Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivka s menším podezřením

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Lothaire
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 pro 2009 21:20

Preventivka s menším podezřením

#1 Příspěvek od Lothaire »

Zdravím dobré duše tohoto fóra,

v poslední době pozoruji u svého NTB známky zpomalení. Jednu dobu to bylo opravdu špatné, nechal jsem tedy řádit antivir a defragmentoval jsem disk. Zlepšení nastalo, pořád to ale není to, co bývalo, tak bych si raději pro jistotu nechal zkontrolovat log. Trochu se i bojím aby něco nebylo špatně s hardwarem, notebook se dost často přenáší a i když se snažím, neodpřísahal bych, že do něj nikdy nikdo na přednášce, byť jen trochu, nekopl. Předem děkuji za pomoc :)


Logfile of random's system information tool 1.10 (written by random/random)
Run by Martin at 2014-10-18 18:34:54
Microsoft Windows 8.1
System drive C: has 194 GB (21%) free of 905 GB
Total RAM: 8048 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:35:01, on 18. 10. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files\trend micro\Martin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: BS Player ControlBar B Toolbar - {31264a33-a653-46c4-af49-1232c59a7da5} - C:\Users\Martin\AppData\LocalLow\BS_Player_ControlBar_B\prxtbBS_P.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: BS Player ControlBar B - {31264a33-a653-46c4-af49-1232c59a7da5} - C:\Users\Martin\AppData\LocalLow\BS_Player_ControlBar_B\prxtbBS_P.dll
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: BS Player ControlBar B Toolbar - {31264a33-a653-46c4-af49-1232c59a7da5} - C:\Users\Martin\AppData\LocalLow\BS_Player_ControlBar_B\prxtbBS_P.dll
O4 - HKLM\..\Run: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [GIGABYTEMOUSE] C:\Users\Martin\Documents\GIGABYTE\GIGABYTE Sim\Mouse.exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE
O4 - Startup: Logitech . Registrace produktu.lnk = C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
O4 - Startup: PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: Stáhnout s Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.connectify.me
O15 - ESC Trusted Zone: http://*.fastspring.com
O15 - ESC Trusted Zone: http://*.connectify.me (HKLM)
O15 - ESC Trusted Zone: http://*.fastspring.com (HKLM)
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\WINDOWS\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\WINDOWS\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Toolbar Service (TBSrv) - ClientConnect Ltd. - C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13680 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
"dwm.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
dashost.exe {acc05985-cd34-47df-97ff2d6fb9e5ad4a}
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\WINDOWS\SysWOW64\PnkBstrA.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 22c864bf-d70c-4904-aedf-066685ed3627 1
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-a3ad0198-379a-4a86-ba6a-b2ba3fb951a7 -SystemEventPortName:HostProcess-445fd0f5-6316-4024-84fe-94a6a62edf22 -IoCancelEventPortName:HostProcess-9409721d-f25b-4f41-8d17-bcdae3b279a7 -NonStateChangingEventPortName:HostProcess-ada47dad-d77d-4a28-9c38-ec40ad8fd4ac -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:91c98981-7c5f-49d1-9b45-f6754a5598c9 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3872.0.1489664876\1211396255" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,17 --gpu-vendor-id=0x8086 --gpu-device-id=0x0166 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=9.17.10.2932 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.2.1571808879\1845880458" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.3.588469538\1991341812" /prefetch:673131151
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe" -start
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.4.453126854\1345211877" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.6.1447910585\1591096749" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.8.1728807172\2136275183" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.10.1147930331\1038608934" /prefetch:673131151
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files\Elantech\ETDIntelligent.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Windows\System32\StikyNot.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.12.1090978104\142840539" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.13.1991983977\792827097" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.14.482119964\1923813486" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.15.521594329\776998519" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.16.294601312\535352604" /prefetch:673131151
"C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.17.1622122863\557495133" /prefetch:673131151
"C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.18.712191381\319998192" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.19.1639927601\1355893210" /prefetch:673131151
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.63.256899039\779902129" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.101.1000774533\787796442" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.104.282788466\217465277" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.109.525897782\1559943236" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3872.139.300727429\131586593" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.144.1615484902\1264983318" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.147.749790333\1218595691" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.148.1566885991\270096030" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.156.1072640035\1056661097" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.159.342210804\1925673473" /prefetch:673131151
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe26_ Global\UsGthrCtrlFltPipeMssGthrPipe26 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/PP_Ethersuggest_A6_Stable_R8/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_50/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3872.162.20219260\1538545235" /prefetch:673131151
"C:\Users\Martin\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1410772076-1682251192-4122739941-1002Core.job - C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1410772076-1682251192-4122739941-1002UA.job - C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\7vni0jbm.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@lastpass.com/NPLastPass]
"Description"=
"Path"=C:\Program Files (x86)\LastPass\nplastpass.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@lastpass.com/NPLastPass]
"Description"=
"Path"=C:\Program Files (x86)\LastPass\nplastpass64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@unity3d.com/UnityPlayer64,version=1.0]
"Description"=Unity Player 4.5.4f2
"Path"=C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
nppdf32.CZE
nppdf32.dll
nppdf32.HRV
nppdf32.HUN
nppdf32.POL
nppdf32.SKY
nppdf32.SLV
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
QuickTimePlugin.class

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-09-25 218784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-09-20 553896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-09-30 64640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-08-02 612248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2013-07-31 433944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2014-09-16 2334416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-09-20 211880]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31264a33-a653-46c4-af49-1232c59a7da5}]
BS Player ControlBar B Toolbar - C:\Users\Martin\AppData\LocalLow\BS_Player_ControlBar_B\prxtbBS_P.dll [2014-04-10 423744]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-09-25 153240]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-25 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-08-02 457712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-09-04 343456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2013-07-31 364824]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2014-09-16 1729232]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-25 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-09-04 343456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}
{31264A33-A653-46C4-AF49-1232C59A7DA5} - BS Player ControlBar B Toolbar - C:\Users\Martin\AppData\LocalLow\BS_Player_ControlBar_B\prxtbBS_P.dll [2014-04-10 423744]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-09-04 343456]
{31264a33-a653-46c4-af49-1232c59a7da5} - BS Player ControlBar B Toolbar - C:\Users\Martin\AppData\LocalLow\BS_Player_ControlBar_B\prxtbBS_P.dll [2014-04-10 423744]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2012-09-05 2872720]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-10-26 13213840]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2012-10-29 1234064]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2012-08-27 6334096]
"BtPreLoad"=C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [2012-09-30 64640]
"OnekeyStudio"=C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [2012-09-15 4196432]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2012-12-05 17080376]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2012-12-05 191544]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-10-04 2463552]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-10-04 2800296]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2012-12-19 172168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2012-12-19 400008]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2012-12-19 441992]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2013-07-31 3091224]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2012-09-20 3933496]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2013-12-21 116648]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2004-04-17 196608]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2013-11-14 457728]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [2014-03-13 779776]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Dolby Home Theater v4"=C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [2012-07-26 508656]
"YouCam Mirage"=C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27 136488]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-07-27 167024]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2012-04-19 217088]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2012-03-29 91432]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-02 4085896]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2004-04-13 69632]
"GIGABYTEMOUSE"=C:\Users\Martin\Documents\GIGABYTE\GIGABYTE Sim\Mouse.exe [2013-10-14 1304576]
""= []
"Adobe Acrobat Speed Launcher"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [2014-09-04 41360]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2014-09-04 840592]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-25 256896]

C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Logitech . Registrace produktu.lnk - C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
PdaNet Desktop.lnk - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\windows\system32\nvinitx.dll,C:\WINDOWS\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2012-12-13 442880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2013-06-13 66328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"DisableCAD"=1
"PromptOnSecureDesktop"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"midi3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"

======List of files/folders created in the last 1 month======

2014-10-18 18:34:54 ----D---- C:\rsit
2014-10-18 18:34:54 ----D---- C:\Program Files\trend micro
2014-10-18 15:18:35 ----D---- C:\Program Files (x86)\Font Xplorer
2014-10-17 14:00:19 ----D---- C:\ProgramData\Last.fm
2014-10-17 14:00:19 ----D---- C:\Program Files (x86)\Winamp
2014-10-17 13:58:33 ----D---- C:\Program Files (x86)\Last.fm
2014-10-16 12:51:47 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-10-16 12:51:47 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-10-16 12:51:44 ----A---- C:\WINDOWS\system32\winbici.dll
2014-10-16 12:51:03 ----A---- C:\WINDOWS\system32\generaltel.dll
2014-10-16 12:51:03 ----A---- C:\WINDOWS\system32\aepdu.dll
2014-10-16 12:51:02 ----A---- C:\WINDOWS\system32\aeinv.dll
2014-10-16 12:50:34 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2014-10-16 12:50:34 ----A---- C:\WINDOWS\system32\msi.dll
2014-10-15 21:25:31 ----D---- C:\Program Files\IHMC CmapTools
2014-10-15 15:29:51 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2014-10-15 15:28:00 ----A---- C:\WINDOWS\system32\win32k.sys
2014-10-15 15:27:32 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-10-15 15:27:32 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wuwebv.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wups2.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wups.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-10-15 15:27:30 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2014-10-15 15:27:30 ----A---- C:\WINDOWS\system32\wuapp.exe
2014-10-15 15:26:50 ----A---- C:\WINDOWS\system32\authui.dll
2014-10-15 15:26:49 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-10-15 15:26:49 ----A---- C:\WINDOWS\system32\appinfo.dll
2014-10-15 15:26:40 ----A---- C:\WINDOWS\system32\shell32.dll
2014-10-15 15:26:38 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-10-15 15:26:37 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-10-15 15:26:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-10-15 15:26:33 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-10-15 15:26:32 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-10-15 15:26:31 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2014-10-15 15:26:30 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-10-15 15:26:28 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-10-15 15:26:27 ----A---- C:\WINDOWS\system32\ntdll.dll
2014-10-15 15:26:27 ----A---- C:\WINDOWS\system32\KernelBase.dll
2014-10-15 15:26:26 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2014-10-15 15:26:26 ----A---- C:\WINDOWS\system32\propsys.dll
2014-10-15 15:26:25 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-10-15 15:26:24 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-10-15 15:26:24 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2014-10-15 15:26:24 ----A---- C:\WINDOWS\system32\Wldap32.dll
2014-10-15 15:26:24 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-10-15 15:26:23 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2014-10-15 15:26:22 ----A---- C:\WINDOWS\SYSWOW64\Wldap32.dll
2014-10-15 15:26:21 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2014-10-15 15:26:21 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-10-15 15:26:19 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-10-15 15:26:19 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2014-10-15 15:26:19 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-10-15 15:26:19 ----A---- C:\WINDOWS\system32\bisrv.dll
2014-10-15 15:26:18 ----A---- C:\WINDOWS\system32\pcsvDevice.dll
2014-10-15 15:26:18 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2014-10-15 15:26:17 ----A---- C:\WINDOWS\SYSWOW64\SkyDriveShell.dll
2014-10-15 15:26:17 ----A---- C:\WINDOWS\system32\SkyDriveShell.dll
2014-10-15 15:26:17 ----A---- C:\WINDOWS\system32\ProximityService.dll
2014-10-15 15:26:17 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-10-15 15:26:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 15:26:14 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 15:25:32 ----A---- C:\WINDOWS\SYSWOW64\packager.dll
2014-10-15 15:25:32 ----A---- C:\WINDOWS\system32\packager.dll
2014-10-15 15:23:52 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-10-15 15:23:45 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-10-15 15:23:35 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-10-15 15:23:32 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-10-15 15:23:28 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-10-15 15:23:25 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-10-15 15:23:22 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-10-15 15:23:21 ----A---- C:\WINDOWS\system32\wininet.dll
2014-10-15 15:23:20 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-10-15 15:23:18 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-10-15 15:23:18 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-10-15 15:23:15 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-10-15 15:23:15 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-10-15 15:23:13 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-10-15 15:23:10 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-10-15 15:23:09 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-10-15 15:23:09 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-10-15 15:23:05 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-10-15 15:23:01 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2014-10-15 15:23:01 ----A---- C:\WINDOWS\system32\rastls.dll
2014-10-14 14:10:46 ----D---- C:\Program Files\Defraggler
2014-10-05 16:54:42 ----D---- C:\Program Files (x86)\Sherlock Holmes Crimes and Punishments
2014-10-03 16:27:04 ----D---- C:\Users\Martin\AppData\Roaming\Unity
2014-10-03 15:46:23 ----D---- C:\Program Files\Unity
2014-09-28 01:32:15 ----D---- C:\Users\Martin\AppData\Roaming\WebApp
2014-09-25 16:58:21 ----D---- C:\WINDOWS\SYSWOW64\NV
2014-09-25 16:58:21 ----D---- C:\WINDOWS\system32\NV
2014-09-25 16:57:49 ----D---- C:\NVIDIA Corporation
2014-09-25 15:15:11 ----D---- C:\Program Files (x86)\Quake Live
2014-09-21 18:14:15 ----D---- C:\Program Files (x86)\Saints Row IV
2014-09-21 18:11:10 ----D---- C:\Program Files (x86)\AGEIA Technologies
2014-09-21 18:10:31 ----A---- C:\WINDOWS\SYSWOW64\nvStreaming.exe
2014-09-21 18:07:11 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2014-09-21 18:07:11 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2014-09-21 18:07:11 ----A---- C:\WINDOWS\system32\drivers\nvpciflt.sys
2014-09-21 18:07:10 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\SYSWOW64\nvoglshim32.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\nvopencl.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\nvoglshim64.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\nvdispgenco6434411.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\nvdispco6434411.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\nvcuda.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2014-09-21 18:07:10 ----A---- C:\WINDOWS\system32\drivers\nvlddmkm.sys
2014-09-21 17:40:04 ----A---- C:\WINDOWS\system32\drivers\nvvad64v.sys
2014-09-21 17:40:00 ----A---- C:\WINDOWS\SYSWOW64\nvaudcap32v.dll
2014-09-20 16:04:15 ----A---- C:\WINDOWS\SYSWOW64\javaws.exe
2014-09-20 16:04:11 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll
2014-09-20 16:04:11 ----A---- C:\WINDOWS\SYSWOW64\javaw.exe
2014-09-20 16:04:11 ----A---- C:\WINDOWS\SYSWOW64\java.exe
2014-09-20 15:21:05 ----A---- C:\WINDOWS\system32\javaws.exe
2014-09-20 15:20:55 ----A---- C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2014-09-20 15:20:55 ----A---- C:\WINDOWS\system32\javaw.exe
2014-09-20 15:20:55 ----A---- C:\WINDOWS\system32\java.exe
2014-09-20 14:39:45 ----D---- C:\Users\Martin\AppData\Roaming\Galaxy on Fire 2 Full HD
2014-09-20 14:34:05 ----D---- C:\Program Files (x86)\Google

======List of files/folders modified in the last 1 month======

2014-10-18 18:35:01 ----D---- C:\WINDOWS\Prefetch
2014-10-18 18:34:54 ----D---- C:\Program Files
2014-10-18 18:00:01 ----D---- C:\WINDOWS\system32\sru
2014-10-18 16:44:31 ----D---- C:\WINDOWS\system32\config
2014-10-18 16:42:32 ----D---- C:\WINDOWS\Temp
2014-10-18 15:55:30 ----RSD---- C:\WINDOWS\Fonts
2014-10-18 15:18:35 ----RD---- C:\Program Files (x86)
2014-10-18 11:11:26 ----D---- C:\WINDOWS\rescache
2014-10-18 11:06:29 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-18 10:16:58 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-10-18 10:15:34 ----D---- C:\WINDOWS\WinSxS
2014-10-18 10:14:55 ----D---- C:\WINDOWS\Inf
2014-10-18 10:14:16 ----D---- C:\ProgramData\NVIDIA
2014-10-18 10:13:06 ----SD---- C:\WINDOWS\system32\CompatTel
2014-10-18 10:13:06 ----RD---- C:\WINDOWS\System32
2014-10-18 10:13:06 ----D---- C:\WINDOWS\SysWOW64
2014-10-18 10:13:06 ----D---- C:\WINDOWS\MediaViewer
2014-10-18 10:13:06 ----D---- C:\WINDOWS\FileManager
2014-10-18 10:13:06 ----D---- C:\WINDOWS\Camera
2014-10-18 08:33:46 ----D---- C:\WINDOWS\AppReadiness
2014-10-18 04:29:38 ----SHD---- C:\System Volume Information
2014-10-17 21:03:04 ----D---- C:\Users\Martin\AppData\Roaming\vlc
2014-10-17 14:00:19 ----HD---- C:\ProgramData
2014-10-17 10:15:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-16 14:46:21 ----D---- C:\WINDOWS\system32\drivers
2014-10-16 14:01:10 ----D---- C:\WINDOWS\CbsTemp
2014-10-16 13:29:07 ----D---- C:\Program Files (x86)\Battle.net
2014-10-16 12:01:10 ----D---- C:\WINDOWS\system32\FxsTmp
2014-10-16 11:59:33 ----D---- C:\Users\Martin\AppData\Roaming\VMware
2014-10-15 20:50:29 ----D---- C:\Users\Martin\AppData\Roaming\Skype
2014-10-15 18:19:18 ----RSD---- C:\WINDOWS\assembly
2014-10-15 17:13:54 ----SHD---- C:\Config.Msi
2014-10-15 16:35:53 ----RD---- C:\WINDOWS\ToastData
2014-10-15 16:35:53 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-10-15 16:35:53 ----D---- C:\WINDOWS\system32\cs-CZ
2014-10-15 16:35:53 ----D---- C:\Program Files\Internet Explorer
2014-10-15 16:35:53 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-15 16:35:52 ----D---- C:\WINDOWS\WinStore
2014-10-15 16:35:51 ----D---- C:\WINDOWS\system32\DriverStore
2014-10-15 15:35:59 ----SHD---- C:\WINDOWS\Installer
2014-10-15 15:33:29 ----D---- C:\ProgramData\Microsoft Help
2014-10-15 15:30:53 ----A---- C:\WINDOWS\win.ini
2014-10-15 15:20:00 ----D---- C:\WINDOWS\system32\catroot2
2014-10-14 17:50:09 ----D---- C:\Users\Martin\AppData\Roaming\Webshare
2014-10-14 15:05:26 ----D---- C:\Program Files (x86)\WarThunder
2014-10-14 14:54:15 ----D---- C:\WINDOWS\system32\Tasks
2014-10-14 14:08:43 ----D---- C:\Windows
2014-10-14 13:28:40 ----D---- C:\ProgramData\Origin
2014-10-14 13:28:39 ----D---- C:\Program Files (x86)\Steam
2014-10-14 12:19:09 ----D---- C:\Program Files (x86)\Origin
2014-10-12 16:08:29 ----HD---- C:\Program Files\WindowsApps
2014-10-05 15:14:44 ----D---- C:\Program Files (x86)\Hearthstone
2014-10-05 14:00:03 ----D---- C:\Program Files (x86)\The Elder Scrolls V Skyrim
2014-10-04 08:42:47 ----A---- C:\WINDOWS\SYSWOW64\nvspcap.dll
2014-10-04 08:42:47 ----A---- C:\WINDOWS\SYSWOW64\nvspbridge.dll
2014-10-04 08:41:43 ----A---- C:\WINDOWS\system32\nvspcap64.dll
2014-10-04 08:41:43 ----A---- C:\WINDOWS\system32\nvspbridge64.dll
2014-10-03 12:36:02 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2014-10-02 10:32:14 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-02 10:29:55 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-30 00:45:58 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-09-26 21:19:13 ----D---- C:\Program Files (x86)\Glyph
2014-09-25 22:03:58 ----D---- C:\Program Files\WinRAR
2014-09-25 22:03:58 ----D---- C:\Program Files (x86)\SugarSync
2014-09-25 22:03:58 ----D---- C:\Program Files (x86)\SageThumbs
2014-09-25 22:03:58 ----D---- C:\Program Files (x86)\JDownloader
2014-09-25 22:03:58 ----D---- C:\Program Files (x86)\In Verbis Virtus
2014-09-25 22:03:58 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2014-09-21 18:10:40 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-09-21 17:45:56 ----D---- C:\Program Files\NVIDIA Corporation
2014-09-20 16:47:36 ----D---- C:\WINDOWS\Logs
2014-09-20 16:27:01 ----D---- C:\Program Files (x86)\2K Games
2014-09-20 16:23:42 ----D---- C:\Users\Martin\AppData\Roaming\DAEMON Tools Lite
2014-09-20 16:04:32 ----D---- C:\ProgramData\Oracle
2014-09-20 16:04:18 ----D---- C:\Program Files (x86)\Common Files
2014-09-20 16:04:11 ----D---- C:\Program Files (x86)\Java
2014-09-20 15:20:45 ----D---- C:\Program Files\Java
2014-09-20 14:34:07 ----D---- C:\WINDOWS\Tasks
2014-09-20 01:12:13 ----D---- C:\WINDOWS\SYSWOW64\wbem
2014-09-20 01:12:13 ----D---- C:\Program Files\Windows Journal
2014-09-20 01:12:12 ----D---- C:\WINDOWS\SYSWOW64\setup
2014-09-20 01:12:11 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-09-20 01:12:11 ----D---- C:\WINDOWS\system32\wbem
2014-09-20 01:12:11 ----D---- C:\WINDOWS\system32\setup
2014-09-20 01:12:11 ----D---- C:\WINDOWS\system32\oobe
2014-09-20 01:12:11 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2014-09-20 01:12:11 ----D---- C:\WINDOWS\system32\Boot
2014-09-20 01:12:05 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-09-20 01:12:05 ----D---- C:\WINDOWS\SYSWOW64\InputMethod
2014-09-20 01:12:05 ----D---- C:\WINDOWS\system32\migration
2014-09-20 01:12:05 ----D---- C:\WINDOWS\apppatch
2014-09-19 00:17:31 ----D---- C:\ProgramData\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-08-02 65776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-08-02 224896]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-07-09 645952]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2012-12-05 39008]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2014-09-14 32576]
R0 PxHlpa64;PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-08-02 93568]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-08-02 1041168]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-08-02 427360]
R1 dtsoftbus01;@oem67.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-01-02 283064]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-08-02 29208]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-08-02 79184]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-08-02 92008]
R2 hcmon;VMware hcmon; \??\C:\WINDOWS\system32\drivers\hcmon.sys [2012-08-29 52376]
R3 ACPIVPC;@oem45.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2012-12-05 33560]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 BTATH_HCRP;@oem47.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\WINDOWS\System32\drivers\btath_hcrp.sys [2012-09-30 178840]
R3 BTATH_RCP;@oem50.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\WINDOWS\System32\drivers\btath_rcp.sys [2012-09-30 135832]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2014-04-28 599240]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 ETD;@oem37.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2012-09-05 318800]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2012-12-13 5353888]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-10-30 4201104]
R3 IntcDAud;@oem35.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 iwdbus;@oem61.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-09-26 27032]
R3 LEqdUsb;@oem81.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF USB Filter; C:\WINDOWS\system32\DRIVERS\LEqdUsb.Sys [2013-05-23 77592]
R3 LHidEqd;@oem82.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF HID Filter; C:\WINDOWS\system32\DRIVERS\LHidEqd.Sys [2013-05-23 13080]
R3 LHidFilt;@oem85.inf,%LHidFilt.SvcDesc%;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2013-05-23 76568]
R3 MEIx64;@oem54.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-03 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-09-14 13157696]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-10-04 20288]
R3 nvvad_WaveExtensible;@oem107.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 rtsuvc;@oem16.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2012-08-27 8227216]
S3 androidusb;@oem88.inf,%androidusb.SvcDesc%;ADB Interface Driver; C:\WINDOWS\System32\Drivers\androidusb.sys [2010-04-29 32768]
S3 AthBTPort;@oem44.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\WINDOWS\system32\DRIVERS\btath_flt.sys [2012-09-30 88728]
S3 BTATH_A2DP;@oem43.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\WINDOWS\system32\drivers\btath_a2dp.sys [2012-09-30 344216]
S3 btath_avdt;@oem43.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\WINDOWS\system32\drivers\btath_avdt.sys [2012-09-30 114840]
S3 BTATH_LWFLT;@oem48.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [2012-09-30 76952]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 EagleX64;EagleX64; \??\C:\WINDOWS\system32\drivers\EagleX64.sys []
S3 intaud_WaveExtensible;@oem60.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-09-26 39320]
S3 LGDDCDevice;LGDDCDevice; \??\C:\WINDOWS\system32\LGI2CDriver.sys []
S3 LGII2CDevice;LGII2CDevice; \??\C:\WINDOWS\system32\LGPII2CDriver.sys []
S3 pneteth;@oem56.inf,%pneteth.Service.DispName%;PdaNet Broadband; C:\WINDOWS\system32\DRIVERS\pneteth.sys [2011-11-25 15360]
S3 RSUSBVSTOR;@oem53.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [2012-06-13 315536]
S3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2013-08-22 20992]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 44544]
S3 usbser;@oem89.inf,%SERVICE%;USB RS-232 Emulation Driver; C:\WINDOWS\system32\DRIVERS\USBSER.sys [2013-08-22 33280]
S3 vmusb;@oem69.inf,%S_ServiceDisplayName%;VMware USB Client Driver; C:\WINDOWS\System32\Drivers\vmusb.sys [2012-08-29 37680]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-08-02 50344]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-10-04 1149760]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-21 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-18 277824]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-10-04 1796928]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-10-04 19440960]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-09-13 934216]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\syswow64\PnkBstrA.exe [2014-06-04 76888]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-09-13 411968]
R2 TBSrv;Toolbar Service; C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe [2014-04-10 350528]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-18 365376]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-20 116648]
S2 Service KMSELDI;Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [2013-12-11 1050904]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-09 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2012-12-19 277640]
S3 EasyAntiCheat;EasyAntiCheat; C:\WINDOWS\syswow64\EasyAntiCheat.exe [2014-07-09 107552]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-20 116648]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2013-06-13 357144]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 150600]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-09-23 833728]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S4 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2012-09-30 220288]
S4 HiPatchService;Hi-Rez Studios Authenticate and Update Service; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2014-02-28 9216]
S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-10-02 114288]
S4 OracleJobSchedulerXE;OracleJobSchedulerXE; c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe [2011-08-27 49152]
S4 OracleMTSRecoveryService;OracleMTSRecoveryService; C:\oraclexe\app\oracle\product\11.2.0\server\BIN\omtsreco.exe [2011-08-27 69632]
S4 OracleServiceXE;OracleServiceXE; c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE [2011-08-27 115773440]
S4 OracleXEClrAgent;OracleXEClrAgent; C:\oraclexe\app\oracle\product\11.2.0\server\bin\OraClrAgnt.exe [2011-08-27 12800]
S4 OracleXETNSListener;OracleXETNSListener; C:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe [2011-08-27 512000]
S4 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-08-06 5052224]
S4 VMUSBArbService;VMware USB Arbitration Service; C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2012-08-29 918168]
S4 vmware-view-usbd;VMware View USB; C:\Program Files\VMware\VMware View\Client\bin\vmware-view-usbd.exe [2012-09-05 2433024]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka s menším podezřením

#2 Příspěvek od Márty84 »

Zdravim :)

:arrow: Stahnete crystal disk info http://sourceforge.jp/projects/crystald ... 5_0_0.zip/
Spustte jako spravce. Za chvili se zobrazi vysledek.
Kliknete nahore na napis Úpravy a pak na napis Kopírovat. To co se zkopiruje (ulozi se to do pameti) mi sem vlozte (ctrl + V)

:arrow: Stahnete AdwCleaner https://toolslib.net/downloads/finish/1/ a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Lothaire
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 pro 2009 21:20

Re: Preventivka s menším podezřením

#3 Příspěvek od Lothaire »

Děkuji za odpověď :)


Zatím log z CrystalDiskInfo

----------------------------------------------------------------------------
CrystalDiskInfo 5.0.0 (C) 2008-2012 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 8 [6.2 Build 9200] (x64)
Date : 2014/10/19 13:37:37

-- Controller Map ----------------------------------------------------------
+ Intel(R) 7 Series Chipset Family SATA AHCI Controller [ATA]
- ST1000LM024 HN-M101MBB
- HL-DT-ST DVDRAM GU70N
- Řadič prostorů úložišť [SCSI]

-- Disk List ---------------------------------------------------------------
(1) ST1000LM024 HN-M101MBB : 1000,2 GB [0/0/0, pd1] - st

----------------------------------------------------------------------------
(1) ST1000LM024 HN-M101MBB
----------------------------------------------------------------------------
Model : ST1000LM024 HN-M101MBB
Firmware : 2AR10001
Serial Number : S2U5J9FCB27607
Disk Size : 1000,2 GB (8,4/137,4/1000,2)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 1953525168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 6
Transfer Mode : SATA/300
Power On Hours : 6966 hod.
Power On Count : 1296 krát
Temparature : 37 C (98 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 0080h [ON]
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _51 000000000040 Počet chyb čtení
02 252 252 __0 000000000000 Průchodnost disku
03 _89 _89 _25 000000000D7C Čas na roztočení ploten
04 _99 _99 __0 00000000050F Počet spuštění/zastavení
05 252 252 _10 000000000000 Počet přemapovaných sektorů
07 252 252 _51 000000000000 Počet chybných hledání
08 252 252 _15 000000000000 Čas potřebný na vyhledání
09 100 100 __0 000000001B36 Hodin v činnosti
0A 252 252 _51 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000309 Počet pokusů o překalibrování
0C _99 _99 __0 000000000510 Počet cyklů zapnutí zařízení
BF 100 100 __0 0000000000EA Počet udalostí zaznamenaných otřesovým senzorem
C0 252 252 __0 000000000000 Počet vypnutí disku
C2 _63 _53 __0 002F00080025 Teplota
C3 100 100 __0 000000000000 Počet oprav chybného čtení
C4 252 252 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 252 252 __0 000000000000 Počet podezřelých sektorů
C6 252 252 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 __1 __1 __0 000000008741 Počet chyb při zápisu sektorů
DF 100 100 __0 000000000309 Zatížení budiče magnetických hlav způsobené opakovanými úkony
E1 _91 _91 __0 0000000165F2 Počet cyklů načítání/vymazání

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0040 3FFF C837 0010 0000 003F 003F 0000 0000 0000
010: 5332 5535 4A39 4643 4232 3037 3037 2020 2020 2020
020: 0000 4000 0004 3241 5231 3031 3031 5354 3130 3030
030: 4C4D 3032 3420 484E 2D4D 314D 314D 4242 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0200 0200 0006 3FFF 003F 003F FC10 00FB 0000
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 0F06 0F06 0004 004C 0048
080: 01FF 0028 746B 7D09 6123 BC09 BC09 6123 203F 006B
090: 006B 0080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6DB0 7470 0000 0000 0000 6003 6003 0000 5000 4CF2
110: 08DF FEBD 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 003F 003F 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103F 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 07A5

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka s menším podezřením

#4 Příspěvek od Márty84 »

Disk hlasi dost chyb, i to muze pusobit problemy. Uvidime po procisteni :?:
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Lothaire
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 pro 2009 21:20

Re: Preventivka s menším podezřením

#5 Příspěvek od Lothaire »

# AdwCleaner v4.000 - Report created 19/10/2014 at 13:42:59
# DB v2014-10-17.9
# Updated 12/10/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Martin - CHECKPOINT
# Running from : C:\Users\Martin\Downloads\adwcleaner_4.000.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : TBSrv

***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\Amazon\ABB
Folder Deleted : C:\Users\Martin\AppData\Local\genienext
Folder Deleted : C:\Users\Martin\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Martin\AppData\Roaming\newnext.me
Folder Deleted : C:\Users\Martin\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Martin\AppData\Roaming\Systweak
Folder Deleted : C:\ProgramData\Tbccint
Folder Deleted : C:\Program Files (x86)\Tbccint
Folder Deleted : C:\Users\Martin\AppData\Local\Tbccint
Folder Deleted : C:\Users\Martin\AppData\LocalLow\Tbccint
Folder Deleted : C:\Users\Martin\AppData\LocalLow\BS_Player_ControlBar_B
File Deleted : C:\Users\Martin\daemonprocess.txt
File Deleted : C:\END
File Deleted : C:\WINDOWS\System32\roboot64.exe

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3329621
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3A1209A4-8568-40F0-9B5E-4A06A2A06417}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{31264A33-A653-46C4-AF49-1232C59A7DA5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31264A33-A653-46C4-AF49-1232C59A7DA5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31264A33-A653-46C4-AF49-1232C59A7DA5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31264A33-A653-46C4-AF49-1232C59A7DA5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3A1209A4-8568-40F0-9B5E-4A06A2A06417}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{31264A33-A653-46C4-AF49-1232C59A7DA5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{31264A33-A653-46C4-AF49-1232C59A7DA5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{31264A33-A653-46C4-AF49-1232C59A7DA5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{31264A33-A653-46C4-AF49-1232C59A7DA5}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{3A1209A4-8568-40F0-9B5E-4A06A2A06417}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{31264A33-A653-46C4-AF49-1232C59A7DA5}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{31264A33-A653-46C4-AF49-1232C59A7DA5}]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Tbccint
Key Deleted : HKCU\Software\Tbccint_HKLM
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\Tbccint
Key Deleted : HKCU\Software\AppDataLow\Software\TbccintSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\BS_Player_ControlBar_B
Key Deleted : HKLM\SOFTWARE\Conduit

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17344


-\\ Mozilla Firefox v32.0.3 (x86 cs)

[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.FF19Solved", "true");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.UserID", "UN40384206953573256");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.fullUserID", "UN40384206953573256.IN.20140828192817");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.installDate", "28/08/2014 19:28:28");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.installSessionId", "f091df77-5689-4a5d-99c9-ac4f98adca09");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.installSp", "false");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.installerVersion", "1.8.1.4");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.searchRevert", "false");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.searchUninstallUserMode", "4");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.searchUserMode", "4");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.toolbarInstallDate", "28-08-2014 19:28:17");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.versionFromInstaller", "10.33.0.17");
[7vni0jbm.default] - Line Deleted : user_pref("CT3329621.xpeMode", "1");
[7vni0jbm.default] - Line Deleted : user_pref("smartbar.machineId", "LNKJ3RV7XAURT7CCZN5TUFAAPXYTYO3R28FGW2XMKV56M+GWIF4G/B5F8P2YKBL1FBZC6P/TZGDW097J4NWECA");

-\\ Google Chrome v37.0.2062.124


*************************

AdwCleaner[R0].txt - [5342 octets] - [19/10/2014 13:40:32]
AdwCleaner[S0].txt - [5030 octets] - [19/10/2014 13:42:59]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5090 octets] ##########

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka s menším podezřením

#6 Příspěvek od Márty84 »

:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=29&t=137928 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Lothaire
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 pro 2009 21:20

Re: Preventivka s menším podezřením

#7 Příspěvek od Lothaire »

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 20. 10. 2014
Čas skenování: 6:26:52
Protokol:
Správce: Ano

Verze: 0.00.0.0000
Databáze malwaru: v2014.10.20.02
Databáze rootkitů: v2014.10.17.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Sebeobrany: Vypnuto

OS: Windows 8.1
CPU: x64
Souborový systém: NTFS
Uživatel: Martin

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 813039
Uplynulý čas: 4 hod, 25 min, 0 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Žádné zákerné zjištěny položek)

Moduly: 0
(Žádné zákerné zjištěny položek)

Klíče registru: 0
(Žádné zákerné zjištěny položek)

Hodnoty registru: 0
(Žádné zákerné zjištěny položek)

Data registru: 0
(Žádné zákerné zjištěny položek)

Složky: 0
(Žádné zákerné zjištěny položek)

Soubory: 0
(Žádné zákerné zjištěny položek)

Fyzické sektory: 0
(Žádné zákerné zjištěny položek)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka s menším podezřením

#8 Příspěvek od Márty84 »

Vyborne, MBAM odinstalujte a dejte novy log z RSIT
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Lothaire
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 pro 2009 21:20

Re: Preventivka s menším podezřením

#9 Příspěvek od Lothaire »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Martin at 2014-10-21 09:42:10
Microsoft Windows 8.1
System drive C: has 192 GB (21%) free of 905 GB
Total RAM: 8048 MB (83% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:42:11, on 21. 10. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\trend micro\Martin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [GIGABYTEMOUSE] C:\Users\Martin\Documents\GIGABYTE\GIGABYTE Sim\Mouse.exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE
O4 - Startup: Logitech . Registrace produktu.lnk = C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
O4 - Startup: PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: Stáhnout s Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.connectify.me
O15 - ESC Trusted Zone: http://*.fastspring.com
O15 - ESC Trusted Zone: http://*.connectify.me (HKLM)
O15 - ESC Trusted Zone: http://*.fastspring.com (HKLM)
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\WINDOWS\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\WINDOWS\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Service KMSELDI - Unknown owner - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13212 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
dashost.exe {223026bf-99c9-437a-9d873717a4286000}
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\WINDOWS\SysWOW64\PnkBstrA.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 22c864bf-d70c-4904-aedf-066685ed3627 1
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-55197492-5ace-472b-889a-43bbc7856dbb -SystemEventPortName:HostProcess-ef482fb9-0b8a-457a-b869-fbe66d322ea0 -IoCancelEventPortName:HostProcess-c22fe1c6-a6e2-42fe-ae6d-b0862cfa7ab3 -NonStateChangingEventPortName:HostProcess-1637c3a4-ac4b-4018-b4b7-d681ba5a4bce -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:934721da-4d7a-452b-a1c1-c0a7e402307d -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Elantech\ETDIntelligent.exe"
"C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe" -start
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Martin\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1410772076-1682251192-4122739941-1002Core.job - C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1410772076-1682251192-4122739941-1002UA.job - C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\7vni0jbm.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@lastpass.com/NPLastPass]
"Description"=
"Path"=C:\Program Files (x86)\LastPass\nplastpass.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@lastpass.com/NPLastPass]
"Description"=
"Path"=C:\Program Files (x86)\LastPass\nplastpass64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@unity3d.com/UnityPlayer64,version=1.0]
"Description"=Unity Player 4.5.4f2
"Path"=C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
nppdf32.CZE
nppdf32.dll
nppdf32.HRV
nppdf32.HUN
nppdf32.POL
nppdf32.SKY
nppdf32.SLV
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
QuickTimePlugin.class

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-09-25 218784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-09-20 553896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-09-30 64640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-08-02 612248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2013-07-31 433944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2014-09-16 2334416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-09-20 211880]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-09-25 153240]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-25 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-08-02 457712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-09-04 343456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2013-07-31 364824]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2014-09-16 1729232]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-25 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-09-04 343456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-09-04 343456]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2012-09-05 2872720]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-10-26 13213840]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2012-10-29 1234064]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2012-08-27 6334096]
"BtPreLoad"=C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [2012-09-30 64640]
"OnekeyStudio"=C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [2012-09-15 4196432]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2012-12-05 17080376]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2012-12-05 191544]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-10-04 2463552]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-10-04 2800296]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2012-12-19 172168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2012-12-19 400008]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2012-12-19 441992]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2013-07-31 3091224]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2012-09-20 3933496]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2013-12-21 116648]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2004-04-17 196608]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE [2014-03-13 779776]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Dolby Home Theater v4"=C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [2012-07-26 508656]
"YouCam Mirage"=C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27 136488]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-07-27 167024]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2012-04-19 217088]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2012-03-29 91432]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-02 4085896]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2004-04-13 69632]
"GIGABYTEMOUSE"=C:\Users\Martin\Documents\GIGABYTE\GIGABYTE Sim\Mouse.exe [2013-10-14 1304576]
""= []
"Adobe Acrobat Speed Launcher"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [2014-09-04 41360]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2014-09-04 840592]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-25 256896]

C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Logitech . Registrace produktu.lnk - C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe
PdaNet Desktop.lnk - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\windows\system32\nvinitx.dll,C:\WINDOWS\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2012-12-13 442880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2013-06-13 66328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"DisableCAD"=1
"PromptOnSecureDesktop"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"midi3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe","%1"

======List of files/folders created in the last 1 month======

2014-10-19 20:48:20 ----D---- C:\ProgramData\Malwarebytes
2014-10-19 13:40:30 ----D---- C:\AdwCleaner
2014-10-18 18:34:54 ----D---- C:\rsit
2014-10-18 18:34:54 ----D---- C:\Program Files\trend micro
2014-10-18 15:18:35 ----D---- C:\Program Files (x86)\Font Xplorer
2014-10-17 14:00:19 ----D---- C:\ProgramData\Last.fm
2014-10-17 14:00:19 ----D---- C:\Program Files (x86)\Winamp
2014-10-17 13:58:33 ----D---- C:\Program Files (x86)\Last.fm
2014-10-16 12:51:47 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-10-16 12:51:47 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-10-16 12:51:44 ----A---- C:\WINDOWS\system32\winbici.dll
2014-10-16 12:51:03 ----A---- C:\WINDOWS\system32\generaltel.dll
2014-10-16 12:51:03 ----A---- C:\WINDOWS\system32\aepdu.dll
2014-10-16 12:51:02 ----A---- C:\WINDOWS\system32\aeinv.dll
2014-10-16 12:50:34 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2014-10-16 12:50:34 ----A---- C:\WINDOWS\system32\msi.dll
2014-10-15 21:25:31 ----D---- C:\Program Files\IHMC CmapTools
2014-10-15 15:29:51 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2014-10-15 15:28:00 ----A---- C:\WINDOWS\system32\win32k.sys
2014-10-15 15:27:32 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-10-15 15:27:32 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wuwebv.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wups2.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wups.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-10-15 15:27:31 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-10-15 15:27:30 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2014-10-15 15:27:30 ----A---- C:\WINDOWS\system32\wuapp.exe
2014-10-15 15:26:50 ----A---- C:\WINDOWS\system32\authui.dll
2014-10-15 15:26:49 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-10-15 15:26:49 ----A---- C:\WINDOWS\system32\appinfo.dll
2014-10-15 15:26:40 ----A---- C:\WINDOWS\system32\shell32.dll
2014-10-15 15:26:38 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-10-15 15:26:37 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-10-15 15:26:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-10-15 15:26:33 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-10-15 15:26:32 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-10-15 15:26:31 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2014-10-15 15:26:30 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-10-15 15:26:28 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-10-15 15:26:27 ----A---- C:\WINDOWS\system32\ntdll.dll
2014-10-15 15:26:27 ----A---- C:\WINDOWS\system32\KernelBase.dll
2014-10-15 15:26:26 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2014-10-15 15:26:26 ----A---- C:\WINDOWS\system32\propsys.dll
2014-10-15 15:26:25 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-10-15 15:26:24 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-10-15 15:26:24 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2014-10-15 15:26:24 ----A---- C:\WINDOWS\system32\Wldap32.dll
2014-10-15 15:26:24 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-10-15 15:26:23 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2014-10-15 15:26:22 ----A---- C:\WINDOWS\SYSWOW64\Wldap32.dll
2014-10-15 15:26:21 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2014-10-15 15:26:21 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-10-15 15:26:19 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-10-15 15:26:19 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2014-10-15 15:26:19 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-10-15 15:26:19 ----A---- C:\WINDOWS\system32\bisrv.dll
2014-10-15 15:26:18 ----A---- C:\WINDOWS\system32\pcsvDevice.dll
2014-10-15 15:26:18 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2014-10-15 15:26:17 ----A---- C:\WINDOWS\SYSWOW64\SkyDriveShell.dll
2014-10-15 15:26:17 ----A---- C:\WINDOWS\system32\SkyDriveShell.dll
2014-10-15 15:26:17 ----A---- C:\WINDOWS\system32\ProximityService.dll
2014-10-15 15:26:17 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-10-15 15:26:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 15:26:14 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 15:25:32 ----A---- C:\WINDOWS\SYSWOW64\packager.dll
2014-10-15 15:25:32 ----A---- C:\WINDOWS\system32\packager.dll
2014-10-15 15:23:52 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-10-15 15:23:45 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-10-15 15:23:35 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-10-15 15:23:32 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-10-15 15:23:28 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-10-15 15:23:25 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-10-15 15:23:22 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-10-15 15:23:21 ----A---- C:\WINDOWS\system32\wininet.dll
2014-10-15 15:23:20 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-10-15 15:23:18 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-10-15 15:23:18 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-10-15 15:23:15 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-10-15 15:23:15 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-10-15 15:23:13 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-10-15 15:23:10 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-10-15 15:23:09 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-10-15 15:23:09 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-10-15 15:23:05 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-10-15 15:23:04 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-10-15 15:23:01 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2014-10-15 15:23:01 ----A---- C:\WINDOWS\system32\rastls.dll
2014-10-14 14:10:46 ----D---- C:\Program Files\Defraggler
2014-10-05 16:54:42 ----D---- C:\Program Files (x86)\Sherlock Holmes Crimes and Punishments
2014-10-03 16:27:04 ----D---- C:\Users\Martin\AppData\Roaming\Unity
2014-10-03 15:46:23 ----D---- C:\Program Files\Unity
2014-09-28 01:32:15 ----D---- C:\Users\Martin\AppData\Roaming\WebApp
2014-09-25 16:58:21 ----D---- C:\WINDOWS\SYSWOW64\NV
2014-09-25 16:58:21 ----D---- C:\WINDOWS\system32\NV
2014-09-25 16:57:49 ----D---- C:\NVIDIA Corporation
2014-09-25 15:15:11 ----D---- C:\Program Files (x86)\Quake Live

======List of files/folders modified in the last 1 month======

2014-10-21 09:34:46 ----D---- C:\WINDOWS\Prefetch
2014-10-21 09:31:37 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-10-21 09:29:37 ----D---- C:\WINDOWS\Temp
2014-10-21 09:28:56 ----D---- C:\ProgramData\NVIDIA
2014-10-21 09:28:27 ----RD---- C:\Program Files (x86)
2014-10-21 09:26:02 ----D---- C:\WINDOWS\system32\drivers
2014-10-21 09:00:00 ----D---- C:\WINDOWS\system32\sru
2014-10-21 03:23:36 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-20 16:45:08 ----SHD---- C:\WINDOWS\Installer
2014-10-20 16:45:08 ----SHD---- C:\Config.Msi
2014-10-20 16:40:28 ----D---- C:\WINDOWS\Tasks
2014-10-20 06:04:30 ----RSD---- C:\WINDOWS\assembly
2014-10-20 06:03:38 ----D---- C:\ProgramData\Microsoft Help
2014-10-19 20:48:20 ----HD---- C:\ProgramData
2014-10-19 13:43:08 ----RD---- C:\WINDOWS\System32
2014-10-19 13:43:00 ----D---- C:\Program Files (x86)\Amazon
2014-10-19 10:39:04 ----D---- C:\WINDOWS\system32\MRT
2014-10-19 10:33:06 ----A---- C:\WINDOWS\system32\MRT.exe
2014-10-19 10:32:56 ----D---- C:\WINDOWS\AppReadiness
2014-10-19 09:49:27 ----D---- C:\WINDOWS\Inf
2014-10-19 09:49:27 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-19 01:11:32 ----D---- C:\WINDOWS\system32\catroot2
2014-10-19 01:11:32 ----D---- C:\WINDOWS\system32\catroot
2014-10-18 18:34:54 ----D---- C:\Program Files
2014-10-18 16:44:31 ----D---- C:\WINDOWS\system32\config
2014-10-18 15:55:30 ----RSD---- C:\WINDOWS\Fonts
2014-10-18 11:11:26 ----D---- C:\WINDOWS\rescache
2014-10-18 10:15:34 ----D---- C:\WINDOWS\WinSxS
2014-10-18 10:13:06 ----SD---- C:\WINDOWS\system32\CompatTel
2014-10-18 10:13:06 ----D---- C:\WINDOWS\SysWOW64
2014-10-18 10:13:06 ----D---- C:\WINDOWS\MediaViewer
2014-10-18 10:13:06 ----D---- C:\WINDOWS\FileManager
2014-10-18 10:13:06 ----D---- C:\WINDOWS\Camera
2014-10-18 04:29:38 ----SHD---- C:\System Volume Information
2014-10-17 21:03:04 ----D---- C:\Users\Martin\AppData\Roaming\vlc
2014-10-16 14:01:10 ----D---- C:\WINDOWS\CbsTemp
2014-10-16 13:29:07 ----D---- C:\Program Files (x86)\Battle.net
2014-10-16 12:01:10 ----D---- C:\WINDOWS\system32\FxsTmp
2014-10-16 11:59:33 ----D---- C:\Users\Martin\AppData\Roaming\VMware
2014-10-15 20:50:29 ----D---- C:\Users\Martin\AppData\Roaming\Skype
2014-10-15 16:35:53 ----RD---- C:\WINDOWS\ToastData
2014-10-15 16:35:53 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-10-15 16:35:53 ----D---- C:\WINDOWS\system32\cs-CZ
2014-10-15 16:35:53 ----D---- C:\Program Files\Internet Explorer
2014-10-15 16:35:53 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-15 16:35:52 ----D---- C:\WINDOWS\WinStore
2014-10-15 16:35:51 ----D---- C:\WINDOWS\system32\DriverStore
2014-10-15 15:30:53 ----A---- C:\WINDOWS\win.ini
2014-10-14 17:50:09 ----D---- C:\Users\Martin\AppData\Roaming\Webshare
2014-10-14 15:05:26 ----D---- C:\Program Files (x86)\WarThunder
2014-10-14 14:54:15 ----D---- C:\WINDOWS\system32\Tasks
2014-10-14 14:08:43 ----D---- C:\Windows
2014-10-14 13:28:40 ----D---- C:\ProgramData\Origin
2014-10-14 13:28:39 ----D---- C:\Program Files (x86)\Steam
2014-10-14 12:19:09 ----D---- C:\Program Files (x86)\Origin
2014-10-12 16:08:29 ----HD---- C:\Program Files\WindowsApps
2014-10-05 15:14:44 ----D---- C:\Program Files (x86)\Hearthstone
2014-10-05 14:00:03 ----D---- C:\Program Files (x86)\The Elder Scrolls V Skyrim
2014-10-04 08:42:47 ----A---- C:\WINDOWS\SYSWOW64\nvspcap.dll
2014-10-04 08:42:47 ----A---- C:\WINDOWS\SYSWOW64\nvspbridge.dll
2014-10-04 08:41:43 ----A---- C:\WINDOWS\system32\nvspcap64.dll
2014-10-04 08:41:43 ----A---- C:\WINDOWS\system32\nvspbridge64.dll
2014-10-03 12:36:02 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2014-10-02 10:32:14 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-02 10:29:55 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-30 00:45:58 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-09-26 21:19:13 ----D---- C:\Program Files (x86)\Glyph
2014-09-25 22:03:58 ----D---- C:\Program Files\WinRAR
2014-09-25 22:03:58 ----D---- C:\Program Files (x86)\SugarSync
2014-09-25 22:03:58 ----D---- C:\Program Files (x86)\SageThumbs
2014-09-25 22:03:58 ----D---- C:\Program Files (x86)\JDownloader
2014-09-25 22:03:58 ----D---- C:\Program Files (x86)\In Verbis Virtus
2014-09-25 22:03:58 ----D---- C:\Program Files (x86)\DAEMON Tools Lite

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-08-02 65776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-08-02 224896]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-07-09 645952]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2012-12-05 39008]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2014-09-14 32576]
R0 PxHlpa64;PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-08-02 93568]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-08-02 1041168]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-08-02 427360]
R1 dtsoftbus01;@oem67.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-01-02 283064]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-08-02 29208]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-08-02 79184]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-08-02 92008]
R2 hcmon;VMware hcmon; \??\C:\WINDOWS\system32\drivers\hcmon.sys [2012-08-29 52376]
R3 ACPIVPC;@oem45.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2012-12-05 33560]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 BTATH_HCRP;@oem47.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\WINDOWS\System32\drivers\btath_hcrp.sys [2012-09-30 178840]
R3 BTATH_RCP;@oem50.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\WINDOWS\System32\drivers\btath_rcp.sys [2012-09-30 135832]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2014-04-28 599240]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 ETD;@oem37.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2012-09-05 318800]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2012-12-13 5353888]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-10-30 4201104]
R3 IntcDAud;@oem35.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 iwdbus;@oem61.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-09-26 27032]
R3 LEqdUsb;@oem81.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF USB Filter; C:\WINDOWS\system32\DRIVERS\LEqdUsb.Sys [2013-05-23 77592]
R3 LHidEqd;@oem82.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF HID Filter; C:\WINDOWS\system32\DRIVERS\LHidEqd.Sys [2013-05-23 13080]
R3 LHidFilt;@oem85.inf,%LHidFilt.SvcDesc%;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2013-05-23 76568]
R3 MEIx64;@oem54.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-03 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-09-14 13157696]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-10-04 20288]
R3 nvvad_WaveExtensible;@oem107.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 rtsuvc;@oem16.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2012-08-27 8227216]
S3 androidusb;@oem88.inf,%androidusb.SvcDesc%;ADB Interface Driver; C:\WINDOWS\System32\Drivers\androidusb.sys [2010-04-29 32768]
S3 AthBTPort;@oem44.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\WINDOWS\system32\DRIVERS\btath_flt.sys [2012-09-30 88728]
S3 BTATH_A2DP;@oem43.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\WINDOWS\system32\drivers\btath_a2dp.sys [2012-09-30 344216]
S3 btath_avdt;@oem43.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\WINDOWS\system32\drivers\btath_avdt.sys [2012-09-30 114840]
S3 BTATH_LWFLT;@oem48.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [2012-09-30 76952]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 EagleX64;EagleX64; \??\C:\WINDOWS\system32\drivers\EagleX64.sys []
S3 intaud_WaveExtensible;@oem60.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-09-26 39320]
S3 LGDDCDevice;LGDDCDevice; \??\C:\WINDOWS\system32\LGI2CDriver.sys []
S3 LGII2CDevice;LGII2CDevice; \??\C:\WINDOWS\system32\LGPII2CDriver.sys []
S3 pneteth;@oem56.inf,%pneteth.Service.DispName%;PdaNet Broadband; C:\WINDOWS\system32\DRIVERS\pneteth.sys [2011-11-25 15360]
S3 RSUSBVSTOR;@oem53.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [2012-06-13 315536]
S3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2013-08-22 20992]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 44544]
S3 usbser;@oem89.inf,%SERVICE%;USB RS-232 Emulation Driver; C:\WINDOWS\system32\DRIVERS\USBSER.sys [2013-08-22 33280]
S3 vmusb;@oem69.inf,%S_ServiceDisplayName%;VMware USB Client Driver; C:\WINDOWS\System32\Drivers\vmusb.sys [2012-08-29 37680]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-08-02 50344]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-10-04 1149760]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-21 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-18 277824]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-10-04 1796928]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-10-04 19440960]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-09-13 934216]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\syswow64\PnkBstrA.exe [2014-06-04 76888]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-09-13 411968]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-18 365376]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-20 116648]
S2 Service KMSELDI;Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [2013-12-11 1050904]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-09 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2012-12-19 277640]
S3 EasyAntiCheat;EasyAntiCheat; C:\WINDOWS\syswow64\EasyAntiCheat.exe [2014-07-09 107552]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-20 116648]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2013-06-13 357144]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 150600]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-09-23 833728]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S4 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2012-09-30 220288]
S4 HiPatchService;Hi-Rez Studios Authenticate and Update Service; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2014-02-28 9216]
S4 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-10-02 114288]
S4 OracleJobSchedulerXE;OracleJobSchedulerXE; c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe [2011-08-27 49152]
S4 OracleMTSRecoveryService;OracleMTSRecoveryService; C:\oraclexe\app\oracle\product\11.2.0\server\BIN\omtsreco.exe [2011-08-27 69632]
S4 OracleServiceXE;OracleServiceXE; c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE [2011-08-27 115773440]
S4 OracleXEClrAgent;OracleXEClrAgent; C:\oraclexe\app\oracle\product\11.2.0\server\bin\OraClrAgnt.exe [2011-08-27 12800]
S4 OracleXETNSListener;OracleXETNSListener; C:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe [2011-08-27 512000]
S4 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-08-06 5052224]
S4 VMUSBArbService;VMware USB Arbitration Service; C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2012-08-29 918168]
S4 vmware-view-usbd;VMware View USB; C:\Program Files\VMware\VMware View\Client\bin\vmware-view-usbd.exe [2012-09-05 2433024]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka s menším podezřením

#10 Příspěvek od Márty84 »

:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Lothaire
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 pro 2009 21:20

Re: Preventivka s menším podezřením

#11 Příspěvek od Lothaire »

OTL:
OTL logfile created on: 21. 10. 2014 15:44:12 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Martin\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17351)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d. M. yyyy

7,86 Gb Total Physical Memory | 3,03 Gb Available Physical Memory | 38,56% Memory free
12,61 Gb Paging File | 5,32 Gb Available in Paging File | 42,22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 883,50 Gb Total Space | 187,04 Gb Free Space | 21,17% Space Free | Partition Type: NTFS
Drive D: | 25,00 Gb Total Space | 21,15 Gb Free Space | 84,59% Space Free | Partition Type: NTFS

Computer Name: CHECKPOINT | User Name: Martin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2014/10/21 15:42:41 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Martin\Desktop\OTL.exe
PRC - [2014/10/04 08:44:13 | 002,463,552 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2014/10/04 08:44:03 | 001,796,928 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2014/09/13 22:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2014/09/12 11:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/09/04 14:50:58 | 000,840,592 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2014/08/02 17:43:54 | 004,085,896 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014/08/02 17:43:17 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014/07/25 12:29:36 | 000,511,872 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2014/06/04 21:39:06 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/07/27 21:52:44 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
PRC - [2012/07/18 00:57:22 | 000,365,376 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2012/07/18 00:57:20 | 000,277,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2012/06/25 20:57:14 | 000,166,720 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
PRC - [2012/04/24 15:37:56 | 000,169,752 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe


========== Modules (No Company Name) ==========

MOD - [2014/09/04 14:52:10 | 000,019,968 | ---- | M] () -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\cs_CZ\AcroTray.CZE
MOD - [2014/08/02 17:43:19 | 019,329,904 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014/08/02 17:43:18 | 000,301,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswProperty.dll


========== Services (SafeList) ==========

SRV:64bit: - [2014/10/04 08:44:02 | 001,149,760 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
SRV:64bit: - [2014/10/04 08:43:58 | 019,440,960 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
SRV:64bit: - [2014/09/11 12:03:05 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/08/16 05:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:64bit: - [2014/08/16 02:58:35 | 000,287,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:64bit: - [2014/08/16 02:45:51 | 000,267,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:64bit: - [2014/08/02 17:43:17 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2014/07/24 09:28:58 | 001,600,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:64bit: - [2014/04/06 13:20:36 | 000,201,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2014/03/24 04:31:14 | 000,347,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:64bit: - [2014/03/24 04:31:14 | 000,023,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:64bit: - [2014/03/14 08:26:25 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:64bit: - [2014/03/08 07:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:64bit: - [2014/03/06 09:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:64bit: - [2014/02/22 17:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:64bit: - [2014/02/22 11:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:64bit: - [2014/02/22 11:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:64bit: - [2014/02/22 11:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:64bit: - [2014/02/22 11:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:64bit: - [2013/12/11 15:59:12 | 001,050,904 | ---- | M] () [Auto | Stopped] -- C:\Program Files\KMSpico\Service_KMS.exe -- (Service KMSELDI)
SRV:64bit: - [2013/12/10 09:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:64bit: - [2013/08/22 13:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:64bit: - [2013/08/22 13:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:64bit: - [2013/08/22 13:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:64bit: - [2013/08/22 13:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:64bit: - [2013/08/22 13:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:64bit: - [2013/08/22 12:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:64bit: - [2013/08/22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:64bit: - [2013/08/22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:64bit: - [2013/08/22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:64bit: - [2013/08/22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:64bit: - [2013/08/22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:64bit: - [2013/08/22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:64bit: - [2013/08/22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:64bit: - [2013/08/22 12:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:64bit: - [2013/08/22 11:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:64bit: - [2013/08/22 11:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:64bit: - [2013/08/22 11:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:64bit: - [2013/08/22 11:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:64bit: - [2013/08/22 11:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:64bit: - [2013/08/22 11:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:64bit: - [2013/08/22 11:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:64bit: - [2013/08/22 11:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:64bit: - [2013/06/13 21:31:10 | 000,357,144 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2012/09/21 08:06:46 | 000,472,216 | ---- | M] (VMware, Inc.) [Disabled | Stopped] -- C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe -- (wsnm)
SRV:64bit: - [2012/09/05 17:28:48 | 002,433,024 | ---- | M] (VMware, Inc.) [Disabled | Stopped] -- C:\Program Files\VMware\VMware View\Client\bin\vmware-view-usbd.exe -- (vmware-view-usbd)
SRV:64bit: - [2012/04/21 00:16:12 | 000,635,104 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV - [2014/10/04 08:44:03 | 001,796,928 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2014/10/02 10:29:50 | 000,114,288 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/09/23 06:32:08 | 000,833,728 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014/09/13 22:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2014/09/12 11:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/09/09 19:25:41 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/08/16 05:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2014/08/06 11:34:34 | 005,052,224 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
SRV - [2014/07/09 14:02:50 | 000,107,552 | ---- | M] (EasyAntiCheat Ltd) [On_Demand | Stopped] -- C:\Windows\SysWOW64\EasyAntiCheat.exe -- (EasyAntiCheat)
SRV - [2014/06/04 21:39:06 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2014/04/03 20:21:48 | 000,315,008 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2014/03/14 08:10:16 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2014/02/28 15:23:54 | 000,009,216 | ---- | M] (Hi-Rez Studios) [Disabled | Stopped] -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)
SRV - [2013/08/22 05:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2013/08/22 04:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2012/12/19 09:09:24 | 000,277,640 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2012/09/30 05:01:56 | 000,220,288 | ---- | M] (Qualcomm Atheros Commnucations) [Disabled | Stopped] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2012/09/30 04:18:26 | 000,323,584 | R--- | M] (Atheros) [Disabled | Stopped] -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe -- (ZAtheros Bt and Wlan Coex Agent)
SRV - [2012/08/29 15:09:02 | 000,918,168 | ---- | M] (VMware, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe -- (VMUSBArbService)
SRV - [2012/07/18 00:57:22 | 000,365,376 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2012/07/18 00:57:20 | 000,277,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2012/06/25 20:57:14 | 000,166,720 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2012/04/24 15:37:56 | 000,169,752 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe -- (ICCS)
SRV - [2011/08/27 10:01:00 | 000,012,800 | ---- | M] (Oracle Corporation) [Disabled | Stopped] -- C:\oraclexe\app\oracle\product\11.2.0\server\bin\OraClrAgnt.exe -- (OracleXEClrAgent)
SRV - [2011/08/27 10:00:20 | 000,512,000 | ---- | M] (Oracle Corporation) [Disabled | Stopped] -- C:\oraclexe\app\oracle\product\11.2.0\server\bin\TNSLSNR.EXE -- (OracleXETNSListener)
SRV - [2011/08/27 09:59:56 | 000,069,632 | ---- | M] (Oracle Corporation) [Disabled | Stopped] -- C:\oraclexe\app\oracle\product\11.2.0\server\BIN\omtsreco.exe -- (OracleMTSRecoveryService)
SRV - [2011/08/27 09:58:52 | 000,049,152 | ---- | M] () [Disabled | Stopped] -- c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe -- (OracleJobSchedulerXE)
SRV - [2011/08/27 09:58:50 | 115,773,440 | ---- | M] (Oracle Corporation) [Disabled | Stopped] -- c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE -- (OracleServiceXE)
SRV - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2014/10/04 08:43:58 | 000,020,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV:64bit: - [2014/09/14 01:48:03 | 000,032,576 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt)
DRV:64bit: - [2014/09/04 21:14:38 | 000,038,048 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:64bit: - [2014/08/15 02:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:64bit: - [2014/08/02 17:43:53 | 000,427,360 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsp.sys -- (aswSP)
DRV:64bit: - [2014/08/02 17:43:27 | 001,041,168 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2014/08/02 17:43:27 | 000,224,896 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2014/08/02 17:43:27 | 000,092,008 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2014/08/02 17:43:27 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2014/08/02 17:43:27 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2014/08/02 17:43:27 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2014/08/02 17:43:26 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2014/07/24 17:28:38 | 000,468,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:64bit: - [2014/07/24 17:28:38 | 000,412,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:64bit: - [2014/07/24 13:42:22 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:64bit: - [2014/05/01 15:31:39 | 000,055,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:64bit: - [2014/04/28 06:33:30 | 000,599,240 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2014/03/24 04:30:57 | 000,257,880 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:64bit: - [2014/03/24 04:30:57 | 000,123,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:64bit: - [2014/03/24 04:27:03 | 000,035,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:64bit: - [2014/03/20 05:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:64bit: - [2014/03/18 10:18:42 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb22.sys -- (xusb22)
DRV:64bit: - [2014/03/13 14:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:64bit: - [2014/03/08 22:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:64bit: - [2014/02/22 18:00:25 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2014/02/22 17:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:64bit: - [2014/02/22 17:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:64bit: - [2014/02/22 17:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:64bit: - [2014/02/22 17:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
DRV:64bit: - [2014/02/22 14:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:64bit: - [2014/01/02 22:48:38 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2013/12/22 01:52:29 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:64bit: - [2013/12/22 01:52:29 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:64bit: - [2013/12/22 01:52:29 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:64bit: - [2013/12/04 20:41:54 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BthLEEnum.sys -- (BthLEEnum)
DRV:64bit: - [2013/11/14 14:46:08 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:64bit: - [2013/11/14 14:39:18 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:64bit: - [2013/11/14 14:26:21 | 000,027,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2013/11/14 14:26:16 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2013/09/26 11:08:22 | 000,039,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:64bit: - [2013/09/26 11:08:22 | 000,027,032 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:64bit: - [2013/08/22 15:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:64bit: - [2013/08/22 15:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2013/08/22 14:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:64bit: - [2013/08/22 14:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:64bit: - [2013/08/22 14:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2013/08/22 14:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:64bit: - [2013/08/22 14:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:64bit: - [2013/08/22 14:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2013/08/22 14:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2013/08/22 14:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:64bit: - [2013/08/22 14:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2013/08/22 14:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:64bit: - [2013/08/22 14:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:64bit: - [2013/08/22 14:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2013/08/22 14:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2013/08/22 14:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:64bit: - [2013/08/22 14:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2013/08/22 14:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:64bit: - [2013/08/22 14:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:64bit: - [2013/08/22 14:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2013/08/22 14:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:64bit: - [2013/08/22 14:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:64bit: - [2013/08/22 14:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2013/08/22 14:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:64bit: - [2013/08/22 14:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:64bit: - [2013/08/22 14:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:64bit: - [2013/08/22 14:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:64bit: - [2013/08/22 14:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:64bit: - [2013/08/22 14:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:64bit: - [2013/08/22 13:40:00 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBSER.sys -- (usbser)
DRV:64bit: - [2013/08/22 13:39:58 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2013/08/22 13:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:64bit: - [2013/08/22 13:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:64bit: - [2013/08/22 13:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:64bit: - [2013/08/22 13:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:64bit: - [2013/08/22 13:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:64bit: - [2013/08/22 13:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:64bit: - [2013/08/22 13:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:64bit: - [2013/08/22 13:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:64bit: - [2013/08/22 13:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:64bit: - [2013/08/22 13:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:64bit: - [2013/08/22 13:38:17 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2013/08/22 13:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:64bit: - [2013/08/22 13:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:64bit: - [2013/08/22 13:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2013/08/22 13:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:64bit: - [2013/08/22 13:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/08/22 13:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:64bit: - [2013/08/22 13:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2013/08/22 13:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:64bit: - [2013/08/22 13:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:64bit: - [2013/08/22 13:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:64bit: - [2013/08/22 13:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:64bit: - [2013/08/22 10:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:64bit: - [2013/08/13 01:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:64bit: - [2013/08/10 02:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:64bit: - [2013/07/30 20:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:64bit: - [2013/07/25 21:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:64bit: - [2013/06/18 16:46:17 | 000,591,360 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:64bit: - [2013/06/18 16:45:02 | 003,680,256 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athw8x.sys -- (athr)
DRV:64bit: - [2013/05/23 08:12:50 | 000,076,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2013/05/23 08:12:48 | 000,077,592 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LEqdUsb.sys -- (LEqdUsb)
DRV:64bit: - [2013/05/23 08:12:48 | 000,013,080 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidEqd.sys -- (LHidEqd)
DRV:64bit: - [2012/12/13 09:42:26 | 005,353,888 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2012/12/05 04:08:08 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr)
DRV:64bit: - [2012/12/05 04:08:08 | 000,033,560 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2012/09/30 04:43:24 | 000,135,832 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2012/09/30 04:43:22 | 000,178,840 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2012/09/30 04:43:22 | 000,076,952 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2012/09/30 04:43:20 | 000,344,216 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2012/09/30 04:43:20 | 000,114,840 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:64bit: - [2012/09/30 04:43:20 | 000,088,728 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2012/09/05 05:30:20 | 000,318,800 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2012/08/29 15:09:16 | 000,052,376 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2012/08/29 15:08:42 | 000,037,680 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmusb.sys -- (vmusb)
DRV:64bit: - [2012/08/27 09:48:34 | 008,227,216 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtsuvc.sys -- (rtsuvc)
DRV:64bit: - [2012/07/09 23:43:12 | 000,645,952 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:64bit: - [2012/07/03 01:16:02 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2012/06/19 16:40:51 | 000,342,528 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2012/06/14 03:10:32 | 000,102,376 | ---- | M] ("CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2012/06/13 12:24:02 | 000,315,536 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUVStor.sys -- (RSUSBVSTOR)
DRV:64bit: - [2011/11/25 02:25:52 | 000,015,360 | ---- | M] (June Fabrics Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pneteth.sys -- (pneteth)
DRV:64bit: - [2011/11/03 04:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2010/04/29 07:55:42 | 000,032,768 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\androidusb.sys -- (androidusb)
DRV - [2011/02/11 18:34:28 | 000,019,968 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\LGPII2CDriver.sys -- (LGII2CDevice)
DRV - [2010/08/04 11:05:12 | 000,016,384 | ---- | M] (LG Soft India) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\LGI2CDriver.sys -- (LGDDCDevice)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{C9025ABC-81CC-492C-81D4-9DA87B28B4EE}: "URL" = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{C9025ABC-81CC-492C-81D4-9DA87B28B4EE}: "URL" = http://www.bing.com/search?q={searchTer ... &pc=MALNJS


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-1410772076-1682251192-4122739941-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
IE - HKU\S-1-5-21-1410772076-1682251192-4122739941-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com [binary data]
IE - HKU\S-1-5-21-1410772076-1682251192-4122739941-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com [binary data]
IE - HKU\S-1-5-21-1410772076-1682251192-4122739941-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com
IE - HKU\S-1-5-21-1410772076-1682251192-4122739941-1002\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1410772076-1682251192-4122739941-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-1410772076-1682251192-4122739941-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7Bb749fc7c-e949-447f-926c-3f4eed6accfe%7D:0.7.1.1
FF - prefs.js..extensions.enabledAddons: %7Bc45c406e-ab73-11d8-be73-000a95be3b12%7D:1.2.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:32.0.3
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@lastpass.com/NPLastPass: C:\Program Files (x86)\LastPass\nplastpass64.dll (LastPass)
FF:64bit: - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer64,version=1.0: C:\Program Files\Unity\WebPlayer64\loader-x64\npUnity3D64.dll (Unity Technologies ApS)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@lastpass.com/NPLastPass: C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Martin\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Martin\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F003DA68-8256-4b37-A6C4-350FA04494DF}: C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014/01/19 01:59:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2014/10/03 16:02:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014/08/02 17:43:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/10/03 16:02:35 | 000,000,000 | ---D | M]

[2014/02/21 01:53:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Martin\AppData\Roaming\mozilla\Extensions
[2014/10/17 20:45:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Martin\AppData\Roaming\mozilla\Firefox\Profiles\7vni0jbm.default\extensions
[2014/05/01 14:52:43 | 000,061,705 | ---- | M] () (No name found) -- C:\Users\Martin\AppData\Roaming\mozilla\firefox\profiles\7vni0jbm.default\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}.xpi
[2014/10/17 20:45:38 | 001,360,435 | ---- | M] () (No name found) -- C:\Users\Martin\AppData\Roaming\mozilla\firefox\profiles\7vni0jbm.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
[2014/02/21 01:52:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/10/02 10:29:53 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/11/15 04:30:36 | 000,034,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll

========== Chrome ==========

CHR - default_search_provider: (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.10.3_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\3.1.61_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmdcmlfkchdmnmnmheododdhjedfccka\0.3.6_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\iggpfpnahkgpnindfkdncknoldgnccdg\5.2.4_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnjjlbngpejmmhgcaagljaomgnginml\7.1_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfkgmnnajiljnolcgolmmgnecgldgeld\0.17.14_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mblbciejcodpealifnhfjbdlkedplodp\1.3.4_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmbdmpjmlijibeockamioakdpmhjnpk\1.1.112_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: PrvnĂ­ uĹľivatel = C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp\5.2.4_0\

O1 HOSTS File: ([2014/02/10 00:30:05 | 000,002,041 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 192.150.14.69
O1 - Hosts: 127.0.0.1 192.150.18.101
O1 - Hosts: 127.0.0.1 192.150.18.108
O1 - Hosts: 127.0.0.1 192.150.22.40
O1 - Hosts: 127.0.0.1 192.150.8.100
O1 - Hosts: 127.0.0.1 192.150.8.118
O1 - Hosts: 127.0.0.1 209-34-83-73.ood.opsource.net
O1 - Hosts: 127.0.0.1 3dns-1.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-4.adobe.com
O1 - Hosts: 127.0.0.1 3dns.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip2.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 15 more lines...
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BtPreLoad] C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe ()
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\WINDOWS\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [OnekeyStudio] C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtsFT] C:\WINDOWS\RTFTrack.exe (Realtek semiconductor)
O4:64bit: - HKLM..\Run: [ShadowPlay] C:\WINDOWS\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Dolby Home Theater v4] C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (Dolby Laboratories Inc.)
O4 - HKLM..\Run: [GIGABYTEMOUSE] C:\Users\Martin\Documents\GIGABYTE\GIGABYTE Sim\Mouse.exe ()
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [YouCam Mirage] C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (CyberLink)
O4 - HKLM..\Run: [YouCam Tray] C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-1410772076-1682251192-4122739941-1002..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKU\S-1-5-21-1410772076-1682251192-4122739941-1002..\Run: [Zoner Photo Studio Autoupdate] C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTray.exe (ZONER software)
O4 - Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registrace produktu.lnk = C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
O4 - Startup: C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Stáhnout s Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm File not found
O8 - Extra context menu item: Stáhnout s Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm File not found
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{488FD450-8140-47FA-A0D3-651E120F440B}: DhcpNameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{611A4549-2BEA-4624-BF5F-877C21BF12A7}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C5EFCC78-097F-4BEA-81A0-D1A7D490C72D}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\osf - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20:64bit: - AppInit_DLLs: (C:\WINDOWS\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30:64bit: - LSA: Security Packages - (wsauth) - C:\WINDOWS\SysNative\wsauth.dll (VMware, Inc.)
O30 - LSA: Security Packages - (livessp) - File not found
O30 - LSA: Security Packages - (wsauth) - File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c7139f89-0e84-11e4-beac-20898427258f}\Shell - "" = AutoRun
O33 - MountPoints2\{c7139f89-0e84-11e4-beac-20898427258f}\Shell\AutoRun\command - "" = "H:\Bolt.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs:64bit: lfsvc - C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
NetSvcs:64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.clmp3enc - C:\Program Files (x86)\Lenovo\Power2Go\CLMP3Enc.ACM (CyberLink Corp.)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\WINDOWS\SysWow64\iccvid.dll (Radius Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2014/10/21 15:42:40 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Martin\Desktop\OTL.exe
[2014/10/19 20:48:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/10/19 13:40:30 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/10/18 21:20:43 | 000,000,000 | ---D | C] -- C:\Users\Martin\Documents\WORDPRESS
[2014/10/18 20:51:02 | 000,000,000 | ---D | C] -- C:\Users\Martin\Desktop\web
[2014/10/18 18:34:54 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2014/10/18 18:34:54 | 000,000,000 | ---D | C] -- C:\rsit
[2014/10/18 15:18:35 | 000,000,000 | ---D | C] -- C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Font Xplorer
[2014/10/18 15:18:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Font Xplorer
[2014/10/18 15:18:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Font Xplorer
[2014/10/18 14:59:16 | 000,000,000 | ---D | C] -- C:\Users\Martin\Desktop\PSTA
[2014/10/17 14:00:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winamp
[2014/10/17 14:00:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Last.fm
[2014/10/17 13:59:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Last.fm
[2014/10/17 13:58:33 | 000,000,000 | ---D | C] -- C:\Users\Martin\AppData\Local\Last.fm
[2014/10/17 13:58:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Last.fm
[2014/10/16 12:51:47 | 000,921,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2014/10/16 12:51:47 | 000,626,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2014/10/16 12:51:44 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbici.dll
[2014/10/16 12:51:03 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014/10/16 12:51:03 | 000,275,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2014/10/16 12:51:02 | 000,527,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2014/10/16 12:50:34 | 002,779,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2014/10/15 21:25:31 | 000,000,000 | ---D | C] -- C:\Program Files\IHMC CmapTools
[2014/10/15 21:24:58 | 000,000,000 | -H-D | C] -- C:\Users\Martin\InstallAnywhere
[2014/10/15 15:29:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft ASP.NET
[2014/10/15 15:27:32 | 000,839,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2014/10/15 15:27:31 | 001,702,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2014/10/15 15:27:31 | 000,672,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2014/10/15 15:27:31 | 000,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2014/10/15 15:27:31 | 000,137,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2014/10/15 15:27:31 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2014/10/15 15:27:31 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2014/10/15 15:27:31 | 000,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2014/10/15 15:27:31 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups.dll
[2014/10/15 15:27:31 | 000,054,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2014/10/15 15:27:31 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wups2.dll
[2014/10/15 15:27:30 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2014/10/15 15:27:30 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2014/10/15 15:26:50 | 002,646,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2014/10/15 15:26:49 | 002,321,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2014/10/15 15:26:38 | 008,757,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Search.dll
[2014/10/15 15:26:34 | 005,902,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Search.dll
[2014/10/15 15:26:33 | 006,649,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mstscax.dll
[2014/10/15 15:26:32 | 005,777,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mstscax.dll
[2014/10/15 15:26:31 | 004,758,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll
[2014/10/15 15:26:28 | 001,106,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SearchFolder.dll
[2014/10/15 15:26:27 | 001,710,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2014/10/15 15:26:27 | 001,112,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2014/10/15 15:26:26 | 001,507,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\propsys.dll
[2014/10/15 15:26:25 | 000,920,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll
[2014/10/15 15:26:24 | 000,756,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll
[2014/10/15 15:26:24 | 000,359,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wldap32.dll
[2014/10/15 15:26:21 | 000,287,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SystemEventsBrokerServer.dll
[2014/10/15 15:26:19 | 001,120,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDrive.exe
[2014/10/15 15:26:19 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveTelemetry.dll
[2014/10/15 15:26:19 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\bisrv.dll
[2014/10/15 15:26:19 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\httpprxm.dll
[2014/10/15 15:26:18 | 000,428,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS
[2014/10/15 15:26:18 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\pcsvDevice.dll
[2014/10/15 15:26:17 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ProximityService.dll
[2014/10/15 15:26:17 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveShell.dll
[2014/10/15 15:26:17 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SkyDriveShell.dll
[2014/10/15 15:26:17 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\adhsvc.dll
[2014/10/15 15:26:14 | 000,249,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2014/10/15 15:26:14 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2014/10/15 15:25:32 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\packager.dll
[2014/10/15 15:25:32 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\packager.dll
[2014/10/15 15:23:35 | 005,829,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2014/10/15 15:23:15 | 000,731,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2014/10/15 15:23:14 | 002,108,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2014/10/15 15:23:11 | 002,017,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2014/10/15 15:23:09 | 000,710,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2014/10/15 15:23:05 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2014/10/15 15:23:04 | 000,775,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2014/10/15 15:23:04 | 000,758,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2014/10/15 15:23:04 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2014/10/15 15:23:04 | 000,547,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2014/10/15 15:23:04 | 000,289,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2014/10/15 15:23:04 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2014/10/15 15:23:04 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2014/10/15 15:23:04 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2014/10/15 15:23:01 | 000,590,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rastls.dll
[2014/10/15 15:23:01 | 000,514,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rastls.dll
[2014/10/14 14:10:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
[2014/10/14 14:10:46 | 000,000,000 | ---D | C] -- C:\Program Files\Defraggler
[2014/10/07 18:54:42 | 000,000,000 | ---D | C] -- C:\Users\Martin\Desktop\Behance
[2014/10/05 17:06:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sherlock Holmes Crimes and Punishments
[2014/10/05 16:54:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sherlock Holmes Crimes and Punishments
[2014/10/03 16:27:04 | 000,000,000 | ---D | C] -- C:\Users\Martin\AppData\Roaming\Unity
[2014/10/03 15:46:23 | 000,000,000 | ---D | C] -- C:\Program Files\Unity
[2014/09/28 19:14:16 | 000,000,000 | ---D | C] -- C:\Users\Martin\AppData\Local\TuneUp Software
[2014/09/28 01:32:15 | 000,000,000 | ---D | C] -- C:\Users\Martin\AppData\Roaming\WebApp
[2014/09/25 16:58:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\NV
[2014/09/25 16:58:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\NV
[2014/09/25 16:57:49 | 000,000,000 | ---D | C] -- C:\NVIDIA Corporation
[2014/09/25 15:16:07 | 000,000,000 | ---D | C] -- C:\Users\Martin\AppData\Local\Launcher
[2014/09/25 15:16:07 | 000,000,000 | ---D | C] -- C:\Users\Martin\AppData\Local\id Software
[2014/09/25 15:15:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Quake Live
[2014/09/21 18:31:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Saints Row IV
[2014/09/21 18:14:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Saints Row IV
[2014/09/21 18:11:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2014/09/21 18:10:31 | 000,613,696 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvStreaming.exe
[2014/09/21 18:07:11 | 020,589,536 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvwgf2umx.dll
[2014/09/21 18:07:11 | 018,106,152 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvwgf2um.dll
[2014/09/21 18:07:11 | 000,032,576 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\drivers\nvpciflt.sys
[2014/09/21 18:07:10 | 031,887,680 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvoglv64.dll
[2014/09/21 18:07:10 | 024,552,592 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvoglv32.dll
[2014/09/21 18:07:10 | 020,922,512 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcompiler.dll
[2014/09/21 18:07:10 | 017,259,664 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcompiler.dll
[2014/09/21 18:07:10 | 014,026,304 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvopencl.dll
[2014/09/21 18:07:10 | 013,939,272 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuda.dll
[2014/09/21 18:07:10 | 011,392,576 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvopencl.dll
[2014/09/21 18:07:10 | 011,330,776 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuda.dll
[2014/09/21 18:07:10 | 004,287,296 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvcuvid.dll
[2014/09/21 18:07:10 | 004,008,592 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvcuvid.dll
[2014/09/21 18:07:10 | 002,838,424 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvapi.dll
[2014/09/21 18:07:10 | 001,876,296 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispco6434411.dll
[2014/09/21 18:07:10 | 001,539,272 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvdispgenco6434411.dll
[2014/09/21 18:07:10 | 000,957,584 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFR64.dll
[2014/09/21 18:07:10 | 000,925,896 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvFBC64.dll
[2014/09/21 18:07:10 | 000,919,240 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFR.dll
[2014/09/21 18:07:10 | 000,894,096 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvFBC.dll
[2014/09/21 18:07:10 | 000,501,064 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvEncodeAPI64.dll
[2014/09/21 18:07:10 | 000,417,096 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvEncodeAPI.dll
[2014/09/21 18:07:10 | 000,393,024 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\NvIFROpenGL.dll
[2014/09/21 18:07:10 | 000,352,016 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvoglshim64.dll
[2014/09/21 18:07:10 | 000,348,304 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\NvIFROpenGL.dll
[2014/09/21 18:07:10 | 000,303,600 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvoglshim32.dll
[2014/09/21 17:40:04 | 000,038,048 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\drivers\nvvad64v.sys
[2014/09/21 17:40:00 | 000,032,416 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvaudcap32v.dll

========== Files - Modified Within 30 Days ==========

[2014/10/21 15:47:15 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2014/10/21 15:45:00 | 000,000,982 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/10/21 15:42:41 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Martin\Desktop\OTL.exe
[2014/10/21 15:25:00 | 000,000,914 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/10/21 09:31:21 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/10/21 09:30:40 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/10/21 09:28:36 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014/10/21 09:28:31 | 2455,781,375 | -HS- | M] () -- C:\hiberfil.sys
[2014/10/21 09:24:09 | 002,383,872 | ---- | M] () -- C:\Users\Martin\Desktop\stepanek_dvoracek_veznice.eap
[2014/10/20 15:02:44 | 000,000,600 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\winscp.rnd
[2014/10/19 17:12:47 | 000,000,132 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
[2014/10/19 13:44:57 | 005,370,232 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2014/10/19 09:49:27 | 001,752,112 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2014/10/19 09:49:27 | 000,742,002 | ---- | M] () -- C:\WINDOWS\SysNative\perfh005.dat
[2014/10/19 09:49:27 | 000,724,554 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2014/10/19 09:49:27 | 000,152,432 | ---- | M] () -- C:\WINDOWS\SysNative\perfc005.dat
[2014/10/19 09:49:27 | 000,136,414 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2014/10/18 18:31:07 | 001,222,144 | ---- | M] () -- C:\Users\Martin\Desktop\RSITx64.exe
[2014/10/17 14:36:48 | 000,001,097 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2014/10/17 13:59:17 | 000,001,008 | ---- | M] () -- C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
[2014/10/14 21:43:07 | 059,455,678 | ---- | M] () -- C:\Users\Martin\Desktop\WIP.psd
[2014/10/14 19:58:39 | 000,112,168 | ---- | M] () -- C:\Users\Martin\Desktop\BPMN1_1_Poster_EN.pdf
[2014/10/14 18:44:46 | 004,198,400 | ---- | M] () -- C:\Users\Martin\Desktop\auto_pujcovna(1).eap
[2014/10/10 00:16:51 | 000,678,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014/10/09 00:09:34 | 000,275,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2014/10/07 18:37:53 | 000,843,776 | ---- | M] () -- C:\Users\Martin\Documents\cv.indd
[2014/10/04 08:42:47 | 002,197,680 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvspcap.dll
[2014/10/04 08:42:47 | 001,291,280 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysWow64\nvspbridge.dll
[2014/10/04 08:41:43 | 002,800,296 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvspcap64.dll
[2014/10/04 08:41:43 | 001,715,224 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SysNative\nvspbridge64.dll
[2014/10/04 00:39:33 | 000,001,480 | ---- | M] () -- C:\Users\Martin\AppData\Local\Adobe Uložit pro web 13.0 Prefs
[2014/10/01 15:30:31 | 003,164,160 | ---- | M] () -- C:\Users\Martin\Desktop\softwarova_firma.eap
[2014/09/30 00:45:58 | 000,706,016 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014/09/30 00:45:58 | 000,105,440 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014/09/28 01:53:51 | 000,001,489 | ---- | M] () -- C:\Users\Martin\Desktop\ROZVRH.lnk
[2014/09/26 00:46:19 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2014/09/26 00:32:04 | 002,017,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2014/09/26 00:31:02 | 002,108,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl

========== Files Created - No Company Name ==========

[2014/10/21 15:47:15 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2014/10/18 18:31:05 | 001,222,144 | ---- | C] () -- C:\Users\Martin\Desktop\RSITx64.exe
[2014/10/17 14:36:48 | 000,001,097 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2014/10/17 13:59:17 | 000,001,008 | ---- | C] () -- C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
[2014/10/15 15:26:14 | 000,388,729 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2014/10/14 19:58:39 | 000,112,168 | ---- | C] () -- C:\Users\Martin\Desktop\BPMN1_1_Poster_EN.pdf
[2014/10/14 19:29:05 | 003,081,044 | ---- | C] () -- C:\Users\Martin\Desktop\BPMN_by_examples.pdf
[2014/10/14 19:27:16 | 003,065,856 | ---- | C] () -- C:\Users\Martin\Desktop\billiardclub.eap
[2014/10/14 19:27:12 | 003,164,160 | ---- | C] () -- C:\Users\Martin\Desktop\softwarova_firma.eap
[2014/10/14 19:27:10 | 002,383,872 | ---- | C] () -- C:\Users\Martin\Desktop\stepanek_dvoracek_veznice.eap
[2014/10/14 18:44:44 | 004,198,400 | ---- | C] () -- C:\Users\Martin\Desktop\auto_pujcovna(1).eap
[2014/10/13 17:30:04 | 059,455,678 | ---- | C] () -- C:\Users\Martin\Desktop\WIP.psd
[2014/10/06 18:26:40 | 000,843,776 | ---- | C] () -- C:\Users\Martin\Documents\cv.indd
[2014/09/28 01:53:51 | 000,001,489 | ---- | C] () -- C:\Users\Martin\Desktop\ROZVRH.lnk
[2014/09/25 15:15:24 | 000,001,074 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quake Live.lnk
[2014/04/18 17:35:33 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014/04/09 23:01:05 | 001,772,950 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2014/04/04 03:01:58 | 000,001,056 | ---- | C] () -- C:\Users\Martin\AppData\Local\MRDownloader.nast
[2014/03/31 20:45:31 | 000,000,190 | ---- | C] () -- C:\Users\Martin\.packettracer
[2014/03/21 00:05:43 | 000,001,480 | ---- | C] () -- C:\Users\Martin\AppData\Local\Adobe Uložit pro web 13.0 Prefs
[2014/03/20 23:20:15 | 000,290,184 | ---- | C] () -- C:\WINDOWS\SysWow64\PnkBstrB.exe
[2014/03/20 23:20:14 | 000,076,888 | ---- | C] () -- C:\WINDOWS\SysWow64\PnkBstrA.exe
[2014/03/20 23:20:13 | 003,123,272 | R--- | C] () -- C:\WINDOWS\SysWow64\pbsvc.exe
[2014/03/18 01:47:58 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2014/02/05 23:33:59 | 000,000,132 | ---- | C] () -- C:\Users\Martin\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
[2014/01/16 15:34:57 | 000,049,152 | ---- | C] () -- C:\WINDOWS\SysWow64\LGErrorHandler.dll
[2014/01/16 15:34:57 | 000,019,968 | ---- | C] () -- C:\WINDOWS\SysWow64\LGPII2CDriver.sys
[2014/01/12 18:57:09 | 000,598,384 | ---- | C] () -- C:\WINDOWS\SysWow64\igvpkrng700.bin
[2014/01/12 18:57:04 | 000,064,512 | ---- | C] () -- C:\WINDOWS\SysWow64\igdde32.dll
[2014/01/12 18:57:03 | 000,754,652 | ---- | C] () -- C:\WINDOWS\SysWow64\igcodeckrng700.bin
[2014/01/12 17:44:23 | 000,000,600 | ---- | C] () -- C:\Users\Martin\AppData\Roaming\winscp.rnd
[2013/10/04 00:42:46 | 000,343,040 | ---- | C] () -- C:\WINDOWS\SysWow64\igdmd32.dll
[2013/10/04 00:42:38 | 000,142,848 | ---- | C] () -- C:\WINDOWS\SysWow64\igdail32.dll
[2013/08/22 17:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013/08/22 17:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013/08/22 16:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013/08/22 09:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013/08/22 05:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013/08/22 01:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013/08/22 01:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
[2012/12/05 04:04:54 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl

========== ZeroAccess Check ==========

[2014/01/12 18:13:12 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/08/16 06:08:41 | 021,195,616 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/08/16 05:16:40 | 018,722,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 11:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/22 04:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 11:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/12/22 03:16:36 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\AVAST Software
[2014/03/15 02:07:54 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Awesomium
[2014/03/02 02:17:07 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\BalsamiqMockupsForDesktop
[2014/03/02 02:15:53 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\BalsamiqMockupsForDesktop.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1
[2013/12/21 22:51:20 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Battle.net
[2014/05/03 19:29:12 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\BSplayer
[2013/12/22 02:55:42 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\BSplayer Pro
[2014/01/18 14:15:53 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2014/09/20 16:23:42 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\DAEMON Tools Lite
[2014/03/05 15:13:21 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\digipen
[2014/06/05 15:57:08 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Empty Clip Studios
[2014/01/09 00:50:36 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\EPSON
[2014/09/20 14:54:28 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Galaxy on Fire 2 Full HD
[2014/05/19 16:53:40 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Guild Wars 2
[2014/01/02 00:19:21 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Gyazo
[2014/02/01 16:32:56 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Injustice
[2014/01/19 01:59:55 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Leadertech
[2014/01/07 01:48:56 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Lenovo
[2014/01/27 19:04:24 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\LolClient
[2014/04/03 21:59:08 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\MetaQuotes
[2013/12/27 00:03:55 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Mipony
[2014/04/06 01:41:24 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\NCSOFT
[2014/01/19 15:18:30 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\NetBeans
[2014/06/04 21:27:30 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Origin
[2014/01/27 12:43:38 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Riot Games
[2014/03/10 19:11:31 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Sparx Systems
[2014/05/07 10:24:32 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\SQL Developer
[2014/04/17 19:20:16 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\sqldeveloper
[2014/01/03 22:09:31 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2014/08/29 23:32:58 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Steam
[2014/07/16 19:45:04 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\TERA
[2014/08/02 19:47:32 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Trine2
[2014/07/16 21:29:16 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Tropico 5
[2014/09/18 22:42:39 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\TuneUp Software
[2014/10/03 16:27:04 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Unity
[2014/09/09 18:14:46 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\uTorrent
[2014/01/18 14:06:27 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\VSRevoGroup
[2014/09/28 01:32:15 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\WebApp
[2014/10/14 17:50:09 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Webshare
[2014/07/09 14:37:31 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\WizardWars
[2014/08/14 16:09:21 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Zoner

========== Purity Check ==========



========== Custom Scans ==========

< >
[2013/08/22 16:45:54 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2013/12/21 21:58:53 | 000,000,936 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1410772076-1682251192-4122739941-1002Core.job
[2013/12/21 21:58:55 | 000,000,988 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1410772076-1682251192-4122739941-1002UA.job
[2014/04/30 12:14:25 | 000,000,914 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2014/09/20 14:34:06 | 000,000,978 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2014/09/20 14:34:07 | 000,000,982 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

< >

< MD5 for: AGP440.SYS >
[2014/04/26 15:04:31 | 000,000,012 | ---- | M] () MD5=06C6E29A8643D00197E214F3AA26A4B9 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.16384_none_aad14d4692a7dfee\AGP440.sys
[2013/08/22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\WINDOWS\SysNative\drivers\AGP440.sys
[2013/08/22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\machine.inf_amd64_36be84f8fc597ea3\AGP440.sys
[2013/08/22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_ab0b455c927bd60f\AGP440.sys
[2014/09/20 07:59:32 | 000,000,012 | ---- | M] () MD5=AC26F500DB64617F336315BB5A0FDBE1 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17031_none_ab043f8a92822a60\AGP440.sys

< MD5 for: ATAPI.SYS >
[2013/08/22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\WINDOWS\SysNative\drivers\atapi.sys
[2013/08/22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\WINDOWS\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_64aa4354da84c2df\atapi.sys
[2013/08/22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_cdf68824f580d510\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2014/04/26 15:07:25 | 000,028,249 | ---- | M] () MD5=0CBDE27FB26761852F7B22AFB8C51ACB -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.16384_none_d2b24d5495b82963\autochk.exe
[2014/02/22 13:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\SysWOW64\autochk.exe
[2014/02/22 13:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_76c6a414dd35029f\autochk.exe
[2014/02/22 14:17:06 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\WINDOWS\SysNative\autochk.exe
[2014/02/22 14:17:06 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_d2e53f98959273d5\autochk.exe
[2014/04/26 15:54:39 | 000,023,596 | ---- | M] () MD5=83A4C9BE342BC296EC09492FF7594F13 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.16384_none_7693b1d0dd5ab82d\autochk.exe

< MD5 for: CDROM.SYS >
[2013/08/22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\WINDOWS\SysNative\drivers\cdrom.sys
[2013/08/22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\WINDOWS\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_42e9c29f0affc440\cdrom.sys
[2013/08/22 10:46:35 | 000,164,352 | ---- | M] (Microsoft Corporation) MD5=C6796EA22B513E3457514D92DCDB1A3D -- C:\Windows\WinSxS\amd64_cdrom.inf_31bf3856ad364e35_6.3.9600.16384_none_5067bbed77be70be\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2013/08/22 12:01:39 | 000,129,536 | ---- | M] (Microsoft Corporation) MD5=0EFE4B5884A8032617826A4D76F80969 -- C:\WINDOWS\SysNative\cryptsvc.dll
[2013/08/22 12:01:39 | 000,129,536 | ---- | M] (Microsoft Corporation) MD5=0EFE4B5884A8032617826A4D76F80969 -- C:\Windows\WinSxS\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.3.9600.16384_none_66bdf96f6ec6545d\cryptsvc.dll

< MD5 for: EXPLORER.EXE >
[2014/08/23 09:13:24 | 002,084,520 | ---- | M] (Microsoft Corporation) MD5=195822ACCDAA2B4815DD01BAFC335595 -- C:\Windows\SysWOW64\explorer.exe
[2014/08/23 09:13:24 | 002,084,520 | ---- | M] (Microsoft Corporation) MD5=195822ACCDAA2B4815DD01BAFC335595 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4cc798c1821453a8\explorer.exe
[2014/09/20 08:02:10 | 000,270,774 | ---- | M] () MD5=2195687491E604BA42961470EDA7660E -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17238_none_42acff334d876b54\explorer.exe
[2014/09/20 08:11:22 | 000,220,250 | ---- | M] () MD5=286928E00AD34E9F88EB5BFA52660A70 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17238_none_4d01a98581e82d4f\explorer.exe
[2014/04/26 15:42:08 | 000,015,546 | ---- | M] () MD5=347EFF7EC89C3EB4F72F2408E1C4E16D -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_4cfaa3b381ee81a0\explorer.exe
[2014/04/26 15:42:05 | 000,238,918 | ---- | M] () MD5=5177BB4FECDDB9CDBCF10EF65916968D -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_4ceff22781f6788c\explorer.exe
[2014/09/20 08:02:07 | 000,271,249 | ---- | M] () MD5=667BC926C7CB889BF276A5FEA316CAEE -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_42adfbb14d868a5d\explorer.exe
[2014/04/26 15:13:55 | 000,169,957 | ---- | M] () MD5=6D919C26DCB567396CD2E119B8E4310E -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_42a5f9614d8dbfa5\explorer.exe
[2014/08/23 09:48:28 | 002,374,784 | ---- | M] (Microsoft Corporation) MD5=ACDBE1ED38167C8B01B8F63161BB2CEA -- C:\Windows\explorer.exe
[2014/08/23 09:48:28 | 002,374,784 | ---- | M] (Microsoft Corporation) MD5=ACDBE1ED38167C8B01B8F63161BB2CEA -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4272ee6f4db391ad\explorer.exe
[2014/09/20 08:11:26 | 000,219,647 | ---- | M] () MD5=B75E9C8434D53F8C187D352FA7F692D4 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17249_none_4cf7d9e381ef6297\explorer.exe
[2014/09/20 08:11:17 | 000,208,662 | ---- | M] () MD5=C131BC6F12417306A9C8469CA49110B1 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_4d02a60381e74c58\explorer.exe
[2014/09/20 08:02:13 | 000,270,403 | ---- | M] () MD5=C20A0C44E241606430009E7F126A1125 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17249_none_42a32f914d8ea09c\explorer.exe
[2014/04/26 15:13:52 | 000,283,735 | ---- | M] () MD5=FA98C5D746E7C9E0912E88AC44FF9926 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_429b47d54d95b691\explorer.exe

< MD5 for: HAL.DLL >
[2014/06/02 04:10:31 | 000,423,768 | ---- | M] (Microsoft Corporation) MD5=08DCA300264238F9AE941302321F3D54 -- C:\WINDOWS\SysNative\hal.dll
[2014/06/02 04:10:31 | 000,423,768 | ---- | M] (Microsoft Corporation) MD5=08DCA300264238F9AE941302321F3D54 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.17196_none_9bde68c32da7abbb\hal.dll
[2014/08/18 13:03:00 | 000,024,467 | ---- | M] () MD5=2635F50EAF3E1B4A8D32B21E1203E130 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.17031_none_9c1a44f32d7b883b\hal.dll
[2014/03/21 14:09:30 | 000,014,096 | ---- | M] () MD5=64D2873F32BB723BFFF3F8895032AA35 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.16408_none_9c41d51d2d5cc0c4\hal.dll
[2014/04/26 15:14:54 | 000,066,843 | ---- | M] () MD5=D714202F057A317C8E31776EBEA0AEA2 -- C:\Windows\WinSxS\amd64_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.16500_none_9c39d4b32d63f333\hal.dll

< MD5 for: IASTORV.SYS >
[2013/08/22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\WINDOWS\SysNative\drivers\iaStorV.sys
[2013/08/22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_5069105fb236ae4b\iaStorV.sys
[2013/08/22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_6.3.9600.16384_none_9fcfb2835bbf0103\iaStorV.sys

Lothaire
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 pro 2009 21:20

Re: Preventivka s menším podezřením

#12 Příspěvek od Lothaire »

Pokračování OTL:
< MD5 for: ISAPNP.SYS >
[2014/04/26 15:04:31 | 000,000,012 | ---- | M] () MD5=06C6E29A8643D00197E214F3AA26A4B9 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.16384_none_aad14d4692a7dfee\isapnp.sys
[2013/08/22 14:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\WINDOWS\SysNative\drivers\isapnp.sys
[2013/08/22 14:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\machine.inf_amd64_36be84f8fc597ea3\isapnp.sys
[2013/08/22 14:43:45 | 000,021,856 | ---- | M] (Microsoft Corporation) MD5=8AFEEA3955AA43616A60F133B1D25F21 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_ab0b455c927bd60f\isapnp.sys
[2014/09/20 07:59:33 | 000,000,012 | ---- | M] () MD5=AC26F500DB64617F336315BB5A0FDBE1 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17031_none_ab043f8a92822a60\isapnp.sys

< MD5 for: LSASS.EXE >
[2013/08/22 15:25:35 | 000,045,008 | ---- | M] (Microsoft Corporation) MD5=F6F209DDB94959BA104FC8FC87C53759 -- C:\WINDOWS\SysNative\lsass.exe
[2013/08/22 15:25:35 | 000,045,008 | ---- | M] (Microsoft Corporation) MD5=F6F209DDB94959BA104FC8FC87C53759 -- C:\Windows\WinSxS\amd64_microsoft-windows-lsa-minwin_31bf3856ad364e35_6.3.9600.16408_none_2e8484166600f08e\lsass.exe

< MD5 for: NDIS.SYS >
[2014/02/28 13:09:55 | 000,046,734 | ---- | M] () MD5=68A9BA38BB275850F91165D1C1FCA8DA -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16408_none_4a6e60adfbbe952c\ndis.sys
[2014/04/26 15:23:57 | 000,140,607 | ---- | M] () MD5=7B886741BDAE33AC4F116DF991D1E3CB -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16475_none_4a1fb05bfbfa0cbe\ndis.sys
[2014/09/20 08:05:37 | 000,025,682 | ---- | M] () MD5=D2D6A481A75207BF24E9D48C61B7F012 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17031_none_4a46d083fbdd5ca3\ndis.sys
[2014/06/05 16:00:18 | 001,118,040 | ---- | M] (Microsoft Corporation) MD5=E4B4BE2D7750849C07589DA0B0AABA01 -- C:\WINDOWS\SysNative\drivers\ndis.sys
[2014/06/05 16:00:18 | 001,118,040 | ---- | M] (Microsoft Corporation) MD5=E4B4BE2D7750849C07589DA0B0AABA01 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17199_none_4a0df531fc06cc28\ndis.sys

< MD5 for: NETLOGON.DLL >
[2014/03/06 09:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) MD5=2468C21E34C49E4735B4BA430D448E91 -- C:\WINDOWS\SysNative\netlogon.dll
[2014/03/06 09:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) MD5=2468C21E34C49E4735B4BA430D448E91 -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_ee9e39a60bd3552e\netlogon.dll
[2014/04/26 15:49:47 | 000,058,552 | ---- | M] () MD5=35048C9600694C3BF01D644D1AAE62BE -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_f8cac1a04051b0c6\netlogon.dll
[2014/03/06 08:29:17 | 000,688,640 | ---- | M] (Microsoft Corporation) MD5=582918F96C2B7E1E3AE17D08DB6DAC41 -- C:\Windows\SysWOW64\netlogon.dll
[2014/03/06 08:29:17 | 000,688,640 | ---- | M] (Microsoft Corporation) MD5=582918F96C2B7E1E3AE17D08DB6DAC41 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_f8f2e3f840341729\netlogon.dll
[2014/04/26 15:28:04 | 000,108,975 | ---- | M] () MD5=D817ED82C2A0E1CED9B396826F52F7CB -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_ee76174e0bf0eecb\netlogon.dll

< MD5 for: NVRAID.SYS >
[2013/08/22 14:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\WINDOWS\SysNative\drivers\nvraid.sys
[2013/08/22 14:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvraid.sys
[2013/08/22 14:43:31 | 000,150,368 | ---- | M] (NVIDIA Corporation) MD5=BC6B5942AFF25EBAF62DE43C3807EDF8 -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_2a99233292f5aadb\nvraid.sys

< MD5 for: NVSTOR.SYS >
[2013/08/22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\WINDOWS\SysNative\drivers\nvstor.sys
[2013/08/22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\WINDOWS\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvstor.sys
[2013/08/22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_2a99233292f5aadb\nvstor.sys

< MD5 for: SCECLI.DLL >
[2013/08/22 04:48:17 | 000,207,360 | ---- | M] (Microsoft Corporation) MD5=1F142D5BD1C3869C5D902779B6FEC3EF -- C:\Windows\SysWOW64\scecli.dll
[2013/08/22 04:48:17 | 000,207,360 | ---- | M] (Microsoft Corporation) MD5=1F142D5BD1C3869C5D902779B6FEC3EF -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_3320ecb8e1733781\scecli.dll
[2013/08/22 11:55:43 | 000,271,360 | ---- | M] (Microsoft Corporation) MD5=1F1B8D07708E40E54C55B392C78ECCE2 -- C:\WINDOWS\SysNative\scecli.dll
[2013/08/22 11:55:43 | 000,271,360 | ---- | M] (Microsoft Corporation) MD5=1F1B8D07708E40E54C55B392C78ECCE2 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_28cc4266ad127586\scecli.dll

< MD5 for: SMSS.EXE >
[2014/04/26 15:30:07 | 000,019,120 | ---- | M] () MD5=5FBA1F5F9AA1E09595F015118AE83A36 -- C:\Windows\WinSxS\amd64_microsoft-windows-smss-minwin_31bf3856ad364e35_6.3.9600.16384_none_6f1f364dbcc273d3\smss.exe
[2014/02/22 17:43:03 | 000,142,576 | ---- | M] (Microsoft Corporation) MD5=D8564418BAC13776E43DB5F6B4FA775E -- C:\WINDOWS\SysNative\smss.exe
[2014/02/22 17:43:03 | 000,142,576 | ---- | M] (Microsoft Corporation) MD5=D8564418BAC13776E43DB5F6B4FA775E -- C:\Windows\WinSxS\amd64_microsoft-windows-smss-minwin_31bf3856ad364e35_6.3.9600.17031_none_6f522891bc9cbe45\smss.exe

< MD5 for: SVCHOST.EXE >
[2013/08/22 07:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) MD5=425E22D9F5C01616AFC92987791B19E9 -- C:\Windows\SysWOW64\svchost.exe
[2013/08/22 07:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) MD5=425E22D9F5C01616AFC92987791B19E9 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_4a5b1e2820e75323\svchost.exe
[2013/08/22 14:45:17 | 000,037,768 | ---- | M] (Microsoft Corporation) MD5=E4CA434F251681590D0538BC21C32D2F -- C:\WINDOWS\SysNative\svchost.exe
[2013/08/22 14:45:17 | 000,037,768 | ---- | M] (Microsoft Corporation) MD5=E4CA434F251681590D0538BC21C32D2F -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_a679b9abd944c459\svchost.exe

< MD5 for: TCPIP.SYS >
[2014/02/28 13:17:35 | 000,210,441 | ---- | M] () MD5=01941724D120729E2B680B22F05D4123 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16423_none_a41c53813a2d8394\tcpip.sys
[2014/03/21 14:13:10 | 000,271,861 | ---- | M] () MD5=2102610D6FD1D928A3D7155077A78B82 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16456_none_a3fee49b3a43236c\tcpip.sys
[2014/04/26 15:31:59 | 000,481,295 | ---- | M] () MD5=2F83A7537A9B8CF98E6B4710A3E3D381 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16521_none_a41a54d33a2f4e0d\tcpip.sys
[2014/08/16 05:57:37 | 002,498,880 | ---- | M] (Microsoft Corporation) MD5=87F3713E620F62D243A82B3CB66CBDDE -- C:\WINDOWS\SysNative\drivers\tcpip.sys
[2014/08/16 05:57:37 | 002,498,880 | ---- | M] (Microsoft Corporation) MD5=87F3713E620F62D243A82B3CB66CBDDE -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17278_none_a3eb2ac33a51ad4f\tcpip.sys
[2014/08/18 13:10:25 | 000,223,198 | ---- | M] () MD5=889B53B7C56665B0277CC00EF4051DE4 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17085_none_a3dd562d3a5c82ed\tcpip.sys
[2014/09/20 08:08:31 | 000,254,700 | ---- | M] () MD5=8B15952BE4FB7CF329EC3437A7EC4828 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17039_none_a41766f13a305c94\tcpip.sys
[2014/09/20 08:08:35 | 000,242,003 | ---- | M] () MD5=90511DE4535E8829764B1E1E220F56DB -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17136_none_a41467f93a330db6\tcpip.sys
[2014/07/24 16:57:08 | 002,515,264 | ---- | M] (Microsoft Corporation) MD5=FEBAA7D782E30882FFF1CBCBBE8AD467 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17238_none_a4166a733a313d8b\tcpip.sys

< MD5 for: USERINIT.EXE >
[2013/08/22 12:03:12 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=08C191B2917862BE90C33E31CB6B6D79 -- C:\WINDOWS\SysNative\userinit.exe
[2013/08/22 12:03:12 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=08C191B2917862BE90C33E31CB6B6D79 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_cce71a20a5a6fe7f\userinit.exe
[2013/08/22 04:54:12 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=41636F77AD6D9A396EA34E4786B96F2B -- C:\Windows\SysWOW64\userinit.exe
[2013/08/22 04:54:12 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=41636F77AD6D9A396EA34E4786B96F2B -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_70c87e9ced498d49\userinit.exe

< MD5 for: WINLOGON.EXE >
[2014/02/22 11:45:48 | 000,562,176 | ---- | M] (Microsoft Corporation) MD5=306EB21E5B480AE9065EA55AC8C35936 -- C:\WINDOWS\SysNative\winlogon.exe
[2014/02/22 11:45:48 | 000,562,176 | ---- | M] (Microsoft Corporation) MD5=306EB21E5B480AE9065EA55AC8C35936 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_60b45365a8c2ccdb\winlogon.exe
[2014/04/26 15:34:50 | 000,089,459 | ---- | M] () MD5=E40DC8DF924E02F04F3620DBAC1ACE31 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.16384_none_60816121a8e88269\winlogon.exe

< MD5 for: WS2_32.DLL >
[2013/08/22 07:17:54 | 000,313,488 | ---- | M] (Microsoft Corporation) MD5=428AF7FA03FF09CE1CD373ABFEBAD8A3 -- C:\Windows\SysWOW64\ws2_32.dll
[2013/08/22 07:17:54 | 000,313,488 | ---- | M] (Microsoft Corporation) MD5=428AF7FA03FF09CE1CD373ABFEBAD8A3 -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_87577549e9ef9b02\ws2_32.dll
[2013/08/22 15:25:35 | 000,355,872 | ---- | M] (Microsoft Corporation) MD5=6F997D98C6A30D79C622811FBAB9119E -- C:\WINDOWS\SysNative\ws2_32.dll
[2013/08/22 15:25:35 | 000,355,872 | ---- | M] (Microsoft Corporation) MD5=6F997D98C6A30D79C622811FBAB9119E -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_e37610cda24d0c38\ws2_32.dll

< >

< %systemroot%*.* /U /s >
[2 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[2 C:\WINDOWS\Inf\Oracle Data Provider for .NET\*.tmp files -> C:\WINDOWS\Inf\Oracle Data Provider for .NET\*.tmp -> ]
[1 C:\WINDOWS\Inf\Oracle Data Provider for .NET\0000\*.tmp files -> C:\WINDOWS\Inf\Oracle Data Provider for .NET\0000\*.tmp -> ]
[1 C:\WINDOWS\Inf\Oracle Data Provider for .NET\0005\*.tmp files -> C:\WINDOWS\Inf\Oracle Data Provider for .NET\0005\*.tmp -> ]
[1 C:\WINDOWS\Inf\Oracle Data Provider for .NET\0009\*.tmp files -> C:\WINDOWS\Inf\Oracle Data Provider for .NET\0009\*.tmp -> ]
[7 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[2 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >
[2007/11/07 09:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2014/03/21 00:05:02 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Adobe
[2014/02/25 17:50:15 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Apple Computer
[2013/12/21 18:39:38 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Atheros
[2013/12/22 03:16:36 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\AVAST Software
[2014/03/15 02:07:54 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Awesomium
[2014/03/02 02:17:07 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\BalsamiqMockupsForDesktop
[2014/03/02 02:15:53 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\BalsamiqMockupsForDesktop.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1
[2013/12/21 22:51:20 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Battle.net
[2014/05/03 19:29:12 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\BSplayer
[2013/12/22 02:55:42 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\BSplayer Pro
[2014/01/18 14:15:53 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2014/01/07 01:48:54 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\CyberLink
[2014/09/20 16:23:42 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\DAEMON Tools Lite
[2014/03/05 15:13:21 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\digipen
[2014/06/05 15:57:08 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Empty Clip Studios
[2014/01/09 00:50:36 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\EPSON
[2014/09/20 14:54:28 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Galaxy on Fire 2 Full HD
[2014/05/19 16:53:40 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Guild Wars 2
[2014/01/02 00:19:21 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Gyazo
[2013/12/22 02:17:10 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Identities
[2014/02/01 16:32:56 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Injustice
[2014/01/19 01:59:55 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Leadertech
[2014/01/07 01:48:56 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Lenovo
[2014/01/19 01:50:09 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Logishrd
[2014/01/19 02:14:59 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Logitech
[2014/01/27 19:04:24 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\LolClient
[2013/12/21 18:37:13 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Macromedia
[2014/04/03 21:59:08 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\MetaQuotes
[2014/06/23 11:08:22 | 000,000,000 | --SD | M] -- C:\Users\Martin\AppData\Roaming\Microsoft
[2014/07/10 13:58:52 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Microsoft Games
[2013/12/27 00:03:55 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Mipony
[2014/02/21 01:53:12 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Mozilla
[2014/04/06 01:41:24 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\NCSOFT
[2014/01/19 15:18:30 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\NetBeans
[2014/02/04 20:33:49 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\NVIDIA
[2014/06/04 21:27:30 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Origin
[2014/01/27 12:43:38 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Riot Games
[2014/10/15 20:50:29 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Skype
[2014/03/10 19:11:31 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Sparx Systems
[2014/05/07 10:24:32 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\SQL Developer
[2014/04/17 19:20:16 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\sqldeveloper
[2014/01/03 22:09:31 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2014/08/29 23:32:58 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Steam
[2014/07/16 19:45:04 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\TERA
[2014/08/02 19:47:32 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Trine2
[2014/07/16 21:29:16 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Tropico 5
[2014/09/18 22:42:39 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\TuneUp Software
[2014/10/03 16:27:04 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Unity
[2014/09/09 18:14:46 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\uTorrent
[2014/10/17 21:03:04 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\vlc
[2014/10/16 11:59:33 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\VMware
[2014/01/18 14:06:27 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\VSRevoGroup
[2014/09/28 01:32:15 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\WebApp
[2014/10/14 17:50:09 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Webshare
[2013/12/29 02:49:55 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\WinRAR
[2014/07/09 14:37:31 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\WizardWars
[2014/08/14 16:09:21 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Zoner

< %APPDATA%\*.exe /s >
[2009/08/11 22:21:26 | 000,087,552 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\BSplayer\AC3 Filter\ac3config.exe
[2009/08/11 22:21:30 | 000,090,112 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\BSplayer\AC3 Filter\spdif_test.exe
[2010/03/22 15:52:04 | 000,697,690 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\BSplayer\AC3 Filter\unins000.exe
[2012/10/11 10:01:20 | 001,175,371 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\BSplayer\FFDShow\unins000.exe
[2010/08/14 11:42:54 | 000,113,152 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\BSplayer\Haali media splitter\dsmux.exe
[2010/08/14 11:45:10 | 000,358,400 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\BSplayer\Haali media splitter\gdsmux.exe
[2010/08/14 11:42:06 | 000,137,728 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\BSplayer\Haali media splitter\mkv2vfr.exe
[2010/09/30 16:30:22 | 000,042,305 | ---- | M] () -- C:\Users\Martin\AppData\Roaming\BSplayer\Haali media splitter\uninstall.exe
[2014/01/19 01:59:54 | 000,053,248 | R--- | M] (Acresso Software Inc.) -- C:\Users\Martin\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
[2014/02/20 23:38:28 | 000,370,070 | R--- | M] () -- C:\Users\Martin\AppData\Roaming\Microsoft\Installer\{9A781940-AC41-4D5E-8E1E-76A04B916FB9}\_D751D9D775A8FD8178CCB6.exe
[2014/08/27 17:24:24 | 000,119,808 | R--- | M] () -- C:\Users\Martin\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
[2014/04/30 18:26:10 | 001,270,352 | ---- | M] (BitTorrent Inc.) -- C:\Users\Martin\AppData\Roaming\uTorrent\uTorrent.exe
[2013/12/22 03:19:49 | 001,142,864 | ---- | M] (BitTorrent Inc.) -- C:\Users\Martin\AppData\Roaming\uTorrent\updates\3.3.2_30416.exe
[2014/02/08 00:39:34 | 000,905,296 | ---- | M] (BitTorrent Inc.) -- C:\Users\Martin\AppData\Roaming\uTorrent\updates\3.3.2_30488.exe
[2014/04/30 18:26:10 | 001,270,352 | ---- | M] (BitTorrent Inc.) -- C:\Users\Martin\AppData\Roaming\uTorrent\updates\3.4.1_30888.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2014/10/21 09:31:37 | 000,000,018 | ---- | M] () -- C:\WINDOWS\system32\log.txt

< %SYSTEMDRIVE%\*.exe >
[2007/11/07 09:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Google Update" = "C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe" /c -- [2013/12/21 21:57:55 | 000,116,648 | ---- | M] (Google Inc.)
"ISUSPM Startup" = C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup -- [2004/04/17 13:41:30 | 000,196,608 | ---- | M] (InstallShield Software Corporation)
"DAEMON Tools Lite" = "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun -- [2013/10/28 10:29:38 | 003,675,352 | ---- | M] (Disc Soft Ltd)
"Zoner Photo Studio Autoupdate" = C:\PROGRAM FILES\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE -- [2014/03/13 18:11:32 | 000,779,776 | ---- | M] (ZONER software)

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k netsvcs

< >

< type c:\boot.ini >> test.txt /c >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2014/10/21 15:47:15 | 000,000,512 | ---- | M] () MD5=AC3BBA1A98D8EEB7422CAF5F58137E0D -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2012/03/31 01:24:54 | 000,003,556 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS6\configuration\Content\Reference\PHP\CrackF.html
[2014/01/28 00:51:14 | 000,004,041 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\plugins\hoster\CrackedCom.class
[2014/07/09 16:01:38 | 001,099,940 | ---- | M] () -- \Program Files (x86)\TERA\Client\S1Game\CookedPC\Art_Data\Packages\BG\Extension_01\Original\EX01_BlackCrack_OBJ.gpk
[2014/07/09 16:20:36 | 008,695,706 | ---- | M] () -- \Program Files (x86)\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\BlackCrack_BigStone.gpk
[2014/07/09 16:20:34 | 006,332,931 | ---- | M] () -- \Program Files (x86)\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\BlackCrack_BigStone_ANI.gpk
[2014/07/09 16:20:34 | 003,335,217 | ---- | M] () -- \Program Files (x86)\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\BlackCrack_NPC_OBJ.gpk
[2014/07/09 16:20:34 | 000,036,564 | ---- | M] () -- \Program Files (x86)\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\BlackCrack_NPC_OBJ_ANI.gpk
[2014/07/09 16:20:34 | 000,685,163 | ---- | M] () -- \Program Files (x86)\TERA\Client\S1Game\CookedPC\Art_Data\Packages\CH\NPC\NPC_Objects\Black_Crack_Wall.gpk
[2012/03/02 06:24:04 | 001,159,409 | ---- | M] () -- \Program Files\Adobe\Adobe After Effects CS6\Support Files\Presets\Image - Special Effects\Cracked Tiles.ffx
[2012/03/27 02:37:40 | 000,822,440 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS6\Plug-ins\en_US\VSTPlugins\DeCrackler1.dll
[2012/03/27 02:37:42 | 000,822,440 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS6\Plug-ins\en_US\VSTPlugins\DeCrackler2.dll
[2012/03/27 02:37:44 | 000,822,440 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS6\Plug-ins\en_US\VSTPlugins\DeCrackler6.dll
[2012/03/27 02:58:54 | 000,822,440 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS6\Plug-ins\zh_CN\VSTPlugins\DeCrackler1.dll
[2012/03/27 02:58:56 | 000,822,440 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS6\Plug-ins\zh_CN\VSTPlugins\DeCrackler2.dll
[2012/03/27 02:59:00 | 000,822,440 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS6\Plug-ins\zh_CN\VSTPlugins\DeCrackler6.dll
[2014/10/01 15:22:20 | 300,804,094 | ---- | M] () -- \Users\Martin\Documents\5. HRY\G1238\Sherlock Holmes - Crimes And Punishments + Crack.iso

< *keygen* /s >
[2012/03/31 01:24:44 | 000,013,367 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS6\configuration\Content\Reference\HTML\KEYGEN.html
[2012/03/31 01:26:56 | 000,009,211 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS6\configuration\TagLibraries\HTML\keygen.vtm

< *AntiWPA* /s >

< *loader* /s >
[2013/12/28 02:10:53 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Users\Martin\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded\loader.gif.vir
[2013/12/28 02:10:53 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Users\Martin\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square\loader.gif.vir
[2013/12/28 02:10:53 | 000,006,331 | ---- | M] () -- \AdwCleaner\Quarantine\C\Users\Martin\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default\loader.gif.vir
[2013/12/28 02:10:53 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Users\Martin\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\loader.gif.vir
[2013/12/28 02:10:53 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Users\Martin\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_rounded\loader.gif.vir
[2013/12/28 02:10:53 | 000,002,545 | ---- | M] () -- \AdwCleaner\Quarantine\C\Users\Martin\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_square\loader.gif.vir
[2010/08/24 17:23:59 | 000,071,008 | ---- | M] () -- \Program Files (x86)\2K Games\Mafia II\pc\PhysXLoader.dll
[2011/09/05 11:05:04 | 000,012,278 | ---- | M] () -- \Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\WebPublish\BootStrapLoader.swf
[2012/03/13 13:18:28 | 003,297,128 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\Photodownloader.exe
[2012/03/13 11:41:34 | 000,000,860 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\Photodownloader.exe.manifest
[2012/03/13 11:41:58 | 000,011,161 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\bitmaps\main_window\C_LoadError.png
[2012/03/13 11:42:00 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\da_dk\Photodownloader.ini
[2012/03/13 11:42:02 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\de_de\Photodownloader.ini
[2012/03/13 11:42:02 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\en_us\Photodownloader.ini
[2012/03/13 11:42:02 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\es_es\Photodownloader.ini
[2012/03/13 11:42:02 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\fi_fi\Photodownloader.ini
[2012/03/13 11:42:02 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\fr_fr\Photodownloader.ini
[2012/03/13 11:42:02 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\it_it\Photodownloader.ini
[2012/03/13 11:42:04 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\ja_jp\Photodownloader.ini
[2012/03/13 11:42:04 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\ko_kr\Photodownloader.ini
[2012/03/13 11:42:04 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\nl_nl\Photodownloader.ini
[2012/03/13 11:42:04 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\no_no\Photodownloader.ini
[2012/03/13 11:42:04 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\pt_br\Photodownloader.ini
[2012/03/13 11:42:04 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\sv_se\Photodownloader.ini
[2012/03/13 11:42:06 | 000,000,324 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\zh_cn\Photodownloader.ini
[2012/03/13 11:42:06 | 000,000,011 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Bridge CS6\apd\shared_assets\locales\zh_tw\Photodownloader.ini
[2012/03/31 01:26:14 | 000,000,454 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS6\configuration\PhoneGapBuildPlugin\res\loader.htm
[2012/03/31 01:26:42 | 000,037,112 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS6\configuration\Shared\MM\Media\FLVLoader.swf
[2012/03/31 01:27:02 | 000,000,366 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS6\configuration\Third Party Source Code\jquery-mobile\images\ajax-loader.png
[2012/03/30 12:57:02 | 000,000,366 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS6\cs_CZ\Configuration\Third Party Source Code\jquery-mobile\images\ajax-loader.png
[2012/03/30 21:39:20 | 000,000,913 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Fireworks CS6\Configuration\HTML Code\jQuery\preview_browser\css\images\ajax-loader.png
[2012/03/30 21:37:08 | 000,000,913 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Fireworks CS6\First Run\Commands\jQuery\preview_browser\css\images\ajax-loader.png
[2012/03/30 21:37:08 | 000,061,190 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Fireworks CS6\First Run\Common Library\Animations\Loader01.animation.png
[2012/03/30 21:37:10 | 000,312,906 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Fireworks CS6\First Run\Common Library\Animations\Loader02.animation.png
[2012/03/30 21:37:10 | 000,119,812 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Fireworks CS6\First Run\Common Library\Animations\Loader03.animation.png
[2012/03/30 21:37:10 | 000,237,114 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Fireworks CS6\First Run\Common Library\Animations\Loader04.animation.png
[2012/03/16 04:32:56 | 000,000,706 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flash.codemodel.osgi_4.6.1.335153\classes\javax\xml\stream\FactoryFinder$ClassLoaderFinder.class
[2012/03/16 04:32:56 | 000,000,791 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flash.codemodel.osgi_4.6.1.335153\classes\javax\xml\stream\FactoryFinder$ClassLoaderFinderConcrete.class
[2012/03/16 04:34:40 | 000,001,648 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\events\DownloadErrorEvent.as
[2012/03/16 04:34:22 | 000,005,941 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\net\FileDownloader.as
[2012/03/16 04:34:54 | 000,007,791 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\ui\EmbeddedUILoader.as
[2012/03/16 04:35:32 | 000,007,394 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\airframework\src\mx\core\FlexHTMLLoader.as
[2012/03/16 04:35:42 | 000,008,429 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\automation\src\mx\automation\delegates\controls\SWFLoaderAutomationImpl.as
[2012/03/16 04:35:16 | 000,077,955 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\controls\SWFLoader.as
[2012/03/16 04:35:34 | 000,000,766 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\controls\SWFLoader.png
[2012/03/16 04:34:40 | 000,003,290 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\core\FlexLoader.as
[2012/03/16 04:35:18 | 000,002,622 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\core\ISWFLoader.as
[2012/03/16 04:34:58 | 000,005,562 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\core\MovieClipLoaderAsset.as
[2012/03/16 04:34:26 | 000,006,952 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\core\RSLListLoader.as
[2012/03/16 04:35:02 | 000,002,617 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\messaging\config\LoaderConfig.as
[2012/03/16 04:35:00 | 000,013,404 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\modules\ModuleLoader.as
[2012/03/16 04:34:56 | 000,003,534 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\preloaders\IPreloaderDisplay.as
[2012/03/16 04:34:58 | 000,012,861 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\preloaders\Preloader.as
[2012/03/16 04:34:32 | 000,007,131 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\utils\LoaderUtil.as
[2012/03/16 04:34:32 | 000,009,328 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\rpc\src\mx\rpc\wsdl\WSDLLoader.as
[2012/03/16 04:35:04 | 000,008,335 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\rpc\src\mx\rpc\xml\SchemaLoader.as
[2012/03/16 04:35:16 | 000,003,482 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\rpc\src\mx\rpc\xml\XMLLoader.as
[2012/03/16 04:38:32 | 000,001,702 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\events\DownloadErrorEvent.as
[2012/03/16 04:36:46 | 000,006,153 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\net\FileDownloader.as
[2012/03/16 04:37:32 | 000,010,340 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\ui\EmbeddedUILoader.as
[2012/03/16 04:38:22 | 000,012,840 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\airframework\src\mx\core\FlexHTMLLoader.as
[2012/03/16 04:36:40 | 000,009,363 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\automation\src\mx\automation\delegates\controls\SWFLoaderAutomationImpl.as
[2012/03/16 04:37:04 | 000,010,767 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\controls\MovieClipSWFLoader.as
[2012/03/16 04:38:08 | 000,090,491 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\controls\SWFLoader.as
[2012/03/16 04:37:20 | 000,000,766 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\controls\SWFLoader.png
[2012/03/16 04:37:28 | 000,003,762 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\core\FlexLoader.as
[2012/03/16 04:36:14 | 000,003,066 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\core\ISWFLoader.as
[2012/03/16 04:36:36 | 000,006,534 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\core\MovieClipLoaderAsset.as
[2012/03/16 04:38:36 | 000,008,136 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\core\RSLListLoader.as
[2012/03/16 04:37:16 | 000,003,886 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\messaging\config\LoaderConfig.as
[2012/03/16 04:38:52 | 000,004,842 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\preloaders\IPreloaderDisplay.as
[2012/03/16 04:38:36 | 000,021,021 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\preloaders\Preloader.as
[2012/03/16 04:36:10 | 000,024,964 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\utils\LoaderUtil.as
[2012/03/16 04:37:04 | 000,017,374 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\mx\src\mx\modules\ModuleLoader.as
[2012/03/16 04:37:28 | 000,001,308 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\mx\src\mx\modules\ModuleLoader.png
[2012/03/16 04:36:24 | 000,008,511 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\F4MLoader.as
[2012/03/16 04:37:28 | 000,004,465 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\ImageLoader.as
[2012/03/16 04:38:22 | 000,008,773 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\SoundLoader.as
[2012/03/16 04:38:58 | 000,005,733 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\SWFLoader.as
[2012/03/16 04:36:12 | 000,007,015 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\TraitLoader.as
[2012/03/16 04:35:54 | 000,002,829 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\TraitLoaderEvent.as
[2012/03/16 04:38:50 | 000,002,361 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\loaderClasses\LoaderLoadTrait.as
[2012/03/16 04:38:38 | 000,009,822 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\loaderClasses\LoaderUtils.as
[2012/03/16 04:36:50 | 000,004,197 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\events\LoaderEvent.as
[2012/03/16 04:36:16 | 000,005,201 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\media\pluginClasses\DynamicPluginLoader.as
[2012/03/16 04:36:02 | 000,007,943 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\media\pluginClasses\PluginLoader.as
[2012/03/16 04:37:36 | 000,002,706 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\media\pluginClasses\StaticPluginLoader.as
[2012/03/16 04:36:16 | 000,014,266 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\net\NetLoader.as
[2012/03/16 04:38:56 | 000,003,370 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\net\dvr\DVRCastNetLoader.as
[2012/03/16 04:38:00 | 000,005,866 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\net\httpstreaming\HTTPStreamingNetLoader.as
[2012/03/16 04:36:44 | 000,004,594 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\net\rtmpstreaming\RTMPDynamicStreamingNetLoader.as
[2012/03/16 04:38:42 | 000,008,881 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\traits\LoaderBase.as
[2012/03/16 04:36:50 | 000,006,698 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\utils\HTTPLoader.as
[2012/03/16 04:38:38 | 000,010,133 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\rpc\src\mx\rpc\wsdl\WSDLLoader.as
[2012/03/16 04:36:02 | 000,008,711 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\rpc\src\mx\rpc\xml\SchemaLoader.as
[2012/03/16 04:39:06 | 000,004,005 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\rpc\src\mx\rpc\xml\XMLLoader.as
[2012/03/16 04:38:32 | 000,001,762 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\spark\src\spark\core\IContentLoader.as
[2012/03/16 04:39:02 | 000,004,399 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\spark\src\spark\events\LoaderInvalidationEvent.as
[2012/03/16 04:37:04 | 000,023,408 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\spark\src\spark\modules\ModuleLoader.as
[2012/03/16 04:37:20 | 000,001,308 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\spark\src\spark\modules\ModuleLoader.png
[2012/03/16 04:37:10 | 000,001,841 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\samples\themes\cobalt\src\assets\SWFLoader_brokenImageSkin.png
[2012/02/23 01:05:38 | 000,001,702 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\AIR3.2\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\events\DownloadErrorEvent.as
[2012/02/23 01:05:36 | 000,006,153 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\AIR3.2\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\net\FileDownloader.as
[2012/02/23 01:05:38 | 000,010,395 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\AIR3.2\frameworks\projects\air\ApplicationUpdater\src\ApplicationUpdater\air\update\ui\EmbeddedUILoader.as
[2012/03/30 17:19:56 | 000,044,219 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\Configuration\ActionScript 3.0\projects\Flash\src\fl\display\ProLoader.as
[2012/03/30 17:19:56 | 000,027,387 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\Configuration\ActionScript 3.0\projects\Flash\src\fl\display\ProLoaderInfo.as
[2012/03/30 17:19:56 | 000,000,951 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\Configuration\ActionScript 3.0\projects\Flash\src\fl\events\ProLoaderRSLPreloaderSandboxEvent.as
[2012/03/30 17:19:56 | 000,018,626 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\Configuration\ActionScript 3.0\projects\Flash\src\fl\rsl\RSLPreloader.as
[2012/03/30 17:19:56 | 000,010,604 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\Configuration\ActionScript 3.0\rsls\loader_animation.fla
[2012/03/30 17:19:56 | 000,001,253 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\Configuration\ActionScript 3.0\rsls\loader_animation.swf
[2012/03/30 17:19:56 | 000,027,163 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\Configuration\Component Source\ActionScript 3.0\User Interface\fl\containers\UILoader.as
[2012/03/30 17:19:56 | 000,044,966 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\Configuration\Components\User Interface\Loader.swc
[2012/03/30 17:20:02 | 000,000,544 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\First Run\Classes\FP7\MovieClipLoader.as
[2012/03/30 17:20:02 | 000,000,544 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\First Run\Classes\FP8\MovieClipLoader.as
[2012/03/30 17:20:02 | 000,000,576 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\First Run\Classes\FP9\MovieClipLoader.as
[2012/03/30 17:20:02 | 000,010,454 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\First Run\Classes\mx\controls\Loader.as
[2012/03/30 19:25:32 | 000,033,181 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\cs_CZ\Configuration\Templates\Sample Files\Preloader for External File.fla
[2012/03/30 19:25:32 | 000,036,801 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\cs_CZ\Configuration\Templates\Sample Files\Preloader for SWF.fla
[2012/03/28 19:52:50 | 000,008,962 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe InDesign CS6\Presets\multimedia\HTMLLoader\HTMLLoader-app.xml
[2012/03/28 19:52:50 | 000,268,719 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe InDesign CS6\Presets\multimedia\HTMLLoader\HTMLLoader.swf
[2012/03/28 19:52:04 | 000,003,754 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe InDesign CS6\Scripts\converturltohyperlink\startup scripts\ConvertURLToHyperlinkMenuItemLoader.jsx
[2012/03/16 04:49:26 | 000,078,336 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Media Encoder CS6\MXF_SDK_MetaMetadata_BinaryLoader_4.4.3.dll
[2012/03/16 04:49:26 | 000,155,136 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Media Encoder CS6\MXF_SDK_MetaMetadata_XSDLoader2_4.4.3.dll
[2012/03/16 04:49:26 | 000,117,248 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Media Encoder CS6\MXF_SDK_MetaMetadata_XSDLoader_4.4.3.dll
[2012/03/27 06:11:22 | 000,078,336 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Prelude CS6\MXF_SDK_MetaMetadata_BinaryLoader_4.4.3.dll
[2012/03/27 06:11:22 | 000,155,136 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Prelude CS6\MXF_SDK_MetaMetadata_XSDLoader2_4.4.3.dll
[2012/03/27 06:11:22 | 000,117,248 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Prelude CS6\MXF_SDK_MetaMetadata_XSDLoader_4.4.3.dll
[2012/02/23 00:11:56 | 000,078,336 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_BinaryLoader_4.4.3.dll
[2012/02/23 00:11:56 | 000,155,136 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_XSDLoader2_4.4.3.dll
[2012/02/23 00:11:56 | 000,117,248 | ---- | M] () -- \Program Files (x86)\Common Files\Adobe\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_XSDLoader_4.4.3.dll
[2013/04/21 22:44:16 | 000,008,827 | ---- | M] () -- \Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit.resources\inspector\HeapSnapshotLoader.js
[2014/01/23 16:00:46 | 000,268,440 | ---- | M] () -- \Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOLoader.dll
[2013/05/09 02:40:52 | 000,019,080 | ---- | M] () -- \Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2014/04/03 12:17:48 | 000,192,896 | ---- | M] () -- \Program Files (x86)\GameforgeLive\MultiHTTPDownloader.exe
[2014/10/05 14:58:04 | 001,738,240 | ---- | M] () -- \Program Files (x86)\Glyph\GlyphDownloader.exe
[2013/02/01 01:16:50 | 000,065,344 | R--- | M] () -- \Program Files (x86)\Hi-Rez Studios\HiRezGames\smite\Binaries\Win32\PhysXLoader.dll
[2011/08/31 19:24:50 | 000,064,280 | ---- | M] () -- \Program Files (x86)\In Verbis Virtus\Binaries\Win32\PhysXLoader.dll
[2012/05/22 09:43:16 | 000,214,528 | ---- | M] () -- \Program Files (x86)\JDownloader\JDownloader.exe
[2012/05/22 09:43:16 | 000,593,293 | ---- | M] () -- \Program Files (x86)\JDownloader\JDownloader.jar
[2012/05/22 09:43:16 | 000,218,816 | ---- | M] () -- \Program Files (x86)\JDownloader\JDownloaderBETA.exe
[2012/05/22 09:43:16 | 000,218,816 | ---- | M] () -- \Program Files (x86)\JDownloader\JDownloaderD3D.exe
[2012/05/22 09:43:16 | 000,219,264 | ---- | M] () -- \Program Files (x86)\JDownloader\JDownloaderPortable.exe
[2014/01/03 20:02:37 | 000,000,101 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\img\hosterlogos\exclusiveloader.com.png
[2013/12/28 02:11:13 | 000,000,105 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\img\hosterlogos\uploader.pl.png
[2014/07/02 21:15:18 | 000,004,156 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\plugins\hoster\BigDownloaderCom.class
[2013/12/28 02:14:45 | 000,011,071 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\plugins\hoster\MyDownloaderNet.class
[2013/12/28 02:14:22 | 000,004,584 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\plugins\hoster\OmpLoaderOrg.class
[2014/01/28 00:50:51 | 000,003,882 | ---- | M] () -- \Program Files (x86)\JDownloader\jd\plugins\hoster\UploaderJp.class
[2012/05/22 09:43:16 | 000,032,222 | ---- | M] () -- \Program Files (x86)\JDownloader\licenses\jdownloader.license
[2012/05/26 03:47:16 | 000,126,064 | ---- | M] () -- \Program Files (x86)\Lenovo\PowerDVD10\PK\Koan\pyloader.dll
[2012/05/26 03:47:16 | 000,028,238 | ---- | M] () -- \Program Files (x86)\Lenovo\PowerDVD10\PK\subsys\PyImpLoader\PyImpLoader.kc
[2012/05/26 03:47:16 | 000,121,968 | ---- | M] () -- \Program Files (x86)\Lenovo\PowerDVD10\PK\subsys\PyImpLoader\_PyImpLoader.pyd
[2012/05/18 08:15:48 | 000,010,781 | ---- | M] () -- \Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\mm\MediaCtrl\ImageLoader.kc
[2012/05/18 08:15:50 | 000,003,492 | ---- | M] () -- \Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\widget\langloader.kc
[2012/05/18 08:15:50 | 000,013,453 | ---- | M] () -- \Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\widget\layoutloader.kc
[2012/08/01 03:15:46 | 000,010,775 | ---- | M] () -- \Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cox\mm\MediaCtrl\ImageLoader.kc
[2012/08/01 03:15:48 | 000,003,567 | ---- | M] () -- \Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cox\widget\langloader.kc
[2012/08/01 03:15:48 | 000,013,369 | ---- | M] () -- \Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cox\widget\layoutloader.kc
[2012/08/03 20:36:42 | 000,127,504 | ---- | M] () -- \Program Files (x86)\Lenovo\YouCam\Koan\pyloader.dll
[2012/07/27 21:52:42 | 000,020,119 | ---- | M] () -- \Program Files (x86)\Lenovo\YouCam\subsys\Uploader\PyUploader.kc
[2012/07/27 21:52:42 | 000,232,560 | ---- | M] () -- \Program Files (x86)\Lenovo\YouCam\subsys\Uploader\_PyUploader.pyd
[2012/07/24 20:28:46 | 000,167,720 | ---- | M] () -- \Program Files (x86)\Lenovo\YouCam\subsys\YouCam\CES_3DLoaderC3S.dll
[2012/07/24 20:28:46 | 002,525,480 | ---- | M] () -- \Program Files (x86)\Lenovo\YouCam\subsys\YouCam\CES_3DLoaderFBX.dll
[2013/10/11 15:56:11 | 000,000,483 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\enterprise\config\Modules\org-netbeans-modules-j2ee-ddloaders.xml
[2014/01/19 15:05:29 | 003,317,974 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\enterprise\modules\org-netbeans-modules-j2ee-ddloaders.jar
[2014/01/19 15:05:21 | 000,033,148 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\enterprise\modules\locale\org-netbeans-modules-j2ee-ddloaders_ja.jar
[2014/01/19 15:05:18 | 000,030,704 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\enterprise\modules\locale\org-netbeans-modules-j2ee-ddloaders_pt_BR.jar
[2014/01/19 15:05:20 | 000,035,753 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\enterprise\modules\locale\org-netbeans-modules-j2ee-ddloaders_ru.jar
[2014/01/19 15:05:18 | 000,031,757 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\enterprise\modules\locale\org-netbeans-modules-j2ee-ddloaders_zh_CN.jar
[2014/01/19 15:06:00 | 000,000,829 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\enterprise\update_tracking\org-netbeans-modules-j2ee-ddloaders.xml
[2013/10/11 15:56:11 | 000,002,941 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\platform\config\ModuleAutoDeps\org-openide-loaders.xml
[2013/10/11 15:56:11 | 000,000,411 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\platform\config\Modules\org-openide-loaders.xml
[2014/01/19 15:02:44 | 001,421,800 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\platform\modules\org-openide-loaders.jar
[2014/01/19 15:02:36 | 000,007,125 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\platform\modules\locale\org-openide-loaders_ja.jar
[2014/01/19 15:02:34 | 000,006,534 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\platform\modules\locale\org-openide-loaders_pt_BR.jar
[2014/01/19 15:02:36 | 000,007,647 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\platform\modules\locale\org-openide-loaders_ru.jar
[2014/01/19 15:02:35 | 000,006,730 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\platform\modules\locale\org-openide-loaders_zh_CN.jar
[2014/01/19 15:03:58 | 000,000,801 | ---- | M] () -- \Program Files (x86)\NetBeans 7.4\platform\update_tracking\org-openide-loaders.xml
[2014/10/04 08:43:23 | 001,172,288 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\ExtensionLoader.dll
[2014/06/10 16:42:34 | 000,065,344 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader.dll
[2014/06/10 16:42:34 | 000,067,904 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXLoader64.dll
[2014/06/10 16:42:30 | 000,070,464 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXUpdateLoader.dll
[2014/06/10 16:42:30 | 000,085,312 | ---- | M] () -- \Program Files (x86)\NVIDIA Corporation\PhysX\Common\PhysXUpdateLoader64.dll
[2014/01/27 12:54:24 | 000,000,404 | ---- | M] () -- \Program Files (x86)\Riot Games\League of Legemds\RADS\projects\lol_air_client\releases\0.0.1.101\deploy\assets\storeImages\layout\small_loader.gif
[1999/12/12 01:00:00 | 000,076,120 | ---- | M] () -- \Program Files (x86)\Sherlock Holmes Crimes and Punishments\Binaries\Win32\PhysXLoader.dll
[2013/10/23 22:07:40 | 000,007,825 | ---- | M] () -- \Program Files (x86)\Steam\remoteui\static\libs\images\ajax-loader.gif
[2014/03/22 23:25:49 | 000,061,720 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Dungeon Defenders\Binaries\Win32\PhysXLocal\PhysXLoader.dll
[2014/06/30 14:15:03 | 000,064,280 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\Binaries\Win32\PhysXLoader.dll
[2014/06/30 14:15:00 | 000,067,864 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\Binaries\Win64\PhysXLoader64.dll
[2014/06/30 17:18:49 | 000,064,280 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\CDW\Binaries\Win32\PhysXLoader.dll
[2014/06/30 17:19:26 | 000,067,864 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\CDW\Binaries\Win64\PhysXLoader64.dll
[2014/06/30 18:10:28 | 000,008,042 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\CDW\Development\Src\IpDrv\classes\OnlineImageDownloaderWeb.uc
[2014/08/17 16:51:58 | 000,021,856 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\CDW\Development\Src\UDKBase\classes\GameplayEventsAnalyticsUploader.uc
[2014/06/30 18:10:29 | 000,002,630 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\CDW\Development\Src\UnrealEd\classes\GameStatsDBUploader.uc
[2014/07/23 12:47:20 | 000,003,808 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\Development\Src\AOC\Flash\FLA\Frontend\AS Classes\CharacterUILoader.as
[2014/07/23 12:47:20 | 000,000,900 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\Development\Src\AOC\Flash\FLA\Frontend\AS Classes\TBSUILoader.as
[2014/06/30 14:15:35 | 000,008,042 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\Development\Src\IpDrv\classes\OnlineImageDownloaderWeb.uc
[2014/06/30 14:16:50 | 000,021,856 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\Development\Src\UDKBase\classes\GameplayEventsAnalyticsUploader.uc
[2014/06/30 14:16:51 | 000,002,630 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\Development\Src\UnrealEd\classes\GameStatsDBUploader.uc
[2014/07/24 17:03:34 | 000,064,280 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\nosgoth\Binaries\Win32\PhysXLoader.dll
[2014/06/21 20:40:09 | 000,064,352 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Trine 2\PhysXLoader.dll
[2014/06/21 20:23:45 | 000,066,912 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Trine 2\PhysXLoader64.dll
[2014/07/09 15:31:02 | 000,068,688 | ---- | M] () -- \Program Files (x86)\TERA\Client\Binaries\PhysXLoader.dll
[2013/06/23 21:49:46 | 000,134,144 | ---- | M] () -- \Program Files (x86)\The Elder Scrolls V Skyrim\skse_loader.exe
[2013/06/23 21:49:44 | 000,116,224 | ---- | M] () -- \Program Files (x86)\The Elder Scrolls V Skyrim\skse_steam_loader.dll
[2014/03/21 00:04:59 | 000,419,232 | ---- | M] () -- \Program Files (x86)\Ubisoft\Assassin's Creed IV Black Flag\uplay_r1_loader.dll
[2014/08/27 14:36:38 | 000,439,096 | ---- | M] () -- \Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\The Crew (Beta)\uplay_r1_loader.dll
[2012/03/13 13:10:54 | 003,297,128 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\Photodownloader.exe
[2012/03/13 11:42:26 | 000,011,161 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\bitmaps\main_window\C_LoadError.png
[2012/03/13 11:42:28 | 000,011,161 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\combined_bitmaps\main_window\C_LoadError.png
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\da_dk\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\de_de\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\en_us\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\es_es\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\fi_fi\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\fr_fr\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\it_it\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\ja_jp\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\ko_kr\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\nl_nl\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\no_no\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\pt_br\Photodownloader.ini
[2012/03/13 11:42:28 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\sv_se\Photodownloader.ini
[2012/03/13 11:42:30 | 000,000,324 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\zh_cn\Photodownloader.ini
[2012/03/13 11:42:30 | 000,000,011 | ---- | M] () -- \Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\photodownloader\apd\shared_assets\locales\zh_tw\Photodownloader.ini
[2012/03/27 04:04:08 | 000,121,504 | ---- | M] () -- \Program Files\Adobe\Adobe Encore CS6\MXF_SDK_MetaMetadata_BinaryLoader_4.4.3.dll
[2012/03/27 04:04:18 | 000,231,072 | ---- | M] () -- \Program Files\Adobe\Adobe Encore CS6\MXF_SDK_MetaMetadata_XSDLoader2_4.4.3.dll
[2012/03/27 04:04:30 | 000,169,632 | ---- | M] () -- \Program Files\Adobe\Adobe Encore CS6\MXF_SDK_MetaMetadata_XSDLoader_4.4.3.dll
[2012/03/16 01:17:30 | 000,115,712 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS6\MXF_SDK_MetaMetadata_BinaryLoader_4.4.3.dll
[2012/03/16 01:17:30 | 000,225,280 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS6\MXF_SDK_MetaMetadata_XSDLoader2_4.4.3.dll
[2012/03/16 01:17:30 | 000,163,840 | ---- | M] () -- \Program Files\Adobe\Adobe Media Encoder CS6\MXF_SDK_MetaMetadata_XSDLoader_4.4.3.dll
[2013/12/02 17:33:02 | 000,099,328 | ---- | M] () -- \Program Files\Adobe\Adobe Photoshop Lightroom 5.3\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_BinaryLoader_4.4.22.dll
[2013/12/02 17:33:02 | 000,196,608 | ---- | M] () -- \Program Files\Adobe\Adobe Photoshop Lightroom 5.3\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_XSDLoader2_4.4.22.dll
[2013/12/02 17:33:02 | 000,148,480 | ---- | M] () -- \Program Files\Adobe\Adobe Photoshop Lightroom 5.3\Support\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\MXF_SDK_MetaMetadata_XSDLoader_4.4.22.dll
[2012/03/26 23:19:56 | 000,115,712 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS6\MXF_SDK_MetaMetadata_BinaryLoader_4.4.3.dll
[2012/03/26 23:19:56 | 000,225,280 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS6\MXF_SDK_MetaMetadata_XSDLoader2_4.4.3.dll
[2012/03/26 23:19:56 | 000,163,840 | ---- | M] () -- \Program Files\Adobe\Adobe Premiere Pro CS6\MXF_SDK_MetaMetadata_XSDLoader_4.4.3.dll
[2014/08/02 17:43:17 | 000,071,968 | ---- | M] () -- \Program Files\AVAST Software\Avast\aswWrcIELoader32.exe
[2014/08/02 17:43:17 | 000,085,376 | ---- | M] () -- \Program Files\AVAST Software\Avast\aswWrcIELoader64.exe
[2014/01/23 16:00:46 | 000,364,184 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2013/05/09 02:45:06 | 000,019,080 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2014/01/19 14:59:13 | 000,000,948 | ---- | M] () -- \Program Files\Java\jdk1.7.0_51\lib\visualvm\platform\config\ModuleAutoDeps\org-openide-loaders.xml
[2014/01/19 14:59:13 | 000,000,411 | ---- | M] () -- \Program Files\Java\jdk1.7.0_51\lib\visualvm\platform\config\Modules\org-openide-loaders.xml
[2014/01/19 14:59:15 | 001,183,660 | ---- | M] () -- \Program Files\Java\jdk1.7.0_51\lib\visualvm\platform\modules\org-openide-loaders.jar
[2014/01/19 14:59:15 | 000,006,274 | ---- | M] () -- \Program Files\Java\jdk1.7.0_51\lib\visualvm\platform\modules\locale\org-openide-loaders_ja.jar
[2014/01/19 14:59:15 | 000,005,853 | ---- | M] () -- \Program Files\Java\jdk1.7.0_51\lib\visualvm\platform\modules\locale\org-openide-loaders_zh_CN.jar
[2014/01/19 14:59:17 | 000,000,457 | ---- | M] () -- \Program Files\Java\jdk1.7.0_51\lib\visualvm\platform\update_tracking\org-openide-loaders.xml
[2014/02/05 11:31:23 | 001,169,184 | ---- | M] () -- \Program Files\NVIDIA Corporation\Installer2\Display.GFExperience.{18619B52-C076-4285-B5E6-E1C1360386F2}\ExtensionLoader.dll
[2014/02/18 23:18:01 | 000,000,856 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.212_x64__8wekyb3d8bbwe\js\HtmlFileLoader.js
[2013/11/14 14:26:50 | 000,001,160 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\modernpeople\appframe\backgroundloader.js
[2013/11/14 14:26:50 | 000,004,996 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\modernshareanything\sharedataloader.js
[2013/11/14 14:26:50 | 000,002,125 | ---- | M] () -- \Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\modernsharetarget\sharemaildataloader.js
[2013/11/14 14:29:10 | 000,043,128 | ---- | M] () -- \Program Files\WindowsApps\Microsoft.XboxLIVEGames_2.0.139.0_x64__8wekyb3d8bbwe\Framework\imageLoader.js
[2013/12/01 15:09:05 | 000,061,528 | ---- | M] () -- \Program Files\WinRAR\Formats\ace32loader.exe
[2013/03/05 11:11:10 | 000,432,128 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Facebook\ZPSFacebookUploader.exe
[2010/04/29 15:12:40 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Facebook\ZPSPluginLoader.exe
[2013/02/06 17:42:00 | 000,323,584 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Facebook\en\ZPSFacebookUploader.resources.dll
[2013/03/05 14:03:44 | 000,443,904 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Flickr\ZPSFlickrUploader.exe
[2010/04/29 15:12:42 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Flickr\ZPSPluginLoader.exe
[2011/12/06 14:06:40 | 000,323,584 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Flickr\en\ZPSFlickrUploader.resources.dll
[2013/03/05 13:34:20 | 000,192,512 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Picasa\ZPSPicasaUploader.exe
[2010/04/29 15:12:40 | 000,053,640 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Picasa\ZPSPluginLoader.exe
[2013/02/06 17:20:12 | 000,323,584 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Plugins\Picasa\en\ZPSPicasaUploader.resources.dll
[2014/03/13 18:11:18 | 000,103,936 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Program32\8bfLoader.exe
[2014/03/13 18:11:24 | 000,017,920 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Program32\WICLoader.exe
[2014/03/13 18:12:08 | 000,020,480 | ---- | M] () -- \Program Files\Zoner\Photo Studio 15\Program64\WICLoader.exe
[2013/12/28 02:10:05 | 000,001,951 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2013/12/28 02:10:05 | 000,002,028 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2013/12/28 02:10:05 | 000,001,951 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2013/12/28 02:10:05 | 000,002,028 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2014/04/04 18:45:24 | 000,001,056 | ---- | M] () -- \Users\Martin\AppData\Local\MRDownloader.nast
[2012/03/30 17:20:02 | 000,000,544 | ---- | M] () -- \Users\Martin\AppData\Local\Adobe\Flash CS6\cs_CZ\Configuration\Classes\FP7\MovieClipLoader.as
[2012/03/30 17:20:02 | 000,000,544 | ---- | M] () -- \Users\Martin\AppData\Local\Adobe\Flash CS6\cs_CZ\Configuration\Classes\FP8\MovieClipLoader.as
[2012/03/30 17:20:02 | 000,000,576 | ---- | M] () -- \Users\Martin\AppData\Local\Adobe\Flash CS6\cs_CZ\Configuration\Classes\FP9\MovieClipLoader.as
[2012/03/30 17:20:02 | 000,010,454 | ---- | M] () -- \Users\Martin\AppData\Local\Adobe\Flash CS6\cs_CZ\Configuration\Classes\mx\controls\Loader.as
[2014/08/13 13:14:30 | 000,009,418 | ---- | M] () -- \Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.10.3_0\img\gifloader.gif
[2012/12/25 16:58:32 | 000,004,273 | ---- | M] () -- \Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp\5.2.4_0\icons\loader-big.gif
[2012/12/25 16:58:32 | 000,003,832 | ---- | M] () -- \Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp\5.2.4_0\icons\loader-darkgray.gif
[2012/12/25 16:58:32 | 000,003,831 | ---- | M] () -- \Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp\5.2.4_0\icons\loader-gray.gif
[2013/03/17 22:33:00 | 000,006,116 | ---- | M] () -- \Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp\5.2.4_0\icons\loader-gray_2x.gif
[2013/03/17 22:33:00 | 000,001,030 | ---- | M] () -- \Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp\5.2.4_0\reader\feedloader.js
[2013/01/03 16:06:30 | 000,000,465 | ---- | M] () -- \Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp\5.2.4_0\reader\parser\googleloader.js
[2013/03/17 22:33:00 | 000,000,352 | ---- | M] () -- \Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp\5.2.4_0\reader\parser\onlineloader.js
[2012/12/25 16:58:32 | 000,000,042 | ---- | M] () -- \Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp\5.2.4_0\reader\parser\rssloader.js
[2014/04/13 21:36:38 | 000,002,848 | ---- | M] () -- \Users\Martin\AppData\Local\NetBeans\Cache\7.4\index\s128\java\14\classes\c05_stepanek_martin\Img32Loader.sig
[2014/04/13 14:11:03 | 000,002,961 | ---- | M] () -- \Users\Martin\AppData\Local\NetBeans\Cache\7.4\index\s150\java\14\classes\Img32Loader.sig
[2014/04/13 20:31:04 | 000,002,848 | ---- | M] () -- \Users\Martin\AppData\Local\NetBeans\Cache\7.4\index\s200\java\14\classes\c05_stepanek_martin\Img32Loader.sig
[2014/07/01 11:46:16 | 000,072,638 | ---- | M] () -- \Users\Martin\AppData\Local\Skype\Apps\login\images\loader.gif
[2014/07/01 11:46:16 | 000,003,032 | ---- | M] () -- \Users\Martin\AppData\Local\Skype\Apps\login\images\loader.png
[2014/07/01 11:46:16 | 000,006,012 | ---- | M] () -- \Users\Martin\AppData\Local\Skype\Apps\login\images\normal\loader_15fps.gif
[2014/07/01 11:46:16 | 000,021,956 | ---- | M] () -- \Users\Martin\AppData\Local\Skype\Apps\login\images\normal\loader_30fps.gif
[2014/07/01 11:46:16 | 000,009,772 | ---- | M] () -- \Users\Martin\AppData\Local\Skype\Apps\login\images\retina\loader@2x.png
[2013/12/28 02:10:12 | 000,002,028 | ---- | M] () -- \Users\Martin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\JDownloader.lnk
[2013/03/25 17:21:00 | 000,388,776 | ---- | M] () -- \Users\Martin\AppData\Roaming\TERA\launcher\live\downloader.bundle
[2013/03/20 08:02:00 | 000,694,656 | ---- | M] () -- \Users\Martin\AppData\Roaming\TERA\launcher\live\downloader.dll
[2014/01/10 05:42:12 | 000,112,132 | ---- | M] () -- \Users\Martin\Documents\3. MOBIL\cxq_v3_inew_v1.0.3\cxq_v3_inew_v1.0.3\preloader_eastaeon82_wet_16_jb5.bin
[2014/01/17 06:37:36 | 000,112,124 | ---- | M] () -- \Users\Martin\Documents\3. MOBIL\cxq_v3_inew_v1.0.4_SP_flash\preloader_eastaeon82_wet_16_jb5.bin
[2014/05/07 10:49:00 | 000,003,297 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-jee-kepler-SR2-win32-x86_64\eclipse\configuration\org.eclipse.osgi\bundles\525\1\.cp\org\eclipse\m2e\core\ui\internal\wizards\MavenProjectWizardArchetypeParametersPage$RequiredPropertiesLoader.class
[2014/04/12 19:16:44 | 000,000,718 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-standard-kepler-SR1-win32\eclipse\configuration\org.eclipse.osgi\bundles\208\1\.cp\org\eclipse\swt\graphics\ImageDataLoader.class
[2014/04/12 19:16:44 | 000,003,437 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-standard-kepler-SR1-win32\eclipse\configuration\org.eclipse.osgi\bundles\208\1\.cp\org\eclipse\swt\graphics\ImageLoader.class
[2014/04/12 19:16:44 | 000,001,355 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-standard-kepler-SR1-win32\eclipse\configuration\org.eclipse.osgi\bundles\208\1\.cp\org\eclipse\swt\graphics\ImageLoaderEvent.class
[2014/04/12 19:16:44 | 000,000,268 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-standard-kepler-SR1-win32\eclipse\configuration\org.eclipse.osgi\bundles\208\1\.cp\org\eclipse\swt\graphics\ImageLoaderListener.class
[2013/01/17 10:11:26 | 000,000,948 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\jdk\lib\visualvm\platform\config\ModuleAutoDeps\org-openide-loaders.xml
[2013/01/17 10:11:26 | 000,000,411 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\jdk\lib\visualvm\platform\config\Modules\org-openide-loaders.xml
[2013/01/17 10:11:26 | 001,183,660 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\jdk\lib\visualvm\platform\modules\org-openide-loaders.jar
[2013/01/17 10:14:02 | 000,006,274 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\jdk\lib\visualvm\platform\modules\locale\org-openide-loaders_ja.jar
[2013/01/17 10:14:02 | 000,005,853 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\jdk\lib\visualvm\platform\modules\locale\org-openide-loaders_zh_CN.jar
[2013/01/17 10:11:26 | 000,000,457 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\jdk\lib\visualvm\platform\update_tracking\org-openide-loaders.xml
[2014/02/07 14:59:46 | 000,002,941 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\config\ModuleAutoDeps\org-openide-loaders.xml
[2014/02/07 14:59:46 | 000,000,411 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\config\Modules\org-openide-loaders.xml
[2014/02/07 14:59:46 | 001,403,749 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\modules\org-openide-loaders.jar
[2014/02/07 14:59:46 | 000,006,542 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\modules\locale\org-openide-loaders_de.jar
[2014/02/07 14:59:46 | 000,006,456 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\modules\locale\org-openide-loaders_es.jar
[2014/02/07 14:59:46 | 000,006,597 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\modules\locale\org-openide-loaders_fr.jar
[2014/02/07 14:59:46 | 000,006,410 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\modules\locale\org-openide-loaders_it.jar
[2014/02/07 14:59:46 | 000,007,129 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\modules\locale\org-openide-loaders_ja.jar
[2014/02/07 14:59:46 | 000,006,915 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\modules\locale\org-openide-loaders_ko.jar
[2014/02/07 14:59:46 | 000,006,538 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\modules\locale\org-openide-loaders_pt_BR.jar
[2014/02/07 14:59:46 | 000,006,734 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\modules\locale\org-openide-loaders_zh_CN.jar
[2014/02/07 14:59:46 | 000,005,829 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\modules\locale\org-openide-loaders_zh_TW.jar
[2014/02/07 14:59:46 | 000,001,195 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\netbeans\platform\update_tracking\org-openide-loaders.xml
[2014/04/13 20:31:05 | 000,002,848 | ---- | M] () -- \Users\Martin\Documents\JAVA\c05_stepanek_martin_PGRF2\build\classes\c05_stepanek_martin\Img32Loader.class
[2014/04/13 20:31:04 | 000,002,266 | ---- | M] () -- \Users\Martin\Documents\JAVA\c05_stepanek_martin_PGRF2\src\c05_stepanek_martin\Img32Loader.java
[2014/04/13 14:11:01 | 000,002,961 | ---- | M] () -- \Users\Martin\Documents\JAVA\Komprese\build\classes\Img32Loader.class
[2014/04/13 14:10:57 | 000,002,556 | ---- | M] () -- \Users\Martin\Documents\JAVA\Komprese\src\Img32Loader.java
[2012/12/05 07:30:36 | 000,010,540 | ---- | M] () -- \Users\Martin\Documents\JAVA\lwjgl-X.X\src\java\org\lwjgl\examples\spaceinvaders\TextureLoader.java
[2012/12/05 07:30:36 | 000,002,423 | ---- | M] () -- \Users\Martin\Documents\JAVA\lwjgl-X.X\src\java\org\lwjgl\test\applet\AppletLoaderTest.java
[2012/12/18 12:50:30 | 000,006,976 | ---- | M] () -- \Users\Martin\Documents\JAVA\lwjgl-X.X\src\java\org\lwjgl\test\opengl\multithread\BackgroundLoader.java
[2013/12/02 20:52:18 | 000,068,898 | ---- | M] () -- \Users\Martin\Documents\JAVA\lwjgl-X.X\src\java\org\lwjgl\util\applet\AppletLoader.java
[2012/12/05 07:30:38 | 000,006,903 | ---- | M] () -- \Users\Martin\Documents\JAVA\lwjgl-X.X\src\java\org\lwjgl\util\mapped\MappedObjectClassLoader.java
[2014/10/05 14:00:59 | 000,000,948 | ---- | M] () -- \Users\Martin\Documents\My Games\Skyrim\SKSE\skse_loader.log
[2014/02/06 23:26:18 | 000,000,948 | ---- | M] () -- \Users\Martin\Documents\My Games\Skyrim\SKSE\skse_loader.log0
[2012/04/16 22:56:19 | 005,401,737 | ---- | M] () -- \Users\Martin\Music\Toploader - Dancing in The Moonlight.mp3
[2012/04/16 22:56:19 | 005,401,737 | ---- | M] () -- \Users\Martin\Music\Florbálko music\Toploader - Dancing in The Moonlight.mp3
[2014/04/13 20:31:04 | 000,002,266 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\1. ŠKOLA\PGRF\Komprese projekt\c05_stepanek_martin\c05_stepanek_martin\src\c05_stepanek_martin\Img32Loader.java
[2014/03/29 14:20:14 | 000,032,737 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\1. ŠKOLA\PSIT\Cisco\DIR příkaz - konfigurace switche skrz BOOT LOADER.PNG
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\loader.gif
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\dark_rounded\loader.gif
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\dark_square\loader.gif
[2013/07/29 00:00:00 | 000,006,331 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\default\loader.gif
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\facebook\loader.gif
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\light_rounded\loader.gif
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\light_square\loader.gif
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\loader.gif
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\dark_rounded\loader.gif
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\dark_square\loader.gif
[2013/07/29 00:00:00 | 000,006,331 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\default\loader.gif
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\facebook\loader.gif
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\light_rounded\loader.gif
[2013/07/29 00:00:00 | 000,002,545 | ---- | M] () -- \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\light_square\loader.gif
[2014/04/20 18:26:03 | 000,015,872 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.O29577370#\4b0d7ec436be34964809a1dd04215f49\Microsoft.Office.InfoPath.CLRLoader.ni.dll
[2014/04/20 18:26:03 | 000,000,696 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.O29577370#\4b0d7ec436be34964809a1dd04215f49\Microsoft.Office.InfoPath.CLRLoader.ni.dll.aux
[2012/10/01 21:47:24 | 000,019,048 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005109A20000000100000000F01FEC\15.0.4420\FL_VSTOLoaderUI_dll_amd64_ln.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2012/10/01 21:47:24 | 000,019,048 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005109A20000000100000000F01FEC\15.0.4420\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2012/10/01 21:47:24 | 000,364,128 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005109A20000000100000000F01FEC\15.0.4420\VSTOLoader_dll_amd64.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2012/10/01 21:47:24 | 000,268,384 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005109A20000000100000000F01FEC\15.0.4420\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2013/05/09 02:45:06 | 000,019,080 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005109A20000000100000000F01FEC\15.0.4569\FL_VSTOLoaderUI_dll_amd64_ln.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2013/05/09 02:40:52 | 000,019,080 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005109A20000000100000000F01FEC\15.0.4569\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2012/10/01 21:47:24 | 000,019,048 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005119110000000000000000F01FEC\15.0.4420\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2013/05/09 02:40:52 | 000,268,440 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005119110000000000000000F01FEC\15.0.4420\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8.41B86362_9D8B_4D9B_B426_8A6D1F809A25
[2012/10/01 21:47:24 | 000,268,384 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005119110000000000000000F01FEC\15.0.4420\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2013/05/09 02:40:52 | 000,019,080 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005119110000000000000000F01FEC\15.0.4569\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2014/01/23 16:00:46 | 000,268,440 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005119110000000000000000F01FEC\15.0.4569\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2014/01/02 22:59:09 | 000,015,528 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Office.InfoPath.CLRLoader\v4.0_15.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.CLRLoader.dll
[2014/10/05 14:00:59 | 000,025,684 | ---- | M] () -- \Windows\Prefetch\SKSE_LOADER.EXE-7C6E5D20.pf
[2013/08/22 06:17:27 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/22 06:17:25 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-1.dll
[2013/08/22 06:17:24 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-2-0.dll
[2013/08/22 06:17:20 | 000,002,560 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-private-l1-1-0.dll
[2013/08/22 06:17:34 | 000,002,560 | -H-- | M] () -- \Windows\System32\api-ms-win-core-stringloader-l1-1-0.dll
[2013/08/22 06:17:33 | 000,002,560 | -H-- | M] () -- \Windows\System32\api-ms-win-core-stringloader-l1-1-1.dll
[2013/08/22 05:55:19 | 000,036,352 | ---- | M] () -- \Windows\System32\dmloader.dll
[2013/08/22 15:25:39 | 000,003,584 | ---- | M] () -- \Windows\System32\downlevel\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/22 15:25:39 | 000,003,072 | ---- | M] () -- \Windows\System32\downlevel\api-ms-win-core-libraryloader-l1-1-1.dll
[2013/08/22 15:25:38 | 000,002,560 | ---- | M] () -- \Windows\System32\downlevel\api-ms-win-core-stringloader-l1-1-1.dll
[2013/08/22 06:17:27 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/22 06:17:25 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-1.dll
[2013/08/22 06:17:24 | 000,003,584 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-l1-2-0.dll
[2013/08/22 06:17:20 | 000,002,560 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-libraryloader-private-l1-1-0.dll
[2013/08/22 06:17:34 | 000,002,560 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-stringloader-l1-1-0.dll
[2013/08/22 06:17:33 | 000,002,560 | -H-- | M] () -- \Windows\SysWOW64\api-ms-win-core-stringloader-l1-1-1.dll
[2013/08/22 05:55:19 | 000,036,352 | ---- | M] () -- \Windows\SysWOW64\dmloader.dll
[2013/08/22 15:25:39 | 000,003,584 | ---- | M] () -- \Windows\SysWOW64\downlevel\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/22 15:25:39 | 000,003,072 | ---- | M] () -- \Windows\SysWOW64\downlevel\api-ms-win-core-libraryloader-l1-1-1.dll
[2013/08/22 15:25:38 | 000,002,560 | ---- | M] () -- \Windows\SysWOW64\downlevel\api-ms-win-core-stringloader-l1-1-1.dll
[2014/04/26 15:04:45 | 000,592,677 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.16384_none_210fb36c397c4e2b\hvloader.efi
[2014/04/26 15:04:44 | 000,536,051 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.16384_none_210fb36c397c4e2b\hvloader.exe
[2014/04/26 15:04:50 | 000,598,463 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.17031_none_2142a5b03956989d\hvloader.efi
[2014/04/26 15:04:49 | 000,542,292 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.17031_none_2142a5b03956989d\hvloader.exe
[2014/04/26 15:04:57 | 000,598,454 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.17039_none_214aa800394f6355\hvloader.efi
[2014/04/26 15:04:55 | 000,542,288 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.17039_none_214aa800394f6355\hvloader.exe
[2013/08/22 13:21:30 | 000,046,592 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.3.9600.16384_none_36b27bfc6399d5ce\dmloader.dll
[2013/08/22 15:25:37 | 000,003,584 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_b8233abb5511544f\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/22 15:25:37 | 000,003,072 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_b8233abb5511544f\api-ms-win-core-libraryloader-l1-1-1.dll
[2013/08/22 15:25:36 | 000,002,560 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_b8233abb5511544f\api-ms-win-core-stringloader-l1-1-1.dll
[2013/08/22 13:45:31 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/22 13:45:33 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-libraryloader-l1-1-1.dll
[2013/08/22 13:45:35 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-libraryloader-l1-2-0.dll
[2013/08/22 13:45:30 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-libraryloader-private-l1-1-0.dll
[2013/08/22 13:45:40 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-stringloader-l1-1-0.dll
[2013/08/22 13:45:44 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_fb7050014fc6f9b0\api-ms-win-core-stringloader-l1-1-1.dll
[2014/04/18 18:11:34 | 000,000,465 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb.manifest
[2014/04/26 16:04:43 | 000,009,588 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb_winload.efi.mui_35ee487d
[2014/04/26 16:04:43 | 000,009,604 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb_winload.exe.mui_3bc5b827
[2014/04/26 16:04:43 | 000,007,885 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb_winresume.efi.mui_f412814e
[2014/04/26 16:04:43 | 000,007,900 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb_winresume.exe.mui_ff8b5358
[2014/09/15 09:55:08 | 000,000,547 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.17238_none_4c1f12534071dcdd.manifest
[2014/09/20 08:16:15 | 000,724,249 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.17238_none_4c1f12534071dcdd_winload.efi_75834aa0
[2014/09/20 08:16:16 | 000,660,625 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.17238_none_4c1f12534071dcdd_winload.exe_75835076
[2014/09/20 08:16:17 | 000,646,411 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.17238_none_4c1f12534071dcdd_winresume.efi_85cd069f
[2014/09/20 08:16:18 | 000,587,303 | ---- | M] () -- \Windows\WinSxS\Backup\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.17238_none_4c1f12534071dcdd_winresume.exe_85cd1215
[2013/08/22 17:34:52 | 000,000,596 | ---- | M] () -- \Windows\WinSxS\FileMaps\programdata_microsoft_network_downloader_7fafaef6d33e4371.cdf-ms
[2013/11/14 14:22:40 | 000,000,463 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_2400ceb4d1008089.manifest
[2014/04/18 16:28:11 | 000,000,465 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.3.9600.17031_cs-cz_2433c0f8d0dacafb.manifest
[2013/08/22 17:22:38 | 000,000,542 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.16384_none_4be51a3d409de6bc.manifest
[2013/11/14 14:38:28 | 000,000,545 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.16411_none_4c2dcab94067d447.manifest
[2013/11/14 14:50:45 | 000,000,546 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.16415_none_4c31cbe1406439a3.manifest
[2013/12/22 01:52:20 | 000,000,545 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.16452_none_4c038b5340875d62.manifest
[2014/04/18 16:28:13 | 000,000,545 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.17031_none_4c180c814078312e.manifest
[2014/09/14 15:24:30 | 000,000,547 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.17238_none_4c1f12534071dcdd.manifest
[2014/10/18 16:22:17 | 000,000,596 | ---- | M] () -- \Windows\WinSxS\Temp\PendingRenames\36cda7ebdeeacf019e2700009414680c.programdata_microsoft_network_downloader_7fafaef6d33e4371.cdf-ms
[2013/08/22 05:55:19 | 000,036,352 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.3.9600.16384_none_da93e078ab3c6498\dmloader.dll
[2013/08/22 15:25:39 | 000,003,584 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_5c049f379cb3e319\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/22 15:25:39 | 000,003,072 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_5c049f379cb3e319\api-ms-win-core-libraryloader-l1-1-1.dll
[2013/08/22 15:25:38 | 000,002,560 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-m..namespace-downlevel_31bf3856ad364e35_6.3.9600.16384_none_5c049f379cb3e319\api-ms-win-core-stringloader-l1-1-1.dll
[2013/08/22 06:17:27 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/08/22 06:17:25 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-libraryloader-l1-1-1.dll
[2013/08/22 06:17:24 | 000,003,584 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-libraryloader-l1-2-0.dll
[2013/08/22 06:17:20 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-libraryloader-private-l1-1-0.dll
[2013/08/22 06:17:34 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-stringloader-l1-1-0.dll
[2013/08/22 06:17:33 | 000,002,560 | -H-- | M] () -- \Windows\WinSxS\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.3.9600.16384_none_9f51b47d9769887a\api-ms-win-core-stringloader-l1-1-1.dll

< *minodlogin* /s >

< *tnod* /s >
[2011/08/27 09:59:40 | 000,005,990 | ---- | M] () -- \oraclexe\app\oracle\product\11.2.0\server\rdbms\admin\catnodp.sql
[2011/08/27 09:59:40 | 000,005,209 | ---- | M] () -- \oraclexe\app\oracle\product\11.2.0\server\rdbms\admin\catnodpt.sql
[2012/03/31 01:24:50 | 000,000,631 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Dreamweaver CS6\configuration\Content\Reference\JavaScript\TextNode.html
[2012/03/16 04:38:54 | 000,002,459 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\framework\src\mx\utils\LinkedListNode.as
[2014/03/22 23:26:54 | 000,003,128 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\Dungeon Defenders\Engine\EditorResources\FaceFX\res\icons\FxGenericTargetNode.bmp
[2014/06/30 18:11:09 | 000,000,068 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\CDW\Development\Src\CDW\classes\AOCAICombatNode.uc
[2014/06/30 18:13:45 | 000,003,128 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\CDW\Engine\EditorResources\FaceFX\res\icons\FxGenericTargetNode.bmp
[2014/06/30 14:15:00 | 000,000,068 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\Development\Src\AOC\classes\AOCAICombatNode.uc
[2014/06/30 14:18:32 | 000,003,128 | ---- | M] () -- \Program Files (x86)\Steam\SteamApps\common\chivalrymedievalwarfare\Engine\EditorResources\FaceFX\res\icons\FxGenericTargetNode.bmp
[2014/05/07 10:48:59 | 000,002,141 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-jee-kepler-SR2-win32-x86_64\eclipse\configuration\org.eclipse.osgi\bundles\525\1\.cp\org\eclipse\m2e\core\ui\internal\views\build\ProjectNode.class
[2014/05/07 10:48:59 | 000,000,200 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-jee-kepler-SR2-win32-x86_64\eclipse\configuration\org.eclipse.osgi\bundles\525\1\.cp\org\eclipse\m2e\core\ui\internal\views\nodes\IArtifactNode.class
[2014/05/07 10:48:59 | 000,002,965 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-jee-kepler-SR2-win32-x86_64\eclipse\configuration\org.eclipse.osgi\bundles\525\1\.cp\org\eclipse\m2e\core\ui\internal\views\nodes\IndexedArtifactNode.class
[2014/05/07 10:48:59 | 000,001,891 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-jee-kepler-SR2-win32-x86_64\eclipse\configuration\org.eclipse.osgi\bundles\525\1\.cp\org\eclipse\m2e\core\ui\internal\views\nodes\LocalRepositoryRootNode.class
[2012/12/05 07:30:38 | 000,004,347 | ---- | M] () -- \Users\Martin\Documents\JAVA\lwjgl-X.X\src\java\org\lwjgl\util\glu\tessellation\DictNode.java

< *AutoKMS* /s >
[2014/01/02 23:42:16 | 003,334,144 | ---- | M] () -- \Windows\AutoKMS\AutoKMS.exe
[2014/10/20 22:43:59 | 000,071,675 | ---- | M] () -- \Windows\AutoKMS\AutoKMS.log
[2014/10/20 22:44:00 | 000,001,513 | ---- | M] () -- \Windows\System32\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\AutoKMS.exe.log
[2014/10/20 22:44:00 | 000,001,513 | ---- | M] () -- \Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\AutoKMS.exe.log

Lothaire
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 pro 2009 21:20

Re: Preventivka s menším podezřením

#13 Příspěvek od Lothaire »

Konec OTL:
< *activator* /s >
[2012/03/16 04:32:54 | 000,002,513 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flash.codemodel.osgi_4.6.1.335153\classes\com\ctc\wstx\osgi\WstxBundleActivator.class
[2012/03/16 04:33:24 | 000,000,926 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexide.exportimport_4.6.1.335153\com\adobe\flexide\exportimport\Activator.class
[2012/03/16 04:34:50 | 000,007,593 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\framework\src\mx\skins\halo\ActivatorSkin.as
[2012/03/16 04:34:28 | 000,005,181 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\haloclassic\src\haloclassic\ActivatorSkin.as
[2012/03/16 04:35:52 | 000,008,253 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\mx\src\mx\skins\halo\ActivatorSkin.as
[2012/03/30 17:20:02 | 000,002,319 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\First Run\Classes\mx\skins\halo\ActivatorSkin.as
[2012/03/30 17:20:02 | 000,001,806 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash CS6\Common\First Run\Classes\mx\skins\sample\ActivatorSkin.as
[2012/03/30 17:20:02 | 000,002,319 | ---- | M] () -- \Users\Martin\AppData\Local\Adobe\Flash CS6\cs_CZ\Configuration\Classes\mx\skins\halo\ActivatorSkin.as
[2012/03/30 17:20:02 | 000,001,806 | ---- | M] () -- \Users\Martin\AppData\Local\Adobe\Flash CS6\cs_CZ\Configuration\Classes\mx\skins\sample\ActivatorSkin.as
[2014/05/07 10:49:00 | 000,005,248 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-jee-kepler-SR2-win32-x86_64\eclipse\configuration\org.eclipse.osgi\bundles\525\1\.cp\org\eclipse\m2e\core\ui\internal\M2EUIPluginActivator.class

< *serial* /s >
[2012/03/16 04:33:30 | 000,293,200 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\org.apache.xml.serializer_2.7.1.v201005080400.jar
[2012/03/16 04:33:02 | 000,001,937 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.6.1.335153\nl\de_DE\dcradSwcs\3.6\locale\serializers_rb.swc
[2012/03/16 04:33:02 | 000,001,937 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.6.1.335153\nl\de_DE\dcradSwcs\4.5\locale\serializers_rb.swc
[2012/03/16 04:33:02 | 000,001,958 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.6.1.335153\nl\fr_FR\dcradSwcs\3.6\locale\serializers_rb.swc
[2012/03/16 04:33:02 | 000,001,956 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.6.1.335153\nl\fr_FR\dcradSwcs\4.5\locale\serializers_rb.swc
[2012/03/16 04:33:02 | 000,001,985 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.6.1.335153\nl\ja_JP\dcradSwcs\3.6\locale\serializers_rb.swc
[2012/03/16 04:33:02 | 000,001,980 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.6.1.335153\nl\ja_JP\dcradSwcs\4.5\locale\serializers_rb.swc
[2012/03/16 04:33:02 | 000,002,003 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.6.1.335153\nl\ru_RU\dcradSwcs\3.6\locale\serializers_rb.swc
[2012/03/16 04:33:02 | 000,002,000 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.6.1.335153\nl\ru_RU\dcradSwcs\4.5\locale\serializers_rb.swc
[2012/03/16 04:33:02 | 000,000,153 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.6.1.335153\nl\xx_XX\serializers\bundles\src\serializer.properties
[2012/03/16 04:33:02 | 000,001,966 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.6.1.335153\nl\zh_CN\dcradSwcs\3.6\locale\serializers_rb.swc
[2012/03/16 04:33:02 | 000,001,961 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project.nl1_4.6.1.335153\nl\zh_CN\dcradSwcs\4.5\locale\serializers_rb.swc
[2012/03/16 04:33:04 | 000,016,397 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project_4.6.1.335153\dcradSwcs\3.6\libs\serializers.swc
[2012/03/16 04:33:04 | 000,001,917 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project_4.6.1.335153\dcradSwcs\3.6\locale\serializers_rb.swc
[2012/03/16 04:33:04 | 000,016,835 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project_4.6.1.335153\dcradSwcs\4.5\libs\serializers.swc
[2012/03/16 04:33:04 | 000,001,949 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.project_4.6.1.335153\dcradSwcs\4.5\locale\serializers_rb.swc
[2012/03/16 04:34:22 | 000,001,711 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\rpc\src\mx\messaging\errors\MessageSerializationError.as
[2012/03/16 04:35:22 | 000,008,889 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\3.6.0\frameworks\projects\rpc\src\mx\rpc\http\SerializationFilter.as
[2012/03/16 04:38:16 | 000,011,140 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\SerialElement.as
[2012/03/16 04:38:40 | 000,005,739 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialDisplayObjectTrait.as
[2012/03/16 04:37:20 | 000,005,664 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialDynamicStreamTrait.as
[2012/03/16 04:36:22 | 000,001,909 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialElementSegment.as
[2012/03/16 04:38:28 | 000,006,077 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialElementTransitionManager.as
[2012/03/16 04:38:28 | 000,002,395 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialSeekOperationInfo.as
[2012/03/16 04:38:30 | 000,015,172 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\elements\compositeClasses\SerialSeekTrait.as
[2012/03/16 04:38:20 | 000,002,953 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\osmf\src\org\osmf\events\SerialElementEvent.as
[2012/03/16 04:37:22 | 000,002,248 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\rpc\src\mx\messaging\errors\MessageSerializationError.as
[2012/03/16 04:38:14 | 000,010,400 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Flash Builder 4.6\sdks\4.6.0\frameworks\projects\rpc\src\mx\rpc\http\SerializationFilter.as
[2012/03/25 08:21:28 | 000,798,352 | ---- | M] () -- \Program Files (x86)\Adobe\Adobe Illustrator CS6\Support Files\Contents\Windows\boost_serialization.dll
[2013/03/27 09:58:10 | 000,006,208 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\ComponentBox\SpecificSerialDCE_40x40.xpm
[2013/03/27 09:58:10 | 000,005,807 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\ComponentBox\SpecificSerialDTE_40x40.xpm
[2013/03/27 09:58:10 | 000,012,050 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerialDCE_HeadDown.xpm
[2013/03/27 09:58:10 | 000,009,408 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerialDCE_HeadDownSide.xpm
[2013/03/27 09:58:10 | 000,012,079 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerialDCE_HeadUp.xpm
[2013/03/27 09:58:10 | 000,015,536 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerialDCE_HeadUpSide.xpm
[2013/03/27 09:58:10 | 000,001,867 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerialDCE_Vert.xpm
[2013/03/27 09:58:10 | 000,011,965 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerialDTE_HeadDown.xpm
[2013/03/27 09:58:10 | 000,009,017 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerialDTE_HeadDownSide.xpm
[2013/03/27 09:58:10 | 000,012,096 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerialDTE_HeadUp.xpm
[2013/03/27 09:58:10 | 000,015,570 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerialDTE_HeadUpSide.xpm
[2013/03/27 09:58:10 | 000,001,867 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerialDTE_Vert.xpm
[2013/03/27 09:58:10 | 000,008,834 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerial_HeadDown.xpm
[2013/03/27 09:58:10 | 000,008,262 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSerial_HeadUp.xpm
[2013/03/27 09:58:10 | 000,010,485 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDCE_HeadDow.xpm
[2013/03/27 09:58:10 | 000,011,149 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDCE_HeadDown.xpm
[2013/03/27 09:58:10 | 000,009,531 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDCE_HeadSide.xpm
[2013/03/27 09:58:10 | 000,010,644 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDCE_HeadUp.xpm
[2013/03/27 09:58:10 | 000,000,471 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDCE_Vert.xpm
[2013/03/27 09:58:10 | 000,000,799 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDCE_Vert_HeadDown.xpm
[2013/03/27 09:58:10 | 000,000,471 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDCE_Vert_HeadSide.xpm
[2013/03/27 09:58:10 | 000,011,115 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDTE_HeadDown.xpm
[2013/03/27 09:58:10 | 000,009,429 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDTE_HeadSide.xpm
[2013/03/27 09:58:10 | 000,010,610 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDTE_HeadUp.xpm
[2013/03/27 09:58:10 | 000,000,471 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDTE_Vert.xpm
[2013/03/27 09:58:10 | 000,000,799 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDTE_Vert_HeadDown.xpm
[2013/03/27 09:58:10 | 000,000,471 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\PhysicalView\Cables\gRealSmartSerialDTE_Vert_HeadSide.xpm
[2013/03/27 09:58:10 | 000,000,443 | ---- | M] () -- \Program Files (x86)\Cisco Packet Tracer 6.0.1\art\Workspace\Logical\SerialIcon.xpm
[2013/02/13 15:09:51 | 000,020,800 | R--- | M] () -- \Program Files (x86)\Hi-Rez Studios\HiRezGames\smite\Binaries\Autoreporter.XmlSerializers.dll
[2014/09/16 13:50:00 | 000,167,592 | ---- | M] () -- \Program Files (x86)\Microsoft Office\Office15\ADDINS\PowerPivot Excel Add-in\Microsoft.AnalysisServices.Excel.BackEnd.XmlSerializers.dll
[2014/09/16 13:50:02 | 000,210,088 | ---- | M] () -- \Program Files (x86)\Microsoft Office\Office15\ADDINS\PowerPivot Excel Add-in\Microsoft.AnalysisServices.Excel.Common.FrontEnd.XmlSerializers.dll
[2014/05/13 23:17:02 | 000,434,368 | ---- | M] () -- \Program Files (x86)\Microsoft Silverlight\5.1.30514.0\System.Runtime.Serialization.dll
[2014/09/10 21:12:24 | 001,164,288 | ---- | M] () -- \Program Files (x86)\Microsoft Silverlight\5.1.30514.0\System.Runtime.Serialization.ni.dll
[2014/07/09 03:45:06 | 000,970,752 | ---- | M] () -- \Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2012/03/26 23:01:20 | 000,001,673 | ---- | M] () -- \Program Files\Adobe\Adobe Encore CS6\LMResources\BadSerialNumberAlert.exv
[2012/03/26 23:01:20 | 000,001,561 | ---- | M] () -- \Program Files\Adobe\Adobe Encore CS6\LMResources\CantChangeSerialNumberAlert.exv
[2012/03/26 23:01:20 | 000,001,639 | ---- | M] () -- \Program Files\Adobe\Adobe Encore CS6\LMResources\InValidUpGradeSerialNumberAlert.exv
[2012/03/26 23:01:20 | 000,000,849 | ---- | M] () -- \Program Files\Adobe\Adobe Encore CS6\LMResources\ReserializeAlert.exv
[2012/03/26 23:01:20 | 000,027,443 | ---- | M] () -- \Program Files\Adobe\Adobe Encore CS6\LMResources\SerializationWF.exv
[2012/03/26 23:28:46 | 000,119,808 | ---- | M] () -- \Program Files\Adobe\Adobe Encore CS6\Plug-ins\Common\DeviceControlSerial.prm
[2012/03/25 04:50:58 | 000,439,440 | ---- | M] () -- \Program Files\Adobe\Adobe Illustrator CS6 (64 Bit)\Support Files\Contents\Windows\boost_serialization.dll
[2014/01/19 14:59:03 | 000,015,752 | ---- | M] () -- \Program Files\Java\jdk1.7.0_51\bin\serialver.exe
[2014/07/09 03:45:33 | 000,847,872 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2013/12/22 01:48:42 | 000,090,112 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\cs\System.RunTime.Serialization.Resources.dll
[2014/08/02 15:22:55 | 000,002,481 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.6.0_x86__k1h2ywk1493x8\Lenovo.Discovery.Components.Registration\Assets\FindSerial_ThinkCentreNetVistaValueLineAndOtherDesktops.gif
[2014/08/02 15:22:55 | 000,003,976 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.6.0_x86__k1h2ywk1493x8\Lenovo.Discovery.Components.Registration\Assets\FindSerial_ThinkPadAndValueLineNotebooks.gif
[2014/08/02 15:22:55 | 000,021,466 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.6.0_x86__k1h2ywk1493x8\Lenovo.Discovery.Components.Registration\Assets\FindSerial_ValueLineAndIdeaCentreDesktops.gif
[2014/08/02 15:22:55 | 000,027,531 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.6.0_x86__k1h2ywk1493x8\Lenovo.Discovery.Components.Registration\Assets\FindSerial_ValueLineAndIdeaPadNotebooks.gif
[2014/10/12 15:52:39 | 000,012,209 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.6.0_x86__k1h2ywk1493x8\Lenovo.Discovery.Components.Registration\Views\Pages\FindSerialNumberPage.xbf
[2014/08/02 15:22:55 | 000,002,481 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.6.0_x86__k1h2ywk1493x8\Lenovo.Discovery.Components.Warranty\Assets\FindSerial_ThinkCentreNetVistaValueLineAndOtherDesktops.gif
[2014/08/02 15:22:55 | 000,003,976 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.6.0_x86__k1h2ywk1493x8\Lenovo.Discovery.Components.Warranty\Assets\FindSerial_ThinkPadAndValueLineNotebooks.gif
[2014/08/02 15:22:55 | 000,021,466 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.6.0_x86__k1h2ywk1493x8\Lenovo.Discovery.Components.Warranty\Assets\FindSerial_ValueLineAndIdeaCentreDesktops.gif
[2014/08/02 15:22:55 | 000,027,531 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.6.0_x86__k1h2ywk1493x8\Lenovo.Discovery.Components.Warranty\Assets\FindSerial_ValueLineAndIdeaPadNotebooks.gif
[2014/10/12 15:52:39 | 000,012,195 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.6.0_x86__k1h2ywk1493x8\Lenovo.Discovery.Components.Warranty\Views\Pages\SerialNumberCheck.xbf
[2012/08/18 20:11:42 | 000,002,481 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Registration\Assets\FindSerial_ThinkCentreNetVistaValueLineAndOtherDesktops.gif
[2012/08/18 20:11:42 | 000,003,976 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Registration\Assets\FindSerial_ThinkPadAndValueLineNotebooks.gif
[2012/08/18 20:11:42 | 000,021,466 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Registration\Assets\FindSerial_ValueLineAndIdeaCentreDesktops.gif
[2012/08/18 20:11:42 | 000,039,047 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Registration\Assets\FindSerial_ValueLineAndIdeaPadNotebooks.gif
[2013/12/23 14:19:12 | 000,009,132 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Registration\Views\Pages\FindSerialNumberPage.xbf
[2012/08/18 20:11:42 | 000,002,481 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Warranty\Assets\FindSerial_ThinkCentreNetVistaValueLineAndOtherDesktops.gif
[2012/08/18 20:11:42 | 000,003,976 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Warranty\Assets\FindSerial_ThinkPadAndValueLineNotebooks.gif
[2012/08/18 20:11:42 | 000,021,466 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Warranty\Assets\FindSerial_ValueLineAndIdeaCentreDesktops.gif
[2012/08/18 20:11:42 | 000,027,531 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Warranty\Assets\FindSerial_ValueLineAndIdeaPadNotebooks.gif
[2013/12/23 14:19:13 | 000,012,181 | ---- | M] () -- \Program Files\WindowsApps\E046963F.LenovoSupport_2.0.4.0_x86__k1h2ywk1493x8\Sections_Warranty\Views\Pages\SerialNumberCheck.xbf
[2014/10/18 10:22:03 | 001,760,256 | ---- | M] () -- \Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.sledujuserialy.cz_0.localstorage
[2014/10/18 10:22:03 | 000,016,384 | ---- | M] () -- \Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.sledujuserialy.cz_0.localstorage-journal
[2014/05/07 10:48:58 | 000,004,964 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-jee-kepler-SR2-win32-x86_64\eclipse\configuration\org.eclipse.osgi\bundles\285\1\.cp\org\eclipse\epp\internal\mpc\ui\wizards\SelectionModelStateSerializer.class
[2014/02/24 06:04:52 | 000,302,018 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-jee-kepler-SR2-win32-x86_64\eclipse\plugins\org.apache.xml.serializer_2.7.1.v201005080400.jar
[2014/04/12 19:16:45 | 000,000,184 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-standard-kepler-SR1-win32\eclipse\configuration\org.eclipse.osgi\bundles\208\1\.cp\org\eclipse\swt\internal\SerializableCompatibility.class
[2014/04/12 19:16:45 | 000,001,242 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-standard-kepler-SR1-win32\eclipse\configuration\org.eclipse.osgi\bundles\208\1\.cp\org\eclipse\swt\internal\mozilla\nsIDOMSerializer.class
[2014/04/12 19:16:45 | 000,001,240 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-standard-kepler-SR1-win32\eclipse\configuration\org.eclipse.osgi\bundles\208\1\.cp\org\eclipse\swt\internal\mozilla\nsIDOMSerializer_1_7.class
[2014/04/12 19:16:45 | 000,001,128 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-standard-kepler-SR1-win32\eclipse\configuration\org.eclipse.osgi\bundles\208\1\.cp\org\eclipse\swt\internal\mozilla\nsISerializable.class
[2014/01/21 01:07:30 | 000,004,964 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\eclipse-standard-kepler-SR1-win32\eclipse\configuration\org.eclipse.osgi\bundles\91\1\.cp\org\eclipse\epp\internal\mpc\ui\wizards\SelectionModelStateSerializer.class
[2013/12/18 19:51:12 | 000,015,752 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\jdk\bin\serialver.exe
[2013/11/17 19:48:16 | 000,004,138 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\modules\oracle.xdk_12.1.2\xsqlserializers.jar
[2014/02/17 23:42:32 | 000,188,993 | ---- | M] () -- \Users\Martin\Documents\4. PROGRAMY\sqldeveloper-4.0.1.14.48-x64\sqldeveloper\sqldeveloper\extensions\oracle.datamodeler\lib\serializer-2.7.0.jar
[2006/05/03 09:37:32 | 000,016,993 | ---- | M] () -- \Users\Martin\Documents\JAVA\FIMUtilsDoc\doc\serialized-form.html
[2014/03/11 07:04:22 | 000,034,665 | ---- | M] () -- \Users\Martin\Documents\JAVA\OpenGL\jogl\javadoc\serialized-form.html
[2014/03/11 06:59:02 | 000,016,355 | ---- | M] () -- \Users\Martin\Documents\JAVA\OpenGL\jogl\javadoc_jogl_spec\serialized-form.html
[2014/03/11 06:54:18 | 000,004,078 | ---- | M] () -- \Users\Martin\Documents\JAVA\OpenGL\jogl\javadoc_nativewindow_spec\serialized-form.html
[2007/01/07 22:42:16 | 000,033,955 | ---- | M] () -- \Users\Martin\Documents\JAVA\PGRF2_Zdenek_Horak\PGRF2_Zdeněk_Horák\javadoc\serialized-form.html
[2013/08/17 02:06:37 | 000,011,776 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\2.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014/06/24 00:12:42 | 000,131,072 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2013/12/22 01:48:42 | 000,090,112 | ---- | M] () -- \Windows\assembly\GAC_MSIL\system.runtime.serialization.resources\3.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.Resources.dll
[2014/07/09 03:45:06 | 000,970,752 | ---- | M] () -- \Windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2014/09/12 13:50:02 | 000,306,176 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runt9064068c#\936b6c5aa7f7dd84cc77bfd146c54720\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014/09/12 13:50:02 | 000,000,440 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runt9064068c#\936b6c5aa7f7dd84cc77bfd146c54720\System.Runtime.Serialization.Formatters.Soap.ni.dll.aux
[2014/04/23 15:51:08 | 000,008,704 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtdf6812ee#\b7c90cd61aa57b4858a896d7e33c30d9\System.Runtime.Serialization.Primitives.ni.dll
[2014/04/23 15:51:08 | 000,000,300 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runtdf6812ee#\b7c90cd61aa57b4858a896d7e33c30d9\System.Runtime.Serialization.Primitives.ni.dll.aux
[2014/10/15 18:13:12 | 002,803,200 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\ab763e7f2c7532e9fe8f587995105156\System.Runtime.Serialization.ni.dll
[2014/10/15 18:13:12 | 000,000,980 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\ab763e7f2c7532e9fe8f587995105156\System.Runtime.Serialization.ni.dll.aux
[2014/10/15 18:17:33 | 000,366,080 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runt9064068c#\c2607e5e30faa9f137b103acde244fdf\System.Runtime.Serialization.Formatters.Soap.ni.dll
[2014/10/15 18:17:33 | 000,000,440 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runt9064068c#\c2607e5e30faa9f137b103acde244fdf\System.Runtime.Serialization.Formatters.Soap.ni.dll.aux
[2014/04/21 17:44:44 | 000,009,728 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runtdf6812ee#\d7c19ec0784ce130d53d43af71a371db\System.Runtime.Serialization.Primitives.ni.dll
[2014/04/21 17:44:44 | 000,000,300 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runtdf6812ee#\d7c19ec0784ce130d53d43af71a371db\System.Runtime.Serialization.Primitives.ni.dll.aux
[2014/10/15 17:28:10 | 003,529,216 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runteb92aa12#\769339283c5376245c011d81ce725abd\System.Runtime.Serialization.ni.dll
[2014/10/15 17:28:10 | 000,000,980 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Runteb92aa12#\769339283c5376245c011d81ce725abd\System.Runtime.Serialization.ni.dll.aux
[2014/04/22 18:40:58 | 000,010,752 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Xml.429e8964#\30e2997004b1856ef707fb74771d5d8f\System.Xml.XmlSerializer.ni.dll
[2014/04/22 18:40:58 | 000,000,284 | ---- | M] () -- \Windows\assembly\NativeImages_v4.0.30319_64\System.Xml.429e8964#\30e2997004b1856ef707fb74771d5d8f\System.Xml.XmlSerializer.ni.dll.aux
[2013/08/22 17:32:39 | 000,001,032 | ---- | M] () -- \Windows\Inf\c_multiportserial.inf
[2012/10/01 21:32:44 | 000,166,864 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005119110000000000000000F01FEC\15.0.4420\AS_Client_BackEnd_XmlSerializers_dll_32.B4988E63_555A_4DEB_A5F4_A9E5864569F1
[2012/10/01 21:32:44 | 000,209,360 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005119110000000000000000F01FEC\15.0.4420\AS_Client_Common_FrontEnd_XmlSerializers_dll_32.B4988E63_555A_4DEB_A5F4_A9E5864569F1
[2014/01/23 15:55:16 | 000,167,616 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005119110000000000000000F01FEC\15.0.4569\AS_Client_BackEnd_XmlSerializers_dll_32.B4988E63_555A_4DEB_A5F4_A9E5864569F1
[2014/01/23 15:55:16 | 000,210,112 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00005119110000000000000000F01FEC\15.0.4569\AS_Client_Common_FrontEnd_XmlSerializers_dll_32.B4988E63_555A_4DEB_A5F4_A9E5864569F1
[2013/11/14 14:23:26 | 000,027,920 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap.resources\v4.0_4.0.0.0_cs_b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013/08/10 02:55:16 | 000,142,104 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
[2013/08/10 02:55:16 | 000,029,392 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Json\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Json.dll
[2013/08/10 02:55:16 | 000,029,432 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Primitives\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Primitives.dll
[2014/06/05 05:33:14 | 000,113,952 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.RunTime.Serialization.resources\v4.0_4.0.0.0_cs_b77a5c561934e089\System.RunTime.Serialization.resources.dll
[2013/08/10 02:55:16 | 000,029,896 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Xml\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Xml.dll
[2014/07/24 05:20:32 | 001,059,536 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
[2013/08/10 02:55:49 | 000,045,720 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Serialization\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Serialization.dll
[2013/08/10 02:55:49 | 000,029,848 | ---- | M] () -- \Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml.XmlSerializer\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Xml.XmlSerializer.dll
[2014/06/24 00:12:42 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2013/08/17 02:06:37 | 000,011,776 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014/07/09 03:45:07 | 000,970,752 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2014/07/24 05:20:32 | 001,059,536 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.dll
[2013/08/10 02:55:16 | 000,142,104 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2013/08/10 02:55:16 | 000,029,392 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Json.dll
[2013/08/10 02:55:16 | 000,029,432 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Primitives.dll
[2013/08/10 02:55:16 | 000,029,896 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Runtime.Serialization.Xml.dll
[2013/08/10 02:55:49 | 000,045,720 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.Serialization.dll
[2013/08/10 02:55:49 | 000,029,848 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\System.Xml.XmlSerializer.dll
[2013/11/14 14:23:26 | 000,027,920 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014/06/05 05:33:14 | 000,113,952 | ---- | M] () -- \Windows\Microsoft.NET\Framework\v4.0.30319\cs\System.RunTime.Serialization.resources.dll
[2014/06/24 00:12:50 | 000,131,072 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
[2013/08/17 02:06:37 | 000,011,776 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v2.0.50727\cs\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2014/07/09 03:45:34 | 000,847,872 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
[2014/07/24 05:20:21 | 001,059,536 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.dll
[2013/08/10 02:41:27 | 000,142,104 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Formatters.Soap.dll
[2013/08/10 02:41:27 | 000,029,392 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Json.dll
[2013/08/10 02:41:28 | 000,029,432 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Primitives.dll
[2013/08/10 02:41:28 | 000,029,896 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Serialization.Xml.dll
[2013/08/10 02:42:08 | 000,045,720 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Xml.Serialization.dll
[2013/08/10 02:42:08 | 000,029,848 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\System.Xml.XmlSerializer.dll
[2013/11/14 14:23:25 | 000,027,920 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\cs\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014/06/05 05:33:14 | 000,113,952 | ---- | M] () -- \Windows\Microsoft.NET\Framework64\v4.0.30319\cs\System.RunTime.Serialization.resources.dll
[2013/08/22 23:12:22 | 000,008,827 | ---- | M] () -- \Windows\servicing\Packages\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~cs-CZ~6.3.9600.16384.cat
[2013/08/22 22:40:12 | 000,000,781 | ---- | M] () -- \Windows\servicing\Packages\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~cs-CZ~6.3.9600.16384.mum
[2013/08/22 14:55:01 | 000,008,827 | ---- | M] () -- \Windows\servicing\Packages\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~~6.3.9600.16384.cat
[2013/08/22 08:47:48 | 000,000,511 | ---- | M] () -- \Windows\servicing\Packages\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~~6.3.9600.16384.mum
[2013/08/22 05:48:16 | 000,015,872 | ---- | M] () -- \Windows\System32\serialui.dll
[2013/08/22 23:12:22 | 000,008,827 | ---- | M] () -- \Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~cs-CZ~6.3.9600.16384.cat
[2013/08/22 14:55:01 | 000,008,827 | ---- | M] () -- \Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Serial-UartClass-package~31bf3856ad364e35~amd64~~6.3.9600.16384.cat
[2013/11/14 14:23:17 | 000,005,120 | ---- | M] () -- \Windows\System32\cs-CZ\serialui.dll.mui
[2013/11/14 14:23:10 | 000,000,232 | ---- | M] () -- \Windows\System32\DriverStore\en-US\c_multiportserial.inf_loc
[2013/08/22 08:57:38 | 000,001,032 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\c_multiportserial.inf_amd64_7875073d426d59a6\c_multiportserial.inf
[2013/12/22 02:01:44 | 000,004,224 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\c_multiportserial.inf_amd64_7875073d426d59a6\c_multiportserial.PNF
[2013/08/22 13:40:08 | 000,083,456 | ---- | M] () -- \Windows\System32\DriverStore\FileRepository\msports.inf_amd64_1be60ad3a61e5531\serial.sys
[2013/08/22 05:48:16 | 000,015,872 | ---- | M] () -- \Windows\SysWOW64\serialui.dll
[2013/11/14 14:23:17 | 000,005,120 | ---- | M] () -- \Windows\SysWOW64\cs-CZ\serialui.dll.mui
[2013/11/14 14:23:10 | 000,000,232 | ---- | M] () -- \Windows\WinSxS\amd64_c_multiportserial.inf.resources_31bf3856ad364e35_6.3.9600.16384_en-us_35eaebe6834354eb\c_multiportserial.inf_loc
[2013/08/22 08:57:38 | 000,001,032 | ---- | M] () -- \Windows\WinSxS\amd64_c_multiportserial.inf_31bf3856ad364e35_6.3.9600.16384_none_91b10a007e43beff\c_multiportserial.inf
[2014/08/18 13:08:43 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_b0eacafe7f4d1992\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2013/08/17 02:06:37 | 000,011,776 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.17226_cs-cz_b12d926c7f1ac114\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2014/08/18 13:08:45 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.20708_cs-cz_b1ceee03982636a5\System.Runtime.Serialization.Formatters.Soap.Resources.dll
[2013/11/14 14:23:17 | 000,005,120 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_3f29419cb7a1caf0\serialui.dll.mui
[2013/08/22 13:13:54 | 000,017,920 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-unimodem-config_31bf3856ad364e35_6.3.9600.16384_none_e5c00198f2a1c32d\serialui.dll
[2014/08/18 13:10:34 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_4e32729c2675dfcf\System.RunTime.Serialization.Resources.dll
[2013/12/22 01:48:42 | 000,090,112 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.3.9600.17226_cs-cz_4e753a0a26438751\System.RunTime.Serialization.Resources.dll
[2014/08/18 13:10:35 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\amd64_microsoft-windows-wcfcorecomp.resources_31bf3856ad364e35_6.3.9600.20708_cs-cz_4f1695a13f4efce2\System.RunTime.Serialization.Resources.dll
[2013/11/14 14:23:10 | 000,009,728 | ---- | M] () -- \Windows\WinSxS\amd64_msports.inf.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_b574829120336a99\serial.sys.mui
[2013/08/22 13:40:08 | 000,083,456 | ---- | M] () -- \Windows\WinSxS\amd64_msports.inf_31bf3856ad364e35_6.3.9600.16384_none_e95610bc8c554aa7\serial.sys
[2014/09/12 14:58:54 | 000,003,691 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..alization.resources_b03f5f7f11d50a3a_4.0.9600.16384_cs-cz_1da5c476c59b0e5b\System.RunTime.Serialization.resources.dll
[2014/06/05 05:33:14 | 000,113,952 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..alization.resources_b03f5f7f11d50a3a_4.0.9600.17238_cs-cz_1da069eec59ff302\System.RunTime.Serialization.resources.dll
[2014/09/12 14:58:55 | 000,003,304 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..alization.resources_b03f5f7f11d50a3a_4.0.9600.20720_cs-cz_06d276aedf4770c6\System.RunTime.Serialization.resources.dll
[2013/08/10 02:41:27 | 000,142,104 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..ion.formatters.soap_b03f5f7f11d50a3a_4.0.9600.16384_none_f73c7de0bb1de286\System.Runtime.Serialization.Formatters.Soap.dll
[2013/08/10 02:41:28 | 000,029,432 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..lization.primitives_b03f5f7f11d50a3a_4.0.9600.16384_none_64635c6af076b012\System.Runtime.Serialization.Primitives.dll
[2013/11/14 14:23:25 | 000,027,920 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runti..ters.soap.resources_b03f5f7f11d50a3a_4.0.9600.16384_cs-cz_65f374ee29342685\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013/08/10 02:41:27 | 000,029,392 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runtime.serialization.json_b03f5f7f11d50a3a_4.0.9600.16384_none_031841e9b021a288\System.Runtime.Serialization.Json.dll
[2013/08/10 02:41:28 | 000,029,896 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runtime.serialization.xml_b03f5f7f11d50a3a_4.0.9600.16384_none_ea3019bcd508d7f5\System.Runtime.Serialization.Xml.dll
[2014/09/12 14:58:57 | 000,018,929 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.16384_none_afcfdcce0af8e4ba\System.Runtime.Serialization.dll
[2014/07/24 05:20:21 | 001,059,536 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.17238_none_afca82460afdc961\System.Runtime.Serialization.dll
[2014/09/12 14:58:59 | 000,004,122 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.20720_none_98fc8f0624a54725\System.Runtime.Serialization.dll
[2013/08/10 02:42:08 | 000,045,720 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.xml.serialization_b03f5f7f11d50a3a_4.0.9600.16384_none_1f92ce7ac9b9f399\System.Xml.Serialization.dll
[2013/08/10 02:42:08 | 000,029,848 | ---- | M] () -- \Windows\WinSxS\amd64_netfx4-system.xml.xmlserializer_b03f5f7f11d50a3a_4.0.9600.16384_none_0b1c65bd7b1ef04c\System.Xml.XmlSerializer.dll
[2014/08/18 13:13:58 | 000,000,531 | ---- | M] () -- \Windows\WinSxS\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.16384_none_f057a9271ce694b1\System.Runtime.Serialization.Formatters.Soap.dll
[2014/06/24 00:12:50 | 000,131,072 | ---- | M] () -- \Windows\WinSxS\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.17226_none_f0517be51cec2cbf\System.Runtime.Serialization.Formatters.Soap.dll
[2014/08/18 13:14:00 | 000,000,491 | ---- | M] () -- \Windows\WinSxS\amd64_netfx-system.runtim..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.20708_none_d981a48b36959176\System.Runtime.Serialization.Formatters.Soap.dll
[2014/08/18 13:15:47 | 000,000,639 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.16384_none_9fc99c9c7c4c05c7\System.Runtime.Serialization.dll
[2014/09/12 15:00:42 | 000,000,425 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.17226_none_9fc36f5a7c519dd5\System.Runtime.Serialization.dll
[2014/07/09 03:45:34 | 000,847,872 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.17231_none_9fc4e18c7c503707\System.Runtime.Serialization.dll
[2014/08/18 13:15:49 | 000,000,424 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.20708_none_88f3980095fb028c\System.Runtime.Serialization.dll
[2014/09/12 15:00:43 | 000,000,619 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.20717_none_88f4af1295fa0242\System.Runtime.Serialization.dll
[2014/08/18 13:15:51 | 000,000,639 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.16384_none_daa0a966d0440060\System.Runtime.Serialization.dll
[2014/09/12 15:00:45 | 000,000,425 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17226_none_da9a7c24d049986e\System.Runtime.Serialization.dll
[2014/07/09 03:45:33 | 000,847,872 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17231_none_da9bee56d04831a0\System.Runtime.Serialization.dll
[2014/08/18 13:15:53 | 000,000,424 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20708_none_c3caa4cae9f2fd25\System.Runtime.Serialization.dll
[2014/09/12 15:00:46 | 000,000,619 | ---- | M] () -- \Windows\WinSxS\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20717_none_c3cbbbdce9f1fcdb\System.Runtime.Serialization.dll
[2013/11/14 14:22:01 | 000,000,276 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_c_multiportserial.inf-languagepack_31bf3856ad364e35_6.3.9600.16384_cs-cz_c3036df581d2c4e4.manifest
[2013/11/14 14:22:15 | 000,000,249 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_c_multiportserial.inf.resources_31bf3856ad364e35_6.3.9600.16384_en-us_35eaebe6834354eb.manifest
[2013/08/22 17:20:14 | 000,000,210 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_c_multiportserial.inf_31bf3856ad364e35_6.3.9600.16384_none_91b10a007e43beff.manifest
[2013/08/22 15:25:34 | 000,000,297 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-b..gertransport-serial_31bf3856ad364e35_6.3.9600.16384_none_0273ed2980a1f589.manifest
[2013/08/22 17:22:11 | 000,001,512 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft-windows-serial-classextension_31bf3856ad364e35_6.3.9600.16384_none_26d3123b2d2a9360.manifest
[2013/08/22 17:22:07 | 000,000,110 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_microsoft.windows.h..tserial-driverclass_31bf3856ad364e35_6.3.9600.16384_none_1d7b32f2da6cfe0c.manifest
[2013/08/22 17:24:27 | 000,000,402 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.runtime.serialization.json_b03f5f7f11d50a3a_4.0.9600.16384_none_031841e9b021a288.manifest
[2013/08/22 17:24:29 | 000,000,401 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.runtime.serialization.xml_b03f5f7f11d50a3a_4.0.9600.16384_none_ea3019bcd508d7f5.manifest
[2013/08/22 17:24:24 | 000,000,420 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.16384_none_afcfdcce0af8e4ba.manifest
[2014/09/10 21:20:24 | 000,000,420 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.17238_none_afca82460afdc961.manifest
[2014/09/10 21:20:24 | 000,000,413 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.runtime.serialization_b03f5f7f11d50a3a_4.0.9600.20720_none_98fc8f0624a54725.manifest
[2013/08/22 17:24:28 | 000,000,397 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.xml.serialization_b03f5f7f11d50a3a_4.0.9600.16384_none_1f92ce7ac9b9f399.manifest
[2013/08/22 17:24:27 | 000,000,403 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_netfx4-system.xml.xmlserializer_b03f5f7f11d50a3a_4.0.9600.16384_none_0b1c65bd7b1ef04c.manifest
[2013/08/22 17:24:13 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.16384_none_9fc99c9c7c4c05c7.manifest
[2014/08/14 10:54:28 | 000,000,404 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.17226_none_9fc36f5a7c519dd5.manifest
[2014/09/10 21:21:52 | 000,000,404 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.17231_none_9fc4e18c7c503707.manifest
[2014/08/14 10:54:28 | 000,000,407 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.20708_none_88f3980095fb028c.manifest
[2014/09/10 21:21:52 | 000,000,406 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization.ref_b03f5f7f11d50a3a_6.3.9600.20717_none_88f4af1295fa0242.manifest
[2013/08/22 17:24:13 | 000,000,416 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.16384_none_daa0a966d0440060.manifest
[2014/08/14 10:54:28 | 000,000,413 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17226_none_da9a7c24d049986e.manifest
[2014/09/10 21:21:52 | 000,000,412 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17231_none_da9bee56d04831a0.manifest
[2014/08/14 10:54:28 | 000,000,415 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20708_none_c3caa4cae9f2fd25.manifest
[2014/09/10 21:21:52 | 000,000,414 | ---- | M] () -- \Windows\WinSxS\Manifests\amd64_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20717_none_c3cbbbdce9f1fcdb.manifest
[2013/08/22 17:24:29 | 000,000,418 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.json_b03f5f7f11d50a3a_4.0.9600.16384_none_61eedd30ec040245.manifest
[2013/08/22 17:24:24 | 000,000,430 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.primitives_b03f5f7f11d50a3a_4.0.9600.16384_none_dde82ee214ba2d3d.manifest
[2013/08/22 17:24:13 | 000,000,400 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.16384_none_ed2ffed67c428df1.manifest
[2014/08/14 10:54:28 | 000,000,399 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.17226_none_ed29d1947c4825ff.manifest
[2014/09/10 21:21:51 | 000,000,401 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.17231_none_ed2b43c67c46bf31.manifest
[2014/08/14 10:54:28 | 000,000,399 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.20708_none_d659fa3a95f18ab6.manifest
[2014/09/10 21:21:51 | 000,000,401 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.20717_none_d65b114c95f08a6c.manifest
[2013/11/14 14:22:50 | 000,000,448 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.16384_cs-cz_25789e4d6d93f144.manifest
[2014/09/10 21:20:23 | 000,000,449 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.17238_cs-cz_257343c56d98d5eb.manifest
[2014/09/10 21:20:23 | 000,000,445 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.20720_cs-cz_0ea55085874053af.manifest
[2013/11/14 14:22:49 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.16384_cs-cz_7adb458f8b8eae0b.manifest
[2014/08/14 10:54:26 | 000,000,406 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.17226_cs-cz_7ad5184d8b944619.manifest
[2014/09/10 21:21:51 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.17231_cs-cz_7ad68a7f8b92df4b.manifest
[2014/08/14 10:54:26 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.20708_cs-cz_640540f3a53daad0.manifest
[2014/09/10 21:21:51 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.20717_cs-cz_64065805a53caa86.manifest
[2013/08/22 17:24:24 | 000,000,419 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization.xml_b03f5f7f11d50a3a_4.0.9600.16384_none_0d0d9cf22bac10f4.manifest
[2013/08/22 17:24:27 | 000,000,471 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.16384_none_c8108d2e85eed25d.manifest
[2014/09/10 21:20:24 | 000,000,471 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.17238_none_c80b32a685f3b704.manifest
[2014/09/10 21:20:24 | 000,000,465 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.20720_none_b13d3f669f9b34c8.manifest
[2013/08/22 17:24:13 | 000,000,422 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.16384_none_1d733470a3e98f24.manifest
[2014/08/14 10:54:28 | 000,000,421 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.17226_none_1d6d072ea3ef2732.manifest
[2014/09/10 21:21:51 | 000,000,422 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.17231_none_1d6e7960a3edc064.manifest
[2014/08/14 10:54:28 | 000,000,421 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.20708_none_069d2fd4bd988be9.manifest
[2014/09/10 21:21:51 | 000,000,423 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.20717_none_069e46e6bd978b9f.manifest
[2013/08/22 17:24:28 | 000,000,447 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.xml.serialization_b77a5c561934e089_4.0.9600.16384_none_5aaf0d34c0033202.manifest
[2013/08/22 17:24:24 | 000,000,420 | ---- | M] () -- \Windows\WinSxS\Manifests\msil_system.xml.xmlserializer_b03f5f7f11d50a3a_4.0.9600.16384_none_3cc4c9f9340d8755.manifest
[2013/08/22 17:24:56 | 000,000,411 | ---- | M] () -- \Windows\WinSxS\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.16384_none_224de03de4c02966.manifest
[2014/08/14 10:54:28 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17226_none_2247b2fbe4c5c174.manifest
[2014/09/10 21:21:51 | 000,000,412 | ---- | M] () -- \Windows\WinSxS\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17231_none_2249252de4c45aa6.manifest
[2014/08/14 10:54:28 | 000,000,408 | ---- | M] () -- \Windows\WinSxS\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20708_none_0b77dba1fe6f262b.manifest
[2014/09/10 21:21:51 | 000,000,411 | ---- | M] () -- \Windows\WinSxS\Manifests\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20717_none_0b78f2b3fe6e25e1.manifest
[2013/08/10 02:55:16 | 000,142,104 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_4.0.9600.16384_none_0dbd81c1c9e100df\System.Runtime.Serialization.Formatters.Soap.dll
[2014/08/18 13:18:31 | 000,000,531 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.16384_none_63202903e7dbbda6\System.Runtime.Serialization.Formatters.Soap.dll
[2014/06/24 00:12:42 | 000,131,072 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.17226_none_6319fbc1e7e155b4\System.Runtime.Serialization.Formatters.Soap.dll
[2014/08/18 13:18:32 | 000,000,491 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ion.formatters.soap_b03f5f7f11d50a3a_6.3.9600.20708_none_4c4a2468018aba6b\System.Runtime.Serialization.Formatters.Soap.dll
[2013/11/14 14:23:26 | 000,027,920 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_4.0.9600.16384_cs-cz_c6e6982dc37909d8\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014/08/18 13:18:32 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.3.9600.16384_cs-cz_1c493f6fe173c69f\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013/08/17 02:06:37 | 000,011,776 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.3.9600.17226_cs-cz_1c43122de1795ead\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014/08/18 13:18:33 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.seri..ters.soap.resources_b03f5f7f11d50a3a_6.3.9600.20708_cs-cz_05733ad3fb22c364\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013/08/10 02:55:16 | 000,029,392 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.json_b03f5f7f11d50a3a_4.0.9600.16384_none_61eedd30ec040245\System.Runtime.Serialization.Json.dll
[2013/08/10 02:55:16 | 000,029,432 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.primitives_b03f5f7f11d50a3a_4.0.9600.16384_none_dde82ee214ba2d3d\System.Runtime.Serialization.Primitives.dll
[2014/08/18 13:18:34 | 000,000,661 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.16384_none_ed2ffed67c428df1\System.Runtime.Serialization.dll
[2014/09/12 15:02:04 | 000,000,436 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.17226_none_ed29d1947c4825ff\System.Runtime.Serialization.dll
[2014/07/09 03:45:07 | 000,970,752 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.17231_none_ed2b43c67c46bf31\System.Runtime.Serialization.dll
[2014/08/18 13:18:36 | 000,000,433 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.20708_none_d659fa3a95f18ab6\System.Runtime.Serialization.dll
[2014/09/12 15:02:06 | 000,000,632 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.ref_b77a5c561934e089_6.3.9600.20717_none_d65b114c95f08a6c\System.Runtime.Serialization.dll
[2014/09/12 15:02:07 | 000,003,691 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.16384_cs-cz_25789e4d6d93f144\System.RunTime.Serialization.resources.dll
[2014/06/05 05:33:14 | 000,113,952 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.17238_cs-cz_257343c56d98d5eb\System.RunTime.Serialization.resources.dll
[2014/09/12 15:02:08 | 000,003,304 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_4.0.9600.20720_cs-cz_0ea55085874053af\System.RunTime.Serialization.resources.dll
[2014/08/18 13:18:37 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.16384_cs-cz_7adb458f8b8eae0b\System.RunTime.Serialization.Resources.dll
[2014/09/12 15:02:09 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.17226_cs-cz_7ad5184d8b944619\System.RunTime.Serialization.Resources.dll
[2013/12/22 01:48:42 | 000,090,112 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.17231_cs-cz_7ad68a7f8b92df4b\System.RunTime.Serialization.Resources.dll
[2014/08/18 13:18:37 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.20708_cs-cz_640540f3a53daad0\System.RunTime.Serialization.Resources.dll
[2014/09/12 15:02:09 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.resources_b77a5c561934e089_6.3.9600.20717_cs-cz_64065805a53caa86\System.RunTime.Serialization.Resources.dll
[2013/08/10 02:55:16 | 000,029,896 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization.xml_b03f5f7f11d50a3a_4.0.9600.16384_none_0d0d9cf22bac10f4\System.Runtime.Serialization.Xml.dll
[2014/09/12 15:02:11 | 000,018,929 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.16384_none_c8108d2e85eed25d\System.Runtime.Serialization.dll
[2014/07/24 05:20:32 | 001,059,536 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.17238_none_c80b32a685f3b704\System.Runtime.Serialization.dll
[2014/09/12 15:02:13 | 000,004,122 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_4.0.9600.20720_none_b13d3f669f9b34c8\System.Runtime.Serialization.dll
[2014/08/18 13:18:39 | 000,000,661 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.16384_none_1d733470a3e98f24\System.Runtime.Serialization.dll
[2014/09/12 15:02:15 | 000,000,436 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.17226_none_1d6d072ea3ef2732\System.Runtime.Serialization.dll
[2014/07/09 03:45:06 | 000,970,752 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.17231_none_1d6e7960a3edc064\System.Runtime.Serialization.dll
[2014/08/18 13:18:41 | 000,000,433 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.20708_none_069d2fd4bd988be9\System.Runtime.Serialization.dll
[2014/09/12 15:02:16 | 000,000,632 | ---- | M] () -- \Windows\WinSxS\msil_system.runtime.serialization_b77a5c561934e089_6.3.9600.20717_none_069e46e6bd978b9f\System.Runtime.Serialization.dll
[2013/08/10 02:55:49 | 000,045,720 | ---- | M] () -- \Windows\WinSxS\msil_system.xml.serialization_b77a5c561934e089_4.0.9600.16384_none_5aaf0d34c0033202\System.Xml.Serialization.dll
[2013/08/10 02:55:49 | 000,029,848 | ---- | M] () -- \Windows\WinSxS\msil_system.xml.xmlserializer_b03f5f7f11d50a3a_4.0.9600.16384_none_3cc4c9f9340d8755\System.Xml.XmlSerializer.dll
[2014/08/18 13:29:11 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_54cc2f7ac6efa85c\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013/08/17 02:06:37 | 000,011,776 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.17226_cs-cz_550ef6e8c6bd4fde\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2014/08/18 13:29:14 | 000,000,012 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.3.9600.20708_cs-cz_55b0527fdfc8c56f\System.Runtime.Serialization.Formatters.Soap.resources.dll
[2013/11/14 14:23:17 | 000,005,120 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-u..em-config.resources_31bf3856ad364e35_6.3.9600.16384_cs-cz_e30aa618ff4459ba\serialui.dll.mui
[2013/08/22 05:48:16 | 000,015,872 | ---- | M] () -- \Windows\WinSxS\x86_microsoft-windows-unimodem-config_31bf3856ad364e35_6.3.9600.16384_none_89a166153a4451f7\serialui.dll
[2014/08/18 13:32:34 | 000,000,661 | ---- | M] () -- \Windows\WinSxS\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.16384_none_224de03de4c02966\System.Runtime.Serialization.dll
[2014/09/12 15:10:15 | 000,000,436 | ---- | M] () -- \Windows\WinSxS\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17226_none_2247b2fbe4c5c174\System.Runtime.Serialization.dll
[2014/07/09 03:45:06 | 000,970,752 | ---- | M] () -- \Windows\WinSxS\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.17231_none_2249252de4c45aa6\System.Runtime.Serialization.dll
[2014/08/18 13:32:36 | 000,000,433 | ---- | M] () -- \Windows\WinSxS\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20708_none_0b77dba1fe6f262b\System.Runtime.Serialization.dll
[2014/09/12 15:10:17 | 000,000,632 | ---- | M] () -- \Windows\WinSxS\x86_wcf-system.runtime.serialization_b03f5f7f11d50a3a_6.3.9600.20717_none_0b78f2b3fe6e25e1\System.Runtime.Serialization.dll

< *w7lxe* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\light_square\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\light_rounded\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\facebook\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\default\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\dark_square\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\dark_rounded\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\light_square\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\light_rounded\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\facebook\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\default\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\dark_square\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\dark_rounded\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\1. ŠKOLA\PSIT\Cisco\DIR příkaz - konfigurace switche skrz BOOT LOADER.PNG:ms-properties
@Alternate Data Stream - 314 bytes -> C:\WINDOWS\Fonts\+KAMIKZOM.ttf:ms-properties
@Alternate Data Stream - 314 bytes -> C:\WINDOWS\Fonts\+gunplay.ttf:ms-properties
@Alternate Data Stream - 314 bytes -> C:\WINDOWS\Fonts\+3rd Man.otf:ms-properties
@Alternate Data Stream - 314 bytes -> \Users\Martin\SkyDrive\Dokumenty\1. ŠKOLA\PGRF\Komprese projekt\c05_stepanek_martin\c05_stepanek_martin\src\c05_stepanek_martin\Img32Loader.java:ms-properties
@Alternate Data Stream - 237 bytes -> C:\Users\Martin\SkyDrive:ms-properties

< End of report >

Lothaire
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 pro 2009 21:20

Re: Preventivka s menším podezřením

#14 Příspěvek od Lothaire »

A konečně Extras:

OTL Extras logfile created on: 21. 10. 2014 15:44:12 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Martin\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17351)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d. M. yyyy

7,86 Gb Total Physical Memory | 3,03 Gb Available Physical Memory | 38,56% Memory free
12,61 Gb Paging File | 5,32 Gb Available in Paging File | 42,22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 883,50 Gb Total Space | 187,04 Gb Free Space | 21,17% Space Free | Partition Type: NTFS
Drive D: | 25,00 Gb Total Space | 21,15 Gb Free Space | 84,59% Space Free | Partition Type: NTFS

Computer Name: CHECKPOINT | User Name: Martin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS6\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS6\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05FA6173-56F2-4B52-B59A-AAF1EE13D131}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{11C54761-D7AE-4524-B19D-56B27B7550D2}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{12A17E0B-C8E7-418E-BB7F-EEF1481E4C5C}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |
"{12EB3CE1-79C8-40BC-8738-6ADC1B2A3B21}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1A72A1D4-39F9-4444-80B5-B6BDE0620893}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{208127A0-9BC8-4AEE-BD0E-D78A4717E7E1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{20F5C9D8-C9F7-4897-B4B1-4CA05712260B}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{2A8CBA40-B701-4B40-9EC8-DDFFAD5320F6}" = rport=137 | protocol=17 | dir=out | app=system |
"{2C03A367-5BDF-4D33-BB83-F3A289529315}" = lport=139 | protocol=6 | dir=in | app=system |
"{35C9C3E2-3CE9-421C-AFAF-37CD5A018EBC}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{37C2FB67-82EC-4E08-86CB-813890D7ABE3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{39497E40-B80B-4A69-B371-96A4ACB672D2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{3CBE9F57-B6FA-47C5-91A8-607C787D1F4D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4367E9B1-3B21-4714-B61F-2480B2699A01}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office15\outlook.exe |
"{43B6129F-048C-4E94-9B73-D26B6B05F109}" = lport=2869 | protocol=6 | dir=in | app=system |
"{476FD7E4-2762-44F0-A5A5-8763C32751A8}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{52037BF3-FE7B-4CB8-BD62-B2C1D04B470F}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{6460737A-FC40-41E7-B45D-C9CA0F89D193}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{69D4806D-2E01-4296-BB11-14E2D82AA568}" = rport=10243 | protocol=6 | dir=out | app=system |
"{6AF5386B-A011-4D8E-8C05-A7BFA0E8FDB6}" = lport=445 | protocol=6 | dir=in | app=system |
"{74C9BBA9-6662-462D-8E66-181F90CAC5A4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{77A03DA4-4F9F-445B-947C-993CEF063624}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{8B4E242B-6054-4E88-9227-401C1E90C286}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8EA7323B-0914-4507-9319-C13F7133F91E}" = lport=138 | protocol=17 | dir=in | app=system |
"{9342A9D6-4A6A-47BA-92BA-364F92213AF3}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{93BEFC9D-A5A2-4500-B132-2DBE99E0599D}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{998D2AAB-D373-4283-98DF-0741B6610CA7}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |
"{9AACF240-62B4-4B74-A531-564A4232855A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9E378FB2-29D3-4445-B280-F707D31E1F99}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A7588F44-2D32-406A-88AF-09E6FAC592C2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AA59AEAC-70C1-4CA1-95F1-604EF735FEA2}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |
"{AEA0C64C-4016-44CF-A0C2-B0C167172699}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\dashost.exe |
"{B27C5D06-22EC-4893-B33A-9AA3BB9D39BD}" = lport=137 | protocol=17 | dir=in | app=system |
"{B3201D1B-E97B-4BC2-95A0-EE881B1D94C7}" = rport=2869 | protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B83A5222-ACD3-481C-9A03-B5C8E806F320}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{C17258B6-A851-4355-B4EC-016B2520CC7D}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{C549BBB4-3030-4DFA-89FE-24367814E25D}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{CCC4CF31-9499-4E36-93FE-EE4E8B0E58FD}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D11C044E-E331-4EBD-86A3-AFB3CB2C41EC}" = rport=139 | protocol=6 | dir=out | app=system |
"{D27F3EF7-8FFC-49DA-9D2E-EB022D8D90F4}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{D45F4ADB-12B1-49AE-AD8F-C5F8605269A0}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |
"{DD92FCB4-0D78-4968-932A-A0F049E2ABF2}" = rport=445 | protocol=6 | dir=out | app=system |
"{DDA35729-02C2-4304-9195-750EA7D96616}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe |
"{DDEFE4DE-0E2D-4B9E-BE55-9CAFE58D2A98}" = lport=10243 | protocol=6 | dir=in | app=system |
"{DE3E8C4D-42E4-4885-B9F4-D664D8175B84}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{E04DF353-0D1F-4E5B-9232-FAC1FE50F9EE}" = lport=7935 | protocol=6 | dir=in | name=adobe flash builder 4.6 |
"{E110FA3D-72B8-4918-9706-96A4807DF3CB}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{EA0D5816-F3A9-494A-BB29-C1DC3F9A21DD}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |
"{F226864A-A0BB-4428-A250-A1229F3E32DB}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |
"{F28E8A97-C1BF-445D-9226-C986F59A0A1E}" = rport=138 | protocol=17 | dir=out | app=system |
"{F3EDDD0D-94F2-4BAA-84AA-BE8E0B5A2EB8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FD317229-E214-4CB0-B616-F1D555824C50}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{000046D3-736C-4A7D-9151-1508A2D27743}" = dir=out | name=@{microsoft.bingnews_3.0.4.213_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
"{00E1DBF3-6209-46D4-87FE-8C066E23ED97}" = dir=in | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{05C5F728-4746-45D1-AECA-50FABEDE6E11}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nosgoth\binaries\win32\nosgoth.exe |
"{08FE0044-7F71-4954-98F8-C47A636E5AE7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{09787FE1-FB29-4B4D-A741-92F45CF1C871}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2\trine2_launcher.exe |
"{0992C60F-E77C-4CEE-8CFC-FA825B6EE7FE}" = dir=out | name=juniper networks junos pulse |
"{0AD534E2-E0D6-4FA7-820F-4953027EF438}" = protocol=17 | dir=in | app=c:\users\martin\appdata\roaming\utorrent\utorrent.exe |
"{0CE5B665-28F5-4E6F-9489-F46D62F78744}" = dir=in | name=juniper networks junos pulse |
"{0D40E89E-11E4-4711-A004-22D21B904E55}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{0DB448CC-5BCB-418B-8F57-E9DF74CCAE92}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{0E13AD59-44C6-4968-A99A-BC2FFAE70407}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\plants vs. zombies\plantsvszombies.exe |
"{0EF9BADB-547A-4C42-85CA-9F6656D9C40F}" = protocol=6 | dir=in | app=c:\users\martin\documents\4. programy\eclipse-standard-kepler-sr1-win32\eclipse\eclipse.exe |
"{0FA607D7-298B-48C5-B95F-1FE61B957106}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{0FCB56BD-DDD2-4300-8CBC-F830FA97F370}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\free to play\ftp.exe |
"{13DFD5E6-AC60-4D77-8262-06E0B82921D8}" = protocol=6 | dir=in | app=c:\program files (x86)\adobe\adobe flash builder 4.6\flashbuilder.exe |
"{193F854D-9960-4544-8CB3-0E6400092126}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\galaxy on fire 2 hd\gof2launcher.exe |
"{1A1116C4-4843-4793-8834-E6D182E611AC}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe |
"{1CE47A40-87D6-4237-A406-F68A287BB363}" = dir=out | name=@{microsoft.bingtravel_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
"{1D76CB83-DD78-4080-9C95-8AA5FD8B5B65}" = protocol=17 | dir=in | app=c:\users\martin\documents\4. programy\eclipse-standard-kepler-sr1-win32\eclipse\eclipse.exe |
"{1EA42505-ED48-4E0D-8684-7B42F7473BC0}" = protocol=6 | dir=out | app=system |
"{208C6DC4-56A3-4F97-A064-64278C3184EB}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe |
"{21FEF23D-B34A-473B-BD93-0F09CB38C510}" = dir=out | name=@{microsoft.zunevideo_2.6.344.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{2383E535-0D7A-407C-9609-CA9A914C59CC}" = protocol=17 | dir=in | app=c:\program files\vmware\vmware view\client\bin\wswc.exe |
"{24938043-CE80-46F2-8958-EF33A8177136}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2638\agent.exe |
"{26BD75B5-C7AF-43E4-82F7-39190B23891A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{27F9548B-3A8C-43AE-93FF-5EF0D982CE1D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{294DE9A7-D15F-4636-A414-15EE07B0E5E9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{2A0E89D7-06D2-4D1C-8180-8502EF68CC65}" = protocol=17 | dir=in | app=c:\program files (x86)\warthunder\launcher.exe |
"{2A587248-2118-4CE2-8EB3-0C8083B7C666}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe |
"{2CDE386B-C423-49A5-8DAF-B9A33B12432C}" = protocol=17 | dir=in | app=c:\program files\kmspico\kmseldi.exe |
"{2D9E79FE-C49E-4028-8FE3-82F732417E7E}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office15\ucmapi.exe |
"{3166F63E-38A6-4602-AA77-0F3F9019B591}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{3190FF1E-C59D-4B27-BD77-A2D0A12544A6}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2638\agent.exe |
"{32580797-BA05-4869-AA29-942387E16342}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fable the lost chapters\fable.exe |
"{33F0745C-7141-43C6-A3D8-CA09E1D48D8D}" = dir=out | name=@{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{340D1AFB-4B85-4F33-ADDB-F94183EBAD00}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{344933D8-0343-4073-B848-C390DE7AE379}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\might & magic - duel of champions\game.exe |
"{366027BE-5F40-49D5-B3FD-85AEF34E707D}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{393D5B4F-6442-4A73-A033-51BDEF6D2C7F}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{39BE001A-4241-49CF-9B05-C5897138807C}" = dir=out | name=windows_ie_ac_001 |
"{39F62F93-D95F-45C7-9FD1-AAC023085254}" = dir=out | name=windows_ie_ac_001 |
"{3BA111A4-C862-45AC-86C3-3A9146B1CB46}" = dir=out | name=lenovo support |
"{3DC02124-45E6-4A85-8379-D4F623FEA48A}" = dir=out | name=companion |
"{3DFF791E-D209-401C-8F58-FD79AA49B768}" = dir=out | name=@{microsoft.bingsports_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
"{4038350F-B949-43A2-B80D-0312A2E62255}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2\trine2_launcher.exe |
"{414D906F-1C4D-47AF-8618-AEBDFA1F74DC}" = dir=out | name=powerdvd for lenovo idea |
"{41CC5519-BCEE-4EFC-9A35-2F2085D7843A}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer_service.exe |
"{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn |
"{42ED018A-EFEC-495B-B271-FA485D2788B6}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office15\lync.exe |
"{4363AEB0-3D90-4E93-9006-D5EC49327FD3}" = dir=out | name=windows_ie_ac_001 |
"{46FBE658-0D43-4CAA-A787-F46BF5ED75B2}" = protocol=6 | dir=in | app=c:\users\martin\appdata\roaming\utorrent\utorrent.exe |
"{47BF7A8B-27EE-4C74-AF6F-0D222E118505}" = dir=out | name=@{microsoft.bingfinance_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
"{49B1CE3E-9EA2-432E-9D63-1AD9F6962C8E}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfmp.exe |
"{4A940B17-C785-4425-BEF8-4F8A00BCEC4C}" = dir=out | name=sonicwall mobile connect |
"{4DC3D23B-2B7E-468E-BE6E-CE5C416A514A}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} |
"{4E9D3DD6-43E1-4ED8-9A17-2C251309EDCF}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{4EBD2B26-F5FE-449F-8DEA-25AF7DB0934F}" = protocol=6 | dir=in | app=c:\program files\vmware\vmware view\client\bin\wswc.exe |
"{5108DAE2-989B-4595-8E40-E101BBCBCBCD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect |
"{56AB8E51-157F-45EA-AD7D-EFCFC37A6F14}" = dir=out | name=f5 vpn |
"{57987123-06B4-47E0-B0B0-17AF081DDB33}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{57F5505A-1804-4BCA-989C-2F743C812A67}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office15\lync.exe |
"{5858EA3B-E81D-4C1E-B8A3-D67F431BCA64}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office15\ucmapi.exe |
"{59E3A44C-4B33-480D-A75A-05272E5425DA}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office15\lync.exe |
"{5A33F50F-DB55-41E1-830F-43209660FE8F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect |
"{5F4A27BE-155A-457B-B2B3-0BE116F0FB67}" = dir=in | name=sonicwall mobile connect |
"{5FE3AF78-5AB2-47C5-918C-74D82DFED4C6}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{60856C29-B261-4E88-AB6D-B31FE43B97AC}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{62E39EF9-78FC-4BF6-919D-EB48B65F0F53}" = dir=out | name=@{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} |
"{63FEFB40-3BC0-480A-9D58-C6947AB9BF6C}" = dir=out | name=evernote touch |
"{640CA85F-C191-458A-8258-376CDE8CAB54}" = protocol=17 | dir=in | app=c:\program files\kmspico\service_kms.exe |
"{653ECD2D-D072-4434-A3D6-02E9B1AFA642}" = dir=in | name=f5 vpn |
"{65E4E0AD-42BF-4C86-AE95-3CDB2ACDD058}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{68B17239-53D6-4D17-97A9-666F3AA774C6}" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{68EF4D54-A5C8-4DE1-A75B-56C4FE56EE5D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3427\agent.exe |
"{699C2DBF-FA09-4815-94F1-C4C4416F1410}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{6D65BF25-38EF-4890-91F3-6C666636DC2A}" = protocol=6 | dir=in | app=c:\program files\vmware\vmware view\client\bin\vmware-remotemks.exe |
"{6F31BD66-A55E-4C6B-B79E-E44312846A27}" = dir=out | name=@{microsoft.binghealthandfitness_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} |
"{6F917283-0852-4DAB-9934-84A8C62D1BAF}" = protocol=17 | dir=in | app=c:\program files\vmware\vmware view\client\bin\vmware-remotemks.exe |
"{709183E0-1CE4-49D7-A3DA-58B0657F5648}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{71C498AB-9B60-4F24-B6B1-CEDB23F5E2F2}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} |
"{7245CFF2-5C8E-448C-BCFD-18545A2D61FB}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\games\the crew (beta)\thecrew.exe |
"{7482B3A5-296C-49BE-B014-D063B2A2777B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{751EE065-1362-436F-977B-1B7C56608A7B}" = protocol=17 | dir=in | app=c:\program files\vmware\vmware view\client\bin\vmware-remotemks.exe |
"{771D8483-5AC7-4B93-B25D-9390A4757870}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2638\agent.exe |
"{773A6E80-C11D-4802-B530-F4F7BE1852E6}" = dir=out | name=check point vpn |
"{77694B6F-9CE9-42BE-99F0-A0513A857709}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{776A7CBA-483B-4AD7-A572-49AB9B5D2DAD}" = protocol=6 | dir=in | app=c:\program files (x86)\gameforgelive\gfl_client.exe |
"{7886A591-D0F1-465D-98AC-4A40152C1DC7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe |
"{7B545570-338E-47E5-A6A9-1D1E1AB1E9E9}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{7C673F05-70DE-4A5D-889B-0EED483B6214}" = dir=out | name=@{microsoft.zunemusic_2.6.343.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{7CC81C0C-FB5C-4AD2-9F34-395C43CA8D91}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{829016D4-7AB5-44B8-994A-B995CD17E4B2}" = dir=in | name=evernote touch |
"{83DB2A30-30FE-4D96-995A-D46C221B9B51}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{845264E4-3895-408C-A256-542FA2F06DC6}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{86D84D7C-D14C-4CC5-9F0A-C7322DC3BF6F}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{8790C01A-2275-4F31-B7C8-1E453A52FDC9}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{87ECAEEF-438E-4512-8151-D1730C03134B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3427\agent.exe |
"{881116B5-0C54-4FA2-BB04-924A2B8F4DEF}" = dir=out | name=@{12199asparion.asparioncalculator_3.2.1.37_neutral__f89vgcf3qm37t?ms-resource://12199asparion.asparioncalculator/resources/spackagename} |
"{8CB258DB-E179-4841-8AE1-82952F129B8B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3478\agent.exe |
"{9322355D-3A8A-402A-8A35-EA000CF0A7BD}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{96ED7086-2204-43AD-9968-4346F2C58634}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{975D2171-16A2-4220-A45D-FC7710F664D2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\chivlauncher.exe |
"{9964C3C5-9556-4C9C-82BA-7885A4069E2D}" = protocol=6 | dir=in | app=c:\program files\vmware\vmware view\client\bin\vmware-remotemks.exe |
"{9A74BA8C-7128-4AFA-B3FE-F96A88E22E39}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3346\agent.exe |
"{9B6C7AF0-7807-4301-A65B-3FADFB27ECCD}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{9BB08C68-1B7A-4C14-BBB7-D9DE26A2EF97}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9CED10A3-C1BC-41F4-804C-6F98034D5825}" = dir=out | name=accuweather for windows 8 |
"{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{9FAE63CC-DE8E-4D22-944B-0EB7C20016A5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\bin\steamwebhelper.exe |
"{9FF71672-5B1C-4032-994A-E35726838531}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{A31128B6-793B-4A3A-ABD0-FE378A247D03}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{A413A7AF-95FB-43C9-8ADA-BB8B6425B401}" = protocol=6 | dir=in | app=c:\program files\kmspico\kmseldi.exe |
"{A4CB13B6-88B7-4199-9048-3540F6BFB129}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A503BB47-C33C-4231-AE72-D8F6547FE663}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{A590AE95-1CB9-4DB0-9B74-618DB9352E7E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A68A6496-6C01-4B2D-9732-9C9BD88E35AE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{A7533AA8-A24C-4186-90F1-3EE476E17CF9}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{AA84B3E6-9071-46B1-8A54-B814F0AE48A2}" = protocol=6 | dir=in | app=c:\program files\vmware\vmware view\client\bin\wswc.exe |
"{AB6BD53A-E020-407F-B7BA-387701A0506F}" = dir=in | app=c:\program files (x86)\lenovo\powerdvd10\powerdvd cinema\powerdvdcinema10.exe |
"{AB6ECA75-00E3-416F-B60D-306F62277E48}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{AC96324F-5D68-4C64-87D1-851B33111D12}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforever.exe |
"{AD23CC23-3DE1-4DFD-8684-08C6F4D5A864}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\chivlauncher.exe |
"{AFCC0A7A-AC85-459E-AAF0-E73206C8A365}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{B068A56E-59C0-4F47-8898-0FB9FEF17A3A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
"{B1780339-2ECF-47F3-8D86-C860888A9234}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{B20A630D-2DFF-4150-BEFF-54CE3EC67749}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3478\agent.exe |
"{B5D306DA-69B5-476B-9362-A3EE8DCBE74C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
"{B62ED1CA-2D7D-4D77-AD91-D461CB36B4DE}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2514\agent.exe |
"{B6358865-13EC-4D66-B9F2-68F5B9C39058}" = dir=out | name=@{microsoft.bingweather_3.0.4.214_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} |
"{B7D745E1-399C-4DCB-BFC3-003C9F6D129F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2514\agent.exe |
"{BCA5809C-01D9-4369-A6A8-86F00B1AC31C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\galaxy on fire 2 hd\gof2launcher.exe |
"{BD68F84B-0B03-4A57-8480-F569BE808A43}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nosgoth\binaries\win32\nosgoth.exe |
"{BEB7BE90-B5F0-4C6B-BD6C-8CCA09A70FCF}" = protocol=17 | dir=in | app=c:\program files (x86)\adobe\adobe flash builder 4.6\flashbuilder.exe |
"{C01DC705-9C2B-434A-90C3-49F12257FFD9}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{C080018B-6614-40BA-B78D-067780C89467}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\might & magic - duel of champions\game.exe |
"{C0B5857F-31B9-41AE-9926-D03057792C59}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{C332432A-AA47-4FA2-81B6-2D37A7794F47}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fable the lost chapters\fable.exe |
"{C5626520-07BC-4A7C-AF3C-1DD21643A284}" = protocol=17 | dir=in | app=c:\program files\vmware\vmware view\client\bin\wswc.exe |
"{C82612B5-B306-4C8E-AE62-75DADB3D3CB2}" = dir=out | name=@{15912pengsong.45018a83264eb_1.2.2.0_neutral__vm3wjdvy9nfky?ms-resource://15912pengsong.45018a83264eb/resources/applicationdisplayname} |
"{C859D998-9DCC-423D-A06D-964D0BDA268F}" = dir=in | name=check point vpn |
"{C9C9F711-24A1-431C-AF7F-264FBC32646A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magickawizardwars\wizardwarslauncher.exe |
"{C9CC6C32-1389-453E-92F6-134BA3318863}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{CB9896C4-C6BC-4AAD-BD2D-3EF50936849C}" = dir=out | name=@{microsoft.bingfoodanddrink_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} |
"{CCFCE463-9E52-441C-A729-448B82912FF6}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\games\the crew (beta)\thecrew.exe |
"{CDEA4141-62D9-4066-8308-5DF1427E7C95}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CEBCC48A-504D-4351-A231-F40460AB1BE1}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{CF6173C8-6841-4283-B065-B5460CF8E9FD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{D13FE79E-17E1-4FF0-9104-5B3E4DDC47A0}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{D3A85FD1-2093-409C-ADD1-85FF251C4C3D}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{D56575D2-0CE8-4283-950E-49B39418B8BD}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe |
"{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn |
"{D71C5028-036D-4649-9072-B3FA919F2811}" = dir=in | name=powerdvd for lenovo idea |
"{D7359598-6816-44F8-B407-6C7DB3D4755E}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfmp.exe |
"{DB4809C3-198A-4438-927A-17D04268448D}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office15\lync.exe |
"{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn |
"{DDECEBD5-D74E-4D71-A20D-F9BFB0EEE6DA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{DF5453A7-C292-4A38-86C8-6EA936BDA5BF}" = dir=out | name=facebook |
"{E071AF6C-C3BC-4CC0-BEA5-211D67D8C350}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E09DCAF3-1A51-47EB-91FD-E65AA81AFB64}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforever.exe |
"{E27F7D69-7CD9-43E7-A429-A6639672288F}" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{E3007FF1-3866-43B0-A532-11C215EE84B3}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office15\ucmapi.exe |
"{E3D9612D-DEAA-4681-B001-9434709C5E2E}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E71497BF-F486-4783-83A7-2D0E74F2083F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\free to play\ftp.exe |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{E7D21C66-21C7-42CC-8824-520CB0378202}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{EC6DAC71-57C5-4398-BDAD-1A158940E979}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version9\teamviewer.exe |
"{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn |
"{ED729E31-5058-483C-948C-18115A3E7798}" = protocol=6 | dir=in | app=c:\program files\kmspico\service_kms.exe |
"{F14A5B46-0868-4CDB-B986-FB311D08DDE0}" = dir=in | app=c:\program files (x86)\lenovo\powerdvd10\powerdvd10.exe |
"{F2D27515-E751-4E48-B8FD-8BEEB5EEC961}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magickawizardwars\wizardwarslauncher.exe |
"{F341A54C-7F3B-42A4-8C7B-6AD6706D83A8}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2638\agent.exe |
"{F40D32D3-2643-4348-80D8-FC720A2DB6E4}" = protocol=6 | dir=in | app=c:\program files\kmspico\service_kms.exe |
"{F55077C4-41F1-4518-B292-9FBCC57B810F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3346\agent.exe |
"{F5C4429A-7EC4-4D6C-AD93-C51DFE564108}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office15\ucmapi.exe |
"{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client |
"{F6E9B3B4-DC9A-4C6D-8D93-F5791F9A0336}" = protocol=6 | dir=in | app=c:\program files (x86)\warthunder\launcher.exe |
"{F7777022-8FEC-4BA4-A231-32CA2DEDEE1C}" = protocol=17 | dir=in | app=c:\program files\kmspico\service_kms.exe |
"{F77C3155-877D-4C6E-85A5-FDE55DBB3DFB}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\plants vs. zombies\plantsvszombies.exe |
"{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client |
"{FB208F98-0ED6-4402-A421-6B1DB8ABB010}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nosgoth\binaries\win32\nosgoth.exe |
"{FBD6B060-57CE-458B-A000-ABEA9C957F45}" = dir=out | name=@{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{FC2C38B9-99DD-4DCF-B2BF-E4043765823F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nosgoth\binaries\win32\nosgoth.exe |
"{FDB07EE5-2A7D-4FA0-9608-9F9F2FC6D601}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FDEED9C3-8B29-43A6-A2A1-F30F89DF2BD9}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FF860631-CB91-4649-8088-731604C34B50}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"TCP Query User{0100B222-5047-4CD9-8713-48B99544C488}C:\program files (x86)\hearthstone\hearthstone.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"TCP Query User{1563D003-BC94-4876-AD7E-E64572F77156}C:\users\martin\appdata\local\id software\quakelive\quakelive.exe" = protocol=6 | dir=in | app=c:\users\martin\appdata\local\id software\quakelive\quakelive.exe |
"TCP Query User{187819BA-84D5-42AF-A327-0D06BAF225FA}C:\users\martin\documents\4. programy\eclipse-standard-kepler-sr1-win32\eclipse\eclipse.exe" = protocol=6 | dir=in | app=c:\users\martin\documents\4. programy\eclipse-standard-kepler-sr1-win32\eclipse\eclipse.exe |
"TCP Query User{2D74C57D-545F-4414-AAA8-9D7F42D98518}C:\program files\vmware\vmware view\client\bin\vmware-remotemks.exe" = protocol=6 | dir=in | app=c:\program files\vmware\vmware view\client\bin\vmware-remotemks.exe |
"TCP Query User{3449726E-74F7-4366-8127-BCE17D4D0283}C:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe |
"TCP Query User{36BD44BD-7FC2-4F18-8698-B648E801CCB8}C:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe |
"TCP Query User{5FB92B99-8322-41D2-AB60-045531E6473C}C:\program files (x86)\divinity original sin\shipping\eocapp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\divinity original sin\shipping\eocapp.exe |
"TCP Query User{6B66D7C4-F8D7-485C-99E0-7E1FD7389D60}C:\program files (x86)\in verbis virtus\binaries\win32\udk.exe" = protocol=6 | dir=in | app=c:\program files (x86)\in verbis virtus\binaries\win32\udk.exe |
"TCP Query User{6C4F2876-0554-4E81-A4F9-E587C5256463}C:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe |
"TCP Query User{7A1BB92D-AFEA-41EB-8D86-15A63BBAD27B}C:\program files (x86)\netbeans 7.4\bin\netbeans64.exe" = protocol=6 | dir=in | app=c:\program files (x86)\netbeans 7.4\bin\netbeans64.exe |
"TCP Query User{8105B57D-A30D-443C-A3D7-68A3BBC249A6}C:\program files (x86)\steam\steamapps\common\trine 2\trine2_32bit.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2\trine2_32bit.exe |
"TCP Query User{852C53C0-006E-4C89-8B66-187D9C28B3CE}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=6 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe |
"TCP Query User{877E4C5C-BD23-43DD-8AFA-2A1BF02CE3AA}C:\program files (x86)\tera\tera-launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |
"TCP Query User{89A616E1-3AFA-439B-94DC-274C432426BE}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfmp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfmp.exe |
"TCP Query User{8B722471-2F06-4478-B524-A211A9D8D61A}C:\program files (x86)\need for speed rivals\nfs14.exe" = protocol=6 | dir=in | app=c:\program files (x86)\need for speed rivals\nfs14.exe |
"TCP Query User{933EECEA-C712-45C9-9852-07FAAD09B0B8}C:\windows\system32\javaw.exe" = protocol=6 | dir=in | app=c:\windows\system32\javaw.exe |
"TCP Query User{95EE4BA3-6B8C-47AF-9010-F7B9B2CC8155}C:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe |
"TCP Query User{A29989C2-F3C7-49E8-BC7E-46ACCFF45CE2}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe |
"TCP Query User{AAC1CFD1-6116-4CCC-A4C0-DC67FB7B35C6}C:\program files (x86)\warthunder\aces.exe" = protocol=6 | dir=in | app=c:\program files (x86)\warthunder\aces.exe |
"TCP Query User{AB5AF60A-2DC9-46A3-828D-7CF47FDD7ADC}C:\program files (x86)\need for speed rivals\nfs14_x86.exe" = protocol=6 | dir=in | app=c:\program files (x86)\need for speed rivals\nfs14_x86.exe |
"TCP Query User{AE8074C9-DF7D-4A54-A98F-248F86970EB4}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{B5FB20C5-2E5F-4B7F-8AB9-B8DBF4D56FBB}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{BD7E2C2F-44EC-481D-9394-5612F3391E5C}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{BDA3C2AE-752E-4632-B8BD-E028BF792E22}E:\easysetupassistant\easysetupassistant.exe" = protocol=6 | dir=in | app=e:\easysetupassistant\easysetupassistant.exe |
"TCP Query User{BE53D98B-D700-43E4-ADCF-1EEF4708BB2A}C:\program files (x86)\warthunder\launcher.exe" = protocol=6 | dir=in | app=c:\program files (x86)\warthunder\launcher.exe |
"TCP Query User{C33D0941-60BA-4EB4-87CB-26690C8475F6}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe |
"TCP Query User{E44588A9-D0CB-448F-ABC9-F98EC2089C38}C:\program files (x86)\saints row iv\saintsrowiv.exe" = protocol=6 | dir=in | app=c:\program files (x86)\saints row iv\saintsrowiv.exe |
"TCP Query User{E8F3DBDA-A22D-4188-AC6F-EA8D08E0AED9}C:\program files (x86)\jdownloader\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\jdownloader\jre\bin\javaw.exe |
"TCP Query User{F13E2283-E22C-4DD4-B9C6-51BB89C96135}C:\program files\vmware\vmware view\client\bin\wswc.exe" = protocol=6 | dir=in | app=c:\program files\vmware\vmware view\client\bin\wswc.exe |
"TCP Query User{FCC9DFE0-E360-4158-8336-F7A6996FFAFE}C:\program files (x86)\guild wars 2\gw2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"UDP Query User{0A6DB6D8-CBA4-4A7A-948C-6DDDDE05C723}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=17 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe |
"UDP Query User{1486EAB6-FF71-4505-ADF8-0BAA74C1C8D2}C:\program files (x86)\need for speed rivals\nfs14_x86.exe" = protocol=17 | dir=in | app=c:\program files (x86)\need for speed rivals\nfs14_x86.exe |
"UDP Query User{1A387CC3-A968-4613-8EEC-A6FF05680C09}C:\program files (x86)\tera\tera-launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tera\tera-launcher.exe |
"UDP Query User{1EBCD0AB-940D-409A-AC28-A3E9D866D16F}C:\program files (x86)\jdownloader\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\jdownloader\jre\bin\javaw.exe |
"UDP Query User{2BE43FCB-555A-4E61-9C2B-66D1B5208D61}C:\program files (x86)\divinity original sin\shipping\eocapp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\divinity original sin\shipping\eocapp.exe |
"UDP Query User{306DF108-B616-404C-9B33-D3D89F3A8D44}C:\program files (x86)\steam\steamapps\common\trine 2\trine2_32bit.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine 2\trine2_32bit.exe |
"UDP Query User{38434D9C-2FB1-46EE-9717-4D1450DD235C}C:\program files (x86)\hearthstone\hearthstone.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"UDP Query User{38CB6E65-C5C6-4381-93F3-2FEA02810B73}C:\program files\vmware\vmware view\client\bin\vmware-remotemks.exe" = protocol=17 | dir=in | app=c:\program files\vmware\vmware view\client\bin\vmware-remotemks.exe |
"UDP Query User{3B166FA9-DD09-4644-BF60-D4C24FC26FE4}C:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magickawizardwars\bitsquid_win32_dev.exe |
"UDP Query User{4400C463-BC3B-4420-9950-0BDA55C1429B}C:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe |
"UDP Query User{459CACCF-27DE-4CBD-8CF9-A4F5A8382585}C:\windows\system32\javaw.exe" = protocol=17 | dir=in | app=c:\windows\system32\javaw.exe |
"UDP Query User{476DFD1F-DDDC-41EE-8704-61C6E04BAD0D}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{5013BBD9-7669-4276-9BE9-4D445E970D39}C:\program files (x86)\saints row iv\saintsrowiv.exe" = protocol=17 | dir=in | app=c:\program files (x86)\saints row iv\saintsrowiv.exe |
"UDP Query User{523B608B-AF94-4922-8B00-F6C88C29C916}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfmp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfmp.exe |
"UDP Query User{632514B9-C506-4356-8409-7C44AD23634E}C:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed iv black flag\ac4bfsp.exe |
"UDP Query User{6E9B6BA1-1AB7-4A3A-8A34-94A6BD42F4D9}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe |
"UDP Query User{6EB2C631-6EE4-4C00-89AC-AEAF5A485AE2}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{706ACC59-0359-4996-A268-99F74CD9E402}C:\users\martin\documents\4. programy\eclipse-standard-kepler-sr1-win32\eclipse\eclipse.exe" = protocol=17 | dir=in | app=c:\users\martin\documents\4. programy\eclipse-standard-kepler-sr1-win32\eclipse\eclipse.exe |
"UDP Query User{721B8045-E0B5-4904-A446-CC38B2C3D81E}C:\users\martin\appdata\local\id software\quakelive\quakelive.exe" = protocol=17 | dir=in | app=c:\users\martin\appdata\local\id software\quakelive\quakelive.exe |
"UDP Query User{76CD7A48-0FD5-4973-8DE2-FA37FFD427E5}E:\easysetupassistant\easysetupassistant.exe" = protocol=17 | dir=in | app=e:\easysetupassistant\easysetupassistant.exe |
"UDP Query User{7A9AE197-F8FA-489D-A1A7-C56CB883403F}C:\program files (x86)\guild wars 2\gw2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\guild wars 2\gw2.exe |
"UDP Query User{81182EB7-31FA-4E87-92DB-3842CDC0C798}C:\program files\vmware\vmware view\client\bin\wswc.exe" = protocol=17 | dir=in | app=c:\program files\vmware\vmware view\client\bin\wswc.exe |
"UDP Query User{84683BE3-DC57-46C7-9127-BE3B6A614870}C:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe |
"UDP Query User{888BBF36-930E-4B47-8506-55F57BF1BFBB}C:\program files (x86)\warthunder\aces.exe" = protocol=17 | dir=in | app=c:\program files (x86)\warthunder\aces.exe |
"UDP Query User{8E2D4128-4860-4541-857C-6A83369E48E5}C:\program files (x86)\need for speed rivals\nfs14.exe" = protocol=17 | dir=in | app=c:\program files (x86)\need for speed rivals\nfs14.exe |
"UDP Query User{ABD30661-C601-46EC-B921-730D321C3A4C}C:\program files (x86)\in verbis virtus\binaries\win32\udk.exe" = protocol=17 | dir=in | app=c:\program files (x86)\in verbis virtus\binaries\win32\udk.exe |
"UDP Query User{C3820DB6-47FE-434F-A9FC-49C9154D5F12}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{CCE8439C-A3FE-4431-80C6-17B114C92032}C:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe |
"UDP Query User{DD437061-0047-40CA-8902-8D40A07F8F3D}C:\program files (x86)\warthunder\launcher.exe" = protocol=17 | dir=in | app=c:\program files (x86)\warthunder\launcher.exe |
"UDP Query User{E29BDF64-6C62-4DC3-B942-0E3CD002B8A6}C:\program files (x86)\netbeans 7.4\bin\netbeans64.exe" = protocol=17 | dir=in | app=c:\program files (x86)\netbeans 7.4\bin\netbeans64.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A8A841B-29C4-4947-BF59-241216B4D904}" = Microsoft SQL Server Compact 4.0 x64 CSY
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{90150000-002A-0000-1000-0000000FF1CE}" = Microsoft Office 64-bit Components 2013
"{90150000-002A-0405-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Czech) 2013
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 2.1.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus Update 16.13.56
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizace NVIDIA 16.13.56
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService" = NVIDIA GeForce Experience Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 16.13.56
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController" = SHIELD Wireless Controller Driver
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.25
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"71BC3FD63F450BA0A957AAECBDB4A000C4F2BE42" = Windows Driver Package - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1)
"8A223E56FB1ED4F697B54E5BF96F1EB63B512684" = Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733)
"Defraggler" = Defraggler
"UnityWebPlayer" = Unity Web Player (x64) (All users)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}" = Microsoft ASP.NET MVC 4 Runtime
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7f51bdb9-ee21-49ee-94d6-90afc321780e}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90150000-0015-0405-0000-0000000FF1CE}" = Microsoft Access MUI (Czech) 2013
"{90150000-0016-0405-0000-0000000FF1CE}" = Microsoft Excel MUI (Czech) 2013
"{90150000-0018-0405-0000-0000000FF1CE}" = Microsoft PowerPoint MUI (Czech) 2013
"{90150000-0019-0405-0000-0000000FF1CE}" = Microsoft Publisher MUI (Czech) 2013
"{90150000-001A-0405-0000-0000000FF1CE}" = Microsoft Outlook MUI (Czech) 2013
"{90150000-001B-0405-0000-0000000FF1CE}" = Microsoft Word MUI (Czech) 2013
"{90150000-001F-0405-0000-0000000FF1CE}" = Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština
"{90150000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Korrekturhilfen 2013 - Deutsch
"{90150000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English
"{90150000-001F-041B-0000-0000000FF1CE}" = Nástroje korektúry balíka Microsoft Office 2013 - slovenčina
"{90150000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2013
"{90150000-0044-0405-0000-0000000FF1CE}" = Microsoft InfoPath MUI (Czech) 2013
"{90150000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2013
"{90150000-0090-0405-0000-0000000FF1CE}" = Microsoft DCF MUI (Czech) 2013
"{90150000-00A1-0405-0000-0000000FF1CE}" = Microsoft OneNote MUI (Czech) 2013
"{90150000-00BA-0405-0000-0000000FF1CE}" = Microsoft Groove MUI (Czech) 2013
"{90150000-00E1-0405-0000-0000000FF1CE}" = Microsoft Office OSM MUI (Czech) 2013
"{90150000-00E2-0405-0000-0000000FF1CE}" = Microsoft Office OSM UX MUI (Czech) 2013
"{90150000-012B-0405-0000-0000000FF1CE}" = Microsoft Lync MUI (Czech) 2013
"{91150000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2013
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{970FCA80-7160-4481-8B7E-1D011BD7778B}" = System Requirements Lab Detection
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1029-4770-7760-000000000005}" = Adobe Acrobat X Pro - Eastern European (Group 1)
"{AC76BA86-7AD7-1029-7B44-AB0000000001}" = Adobe Reader XI (11.0.09) - Czech
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{CCF298AF-9CE1-4B26-B251-486E98A34789}" = Windows 7 USB/DVD Download Tool
"{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Font Xplorer" = Font Xplorer 1.2.2
"Google Chrome" = Google Chrome
"LastFM_is1" = Last.fm Scrobbler 2.1.36
"Mozilla Firefox 32.0.3 (x86 cs)" = Mozilla Firefox 32.0.3 (x86 cs)
"Office15.PROPLUSR" = Microsoft Office Professional Plus 2013
"Sherlock Holmes Crimes and Punishments_is1" = Sherlock Holmes Crimes and Punishments
"steam app 8930" = Sid Meier's Civilization V
"VLC media player" = VLC media player
"Windows Media Encoder 9" = Windows Media Encoder 9 Series

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1410772076-1682251192-4122739941-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"uTorrent" = µTorrent

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 4. 6. 2014 14:08:37 | Computer Name = Checkpoint | Source = Microsoft-Windows-Immersive-Shell | ID = 2486
Description = Aplikace FileManager_6.3.9600.16384_neutral_neutral_cw5n1h2txyewy+Microsoft.Windows.PhotoManager
se nespustila ve stanovenou dobu.

Error - 4. 6. 2014 14:08:39 | Computer Name = Checkpoint | Source = Application Hang | ID = 1002
Description = Program HandyCurrencyConverter.exe verze 1.0.0.0 přestal spolupracovat
se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací
o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID
procesu: 2854 Čas spuštění: 01cf801ff595eb99 Čas ukončení: 4294967295 Cesta k aplikaci:
C:\Program Files\WindowsApps\15912PengSong.45018A83264EB_1.2.2.0_neutral__vm3wjdvy9nfky\HandyCurrencyConverter.exe

ID
hlášení: 3c7a31ad-ec13-11e3-bea6-20898427258f Úplný název chybujícího balíčku: 15912PengSong.45018A83264EB_1.2.2.0_neutral__vm3wjdvy9nfky

ID
aplikace související s chybujícím balíčkem: App

Error - 4. 6. 2014 14:08:40 | Computer Name = Checkpoint | Source = Application Hang | ID = 1002
Description = Program PhotosApp.exe verze 6.3.9600.17031 přestal spolupracovat se
systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací
o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID
procesu: 1b38 Čas spuštění: 01cf801ff82000d9 Čas ukončení: 4294967295 Cesta k aplikaci:
C:\WINDOWS\FileManager\PhotosApp.exe ID hlášení: 3fa3c0c2-ec13-11e3-bea6-20898427258f

Úplný
název chybujícího balíčku: FileManager_6.3.9600.16384_neutral_neutral_cw5n1h2txyewy

ID
aplikace související s chybujícím balíčkem: Microsoft.Windows.PhotoManager

Error - 4. 6. 2014 14:08:39 | Computer Name = Checkpoint | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = Aplikaci 15912PengSong.45018A83264EB_vm3wjdvy9nfky!App se nepovedlo
aktivovat, protože došlo k chybě: -2144927142. Další informace najdete v protokolu
Microsoft-Windows-TWinUI/Operational.

Error - 4. 6. 2014 15:38:45 | Computer Name = Checkpoint | Source = Application Hang | ID = 1002
Description = Program LiveComm.exe verze 17.5.9600.20498 přestal spolupracovat se
systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací
o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID
procesu: a98 Čas spuštění: 01cf802bd1404cdd Čas ukončení: 4294967295 Cesta k aplikaci:
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe

ID
hlášení: c4ae4a75-ec1f-11e3-bea6-20898427258f Úplný název chybujícího balíčku: microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe

ID
aplikace související s chybujícím balíčkem: ppleae38af2e007f4358a809ac99a64a67c1


Error - 4. 6. 2014 15:41:54 | Computer Name = Checkpoint | Source = Application Error | ID = 1000
Description = Název chybující aplikace: bf3.exe, verze: 1.6.0.0, časové razítko:
0x511c9356 Název chybujícího modulu: ntdll.dll, verze: 6.3.9600.17031, časové razítko:
0x5308893d Kód výjimky: 0xc0000005 Posun chyby: 0x0001f0a3 ID chybujícího procesu:
0x13ec Čas spuštění chybující aplikace: 0x01cf802bdeca1485 Cesta k chybující aplikaci:
C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe Cesta k chybujícímu modulu:
C:\WINDOWS\SYSTEM32\ntdll.dll ID zprávy: 4762bc2c-ec20-11e3-bea6-20898427258f Úplný
název chybujícího balíčku: ID aplikace související s chybujícím balíčkem:

Error - 4. 6. 2014 16:56:35 | Computer Name = Checkpoint | Source = Microsoft-Windows-Immersive-Shell | ID = 2486
Description = Aplikace 15912PengSong.45018A83264EB_1.2.2.0_neutral__vm3wjdvy9nfky+App
se nespustila ve stanovenou dobu.

Error - 4. 6. 2014 16:56:42 | Computer Name = Checkpoint | Source = Application Hang | ID = 1002
Description = Program HandyCurrencyConverter.exe verze 1.0.0.0 přestal spolupracovat
se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací
o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID
procesu: 176c Čas spuštění: 01cf80376fb739ff Čas ukončení: 4294967295 Cesta k aplikaci:
C:\Program Files\WindowsApps\15912PengSong.45018A83264EB_1.2.2.0_neutral__vm3wjdvy9nfky\HandyCurrencyConverter.exe

ID
hlášení: b6f67faf-ec2a-11e3-bea6-20898427258f Úplný název chybujícího balíčku: 15912PengSong.45018A83264EB_1.2.2.0_neutral__vm3wjdvy9nfky

ID
aplikace související s chybujícím balíčkem: App

Error - 5. 6. 2014 6:49:00 | Computer Name = Checkpoint | Source = Application Error | ID = 1000
Description = Název chybující aplikace: isuspm.exe, verze: 3.0.100.1131, časové
razítko: 0x40816c48 Název chybujícího modulu: isuspm.exe, verze: 3.0.100.1131, časové
razítko: 0x40816c48 Kód výjimky: 0xc0000005 Posun chyby: 0x0001648b ID chybujícího
procesu: 0x2910 Čas spuštění chybující aplikace: 0x01cf80aba4b4c598 Cesta k chybující
aplikaci: c:\program files (x86)\common files\installshield\updateservice\isuspm.exe
Cesta
k chybujícímu modulu: c:\program files (x86)\common files\installshield\updateservice\isuspm.exe
ID
zprávy: ffd4d4b3-ec9e-11e3-bea6-20898427258f Úplný název chybujícího balíčku: ID
aplikace související s chybujícím balíčkem:

Error - 5. 6. 2014 7:35:27 | Computer Name = Checkpoint | Source = Customer Experience Improvement Program | ID = 1008
Description =

[ System Events ]
Error - 21. 10. 2014 10:38:20 | Computer Name = Checkpoint | Source = DCOM | ID = 10010
Description =

Error - 21. 10. 2014 10:43:54 | Computer Name = Checkpoint | Source = DCOM | ID = 10010
Description =

Error - 21. 10. 2014 10:43:55 | Computer Name = Checkpoint | Source = DCOM | ID = 10010
Description =

Error - 21. 10. 2014 10:43:55 | Computer Name = Checkpoint | Source = DCOM | ID = 10010
Description =

Error - 21. 10. 2014 10:55:38 | Computer Name = Checkpoint | Source = DCOM | ID = 10010
Description =

Error - 21. 10. 2014 10:58:58 | Computer Name = Checkpoint | Source = DCOM | ID = 10010
Description =

Error - 21. 10. 2014 11:13:54 | Computer Name = Checkpoint | Source = DCOM | ID = 10010
Description =

Error - 21. 10. 2014 11:13:56 | Computer Name = Checkpoint | Source = DCOM | ID = 10010
Description =

Error - 21. 10. 2014 11:13:56 | Computer Name = Checkpoint | Source = DCOM | ID = 10010
Description =

Error - 21. 10. 2014 11:17:55 | Computer Name = Checkpoint | Source = DCOM | ID = 10010
Description =


< End of report >

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Preventivka s menším podezřením

#15 Příspěvek od Márty84 »

:arrow: Napiste mi velikost adresare plochy (C:\Users\Martin\Desktop)




:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Znovu spustte OTL jako spravce
Do spodniho okna vlozte nasledujici text (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[RESETHOSTS]
[Purity]
[CreateRestorePoint]

:services
AdobeARMservice
gupdate
SkypeUpdate
AdobeFlashPlayerUpdateSvc
gupdatem
SwitchBoard

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1410772076-1682251192-4122739941-1002Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1410772076-1682251192-4122739941-1002UA.job
C:\ProgramData\Malwarebytes

:otl
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{C9025ABC-81CC-492C-81D4-9DA87B28B4EE}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{C9025ABC-81CC-492C-81D4-9DA87B28B4EE}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
IE - HKU\S-1-5-21-1410772076-1682251192-4122739941-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
O3:64bit: - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O8:64bit: - Extra context menu item: Stáhnout s Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm File not found
O8 - Extra context menu item: Stáhnout s Mipony - file://C:\Program Files (x86)\MiPony\Browser\IEContext.htm File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
[2 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
[2 C:\WINDOWS\Inf\Oracle Data Provider for .NET\*.tmp files -> C:\WINDOWS\Inf\Oracle Data Provider for .NET\*.tmp -> ]
[1 C:\WINDOWS\Inf\Oracle Data Provider for .NET\0000\*.tmp files -> C:\WINDOWS\Inf\Oracle Data Provider for .NET\0000\*.tmp -> ]
[1 C:\WINDOWS\Inf\Oracle Data Provider for .NET\0005\*.tmp files -> C:\WINDOWS\Inf\Oracle Data Provider for .NET\0005\*.tmp -> ]
[1 C:\WINDOWS\Inf\Oracle Data Provider for .NET\0009\*.tmp files -> C:\WINDOWS\Inf\Oracle Data Provider for .NET\0009\*.tmp -> ]
[7 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[2 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> ]
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\light_square\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\light_rounded\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\facebook\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\default\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\dark_square\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\prettyPhoto\dark_rounded\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\OLD\images\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\light_square\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\light_rounded\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\facebook\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\default\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\dark_square\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\prettyPhoto\dark_rounded\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\2. GRAFIKA\+SUUHK\SEZNAMOVÁK\SEZNAMOVÁK WEB\images\loader.gif:ms-properties
@Alternate Data Stream - 376 bytes -> \Users\Martin\SkyDrive\Dokumenty\1. ŠKOLA\PSIT\Cisco\DIR příkaz - konfigurace switche skrz BOOT LOADER.PNG:ms-properties
@Alternate Data Stream - 314 bytes -> C:\WINDOWS\Fonts\+KAMIKZOM.ttf:ms-properties
@Alternate Data Stream - 314 bytes -> C:\WINDOWS\Fonts\+gunplay.ttf:ms-properties
@Alternate Data Stream - 314 bytes -> C:\WINDOWS\Fonts\+3rd Man.otf:ms-properties
@Alternate Data Stream - 314 bytes -> \Users\Martin\SkyDrive\Dokumenty\1. ŠKOLA\PGRF\Komprese projekt\c05_stepanek_martin\c05_stepanek_martin\src\c05_stepanek_martin\Img32Loader.java:ms-properties
@Alternate Data Stream - 237 bytes -> C:\Users\Martin\SkyDrive:ms-properties

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=-
"ISUSPM Startup"=-
"DAEMON Tools Lite"=-
"Zoner Photo Studio Autoupdate"=-
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
"ISUSScheduler"=-
""=-
"Adobe Acrobat Speed Launcher"=-
"Acrobat Assistant 8.0"=-
"QuickTime Task"=-
"SunJavaUpdateSched"=-
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno