKU\S-1-5-21-544068036-3592919291-2501284661-1000..\Run: [eMuleAutoStart] C:\Program Files (x86)\eMule\emule.exe (
http://www.emule-project.net)
O4 - HKU\S-1-5-21-544068036-3592919291-2501284661-1000..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
O4 - Startup: C:\Users\Dexter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FFRDeluxe.lnk = C:\Program Files (x86)\Font Fitting Room Deluxe\ffr.exe (ApoliSoft)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-544068036-3592919291-2501284661-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-544068036-3592919291-2501284661-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:
64bit: - Extra context menu item: Převést cíl vazby do Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Převést do Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Připojit cíl vazby k existujícímu PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Připojit k existujícímu PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Převést do Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Připojit k existujícímu PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/ ... ontrol.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 10.67.2)
O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 10.67.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2259E25B-439D-41A8-A0F7-ACBB0745A093}: DhcpNameServer = 192.168.0.1
O18:
64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:
64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.12.19 05:12:06 | 000,000,027 | R--- | M] () - I:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014.11.11 12:27:14 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Dexter\Desktop\OTL.exe
[2014.11.07 22:00:32 | 000,000,000 | ---D | C] -- C:\Program Files\Nightly
[2014.11.07 03:14:43 | 000,000,000 | ---D | C] -- C:\NVIDIA Corporation
[2014.11.07 03:14:43 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2014.11.07 00:57:29 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2014.10.29 22:05:14 | 000,000,000 | ---D | C] -- C:\FRST
[2014.10.29 22:04:37 | 002,113,536 | ---- | C] (Farbar) -- C:\Users\Dexter\Desktop\FRST64.exe
[2014.10.28 01:24:43 | 000,129,752 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.10.28 01:22:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014.10.28 01:22:51 | 000,093,400 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014.10.28 01:22:51 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014.10.28 01:22:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014.10.15 10:22:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft ASP.NET
[2014.10.15 10:18:13 | 000,507,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2014.10.15 10:18:13 | 000,276,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll
[2014.10.15 10:18:12 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2014.10.15 10:17:00 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014.10.15 10:16:52 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014.10.15 10:16:50 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014.10.15 10:16:49 | 000,710,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014.10.15 10:16:49 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014.10.15 10:16:49 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014.10.15 10:16:48 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014.10.15 10:16:48 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014.10.15 10:16:48 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014.10.15 10:16:45 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014.10.15 10:16:43 | 002,017,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014.10.15 10:16:40 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014.10.15 10:16:38 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014.10.15 10:16:35 | 000,446,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014.10.15 10:16:34 | 000,440,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014.10.15 10:16:33 | 000,731,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014.10.15 10:16:30 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014.10.15 10:16:25 | 002,108,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014.10.15 10:16:22 | 001,068,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014.10.15 10:16:22 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014.10.15 10:16:19 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014.10.15 10:16:06 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014.10.15 10:16:04 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014.10.15 10:15:56 | 000,289,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014.10.15 10:15:54 | 000,595,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014.10.15 10:15:48 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014.10.15 10:15:47 | 001,249,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014.10.15 10:15:47 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014.10.15 10:15:46 | 005,829,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014.10.15 10:15:46 | 000,758,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014.10.15 10:15:45 | 000,775,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014.10.15 10:15:45 | 000,547,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014.10.15 10:15:43 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014.10.15 10:15:42 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014.10.15 10:15:40 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014.10.15 10:14:35 | 000,842,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\blackbox.dll
[2014.10.15 10:14:32 | 001,202,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmv2clt.dll
[2014.10.15 10:14:32 | 000,744,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\blackbox.dll
[2014.10.15 10:14:31 | 000,988,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmv2clt.dll
[2014.10.15 10:14:30 | 004,120,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2014.10.15 10:14:29 | 000,782,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmsdk.dll
[2014.10.15 10:14:29 | 000,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmsdk.dll
[2014.10.15 10:14:28 | 000,500,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll
[2014.10.15 10:14:26 | 000,497,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmmgrtn.dll
[2014.10.15 10:14:17 | 003,208,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2014.10.15 10:13:47 | 000,406,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmmgrtn.dll
[2014.10.15 10:13:40 | 000,457,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll
[2014.10.15 10:13:33 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll
[2014.10.15 10:13:28 | 000,616,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2014.10.15 10:13:24 | 000,693,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2014.10.15 10:13:19 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll
[2014.10.15 10:13:00 | 001,574,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2014.10.15 10:12:45 | 000,619,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2014.10.15 10:12:29 | 000,532,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2014.10.15 10:12:26 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2014.10.15 10:12:24 | 005,551,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2014.10.15 10:11:54 | 000,631,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\evr.dll
[2014.10.15 10:11:53 | 003,970,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2014.10.15 10:11:48 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDump.dll
[2014.10.15 10:11:44 | 001,480,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2014.10.15 10:11:44 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptui.dll
[2014.10.15 10:11:44 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2014.10.15 10:11:43 | 003,914,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2014.10.15 10:11:43 | 001,329,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2014.10.15 10:11:43 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\evr.dll
[2014.10.15 10:11:43 | 000,432,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfplat.dll
[2014.10.15 10:11:36 | 001,005,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptui.dll
[2014.10.15 10:11:31 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2014.10.15 10:11:31 | 000,354,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfplat.dll
[2014.10.15 10:11:20 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptsp.dll
[2014.10.15 10:11:19 | 000,641,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscp.dll
[2014.10.15 10:11:18 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscp.dll
[2014.10.15 10:11:18 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msnetobj.dll
[2014.10.15 10:11:18 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2014.10.15 10:11:17 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msnetobj.dll
[2014.10.15 10:11:17 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2014.10.15 10:11:17 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidpolicyconverter.exe
[2014.10.15 10:11:17 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe
[2014.10.15 10:11:17 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2014.10.15 10:11:17 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setbcdlocale.dll
[2014.10.15 10:11:17 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidapi.dll
[2014.10.15 10:11:17 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rrinstaller.exe
[2014.10.15 10:11:17 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\appidapi.dll
[2014.10.15 10:11:17 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rrinstaller.exe
[2014.10.15 10:11:17 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfpmp.exe
[2014.10.15 10:11:16 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2014.10.15 10:11:16 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfpmp.exe
[2014.10.15 10:11:16 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidcertstorecheck.exe
[2014.10.15 10:11:16 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mferror.dll
[2014.10.15 10:11:16 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mferror.dll
[2014.10.15 10:09:36 | 003,179,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
[2014.10.15 10:08:00 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2014.10.15 10:08:00 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsta.dll
[2014.10.15 10:08:00 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2014.10.15 10:07:31 | 006,584,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2014.10.15 10:07:30 | 005,703,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2014.10.15 10:07:29 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rastls.dll
[2014.10.15 10:07:29 | 000,372,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastls.dll
[2014.10.15 10:07:27 | 003,241,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2014.10.15 10:06:42 | 001,943,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll
[2014.10.15 10:06:42 | 001,131,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll
[2014.10.15 10:06:42 | 000,156,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscorier.dll
[2014.10.15 10:06:42 | 000,156,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscorier.dll
[2014.10.15 10:06:42 | 000,081,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscories.dll
[2014.10.15 10:06:42 | 000,073,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscories.dll
[2014.10.15 09:59:36 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll
[2014.10.15 09:59:36 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll
[2014.10.14 00:24:22 | 000,000,000 | -HSD | C] -- C:\Users\Dexter\AppData\Local\EmieUserList
[2014.10.14 00:24:22 | 000,000,000 | -HSD | C] -- C:\Users\Dexter\AppData\Local\EmieSiteList
[2 C:\Users\Dexter\Desktop\*.tmp files -> C:\Users\Dexter\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014.11.12 11:35:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.11.12 10:46:35 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2014.11.12 10:39:06 | 000,022,448 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.11.12 10:39:06 | 000,022,448 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.11.12 10:31:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.11.11 12:27:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dexter\Desktop\OTL.exe
[2014.10.29 23:07:08 | 000,010,672 | ---- | M] () -- C:\Users\Dexter\Desktop\addition.RAR
[2014.10.29 22:04:41 | 002,113,536 | ---- | M] (Farbar) -- C:\Users\Dexter\Desktop\FRST64.exe
[2014.10.29 20:35:59 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.10.29 14:04:34 | 000,001,480 | ---- | M] () -- C:\Users\Dexter\AppData\Local\Adobe Uložit pro web 12.0 Prefs
[2014.10.28 21:07:17 | 001,584,626 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014.10.28 21:07:17 | 000,668,882 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2014.10.28 21:07:17 | 000,654,270 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014.10.28 21:07:17 | 000,141,542 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2014.10.28 21:07:17 | 000,122,142 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014.10.28 01:23:05 | 000,001,102 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.10.27 20:04:19 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014.10.27 20:04:07 | 001,998,336 | ---- | M] () -- C:\Users\Dexter\Desktop\adwcleaner_4.002.exe
[2014.10.26 16:06:16 | 001,222,144 | ---- | M] () -- C:\Users\Dexter\Desktop\RSITx64.exe
[2014.10.18 20:18:22 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014.10.18 20:18:22 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014.10.15 10:42:08 | 005,029,912 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014.10.14 11:35:01 | 000,024,137 | ---- | M] () -- C:\Users\Dexter\Desktop\1891099_299739706898054_6598122829396492814_n.jpg
[2 C:\Users\Dexter\Desktop\*.tmp files -> C:\Users\Dexter\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.11.11 12:37:25 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2014.10.29 23:06:47 | 000,010,672 | ---- | C] () -- C:\Users\Dexter\Desktop\addition.RAR
[2014.10.27 20:04:07 | 001,998,336 | ---- | C] () -- C:\Users\Dexter\Desktop\adwcleaner_4.002.exe
[2014.10.14 11:35:01 | 000,024,137 | ---- | C] () -- C:\Users\Dexter\Desktop\1891099_299739706898054_6598122829396492814_n.jpg
[2014.08.13 11:02:21 | 000,000,218 | ---- | C] () -- C:\Users\Dexter\AppData\Local\recently-used.xbel
[2013.12.18 13:49:11 | 000,000,132 | ---- | C] () -- C:\Users\Dexter\AppData\Roaming\Adobe Formát BMP CS5 – předvolby
[2013.11.21 14:09:14 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\BarExpert.exe
[2013.09.05 10:19:02 | 000,444,283 | ---- | C] () -- C:\Program Files\Common Files\WinPcapNmap.exe
[2013.05.30 13:17:16 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2013.04.02 18:23:24 | 000,004,096 | -H-- | C] () -- C:\Users\Dexter\AppData\Local\keyfile3.drm
[2013.03.20 16:35:42 | 000,000,132 | ---- | C] () -- C:\Users\Dexter\AppData\Roaming\Adobe Formát Targa CS5 – předvolby
[2013.03.07 23:24:55 | 000,074,703 | ---- | C] () -- C:\Windows\SysWow64\mfc45.dll
[2013.02.05 23:26:02 | 000,013,030 | ---- | C] () -- C:\Users\Dexter\AppData\Roaming\PDOXUSRS.NET
[2013.01.13 22:14:05 | 001,559,340 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.01.05 11:44:34 | 000,007,605 | ---- | C] () -- C:\Users\Dexter\AppData\Local\resmon.resmoncfg
[2012.09.10 19:57:07 | 000,000,398 | ---- | C] () -- C:\Users\Dexter\AppData\Roaming\hexplorer.dat
[2012.09.10 19:57:07 | 000,000,004 | ---- | C] () -- C:\Users\Dexter\AppData\Roaming\mclip.dat
[2012.07.30 13:30:47 | 000,000,132 | ---- | C] () -- C:\Users\Dexter\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
[2012.03.30 09:31:00 | 000,000,132 | ---- | C] () -- C:\Users\Dexter\AppData\Roaming\Adobe Formát GIF CS5 – předvolby
[2012.01.30 00:06:21 | 000,001,480 | ---- | C] () -- C:\Users\Dexter\AppData\Local\Adobe Uložit pro web 12.0 Prefs
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014.06.25 03:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014.06.25 02:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014.01.24 00:46:34 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Aegisub
[2012.02.02 01:21:16 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Aladdin Systems
[2012.05.22 23:57:10 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Amazon
[2013.10.23 11:43:11 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\AVAST Software
[2012.08.12 20:00:54 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\avidemux
[2012.05.20 16:24:47 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Barnes & Noble
[2012.05.08 18:41:06 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Canneverbe Limited
[2014.01.14 15:23:16 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\chc
[2012.01.29 20:15:11 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2013.08.22 08:02:34 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\CheckPoint
[2013.10.25 13:39:12 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\com.adobe.DC3Module.AdobeADC
[2012.03.06 02:01:13 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\com.adobe.dmp.contentviewer
[2012.05.22 01:43:28 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\com.rainwater-soft
[2012.01.29 01:25:41 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Extensis
[2014.10.29 14:07:53 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\FileZilla
[2014.01.24 00:46:30 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\fontconfig
[2014.02.21 03:58:40 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\In-Tools
[2014.08.13 11:02:58 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\inkscape
[2013.06.19 09:42:56 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\JAM Software
[2013.05.23 21:41:51 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Leadertech
[2012.12.31 20:49:12 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\MPEG Streamclip
[2012.08.15 23:12:45 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Opera
[2013.06.29 15:02:54 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Oracle
[2013.01.13 22:37:02 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\PANTONE
[2014.03.02 13:34:27 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Quite
[2013.06.29 17:26:44 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\SketchUp
[2012.03.25 00:45:55 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Software602
[2014.01.08 15:33:44 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\Spotify
[2012.01.29 20:28:48 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2013.09.05 10:19:35 | 000,000,000 | ---D | M] -- C:\Users\Dexter\AppData\Roaming\VDownloader
========== Purity Check ==========
< End of report >