OTL logfile created on: 5.8.2013 22:04:27 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = D:\stahování z internetu
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
8,00 Gb Total Physical Memory | 4,84 Gb Available Physical Memory | 60,55% Memory free
16,00 Gb Paging File | 12,49 Gb Available in Paging File | 78,07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97,56 Gb Total Space | 43,35 Gb Free Space | 44,43% Space Free | Partition Type: NTFS
Drive D: | 635,49 Gb Total Space | 600,25 Gb Free Space | 94,45% Space Free | Partition Type: NTFS
Drive E: | 198,36 Gb Total Space | 114,96 Gb Free Space | 57,95% Space Free | Partition Type: NTFS
Computer Name: DOMINIK-PC | User Name: dominik | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days
========== Processes (SafeList) ==========
PRC - [2013.08.05 22:03:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\stahování z internetu\OTL.exe
PRC - [2013.07.16 09:35:19 | 015,792,496 | ---- | M] (Wargaming.net) -- E:\Program Files (x86)\WoT\WorldOfTanks.exe
PRC - [2013.06.26 11:08:47 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013.03.08 16:07:36 | 000,506,864 | ---- | M] (MSI) -- C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
PRC - [2012.03.28 17:03:16 | 016,957,056 | ---- | M] (Winstep Software Technologies) -- C:\Program Files (x86)\Winstep\Nexus.exe
PRC - [2011.02.11 20:26:22 | 000,377,344 | ---- | M] (Winstep Software Technologies) -- C:\Program Files (x86)\Winstep\WsxService.exe
PRC - [2010.11.17 10:53:16 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
========== Modules (No Company Name) ==========
MOD - [2013.07.16 09:35:19 | 000,327,680 | ---- | M] () -- E:\Program Files (x86)\WoT\voip.dll
MOD - [2013.07.16 09:35:19 | 000,321,520 | ---- | M] () -- E:\Program Files (x86)\WoT\ortp.dll
MOD - [2013.06.26 11:08:27 | 003,285,912 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2013.06.12 13:05:20 | 000,270,336 | ---- | M] () -- E:\Program Files (x86)\WoT\libcurl.dll
MOD - [2012.02.22 10:41:36 | 001,085,376 | ---- | M] () -- C:\Program Files (x86)\Winstep\wodTelnetDLX.dll
========== Services (SafeList) ==========
SRV:
64bit: - [2013.06.20 20:33:08 | 000,366,600 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:
64bit: - [2013.06.20 20:33:08 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:
64bit: - [2013.05.27 07:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2013.03.29 03:34:18 | 000,241,152 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:
64bit: - [2013.03.28 22:30:42 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:
64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2013.06.26 11:08:46 | 000,117,144 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.06.12 20:25:36 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.04.18 11:06:42 | 000,737,616 | ---- | M] (Nokia) [Disabled | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2013.02.20 11:47:14 | 000,161,264 | ---- | M] (MSI) [Disabled | Stopped] -- C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe -- (MSI_SuperCharger)
SRV - [2012.09.23 21:43:34 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012.07.09 00:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2011.02.11 20:26:22 | 000,377,344 | ---- | M] (Winstep Software Technologies) [Auto | Running] -- C:\Program Files (x86)\Winstep\WsxService.exe -- (Winstep Xtreme Service)
SRV - [2010.02.19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2013.06.18 21:50:08 | 000,139,616 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:
64bit: - [2013.05.04 07:28:29 | 000,564,824 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:
64bit: - [2013.04.10 11:09:24 | 000,849,992 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:
64bit: - [2013.03.29 04:35:02 | 011,658,752 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:
64bit: - [2013.03.29 03:09:44 | 000,581,120 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:
64bit: - [2013.03.22 21:52:31 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:
64bit: - [2013.02.14 13:41:10 | 000,096,768 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:
64bit: - [2013.01.23 10:31:52 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc)
DRV:
64bit: - [2013.01.23 10:31:52 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd)
DRV:
64bit: - [2013.01.23 10:31:52 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt)
DRV:
64bit: - [2013.01.23 10:31:52 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev)
DRV:
64bit: - [2012.10.17 14:53:46 | 000,026,112 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:
64bit: - [2012.08.23 16:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:
64bit: - [2012.08.23 16:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2012.04.09 10:13:58 | 000,057,472 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.2)
DRV:
64bit: - [2012.04.09 10:13:58 | 000,057,472 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.1)
DRV:
64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2011.04.15 15:37:50 | 000,079,488 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:
64bit: - [2011.04.15 15:37:50 | 000,040,064 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:
64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2011.02.10 15:52:34 | 000,181,760 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:
64bit: - [2011.02.10 15:52:34 | 000,082,432 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:
64bit: - [2010.11.29 04:50:38 | 000,044,672 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:
64bit: - [2010.11.20 06:33:36 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010.11.20 03:43:58 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:
64bit: - [2010.06.17 18:15:36 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie64.sys -- (AtiPcie)
DRV:
64bit: - [2010.02.18 10:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:
64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2012.10.25 20:45:52 | 000,013,368 | ---- | M] (MSI) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys -- (NTIOLib_1_0_3)
DRV - [2010.10.22 10:37:36 | 000,014,136 | ---- | M] (MSI) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys -- (NTIOLib_1_0_4)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://websearch.searchesplace.info/?pi ... Z&unqvl=30
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" =
http://websearch.searchesplace.info/?l= ... Z&unqvl=30
IE - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://websearch.searchesplace.info/?pi ... Z&unqvl=30
IE - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - No CLSID value found
IE - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001\..\SearchScopes,DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IE10SR
IE - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001\..\SearchScopes\{936EBED9-5294-4096-8258-1A7EE65FCFCC}: "URL" =
http://www.google.com/search?q={searchT ... utEncoding?}
IE - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001\..\SearchScopes\{B102FA15-A8F4-4A9A-AD3A-1D72375CCEFA}: "URL" =
http://www.mysearchresults.com/search?c ... earchTerms}
IE - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" =
http://websearch.searchesplace.info/?l= ... Z&unqvl=30
IE - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001\..\SearchScopes\{CC466DE6-EA26-417A-9B6D-EB0FA29775C3}: "URL" =
http://websearch.ask.com/redirect?clien ... 2516216B94
IE - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "WebSearch"
FF - prefs.js..browser.search.defaultenginename,S: S", "WebSearch"
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: "
http://websearch.searchesplace.info/?pi ... =30&l=1&q="
FF - prefs.js..browser.search.order.1: "WebSearch"
FF - prefs.js..browser.search.order.1,S: S", "WebSearch"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.selectedEngine,S: S", "WebSearch"
FF - prefs.js..browser.startup.homepage: "
http://www.seznam.cz/"
FF - prefs.js..extensions.enabledAddons: translator%40zoli.bod:2.1.0.3
FF - prefs.js..extensions.enabledAddons: djziggy%40gmail.com:2.0.8
FF - prefs.js..keyword.URL: "
http://websearch.searchesplace.info/?pi ... =30&l=1&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: ""
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF:
64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\dominik\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2013.03.19 03:38:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dominik\AppData\Roaming\Mozilla\Extensions
[2013.06.30 20:44:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dominik\AppData\Roaming\Mozilla\Firefox\Profiles\g4q29tra.default-1363656536534\extensions
[2013.08.04 12:53:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dominik\AppData\Roaming\Mozilla\Firefox\Profiles\p2ixt51r.default-1374902621756\extensions
[2013.07.27 07:41:37 | 000,000,000 | ---D | M] (LavaFox V2-Blue) -- C:\Users\dominik\AppData\Roaming\Mozilla\Firefox\Profiles\p2ixt51r.default-1374902621756\extensions\
djziggy@gmail.com
[2013.07.27 10:38:30 | 000,060,290 | ---- | M] () (No name found) -- C:\Users\dominik\AppData\Roaming\Mozilla\Firefox\Profiles\p2ixt51r.default-1374902621756\extensions\
translator@zoli.bod.xpi
[2013.07.31 09:58:03 | 000,824,302 | ---- | M] () (No name found) -- C:\Users\dominik\AppData\Roaming\Mozilla\Firefox\Profiles\p2ixt51r.default-1374902621756\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013.08.04 12:51:50 | 000,007,849 | ---- | M] () -- C:\Users\dominik\AppData\Roaming\Mozilla\Firefox\Profiles\p2ixt51r.default-1374902621756\searchplugins\WebSearch.xml
[2013.06.26 11:08:23 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013.06.26 11:08:47 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
CHR - homepage:
http://websearch.searchesplace.info/?pi ... Z&unqvl=30
CHR - Extension: SearchNewTab = C:\Users\dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\amofjppaafijeadihifkinhppkamfmhp\1\
CHR - Extension: SavEnsohhare = C:\Users\dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\eabmejbgkanemgeekldaebphkhdiehoa\1\
O1 HOSTS File: ([2012.04.24 20:36:08 | 000,001,836 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
O1 - Hosts: 127.0.0.1
www.adobeereg.com wwis-dubc1-vip60.adobe.com
www.wip.adobe.com www.wip1.adobe.com
O1 - Hosts: 127.0.0.1
www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe (MSI)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001..\Run: [] File not found
O4 - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001..\Run: [Nexus] C:\Program Files (x86)\Winstep\Nexus.exe (Winstep Software Technologies)
O4 - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001..\Run: [tsiVideo] C:\Windows\SysWOW64\rundll32.exe C:\Users\dominik\AppData\Local\Temp\\tsiVi032.dll,start File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-2346373696-3514916518-1655548664-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 109.108.107.106 109.108.109.108
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{000837CA-B460-4FC1-8AAF-CF08892FCC25}: DhcpNameServer = 109.108.107.106 109.108.109.108
O20 - AppInit_DLLs: (c:\progra~2\savesh~1\sprote~1.dll) - File not found
O20 - AppInit_DLLs: (c:\progra~2\websea~1\sprote~1.dll) - File not found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{8703b4fb-92e1-11e2-ab6f-40618692a4cb}\Shell - "" = AutoRun
O33 - MountPoints2\{8703b4fb-92e1-11e2-ab6f-40618692a4cb}\Shell\AutoRun\command - "" = G:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs:
64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:
64bit: msacm.bdmpeg - bdmpega64.acm ()
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:
64bit: vidc.mjpg - bdmjpeg64.dll ()
Drivers32:
64bit: vidc.mpeg - bdmpegv64.dll ()
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.bdmpeg - C:\Windows\SysWow64\bdmpega.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS
http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.LAGS - C:\Windows\SysWow64\lagarith.dll ( )
Drivers32: vidc.mjpg - C:\Windows\SysWow64\bdmjpeg.dll ()
Drivers32: vidc.mpeg - C:\Windows\SysWow64\bdmpegv.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 7 Days ==========
[2013.08.05 18:14:15 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2013.08.05 18:14:14 | 000,000,000 | ---D | C] -- C:\rsit
[2013.08.05 12:29:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2013.08.05 04:41:46 | 000,000,000 | ---D | C] -- C:\Users\dominik\AppData\Roaming\Malwarebytes
[2013.08.05 04:41:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.08.05 03:49:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reFX
[2013.08.05 03:49:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Digidesign
[2013.08.04 23:23:06 | 002,440,704 | ---- | C] (AD © 2010) -- C:\Windows\SysWow64\SYNSOEMU.DLL
[2013.08.04 15:11:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\reFX
[2013.08.04 15:04:42 | 000,400,384 | ---- | C] (reFX CrackerX) -- C:\Windows\SysNative\CRACKNEX.dll
[2013.08.04 12:51:45 | 000,000,000 | ---D | C] -- C:\ProgramData\StarApp
[2013.08.04 12:51:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WebSearch
[2013.08.04 12:51:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SaveShare
[2013.08.04 11:43:25 | 000,000,000 | ---D | C] -- C:\Users\dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Drakensang Online
[2013.07.30 23:21:53 | 000,000,000 | ---D | C] -- C:\Users\dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
[2013.07.30 23:21:51 | 000,000,000 | ---D | C] -- C:\Program Files\Image-Line
[2013.07.30 23:21:42 | 001,554,944 | ---- | C] (HMS
http://hp.vector.co.jp/authors/VA012897/) -- C:\Windows\SysWow64\vorbis.acm
[2013.07.30 23:21:37 | 000,000,000 | ---D | C] -- C:\Users\dominik\AppData\Roaming\FlowStone
[2013.07.30 23:21:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DSPRobotics
[2013.07.30 11:44:05 | 000,000,000 | ---D | C] -- C:\Users\dominik\AppData\Local\cache
[2013.07.30 11:44:01 | 000,000,000 | ---D | C] -- C:\Users\dominik\AppData\Local\FullTiltPoker
[2013.07.30 10:41:33 | 000,000,000 | ---D | C] -- C:\Users\dominik\AppData\Roaming\Media Player Classic
========== Files - Modified Within 7 Days ==========
[2013.08.05 22:05:43 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013.08.05 20:52:34 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.08.05 20:52:34 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.08.05 10:26:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.08.04 16:24:32 | 000,000,520 | ---- | M] () -- C:\Windows\netdet.ini
[2013.08.04 11:43:25 | 000,001,972 | ---- | M] () -- C:\Users\dominik\Desktop\Drakensang Online.lnk
[2013.07.30 23:22:12 | 000,000,939 | ---- | M] () -- C:\Users\Public\Desktop\FL Studio 11.lnk
========== Files Created - No Company Name ==========
[2013.08.05 22:05:43 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2013.07.30 23:22:12 | 000,000,939 | ---- | C] () -- C:\Users\Public\Desktop\FL Studio 11.lnk
[2013.07.30 23:21:50 | 000,000,939 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FL Studio 11.lnk
[2013.07.28 13:40:34 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013.07.25 14:33:02 | 001,559,340 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.07.02 19:09:17 | 000,008,192 | -HS- | C] () -- C:\Windows\o2cLicStore.bin
[2013.07.02 19:09:17 | 000,000,520 | ---- | C] () -- C:\Windows\netdet.ini
[2013.06.07 19:28:36 | 000,000,132 | ---- | C] () -- C:\Users\dominik\AppData\Roaming\Adobe Formát GIF CS6 – předvolby
[2013.05.15 18:13:54 | 000,000,896 | RHS- | C] () -- C:\Users\dominik\ntuser.pol
[2013.03.29 04:13:14 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013.03.29 04:13:12 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013.03.29 03:38:08 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.03.29 03:38:08 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.03.24 13:52:13 | 000,000,281 | ---- | C] () -- C:\Windows\EReg072.dat
[2013.03.22 21:54:59 | 000,000,530 | ---- | C] () -- C:\Windows\eReg.dat
[2013.02.10 15:27:26 | 000,000,409 | ---- | C] () -- C:\Windows\MSUTIL.INI
[2013.02.02 15:26:18 | 000,007,625 | ---- | C] () -- C:\Users\dominik\AppData\Local\Resmon.ResmonCfg
[2013.02.02 12:43:52 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2013.02.02 12:43:52 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2013.02.02 12:43:52 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2013.02.02 12:43:51 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2013.02.02 12:43:48 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2013.02.02 12:26:49 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI
[2013.02.02 01:42:25 | 000,000,132 | ---- | C] () -- C:\Users\dominik\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
[2012.11.27 01:18:46 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.11.19 09:33:32 | 000,065,656 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
[2012.11.19 09:33:30 | 000,022,640 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll
[2012.07.02 22:11:02 | 000,016,384 | ---- | C] () -- C:\Windows\SysWow64\theowl.dll
[2012.02.03 05:00:58 | 000,139,264 | ---- | C] () -- C:\Windows\SysWow64\TCPClient.dll
[2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 05:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.07.21 08:35:31 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\BANDISOFT
[2013.07.27 17:57:08 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Canneverbe Limited
[2013.02.01 21:46:10 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013.08.05 00:21:46 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\DAEMON Tools Lite
[2013.07.30 23:21:38 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\FlowStone
[2013.06.08 12:01:07 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\GenArts
[2013.03.20 13:10:05 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\HD Tune Pro
[2013.02.04 04:17:35 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Image-Line
[2013.01.30 12:46:35 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\IObit
[2013.03.29 01:31:54 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\IsolatedStorage
[2013.05.30 18:01:21 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\LolClient
[2013.06.27 14:17:35 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Milestone
[2013.05.13 12:19:37 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Nokia
[2013.02.02 12:26:49 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\PACE Anti-Piracy
[2013.05.13 12:19:33 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\PC Suite
[2013.04.17 07:53:07 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\poclbm
[2013.02.01 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Red Giant Link
[2013.02.28 01:18:52 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2013.02.15 00:05:10 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\SynthMaker
[2013.02.13 19:30:28 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Unity
[2013.01.30 20:20:46 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Wargaming.net
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009.07.14 07:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 07:08:49 | 000,032,594 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2013.04.21 13:34:12 | 000,000,914 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
< >
< MD5 for: ATAPI.SYS >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010.11.20 06:24:28 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.20 06:24:28 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2010.11.20 05:16:56 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.20 05:16:56 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2010.11.20 02:19:22 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.20 02:19:22 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.20 02:19:22 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2011.02.26 07:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 08:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 08:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 05:17:10 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.20 06:24:46 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: HAL.DLL >
[2010.11.20 06:33:36 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.20 06:33:36 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: SCECLI.DLL >
[2010.11.20 05:21:06 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.20 05:21:06 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.20 06:27:26 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.20 06:27:26 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SERVICES.EXE >
[2009.07.14 03:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009.07.14 03:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SVCHOST.EXE >
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2012.10.03 19:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_110e0fbd7d2e4b88\tcpip.sys
[2013.05.08 08:14:42 | 001,900,392 | ---- | M] (Microsoft Corporation) MD5=3E94650745D4DAB67E161F5F32CEA597 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22319_none_11d29984961f0be0\tcpip.sys
[2010.11.20 06:33:58 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2012.08.22 20:06:13 | 001,901,936 | ---- | M] (Microsoft Corporation) MD5=7880A26B7D3B96FDA8EFD9F985036B1D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22097_none_117a13de9661c145\tcpip.sys
[2012.03.30 12:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
[2013.05.08 08:39:01 | 001,910,632 | ---- | M] (Microsoft Corporation) MD5=9849EA3843A2ADBDD1497E97A85D8CAE -- C:\Windows\SysNative\drivers\tcpip.sys
[2013.05.08 08:39:01 | 001,910,632 | ---- | M] (Microsoft Corporation) MD5=9849EA3843A2ADBDD1497E97A85D8CAE -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18148_none_11278ac57d1aa96b\tcpip.sys
[2012.03.30 13:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
[2013.01.03 08:00:54 | 001,913,192 | ---- | M] (Microsoft Corporation) MD5=B62A953F2BF3922C8764A29C34A22899 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18042_none_112187237d20143a\tcpip.sys
[2013.01.04 07:47:43 | 001,901,416 | ---- | M] (Microsoft Corporation) MD5=B8C1AAC0523E1C33AEB0EF7572144BA2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22209_none_11dd678a9616f2c8\tcpip.sys
[2012.10.03 19:44:29 | 001,902,472 | ---- | M] (Microsoft Corporation) MD5=D5707FC2300AA5B04B7BFE86D40C0133 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_11c2c45a962baed0\tcpip.sys
[2012.08.22 20:12:50 | 001,913,200 | ---- | M] (Microsoft Corporation) MD5=F782CAD3CEDBB3F9FFE3BF2775D92DDC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17939_none_113380f37d117668\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010.11.20 05:17:50 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 05:17:50 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.20 06:25:26 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 06:25:26 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010.11.20 06:25:32 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 06:25:32 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< >
< %systemroot%*.* /U /s >
[3 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[6 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[1 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2013.03.11 01:12:14 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Adobe
[2013.02.11 03:24:13 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Apple Computer
[2013.07.28 13:40:45 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\ATI
[2013.07.21 08:35:31 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\BANDISOFT
[2013.07.27 17:57:08 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Canneverbe Limited
[2013.02.01 21:46:10 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013.08.05 00:21:46 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\DAEMON Tools Lite
[2013.07.30 23:21:38 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\FlowStone
[2013.06.08 12:01:07 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\GenArts
[2013.03.20 13:10:05 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\HD Tune Pro
[2013.01.30 01:38:30 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Identities
[2013.02.04 04:17:35 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Image-Line
[2013.01.30 12:46:35 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\IObit
[2013.03.29 01:31:54 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\IsolatedStorage
[2013.05.30 18:01:21 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\LolClient
[2013.01.30 12:38:13 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Macromedia
[2013.08.05 04:41:46 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Malwarebytes
[2009.07.14 17:36:38 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Media Center Programs
[2013.08.05 00:21:46 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Media Player Classic
[2013.08.03 21:53:01 | 000,000,000 | --SD | M] -- C:\Users\dominik\AppData\Roaming\Microsoft
[2013.06.27 14:17:35 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Milestone
[2013.03.19 03:38:50 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Mozilla
[2013.05.13 12:19:37 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Nokia
[2013.02.02 12:26:49 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\PACE Anti-Piracy
[2013.05.13 12:19:33 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\PC Suite
[2013.04.17 07:53:07 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\poclbm
[2013.02.01 13:48:58 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Red Giant Link
[2013.07.27 12:39:28 | 000,000,000 | RH-D | M] -- C:\Users\dominik\AppData\Roaming\SecuROM
[2013.02.28 01:18:52 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2013.02.15 00:05:10 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\SynthMaker
[2013.02.13 19:30:28 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Unity
[2013.01.30 20:20:46 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\Wargaming.net
[2013.01.30 02:42:00 | 000,000,000 | ---D | M] -- C:\Users\dominik\AppData\Roaming\WinRAR
< %APPDATA%\*.exe /s >
[2013.02.02 00:32:41 | 000,055,424 | ---- | M] (Adobe Systems Inc.) -- C:\Users\dominik\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2013.02.01 13:48:51 | 000,262,144 | ---- | M] () -- C:\Users\dominik\AppData\Roaming\Red Giant Link\tools\RGLicenseCheck.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job >
[2013.06.13 05:23:54 | 000,000,914 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"AdobeBridge" =
"Nexus" = C:\Program Files (x86)\Winstep\Nexus.exe autostart -- [2012.03.28 17:03:16 | 016,957,056 | ---- | M] (Winstep Software Technologies)
"" =
"tsiVideo" = C:\Windows\SysWOW64\rundll32.exe C:\Users\dominik\AppData\Local\Temp\\tsiVi032.dll,start -- [2009.07.14 03:14:31 | 000,044,544 | ---- | M] (Microsoft Corporation)
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
[2013.06.26 11:08:47 | 000,920,472 | ---- | M] (Mozilla Corporation) MD5=C8D28F8B498CADBB9445AC4545BD41B7 -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2013.06.12 02:23:57 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.08.05 22:05:43 | 000,000,512 | ---- | M] () MD5=6B5B61628D317E3539375CE5F97AACF5 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2012.04.21 15:59:07 | 001,306,290 | ---- | M] () -- \software\AAE-projedts\VideoHive Mega Collection Pack 3-BLUEPLANET\videohive_Urban-of-the-cinematic\Assets\Environement Textures\Concrete Crack.jpg
[2009.11.30 20:31:05 | 003,096,763 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_01.mov
[2009.11.30 22:37:43 | 004,551,510 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_02.mov
[2009.11.30 22:37:56 | 004,492,767 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_03.mov
[2009.11.30 19:58:24 | 003,459,479 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_04.mov
[2009.11.30 20:31:05 | 003,179,829 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_05.mov
[2009.11.30 18:58:10 | 002,592,017 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_06.mov
[2009.11.30 20:33:19 | 003,082,263 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_07.mov
[2009.11.30 21:24:16 | 002,995,649 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_08.mov
[2009.11.30 20:12:18 | 002,699,493 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_09.mov
[2009.11.30 21:06:07 | 002,488,734 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_10.mov
[2009.11.30 20:12:18 | 002,608,502 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_11.mov
[2009.11.30 22:35:34 | 002,856,210 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_12.mov
[2009.11.30 21:06:07 | 002,509,509 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_13.mov
[2009.11.30 18:58:51 | 002,792,158 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_14.mov
[2009.11.30 21:45:27 | 002,196,137 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\16. Sparks\FireCracker_15.mov
[2009.11.30 20:03:55 | 000,111,594 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_01.jpg
[2009.11.30 20:03:55 | 000,108,963 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_02.jpg
[2009.11.30 20:03:55 | 000,107,869 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_03.jpg
[2009.11.30 20:03:55 | 000,104,605 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_04.jpg
[2009.11.30 20:03:55 | 000,093,997 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_05.jpg
[2009.11.30 20:03:55 | 000,126,376 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_06.jpg
[2009.11.30 20:03:55 | 000,118,902 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_07.jpg
[2009.11.30 20:03:55 | 000,104,510 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_08.jpg
[2009.11.30 20:03:55 | 000,085,621 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_09.jpg
[2009.11.30 20:03:55 | 000,152,988 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_10.jpg
[2009.11.30 20:03:55 | 000,107,645 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_11.jpg
[2009.11.30 20:47:07 | 000,160,512 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_12.jpg
[2009.11.30 20:03:55 | 000,093,142 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_13.jpg
[2009.11.30 20:03:55 | 000,105,132 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Cracks\Ground_Crack_14.jpg
[2009.11.30 20:34:36 | 000,565,096 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Windshields\Glass_Cracks_01.jpg
[2009.11.30 22:36:39 | 001,160,984 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Windshields\Glass_Cracks_02.jpg
[2009.11.30 22:36:39 | 001,469,487 | ---- | M] () -- \software\Action Essentials 2\Action_Essentials_720p\20. Textures\Windshields\Glass_Cracks_03.jpg
[2009.11.30 19:24:21 | 000,713,390 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_01.mp4
[2009.11.30 19:24:21 | 000,711,341 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_02.mp4
[2009.11.30 18:58:35 | 000,736,017 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_03.mp4
[2009.11.30 19:24:21 | 000,714,475 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_04.mp4
[2009.11.30 20:00:32 | 000,721,673 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_05.mp4
[2009.11.30 19:24:21 | 000,712,739 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_06.mp4
[2009.11.30 20:00:32 | 000,720,995 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_07.mp4
[2009.11.30 20:00:32 | 000,722,650 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_08.mp4
[2009.11.30 18:57:58 | 000,717,232 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_09.mp4
[2009.11.30 18:57:58 | 000,714,980 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_10.mp4
[2009.11.30 18:57:58 | 000,719,415 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_11.mp4
[2009.11.30 20:00:32 | 000,727,484 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_12.mp4
[2009.11.30 18:57:58 | 000,717,181 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_13.mp4
[2009.11.30 20:00:32 | 000,727,358 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_14.mp4
[2009.11.30 18:57:58 | 000,715,397 | ---- | M] () -- \software\Action Essentials 2\Video_Thumbnails\16. Sparks\FireCracker_15.mp4
[2013.02.09 11:57:05 | 000,033,045 | ---- | M] () -- \software\Editing packs\Editing pack vol. 10\Zvuky\01327_SFX - lámání,cracking.mp3
[2011.01.12 15:36:00 | 000,243,712 | ---- | M] () -- \software\Optical Flares\OpticalFlaresCrack(Spider) 1.2.132.exe
[2013.03.11 03:50:24 | 000,000,590 | ---- | M] () -- \software\VCFlaresBundle 1.3.3\Crack\crack.txt
[2013.02.03 15:59:30 | 003,699,294 | ---- | M] () -- \software\Video.Copilot.Element.3D.v1.5.WiN\Crack.rar
< *keygen* /s >
< *loader* /s >
[2002.05.26 11:40:58 | 000,013,824 | ---- | M] () -- \software\ArCon v.6 + Tiler 2.2 CZ + Katalogy_\Arcon 6.02 CZ\crack\loader.exe
[2010.07.19 20:11:57 | 000,011,927 | ---- | M] () -- \software\ArCon v.6 + Tiler 2.2 CZ + Katalogy_\Arcon 6.02 CZ\crack\loader.rar
========== Alternate Data Streams ==========
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:66BB1E73
@Alternate Data Stream - 1143 bytes -> C:\ProgramData\Microsoft:oSClbidpucKhLVdkzXxmUEScc
@Alternate Data Stream - 1026 bytes -> C:\ProgramData\Microsoft:nQLbaVX5ngJZNEpetyEjGy1p
< End of report >