========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.04.13 01:02:48 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\.minecraft
[2012.04.16 19:01:48 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Artisteer
[2012.12.24 15:58:17 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Ashampoo
[2012.02.16 21:58:42 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Atari
[2013.02.19 14:17:14 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Audacity
[2013.07.06 01:19:35 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\BoL
[2013.05.21 17:34:55 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\CAD-KAS
[2012.03.26 14:55:28 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Chrome
[2012.11.24 20:07:54 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\CMUV
[2012.02.17 15:32:51 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013.08.25 16:32:20 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\DAEMON Tools Lite
[2012.08.02 17:38:22 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\DBC2F6FD-3140-41E0-A2A1-D6BAB77D5E21__F893F7CA-8278-41DF-A76F-CAF0437A90CD__
[2012.05.13 20:25:49 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Dream Aquarium
[2012.11.25 20:43:11 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Dropbox
[2012.12.29 18:30:47 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\FileZilla
[2013.06.26 22:17:30 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\FlvtoConverter
[2013.08.31 14:56:14 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\foobar2000
[2012.07.07 13:55:55 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\GHISLER
[2013.07.08 13:50:49 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\GlarySoft
[2012.10.10 20:58:49 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\HTC
[2012.11.04 21:43:58 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\HTC Sync
[2012.05.17 19:32:50 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\ImTOO
[2012.02.28 21:11:22 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\KeePass
[2012.02.29 22:50:04 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Lamantine
[2012.10.03 18:58:13 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\LolClient
[2013.07.06 14:43:17 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\LoLPlus
[2012.02.29 20:24:08 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Luxand
[2012.08.28 19:03:23 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\MegaCloud
[2013.08.23 17:26:15 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Milestone
[2012.04.07 14:32:31 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Miranda
[2012.08.14 20:08:09 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\MOBILedit
[2012.06.09 19:37:34 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\MP3SkypeRecorder
[2012.10.10 14:29:08 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Nokia
[2012.10.10 14:29:09 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Nokia Suite
[2013.07.09 11:29:23 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\OBS
[2012.04.17 15:39:42 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\ObviousIdea
[2013.08.31 11:19:30 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\OpenOffice
[2012.02.24 14:12:19 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\OpenOffice.org
[2012.03.16 20:54:31 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Opera
[2012.02.18 15:21:47 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Origin
[2012.10.10 20:58:44 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Outlook
[2012.06.11 17:54:12 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Pamela
[2012.03.05 15:35:13 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\PC Suite
[2012.06.05 19:34:03 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\PhotoFiltre 7
[2012.08.20 20:51:57 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Posta
[2012.10.02 16:50:05 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\ProtectDISC
[2012.02.17 15:40:43 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Publish Providers
[2012.07.22 20:22:45 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Rajce
[2013.06.30 19:55:20 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Riot Games
[2012.10.02 13:56:41 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Rovio
[2012.02.22 15:56:28 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\SFBot
[2012.02.27 20:22:39 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\SkyMonk
[2012.03.05 23:55:08 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Solveig Multimedia
[2012.07.03 20:08:52 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Sony
[2012.06.29 20:39:57 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Sony Creative Software Inc
[2012.06.08 20:36:09 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\SplitMediaLabs
[2013.07.21 17:00:45 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Spotify
[2012.06.06 13:56:36 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012.09.12 20:17:09 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Student dog
[2012.07.14 19:07:34 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Synaptics
[2012.12.06 01:01:56 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\TeamViewer
[2012.05.13 21:16:27 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Thunderbird
[2012.02.10 15:20:53 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\TightVNC
[2013.09.01 21:54:56 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\TS3Client
[2012.10.03 13:45:09 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\ts3overlay
[2013.08.23 22:19:15 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\uTorrent
[2012.08.29 20:23:53 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Vso
[2012.09.11 20:33:21 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\wargaming.net
[2013.06.05 17:52:49 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\WildTangent
[2012.02.17 21:48:36 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Windows Live Writer
[2013.08.26 17:30:59 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\xrecode2
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009.07.14 07:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.07.14 07:08:49 | 000,032,630 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2013.01.09 20:10:45 | 000,000,914 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013.07.06 17:16:16 | 000,000,948 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013.07.06 17:16:17 | 000,000,952 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2013.07.08 13:50:50 | 000,000,328 | ---- | C] () -- C:\Windows\Tasks\GlaryInitialize 3.job
[2013.07.09 19:47:49 | 000,000,404 | ---- | C] () -- C:\Windows\Tasks\GlaryOneClickOptimizer 3.job
< >
< MD5 for: AGP440.SYS >
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009.07.14 03:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 03:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\SysNative\autochk.exe
[2010.11.21 05:24:27 | 000,777,728 | ---- | M] (Microsoft Corporation) MD5=3B536A8BEC3B4F23FFDFD78B11A2AB93 -- C:\Windows\winsxs\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_4019f2b8d860ad30\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\SysWOW64\autochk.exe
[2010.11.21 05:23:53 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Users\Jakub\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20130708T090623267631\gencdrom\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Users\Jakub\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20130708T091608332733\gencdrom\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys
[2010.11.21 05:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys
< MD5 for: CNGAUDIT.DLL >
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\SysWOW64\cngaudit.dll
[2009.07.14 03:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\SysNative\cngaudit.dll
[2009.07.14 03:40:20 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: CRYPTSVC.DLL >
[2012.06.02 06:52:32 | 000,142,336 | ---- | M] (Microsoft Corporation) MD5=063DD65889D21035311463337BD268E7 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22010_none_788c7cc71232cc19\cryptsvc.dll
[2012.04.24 06:36:42 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=06E771AA596B8761107AB57E99F128D7 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17827_none_77ff39f3f916c65f\cryptsvc.dll
[2010.11.21 05:24:16 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=15597883FBE9B056F276ADA3AD87D9AF -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_d4259ed3b16ed82a\cryptsvc.dll
[2012.04.24 06:28:22 | 000,142,336 | ---- | M] (Microsoft Corporation) MD5=21993009E0CCB9B4FA195F14D3408626 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.21979_none_7854c7b7125b248c\cryptsvc.dll
[2013.05.10 06:49:59 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=33ADF6E0853AB39EA1723BE82842C1D3 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18150_none_77d7a417f9359661\cryptsvc.dll
[2013.05.13 06:45:55 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=3897DFF247D9ED0006190349DE264E14 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18151_none_77d8a461f934afb8\cryptsvc.dll
[2013.07.09 16:47:30 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=434CCE8E7150CD1324C5FAA088D1D061 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22380_none_d45f6e88cac8f85b\cryptsvc.dll
[2012.04.24 07:37:37 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=4F5414602E2544A4554D95517948B705 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17827_none_d41dd577b1743795\cryptsvc.dll
[2013.07.09 07:46:20 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=6B400F211BEE880A37A1ED0368776BF4 -- C:\Windows\SysNative\cryptsvc.dll
[2013.07.09 07:46:20 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=6B400F211BEE880A37A1ED0368776BF4 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18205_none_d431528fb165f7bc\cryptsvc.dll
[2013.07.09 15:57:37 | 000,142,848 | ---- | M] (Microsoft Corporation) MD5=6DB499DEFCC827317C5371164A7CDB27 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22380_none_7840d305126b8725\cryptsvc.dll
[2013.07.09 06:46:31 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=7CA1BECEA5DE2643ADDAD32670E7A4C9 -- C:\Windows\SysWOW64\cryptsvc.dll
[2013.07.09 06:46:31 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=7CA1BECEA5DE2643ADDAD32670E7A4C9 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18205_none_7812b70bf9088686\cryptsvc.dll
[2012.06.04 09:52:35 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=7E7D2DACF65D750D466F36BD3D09AE20 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22010_none_d4ab184aca903d4f\cryptsvc.dll
[2013.05.10 07:49:28 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=7FDC4626B01106A8EF328C88C7C0DEE3 -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18150_none_d3f63f9bb1930797\cryptsvc.dll
[2013.05.11 07:18:23 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=8122252F0A4ACFA92FA0C1D50D18493B -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22322_none_d4a24ea4ca968363\cryptsvc.dll
[2012.06.02 06:36:29 | 000,140,288 | ---- | M] (Microsoft Corporation) MD5=96C0E38905CFD788313BE8E11DAE3F2F -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17856_none_77ddc9e5f93000db\cryptsvc.dll
[2012.06.02 07:41:28 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=9C01375BE382E834CC26D1B7EAF2C4FE -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17856_none_d3fc6569b18d7211\cryptsvc.dll
[2010.11.21 05:24:32 | 000,136,192 | ---- | M] (Microsoft Corporation) MD5=A585BEBF7D054BD9618EDA0922D5484A -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_7807034ff91166f4\cryptsvc.dll
[2013.05.11 06:59:05 | 000,142,848 | ---- | M] (Microsoft Corporation) MD5=AC04D05309BB2C418D0D80B9FB014642 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22322_none_7883b3211239122d\cryptsvc.dll
[2012.04.24 07:22:32 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=B7337E9C9E5936355BB700AA33E0936E -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.21979_none_d473633acab895c2\cryptsvc.dll
[2013.05.10 07:18:53 | 000,186,880 | ---- | M] (Microsoft Corporation) MD5=CA13C4F92BEE66DB48E58AB3223DDF6E -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22321_none_d4a14e5aca976a0c\cryptsvc.dll
[2013.05.13 07:51:01 | 000,184,320 | ---- | M] (Microsoft Corporation) MD5=D8129C49798CBBFB2E4351D4B7B8EF9C -- C:\Windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18151_none_d3f73fe5b19220ee\cryptsvc.dll
[2013.05.10 07:06:21 | 000,142,848 | ---- | M] (Microsoft Corporation) MD5=E122AA1C9A3CC46FF9DDDE46E5EB0C58 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22321_none_7882b2d71239f8d6\cryptsvc.dll
< MD5 for: EXPLORER.EXE >
[2011.07.14 07:30:29 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.07.14 07:30:29 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.07.14 07:30:29 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.07.14 07:30:29 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.07.14 07:30:29 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.07.14 07:30:29 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: HAL.DLL >
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\SysNative\hal.dll
[2010.11.21 05:24:08 | 000,263,040 | ---- | M] (Microsoft Corporation) MD5=CFB8C673F9188F99466E76C6972191E0 -- C:\Windows\winsxs\amd64_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_094ef8137049c196\hal.dll
< MD5 for: IASTOR.SYS >
[2010.04.13 03:44:22 | 000,540,696 | ---- | M] (Intel Corporation) MD5=1384872112E8E7FD5786ECEB8BDDF4C9 -- C:\OEM\Preload\Autorun\DRV\Intel AHCI\f6flpy-x64\iaStor.sys
[2010.04.13 18:44:22 | 000,540,696 | ---- | M] (Intel Corporation) MD5=1384872112E8E7FD5786ECEB8BDDF4C9 -- C:\Users\Jakub\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20130708T090623267631\pci\ven_8086&dev_3b29&cc_0106\iaStor.sys
[2010.04.13 18:44:22 | 000,540,696 | ---- | M] (Intel Corporation) MD5=1384872112E8E7FD5786ECEB8BDDF4C9 -- C:\Users\Jakub\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20130708T091608332733\pci\ven_8086&dev_3b29&cc_0106\iaStor.sys
[2010.04.13 18:44:22 | 000,540,696 | ---- | M] (Intel Corporation) MD5=1384872112E8E7FD5786ECEB8BDDF4C9 -- C:\Windows\SysNative\drivers\iaStor.sys
[2010.04.13 18:44:22 | 000,540,696 | ---- | M] (Intel Corporation) MD5=1384872112E8E7FD5786ECEB8BDDF4C9 -- C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_d085c8f0cb5c2856\iaStor.sys
[2010.04.13 03:35:20 | 000,435,736 | ---- | M] (Intel Corporation) MD5=E11ED9B1EA60E747655E1090C7509D08 -- C:\OEM\Preload\Autorun\DRV\Intel AHCI\f6flpy-x86\iaStor.sys
< MD5 for: IASTORV.SYS >
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010.11.21 05:23:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011.07.14 07:35:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011.07.14 07:35:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2011.07.14 07:35:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011.07.14 07:35:47 | 000,410,496 | ---- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
< MD5 for: ISAPNP.SYS >
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\drivers\isapnp.sys
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\isapnp.sys
[2009.07.14 03:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) MD5=2F7B28DC3E1183E5EB418DF55C204F38 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\isapnp.sys
< MD5 for: LSASS.EXE >
[2009.07.14 03:39:16 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0793F40B9B8A1BDD266296409DBD91EA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_04709031736ac277\lsass.exe
[2011.11.17 08:20:34 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=0A10B74FBB437FF9A23F1D5DE4446A83 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_04c1204e8cb39c3f\lsass.exe
[2012.08.24 19:43:36 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=77119F1F9B492B260030C34F9BE327FA -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22099_none_04a88ce28cc4eb33\lsass.exe
[2012.06.04 09:51:10 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=79C908CAA6F43021EB05F4C733A927D1 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22010_none_04f609a88c8c279c\lsass.exe
[2011.11.17 08:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\SysNative\lsass.exe
[2011.11.17 08:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_0466c45b7371f20d\lsass.exe
[2011.11.17 08:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17856_none_044756c773895c5e\lsass.exe
[2011.11.17 08:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) MD5=C118A82CD78818C29AB228366EBF81C3 -- C:\Windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17940_none_044c26dd7386a58a\lsass.exe
< MD5 for: NDIS.SYS >
[2012.08.22 20:06:07 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=5E74508FCB5820B29EEAFE24E6035BCF -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.22097_none_06232d534c0a8d67\ndis.sys
[2012.08.22 20:12:40 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=760E38053BF56E501D562B70AD796B88 -- C:\Windows\SysNative\drivers\ndis.sys
[2012.08.22 20:12:40 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=760E38053BF56E501D562B70AD796B88 -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17939_none_05dc9a6832ba428a\ndis.sys
[2010.11.21 05:23:55 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_05ed313632ae9759\ndis.sys
< MD5 for: NETLOGON.DLL >
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll
[2010.11.21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll
[2010.11.21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
< MD5 for: NVRAID.SYS >
[2011.07.14 07:35:47 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\drivers\nvraid.sys
[2011.07.14 07:35:47 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvraid.sys
[2011.07.14 07:35:47 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=0A92CB65770442ED0DC44834632F66AD -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvraid.sys
[2010.11.21 05:23:47 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvraid.sys
[2010.11.21 05:23:47 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=5D9FD91F3D38DC9DA01E3CB5FA89CD48 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvraid.sys
[2011.07.14 07:35:47 | 000,148,352 | ---- | M] (NVIDIA Corporation) MD5=666CA16F17914C1CD3616CF16DE0A6EA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2011.07.14 07:35:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011.07.14 07:35:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\drivers\nvstor.sys
[2011.07.14 07:35:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.07.14 07:35:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.21 05:23:47 | 000,166,272 | ---- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\SysWOW64\scecli.dll
[2010.11.21 05:23:54 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\SysNative\scecli.dll
[2010.11.21 05:24:32 | 000,232,960 | ---- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< MD5 for: SMSS.EXE >
[2009.07.14 03:39:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=1911A3356FA3F77CCC825CCBAC038C2A -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7600.16385_none_082f99a432e2a661\smss.exe
[2013.03.19 04:57:17 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=498E2A20E145199709CD100CDBA8603D -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22280_none_0a9a7b3b492b4d05\smss.exe
[2013.07.08 04:50:41 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=E65601CF4BC0CF3718AFBE56A9AD846F -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.22379_none_0aae4fa7491b124a\smss.exe
[2013.03.19 05:06:33 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=F0371DE302FFFF8F086661611BE60848 -- C:\Windows\SysNative\smss.exe
[2013.03.19 05:06:33 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=F0371DE302FFFF8F086661611BE60848 -- C:\Windows\winsxs\amd64_microsoft-windows-smss_31bf3856ad364e35_6.1.7601.18113_none_0a5f8ec22fd235a9\smss.exe
< MD5 for: SVCHOST.EXE >
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 03:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: TCPIP.SYS >
[2012.10.03 19:56:54 | 001,914,248 | ---- | M] (Microsoft Corporation) MD5=37608401DFDB388CAF66917F6B2D6FB0 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_110e0fbd7d2e4b88\tcpip.sys
[2011.09.29 19:41:37 | 001,912,176 | ---- | M] (Microsoft Corporation) MD5=3810F06A4D74A7D62641EE73D6B3C660 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21828_none_11c6e9949627e69c\tcpip.sys
[2013.05.08 08:14:42 | 001,900,392 | ---- | M] (Microsoft Corporation) MD5=3E94650745D4DAB67E161F5F32CEA597 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22319_none_11d29984961f0be0\tcpip.sys
[2010.11.21 05:24:08 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=509383E505C973ED7534A06B3D19688D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_114417c17d05cb37\tcpip.sys
[2012.08.22 20:06:13 | 001,901,936 | ---- | M] (Microsoft Corporation) MD5=7880A26B7D3B96FDA8EFD9F985036B1D -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22097_none_117a13de9661c145\tcpip.sys
[2012.03.30 12:26:36 | 001,901,424 | ---- | M] (Microsoft Corporation) MD5=885B202006EE17AE99B9FBCEC9AF88C9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21954_none_11a27a8e9643d23a\tcpip.sys
[2011.07.14 07:24:59 | 001,923,968 | ---- | M] (Microsoft Corporation) MD5=92CE29D95AC9DD2D0EE9061D551BA250 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17603_none_114de9497cfe9316\tcpip.sys
[2013.05.08 08:39:01 | 001,910,632 | ---- | M] (Microsoft Corporation) MD5=9849EA3843A2ADBDD1497E97A85D8CAE -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18148_none_11278ac57d1aa96b\tcpip.sys
[2012.03.30 13:35:47 | 001,918,320 | ---- | M] (Microsoft Corporation) MD5=ACB82BDA8F46C84F465C1AFA517DC4B9 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17802_none_114ceccb7cff740d\tcpip.sys
[2013.07.06 07:20:38 | 001,900,992 | ---- | M] (Microsoft Corporation) MD5=B27F13153343BC37A27EAE01634D94E1 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22378_none_1190b9b296509a2f\tcpip.sys
[2013.01.03 08:00:54 | 001,913,192 | ---- | M] (Microsoft Corporation) MD5=B62A953F2BF3922C8764A29C34A22899 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18042_none_112187237d20143a\tcpip.sys
[2011.07.14 07:24:59 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=B77977AEB2FF159D01DB08A309989C5F -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21712_none_11cbb5de9625357a\tcpip.sys
[2013.01.04 07:47:43 | 001,901,416 | ---- | M] (Microsoft Corporation) MD5=B8C1AAC0523E1C33AEB0EF7572144BA2 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22209_none_11dd678a9616f2c8\tcpip.sys
[2011.07.20 04:13:45 | 001,927,552 | ---- | M] (Microsoft Corporation) MD5=CB6A53EF141CC3DA32DA54F7E75D301B -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.21687_none_118505f696597a9d\tcpip.sys
[2012.10.03 19:44:29 | 001,902,472 | ---- | M] (Microsoft Corporation) MD5=D5707FC2300AA5B04B7BFE86D40C0133 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_11c2c45a962baed0\tcpip.sys
[2013.07.06 08:03:53 | 001,910,208 | ---- | M] (Microsoft Corporation) MD5=DB74544B75566C974815E79A62433F29 -- C:\Windows\SysNative\drivers\tcpip.sys
[2013.07.06 08:03:53 | 001,910,208 | ---- | M] (Microsoft Corporation) MD5=DB74544B75566C974815E79A62433F29 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18203_none_114dcae97cfeb81b\tcpip.sys
[2011.07.20 04:13:45 | 001,924,480 | ---- | M] (Microsoft Corporation) MD5=DC08410DB2D0CC542DACAC7A90E6CB7A -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17582_none_10f667b97d405c20\tcpip.sys
[2012.08.22 20:12:50 | 001,913,200 | ---- | M] (Microsoft Corporation) MD5=F782CAD3CEDBB3F9FFE3BF2775D92DDC -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17939_none_113380f37d117668\tcpip.sys
[2011.09.29 18:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) MD5=FC62769E7BFF2896035AEED399108162 -- C:\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17697_none_10f09b257d43f3eb\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< MD5 for: WS2_32.DLL >
[2010.11.21 05:24:28 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\SysNative\ws2_32.dll
[2010.11.21 05:24:28 | 000,297,984 | ---- | M] (Microsoft Corporation) MD5=4BBFA57F594F7E8A8EDC8F377184C3F0 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_50ddb631e4f59005\ws2_32.dll
[2010.11.21 05:23:55 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\SysWOW64\ws2_32.dll
[2010.11.21 05:23:55 | 000,206,848 | ---- | M] (Microsoft Corporation) MD5=7FF15A4F092CD4A96055BA69F903E3E9 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_f4bf1aae2c981ecf\ws2_32.dll
< >
< %systemroot%*.* /U /s >
[4 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[5 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[7 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[2 C:\Windows\SysWOW64\*.tmp files -> C:\Windows\SysWOW64\*.tmp -> ]
[6 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2013.04.13 01:02:48 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\.minecraft
[2013.08.22 10:31:03 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Adobe
[2012.06.06 13:56:37 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Adobe Mini Bridge CS5.1
[2012.02.10 15:34:12 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Ahead
[2012.04.16 19:01:48 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Apple Computer
[2012.04.25 19:41:48 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\ArcSoft
[2012.04.16 19:01:48 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Artisteer
[2012.12.24 15:58:17 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Ashampoo
[2012.02.16 21:58:42 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Atari
[2013.02.19 14:17:14 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Audacity
[2013.07.06 01:19:35 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\BoL
[2013.05.21 17:34:55 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\CAD-KAS
[2012.03.26 14:55:28 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Chrome
[2012.11.24 20:07:54 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\CMUV
[2012.02.17 15:32:51 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012.11.19 15:21:55 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\CyberLink
[2013.08.25 16:32:20 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\DAEMON Tools Lite
[2012.08.02 17:38:22 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\DBC2F6FD-3140-41E0-A2A1-D6BAB77D5E21__F893F7CA-8278-41DF-A76F-CAF0437A90CD__
[2012.05.13 20:25:49 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Dream Aquarium
[2012.11.25 20:43:11 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Dropbox
[2012.12.29 18:30:47 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\FileZilla
[2013.06.26 22:17:30 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\FlvtoConverter
[2013.08.31 14:56:14 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\foobar2000
[2012.07.07 13:55:55 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\GHISLER
[2013.07.08 13:50:49 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\GlarySoft
[2013.06.10 18:17:17 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Hamachi
[2012.07.02 16:15:46 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\HP
[2012.10.10 20:58:49 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\HTC
[2012.11.04 21:43:58 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\HTC Sync
[2012.02.10 13:09:37 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Identities
[2012.05.17 19:32:50 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\ImTOO
[2012.02.28 21:11:22 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\KeePass
[2012.02.29 22:50:04 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Lamantine
[2012.10.03 18:58:13 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\LolClient
[2013.07.06 14:43:17 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\LoLPlus
[2012.02.29 20:24:08 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Luxand
[2012.02.10 13:10:04 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Macromedia
[2012.07.20 19:02:02 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Malwarebytes
[2010.11.21 09:16:41 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Media Center Programs
[2013.08.25 00:33:47 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Media Player Classic
[2012.08.28 19:03:23 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\MegaCloud
[2013.07.05 19:23:36 | 000,000,000 | --SD | M] -- C:\Users\Jakub\AppData\Roaming\Microsoft
[2013.08.23 17:26:15 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Milestone
[2012.04.07 14:32:31 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Miranda
[2012.02.26 10:54:27 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\mIRC
[2012.08.14 20:08:09 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\MOBILedit
[2013.08.30 19:23:43 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Mozilla
[2012.06.09 19:37:34 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\MP3SkypeRecorder
[2012.10.10 19:53:25 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Nero
[2012.10.10 14:29:08 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Nokia
[2012.10.10 14:29:09 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Nokia Suite
[2013.07.10 09:42:05 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\NVIDIA
[2013.07.09 11:29:23 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\OBS
[2012.04.17 15:39:42 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\ObviousIdea
[2013.08.31 11:19:30 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\OpenOffice
[2012.02.24 14:12:19 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\OpenOffice.org
[2012.03.16 20:54:31 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Opera
[2012.02.18 15:21:47 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Origin
[2012.10.10 20:58:44 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Outlook
[2012.06.11 17:54:12 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Pamela
[2012.03.05 15:35:13 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\PC Suite
[2012.06.05 19:34:03 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\PhotoFiltre 7
[2012.08.20 20:51:57 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Posta
[2012.10.02 16:50:05 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\ProtectDISC
[2012.02.17 15:40:43 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Publish Providers
[2012.07.22 20:22:45 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Rajce
[2013.06.11 17:14:06 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Real
[2012.02.16 21:57:10 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\RealNetworks
[2013.06.30 19:55:20 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Riot Games
[2012.10.02 13:56:41 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Rovio
[2012.03.07 20:49:16 | 000,000,000 | RH-D | M] -- C:\Users\Jakub\AppData\Roaming\SecuROM
[2012.02.22 15:56:28 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\SFBot
[2012.02.27 20:22:39 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\SkyMonk
[2013.09.01 21:44:23 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Skype
[2012.03.05 23:55:08 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Solveig Multimedia
[2012.07.03 20:08:52 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Sony
[2012.04.05 14:57:33 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Sony Corporation
[2012.06.29 20:39:57 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Sony Creative Software Inc
[2012.06.08 20:36:09 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\SplitMediaLabs
[2013.07.21 17:00:45 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Spotify
[2012.06.06 13:56:36 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012.09.12 20:17:09 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Student dog
[2013.06.16 10:37:36 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\SUPERAntiSpyware.com
[2012.07.14 19:07:34 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Synaptics
[2012.12.06 01:01:56 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\TeamViewer
[2012.05.13 21:16:27 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Thunderbird
[2012.02.10 15:20:53 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\TightVNC
[2013.09.01 21:54:56 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\TS3Client
[2012.10.03 13:45:09 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\ts3overlay
[2013.08.23 22:19:15 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\uTorrent
[2013.08.14 15:57:50 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\vlc
[2012.08.29 20:23:53 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Vso
[2012.09.11 20:33:21 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\wargaming.net
[2013.06.05 17:52:49 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\WildTangent
[2012.02.17 21:48:36 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\Windows Live Writer
[2012.02.10 14:20:43 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\WinRAR
[2013.08.26 17:30:59 | 000,000,000 | ---D | M] -- C:\Users\Jakub\AppData\Roaming\xrecode2
< %APPDATA%\*.exe /s >
[2012.06.14 04:08:56 | 027,595,032 | ---- | M] (Dropbox, Inc.) -- C:\Users\Jakub\AppData\Roaming\Dropbox\bin\Dropbox.exe
[2012.06.14 04:09:00 | 000,874,440 | ---- | M] (Dropbox, Inc.) -- C:\Users\Jakub\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe
[2012.06.14 04:09:06 | 000,181,776 | ---- | M] (Dropbox, Inc.) -- C:\Users\Jakub\AppData\Roaming\Dropbox\bin\Uninstall.exe
[2012.03.26 14:54:38 | 001,832,448 | ---- | M] (Mozilla Gecko Tab) -- C:\Users\Jakub\AppData\Roaming\Chrome\Extension\firefoxtab\core\GeckoTab_core.exe
[2012.03.30 18:56:58 | 000,010,134 | R--- | M] () -- C:\Users\Jakub\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2012.08.14 12:26:19 | 040,322,472 | ---- | M] (COMPELSON Laboratories ) -- C:\Users\Jakub\AppData\Roaming\MOBILedit\MOBILEditUpdate.exe
[2013.07.09 11:29:28 | 000,118,784 | ---- | M] (obsproject.com) -- C:\Users\Jakub\AppData\Roaming\OBS\updates\updater.exe
[2013.07.21 16:43:09 | 001,104,384 | ---- | M] (Spotify Ltd) -- C:\Users\Jakub\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
[2012.08.13 14:51:17 | 000,158,000 | ---- | M] () -- C:\Users\Jakub\AppData\Roaming\Thunderbird\Profiles\aqfafplp.default\FlashGot.exe
[2012.11.29 03:52:32 | 000,572,064 | ---- | M] (WildTangent, Inc.) -- C:\Users\Jakub\AppData\Roaming\WildTangent\WildTangent Games\App\Update\Updater.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2013.09.02 16:44:06 | 000,000,018 | ---- | M] () -- C:\Windows\system32\log.txt
[2 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"OscarX7Mouse5Mode" = "C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe" Minimum -- [2012.03.20 18:52:10 | 003,521,024 | ---- | M] ()
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2010.11.21 05:24:51 | 001,475,584 | ---- | M] (Microsoft Corporation)
"GoogleChromeAutoLaunch_7B684F571039795D9613652596821858" = "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window -- [2013.08.24 19:49:56 | 000,829,392 | ---- | M] (Google Inc.)
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k netsvcs
< >
< type c:\boot.ini >> test.txt /c >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.09.02 18:12:26 | 000,000,512 | ---- | M] () MD5=706E7361CFA7B93E06E008FAB704E4D0 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
[2013.08.01 22:11:10 | 000,003,608 | ---- | M] () -- \Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.cracked.com_0.localstorage-journal
< *keygen* /s >
< *AntiWPA* /s >
< *loader* /s >
[2013.05.16 16:41:22 | 001,152,288 | ---- | M] () -- \NVIDIA\DisplayDriver\GeForce320.18Driver\ExtensionLoader.dll
[2013.05.16 16:41:22 | 001,152,288 | ---- | M] () -- \NVIDIA\DisplayDriver\GeForce320.18Driver\GFExperience\ExtensionLoader.dll
[2013.05.16 16:41:22 | 001,152,288 | ---- | M] () -- \NVIDIA\DisplayDriver\GeForce320.49Driver\ExtensionLoader.dll
[2013.05.16 16:41:22 | 001,152,288 | ---- | M] () -- \NVIDIA\DisplayDriver\GeForce320.49Driver\GFExperience\ExtensionLoader.dll
[2003.10.15 09:05:18 | 000,004,960 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_de\images\LoaderBar.gif
[2003.10.15 09:03:28 | 000,001,064 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_de\images\_LoaderBar.gif
[2003.10.15 01:05:18 | 000,004,960 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_default\images\LoaderBar.gif
[2003.10.15 01:03:28 | 000,001,064 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_default\images\_LoaderBar.gif
[2003.10.15 09:05:18 | 000,004,960 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_es\images\LoaderBar.gif
[2003.10.15 09:03:28 | 000,001,064 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_es\images\_LoaderBar.gif
[2003.10.15 09:05:18 | 000,004,960 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_fr\images\LoaderBar.gif
[2003.10.15 09:03:28 | 000,001,064 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_fr\images\_LoaderBar.gif
[2003.10.15 09:05:18 | 000,004,960 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_it\images\LoaderBar.gif
[2003.10.15 09:03:28 | 000,001,064 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_it\images\_LoaderBar.gif
[2003.10.15 09:05:18 | 000,004,960 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_ko\images\LoaderBar.gif
[2003.10.15 09:03:28 | 000,001,064 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_ko\images\_LoaderBar.gif
[2008.09.20 04:11:24 | 000,004,960 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_zh\images\LoaderBar.gif
[2008.09.20 04:11:24 | 000,001,064 | ---- | M] () -- \Program Files (x86)\Acer Games\Zuma Deluxe\wtmui_zh\images\_LoaderBar.gif
[2012.05.04 22:15:18 | 000,127,464 | ---- | M] () -- \Program Files (x86)\Acer\Acer Crystal Eye Webcam\Koan\pyloader.dll
[2012.05.04 22:14:46 | 000,021,172 | ---- | M] () -- \Program Files (x86)\Acer\Acer Crystal Eye Webcam\subsys\Uploader\PyUploader.kc
[2012.05.07 18:19:56 | 000,233,960 | ---- | M] () -- \Program Files (x86)\Acer\Acer Crystal Eye Webcam\subsys\Uploader\_PyUploader.pyd
[2009.04.02 22:23:53 | 000,013,833 | ---- | M] () -- \Program Files (x86)\City interactive\MOTORM4X Offroad Extreme\media\texts\texts_loader.xml
[2010.10.07 05:36:40 | 000,265,552 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2010.10.07 05:36:40 | 000,018,264 | ---- | M] () -- \Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2013.02.09 03:39:28 | 000,000,934 | ---- | M] () -- \Program Files (x86)\Google\Picasa3\runtime\gpuploader_main.fen
[2009.05.21 21:21:18 | 000,007,507 | ---- | M] () -- \Program Files (x86)\HP\Digital Imaging\HelpViewer\Resources\Loader.swf
[2009.09.20 13:15:26 | 000,030,776 | ---- | M] () -- \Program Files (x86)\HP\Digital Imaging\smart web printing\RsrcLoaderLib.dll
[2009.09.20 13:15:26 | 000,002,713 | ---- | M] () -- \Program Files (x86)\HP\Digital Imaging\smart web printing\MozillaAddOn3\xre\components\uriloader.xpt
[2013.02.07 13:08:45 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\BUR\CSS\images\ajax-loader.gif
[2013.01.29 15:09:48 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\CSY\CSS\images\ajax-loader.gif
[2013.01.29 15:09:53 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\DAN\CSS\images\ajax-loader.gif
[2013.01.29 15:09:57 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\DEU\CSS\images\ajax-loader.gif
[2013.01.29 15:10:00 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\ENU\CSS\images\ajax-loader.gif
[2013.01.29 15:10:04 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\ESP\CSS\images\ajax-loader.gif
[2013.01.29 15:10:07 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\FRA\CSS\images\ajax-loader.gif
[2013.01.29 15:09:39 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\CHS\CSS\images\ajax-loader.gif
[2013.01.29 15:09:44 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\CHT\CSS\images\ajax-loader.gif
[2013.01.29 15:10:11 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\ITA\CSS\images\ajax-loader.gif
[2013.01.29 15:10:15 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\JPN\CSS\images\ajax-loader.gif
[2013.01.29 15:10:20 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\NOR\CSS\images\ajax-loader.gif
[2013.01.29 15:10:25 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\PLK\CSS\images\ajax-loader.gif
[2013.01.29 15:10:28 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\PTG\CSS\images\ajax-loader.gif
[2013.01.29 15:10:33 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\RUS\CSS\images\ajax-loader.gif
[2013.01.29 15:10:39 | 000,000,847 | ---- | M] () -- \Program Files (x86)\HTC\HTC Sync Manager\ui\Help\SVE\CSS\images\ajax-loader.gif
[2012.10.13 11:42:23 | 000,000,948 | ---- | M] () -- \Program Files (x86)\Java\jdk1.7.0_07\lib\visualvm\platform\config\ModuleAutoDeps\org-openide-loaders.xml
[2012.10.13 11:42:23 | 000,000,411 | ---- | M] () -- \Program Files (x86)\Java\jdk1.7.0_07\lib\visualvm\platform\config\Modules\org-openide-loaders.xml
[2012.10.13 11:42:26 | 001,170,520 | ---- | M] () -- \Program Files (x86)\Java\jdk1.7.0_07\lib\visualvm\platform\modules\org-openide-loaders.jar
[2012.10.13 11:42:25 | 000,006,244 | ---- | M] () -- \Program Files (x86)\Java\jdk1.7.0_07\lib\visualvm\platform\modules\locale\org-openide-loaders_ja.jar
[2012.10.13 11:42:25 | 000,005,873 | ---- | M] () -- \Program Files (x86)\Java\jdk1.7.0_07\lib\visualvm\platform\modules\locale\org-openide-loaders_zh_CN.jar
[2012.10.13 11:42:26 | 000,000,457 | ---- | M] () -- \Program Files (x86)\Java\jdk1.7.0_07\lib\visualvm\platform\update_tracking\org-openide-loaders.xml
[2005.10.14 02:49:48 | 000,017,624 | ---- | M] () -- \Program Files (x86)\Microsoft SQL Server\90\Tools\Binn\SqlResourceLoader.dll
[2005.10.14 02:49:48 | 000,017,624 | ---- | M] () -- \Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SqlResourceLoader.dll
[2013.08.27 23:16:20 | 001,177,888 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\ExtensionLoader.dll
[2013.06.04 10:57:24 | 000,057,224 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll
[2013.06.04 10:57:24 | 000,065,416 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader64.dll
[2013.06.04 10:57:24 | 000,083,848 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXUpdateLoader.dll
[2013.06.04 10:57:24 | 000,088,968 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXUpdateLoader64.dll
[2013.07.10 22:08:32 | 000,029,696 | ---- | M] () -- \Program Files (x86)\OpenOffice 4\program\javaloader.uno.dll
[2013.07.16 15:31:10 | 000,005,813 | ---- | M] () -- \Program Files (x86)\OpenOffice 4\program\pythonloader.py
[2013.07.10 22:08:34 | 000,020,992 | ---- | M] () -- \Program Files (x86)\OpenOffice 4\program\pythonloader.uno.dll
[2013.07.16 15:35:46 | 000,000,171 | ---- | M] () -- \Program Files (x86)\OpenOffice 4\program\pythonloader.uno.ini
[2013.07.16 15:21:10 | 000,003,868 | ---- | M] () -- \Program Files (x86)\OpenOffice 4\program\classes\unoloader.jar
[2013.07.10 15:46:18 | 000,013,420 | ---- | M] () -- \Program Files (x86)\OpenOffice 4\program\python-core-2.7.5\lib\unittest\loader.py
[2011.09.09 20:18:39 | 018,632,952 | ---- | M] () -- \Program Files (x86)\Sony Media Go Install\PSNDownloaderSetup.exe
[2012.05.21 23:56:04 | 000,002,196 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\GamePlay_Loader.html
[2012.07.19 01:18:28 | 000,000,598 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\EULA\images\downloader_bg_400.gif
[2012.05.21 23:56:04 | 000,009,085 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\Scripts\gameplay_loader.js
[2010.11.03 23:17:00 | 000,002,355 | ---- | M] () -- \Program Files (x86)\WildTangent Games\App\UI\Skins\default\gameplay_loader.css
[2013.08.27 23:16:20 | 001,177,888 | ---- | M] () -- \Program Files\NVIDIA Corporation\Installer2\Display.GFExperience.{9D9368B6-BA54-4DCE-A190-7E9BFEC9F4E9}\ExtensionLoader.dll
[2012.06.09 19:19:37 | 000,055,296 | ---- | M] () -- \Program Files\WinRAR\Formats\ace32loader.exe
[2012.12.04 18:00:50 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2012.12.04 18:00:50 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2012.12.04 18:00:50 | 000,009,772 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\retina\
loader@2x.png
[2012.12.04 18:00:50 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2012.12.04 18:00:50 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2012.12.04 18:00:50 | 000,009,772 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\retina\
loader@2x.png
[2012.03.09 21:45:21 | 000,000,445 | ---- | M] () -- \Users\Jakub\AppData\Local\Downloader\Downloader.ini
[2013.06.25 10:00:24 | 000,454,720 | ---- | M] () -- \Users\Jakub\AppData\Local\Flvto Youtube Downloader\FlvtoYoutubeDownloader.exe
[2013.06.10 10:28:54 | 000,004,322 | ---- | M] () -- \Users\Jakub\AppData\Local\Flvto Youtube Downloader\FlvtoYoutubeDownloader.exe.config
[2013.06.26 22:16:26 | 000,146,372 | ---- | M] () -- \Users\Jakub\AppData\Local\Flvto Youtube Downloader\UninstallFlvtoYoutubeDownloader.exe
[2013.06.25 10:00:22 | 000,012,864 | ---- | M] () -- \Users\Jakub\AppData\Local\Flvto Youtube Downloader\en-US\FlvtoYoutubeDownloader.resources.dll
[2013.08.30 19:22:49 | 000,002,867 | ---- | M] () -- \Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbdjiinahkdjdcdlgfimlcolkjpbooja\2.6.17_0\css\Chrome-YouTube-Downloader.css
[2013.08.30 19:22:49 | 000,009,002 | ---- | M] () -- \Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbdjiinahkdjdcdlgfimlcolkjpbooja\2.6.17_0\script\Chrome-YouTube-Downloader.js
[2012.11.18 22:45:13 | 000,001,849 | ---- | M] () -- \Users\Jakub\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhfkcobomkalfdlmkongnhnhahkmnaad\1.1.1_0\lib\SlickGrid\images\ajax-loader-small.gif
[2012.11.04 21:43:58 | 000,738,570 | ---- | M] () -- \Users\Jakub\AppData\Local\HTC MediaHub\htcSyncLoader.bmp
[2013.07.16 13:35:02 | 000,000,404 | ---- | M] () -- \Users\Jakub\AppData\Local\Microsoft\Windows Sidebar\Gadgets\teamspeak.gadget\images\ajax-loader.gif
[2012.03.20 08:23:25 | 000,000,843 | ---- | M] () -- \Users\Jakub\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fflashvideodownloader.org%2Ffvd-suite%2Fsystem%2Fapplication%2Fviews%2Fthemes%2Ffvd%2Ffavicon.png
[2012.03.17 10:29:50 | 000,040,660 | ---- | M] () -- \Users\Jakub\AppData\Local\Opera\Opera\widgets\fastesttube-youtube-video-downloader-1.5.4-1.oex
[2013.08.27 23:16:20 | 001,177,888 | ---- | M] () -- \Users\Jakub\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\8.3.14.1\GFExperience\ExtensionLoader.dll
[2012.08.03 13:59:39 | 000,001,052 | ---- | M] () -- \Users\Jakub\AppData\Roaming\.minecraft\ModLoader.txt
[2012.08.03 13:59:34 | 000,000,126 | ---- | M] () -- \Users\Jakub\AppData\Roaming\.minecraft\config\ModLoader.cfg
[2012.11.04 21:44:20 | 245,184,699 | ---- | M] () -- \Users\Jakub\AppData\Roaming\HTC Sync\htcSyncLoader.dmp
[2013.06.26 22:16:26 | 000,002,191 | ---- | M] () -- \Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flvto Youtube Downloader\Flvto Youtube Downloader.lnk
[2013.06.26 22:16:26 | 000,002,177 | ---- | M] () -- \Users\Jakub\Desktop\Flvto Youtube Downloader.lnk
[2013.06.26 22:05:01 | 000,098,116 | ---- | M] () -- \Users\Jakub\Downloads\chrome-youtube-downloader-2.6.5 (1).crx
[2013.06.26 22:04:32 | 000,098,116 | ---- | M] () -- \Users\Jakub\Downloads\chrome-youtube-downloader-2.6.5.crx
[2012.12.18 21:35:50 | 000,015,528 | ---- | M] () -- \Windows\assembly\tmp\40JVKJOD\Microsoft.Office.Infopath.CLRLoader.dll
[2012.12.18 22:10:42 | 000,015,528 | ---- | M] () -- \Windows\assembly\tmp\HHURJ1IO\Microsoft.Office.Infopath.CLRLoader.dll
[2010.10.07 05:36:40 | 000,018,264 | ---- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109110000000000000000F01FEC\14.0.6029\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2010.10.07 05:36:40 | 000,265,552 | ---- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109110000000000000000F01FEC\14.0.6029\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2012.11.30 06:45:15 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2 \Windows\System32\*.tmp files -> \Windows\System32\*.tmp -> ]
[2012.04.26 14:26:34 | 000,012,532 | ---- | M] () -- \Windows\System32\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2012.11.30 06:45:15 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.07.14 03:15:12 | 000,038,400 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2 \Windows\SysWOW64\*.tmp files -> \Windows\SysWOW64\*.tmp -> ]
[2012.04.26 14:26:34 | 000,012,532 | ---- | M] () -- \Windows\SysWOW64\Adobe\Shockwave 11\shockwave_Projector_Loader.dcr
[2009.07.14 03:40:31 | 000,047,616 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_a1e90d98a953d601\dmloader.dll
[2009.07.14 03:24:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_66a6e19d9580f9e3\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.05.14 09:04:21 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17617_none_68daf829926cc6a9\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.03 08:44:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17625_none_68ce27a99276afec\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 07:21:03 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17651_none_68a9b6bd92929e63\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.08.20 20:38:32 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17932_none_68c05c919281774d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 19:38:48 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.17965_none_68a2edab92971725\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 07:38:44 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18015_none_68d8d569926ebeb2\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.05.14 09:00:38 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21728_none_695ac552ab919bbb\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.06.03 08:40:10 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21738_none_694ff566ab99b7ac\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.07.16 07:12:44 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.21772_none_691eb3faabbf8f66\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.08.20 20:09:47 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22091_none_6907efc6abd0db81\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.10.04 19:35:00 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22125_none_6957a248ab947a6d\api-ms-win-core-libraryloader-l1-1-0.dll
[2012.11.30 07:39:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22177_none_69239340abbb38d0\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.01.04 07:32:07 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22209_none_6971452eab80a50e\api-ms-win-core-libraryloader-l1-1-0.dll
[2013.07.08 07:11:20 | 000,003,584 | ---- | M] () -- \Windows\winsxs\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22379_none_692597a0abb965cc\api-ms-win-core-libraryloader-l1-1-0.dll
[2011.10.09 01:39:02 | 000,004,431 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc.manifest
[2011.10.09 01:39:02 | 000,033,360 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winload.efi.mui_35ee487d
[2011.10.09 01:39:02 | 000,034,896 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winload.exe.mui_3bc5b827
[2011.10.09 01:39:02 | 000,029,776 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_cs-cz_8f37605116ba80bc_winresume.efi.mui_f412814e
[2011.10.09 01:39:02 | 000,030,288 | ---- | M] () -- \Windows\winsxs\Backup\amd64_microsoft-windows-b..os-