

Spoiler:
OTL logfile created on: 2016-06-11 13:13:43 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\julia\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18314)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
4,00 Gb Total Physical Memory | 2,35 Gb Available Physical Memory | 58,77% Memory free
7,99 Gb Paging File | 6,10 Gb Available in Paging File | 76,29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 195,41 Gb Total Space | 86,66 Gb Free Space | 44,35% Space Free | Partition Type: NTFS
Drive D: | 270,25 Gb Total Space | 202,21 Gb Free Space | 74,82% Space Free | Partition Type: NTFS
Drive E: | 458,95 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: JULIA-KOMPUTER | User Name: julia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2016-06-11 13:00:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\julia\Desktop\OTL.exe
PRC - [2016-06-09 19:18:12 | 000,592,424 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\38.0.2220.29\opera_crashreporter.exe
PRC - [2016-06-09 19:18:11 | 000,710,184 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\38.0.2220.29\opera.exe
PRC - [2016-05-25 10:31:20 | 001,687,680 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2016-05-25 10:30:36 | 001,364,096 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2016-05-12 10:54:56 | 007,032,080 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
PRC - [2016-05-08 16:27:08 | 000,243,296 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2016-04-05 08:29:12 | 002,021,592 | ---- | M] (Adobe Systems, Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
PRC - [2016-01-19 05:02:38 | 000,388,968 | ---- | M] (Digital Wave Ltd.) -- C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
========== Modules (No Company Name) ==========
MOD - [2016-06-09 19:18:11 | 067,942,952 | ---- | M] () -- C:\Program Files (x86)\Opera\38.0.2220.29\opera.dll
MOD - [2016-06-09 19:17:57 | 002,203,176 | ---- | M] () -- C:\Program Files (x86)\Opera\38.0.2220.29\libglesv2.dll
MOD - [2016-06-09 19:17:56 | 000,087,080 | ---- | M] () -- C:\Program Files (x86)\Opera\38.0.2220.29\libegl.dll
========== Services (SafeList) ==========
SRV:64bit: - [2016-06-11 12:51:06 | 000,370,656 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
SRV:64bit: - [2016-05-08 16:27:08 | 000,243,296 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2016-04-23 06:47:35 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2015-07-23 02:02:54 | 001,390,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:64bit: - [2014-09-10 01:08:15 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012-10-19 11:01:04 | 000,581,120 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\atwtusb.exe -- (WTService)
SRV:64bit: - [2009-08-18 03:36:20 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2016-05-25 10:31:20 | 001,687,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2016-05-25 10:30:36 | 001,364,096 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2016-05-13 15:04:13 | 000,269,504 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2016-05-12 10:54:56 | 007,032,080 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe -- (TeamViewer)
SRV - [2016-04-30 02:10:40 | 000,835,664 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2016-04-05 08:29:12 | 002,021,592 | ---- | M] (Adobe Systems, Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe -- (AGSService)
SRV - [2016-03-23 19:08:24 | 000,327,808 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2016-01-19 05:02:38 | 000,388,968 | ---- | M] (Digital Wave Ltd.) [Auto | Running] -- C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe -- (DigitalWave.Update.Service)
SRV - [2016-01-15 16:58:50 | 001,369,464 | ---- | M] (Disc Soft Ltd) [On_Demand | Stopped] -- D:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe -- (Disc Soft Lite Bus Service)
SRV - [2016-01-11 20:49:01 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2014-09-10 01:22:08 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014-04-11 23:08:08 | 000,103,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2016-06-11 12:51:06 | 000,536,312 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\aswNetSec.sys -- (aswNetSec)
DRV:64bit: - [2016-05-08 16:31:50 | 000,037,144 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswKbd.sys -- (aswKbd)
DRV:64bit: - [2016-05-08 16:27:15 | 000,465,792 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2016-05-08 16:27:15 | 000,287,528 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2016-05-08 16:27:15 | 000,166,432 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2016-05-08 16:27:15 | 000,107,792 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2016-05-08 16:27:15 | 000,103,064 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2016-05-08 16:27:15 | 000,074,544 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2016-05-08 16:27:15 | 000,037,656 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2016-05-08 16:26:57 | 001,070,904 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2016-01-24 02:19:57 | 000,047,672 | ---- | M] (Disc Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dtliteusbbus.sys -- (dtliteusbbus)
DRV:64bit: - [2015-12-22 23:06:16 | 000,030,264 | ---- | M] (Disc Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dtlitescsibus.sys -- (dtlitescsibus)
DRV:64bit: - [2015-06-17 18:04:24 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2014-09-10 01:16:06 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2014-09-10 01:16:06 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2014-09-10 01:15:16 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2014-09-10 01:15:16 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2014-09-10 01:12:37 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2014-09-10 01:12:37 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2014-09-10 01:00:36 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2014-09-10 01:00:08 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2014-08-16 00:13:34 | 000,023,040 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2012-06-05 07:45:16 | 000,237,968 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2012-06-01 10:32:38 | 000,379,776 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\V0770Vid.sys -- (V0770Vid)
DRV:64bit: - [2011-11-03 03:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2011-08-23 15:57:24 | 000,565,352 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010-11-21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009-08-26 14:15:10 | 000,007,552 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\walvhid.sys -- (vhidmini)
DRV:64bit: - [2009-08-18 04:48:48 | 006,037,504 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009-03-08 20:16:14 | 000,007,680 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\moufiltr.sys -- (moufiltr)
DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_instalki
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/pl-pl/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pl-PL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F5 55 E5 65 03 3C D1 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.91.2: C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.91.2: C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll ( Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\julia\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2016-06-11 12:51:30 | 000,000,000 | ---D | M]
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\sp@avast.com: C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\SAFEPRICE\FF [2016-06-11 12:51:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-06-11 12:51:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\sp@avast.com: C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-06-11 12:51:29 | 000,000,000 | ---D | M]
[2016-02-10 17:02:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\julia\AppData\Roaming\mozilla\Extensions
========== Chrome ==========
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\11.1.0.221_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\11.1.0.955_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.0_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
O1 HOSTS File: ([2016-05-23 20:04:23 | 000,001,093 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 http://www.mirillis.com
O1 - Hosts: 127.0.0.1 s0ft4pc.com
O1 - Hosts: 127.0.0.1 serwer2.paka-service.com
O1 - Hosts: 127.0.0.1 down.baidu2016.com
O1 - Hosts: 127.0.0.1 123.sogou.com
O1 - Hosts: 127.0.0.1 http://www.czzsyzgm.com
O1 - Hosts: 127.0.0.1 http://www.czzsyzxl.com
O1 - Hosts: 127.0.0.1 union.baidu2019.com
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AtwtusbIcon] C:\Windows\SysNative\AtwtusbIcon.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [V0770Mon.exe] C:\Windows\V0770Mon.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKCU..\Run: [DAEMON Tools Lite Automount] D:\Program Files\DAEMON Tools Lite\DTAgent.exe (Disc Soft Ltd)
O4 - HKCU..\Run: [Discord] C:\Users\julia\AppData\Local\Discord\app-0.0.291\Discord.exe (Hammer & Chisel, Inc.)
O4 - HKCU..\Run: [Steam] D:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O9:64bit: - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.61 62.179.1.63
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{81AAB8BC-A6E0-420D-9F03-96295BCE5CE6}: DhcpNameServer = 62.179.1.61 62.179.1.63
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C0F5FDB1-ECBA-425E-B40E-733B892C23AA}: DhcpNameServer = 192.168.42.129
O18:64bit: - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2015-12-28 01:25:44 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006-03-03 16:54:53 | 000,000,031 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{0c9d5e4a-c9b4-11e5-9fa8-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{0c9d5e4a-c9b4-11e5-9fa8-fcaa14bb116e}\Shell\AutoRun\command - "" = J:\
O33 - MountPoints2\{0c9d5e55-c9b4-11e5-9fa8-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{0c9d5e55-c9b4-11e5-9fa8-fcaa14bb116e}\Shell\AutoRun\command - "" = K:\
O33 - MountPoints2\{4e7f5e15-c751-11e5-97e7-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{4e7f5e15-c751-11e5-97e7-fcaa14bb116e}\Shell\AutoRun\command - "" = J:\
O33 - MountPoints2\{6fc04ccc-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04ccc-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = H:\autorun.exe
O33 - MountPoints2\{6fc04de3-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04de3-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = I:\Autorun.exe
O33 - MountPoints2\{6fc04df9-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04df9-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = J:\Autorun.exe
O33 - MountPoints2\{6fc04dfd-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04dfd-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = K:\autorun.exe
O33 - MountPoints2\{6fc04e19-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04e19-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = H:\
O33 - MountPoints2\{6fc04e24-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04e24-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = I:\Autorun.exe
O33 - MountPoints2\{6fc04e38-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04e38-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = J:\
O33 - MountPoints2\{e5032bf7-c1f3-11e5-973c-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{e5032bf7-c1f3-11e5-973c-fcaa14bb116e}\Shell\AutoRun\command - "" = H:\startme.exe
O33 - MountPoints2\{e5032ced-c1f3-11e5-973c-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{e5032ced-c1f3-11e5-973c-fcaa14bb116e}\Shell\AutoRun\command - "" = H:\Launch.exe
O33 - MountPoints2\{fa51d0e0-a828-11e5-9068-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{fa51d0e0-a828-11e5-9068-806e6f6e6963}\Shell\AutoRun\command - "" = E:\VCD_PLAY.EXE -- [2006-03-03 16:56:01 | 000,462,848 | R--- | M] (Roxio)
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\Launch.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2016-06-11 13:06:43 | 000,000,000 | ---D | C] -- C:\FRST
[2016-06-11 13:03:43 | 002,385,408 | ---- | C] (Farbar) -- C:\Users\julia\Desktop\FRST64.exe
[2016-06-11 13:01:43 | 000,000,000 | ---D | C] -- C:\_OTL
[2016-06-11 13:00:31 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\julia\Desktop\OTL.exe
[2016-06-11 12:51:41 | 000,536,312 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswNetSec.sys
[2016-06-11 12:51:30 | 000,398,152 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2016-06-11 12:43:47 | 000,056,208 | ---- | C] (Rovi Corporation) -- C:\Windows\SysNative\drivers\PxHlpa64.sys
[2016-06-11 12:43:47 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdralw2k.sys
[2016-06-11 12:43:47 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdr4_xp.sys
[2016-06-11 12:43:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared
[2016-06-11 12:43:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2016-06-11 12:43:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\My Company Name
[2016-06-11 12:43:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2016-06-11 10:46:28 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\dash
[2016-06-09 23:31:57 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\cenzura!
[2016-06-09 19:30:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2016-06-09 19:30:16 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2016-06-09 19:27:47 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2016-06-09 19:27:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2016-06-09 19:23:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2016-05-28 10:44:45 | 000,000,000 | ---D | C] -- C:\Users\julia\AppData\Local\Discord
[2016-05-26 16:49:37 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\Start
[2016-05-25 16:35:14 | 000,000,000 | ---D | C] -- C:\Users\julia\Documents\Electronic Arts
[2016-05-25 12:48:47 | 000,000,000 | ---D | C] -- C:\ProgramData\YTD Video Downloader
[2016-05-25 12:48:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader
[2016-05-25 12:48:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GreenTree Applications
[2016-05-24 19:36:25 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\light of your cutie mark
[2016-05-23 22:19:22 | 000,000,000 | ---D | C] -- C:\Users\julia\AppData\Local\Microsoft Games
[2016-05-23 19:53:50 | 000,000,000 | ---D | C] -- C:\PaintToolSAI
[2016-05-23 19:24:07 | 000,000,000 | ---D | C] -- C:\Users\julia\Documents\ArtRage Paintings
[2016-05-23 19:11:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Caphyon
[2016-05-23 19:10:11 | 000,000,000 | ---D | C] -- C:\Users\julia\AppData\Roaming\Ambient Design
[2016-05-23 18:55:40 | 000,096,768 | ---- | C] (WALTOP International Corp.) -- C:\Windows\SysNative\WINTAB32.dll
[2016-05-16 11:25:10 | 000,000,000 | ---D | C] -- C:\Users\julia\AppData\Local\Guntony
[2016-05-16 11:05:27 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Guntony
[2016-05-16 11:05:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Guntony
[2016-05-13 14:07:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2016-05-13 14:04:03 | 020,381,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2016-05-13 13:45:29 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\Projekty
[2016-05-13 13:27:52 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\Start dash
========== Files - Modified Within 30 Days ==========
[2016-06-11 13:13:24 | 000,028,352 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016-06-11 13:13:24 | 000,028,352 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016-06-11 13:05:04 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2016-06-11 13:04:58 | 3219,300,352 | -HS- | M] () -- C:\hiberfil.sys
[2016-06-11 13:04:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2016-06-11 13:03:45 | 002,385,408 | ---- | M] (Farbar) -- C:\Users\julia\Desktop\FRST64.exe
[2016-06-11 13:00:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\julia\Desktop\OTL.exe
[2016-06-11 12:52:11 | 000,151,707 | ---- | M] () -- C:\Users\julia\Desktop\cenzura!.aup
[2016-06-11 12:51:06 | 000,536,312 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswNetSec.sys
[2016-06-11 12:47:01 | 000,000,992 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player PPAPI Notifier.job
[2016-06-11 12:33:26 | 000,634,332 | ---- | M] () -- C:\Users\julia\Desktop\cenzura!.wav
[2016-06-09 21:51:07 | 004,230,311 | ---- | M] () -- C:\Users\julia\Desktop\Start-Dash!!_(Off_Vocal).ogg
[2016-06-09 19:30:25 | 000,001,550 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2016-06-09 19:22:42 | 000,097,856 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2016-06-07 20:33:43 | 003,655,050 | ---- | M] () -- C:\Users\julia\Desktop\_Under Our Spell_ (Acapella) 90% CLEAR [Rainbow Rocks] (HD) Best Version MLP_ FIM HD.mp3
[2016-06-07 16:41:50 | 000,006,795 | ---- | M] () -- C:\Users\julia\.recently-used.xbel
[2016-06-07 16:36:25 | 000,049,152 | -H-- | M] () -- C:\Users\julia\Desktop\photothumb.db
[2016-06-05 21:07:04 | 000,035,251 | ---- | M] () -- C:\Users\julia\Desktop\0b8234004985bcd7a163593d267573d0.jpg
[2016-06-05 10:40:42 | 000,002,170 | ---- | M] () -- C:\Users\julia\Desktop\Discord.lnk
[2016-05-27 23:16:09 | 000,001,303 | ---- | M] () -- C:\Users\Public\Desktop\YTD Video Downloader.lnk
[2016-05-27 23:16:09 | 000,000,571 | ---- | M] () -- C:\Users\Public\Desktop\PaintTool SAI Ver.1.lnk
[2016-05-27 23:16:08 | 000,001,503 | ---- | M] () -- C:\Users\julia\Desktop\Sosnowiec.lnk
[2016-05-27 23:16:08 | 000,001,052 | ---- | M] () -- C:\Users\julia\Desktop\The Sims 3.lnk
[2016-05-26 22:31:09 | 008,282,250 | ---- | M] () -- C:\Users\julia\Documents\START - DASH hanayo mix.mp3
[2016-05-26 22:30:38 | 012,774,686 | ---- | M] () -- C:\Users\julia\Documents\START - DASH hanayo mix.mp4
[2016-05-25 11:36:11 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2016-05-25 11:32:55 | 000,000,001 | ---- | M] () -- C:\Windows\SysWow64\pl.html
[2016-05-19 20:29:38 | 005,487,532 | ---- | M] () -- C:\Users\julia\Desktop\wyzszy.wav
[2016-05-13 15:04:12 | 000,797,376 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2016-05-13 15:04:12 | 000,142,528 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2016-05-13 15:04:06 | 020,381,888 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
========== Files Created - No Company Name ==========
[2016-06-11 12:43:20 | 000,001,007 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2016-06-11 12:33:26 | 000,634,332 | ---- | C] () -- C:\Users\julia\Desktop\cenzura!.wav
[2016-06-09 23:32:00 | 000,151,707 | ---- | C] () -- C:\Users\julia\Desktop\cenzura!.aup
[2016-06-09 21:51:07 | 004,230,311 | ---- | C] () -- C:\Users\julia\Desktop\Start-Dash!!_(Off_Vocal).ogg
[2016-06-09 19:30:25 | 000,001,550 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2016-06-07 20:33:37 | 003,655,050 | ---- | C] () -- C:\Users\julia\Desktop\_Under Our Spell_ (Acapella) 90% CLEAR [Rainbow Rocks] (HD) Best Version MLP_ FIM HD.mp3
[2016-06-07 16:41:50 | 000,006,795 | ---- | C] () -- C:\Users\julia\.recently-used.xbel
[2016-06-05 21:07:04 | 000,035,251 | ---- | C] () -- C:\Users\julia\Desktop\0b8234004985bcd7a163593d267573d0.jpg
[2016-05-28 10:45:00 | 000,002,170 | ---- | C] () -- C:\Users\julia\Desktop\Discord.lnk
[2016-05-26 22:30:55 | 008,282,250 | ---- | C] () -- C:\Users\julia\Documents\START - DASH hanayo mix.mp3
[2016-05-26 22:30:38 | 012,774,686 | ---- | C] () -- C:\Users\julia\Documents\START - DASH hanayo mix.mp4
[2016-05-25 16:35:19 | 000,001,052 | ---- | C] () -- C:\Users\julia\Desktop\The Sims 3.lnk
[2016-05-25 12:48:45 | 000,001,303 | ---- | C] () -- C:\Users\Public\Desktop\YTD Video Downloader.lnk
[2016-05-23 19:53:50 | 000,000,571 | ---- | C] () -- C:\Users\Public\Desktop\PaintTool SAI Ver.1.lnk
[2016-05-23 18:55:40 | 003,593,728 | ---- | C] () -- C:\Windows\SysNative\AtwtusbIcon.exe
[2016-05-23 18:55:40 | 000,559,104 | ---- | C] () -- C:\Windows\RmTablet.exe
[2016-05-19 20:29:38 | 005,487,532 | ---- | C] () -- C:\Users\julia\Desktop\wyzszy.wav
[2016-05-16 11:05:30 | 000,002,118 | ---- | C] () -- C:\Users\julia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[2016-05-13 14:06:46 | 000,000,001 | ---- | C] () -- C:\Windows\SysWow64\pl.html
[2016-05-08 16:09:00 | 001,443,152 | ---- | C] ( ) -- C:\Users\julia\AppData\Roaming\AutoTime_51477.exe
[2016-03-28 21:33:33 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat
[2016-01-31 04:00:43 | 000,122,884 | ---- | C] () -- C:\Windows\UnGins.exe
[2016-01-23 18:18:42 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
[2016-01-11 22:30:33 | 000,000,105 | R--- | C] () -- C:\ProgramData\Ppster.ini
[2016-01-02 16:56:05 | 000,000,632 | ---- | C] () -- C:\Windows\CoD.INI
[2015-12-26 01:33:47 | 000,641,024 | ---- | C] () -- C:\Windows\SysWow64\ficvdec_x86.dll
[2015-12-21 23:31:51 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2015-12-21 23:24:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2014-09-10 11:23:34 | 001,640,128 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
========== ZeroAccess Check ==========
[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2016-01-22 08:19:58 | 014,179,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2016-01-22 08:05:58 | 012,877,824 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\julia\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18314)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
4,00 Gb Total Physical Memory | 2,35 Gb Available Physical Memory | 58,77% Memory free
7,99 Gb Paging File | 6,10 Gb Available in Paging File | 76,29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 195,41 Gb Total Space | 86,66 Gb Free Space | 44,35% Space Free | Partition Type: NTFS
Drive D: | 270,25 Gb Total Space | 202,21 Gb Free Space | 74,82% Space Free | Partition Type: NTFS
Drive E: | 458,95 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: JULIA-KOMPUTER | User Name: julia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2016-06-11 13:00:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\julia\Desktop\OTL.exe
PRC - [2016-06-09 19:18:12 | 000,592,424 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\38.0.2220.29\opera_crashreporter.exe
PRC - [2016-06-09 19:18:11 | 000,710,184 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\38.0.2220.29\opera.exe
PRC - [2016-05-25 10:31:20 | 001,687,680 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2016-05-25 10:30:36 | 001,364,096 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2016-05-12 10:54:56 | 007,032,080 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
PRC - [2016-05-08 16:27:08 | 000,243,296 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2016-04-05 08:29:12 | 002,021,592 | ---- | M] (Adobe Systems, Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
PRC - [2016-01-19 05:02:38 | 000,388,968 | ---- | M] (Digital Wave Ltd.) -- C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
========== Modules (No Company Name) ==========
MOD - [2016-06-09 19:18:11 | 067,942,952 | ---- | M] () -- C:\Program Files (x86)\Opera\38.0.2220.29\opera.dll
MOD - [2016-06-09 19:17:57 | 002,203,176 | ---- | M] () -- C:\Program Files (x86)\Opera\38.0.2220.29\libglesv2.dll
MOD - [2016-06-09 19:17:56 | 000,087,080 | ---- | M] () -- C:\Program Files (x86)\Opera\38.0.2220.29\libegl.dll
========== Services (SafeList) ==========
SRV:64bit: - [2016-06-11 12:51:06 | 000,370,656 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
SRV:64bit: - [2016-05-08 16:27:08 | 000,243,296 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2016-04-23 06:47:35 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2015-07-23 02:02:54 | 001,390,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:64bit: - [2014-09-10 01:08:15 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012-10-19 11:01:04 | 000,581,120 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\atwtusb.exe -- (WTService)
SRV:64bit: - [2009-08-18 03:36:20 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2016-05-25 10:31:20 | 001,687,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2016-05-25 10:30:36 | 001,364,096 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2016-05-13 15:04:13 | 000,269,504 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2016-05-12 10:54:56 | 007,032,080 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe -- (TeamViewer)
SRV - [2016-04-30 02:10:40 | 000,835,664 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2016-04-05 08:29:12 | 002,021,592 | ---- | M] (Adobe Systems, Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe -- (AGSService)
SRV - [2016-03-23 19:08:24 | 000,327,808 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2016-01-19 05:02:38 | 000,388,968 | ---- | M] (Digital Wave Ltd.) [Auto | Running] -- C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe -- (DigitalWave.Update.Service)
SRV - [2016-01-15 16:58:50 | 001,369,464 | ---- | M] (Disc Soft Ltd) [On_Demand | Stopped] -- D:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe -- (Disc Soft Lite Bus Service)
SRV - [2016-01-11 20:49:01 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2014-09-10 01:22:08 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014-04-11 23:08:08 | 000,103,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2016-06-11 12:51:06 | 000,536,312 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\aswNetSec.sys -- (aswNetSec)
DRV:64bit: - [2016-05-08 16:31:50 | 000,037,144 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswKbd.sys -- (aswKbd)
DRV:64bit: - [2016-05-08 16:27:15 | 000,465,792 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2016-05-08 16:27:15 | 000,287,528 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2016-05-08 16:27:15 | 000,166,432 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2016-05-08 16:27:15 | 000,107,792 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2016-05-08 16:27:15 | 000,103,064 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2016-05-08 16:27:15 | 000,074,544 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2016-05-08 16:27:15 | 000,037,656 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2016-05-08 16:26:57 | 001,070,904 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2016-01-24 02:19:57 | 000,047,672 | ---- | M] (Disc Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dtliteusbbus.sys -- (dtliteusbbus)
DRV:64bit: - [2015-12-22 23:06:16 | 000,030,264 | ---- | M] (Disc Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dtlitescsibus.sys -- (dtlitescsibus)
DRV:64bit: - [2015-06-17 18:04:24 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2014-09-10 01:16:06 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2014-09-10 01:16:06 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2014-09-10 01:15:16 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2014-09-10 01:15:16 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2014-09-10 01:12:37 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2014-09-10 01:12:37 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2014-09-10 01:00:36 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2014-09-10 01:00:08 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2014-08-16 00:13:34 | 000,023,040 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2012-06-05 07:45:16 | 000,237,968 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2012-06-01 10:32:38 | 000,379,776 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\V0770Vid.sys -- (V0770Vid)
DRV:64bit: - [2011-11-03 03:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2011-08-23 15:57:24 | 000,565,352 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010-11-21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009-08-26 14:15:10 | 000,007,552 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\walvhid.sys -- (vhidmini)
DRV:64bit: - [2009-08-18 04:48:48 | 006,037,504 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009-03-08 20:16:14 | 000,007,680 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\moufiltr.sys -- (moufiltr)
DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_instalki
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/pl-pl/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pl-PL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F5 55 E5 65 03 3C D1 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.91.2: C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.91.2: C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll ( Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\julia\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2016-06-11 12:51:30 | 000,000,000 | ---D | M]
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\sp@avast.com: C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\SAFEPRICE\FF [2016-06-11 12:51:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-06-11 12:51:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\sp@avast.com: C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-06-11 12:51:29 | 000,000,000 | ---D | M]
[2016-02-10 17:02:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\julia\AppData\Roaming\mozilla\Extensions
========== Chrome ==========
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\11.1.0.221_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\11.1.0.955_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.0_0\
CHR - Extension: No name found = C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
O1 HOSTS File: ([2016-05-23 20:04:23 | 000,001,093 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 http://www.mirillis.com
O1 - Hosts: 127.0.0.1 s0ft4pc.com
O1 - Hosts: 127.0.0.1 serwer2.paka-service.com
O1 - Hosts: 127.0.0.1 down.baidu2016.com
O1 - Hosts: 127.0.0.1 123.sogou.com
O1 - Hosts: 127.0.0.1 http://www.czzsyzgm.com
O1 - Hosts: 127.0.0.1 http://www.czzsyzxl.com
O1 - Hosts: 127.0.0.1 union.baidu2019.com
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AtwtusbIcon] C:\Windows\SysNative\AtwtusbIcon.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [V0770Mon.exe] C:\Windows\V0770Mon.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKCU..\Run: [DAEMON Tools Lite Automount] D:\Program Files\DAEMON Tools Lite\DTAgent.exe (Disc Soft Ltd)
O4 - HKCU..\Run: [Discord] C:\Users\julia\AppData\Local\Discord\app-0.0.291\Discord.exe (Hammer & Chisel, Inc.)
O4 - HKCU..\Run: [Steam] D:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O9:64bit: - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.61 62.179.1.63
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{81AAB8BC-A6E0-420D-9F03-96295BCE5CE6}: DhcpNameServer = 62.179.1.61 62.179.1.63
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C0F5FDB1-ECBA-425E-B40E-733B892C23AA}: DhcpNameServer = 192.168.42.129
O18:64bit: - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2015-12-28 01:25:44 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006-03-03 16:54:53 | 000,000,031 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{0c9d5e4a-c9b4-11e5-9fa8-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{0c9d5e4a-c9b4-11e5-9fa8-fcaa14bb116e}\Shell\AutoRun\command - "" = J:\
O33 - MountPoints2\{0c9d5e55-c9b4-11e5-9fa8-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{0c9d5e55-c9b4-11e5-9fa8-fcaa14bb116e}\Shell\AutoRun\command - "" = K:\
O33 - MountPoints2\{4e7f5e15-c751-11e5-97e7-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{4e7f5e15-c751-11e5-97e7-fcaa14bb116e}\Shell\AutoRun\command - "" = J:\
O33 - MountPoints2\{6fc04ccc-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04ccc-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = H:\autorun.exe
O33 - MountPoints2\{6fc04de3-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04de3-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = I:\Autorun.exe
O33 - MountPoints2\{6fc04df9-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04df9-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = J:\Autorun.exe
O33 - MountPoints2\{6fc04dfd-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04dfd-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = K:\autorun.exe
O33 - MountPoints2\{6fc04e19-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04e19-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = H:\
O33 - MountPoints2\{6fc04e24-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04e24-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = I:\Autorun.exe
O33 - MountPoints2\{6fc04e38-a8aa-11e5-a78b-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{6fc04e38-a8aa-11e5-a78b-fcaa14bb116e}\Shell\AutoRun\command - "" = J:\
O33 - MountPoints2\{e5032bf7-c1f3-11e5-973c-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{e5032bf7-c1f3-11e5-973c-fcaa14bb116e}\Shell\AutoRun\command - "" = H:\startme.exe
O33 - MountPoints2\{e5032ced-c1f3-11e5-973c-fcaa14bb116e}\Shell - "" = AutoRun
O33 - MountPoints2\{e5032ced-c1f3-11e5-973c-fcaa14bb116e}\Shell\AutoRun\command - "" = H:\Launch.exe
O33 - MountPoints2\{fa51d0e0-a828-11e5-9068-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{fa51d0e0-a828-11e5-9068-806e6f6e6963}\Shell\AutoRun\command - "" = E:\VCD_PLAY.EXE -- [2006-03-03 16:56:01 | 000,462,848 | R--- | M] (Roxio)
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\Launch.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2016-06-11 13:06:43 | 000,000,000 | ---D | C] -- C:\FRST
[2016-06-11 13:03:43 | 002,385,408 | ---- | C] (Farbar) -- C:\Users\julia\Desktop\FRST64.exe
[2016-06-11 13:01:43 | 000,000,000 | ---D | C] -- C:\_OTL
[2016-06-11 13:00:31 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\julia\Desktop\OTL.exe
[2016-06-11 12:51:41 | 000,536,312 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswNetSec.sys
[2016-06-11 12:51:30 | 000,398,152 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2016-06-11 12:43:47 | 000,056,208 | ---- | C] (Rovi Corporation) -- C:\Windows\SysNative\drivers\PxHlpa64.sys
[2016-06-11 12:43:47 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdralw2k.sys
[2016-06-11 12:43:47 | 000,010,224 | ---- | C] (Sonic Solutions) -- C:\Windows\SysNative\drivers\cdr4_xp.sys
[2016-06-11 12:43:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared
[2016-06-11 12:43:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2016-06-11 12:43:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\My Company Name
[2016-06-11 12:43:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2016-06-11 10:46:28 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\dash
[2016-06-09 23:31:57 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\cenzura!
[2016-06-09 19:30:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2016-06-09 19:30:16 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2016-06-09 19:27:47 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2016-06-09 19:27:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2016-06-09 19:23:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2016-05-28 10:44:45 | 000,000,000 | ---D | C] -- C:\Users\julia\AppData\Local\Discord
[2016-05-26 16:49:37 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\Start
[2016-05-25 16:35:14 | 000,000,000 | ---D | C] -- C:\Users\julia\Documents\Electronic Arts
[2016-05-25 12:48:47 | 000,000,000 | ---D | C] -- C:\ProgramData\YTD Video Downloader
[2016-05-25 12:48:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader
[2016-05-25 12:48:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GreenTree Applications
[2016-05-24 19:36:25 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\light of your cutie mark
[2016-05-23 22:19:22 | 000,000,000 | ---D | C] -- C:\Users\julia\AppData\Local\Microsoft Games
[2016-05-23 19:53:50 | 000,000,000 | ---D | C] -- C:\PaintToolSAI
[2016-05-23 19:24:07 | 000,000,000 | ---D | C] -- C:\Users\julia\Documents\ArtRage Paintings
[2016-05-23 19:11:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Caphyon
[2016-05-23 19:10:11 | 000,000,000 | ---D | C] -- C:\Users\julia\AppData\Roaming\Ambient Design
[2016-05-23 18:55:40 | 000,096,768 | ---- | C] (WALTOP International Corp.) -- C:\Windows\SysNative\WINTAB32.dll
[2016-05-16 11:25:10 | 000,000,000 | ---D | C] -- C:\Users\julia\AppData\Local\Guntony
[2016-05-16 11:05:27 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Guntony
[2016-05-16 11:05:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Guntony
[2016-05-13 14:07:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2016-05-13 14:04:03 | 020,381,888 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2016-05-13 13:45:29 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\Projekty
[2016-05-13 13:27:52 | 000,000,000 | ---D | C] -- C:\Users\julia\Desktop\Start dash
========== Files - Modified Within 30 Days ==========
[2016-06-11 13:13:24 | 000,028,352 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016-06-11 13:13:24 | 000,028,352 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016-06-11 13:05:04 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2016-06-11 13:04:58 | 3219,300,352 | -HS- | M] () -- C:\hiberfil.sys
[2016-06-11 13:04:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2016-06-11 13:03:45 | 002,385,408 | ---- | M] (Farbar) -- C:\Users\julia\Desktop\FRST64.exe
[2016-06-11 13:00:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\julia\Desktop\OTL.exe
[2016-06-11 12:52:11 | 000,151,707 | ---- | M] () -- C:\Users\julia\Desktop\cenzura!.aup
[2016-06-11 12:51:06 | 000,536,312 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswNetSec.sys
[2016-06-11 12:47:01 | 000,000,992 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player PPAPI Notifier.job
[2016-06-11 12:33:26 | 000,634,332 | ---- | M] () -- C:\Users\julia\Desktop\cenzura!.wav
[2016-06-09 21:51:07 | 004,230,311 | ---- | M] () -- C:\Users\julia\Desktop\Start-Dash!!_(Off_Vocal).ogg
[2016-06-09 19:30:25 | 000,001,550 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2016-06-09 19:22:42 | 000,097,856 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2016-06-07 20:33:43 | 003,655,050 | ---- | M] () -- C:\Users\julia\Desktop\_Under Our Spell_ (Acapella) 90% CLEAR [Rainbow Rocks] (HD) Best Version MLP_ FIM HD.mp3
[2016-06-07 16:41:50 | 000,006,795 | ---- | M] () -- C:\Users\julia\.recently-used.xbel
[2016-06-07 16:36:25 | 000,049,152 | -H-- | M] () -- C:\Users\julia\Desktop\photothumb.db
[2016-06-05 21:07:04 | 000,035,251 | ---- | M] () -- C:\Users\julia\Desktop\0b8234004985bcd7a163593d267573d0.jpg
[2016-06-05 10:40:42 | 000,002,170 | ---- | M] () -- C:\Users\julia\Desktop\Discord.lnk
[2016-05-27 23:16:09 | 000,001,303 | ---- | M] () -- C:\Users\Public\Desktop\YTD Video Downloader.lnk
[2016-05-27 23:16:09 | 000,000,571 | ---- | M] () -- C:\Users\Public\Desktop\PaintTool SAI Ver.1.lnk
[2016-05-27 23:16:08 | 000,001,503 | ---- | M] () -- C:\Users\julia\Desktop\Sosnowiec.lnk
[2016-05-27 23:16:08 | 000,001,052 | ---- | M] () -- C:\Users\julia\Desktop\The Sims 3.lnk
[2016-05-26 22:31:09 | 008,282,250 | ---- | M] () -- C:\Users\julia\Documents\START - DASH hanayo mix.mp3
[2016-05-26 22:30:38 | 012,774,686 | ---- | M] () -- C:\Users\julia\Documents\START - DASH hanayo mix.mp4
[2016-05-25 11:36:11 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2016-05-25 11:32:55 | 000,000,001 | ---- | M] () -- C:\Windows\SysWow64\pl.html
[2016-05-19 20:29:38 | 005,487,532 | ---- | M] () -- C:\Users\julia\Desktop\wyzszy.wav
[2016-05-13 15:04:12 | 000,797,376 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2016-05-13 15:04:12 | 000,142,528 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2016-05-13 15:04:06 | 020,381,888 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
========== Files Created - No Company Name ==========
[2016-06-11 12:43:20 | 000,001,007 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2016-06-11 12:33:26 | 000,634,332 | ---- | C] () -- C:\Users\julia\Desktop\cenzura!.wav
[2016-06-09 23:32:00 | 000,151,707 | ---- | C] () -- C:\Users\julia\Desktop\cenzura!.aup
[2016-06-09 21:51:07 | 004,230,311 | ---- | C] () -- C:\Users\julia\Desktop\Start-Dash!!_(Off_Vocal).ogg
[2016-06-09 19:30:25 | 000,001,550 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2016-06-07 20:33:37 | 003,655,050 | ---- | C] () -- C:\Users\julia\Desktop\_Under Our Spell_ (Acapella) 90% CLEAR [Rainbow Rocks] (HD) Best Version MLP_ FIM HD.mp3
[2016-06-07 16:41:50 | 000,006,795 | ---- | C] () -- C:\Users\julia\.recently-used.xbel
[2016-06-05 21:07:04 | 000,035,251 | ---- | C] () -- C:\Users\julia\Desktop\0b8234004985bcd7a163593d267573d0.jpg
[2016-05-28 10:45:00 | 000,002,170 | ---- | C] () -- C:\Users\julia\Desktop\Discord.lnk
[2016-05-26 22:30:55 | 008,282,250 | ---- | C] () -- C:\Users\julia\Documents\START - DASH hanayo mix.mp3
[2016-05-26 22:30:38 | 012,774,686 | ---- | C] () -- C:\Users\julia\Documents\START - DASH hanayo mix.mp4
[2016-05-25 16:35:19 | 000,001,052 | ---- | C] () -- C:\Users\julia\Desktop\The Sims 3.lnk
[2016-05-25 12:48:45 | 000,001,303 | ---- | C] () -- C:\Users\Public\Desktop\YTD Video Downloader.lnk
[2016-05-23 19:53:50 | 000,000,571 | ---- | C] () -- C:\Users\Public\Desktop\PaintTool SAI Ver.1.lnk
[2016-05-23 18:55:40 | 003,593,728 | ---- | C] () -- C:\Windows\SysNative\AtwtusbIcon.exe
[2016-05-23 18:55:40 | 000,559,104 | ---- | C] () -- C:\Windows\RmTablet.exe
[2016-05-19 20:29:38 | 005,487,532 | ---- | C] () -- C:\Users\julia\Desktop\wyzszy.wav
[2016-05-16 11:05:30 | 000,002,118 | ---- | C] () -- C:\Users\julia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[2016-05-13 14:06:46 | 000,000,001 | ---- | C] () -- C:\Windows\SysWow64\pl.html
[2016-05-08 16:09:00 | 001,443,152 | ---- | C] ( ) -- C:\Users\julia\AppData\Roaming\AutoTime_51477.exe
[2016-03-28 21:33:33 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat
[2016-01-31 04:00:43 | 000,122,884 | ---- | C] () -- C:\Windows\UnGins.exe
[2016-01-23 18:18:42 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
[2016-01-11 22:30:33 | 000,000,105 | R--- | C] () -- C:\ProgramData\Ppster.ini
[2016-01-02 16:56:05 | 000,000,632 | ---- | C] () -- C:\Windows\CoD.INI
[2015-12-26 01:33:47 | 000,641,024 | ---- | C] () -- C:\Windows\SysWow64\ficvdec_x86.dll
[2015-12-21 23:31:51 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2015-12-21 23:24:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2014-09-10 11:23:34 | 001,640,128 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
========== ZeroAccess Check ==========
[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2016-01-22 08:19:58 | 014,179,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2016-01-22 08:05:58 | 012,877,824 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >