OTL logfile created on: 2015-01-19 17:27:18 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Milan Obešlo\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: yyyy-MM-dd
3.25 Gb Total Physical Memory | 1.38 Gb Available Physical Memory | 42.49% Memory free
6.72 Gb Paging File | 4.80 Gb Available in Paging File | 71.49% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 205.68 Gb Total Space | 65.30 Gb Free Space | 31.75% Space Free | Partition Type: NTFS
Drive E: | 725.83 Gb Total Space | 549.69 Gb Free Space | 75.73% Space Free | Partition Type: NTFS
Drive F: | 149.05 Gb Total Space | 29.32 Gb Free Space | 19.67% Space Free | Partition Type: NTFS
Drive N: | 465.76 Gb Total Space | 86.75 Gb Free Space | 18.63% Space Free | Partition Type: NTFS
Computer Name: PCQUAD | User Name: Milan Obešlo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2015-01-19 17:24:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Milan Obešlo\Desktop\OTL.exe
PRC - [2014-12-19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014-11-26 16:48:19 | 001,385,808 | ---- | M] (BitTorrent Inc.) -- C:\Users\Milan Obešlo\AppData\Roaming\uTorrent\uTorrent.exe
PRC - [2014-11-21 06:12:46 | 007,229,752 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
PRC - [2014-10-01 14:40:28 | 001,349,576 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2014-10-01 14:40:14 | 005,088,456 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2014-04-23 07:51:00 | 004,065,648 | ---- | M] (Ghisler Software GmbH) -- C:\Program Files\totalcmd\TOTALCMD.EXE
PRC - [2013-11-12 15:11:50 | 002,532,864 | ---- | M] (MyHeritage) -- C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
PRC - [2013-10-23 08:19:06 | 000,932,640 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2013-10-23 08:19:05 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2013-01-12 10:51:12 | 000,295,072 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\realplayer\Update\realsched.exe
PRC - [2012-11-29 20:31:04 | 000,038,608 | ---- | M] () -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2011-08-05 12:29:56 | 000,159,456 | ---- | M] (Microsoft Corporation) -- C:\Program Files\ZuneLauncher.exe
PRC - [2009-10-21 05:12:50 | 000,106,496 | ---- | M] (NEC Electronics Corporation) -- C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2009-07-30 17:51:02 | 000,068,136 | ---- | M] () -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
PRC - [2009-04-11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009-04-11 07:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2008-09-24 13:57:34 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008-09-24 13:57:14 | 000,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
PRC - [2008-07-20 17:37:36 | 000,606,720 | ---- | M] (Crawler.com) -- C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2008-01-19 08:33:37 | 000,397,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Mail\WinMail.exe
PRC - [2007-09-02 12:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.exe
PRC - [2007-05-22 10:14:54 | 000,405,504 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files\WinFast\WFDTV\WFWIZ_vista.exe
PRC - [2007-05-16 14:43:36 | 000,069,632 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
PRC - [2006-12-02 01:13:10 | 000,045,056 | ---- | M] (Qliner) -- C:\Program Files\Qliner Hotkeys\HotKeys.exe
PRC - [2004-12-13 04:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PRC - [2000-01-01 01:00:00 | 001,914,656 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
========== Modules (No Company Name) ==========
MOD - [2015-01-09 01:35:54 | 009,009,480 | ---- | M] () -- C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\Application\39.0.2171.99\pdf.dll
MOD - [2015-01-09 01:35:48 | 001,677,128 | ---- | M] () -- C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\Application\39.0.2171.99\ffmpegsumo.dll
MOD - [2014-11-12 17:36:25 | 000,774,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\525d2a189e395c60a20cded4d2bfea76\System.Runtime.Remoting.ni.dll
MOD - [2014-10-15 17:06:20 | 000,978,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\a98a13deac020eca5e7dcb5ebb2b7414\System.Configuration.ni.dll
MOD - [2014-10-15 17:04:57 | 005,465,088 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\a224433c0fb9281862f36823e86822fc\System.Xml.ni.dll
MOD - [2014-10-15 17:04:43 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f32d5986039f142f6e4f412de7c8901c\System.Windows.Forms.ni.dll
MOD - [2014-10-15 17:04:35 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\65897bde93bce2462330f19ef677477d\System.Drawing.ni.dll
MOD - [2014-10-15 17:03:21 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cf2c94955471d68d3708b1fbf613ae46\System.ni.dll
MOD - [2014-09-10 11:58:31 | 011,496,960 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\3444fbefcbd532181c499150ace644a4\mscorlib.ni.dll
MOD - [2010-02-10 17:10:12 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2009-03-31 19:04:50 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_cs_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009-03-31 19:04:50 | 000,204,800 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_cs_b77a5c561934e089\System.resources.dll
MOD - [2008-02-10 14:21:04 | 001,077,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\HotKeysLib\1.0.0.0__71ab1dbd1d36106c\HotKeysLib.dll
MOD - [2008-02-10 14:21:04 | 000,143,360 | ---- | M] () -- C:\Windows\assembly\GAC\ICSharpCode.SharpZipLib\0.84.0.0__1b03e6acf1164f73\ICSharpCode.SharpZipLib.dll
MOD - [2008-02-10 14:21:04 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC\Kennedy.ManagedHooks\1.2.0.10__fddfe5478bd2f105\Kennedy.ManagedHooks.dll
MOD - [2007-09-02 12:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.exe
MOD - [2007-09-02 12:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files\RocketDock\RocketDock.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Program Files\Fighters\FighterSuiteService.exe -- (Suite Service)
SRV - File not found [Auto | Stopped] -- C:\Program Files\Fighters\SPAMfighter\sfus.exe -- (SPAMfighter Update Service)
SRV - [2015-01-14 17:40:12 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-12-19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014-11-21 06:12:56 | 000,969,016 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014-11-21 06:12:54 | 001,871,160 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2014-10-01 14:40:28 | 001,349,576 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2012-11-29 20:31:04 | 000,038,608 | ---- | M] () [Auto | Running] -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2012-10-03 15:51:04 | 000,725,400 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011-08-05 12:30:02 | 000,444,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV - [2011-08-05 12:30:02 | 000,268,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\WMZuneComm.exe -- (WMZuneComm)
SRV - [2011-08-05 12:29:56 | 006,363,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2009-07-30 17:51:02 | 000,068,136 | ---- | M] () [Auto | Running] -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service)
SRV - [2008-09-24 13:57:34 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2008-09-24 13:57:14 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Auto | Running] -- C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe -- (PLFlash DeviceIoControl Service)
SRV - [2008-07-20 17:37:36 | 000,606,720 | ---- | M] (Crawler.com) [Auto | Running] -- C:\Program Files\Spyware Terminator\sp_rsser.exe -- (sp_rssrv)
SRV - [2008-01-19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2004-12-13 04:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
SRV - [2000-01-01 01:00:00 | 001,914,656 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\MSI\Live Update 5\NTIOLib.sys -- (NTIOLib_1_0_4)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\MSI\Live Update 5\VGASYS32_100507.sys -- (MSI_VGASYS_010507)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\MSI\Live Update 5\msibios32_100507.sys -- (MSI_MSIBIOS_010507)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\MSI\Live Update 5\DVDSYS32_100507.sys -- (MSI_DVD_010507)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2015-01-19 15:25:14 | 000,114,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV - [2015-01-19 15:25:02 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2014-11-21 06:14:16 | 000,051,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV - [2014-11-21 06:14:06 | 000,023,256 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2014-10-10 08:59:12 | 000,191,928 | ---- | M] (ESET) [File_System | System | Running] -- C:\Windows\System32\drivers\eamonm.sys -- (eamonm)
DRV - [2014-10-10 08:59:12 | 000,135,296 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2014-10-10 08:59:12 | 000,123,424 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV - [2013-11-21 21:11:31 | 000,013,464 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SWDUMon.sys -- (SWDUMon)
DRV - [2012-06-27 15:18:52 | 000,019,072 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2012-06-11 14:17:44 | 000,018,560 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011-02-16 16:52:46 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2010-07-01 18:52:18 | 000,044,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d)
DRV - [2009-10-26 16:19:02 | 000,136,704 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV - [2009-10-26 16:19:00 | 000,058,240 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nusb3hub.sys -- (nusb3hub)
DRV - [2009-10-21 18:30:32 | 000,433,920 | ---- | M] (Leadtek Research Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wfeaglxt.sys -- (WFLR6654)
DRV - [2009-09-02 04:09:24 | 000,176,128 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2009-07-14 00:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2008-12-23 20:42:01 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2008-07-20 17:37:36 | 000,141,312 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\sp_rsdrv2.sys -- (sp_rsdrv2)
DRV - [2007-09-13 20:41:28 | 000,051,608 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2007-09-13 20:41:20 | 000,014,744 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2007-09-13 20:41:02 | 000,029,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2007-09-13 20:40:54 | 000,019,352 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2006-11-06 09:28:11 | 000,030,988 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2006-10-27 09:48:42 | 000,018,944 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\busbcrw.sys -- (busbcrw)
DRV - [2005-01-06 16:55:38 | 000,009,446 | ---- | M] (Leadtek Research Inc.) [Kernel | On_Demand | Running] -- C:\Program Files\WinFast\WFDTV\WFIOCTL.sys -- (WFIOCTL)
DRV - [2003-06-06 14:34:56 | 000,016,695 | ---- | M] (EUTRON) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\eusk2par.sys -- (eusk2par)
DRV - [2001-07-13 13:56:14 | 000,014,976 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\SBKUPNT.SYS -- (SBKUPNT)
DRV - [2000-01-01 01:00:00 | 010,410,272 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2000-01-01 01:00:00 | 000,161,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKU\.DEFAULT\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" =
http://www.crawler.com/search/dispatche ... tbid=60327
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={ ... rer:source?}
IE - HKU\S-1-5-18\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" =
http://www.crawler.com/search/dispatche ... tbid=60327
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
www.google.com
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1000\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - SOFTWARE\Classes\CLSID\{BC86E1AB-EDA5-4059-938F-CE307B0C6F0A}\InprocServer32 File not found
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1000\..\SearchScopes,DefaultScope = {C7809953-FDE8-44ff-8C3F-88E7488CB898}
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1000\..\SearchScopes\{C7809953-FDE8-44ff-8C3F-88E7488CB898}: "URL" =
http://uk.search.yahoo.com/search?p={se ... &type=IEBD
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1000\..\SearchScopes\{DA1676F1-F84B-4812-8AA7-0A14185DA854}: "URL" =
http://www.google.com/custom?client=pub ... earchTerms}
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = socks=
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.centrum.cz/
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - SOFTWARE\Classes\CLSID\{BC86E1AB-EDA5-4059-938F-CE307B0C6F0A}\InprocServer32 File not found
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" =
http://www.crawler.com/search/dispatche ... tbid=60327
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9}: "URL" =
http://www.daemon-search.com/search/web?q={searchTerms}
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\..\SearchScopes\{C7809953-FDE8-44ff-8C3F-88E7488CB898}: "URL" =
http://uk.search.yahoo.com/search?p={se ... &type=IEBD
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\..\SearchScopes\{DA1676F1-F84B-4812-8AA7-0A14185DA854}: "URL" =
http://www.google.com/custom?client=pub ... earchTerms}
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = socks=
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.seznam.cz"
FF - prefs.js..extensions.enabledAddons:
compatibility@addons.mozilla.org:1.1
FF - prefs.js..extensions.enabledAddons: {097d3191-e6fa-4728-9826-b533d755359d}:0.7.14
FF - prefs.js..extensions.enabledAddons: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.17
FF - prefs.js..extensions.enabledAddons: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:7.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {097d3191-e6fa-4728-9826-b533d755359d}:0.7.13
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:4.0.1
FF - prefs.js..extensions.enabledItems:
smartbookmarksbar@remy.juteau:1.4.3
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF - HKLM\Software\MozillaPlugins\@cuminas.jp/DjVuPlugin: C:\Program Files\Cuminas\Document Express DjVu Plug-in\npdjvu.dll (Cuminas Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.55.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.2.72: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.2.72: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.2.72: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.2.72: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.0: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Milan Obešlo\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Milan Obešlo\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009-05-06 18:43:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013-01-12 10:52:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-01-12 10:52:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-06-27 19:59:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014-12-12 16:44:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\
smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009-05-06 18:43:35 | 000,000,000 | ---D | M]
[2008-08-28 20:22:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Milan Obešlo\AppData\Roaming\Mozilla\Extensions
[2015-01-17 13:15:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Milan Obešlo\AppData\Roaming\Mozilla\Firefox\Profiles\p3yzb4q6.default\extensions
[2014-05-20 20:15:56 | 000,000,000 | ---D | M] (SearchPreview) -- C:\Users\Milan Obešlo\AppData\Roaming\Mozilla\Firefox\Profiles\p3yzb4q6.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2012-06-20 17:10:42 | 000,000,000 | ---D | M] (Roomy Bookmarks Toolbar) -- C:\Users\Milan Obešlo\AppData\Roaming\Mozilla\Firefox\Profiles\p3yzb4q6.default\extensions\ALone-live@ya(44).ru
[2013-06-22 07:22:21 | 000,000,000 | ---D | M] (Roomy Bookmarks Toolbar) -- C:\Users\Milan Obešlo\AppData\Roaming\Mozilla\Firefox\Profiles\p3yzb4q6.default\extensions\ALone-live@ya(45).ru
[2012-05-09 18:05:58 | 000,000,000 | ---D | M] (Roomy Bookmarks Toolbar) -- C:\Users\Milan Obešlo\AppData\Roaming\Mozilla\Firefox\Profiles\p3yzb4q6.default\extensions\ALone-live@ya(72).ru
[2012-02-24 11:08:35 | 000,164,722 | ---- | M] () (No name found) -- C:\Users\Milan Obešlo\AppData\Roaming\Mozilla\Firefox\Profiles\p3yzb4q6.default\extensions\
compatibility@addons.mozilla.org.xpi
[2011-06-25 08:57:54 | 000,450,199 | ---- | M] () (No name found) -- C:\Users\Milan Obešlo\AppData\Roaming\Mozilla\Firefox\Profiles\p3yzb4q6.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi
[2013-02-14 18:53:31 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Milan Obešlo\AppData\Roaming\Mozilla\Firefox\Profiles\p3yzb4q6.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014-05-04 11:57:09 | 000,731,942 | ---- | M] () (No name found) -- C:\Users\Milan Obešlo\AppData\Roaming\Mozilla\Firefox\Profiles\p3yzb4q6.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2012-06-20 17:06:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012-06-20 17:17:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\distribution\extensions
[2012-06-20 17:17:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\distribution\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
File not found (No name found) -- C:\USERS\MILAN OBEšLO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3YZB4Q6.DEFAULT\EXTENSIONS\{097D3191-E6FA-4728-9826-B533D755359D}.XPI
File not found (No name found) -- C:\USERS\MILAN OBEšLO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3YZB4Q6.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
File not found (No name found) -- C:\USERS\MILAN OBEšLO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3YZB4Q6.DEFAULT\EXTENSIONS\{EF522540-89F5-46B9-B6FE-1829E2B572C6}
File not found (No name found) -- C:\USERS\MILAN OBEšLO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\P3YZB4Q6.DEFAULT\EXTENSIONS\
COMPATIBILITY@ADDONS.MOZILLA.ORG.XPI
[2012-02-18 10:40:59 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008-01-23 07:20:30 | 000,491,520 | ---- | M] (BitComet) -- C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll
[2013-01-12 10:51:30 | 000,124,056 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012-06-15 01:05:47 | 000,001,583 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\atlas-sk.xml
[2012-06-15 01:05:47 | 000,001,380 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\azet-sk.xml
[2012-06-15 01:05:47 | 000,001,479 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\dunaj-sk.xml
[2012-06-15 01:05:48 | 000,001,473 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slovnik-sk.xml
[2012-06-15 01:05:48 | 000,001,104 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-sk.xml
[2012-06-15 01:05:48 | 000,000,830 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\zoznam-sk.xml
========== Chrome ==========
CHR - default_search_provider: (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Widevine Content Decryption Module (Enabled) = C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.1.377\_platform_specific\win_x86\widevinecdmadapter.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\Application\39.0.2171.99\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\Application\39.0.2171.99\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\Application\39.0.2171.99\pdf.dll
CHR - plugin: Microsoft® Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: BitCometAgent (Disabled) = C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 7.0.510.13 (Enabled) = C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
CHR - plugin: Java(TM) Platform SE 7 U51 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll
CHR - plugin: RealJukebox NS Plugin (Disabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: VLC Web Plugin (Disabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
CHR - plugin: RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit) (Disabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
CHR - plugin: RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit) (Disabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
CHR - plugin: RealDownloader Plugin (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Disabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Milan Obešlo\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpplugin.dll
CHR - Extension: No name found = C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\User Data\Default\Extensions\eeoekjnjgppnaegdjbcafdggilajhpic\2.1_0\
CHR - Extension: No name found = C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj\2.6.4.4_0\
CHR - Extension: No name found = C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: No name found = C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihmigmmflfcbhdpdgbkkeojchjhhphnh\2.1.2.30_0\
CHR - Extension: No name found = C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\Milan Obešlo\AppData\Local\Google\Chrome\User Data\Default\Extensions\oijdcdmnjjgnnhgljmhkjlablaejfeeb\0.2_0\
O1 HOSTS File: ([2007-12-01 10:33:58 | 000,214,260 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 hityou.com
O1 - Hosts: 127.0.0.1
www.hityou.com
O1 - Hosts: 127.0.0.1 180searchassistant.com
O1 - Hosts: 127.0.0.1
www.180searchassistant.com
O1 - Hosts: 127.0.0.1 180solutions.com
O1 - Hosts: 127.0.0.1
www.180solutions.com
O1 - Hosts: 127.0.0.1 bis.180solutions.com
O1 - Hosts: 127.0.0.1 config.180solutions.com
O1 - Hosts: 127.0.0.1 cts.180solutions.com
O1 - Hosts: 127.0.0.1 downloads.180solutions.com
O1 - Hosts: 127.0.0.1 installs.180solutions.com
O1 - Hosts: 127.0.0.1 nowhere.180solutions.com
O1 - Hosts: 127.0.0.1 ping.180solutions.com
O1 - Hosts: 127.0.0.1 tv.180solutions.com
O1 - Hosts: 127.0.0.1 uploads.180solutions.com
O1 - Hosts: 127.0.0.1 public.zangocash.com
O1 - Hosts: 127.0.0.1
www.public.zangocash.com
O1 - Hosts: 127.0.0.1 static.zangocash.com
O1 - Hosts: 127.0.0.1
www.static.zangocash.com
O1 - Hosts: 127.0.0.1
www.zangocash.com
O1 - Hosts: 127.0.0.1 zangocash.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1
www.007guard.com
O1 - Hosts: 7537 more lines...
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O4 - HKLM..\Run: [00Hotkeys] C:\Program Files\Qliner Hotkeys\HotKeys.exe (Qliner)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe (MyHeritage)
O4 - HKLM..\Run: [MSConfig] C:\Windows\System32\msconfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate File not found
O4 - HKLM..\Run: [sfagent] C:\Program Files\Fighters\SPAMfighter\sfagent.exe File not found
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe File not found
O4 - HKLM..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe (Leadtek Research Inc.)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-2124181350-2115944497-1007344975-1000..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKU\S-1-5-21-2124181350-2115944497-1007344975-1000..\Run: [uTorrent] C:\Users\Milan Obešlo\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - HKU\S-1-5-21-2124181350-2115944497-1007344975-1003..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKLM..\RunOnce: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe (Leadtek Research Inc.)
O4 - HKLM..\RunOnce: [WinFast Schedule2] C:\Program Files (x86)\WinFast\WFDTV\WFWIZ.exe File not found
O4 - HKLM..\RunOnce: [WinFast Schedule3] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe File not found
O4 - HKLM..\RunOnce: [WinFast Schedule4] C:\Program Files (x86)\WinFast\WFTVFM\WFWIZ.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWinKeys = 1
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O13 - gopher Prefix: missing
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E}
http://liveupdate.msi.com.tw/autobios/L ... nstall.cab (WebSDev Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 10.55.2)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0055-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_55)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab (Java Plug-in 1.7.0_55)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.224.254 195.146.100.98
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0509E4BA-D1F0-4C3F-9CBB-7B265B7B4707}: DhcpNameServer = 10.0.224.254 195.146.100.98
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F258111-011F-47F0-B870-5E893C703D45}: DhcpNameServer = 192.168.1.20
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | ---- | M] () - F:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - C:\Windows\System32\i420vfw.dll (
www.helixcommunity.org)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2015-01-19 17:24:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Milan Obešlo\Desktop\OTL.exe
[2015-01-18 16:33:22 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2015-01-17 16:40:23 | 000,114,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2015-01-17 16:40:08 | 000,075,480 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamchameleon.sys
[2015-01-17 16:40:08 | 000,051,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mwac.sys
[2015-01-17 16:40:08 | 000,023,256 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2015-01-17 16:40:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes Anti-Malware
[2015-01-17 16:38:09 | 020,447,072 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Milan Obešlo\Desktop\mbam-setup-2.0.4.1028.exe
[2015-01-17 13:13:24 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2015-01-17 11:21:14 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2015-01-15 14:59:49 | 000,093,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncsi.dll
[2015-01-04 10:38:20 | 000,049,152 | ---- | C] (Stirling) -- C:\Program Files\_ISREG32.DLL
[2015-01-04 10:38:12 | 000,000,000 | ---D | C] -- C:\Program Files\ZALOHA
[2015-01-04 10:38:12 | 000,000,000 | ---D | C] -- C:\Program Files\DATA
[2011-08-05 12:34:22 | 001,534,688 | ---- | C] (Microsoft Corporation) -- C:\Program Files\UIX.dll
[2011-08-05 12:34:22 | 001,072,864 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneDBApi.dll
[2011-08-05 12:34:22 | 000,645,856 | ---- | C] (Microsoft Corporation) -- C:\Program Files\UIX.renderapi.dll
[2011-08-05 12:34:20 | 001,424,096 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneShell.dll
[2011-08-05 12:34:20 | 001,293,024 | ---- | C] (Microsoft Corporation) -- C:\Program Files\UIXcontrols.dll
[2011-08-05 12:30:02 | 016,921,312 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneShellResources.dll
[2011-08-05 12:30:02 | 003,945,696 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneSetup.exe
[2011-08-05 12:30:02 | 003,889,376 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneResources.dll
[2011-08-05 12:30:02 | 000,850,144 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneService.dll
[2011-08-05 12:30:02 | 000,679,648 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneQP.dll
[2011-08-05 12:30:02 | 000,653,024 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneWmdu.dll
[2011-08-05 12:30:02 | 000,609,504 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneSH.dll
[2011-08-05 12:30:02 | 000,444,640 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneWlanCfgSvc.exe
[2011-08-05 12:30:02 | 000,406,240 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneSP.dll
[2011-08-05 12:30:02 | 000,376,544 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneSE.dll
[2011-08-05 12:30:02 | 000,301,280 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneSrcWrp.dll
[2011-08-05 12:30:02 | 000,268,512 | ---- | C] (Microsoft Corporation) -- C:\Program Files\WMZuneComm.exe
[2011-08-05 12:30:02 | 000,157,408 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneZMDB.Mobile.dll
[2011-08-05 12:30:02 | 000,131,808 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneZMDB.Library.dll
[2011-08-05 12:30:02 | 000,130,784 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneZMDB.ZuneHD.dll
[2011-08-05 12:30:02 | 000,126,176 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneZMDB.Classic.dll
[2011-08-05 12:30:02 | 000,123,104 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneSA.dll
[2011-08-05 12:30:02 | 000,084,704 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneTaskbar.dll
[2011-08-05 12:30:02 | 000,059,616 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneShellExt.dll
[2011-08-05 12:30:02 | 000,026,336 | ---- | C] (Microsoft Corporation) -- C:\Program Files\WMZuneTCP2UDP.dll
[2011-08-05 12:30:02 | 000,019,680 | ---- | C] (Microsoft Corporation) -- C:\Program Files\WMZuneDTPTDNS.dll
[2011-08-05 12:30:02 | 000,017,120 | ---- | C] (Microsoft Corporation) -- C:\Program Files\WMZuneCommProxyStub.dll
[2011-08-05 12:30:02 | 000,016,608 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneShare.exe
[2011-08-05 12:30:02 | 000,009,440 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneWmduResources.dll
[2011-08-05 12:29:56 | 007,459,552 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneNativeLib.dll
[2011-08-05 12:29:56 | 006,363,872 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneNss.exe
[2011-08-05 12:29:56 | 001,716,960 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneEncEng.dll
[2011-08-05 12:29:56 | 001,359,584 | ---- | C] (Microsoft Corporation) -- C:\Program Files\UIXrender.dll
[2011-08-05 12:29:56 | 001,096,928 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneMarketplaceResources.dll
[2011-08-05 12:29:56 | 001,040,096 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneCore.dll
[2011-08-05 12:29:56 | 001,001,184 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneH264Dec.dll
[2011-08-05 12:29:56 | 000,816,864 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneMde.dll
[2011-08-05 12:29:56 | 000,628,960 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZUNEMP4SDECD.dll
[2011-08-05 12:29:56 | 000,627,424 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneMBR.dll
[2011-08-05 12:29:56 | 000,298,720 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneEvr.dll
[2011-08-05 12:29:56 | 000,268,000 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneNssci.dll
[2011-08-05 12:29:56 | 000,207,072 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Zune.exe
[2011-08-05 12:29:56 | 000,176,864 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneHost.exe
[2011-08-05 12:29:56 | 000,173,280 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneDB.dll
[2011-08-05 12:29:56 | 000,159,456 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneLauncher.exe
[2011-08-05 12:29:56 | 000,121,568 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZunePresenter.dll
[2011-08-05 12:29:56 | 000,111,840 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneEffects.dll
[2011-08-05 12:29:56 | 000,110,304 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneAACDec.dll
[2011-08-05 12:29:56 | 000,056,544 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneDXVA2.dll
[2011-08-05 12:29:56 | 000,050,912 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneCfg.dll
[2011-08-05 12:29:56 | 000,044,256 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneConfig.exe
[2011-08-05 12:29:56 | 000,036,064 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZuneEnc.exe
[2011-08-05 12:29:56 | 000,030,944 | ---- | C] (Microsoft Corporation) -- C:\Program Files\UIXsup.dll
[2011-08-05 12:29:56 | 000,018,656 | ---- | C] (Microsoft Corporation) -- C:\Program Files\ZunePS.dll
[2011-08-05 12:19:50 | 000,222,720 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Program Files\l3codecp.acm
[2011-06-06 13:48:50 | 000,655,872 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msvcr90.dll
[2011-06-06 13:48:50 | 000,572,928 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msvcp90.dll
[2011-06-06 13:48:50 | 000,225,280 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msvcm90.dll
[2007-10-28 15:09:04 | 000,581,632 | ---- | C] (Crystal Dew World) -- C:\Users\Milan Obešlo\CrystalMark09.exe
[2007-10-28 15:09:04 | 000,192,512 | ---- | C] (Crystal Dew World) -- C:\Users\Milan Obešlo\SysInfo.dll
[2007-10-28 15:09:04 | 000,065,536 | ---- | C] (Crystal Dew World) -- C:\Users\Milan Obešlo\CrystalMark09.dll
[2007-10-28 15:09:03 | 000,081,920 | ---- | C] (Crystal Dew World) -- C:\Users\Milan Obešlo\CM09D2D.exe
[2007-10-28 15:09:03 | 000,065,536 | ---- | C] (Crystal Dew World) -- C:\Users\Milan Obešlo\CM09GDI.exe
[2007-08-27 15:56:58 | 001,089,440 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msidcrl40.dll
[8 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[8 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2015-01-19 17:30:00 | 000,000,432 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{85376FE6-FC64-4267-9B06-0829C1319430}.job
[2015-01-19 17:29:49 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2015-01-19 17:24:44 | 000,004,432 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2015-01-19 17:24:44 | 000,004,432 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2015-01-19 17:24:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Milan Obešlo\Desktop\OTL.exe
[2015-01-19 16:57:00 | 000,000,990 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2124181350-2115944497-1007344975-1000UA.job
[2015-01-19 16:57:00 | 000,000,938 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2124181350-2115944497-1007344975-1000Core.job
[2015-01-19 16:41:00 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015-01-19 16:40:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015-01-19 15:25:14 | 000,114,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2015-01-19 15:25:02 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\Windows\gdrv.sys
[2015-01-19 15:24:46 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015-01-19 15:24:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015-01-19 15:24:40 | 3488,079,872 | -HS- | M] () -- C:\hiberfil.sys
[2015-01-18 16:35:28 | 000,645,076 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2015-01-18 16:35:28 | 000,634,274 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2015-01-18 16:35:28 | 000,137,762 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2015-01-18 16:35:28 | 000,119,840 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2015-01-18 09:27:47 | 008,451,858 | ---- | M] () -- C:\Users\Milan Obešlo\Desktop\Veteran arena - Olomouc.pdf
[2015-01-17 16:40:13 | 000,000,904 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015-01-17 16:38:40 | 020,447,072 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Milan Obešlo\Desktop\mbam-setup-2.0.4.1028.exe
[2015-01-17 13:12:16 | 002,186,752 | ---- | M] () -- C:\Users\Milan Obešlo\Desktop\adwcleaner_4.108.exe
[2015-01-17 11:21:02 | 001,107,968 | ---- | M] () -- C:\Users\Milan Obešlo\Desktop\RSIT.exe
[2015-01-17 09:33:55 | 000,000,809 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015-01-14 19:54:17 | 000,002,673 | ---- | M] () -- C:\Users\Milan Obešlo\Desktop\Microsoft Office Word 2003.lnk
[2015-01-14 17:40:11 | 000,701,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2015-01-14 17:40:11 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2015-01-14 17:19:22 | 000,249,160 | ---- | M] () -- C:\Users\Milan Obešlo\Desktop\CENIKFruit2015A.pdf
[2015-01-06 04:36:02 | 000,249,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2015-01-04 10:46:45 | 000,013,030 | ---- | M] () -- C:\Users\Public\Documents\PDOXUSRS.NET
[2015-01-04 10:38:29 | 000,010,609 | ---- | M] () -- C:\Program Files\DeIsL1.isu
[2015-01-04 10:38:21 | 000,000,672 | ---- | M] () -- C:\Users\Public\Desktop\Saturnin - RTP.lnk
[2015-01-04 10:38:20 | 000,000,355 | ---- | M] () -- C:\Program Files\_DEISREG.ISR
[2015-01-03 13:36:30 | 000,031,307 | ---- | M] () -- C:\Users\Milan Obešlo\Desktop\chouette_alors.zip
[8 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[8 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2015-01-19 17:29:49 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2015-01-18 09:27:47 | 008,451,858 | ---- | C] () -- C:\Users\Milan Obešlo\Desktop\Veteran arena - Olomouc.pdf
[2015-01-17 16:40:13 | 000,000,904 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015-01-17 13:12:15 | 002,186,752 | ---- | C] () -- C:\Users\Milan Obešlo\Desktop\adwcleaner_4.108.exe
[2015-01-17 11:21:00 | 001,107,968 | ---- | C] () -- C:\Users\Milan Obešlo\Desktop\RSIT.exe
[2015-01-14 17:19:22 | 000,249,160 | ---- | C] () -- C:\Users\Milan Obešlo\Desktop\CENIKFruit2015A.pdf
[2015-01-04 10:38:21 | 000,000,672 | ---- | C] () -- C:\Users\Public\Desktop\Saturnin - RTP.lnk
[2015-01-04 10:38:20 | 000,000,355 | ---- | C] () -- C:\Program Files\_DEISREG.ISR
[2015-01-04 10:38:13 | 000,097,280 | ---- | C] () -- C:\Program Files\Zipdll.dll
[2015-01-04 10:38:13 | 000,089,088 | ---- | C] ( ) -- C:\Program Files\Unzdll.dll
[2015-01-04 10:38:13 | 000,000,035 | ---- | C] () -- C:\Program Files\Sklad.cfg
[2015-01-04 10:38:12 | 006,648,832 | ---- | C] () -- C:\Program Files\Saturnin.exe
[2015-01-04 10:38:12 | 000,197,622 | ---- | C] () -- C:\Program Files\LOGOJIDEL.bmp
[2015-01-04 10:38:12 | 000,068,966 | ---- | C] () -- C:\Program Files\jidelnicek.bmp
[2015-01-04 10:38:11 | 000,010,609 | ---- | C] () -- C:\Program Files\DeIsL1.isu
[2015-01-03 13:36:29 | 000,031,307 | ---- | C] () -- C:\Users\Milan Obešlo\Desktop\chouette_alors.zip
[2014-07-23 20:24:31 | 000,454,656 | ---- | C] () -- C:\Windows\System32\PaintX.dll
[2014-01-31 18:08:00 | 000,000,004 | ---- | C] () -- C:\Windows\System32\WFSCHDL.dat
[2014-01-31 18:07:49 | 000,003,732 | ---- | C] () -- C:\Windows\System32\FMCodec.dat
[2013-11-20 20:55:58 | 000,217,176 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2013-11-17 19:40:59 | 000,673,037 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2013-11-17 19:19:01 | 000,013,464 | ---- | C] () -- C:\Windows\System32\drivers\SWDUMon.sys
[2013-11-15 18:50:48 | 000,004,096 | -H-- | C] () -- C:\Users\Milan Obešlo\AppData\Local\keyfile3.drm
[2011-08-24 16:04:03 | 000,000,270 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011-06-21 18:33:50 | 009,532,452 | ---- | C] () -- C:\Program Files\Meiryoz.ttc
[2011-06-06 13:50:40 | 000,000,659 | ---- | C] () -- C:\Program Files\Zune.exe.config
[2011-06-06 13:50:28 | 000,001,922 | ---- | C] () -- C:\Program Files\TopBar.gif
[2011-06-06 13:50:28 | 000,000,988 | ---- | C] () -- C:\Program Files\ZuneLogo.gif
[2011-06-06 13:50:26 | 000,251,333 | ---- | C] () -- C:\Program Files\softwaremap.png
[2011-06-06 13:50:26 | 000,122,458 | ---- | C] () -- C:\Program Files\quickplaymap.png
[2011-06-06 13:50:26 | 000,122,068 | ---- | C] () -- C:\Program Files\quickplaymap_csy.png
[2011-06-06 13:50:26 | 000,121,489 | ---- | C] () -- C:\Program Files\quickplaymap_dan.png
[2011-06-06 13:50:26 | 000,097,298 | ---- | C] () -- C:\Program Files\softwaremap_csy.png
[2011-06-06 13:50:26 | 000,000,631 | ---- | C] () -- C:\Program Files\Background.jpg
[2011-06-06 13:50:26 | 000,000,054 | ---- | C] () -- C:\Program Files\Arrow.gif
[2010-12-08 11:01:57 | 000,000,680 | ---- | C] () -- C:\Users\Milan Obešlo\AppData\Local\d3d9caps.dat
[2009-09-24 20:27:52 | 000,000,833 | ---- | C] () -- C:\Users\Milan Obešlo\.recently-used.xbel
[2009-08-11 18:58:21 | 000,000,005 | ---- | C] () -- C:\Program Files\trl.trl
[2009-03-22 17:47:42 | 000,000,573 | ---- | C] () -- C:\Users\Milan Obešlo\AppData\Roaming\AutoGK.ini
[2007-11-10 19:30:47 | 022,490,112 | ---- | C] () -- C:\Program Files\CZDC.pdb
[2007-11-10 19:30:44 | 004,108,288 | ---- | C] () -- C:\Program Files\CZDC.exe
[2007-11-10 19:30:39 | 000,061,817 | ---- | C] () -- C:\Program Files\CZ.xml
[2007-11-10 19:30:39 | 000,000,558 | ---- | C] () -- C:\Program Files\boot.xml.example
[2007-11-03 13:35:34 | 000,183,296 | ---- | C] () -- C:\Program Files\Core Temp.exe
[2007-10-28 15:15:26 | 000,000,174 | ---- | C] () -- C:\Users\Milan Obešlo\CM09D2D.ini
[2007-10-28 15:14:42 | 000,000,168 | ---- | C] () -- C:\Users\Milan Obešlo\CM09GDI.ini
[2007-10-28 15:11:29 | 000,000,094 | ---- | C] () -- C:\Users\Milan Obešlo\CM09OGL.ini
[2007-10-28 15:09:06 | 000,010,240 | ---- | C] () -- C:\Users\Milan Obešlo\SysInfoX64.sys
[2007-10-28 15:09:06 | 000,008,883 | ---- | C] () -- C:\Users\Milan Obešlo\SysInfo.vxd
[2007-10-28 15:09:06 | 000,007,263 | ---- | C] () -- C:\Users\Milan Obešlo\SysInfo.sys
[2007-10-28 15:09:06 | 000,007,039 | ---- | C] () -- C:\Users\Milan Obešlo\SysInfoNT4.sys
[2007-10-28 15:09:06 | 000,000,159 | ---- | C] () -- C:\Users\Milan Obešlo\CrystalMark09.ini
[2007-10-28 15:09:05 | 000,583,756 | ---- | C] () -- C:\Users\Milan Obešlo\HIYOLOGO.GC2
[2007-10-28 15:09:05 | 000,581,204 | ---- | C] () -- C:\Users\Milan Obešlo\PALOMINO.GLD
[2007-10-28 15:09:05 | 000,462,170 | ---- | C] () -- C:\Users\Milan Obešlo\PENTIUM4.GLD
[2007-10-28 15:09:05 | 000,237,568 | ---- | C] () -- C:\Users\Milan Obešlo\GLUT32.DLL
[2007-10-28 15:09:04 | 000,381,647 | ---- | C] () -- C:\Users\Milan Obešlo\REDCONE.GLD
[2007-10-28 15:09:04 | 000,380,857 | ---- | C] () -- C:\Users\Milan Obešlo\GRENCONE.GLD
[2007-10-28 15:09:04 | 000,373,745 | ---- | C] () -- C:\Users\Milan Obešlo\BLUECONE.GLD
[2007-10-28 15:09:04 | 000,066,632 | ---- | C] () -- C:\Users\Milan Obešlo\WIREBACK.GLD
[2007-10-28 15:09:03 | 000,077,824 | ---- | C] () -- C:\Users\Milan Obešlo\CM09OGL.exe
[2007-10-06 10:21:39 | 000,227,328 | ---- | C] () -- C:\Users\Milan Obešlo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003-11-28 09:02:38 | 000,027,981 | ---- | C] () -- C:\Program Files\Readme.html
========== ZeroAccess Check ==========
[2006-11-02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014-03-25 14:26:04 | 011,587,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009-04-11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-04-11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013-04-09 10:24:10 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Acronis
[2008-11-09 11:40:04 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Any Video Converter
[2008-10-10 18:56:10 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Ashampoo
[2010-06-29 19:06:17 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\avidemux
[2011-04-07 17:20:56 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Azureus
[2008-12-23 20:41:46 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\DAEMON Tools
[2009-03-28 15:15:41 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\esmska
[2009-11-20 18:35:26 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\FarmingSimulator2008
[2008-05-04 20:48:57 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\FDRLab
[2010-06-03 20:12:01 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\GetRightToGo
[2013-11-18 20:56:30 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\GHISLER
[2008-09-09 13:56:56 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\GlarySoft
[2009-09-24 20:27:52 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\gtk-2.0
[2013-03-21 19:14:30 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Hard Disk Sentinel
[2008-06-11 20:51:22 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Hide IP NG
[2012-09-18 19:41:38 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\IGC
[2009-08-30 19:15:21 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\IrfanView
[2013-03-20 17:29:33 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Jpeg Resampler
[2013-12-14 10:48:10 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Kastner software
[2009-01-11 10:40:01 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Leadertech
[2014-08-05 16:56:47 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\LiveKit
[2009-06-28 18:23:15 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\MAGIX
[2011-01-04 20:09:01 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\MechCAD
[2009-08-23 18:09:12 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\MMToolz
[2014-07-24 20:42:02 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\MyHeritage
[2011-08-07 18:56:35 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Nokia
[2009-06-27 09:39:22 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Opera
[2014-04-19 18:00:50 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Oracle
[2010-04-09 17:28:26 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\PC Suite
[2011-05-02 18:44:30 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Posta
[2008-02-10 14:22:41 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\qliner
[2011-12-30 13:09:41 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Samsung
[2013-11-18 19:37:52 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Seznam.cz
[2014-09-14 19:56:51 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\SketchUp
[2009-11-15 11:18:37 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Spyware Terminator
[2014-07-23 20:24:31 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\The Complete Genealogy Reporter - FTB
[2015-01-19 17:34:33 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\uTorrent
[2014-07-26 08:58:15 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\VeskrnaMartin
[2009-05-24 16:32:54 | 000,000,000 | ---D | M] -- C:\Users\Milan Obešlo\AppData\Roaming\Zoner
========== Purity Check ==========
========== Custom Scans ==========
< >
[2006-11-02 14:01:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2006-11-02 14:01:49 | 000,032,608 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2007-09-28 10:09:36 | 000,000,432 | -H-- | C] () -- C:\Windows\Tasks\User_Feed_Synchronization-{85376FE6-FC64-4267-9B06-0829C1319430}.job
[2012-03-31 09:06:14 | 000,000,914 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012-09-15 08:02:03 | 000,000,936 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012-09-15 08:02:04 | 000,000,940 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012-09-15 17:55:14 | 000,000,938 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2124181350-2115944497-1007344975-1000Core.job
[2012-09-15 17:55:14 | 000,000,990 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2124181350-2115944497-1007344975-1000UA.job
< >
< MD5 for: AGP440.SYS >
[2008-01-19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008-01-19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008-01-19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008-01-19 08:42:25 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006-11-02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006-11-02 10:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009-04-11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131117T182859357781\internal_ide_channel\atapi.sys
[2009-04-11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131117T182859357781\pci\cc_0101\atapi.sys
[2009-04-11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131117T185523077455\internal_ide_channel\atapi.sys
[2009-04-11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131117T185523077455\pci\cc_0101\atapi.sys
[2009-04-11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131119T201603202379\internal_ide_channel\atapi.sys
[2009-04-11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131119T201603202379\pci\cc_0101\atapi.sys
[2009-04-11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\drivers\atapi.sys
[2009-04-11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009-04-11 07:32:26 | 000,019,944 | ---- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008-01-19 08:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008-01-19 08:41:30 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006-11-02 10:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008-02-13 18:48:47 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008-02-13 18:48:47 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008-02-13 18:48:46 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2009-04-11 07:27:20 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\Windows\System32\autochk.exe
[2009-04-11 07:27:20 | 000,643,072 | ---- | M] (Microsoft Corporation) MD5=10761177A6EBE45843F443E99509F5E7 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6002.18005_none_e3df6655bee2ee3b\autochk.exe
[2008-01-19 08:33:01 | 000,642,560 | ---- | M] (Microsoft Corporation) MD5=2FC5BE79B51714B479809358E4908FC3 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6001.18000_none_e1f3ed49c1c122ef\autochk.exe
[2006-11-02 10:44:50 | 000,640,000 | ---- | M] (Microsoft Corporation) MD5=C08D1FE284C3330934E45D6E5F5B768B -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6000.16386_none_dfbd2b4dc4d6121b\autochk.exe
< MD5 for: CDROM.SYS >
[2008-01-19 06:49:51 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=1EC25CEA0DE6AC4718BF89F9E1778B57 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_a29e71c6\cdrom.sys
[2008-01-19 06:49:51 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=1EC25CEA0DE6AC4718BF89F9E1778B57 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.0.6001.18000_none_5fa95be2a3c76a4a\cdrom.sys
[2009-04-11 05:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131117T182859357781\gencdrom\cdrom.sys
[2009-04-11 05:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131117T185523077455\gencdrom\cdrom.sys
[2009-04-11 05:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131119T201603202379\gencdrom\cdrom.sys
[2009-04-11 05:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Windows\System32\drivers\cdrom.sys
[2009-04-11 05:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_c949a5b6\cdrom.sys
[2009-04-11 05:39:17 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=6B4BFFB9BECD728097024276430DB314 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.0.6002.18005_none_6194d4eea0e93596\cdrom.sys
[2006-11-02 09:51:44 | 000,067,072 | ---- | M] (Microsoft Corporation) MD5=8D1866E61AF096AE8B582454F5E4D303 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_e487f727\cdrom.sys
< MD5 for: CNGAUDIT.DLL >
[2006-11-02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006-11-02 10:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: CRYPTSVC.DLL >
[2013-10-03 14:16:48 | 000,135,168 | ---- | M] (Microsoft Corporation) MD5=165E9D93A84A7F55EBEEB1B554110680 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23235_none_78542a95b127239a\cryptsvc.dll
[2006-11-02 10:46:03 | 000,123,392 | ---- | M] (Microsoft Corporation) MD5=1C26FB097170A2A91066D1E3A24366E3 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6000.16386_none_73c8d7689de43d15\cryptsvc.dll
[2013-04-24 05:00:30 | 000,133,120 | ---- | M] (Microsoft Corporation) MD5=3EDE4C1F9672C972479201544969ADCB -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18831_none_77c6b0b4980cf0e4\cryptsvc.dll
[2013-04-17 13:30:06 | 000,133,120 | ---- | M] (Microsoft Corporation) MD5=58CEF2D243575512657452B9E89A2E1F -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18827_none_77d7825c97ff6cfd\cryptsvc.dll
[2013-07-08 05:16:55 | 000,133,120 | ---- | M] (Microsoft Corporation) MD5=684C130BBC6DB681BAD4920A4C944AA5 -- C:\Windows\System32\cryptsvc.dll
[2013-07-08 05:16:55 | 000,133,120 | ---- | M] (Microsoft Corporation) MD5=684C130BBC6DB681BAD4920A4C944AA5 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18881_none_7790a11898357c99\cryptsvc.dll
[2008-01-19 08:34:00 | 000,128,000 | ---- | M] (Microsoft Corporation) MD5=6DE363F9F99334514C46AEC02D3E3678 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649acf4de9\cryptsvc.dll
[2012-04-23 17:00:53 | 000,133,120 | ---- | M] (Microsoft Corporation) MD5=75C6A297E364014840B48ECCD7525E30 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18618_none_77e34ec697f67015\cryptsvc.dll
[2013-07-08 03:50:53 | 000,135,168 | ---- | M] (Microsoft Corporation) MD5=828805E2E7F529B24849AD52740288DA -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23154_none_783d888db13844fe\cryptsvc.dll
[2012-04-23 15:48:06 | 000,135,168 | ---- | M] (Microsoft Corporation) MD5=C979AEA8C4D8F875CD25507D08980006 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.22840_none_78447b63b1339621\cryptsvc.dll
[2013-04-17 12:28:51 | 000,135,168 | ---- | M] (Microsoft Corporation) MD5=CC8E2C87016A07892B5448D764BF8A30 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23097_none_781547d5b15603a0\cryptsvc.dll
[2012-06-02 12:09:26 | 000,135,168 | ---- | M] (Microsoft Corporation) MD5=DD9CCF40ED80DD0D62F1B607A1EA4449 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.22869_none_7837de25b13bb212\cryptsvc.dll
[2012-06-02 01:02:32 | 000,133,120 | ---- | M] (Microsoft Corporation) MD5=F1E8C34892336D33EDDCDFE44E474F64 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18643_none_77bddd9098134535\cryptsvc.dll
[2009-04-11 07:28:18 | 000,129,024 | ---- | M] (Microsoft Corporation) MD5=FB27772BEAF8E1D28CCD825C09DA939B -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18005_none_77eb127097f11935\cryptsvc.dll
[2013-04-24 04:46:45 | 000,135,168 | ---- | M] (Microsoft Corporation) MD5=FBE051C07C3D2B9011ECB1C7A73120C1 -- C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.23101_none_7870974bb1126d44\cryptsvc.dll
< MD5 for: EXPLORER.EXE >
[2008-10-29 07:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008-10-29 07:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008-10-30 04:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007-11-14 21:30:17 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2007-11-14 21:30:17 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009-04-11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009-04-11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008-10-28 03:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006-11-02 10:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008-01-19 08:33:10 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: HAL.DLL >
[2009-04-11 07:32:46 | 000,177,128 | ---- | M] (Microsoft Corporation) MD5=B8D52005181A15D7D1470CBF2AF214DD -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131117T182859357781\acpiapic\hal.dll
[2009-04-11 07:32:46 | 000,177,128 | ---- | M] (Microsoft Corporation) MD5=B8D52005181A15D7D1470CBF2AF214DD -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131117T185523077455\acpiapic\hal.dll
[2009-04-11 07:32:46 | 000,177,128 | ---- | M] (Microsoft Corporation) MD5=B8D52005181A15D7D1470CBF2AF214DD -- C:\Users\Milan Obešlo\AppData\Local\SlimWare Utilities Inc\SlimDrivers\Backups\20131119T201603202379\acpiapic\hal.dll
[2009-04-11 07:32:46 | 000,177,128 | ---- | M] (Microsoft Corporation) MD5=B8D52005181A15D7D1470CBF2AF214DD -- C:\Windows\System32\hal.dll
< MD5 for: IASTORV.SYS >
[2008-01-19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008-01-19 08:42:51 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006-11-02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006-11-02 10:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: ISAPNP.SYS >
[2006-11-02 10:50:24 | 000,047,208 | ---- | M] (Microsoft Corporation) MD5=350FCA7E73CF65BCEF43FAE1E4E91293 -- C:\Windows\System32\drivers\isapnp.sys
[2006-11-02 10:50:24 | 000,047,208 | ---- | M] (Microsoft Corporation) MD5=350FCA7E73CF65BCEF43FAE1E4E91293 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\isapnp.sys
[2008-01-19 08:42:15 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\isapnp.sys
[2008-01-19 08:42:15 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\isapnp.sys
[2008-01-19 08:42:15 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\isapnp.sys
[2008-01-19 08:42:15 | 000,049,720 | ---- | M] (Microsoft Corporation) MD5=6C70698A3E5C4376C6AB5C7C17FB0614 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\isapnp.sys
< MD5 for: LSASS.EXE >
[2009-06-15 13:51:56 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=203D86EBD6D8E4C8501B222421E81506 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22152_none_a886901f7335e2fc\lsass.exe
[2009-09-10 15:44:14 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=2D3AC5E7AC01E905F3ABD2D745FE3A9B -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\lsass.exe
[2009-06-15 13:48:49 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=3978F3540329E16C0AC3BCF677E5669F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18051_none_a7fbf30a5a1929db\lsass.exe
[2009-02-13 08:26:04 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=59DE082968FDD257FFF0D209B9A5B460 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16820_none_a44eb0105fb4d975\lsass.exe
[2012-06-01 23:37:38 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=613DEB66A91820F0A41915B40BB8833F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22869_none_a882cf8373379c5f\lsass.exe
[2006-11-02 10:45:21 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=6A0E382E74280E4CC0DF17FE2661D003 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16386_none_a413c8c65fe02762\lsass.exe
[2009-06-15 14:03:38 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=6F1F23D3599EAE17734451936B7F17C6 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22450_none_a69e1da376115b2a\lsass.exe
[2014-10-11 00:21:41 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=86C519D59C70327434641E862A70B52B -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.23521_none_a8a5f069731e840f\lsass.exe
[2011-11-16 15:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A3E186B4B935905B829219502557314E -- C:\Windows\System32\lsass.exe
[2011-11-16 15:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A3E186B4B935905B829219502557314E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18541_none_a806cc745a10ffad\lsass.exe
[2011-11-16 15:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A3E186B4B935905B829219502557314E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18643_none_a808ceee5a0f2f82\lsass.exe
[2011-11-16 15:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A3E186B4B935905B829219502557314E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.19214_none_a82a209c59f61a0b\lsass.exe
[2009-06-15 13:57:59 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=A911ECAC81F94ADEAFBE8E3F7873EDB0 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18272_none_a600dfae5d0228c9\lsass.exe
[2009-02-13 05:58:37 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=AFF8A58280863629CA4FFA9E0B259F1E -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21010_none_a4e2f4e978ca9090\lsass.exe
[2009-06-15 13:59:08 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=BA9A67672E025078C77967731BCFC560 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21067_none_a4b3e75378eccda6\lsass.exe
[2014-12-03 01:23:58 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=C4AA089041242987308AE2A7B30E910A -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.23555_none_a88981cd73333d3e\lsass.exe
[2009-06-15 14:10:12 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=C731B1FE449D4E9CEA358C9D55B69BE9 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.16870_none_a418a0745fdd652a\lsass.exe
[2009-09-09 12:09:38 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=CB7E838C140B4087B2DA323F2D4523C5 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\lsass.exe
[2009-09-10 15:47:51 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=D09A5DA84B7C9CA9B02EBCD7FAE41C8D -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\lsass.exe
[2008-01-19 08:33:14 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18000_none_a64a8ac25ccb3836\lsass.exe
[2008-01-19 08:33:14 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_a644c0145ccecd28\lsass.exe
[2008-01-19 08:33:14 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=DCF733788C7D088D814E5F80EB4B3E0F -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.18005_none_a83603ce59ed0382\lsass.exe
[2011-11-16 14:57:04 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=EBFAEB786C46B407930811F94F08877D -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22742_none_a8916b6f732db5f5\lsass.exe
[2009-02-13 09:20:29 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=F4C62B07E5BF96F1FDCA9DB393ECED22 -- C:\Windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22376_none_a68e7da1761c2def\lsass.exe
< MD5 for: NDIS.SYS >
[2009-04-11 07:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\System32\drivers\ndis.sys
[2009-04-11 07:32:49 | 000,527,848 | ---- | M] (Microsoft Corporation) MD5=1357274D1883F68300AEADD15D7BBB42 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6002.18005_none_a9b2a4d31930d864\ndis.sys
[2006-11-02 10:51:42 | 000,500,840 | ---- | M] (Microsoft Corporation) MD5=227C11E1E7CF6EF8AFB2A238D209760C -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6000.16386_none_a59069cb1f23fc44\ndis.sys
[2008-01-19 08:43:31 | 000,529,464 | ---- | M] (Microsoft Corporation) MD5=9BDC71790FA08F0A0B5F10462B1BD0B1 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.0.6001.18000_none_a7c72bc71c0f0d18\ndis.sys
< MD5 for: NETLOGON.DLL >
[2006-11-02 10:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009-04-11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\System32\netlogon.dll
[2009-04-11 07:28:23 | 000,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008-01-19 08:35:36 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVRAID.SYS >
[2008-01-19 08:43:01 | 000,102,968 | ---- | M] (NVIDIA Corporation) MD5=2EDF9E7751554B42CBB60116DE727101 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvraid.sys
[2008-01-19 08:43:01 | 000,102,968 | ---- | M] (NVIDIA Corporation) MD5=2EDF9E7751554B42CBB60116DE727101 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvraid.sys
[2006-11-02 10:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) MD5=E69E946F80C1C31C53003BFBF50CBB7C -- C:\Windows\System32\drivers\nvraid.sys
[2006-11-02 10:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) MD5=E69E946F80C1C31C53003BFBF50CBB7C -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvraid.sys
< MD5 for: NVSTOR.SYS >
[2006-11-02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\drivers\nvstor.sys
[2006-11-02 10:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008-01-19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008-01-19 08:42:09 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008-01-19 08:36:19 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006-11-02 10:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009-04-11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\System32\scecli.dll
[2009-04-11 07:28:24 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
< MD5 for: SMSS.EXE >
[2013-07-08 02:18:50 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=18CE0D0DCB7AF0D3E67ECF12BDE1382D -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.23154_none_ae7897262f9a96cf\smss.exe
[2013-03-09 02:16:53 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=44A40B18D9F6315D35F4539A41ECDE0D -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.23076_none_ae64f5fc2fa90438\smss.exe
[2008-01-19 08:33:31 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=6701DDAF68BEDE6BBEEA9D514D73A35B -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6001.18000_none_ac3aa7fd19319fba\smss.exe
[2009-04-11 07:28:04 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=98AF15A94CD6AC37248E72E5FE789B35 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.18005_none_ae26210916536b06\smss.exe
[2013-05-02 02:27:42 | 000,064,512 | ---- | M] (Microsoft Corporation) MD5=AF2F8F104F119DD10AFA8B54A006F1B6 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.23103_none_aeada6782f72f1c3\smss.exe
[2013-03-09 02:28:08 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=BE7480C91E89EB82FC080F772C220AE4 -- C:\Windows\System32\smss.exe
[2013-03-09 02:28:08 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=BE7480C91E89EB82FC080F772C220AE4 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6002.18805_none_ae2630391653543e\smss.exe
[2006-11-02 10:45:45 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=CAA75757BB3695478C23CB0624342A61 -- C:\Windows\winsxs\x86_microsoft-windows-smss_31bf3856ad364e35_6.0.6000.16386_none_aa03e6011c468ee6\smss.exe
< MD5 for: SVCHOST.EXE >
[2006-11-02 10:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008-01-19 08:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\System32\svchost.exe
[2008-01-19 08:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2014-11-21 06:12:42 | 000,761,656 | ---- | M] (MalwareBytes) MD5=625BB08813743947985B0DEEFC35ED12 -- C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe